Do not use IANA DNSSEC keys in the "rpz" system test

With "dnssec-validation" now defaulting to "auto", it needs to be
explicitly set to "yes" (the previous default value) for all validating
resolvers used in system tests.  Ensure that requirement is satisfied by
the resolvers used in the "rpz" system test.
This commit is contained in:
Michał Kępień
2018-06-26 12:19:41 +02:00
parent 730c6651a0
commit ff6b717955
6 changed files with 12 additions and 0 deletions

View File

@@ -20,6 +20,8 @@ options {
listen-on-v6 { none; };
notify no;
minimal-responses no;
recursion yes;
dnssec-validation yes;
};
key rndc_key {

View File

@@ -26,6 +26,8 @@ options {
listen-on-v6 { none; };
notify yes;
minimal-responses no;
recursion yes;
dnssec-validation yes;
response-policy {
zone "bl" max-policy-ttl 100;

View File

@@ -20,6 +20,8 @@ options {
listen-on-v6 { none; };
notify no;
minimal-responses no;
recursion yes;
dnssec-validation yes;
};
include "../trusted.conf";

View File

@@ -28,6 +28,8 @@ options {
notify-delay 0;
notify yes;
minimal-responses no;
recursion yes;
dnssec-validation yes;
# turn rpz on or off
include "rpz-switch";

View File

@@ -22,6 +22,8 @@ options {
forward only;
forwarders { 10.53.0.3; };
minimal-responses no;
recursion yes;
dnssec-validation yes;
response-policy {
zone "policy1" min-update-interval 0;

View File

@@ -20,6 +20,8 @@ options {
listen-on { 10.53.0.7; };
listen-on-v6 { none; };
minimal-responses no;
recursion yes;
dnssec-validation yes;
response-policy {
zone "policy2";