Compare commits
909
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ccf3c9495e | ||
|
|
1d9d470612 | ||
|
|
e61d9fd573 | ||
|
|
d7d262e488 | ||
|
|
8ac3534192 | ||
|
|
1731228c5b | ||
|
|
9d16f25ab5 | ||
|
|
71a11c4a31 | ||
|
|
a700685a4f | ||
|
|
fe9da456d0 | ||
|
|
a33f17c8cf | ||
|
|
9578d04ae7 | ||
|
|
3cbe2bf66c | ||
|
|
f12e1a6190 | ||
|
|
0b81c8668f | ||
|
|
231b76cdd4 | ||
|
|
52b9529423 | ||
|
|
3da57cdb40 | ||
|
|
1a8933e14e | ||
|
|
850e32b734 | ||
|
|
7aa6ebb714 | ||
|
|
cd833194c6 | ||
|
|
313641e866 | ||
|
|
c807db1af6 | ||
|
|
2a725a364b | ||
|
|
6b3ff3908e | ||
|
|
5e513a0e00 | ||
|
|
36efdc151e | ||
|
|
f815515b20 | ||
|
|
5d01dfa6fa | ||
|
|
5e0523fc23 | ||
|
|
9db1468c76 | ||
|
|
795f1f2db0 | ||
|
|
84a8b6c202 | ||
|
|
7f32d08240 | ||
|
|
3155e024ef | ||
|
|
a7a4ad78e3 | ||
|
|
e3db139030 | ||
|
|
67624a4f1b | ||
|
|
c5081272d8 | ||
|
|
5bd9e3d7ba | ||
|
|
932cc52623 | ||
|
|
0b42bf3f7c | ||
|
|
9749823fa8 | ||
|
|
7d5a816e83 | ||
|
|
f11b7dcfe0 | ||
|
|
7d7a79bab2 | ||
|
|
0b205e1617 | ||
|
|
6b4f4f8be4 | ||
|
|
c88a0aa705 | ||
|
|
80d3859276 | ||
|
|
fa4d117db2 | ||
|
|
59fccc59c0 | ||
|
|
3efa0a02e5 | ||
|
|
825d632436 | ||
|
|
8f6b7d6516 | ||
|
|
eaed96af30 | ||
|
|
26543512a8 | ||
|
|
27fbb459d7 | ||
|
|
0b9365453c | ||
|
|
7e1977e850 | ||
|
|
687f3d28c2 | ||
|
|
193f48d120 | ||
|
|
f1c2e9fc96 | ||
|
|
279fa6e621 | ||
|
|
806f12bd2b | ||
|
|
3c55d1319d | ||
|
|
aaf5712373 | ||
|
|
1263af6197 | ||
|
|
46054b10cc | ||
|
|
2fc748be4d | ||
|
|
311ba6bc1a | ||
|
|
6039a662c1 | ||
|
|
7963e11c7c | ||
|
|
25d78ece28 | ||
|
|
5cab9cc0ce | ||
|
|
0c5ca02bc2 | ||
|
|
6cd296b7ad | ||
|
|
c44bb94bc8 | ||
|
|
8ec9ce2987 | ||
|
|
5d718a2f9c | ||
|
|
c3ffc2e55d | ||
|
|
302cb51bc4 | ||
|
|
9927c641ae | ||
|
|
30a8ca5010 | ||
|
|
780fee45a7 | ||
|
|
a464d01f68 | ||
|
|
40bf7963ac | ||
|
|
adf892c713 | ||
|
|
cdb5f33baf | ||
|
|
e0d80dbc1d | ||
|
|
a022b5a817 | ||
|
|
62e8ffff0a | ||
|
|
7a2f2d9ba0 | ||
|
|
4e1806d320 | ||
|
|
b1f903cfe7 | ||
|
|
d0e0f26753 | ||
|
|
08237a3187 | ||
|
|
52f4e01df1 | ||
|
|
e8bfdebfad | ||
|
|
ddb93d31dc | ||
|
|
f18a54a190 | ||
|
|
43a3530e26 | ||
|
|
90de0c8201 | ||
|
|
12e219aeb7 | ||
|
|
b24553b060 | ||
|
|
3541849eb2 | ||
|
|
b2549fe190 | ||
|
|
cccda7f37e | ||
|
|
be1190b4bd | ||
|
|
fc41c577a3 | ||
|
|
1fc35fe236 | ||
|
|
48d417b283 | ||
|
|
2ee75dd6b6 | ||
|
|
04b69f0fbf | ||
|
|
efa452778d | ||
|
|
dbb6ecaca6 | ||
|
|
859dc25b2a | ||
|
|
67fd4c2705 | ||
|
|
1077d5d5d7 | ||
|
|
eb17eddf9c | ||
|
|
643d0b9816 | ||
|
|
dca9b1cb49 | ||
|
|
9b41e3e190 | ||
|
|
ced43743a8 | ||
|
|
e635e8b30c | ||
|
|
a273274614 | ||
|
|
905105682c | ||
|
|
16717de692 | ||
|
|
cd2a48b5cf | ||
|
|
1863e20b1b | ||
|
|
5f633b1203 | ||
|
|
da3d7fea6c | ||
|
|
54b41a6348 | ||
|
|
e6786ca109 | ||
|
|
428a7f9d79 | ||
|
|
c4dc5084ee | ||
|
|
c225d853f7 | ||
|
|
61c065a82c | ||
|
|
f640a4947f | ||
|
|
19a0f2cc15 | ||
|
|
cd6a9eea35 | ||
|
|
383868ee66 | ||
|
|
fc11dd9ebe | ||
|
|
928f535b8a | ||
|
|
2f925c1025 | ||
|
|
da2dfa2925 | ||
|
|
015ab04856 | ||
|
|
1282a7b132 | ||
|
|
5ffbae904d | ||
|
|
75f62d93df | ||
|
|
305971d1d3 | ||
|
|
29020d67b7 | ||
|
|
6d436a8ece | ||
|
|
2c6713049e | ||
|
|
ed3e5b9f24 | ||
|
|
d173a5fc50 | ||
|
|
394ff0403f | ||
|
|
fff5255c49 | ||
|
|
45852a37a4 | ||
|
|
36a7377ade | ||
|
|
7eefeb32a7 | ||
|
|
3b75fb5c0f | ||
|
|
9cba56a343 | ||
|
|
abac3cc346 | ||
|
|
f2fe866427 | ||
|
|
48141f48b1 | ||
|
|
54dbf48b44 | ||
|
|
08f36cf4fb | ||
|
|
ad69ef9d09 | ||
|
|
40d8785310 | ||
|
|
df800d27d8 | ||
|
|
e163b0fe68 | ||
|
|
fb8c4a6bc9 | ||
|
|
7b36ad9795 | ||
|
|
5641d615c8 | ||
|
|
c0a7296576 | ||
|
|
6157180370 | ||
|
|
8dc44fde9b | ||
|
|
abe57cc913 | ||
|
|
954941b121 | ||
|
|
5994a39c80 | ||
|
|
0c69af9b70 | ||
|
|
12d2470191 | ||
|
|
760e3de10c | ||
|
|
65d3d73195 | ||
|
|
8a932cc59f | ||
|
|
6e9dd32ded | ||
|
|
87850966d0 | ||
|
|
fe349528eb | ||
|
|
9860bf7736 | ||
|
|
f8f74c4133 | ||
|
|
5b976ced07 | ||
|
|
d6143438c3 | ||
|
|
875245e3c4 | ||
|
|
6d07a89f6c | ||
|
|
ab273fe3ac | ||
|
|
39131fff99 | ||
|
|
2d7ef7fdb7 | ||
|
|
bd598c1756 | ||
|
|
10ed862c72 | ||
|
|
b605bbbb0f | ||
|
|
b52da87328 | ||
|
|
4e32ae26b8 | ||
|
|
ba97097eaf | ||
|
|
2176cc236d | ||
|
|
09609ba50d | ||
|
|
b0ccf52763 | ||
|
|
a79df62abf | ||
|
|
80f5acb51e | ||
|
|
68a9007749 | ||
|
|
8d87bd79e5 | ||
|
|
12d91a5519 | ||
|
|
a3398dba83 | ||
|
|
bf10569154 | ||
|
|
b041f0ecb7 | ||
|
|
44dc7cb1d0 | ||
|
|
2e77a957cb | ||
|
|
aee54439cc | ||
|
|
c0f0bbda1e | ||
|
|
e6418829d0 | ||
|
|
877507e813 | ||
|
|
86bccbee3e | ||
|
|
e16fa96712 | ||
|
|
01ffac6927 | ||
|
|
372ce32e19 | ||
|
|
94ca1cb4cb | ||
|
|
e046429e05 | ||
|
|
e2e93dfa7b | ||
|
|
5eee3743e2 | ||
|
|
c717c61ab0 | ||
|
|
0810b14604 | ||
|
|
fc69c74e60 | ||
|
|
f521a47af7 | ||
|
|
bd29cbe6aa | ||
|
|
b67c0e9a49 | ||
|
|
61d91562b1 | ||
|
|
8b071e63b0 | ||
|
|
b8c2fd6c72 | ||
|
|
bff3b1df40 | ||
|
|
ff50f1db55 | ||
|
|
ea30ea795d | ||
|
|
f3a565668f | ||
|
|
455d347569 | ||
|
|
96ce7f6526 | ||
|
|
a46344cd6d | ||
|
|
855cb68fb7 | ||
|
|
5563138dca | ||
|
|
5026340d9f | ||
|
|
