summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--ipalib/plugins/dns.py14
-rw-r--r--ipaserver/install/bindinstance.py6
-rw-r--r--ipatests/test_xmlrpc/test_dns_plugin.py6
3 files changed, 18 insertions, 8 deletions
diff --git a/ipalib/plugins/dns.py b/ipalib/plugins/dns.py
index 61b9e3d7a..dd1e640f4 100644
--- a/ipalib/plugins/dns.py
+++ b/ipalib/plugins/dns.py
@@ -3942,12 +3942,14 @@ class dnsconfig_mod(LDAPUpdate):
# test dnssec forwarders
non_dnssec_forwarders = []
not_responding_forwarders = []
- for forwarder in options.get('idnsforwarders', []):
- dnssec_status = validate_dnssec_forwarder(forwarder)
- if dnssec_status is None:
- not_responding_forwarders.append(forwarder)
- elif dnssec_status is False:
- non_dnssec_forwarders.append(forwarder)
+ forwarders = options.get('idnsforwarders')
+ if forwarders:
+ for forwarder in forwarders:
+ dnssec_status = validate_dnssec_forwarder(forwarder)
+ if dnssec_status is None:
+ not_responding_forwarders.append(forwarder)
+ elif dnssec_status is False:
+ non_dnssec_forwarders.append(forwarder)
result = super(dnsconfig_mod, self).execute(*keys, **options)
self.obj.postprocess_result(result)
diff --git a/ipaserver/install/bindinstance.py b/ipaserver/install/bindinstance.py
index 052665938..6cf018e9c 100644
--- a/ipaserver/install/bindinstance.py
+++ b/ipaserver/install/bindinstance.py
@@ -464,8 +464,10 @@ def check_forwarders(dns_forwarders, logger):
logger.warning("DNS forwarder %s does not return DNSSEC signatures in answers", forwarder)
logger.warning("Please fix forwarder configuration to enable DNSSEC support.\n"
"(For BIND 9 add directive \"dnssec-enable yes;\" to \"options {}\")")
- print ("WARNING: DNS forwarder %s is not configured to support "
- "DNSSEC" % forwarder)
+ print ("WARNING: DNS forwarder %s does not return DNSSEC "
+ "signatures in answers" % forwarder)
+ print "Please fix forwarder configuration to enable DNSSEC support."
+ print "(For BIND 9 add directive \"dnssec-enable yes;\" to \"options {}\")"
return forwarders_dnssec_valid
diff --git a/ipatests/test_xmlrpc/test_dns_plugin.py b/ipatests/test_xmlrpc/test_dns_plugin.py
index 0f9b16ba7..a34d11a32 100644
--- a/ipatests/test_xmlrpc/test_dns_plugin.py
+++ b/ipatests/test_xmlrpc/test_dns_plugin.py
@@ -1662,6 +1662,12 @@ class test_dns(Declarative):
expected={
'value': None,
'summary': None,
+ u'messages': (
+ {u'message': u'DNS server 172.16.31.80 not responding.',
+ u'code': 13006,
+ u'type':u'warning',
+ u'name': u'DNSServerNotRespondingWarning'},
+ ),
'result': {
'idnsforwarders': [fwd_ip],
},