https://downloads.isc.org/isc/bind9/9.16.0/RELEASE-NOTES-bind-9.16.0.html :
Removed Features ... DNSSEC Lookaside Validation (DLV) is now obsolete. The dnssec-lookaside option has been marked as deprecated; when used in named.conf, it will generate a warning but will otherwise be ignored. All code enabling the use of lookaside validation has been removed from the validator, delv, and the DNSSEC tools. [GL #7]
https://gitlab.isc.org/isc-projects/bind9/-/issues/7
For now, FreeIPA allows to manage DLV RRs.
Thanks, we already know about the issue and will remove DLV key configuration as part of PR https://github.com/freeipa/freeipa/pull/4715. We cannot keep supporting the feature when BIND removes it upstream.
Metadata Update from @cheimes: - Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/4715 - Issue assigned to cheimes - Issue priority set to: normal - Issue set to the milestone: FreeIPA 4.8.7
Thank you. The title of that PR 'Fix design bug in named ipa-ext.conf' doesn't leave me a chance to guess right.
I created a new PR https://github.com/freeipa/freeipa/pull/4745. The other PR is already loading too much changes into one change set.
Metadata Update from @cheimes: - Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/4745 (was: https://github.com/freeipa/freeipa/pull/4715)
master:
ipa-4-8:
Metadata Update from @cheimes: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)