bf8c55b56c | ||
|
|
ff25a712f7 | ||
|
|
5fb1530285 | ||
|
|
6d9f4392f9 | ||
|
|
f44c7e71a6 | ||
|
|
151e614c36 | ||
|
|
ca2a1e9eb5 | ||
|
|
0aa5b8c2d8 | ||
|
|
ae06702ca9 | ||
|
|
dbd13430ce | ||
|
|
c6110f2298 | ||
|
|
aedf9eab89 | ||
|
|
9c8d239e5f | ||
|
|
88eb4fca9d | ||
|
|
1d4f3e75f8 | ||
|
|
9f168992da | ||
|
|
5eb1c53ca2 | ||
|
|
79ee58d29d | ||
|
|
16c19e5477 | ||
|
|
550042e162 | ||
|
|
d03e7dd277 | ||
|
|
51fc19f726 | ||
|
|
01347cce29 | ||
|
|
f36db31f96 | ||
|
|
1b50f0d68e | ||
|
|
dc517fde01 | ||
|
|
350f415b02 | ||
|
|
b4d6057cf0 | ||
|
|
366694ad6a | ||
|
|
297f40731e | ||
|
|
b2b5dd559d | ||
|
|
624e141817 | ||
|
|
5f25e73ff9 | ||
|
|
8695fa7a14 | ||
|
|
0fae33c4d5 | ||
|
|
ec955e008d | ||
|
|
bcc65417d7 | ||
|
|
db3543452c | ||
|
|
153ec122b2 | ||
|
|
19e1280ee7 | ||
|
|
1077e73992 | ||
|
|
ac9cc645a2 | ||
|
|
ad544a5ef3 | ||
|
|
3a13626ed1 | ||
|
|
86e79deccd | ||
|
|
2bc8ae2486 | ||
|
|
925392a19f | ||
|
|
c5a50f19df | ||
|
|
279e3f68cc | ||
|
|
68bde02f3e | ||
|
|
247c4bffc3 | ||
|
|
95f8f3ebd1 | ||
|
|
979691b8b5 | ||
|
|
d81f97c523 | ||
|
|
592d281377 | ||
|
|
7aca55cd83 | ||
|
|
5d9f318a8f | ||
|
|
9feb8eda57 | ||
|
|
b20c383c6b | ||
|
|
c71ada9e6e | ||
|
|
905c946de0 | ||
|
|
6ce89d1db6 | ||
|
|
cab45cd588 | ||
|
|
b17ec45352 | ||
|
|
3b956daecf | ||
|
|
9b72b0258e | ||
|
|
1963c1c54a | ||
|
|
763250ea4e | ||
|
|
e5e815d21a | ||
|
|
3f39cbcc76 | ||
|
|
b0f0bbd6bc | ||
|
|
d889e9701a | ||
|
|
41089d26e2 | ||
|
|
9251d20f2a | ||
|
|
6720b9fe94 | ||
|
|
e9c3fd20d6 | ||
|
|
2f2319de0d | ||
|
|
f218fe643a | ||
|
|
c91b60a119 | ||
|
|
7d259433d2 | ||
|
|
27f8686a3b | ||
|
|
0f83518a99 | ||
|
|
8fd7205f18 | ||
|
|
ae53c8c073 | ||
|
|
ef413fafe5 | ||
|
|
67145ee7da | ||
|
|
89b448b506 | ||
|
|
450c3bb498 | ||
|
|
9b4b69eac1 | ||
|
|
f5331a5045 | ||
|
|
c7c6605eb0 | ||
|
|
b4ed36acde | ||
|
|
e02ccd485e | ||
|
|
dfcebf4703 | ||
|
|
ae787010e1 | ||
|
|
a5003acddf | ||
|
|
65bbefae47 | ||
|
|
bd851f3490 | ||
|
|
c7a3571cf6 | ||
|
|
b8f874d1b3 | ||
|
|
10e08bdd6e | ||
|
|
669b1ee4d8 | ||
|
|
b5e566fa4d | ||
|
|
1c22fb9bdc | ||
|
|
dc508331b4 | ||
|
|
e4de496a5d | ||
|
|
b1c2fed160 | ||
|
|
8bd81db458 | ||
|
|
e60977ec32 | ||
|
|
6b2d0a74ac | ||
|
|
f1ff7b7b8b | ||
|
|
b695e0159a | ||
|
|
0bbfdc2806 | ||
|
|
e086d0e6cc | ||
|
|
675944370a | ||
|
|
fce41660df | ||
|
|
3da71a0572 | ||
|
|
50331a1a93 | ||
|
|
f8376838e7 | ||
|
|
a8bb437cbd | ||
|
|
34b8a84928 | ||
|
|
15ab3696b0 | ||
|
|
6fe6eff8de | ||
|
|
cac64d5bd8 | ||
|
|
fcf06578df | ||
|
|
3638fe4f9a | ||
|
|
a3862bb60b | ||
|
|
38917972ea | ||
|
|
985137ff66 | ||
|
|
2eff17e423 | ||
|
|
e331fe245d | ||
|
|
8b7fa47bf2 | ||
|
|
667e5aaded | ||
|
|
ce0d2caf1b | ||
|
|
7362201ff0 | ||
|
|
9573525eaf | ||
|
|
fc9d2a1449 | ||
|
|
a3511da52b | ||
|
|
820251a036 | ||
|
|
862572d505 | ||
|
|
1beb3ce612 | ||
|
|
64ab7727e9 | ||
|
|
f37e34be9d | ||
|
|
34862bb497 | ||
|
|
432b145c6e | ||
|
|
7579191f73 | ||
|
|
bda68146b0 | ||
|
|
1ce9ab3e3b | ||
|
|
0a9fcb1124 | ||
|
|
7025ee2652 | ||
|
|
702ca0b0a8 | ||
|
|
78b3284647 | ||
|
|
cc7f86f702 | ||
|
|
e1fc4161d1 | ||
|
|
71110063f1 | ||
|
|
c8ae58f9f8 | ||
|
|
6519b2ccad | ||
|
|
eb5f89b06e | ||
|
|
f4d18d665f | ||
|
|
0794f78e65 | ||
|
|
93e0978d98 | ||
|
|
91cbc837ff | ||
|
|
375962bc49 | ||
|
|
eb60656b9b | ||
|
|
32967e6895 | ||
|
|
e3e4650e2f | ||
|
|
cdf3ea38b5 | ||
|
|
7860facc0a | ||
|
|
5302b44251 | ||
|
|
7d7346d623 | ||
|
|
ea882c9959 | ||
|
|
36f3facb1a | ||
|
|
01a10cbd81 | ||
|
|
f0d57bc9ad | ||
|
|
40adc17544 | ||
|
|
81fd55a535 | ||
|
|
3c18ba3aba | ||
|
|
5d09fe745e | ||
|
|
cf0516fab3 | ||
|
|
46977c5f31 | ||
|
|
6f0ed96f5f | ||
|
|
eb550d94ea | ||
|
|
f781d497d1 | ||
|
|
76a1507769 | ||
|
|
6cdfe5a4bb | ||
|
|
04b1b38fdb | ||
|
|
04813aa271 | ||
|
|
b0414d02f5 | ||
|
|
514f544c08 | ||
|
|
dbebb4a6cd | ||
|
|
895a62b0be | ||
|
|
e55297ee1e | ||
|
|
79df5c5196 | ||
|
|
d9fdcc5131 | ||
|
|
6d12fcbb39 | ||
|
|
cc3a3a3077 | ||
|
|
ce053ae713 | ||
|
|
8076b157b1 | ||
|
|
63f763baa9 | ||
|
|
e939393c1c | ||
|
|
3d7ca1bba2 | ||
|
|
ba9cececca | ||
|
|
8b39e41b24 | ||
|
|
dee8a42282 | ||
|
|
595db826f7 | ||
|
|
41b324b22a | ||
|
|
e7f4d4e09d | ||
|
|
38637a6e1d | ||
|
|
a9bc1daf4f | ||
|
|
7dc66d649a | ||
|
|
19e91f021d | ||
|
|
0a2ff2f893 | ||
|
|
eeef28e6d0 | ||
|
|
a65d6dc605 | ||
|
|
9afe470beb | ||
|
|
127820c20f | ||
|
|
2ac5c5415c | ||
|
|
fa8f5570bc | ||
|
|
6d4ad45aee | ||
|
|
13de8b7015 | ||
|
|
9b6701361e | ||
|
|
b514948e9d | ||
|
|
f0af708359 | ||
|
|
f75c7e218c | ||
|
|
76d66c8e52 | ||
|
|
a1b08748d8 | ||
|
|
450d4ae030 | ||
|
|
fb76b4340c | ||
|
|
1d08fbdc2d | ||
|
|
5211674cef | ||
|
|
ef2dfb76b9 | ||
|
|
e844d1f3a8 | ||
|
|
5f5bb6cba2 | ||
|
|
961ff176c2 | ||
|
|
ef55474f25 | ||
|
|
ad120f93e4 | ||
|
|
368e6fb1e7 | ||
|
|
64282ffd6d | ||
|
|
c44709c516 | ||
|
|
4d9b982abf | ||
|
|
de9b26db37 | ||
|
|
afdc7dee62 | ||
|
|
eac1bcca33 | ||
|
|
8371f50c6e | ||
|
|
c363a13c50 | ||
|
|
6833e6ba4c | ||
|
|
cd4d18cfee | ||
|
|
520a24ee91 | ||
|
|
0ddedb1781 | ||
|
|
2a2e4dbefb | ||
|
|
27f8258b13 | ||
|
|
ab23f14a30 | ||
|
|
fff31a08a9 | ||
