From Newsgroup: comp.protocols.dns.bind
RPZ wildcard domain whitelist (passthru) doesn't seem to work as it should be.
I have noticed that the last workable version is BIND 9.11.6-P1. I have tested the same configurations with versions 9.11.8, 9.11.19 and 9.11.21,
and all produce the same issue.
Has anyone experienced a similar issue here? or have I
mis-configured something?
Looks like a match for GL #1619:
https://gitlab.isc.org/isc-projects/bind9/-/issues/1619
This will fixed in BIND 9.11.22, which is due in a few weeks.
If you urgently need a patch against BIND 9.11.21, try this one:
https://gitlab.isc.org/isc-projects/bind9/-/commit/33ae88f08dabea846aee3be3af8a515fd9774ee1.diff
Sorry about the trouble!
--
Best regards,
Micha+e K-Opie+a
--- Synchronet 3.21d-Linux NewsLink 1.2