I now use a backport to glibc 2.9 of the RedHat patches in 2.11 instead of my own patch set.
See https://bugs.launchpad.net/ubuntu/+source/glibc/+bug/288011/comments/3
OpenSSH still needs recompiling and "options edns0" in /etc/resolv.conf if you want it to check DNSSEC flags on SSHFP host fingerprint lookups.
I now use a backport to glibc 2.9 of the RedHat patches in 2.11 instead of my own patch set.
See https:/ /bugs.launchpad .net/ubuntu/ +source/ glibc/+ bug/288011/ comments/ 3
OpenSSH still needs recompiling and "options edns0" in /etc/resolv.conf if you want it to check DNSSEC flags on SSHFP host fingerprint lookups.