|
|
e5ad562a79 | ||
|
|
83271977c3 | ||
|
|
799a4ab7d7 | ||
|
|
7cbcbb2938 | ||
|
|
ece0a1d2c8 | ||
|
|
64ebbbcbb1 | ||
|
|
77d2bb78af | ||
|
|
bbf5334896 | ||
|
|
54d1801f14 | ||
|
|
f10e82ecfb | ||
|
|
7115862967 | ||
|
|
a9785879cb | ||
|
|
587355bb62 | ||
|
|
e101c2937c | ||
|
|
a9775fe88d | ||
|
|
b42ba4cace | ||
|
|
b91b3c4f09 | ||
|
|
c459aec591 | ||
|
|
27015815a5 | ||
|
|
e4aad620d2 | ||
|
|
8324731a56 | ||
|
|
02a7cfcc8a | ||
|
|
38a32e22c4 | ||
|
|
5c60871fd9 | ||
|
|
1de271fbae | ||
|
|
001447b3ef | ||
|
|
9f6f43d291 | ||
|
|
895c88905b | ||
|
|
a471195d58 | ||
|
|
10d76890e4 | ||
|
|
7de6178969 | ||
|
|
3a8f5eff97 | ||
|
|
eec72f05ea | ||
|
|
fff59bfeb3 | ||
|
|
d738f55bbf | ||
|
|
f22b76502b | ||
|
|
d6c1bb232c | ||
|
|
7648521c39 | ||
|
|
fe22ed4862 | ||
|
|
ca31221f5b | ||
|
|
fa9ae9dad2 | ||
|
|
55c437ae71 | ||
|
|
b7f5909933 | ||
|
|
6b62b02a83 | ||
|
|
ee73600181 | ||
|
|
f2445757f1 | ||
|
|
2226e9ec25 | ||
|
|
199726face | ||
|
|
3894fcbaad | ||
|
|
194d3c5a10 | ||
|
|
69f73c967e | ||
|
|
a73c49b952 | ||
|
|
dbd66db23f | ||
|
|
6bfa073b71 | ||
|
|
c33527c0d2 | ||
|
|
3a6abd091b | ||
|
|
42e5782189 | ||
|
|
2df4d8d3dd | ||
|
|
00d47e05ae | ||
|
|
4f175dc980 | ||
|
|
6e8045d087 | ||
|
|
e1488ac684 | ||
|
|
e28c0fcdfa | ||
|
|
9178588ed0 | ||
|
|
276ae4fe5c | ||
|
|
1c210d73bd | ||
|
|
04f7e40618 | ||
|
|
e08ab67c41 | ||
|
|
af0159c4ee | ||
|
|
3f52bb9498 | ||
|
|
99c0705417 | ||
|
|
e851b0cf9c | ||
|
|
c3bad668ba | ||
|
|
05eeaf4914 | ||
|
|
eaeb251254 | ||
|
|
6a1f2578fc | ||
|
|
ef42c36b22 | ||
|
|
dfc1a21b59 | ||
|
|
3bbcca9d17 | ||
|
|
6b7a9242d6 | ||
|
|
38d8198fd0 | ||
|
|
2ec35a7772 | ||
|
|
d9f13588fd | ||
|
|
644630bb3c | ||
|
|
4a8fa74137 | ||
|
|
de99148154 | ||
|
|
1166ab523b | ||
|
|
f6779c3053 | ||
|
|
a6c4d1405e | ||
|
|
fcf7d085b9 | ||
|
|
c83d2dbb2b | ||
|
|
23cb85e6e6 | ||
|
|
c5296e040b | ||
|
|
89266715e6 | ||
|
|
59b6d3ae92 | ||
|
|
6e561e503d | ||
|
|
103ebb0f6b | ||
|
|
c93399e357 | ||
|
|
3b0c34c83f | ||
|
|
a2b52a3a7c | ||
|
|
70d6c84aa6 | ||
|
|
0ea743459d | ||
|
|
785eb615e3 | ||
|
|
49c3a15727 | ||
|
|
b450054488 | ||
|
|
8cd113407a | ||
|
|
7de8e021c2 | ||
|
|
0da8837d0e | ||
|
|
94a70dc397 | ||
|
|
a416993543 | ||
|
|
76728b8bc6 | ||
|
|
9822b878e0 | ||
|
|
ccbc5af870 | ||
|
|
bdc250babc | ||
|
|
cb1356b321 | ||
|
|
e1cc7fc197 | ||
|
|
0e57851625 | ||
|
|
5c677cf208 | ||
|
|
bf06c5e25a | ||
|
|
40da04a139 | ||
|
|
81bae80881 | ||
|
|
be30c7f74e | ||
|
|
99525899e8 | ||
|
|
6500973c26 | ||
|
|
3102b936a1 | ||
|
|
5870f67ab1 | ||
|
|
d1ba1579ee | ||
|
|
6ecf117f14 | ||
|
|
7f2157c848 | ||
|
|
06820a34e3 | ||
|
|
ee93a63b2f | ||
|
|
1862010c83 | ||
|
|
7d543e7b8f | ||
|
|
8ce2b50c32 | ||
|
|
8fa3d35e1b | ||
|
|
d84b71a0a9 | ||
|
|
a1cc5e9289 | ||
|
|
f4dd23b4f4 | ||
|
|
6e67205ba7 | ||
|
|
e6be77a26c | ||
|
|
43dd26f988 | ||
|
|
fb1c018ecc | ||
|
|
7341b65d47 | ||
|
|
0d5a20cb05 | ||
|
|
8649a7a09f | ||
|
|
ed26903938 | ||
|
|
0532b01ed6 | ||
|
|
5eddd1ec39 | ||
|
|
dc653165b0 | ||
|
|
8286a91388 | ||
|
|
277cd95e91 | ||
|
|
7b4d892cb6 | ||
|
|
4acf3ecbc7 | ||
|
|
28318a2528 | ||
|
|
4c505019e1 | ||
|
|
8430d83828 | ||
|
|
3754970367 | ||
|
|
443f232a77 | ||
|
|
2a59ad3b8c | ||
|
|
0aa00c0fbe | ||
|
|
9cd3264af8 | ||
|
|
2d7fc2d5a6 | ||
|
|
4b24acd9f1 | ||
|
|
4d6469ffd8 | ||
|
|
b3def9bbf7 | ||
|
|
d9cf22cc5a | ||
|
|
b13b64028b | ||
|
|
22b2741ede | ||
|
|
a42b13d33c | ||
|
|
442d6ced85 | ||
|
|
e5e510dbab | ||
|
|
91c526913b | ||
|
|
c441671e8f | ||
|
|
ff3c8a493f | ||
|
|
cadd13e50e | ||
|
|
e81bc5977d | ||
|
|
5fa0c17a78 | ||
|
|
a75a29c672 | ||
|
|
64b01fda14 | ||
|
|
0d8b7ca851 | ||
|
|
68a6aa2d6b | ||
|
|
2c0dd6a4a0 | ||
|
|
ba58299f9f | ||
|
|
8e2a60c9be | ||
|
|
2e8bd7f1b7 | ||
|
|
a5e335d7fc | ||
|
|
cb1aa919c6 | ||
|
|
d6b57bc73c | ||
|
|
d329d5aa52 | ||
|
|
a6ddec4212 | ||
|
|
846e500945 | ||
|
|
d34be4f321 | ||
|
|
568a4d27a5 | ||
|
|
b96444c0ea | ||
|
|
b8c73bcafc | ||
|
|
0e8a52d67d | ||
|
|
a9a7328240 | ||
|
|
c5f64b7598 | ||
|
|
b6912ff3a5 | ||
|
|
999be987b8 | ||
|
|
e250e9a4cf | ||
|
|
9076806d8b | ||
|
|
e3de0d3aad | ||
|
|
b0e0a30968 | ||
|
|
be63967070 | ||
|
|
4f732afd9f | ||
|
|
9af3aa4881 | ||
|
|
f87803be34 | ||
|
|
12e4b8f53f | ||
|
|
89d64b1a47 | ||
|
|
92d603dee6 | ||
|
|
6274516032 | ||
|
|
c725b1099d | ||
|
|
f3ed132d3e | ||
|
|
3e132fc2dd | ||
|
|
e53dc99784 | ||
|
|
324ee987c2 | ||
|
|
743fcc320a | ||
|
|
6e988470c5 | ||
|
|
7f798dd711 | ||
|
|
6726b1b9ae | ||
|
|
2eb62acc96 | ||
|
|
b98552bc41 | ||
|
|
2967621174 | ||
|
|
b30361923f | ||
|
|
3143f3898a | ||
|
|
cd456aadac | ||
|
|
83a781a5cb | ||
|
|
bf02e7fc0e | ||
|
|
94b66c797a | ||
|
|
906e5d9a44 | ||
|
|
3586ef316a | ||
|
|
06ae29048d | ||
|
|
c0bb9cf185 | ||
|
|
ebf8257047 | ||
|
|
caf3ffe905 | ||
|
|
7c409af694 | ||
|
|
52bf46a127 | ||
|
|
50b107e596 | ||
|
|
436100336e | ||
|
|
874d2a93ca | ||
|
|
780bc6eec5 | ||
|
|
71255518a1 | ||
|
|
209e3656f4 | ||
|
|
7808280b34 | ||
|
|
97fa54f9ce | ||
|
|
d36d62e4bd | ||
|
|
3cb679d7eb | ||
|
|
88d24b4a1f | ||
|
|
247ec13dca | ||
|
|
d76a60502e | ||
|
|
190bfdeebf | ||
|
|
