From a56af7ea87caa25dd8f1cc003a1bd38348494f85 Mon Sep 17 00:00:00 2001 From: Steven Powell Date: Wed, 8 May 2024 10:16:33 -0700 Subject: [PATCH] ISO: Add 50-dnssec.conf to fix DNSSEC issue Some machines configurations no longer have DNSSEC=no set as the system default after the Buildroot update. This results in errors when trying to pull imagse from insecure locations. Adding 50-dnssec.conf that has DNSSEC=no to override system default. --- .../rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf | 2 ++ .../rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf | 2 ++ 2 files changed, 4 insertions(+) create mode 100644 deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf create mode 100644 deploy/iso/minikube-iso/board/minikube/x86_64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf diff --git a/deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf b/deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf new file mode 100644 index 0000000000..d43d54a9da --- /dev/null +++ b/deploy/iso/minikube-iso/board/minikube/aarch64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf @@ -0,0 +1,2 @@ +[Resolve] +DNSSEC=no diff --git a/deploy/iso/minikube-iso/board/minikube/x86_64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf b/deploy/iso/minikube-iso/board/minikube/x86_64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf new file mode 100644 index 0000000000..d43d54a9da --- /dev/null +++ b/deploy/iso/minikube-iso/board/minikube/x86_64/rootfs-overlay/etc/systemd/resolved.conf.d/50-dnssec.conf @@ -0,0 +1,2 @@ +[Resolve] +DNSSEC=no