]> git.netwichtig.de Git - user/henk/code/exim.git/blobdiff - doc/doc-txt/ChangeLog
DANE: do not check dns_again_means_nonexist for TLSA results of TRY_AGAIN
[user/henk/code/exim.git] / doc / doc-txt / ChangeLog
index f51a23c9c9eadba023af75465caa72055ca2bbc7..45834756b1a5b7be528452e4bc2d2f131aeaa30b 100644 (file)
@@ -98,6 +98,10 @@ JH/20 Bug 2954: (OpenSSL) Fix setting of explicit EC curve/group.  Previously
       this always failed, probably leading to the usual downgrade to in-clear
       connections.
 
+JH/20 Fix TLSA lookups.  Previously dns_again_means_nonexist would affect
+      SERVFAIL results, which breaks the downgrade resistance of DANE.  Change
+      to not checking that list for these looks.
+
 
 Exim version 4.96
 -----------------