0accbaef11 | ||
|
|
279b38bba7 | ||
|
|
c5daf291bc | ||
|
|
fa49fa674f | ||
|
|
f9bb7d0c54 | ||
|
|
82494242f6 | ||
|
|
b7e19163d0 | ||
|
|
c4e5249157 | ||
|
|
76ff26a403 | ||
|
|
8e7dd3dc3b | ||
|
|
29066a4d86 | ||
|
|
1d88d93a9f | ||
|
|
09b12d15aa | ||
|
|
5176eed72b | ||
|
|
af9b016643 | ||
|
|
143b2be8af | ||
|
|
337bd0b9a6 | ||
|
|
8a632dc62e | ||
|
|
2eafec42b4 | ||
|
|
8f2f39c7de | ||
|
|
202cfcbd68 | ||
|
|
4e94f97dc3 | ||
|
|
3ce45a6410 | ||
|
|
f0071326b6 | ||
|
|
a69894ef8d | ||
|
|
fd6e014c51 | ||
|
|
9c19f7fb52 | ||
|
|
e48608e085 | ||
|
|
3b14986bdf | ||
|
|
b996c77e49 | ||
|
|
28258cb820 | ||
|
|
f52d07f49d | ||
|
|
6c3042c1c1 | ||
|
|
5c4a9f33ca | ||
|
|
19f6ed9078 | ||
|
|
1f67b99159 | ||
|
|
4225f61923 | ||
|
|
54917c2337 | ||
|
|
d68222d82d | ||
|
|
76da0b0d88 | ||
|
|
5afab04e30 | ||
|
|
b783a1581b | ||
|
|
158f643b1b | ||
|
|
73f5b98c6a | ||
|
|
42bbd88053 | ||
|
|
e3dba335d6 | ||
|
|
869d896a81 | ||
|
|
eeebfdd21a | ||
|
|
ff176a9e4f | ||
|
|
d64c82f27f | ||
|
|
b20d2886be | ||
|
|
6c12ffeaea | ||
|
|
2c72343b44 | ||
|
|
49d33b4bc7 | ||
|
|
3915248ed4 | ||
|
|
13b0ed0b27 | ||
|
|
5f164676bf | ||
|
|
8c76e41fde | ||
|
|
2e8e9ee1c6 | ||
|
|
b7e3a3f29f | ||
|
|
924fdffe5e | ||
|
|
7a9d9a7ba7 | ||
|
|
b28493b383 | ||
|
|
d784df90b6 | ||
|
|
0b1ac9b978 | ||
|
|
cfe4fac9dd | ||
|
|
d715750881 | ||
|
|
91cf1000ac | ||
|
|
4f65b92f3e | ||
|
|
c95fad6e63 | ||
|
|
a6aa7dd5b9 | ||
|
|
23b633ec92 | ||
|
|
46d48a2f5c | ||
|
|
44f2aedc24 | ||
|
|
4d8d8cde8e | ||
|
|
eba7320df5 | ||
|
|
bad4b4d751 | ||
|
|
4e9f851074 | ||
|
|
809350646f | ||
|
|
957babcb24 | ||
|
|
8c55d10d43 | ||
|
|
063a4dc0ca | ||
|
|
2a238ee552 | ||
|
|
31848f6338 | ||
|
|
fe45df681a | ||
|
|
35c4a601b6 | ||
|
|
71da3b1939 | ||
|
|
9bfde0aa2f | ||
|
|
d838cbc2b6 | ||
|
|
99772d76b0 | ||
|
|
7cf5baf22e | ||
|
|
b9ff1fe73f | ||
|
|
5418be142c | ||
|
|
029d4e2e96 | ||
|
|
3e712d3702 | ||
|
|
0f06d0d648 | ||
|
|
254b0113c3 | ||
|
|
99b63ca8e5 | ||
|
|
41b0f3c45e | ||
|
|
d7900926bf | ||
|
|
55c63a0a2a | ||
|
|
69a03ffca0 | ||
|
|
8425487239 | ||
|
|
27c469af58 | ||
|
|
f0abe76652 | ||
|
|
fc2991c7ef | ||
|
|
651daefa44 | ||
|
|
cce4e4dfd1 | ||
|
|
c41d48e594 | ||
|
|
45821672b8 | ||
|
|
0d394c0384 | ||
|
|
f2a67f7a06 | ||
|
|
eb38c046c2 | ||
|
|
a99459476b | ||
|
|
8bdbeeb578 | ||
|
|
c0ea6ba330 | ||
|
|
37f6a3aa4a | ||
|
|
24857eb4d7 | ||
|
|
55a6083be3 | ||
|
|
0f5bed2b20 | ||
|
|
738f50a3ea | ||
|
|
fada3ef8b4 | ||
|
|
1ff98661fd | ||
|
|
aa581ebea2 | ||
|
|
3dd871586f | ||
|
|
66ca4808dc | ||
|
|
4b5c0b2f7f | ||
|
|
77ba4437d2 | ||
|
|
7170458302 | ||
|
|
a944881a26 | ||
|
|
e7e864a4f7 | ||
|
|
5b66b31816 | ||
|
|
e8fea68e5e | ||
|
|
82a9f3af05 | ||
|
|
8b07cdbf50 | ||
|
|
a48b15f7b5 | ||
|
|
edc82c63e0 | ||
|
|
d28b2fe160 | ||
|
|
b1faf7c293 | ||
|
|
2040cb5d03 | ||
|
|
5c55176815 | ||
|
|
22c656d70e | ||
|
|
c7006f0e70 | ||
|
|
8f7c2b2005 | ||
|
|
733dea75ad | ||
|
|
a4f1719ff3 | ||
|
|
575f111831 | ||
|
|
e07e0b2f56 | ||
|
|
5f0be5b5cd | ||
|
|
c636f4796b | ||
|
|
8c9921ab10 | ||
|
|
772e290caa | ||
|
|
baf58aadc7 | ||
|
|
e8b033871d | ||
|
|
6f6d3c23f4 |
@@ -1,76 +0,0 @@
|
|||||||
BasedOnStyle: LLVM
|
|
||||||
IndentWidth: 8
|
|
||||||
UseTab: Always
|
|
||||||
BreakBeforeBraces: Custom
|
|
||||||
BraceWrapping:
|
|
||||||
AfterClass: false
|
|
||||||
AfterEnum: false
|
|
||||||
AfterStruct: false
|
|
||||||
AfterUnion: false
|
|
||||||
AfterControlStatement: MultiLine
|
|
||||||
AfterFunction: false # should also be MultiLine, but not yet supported
|
|
||||||
AfterExternBlock: false
|
|
||||||
BeforeElse: false
|
|
||||||
BeforeWhile: false
|
|
||||||
IndentBraces: false
|
|
||||||
SplitEmptyFunction: true
|
|
||||||
AllowShortIfStatementsOnASingleLine: false
|
|
||||||
IndentCaseLabels: false
|
|
||||||
AlwaysBreakAfterReturnType: All
|
|
||||||
Cpp11BracedListStyle: false
|
|
||||||
ColumnLimit: 80
|
|
||||||
AlignAfterOpenBracket: Align
|
|
||||||
AlignConsecutiveBitFields: true
|
|
||||||
AlignConsecutiveDeclarations: false
|
|
||||||
AlignConsecutiveMacros: true
|
|
||||||
AlignTrailingComments: true
|
|
||||||
AllowAllArgumentsOnNextLine: true
|
|
||||||
AlwaysBreakBeforeMultilineStrings: false
|
|
||||||
BreakBeforeBinaryOperators: None
|
|
||||||
BreakBeforeTernaryOperators: true
|
|
||||||
AlignEscapedNewlines: Left
|
|
||||||
DerivePointerAlignment: false
|
|
||||||
PointerAlignment: Right
|
|
||||||
PointerBindsToType: false
|
|
||||||
IncludeBlocks: Regroup
|
|
||||||
IncludeCategories:
|
|
||||||
- Regex: '^<isc/'
|
|
||||||
Priority: 5
|
|
||||||
- Regex: '^<(pk11|pkcs11)/'
|
|
||||||
Priority: 10
|
|
||||||
- Regex: '^<dns/'
|
|
||||||
Priority: 15
|
|
||||||
- Regex: '^<dst/'
|
|
||||||
Priority: 20
|
|
||||||
- Regex: '^<isccc/'
|
|
||||||
Priority: 25
|
|
||||||
- Regex: '^<isccfg/'
|
|
||||||
Priority: 30
|
|
||||||
- Regex: '^<ns/'
|
|
||||||
Priority: 35
|
|
||||||
- Regex: '^<irs/'
|
|
||||||
Priority: 40
|
|
||||||
- Regex: '^<bind9/'
|
|
||||||
Priority: 45
|
|
||||||
- Regex: '^<(dig|named|rndc|confgen|dlz)/'
|
|
||||||
Priority: 50
|
|
||||||
- Regex: '^<dlz_'
