Page MenuHomeVyOS Platform

insufficient validation or matching too strict for dhcp-server dynamic-dns-update forward-domain/reverse-domain
Open, LowPublic

Description

When setting up dynamic-dns-update for dhcp-server while adding a forward-domain or reverse-domain the domain has to be specified with the trailing root zone dot (example.net./in-addr.arpa.), if it is missing kea-dhcp-ddns will never match the domain domains specified in the example are example.net and 168.192.in-addr.arpa without the trailing dot):

WARN  DHCP_DDNS_NO_MATCH No DNS servers match FQDN client.example.net.
WARN  DHCP_DDNS_NO_MATCH No DNS servers match FQDN 100.0.168.192.in-addr.arpa.

I suggest to either always add the root dot at the end of a domain when it is missing or to validate that a dot is supplied in the config.

Details

Version
VyOS 2026.03.24-0025-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)