Repository navigation
[DNS] add AD Flag support for DNSSEC to allow DANE usage #57159
Description
Activity
- addedfeature requestIssues requesting new Node.js features.Issues requesting new Node.js features.
on Feb 21, 2025 @nodejs/dns
Reacted by abwesend890 and ysautterThis would be highly appreciated and would result in a unified way of performing DANE without the need for everyone to implement such a security critical functionality themselves.
Reacted by Dmytro AlieksieievThe @nodejs/dns team has always been small and populated with folks who are very busy, so it can be hard to get their attention but it seems like maybe @nodejs/crypto might also care about this and want to comment on feasibility or related work?
- added a commit that references this issue
on Feb 3, 2026 This issue has been marked as stale due to 210 days of inactivity.
It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Jun 2, 2026 Not stale
Reacted by Dmytro Alieksieiev- removedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Jun 3, 2026 This issue has been marked as stale due to 90 days of inactivity.
It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Sep 2, 2026 Not stale
- removedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Sep 3, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsAwaiting Triage
What is the problem this feature will solve?
With ef91595 in PR #52983 related to issue #39569 you added support for TLSA resource records via
dns.resolve.This was done with the intention to support DANE.
However, to correctly make use of DANE, the records need to be DNSSEC validated.
Currently there is no possibility to validate DNSSEC via the given API.
As example, the following code (currently a nightly build)
generates the following response
Thus, as next step for the DANE implementation, this feature request aims to add information to above response of
dns.resolve, about if the records have been validated by the resolver.This allows to use technology relying on DNSSEC, such as TLSA records for DANE.
What is the feature you are proposing to solve the problem?
As DNSSEC does not protect the path between client and resolver by design, we can make use of the AD bit: RFC 6840 Section 5.7 and RFC 6840 Section 5.8
According to above mentioned RFC6840, the AD bit should be set in the query to indicate that node is going to honor the AD bit in the response. Then, the AD bit in the reply should be propagated to the returned contents of
dns.resolveIf this request is included we can get to the next step of checking TLSA records within TLS certificate verification.
What alternatives have you considered?
In #39569 @bradh352 mentioned the DO bit (RFC 6840 Section 5.6) and RFC 3225 Section 3, however as I read it, the setting the DO bit indicates that the client can understand DNSSEC related records. Thus, the resolver is going to attach RRSIG, etc. for validation on the client side.
In contrast, the DO bit should be set to 0 to indicate that node is unprepared to handle DNSSEC RR.