|
|
||||||
Priority: 55
|
|
||||||
- Regex: '^".*"'
|
|
||||||
Priority: 99
|
|
||||||
- Regex: '<openssl/'
|
|
||||||
Priority: 1
|
|
||||||
- Regex: '<(mysql|protobuf-c)/'
|
|
||||||
Priority: 1
|
|
||||||
- Regex: '.*'
|
|
||||||
Priority: 0
|
|
||||||
IndentExternBlock: NoIndent
|
|
||||||
KeepEmptyLinesAtTheStartOfBlocks: false
|
|
||||||
MaxEmptyLinesToKeep: 1
|
|
||||||
PenaltyBreakAssignment: 30
|
|
||||||
PenaltyBreakComment: 10
|
|
||||||
PenaltyBreakFirstLessLess: 0
|
|
||||||
PenaltyBreakString: 80
|
|
||||||
PenaltyExcessCharacter: 100
|
|
||||||
Standard: Cpp11
|
|
||||||
ContinuationIndentWidth: 8
|
|
||||||
@@ -1,64 +0,0 @@
|
|||||||
BasedOnStyle: LLVM
|
|
||||||
IndentWidth: 8
|
|
||||||
UseTab: Always
|
|
||||||
BreakBeforeBraces: Custom
|
|
||||||
BraceWrapping:
|
|
||||||
AfterClass: false
|
|
||||||
AfterEnum: false
|
|
||||||
AfterStruct: false
|
|
||||||
AfterUnion: false
|
|
||||||
AfterControlStatement: MultiLine
|
|
||||||
AfterFunction: false # should also be MultiLine, but not yet supported
|
|
||||||
AfterExternBlock: false
|
|
||||||
BeforeElse: false
|
|
||||||
BeforeWhile: false
|
|
||||||
IndentBraces: false
|
|
||||||
SplitEmptyFunction: true
|
|
||||||
AllowShortIfStatementsOnASingleLine: false
|
|
||||||
IndentCaseLabels: false
|
|
||||||
AlwaysBreakAfterReturnType: All
|
|
||||||
Cpp11BracedListStyle: false
|
|
||||||
ColumnLimit: 80
|
|
||||||
AlignAfterOpenBracket: Align
|
|
||||||
AlignConsecutiveBitFields: true
|
|
||||||
AlignConsecutiveDeclarations: true
|
|
||||||
AlignConsecutiveMacros: true
|
|
||||||
AlignTrailingComments: true
|
|
||||||
AllowAllArgumentsOnNextLine: true
|
|
||||||
AlwaysBreakBeforeMultilineStrings: false
|
|
||||||
BreakBeforeBinaryOperators: None
|
|
||||||
BreakBeforeTernaryOperators: true
|
|
||||||
AlignEscapedNewlines: Left
|
|
||||||
DerivePointerAlignment: false
|
|
||||||
PointerAlignment: Right
|
|
||||||
PointerBindsToType: false
|
|
||||||
IncludeBlocks: Regroup
|
|
||||||
IncludeCategories:
|
|
||||||
- Regex: '^<isc/'
|
|
||||||
Priority: 2
|
|
||||||
- Regex: '^<dns/'
|
|
||||||
Priority: 3
|
|
||||||
- Regex: '^<iscccc/'
|
|
||||||
Priority: 4
|
|
||||||
- Regex: '^<isccfg/'
|
|
||||||
Priority: 5
|
|
||||||
- Regex: '^<ns/'
|
|
||||||
Priority: 6
|
|
||||||
- Regex: '^<bind9/)'
|
|
||||||
Priority: 7
|
|
||||||
- Regex: '^(<[^/]*)/)'
|
|
||||||
Priority: 8
|
|
||||||
- Regex: '<[[:alnum:].]+>'
|
|
||||||
Priority: 1
|
|
||||||
- Regex: '".*"'
|
|
||||||
Priority: 9
|
|
||||||
IndentExternBlock: NoIndent
|
|
||||||
KeepEmptyLinesAtTheStartOfBlocks: false
|
|
||||||
MaxEmptyLinesToKeep: 1
|
|
||||||
PenaltyBreakAssignment: 30
|
|
||||||
PenaltyBreakComment: 10
|
|
||||||
PenaltyBreakFirstLessLess: 0
|
|
||||||
PenaltyBreakString: 80
|
|
||||||
PenaltyExcessCharacter: 100
|
|
||||||
Standard: Cpp11
|
|
||||||
ContinuationIndentWidth: 8
|
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
Makefile
|
||||||
|
config.log
|
||||||
|
config.h
|
||||||
|
config.cache
|
||||||
|
config.status
|
||||||
|
libtool
|
||||||
|
isc-config.sh
|
||||||
|
configure.lineno
|
||||||
|
autom4te.cache
|
||||||
-117
@@ -1,117 +0,0 @@
|
|||||||
;;; Directory Local Variables
|
|
||||||
;;; For more information see (info "(emacs) Directory Variables")
|
|
||||||
|
|
||||||
((c-mode .
|
|
||||||
((eval .
|
|
||||||
(set (make-local-variable 'directory-of-current-dir-locals-file)
|
|
||||||
(file-name-directory (locate-dominating-file default-directory ".dir-locals.el"))
|
|
||||||
)
|
|
||||||
)
|
|
||||||
(eval .
|
|
||||||
(set (make-local-variable 'include-directories)
|
|
||||||
(list
|
|
||||||
|
|
||||||
;; top directory
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "./"))
|
|
||||||
|
|
||||||
;; libisc
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isc/unix/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isc/pthreads/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isc/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isc"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isc/netmgr"))
|
|
||||||
|
|
||||||
;; libdns
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/dns/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/dns"))
|
|
||||||
|
|
||||||
;; libisccc
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isccc/include"))
|
|
||||||
|
|
||||||
;; libisccfg
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/isccfg/include"))
|
|
||||||
|
|
||||||
;; libns
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/ns/include"))
|
|
||||||
|
|
||||||
;; libirs
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/irs/include"))
|
|
||||||
|
|
||||||
;; libbind9
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "lib/bind9/include"))
|
|
||||||
|
|
||||||
;; bin
