Add 2024 root zone trust-anchor, it is expected to be used in 2026.
authorflorian <florian@openbsd.org>
Fri, 9 Aug 2024 19:43:26 +0000 (19:43 +0000)
committerflorian <florian@openbsd.org>
Fri, 9 Aug 2024 19:43:26 +0000 (19:43 +0000)
commit1042786821fc1644445a2e36ebf44b9b54ca0add
tree1bbd13a2a7d401345aeea87fe67d9d033fdc19b3
parent6d453ff9e2fb025db67df7bef7da943c4cdb335e
Add 2024 root zone trust-anchor, it is expected to be used in 2026.

The trust-anchor was copied from the upcoming unbound(8) release and
verified against https://www.iana.org/reports/2024/root-ksk-2024.pdf

While here switch the 2017 trust-anchor from DNSKEY to DS to use the
same record type as for the 2024 trust-anchor. They are functionally
equivalent. It was verified against
https://www.iana.org/reports/2017/root-ksk-2017.pdf
As well as with run-time testing, i.e. unwind would still perform
DNSSEC validation.

checked pdfs & OK phessler
sbin/unwind/frontend.c
sbin/unwind/unwind.h