Support for NSEC3 in dnssec-policy

Implement support for NSEC3 in dnssec-policy.  Store the configuration
in kasp objects. When configuring a zone, call 'dns_zone_setnsec3param'
to queue an nsec3param event. This will ensure that any previous
chains will be removed and a chain according to the dnssec-policy is
created.

Add tests for dnssec-policy zones that uses the new 'nsec3param'
option, as well as changing to new values, changing to NSEC, and
changing from NSEC.
This commit is contained in:
Matthijs Mekking
2020-10-13 14:39:21 +02:00
parent f7ca96c805
commit 114af58ee2
18 changed files with 802 additions and 15 deletions

View File

@@ -97,6 +97,7 @@ mirror
mkeys
names
notify
nsec3
nslookup
nsupdate
padding