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/check"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/confgen/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/confgen"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/confgen/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/dig/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/named/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/named/unix/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/rndc/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/dnssec/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/named/include"))
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "bin/rndc/include"))
|
|
||||||
|
|
||||||
(expand-file-name "/usr/local/opt/openssl@1.1/include")
|
|
||||||
(expand-file-name "/usr/local/opt/libxml2/include/libxml2")
|
|
||||||
(expand-file-name "/usr/local/opt/json-c/include/json-c/")
|
|
||||||
(expand-file-name "/usr/local/include")
|
|
||||||
)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
|
|
||||||
(eval setq flycheck-clang-include-path include-directories)
|
|
||||||
(eval setq flycheck-cppcheck-include-path include-directories)
|
|
||||||
(eval setq flycheck-gcc-include-path include-directories)
|
|
||||||
(eval setq flycheck-clang-args
|
|
||||||
(list
|
|
||||||
"-include"
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "config.h"))
|
|
||||||
)
|
|
||||||
)
|
|
||||||
(eval setq flycheck-gcc-args
|
|
||||||
(list
|
|
||||||
"-include"
|
|
||||||
(expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "config.h"))
|
|
||||||
)
|
|
||||||
)
|
|
||||||
(eval setq flycheck-cppcheck-args
|
|
||||||
(list
|
|
||||||
"--enable=all"
|
|
||||||
"--suppress=missingIncludeSystem"
|
|
||||||
"--suppress=nullPointerRedundantCheck"
|
|
||||||
(concat "--suppressions-list=" (expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "util/suppressions.txt")))
|
|
||||||
(concat "-include=" (expand-file-name
|
|
||||||
(concat directory-of-current-dir-locals-file "config.h")))
|
|
||||||
)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
))
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
*.sln.in eol=crlf
|
|
||||||
*.vcxproj.* eol=crlf
|
|
||||||
|
|
||||||
/fuzz/dns_rdata_fromwire_text.in/input-* -text
|
|
||||||
|
|
||||||
.gitignore export-ignore
|
|
||||||
/conftools export-ignore
|
|
||||||
/doc/design export-ignore
|
|
||||||
/doc/dev export-ignore
|
|
||||||
/util/** export-ignore
|
|
||||||
/util/bindkeys.pl -export-ignore
|
|
||||||
/util/check-make-install.in -export-ignore
|
|
||||||
/util/mksymtbl.pl -export-ignore
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
name: 'Lock down mirror repository'
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: opened
|
|
||||||
pull_request:
|
|
||||||
types: opened
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
lockdown:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: dessant/repo-lockdown@v2
|
|
||||||
with:
|
|
||||||
github-token: ${{ github.token }}
|
|
||||||
-100
@@ -1,100 +0,0 @@
|
|||||||
*-symtbl.c
|
|
||||||
*.a
|
|
||||||
*.gcda
|
|
||||||
*.gcno
|
|
||||||
*.la
|
|
||||||
*.lo
|
|
||||||
*.log
|
|
||||||
*.o
|
|
||||||
*.orig
|
|
||||||
*.plist/ # ccc-analyzer store its results in .plist directories
|
|
||||||
*.rej
|
|
||||||
*.so
|
|
||||||
*.trs
|
|
||||||
*_test
|
|
||||||
*.ipch # vscode/intellisense precompiled header
|
|
||||||
*~
|
|
||||||
__pycache__/
|
|
||||||
.ccache/
|
|
||||||
.cproject
|
|
||||||
.deps/
|
|
||||||
.dirstamp
|
|
||||||
.libs/
|
|
||||||
.project
|
|
||||||
.settings
|
|
||||||
/aclocal.m4
|
|
||||||
/ar-lib
|
|
||||||
/autom4te.cache/
|
|
||||||
/bind.keys.h
|
|
||||||
/compile
|
|
||||||
/config.cache
|
|
||||||
/config.guess
|
|
||||||
/config.h
|
|
||||||
/config.h.in
|
|
||||||
/config.log
|
|
||||||
/config.status
|
|
||||||
/config.sub
|
|
||||||
/configure
|
|
||||||
/configure.lineno
|
|
||||||
/depcomp
|
|
||||||
/install-sh
|
|
||||||
/isc-config.sh
|
|
||||||
/libtool
|
|
||||||
/ltmain.sh
|
|
||||||
/m4/libtool.m4
|
|
||||||
/m4/ltargz.m4
|
|
||||||
/m4/ltdl.m4
|
|
||||||
/m4/ltoptions.m4
|
|
||||||
/m4/ltsugar.m4
|
|
||||||
/m4/ltversion.m4
|
|
||||||
/m4/lt~obsolete.m4
|
|
||||||
/missing
|
|
||||||
/py-compile
|
|
||||||
/stamp-h1
|
|
||||||
/test-driver
|
|
||||||
Makefile
|
|
||||||
Makefile.in
|
|
||||||
ans.run
|
|
||||||
gen.dSYM/
|
|
||||||
named.memstats
|
|
||||||
named.run
|
|
||||||
timestamp
|
|
||||||
/compile_commands.json
|
|
||||||
# Gets generated by Build Ear (bear)
|
|
||||||
/compile_commands.commands.json
|
|
||||||
/cppcheck_html/
|
|
||||||
/cppcheck.results
|
|
||||||
/tsan
|
|
||||||
/util/check-make-install
|
|
||||||
/INSTALL
|
|
||||||
doc/man/dnssec-cds.8in
|
|
||||||
doc/man/dnssec-checkds.8in
|
|
||||||
doc/man/dnssec-coverage.8in
|
|
||||||
doc/man/dnssec-dsfromkey.8in
|
|
||||||
doc/man/dnssec-importkey.8in
|
|
||||||
doc/man/dnssec-keyfromlabel.8in
|
|
||||||
doc/man/dnssec-keygen.8in
|
|
||||||
doc/man/dnssec-keymgr.8in
|
|
||||||
doc/man/dnssec-revoke.8in
|
|
||||||
doc/man/dnssec-settime.8in
|
|
||||||
doc/man/dnssec-signzone.8in
|
|
||||||
doc/man/dnssec-verify.8in
|
|
||||||
doc/man/named-checkconf.8in
|
|
||||||
doc/man/named-checkzone.8in
|
|
||||||
doc/man/named-journalprint.8in
|
|
||||||
doc/man/named-nzd2nzf.8in
|
|
||||||
doc/man/nsec3hash.8in
|
|
||||||
doc/man/pkcs11-destroy.8in
|
|
||||||
doc/man/pkcs11-keygen.8in
|
|
||||||
doc/man/pkcs11-list.8in
|
|
||||||
doc/man/pkcs11-tokens.8in
|
|
||||||
# clangd index directory
|
|
||||||
/\.cache/
|
|
||||||
# GNU Global index files
|
|
||||||
/GPATH
|
|
||||||
/GRTAGS
|
|
||||||
/GTAGS
|
|
||||||
# Emacs specific files
|
|
||||||
\.dir-locals-2.el
|
|
||||||
/emacs.desktop
|
|
||||||
/emacs.desktop-lock
|
|
||||||
-1564
File diff suppressed because it is too large
Load Diff
@@ -1,46 +0,0 @@
|
|||||||
<!--
|
|
||||||
If the bug you are reporting is potentially security-related - for example,
|
|
||||||
if it involves an assertion failure or other crash in `named` that can be
|
|
||||||
triggered repeatedly - then please do *NOT* report it here, but send an
|
|
||||||
email to [security-officer@isc.org](security-officer@isc.org).
|
|
||||||
-->
|
|
||||||
|
|
||||||
### Summary
|
|
||||||
|
|
||||||
(Summarize the bug encountered concisely.)
|
|
||||||
|
|
||||||
### BIND version used
|
|
||||||
|
|
||||||
(Paste the output of `named -V`.)
|
|
||||||
|
|
||||||
### Steps to reproduce
|
|
||||||
|
|
||||||
(How one can reproduce the issue - this is very important.)
|
|
||||||
|
|
||||||
### What is the current *bug* behavior?
|
|
||||||
|
|
||||||
(What actually happens.)
|
|
||||||
|
|
||||||
### What is the expected *correct* behavior?
|
|
||||||
|
|
||||||
(What you should see instead.)
|
|
||||||
|
|
||||||
### Relevant configuration files
|
|
||||||
|
|
||||||
(Paste any relevant configuration files - please use code blocks (```)
|
|
||||||
to format console output. If submitting the contents of your
|
|
||||||
configuration file in a non-confidential Issue, it is advisable to
|
|
||||||
obscure key secrets: this can be done automatically by using
|
|
||||||
`named-checkconf -px`.)
|
|
||||||
|
|
||||||
### Relevant logs and/or screenshots
|
|
||||||
|
|
||||||
(Paste any relevant logs - please use code blocks (```) to format console
|
|
||||||
output, logs, and code, as it's very hard to read otherwise.)
|
|
||||||
|
|
||||||
### Possible fixes
|
|
||||||
|
|
||||||
(If you can, link to the line of code that might be responsible for the
|
|
||||||
problem.)
|
|
||||||
|
|
||||||
/label ~bug
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
<!--
|
|
||||||
THIS ISSUE TEMPLATE IS INTENDED ONLY FOR INTERNAL USE.
|
|
||||||
|
|
||||||
If the bug you are reporting is potentially security-related - for example,
|
|
||||||
if it involves an assertion failure or other crash in `named` that can be
|
|
||||||
triggered repeatedly - then please do *NOT* report it here, but send an
|
|
||||||
email to [security-officer@isc.org](security-officer@isc.org).
|
|
||||||
-->
|
|
||||||
|
|
||||||
### CVE-specific actions
|
|
||||||
|
|
||||||
- [ ] Assign a CVE identifier
|
|
||||||
- [ ] Determine CVSS score
|
|
||||||
- [ ] Determine the range of BIND versions affected (including the Subscription Edition)
|
|
||||||
- [ ] Determine whether workarounds for the problem exists
|
|
||||||
- [ ] Create a draft of the security advisory and put the information above in there
|
|
||||||
- [ ] Prepare a detailed description of the problem which should include the following by default:
|
|
||||||
- instructions for reproducing the problem (a system test is good enough)
|
|
||||||
- explanation of code flow which triggers the problem (a system test is *not* good enough)
|
|
||||||
- [ ] Prepare a private merge request containing the following items in separate commits:
|
|
||||||
- a test for the issue (may be moved to a separate merge request for deferred merging)
|
|
||||||
- a fix for the issue
|
|
||||||
- documentation updates (`CHANGES`, release notes, anything else applicable)
|
|
||||||
- [ ] Ensure the merge request from the previous step is reviewed by SWENG staff and has no outstanding discussions
|
|
||||||
- [ ] Ensure the documentation changes introduced by the merge request addressing the problem are reviewed by Support and Marketing staff
|
|
||||||
- [ ] Prepare backports of the merge request addressing the problem for all affected (and still maintained) BIND branches (backporting might affect the issue's scope and/or description)
|
|
||||||
- [ ] Prepare a standalone patch for the last stable release of each affected (and still maintained) BIND branch
|
|
||||||
|
|
||||||
### Release-specific actions
|
|
||||||
|
|
||||||
- [ ] Create/update the private issue containing links to fixes & reproducers for all CVEs fixed in a given release cycle
|
|
||||||
- [ ] Reserve a block of `CHANGES` placeholders once the complete set of vulnerabilities fixed in a given release cycle is determined
|
|
||||||
- [ ] Ensure the merge requests containing CVE fixes are merged into `security-*` branches in CVE identifier order
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
### Description
|
|
||||||
|
|
||||||
(Describe the problem, use cases, benefits, and/or goals.)
|
|
||||||
|
|
||||||
### Request
|
|
||||||
|
|
||||||
(Describe the solution you'd like to see.)
|
|
||||||
|
|
||||||
### Links / references
|
|
||||||
|
|
||||||
/label ~"feature request"
|
|
||||||
@@ -1,93 +0,0 @@
|
|||||||
## Release Schedule
|
|
||||||
|
|
||||||
**Code Freeze:**
|
|
||||||
|
|
||||||
**Tagging Deadline:**
|
|
||||||
|
|
||||||
**Public Release:**
|
|
||||||
|
|
||||||
## Documentation Review Links
|
|
||||||
|
|
||||||
**Closed issues assigned to the milestone without a release note:**
|
|
||||||
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
|
|
||||||
**Merge requests merged into the milestone without a release note:**
|
|
||||||
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
|
|
||||||
**Merge requests merged into the milestone without a `CHANGES` entry:**
|
|
||||||
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
- []()
|
|
||||||
|
|
||||||
## Release Checklist
|
|
||||||
|
|
||||||
### Before the Code Freeze
|
|
||||||
|
|
||||||
- [ ] ***(QA)*** Inform Support and Marketing of impending release (and give estimated release dates).
|
|
||||||
- [ ] ***(QA)*** Ensure there are no permanent test failures on any platform.
|
|
||||||
- [ ] ***(QA)*** Check Perflab to ensure there has been no unexplained drop in performance for the versions being released.
|
|
||||||
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
|
|
||||||
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
|
|
||||||
- [ ] ***(QA)*** Ensure all merge requests marked for backporting have been indeed backported.
|
|
||||||
|
|
||||||
### Before the Tagging Deadline
|
|
||||||
|
|
||||||
- [ ] ***(QA)*** Look for outstanding documentation issues (e.g. `CHANGES` mistakes) and address them if any are found.
|
|
||||||
- [ ] ***(QA)*** Ensure release notes are correct, ask Support and Marketing to check them as well.
|
|
||||||
- [ ] ***(QA)*** Update API files for libraries with new version information.
|
|
||||||
- [ ] ***(QA)*** Change software version and library versions in `configure.ac` (new major release only).
|
|
||||||
- [ ] ***(QA)*** Rebuild `configure` using Autoconf on `docs.isc.org`.
|
|
||||||
- [ ] ***(QA)*** Update `CHANGES`.
|
|
||||||
- [ ] ***(QA)*** Update `CHANGES.SE` (Subscription Edition only).
|
|
||||||
- [ ] ***(QA)*** Update `README.md`.
|
|
||||||
- [ ] ***(QA)*** Update `version`.
|
|
||||||
- [ ] ***(QA)*** Build documentation on `docs.isc.org`.
|
|
||||||
- [ ] ***(QA)*** Check that the formatting is correct for text, PDF, and HTML versions of release notes.
|
|
||||||
- [ ] ***(QA)*** Check that the formatting of the generated man pages is correct.
|
|
||||||
- [ ] ***(QA)*** Tag the releases in the private repository (`git tag -s -m "BIND 9.x.y" v9_x_y`).
|
|
||||||
|
|
||||||
### Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
|
|
||||||
|
|
||||||
- [ ] ***(QA)*** Verify GitLab CI results for the tags created and prepare a QA report for the releases to be published.
|
|
||||||
- [ ] ***(QA)*** Request signatures for the tarballs, providing their location and checksums.
|
|
||||||
- [ ] ***(Signers)*** Validate tarball checksums, sign tarballs, and upload signatures.
|
|
||||||
- [ ] ***(QA)*** Verify tarball signatures and check tarball checksums again.
|
|
||||||
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
|
|
||||||
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
|
|
||||||
- [ ] ***(QA)*** Notify Support that the releases have been prepared.
|
|
||||||
- [ ] ***(Support)*** Send out ASNs (if applicable).
|
|
||||||
|
|
||||||
### On the Day of Public Release
|
|
||||||
|
|
||||||
- [ ] ***(Support)*** Wait for clearance from Security Officer to proceed with the public release (if applicable).
|
|
||||||
- [ ] ***(Support)*** Place tarballs in public location on FTP site.
|
|
||||||
- [ ] ***(Support)*** Publish links to downloads on ISC website.
|
|
||||||
- [ ] ***(Support)*** Write release email to *bind-announce*.
|
|
||||||
- [ ] ***(Support)*** Write email to *bind-users* (if a major release).
|
|
||||||
- [ ] ***(Support)*** Send eligible customers updated links to the Subscription Edition (update the -S edition delivery tickets, even if those links were provided earlier via an ASN ticket).
|
|
||||||
- [ ] ***(Support)*** Update tickets in case of waiting support customers.
|
|
||||||
- [ ] ***(QA)*** Build and test any outstanding private packages.
|
|
||||||
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
|
|
||||||
- [ ] ***(QA)*** Inform Marketing of the release.
|
|
||||||
- [ ] ***(QA)*** Update the internal [BIND release dates wiki page](https://wiki.isc.org/bin/view/Main/BindReleaseDates) when public announcement has been made.
|
|
||||||
- [ ] ***(Marketing)*** Post short note to Twitter.
|
|
||||||
- [ ] ***(Marketing)*** Update [Wikipedia entry for BIND](https://en.wikipedia.org/wiki/BIND).
|
|
||||||
- [ ] ***(Marketing)*** Write blog article (if a major release).
|
|
||||||
- [ ] ***(QA)*** Ensure all new tags are annotated and signed.
|
|
||||||
- [ ] ***(QA)*** Push tags for the published releases to the public repository.
|
|
||||||
- [ ] ***(QA)*** Merge the automatically prepared `prep 9.x.y` commit which updates `version` and documentation on the release branch into the relevant maintenance branch (`v9_x`).
|
|
||||||
- [ ] ***(QA)*** For each maintained branch, update the `BIND_BASELINE_VERSION` variable for the `abi-check` job in `.gitlab-ci.yml` to the latest published BIND version tag for a given branch.
|
|
||||||
- [ ] ***(QA)*** Prepare empty release notes for the next set of releases.
|
|
||||||
- [ ] ***(QA)*** Sanitize confidential issues which are assigned to the current release milestone and do not describe a security vulnerability, then make them public.
|
|
||||||
- [ ] ***(QA)*** Sanitize confidential issues which are assigned to older release milestones and describe security vulnerabilities, then make them public if appropriate[^2].
|
|
||||||
- [ ] ***(QA)*** Update QA tools used in GitLab CI (e.g. Flake8, PyLint) by modifying the relevant `Dockerfile`.
|
|
||||||
|
|
||||||
[^1]: If not, use the time remaining until the tagging deadline to ensure all outstanding issues are either resolved or moved to a different milestone.
|
|
||||||
[^2]: As a rule of thumb, security vulnerabilities which have reproducers merged to the public repository are considered okay for full disclosure.
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
extraction:
|
|
||||||
cpp:
|
|
||||||
prepare:
|
|
||||||
packages:
|
|
||||||
- "libxml2-dev"
|
|
||||||
- "libjson-c-dev"
|
|
||||||
- "libssl-dev"
|
|
||||||
- "zlib1g-dev"
|
|
||||||
- "libcmocka-dev"
|
|
||||||
- "pkg-config"
|
|
||||||
- "libcap2-dev"
|
|
||||||
- "libedit-dev"
|
|
||||||
- "libidn2-dev"
|
|
||||||
- "libmaxminddb-dev"
|
|
||||||
- "libuv1-dev"
|
|
||||||
- "libnghttp2-dev"
|
|
||||||
configure:
|
|
||||||
command:
|
|
||||||
- "autoreconf -fi"
|
|
||||||
- "CFLAGS=\"-Og -g\" ./configure --enable-developer"
|
|
||||||
path_classifiers:
|
|
||||||
test:
|
|
||||||
- "lib/*/tests/"
|
|
||||||
- "bin/tests/"
|
|
||||||
docs:
|
|
||||||
- "**/*.xml"
|
|
||||||
- "**/*.docbook"
|
|
||||||
- "**/*.html"
|
|
||||||
- "**/*.1"
|
|
||||||
- "**/*.5"
|
|
||||||
- "**/*.8"
|
|
||||||
queries:
|
|
||||||
- exclude: fuzz/
|
|
||||||
- exclude: "bin/tests/system/*/ans*/*.py"
|
|
||||||
- exclude: cpp/use-of-goto
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
[MASTER]
|
|
||||||
disable=
|
|
||||||
C0114, # missing-module-docstring
|
|
||||||
C0115, # missing-class-docstring
|
|
||||||
C0116, # missing-function-docstring
|
|
||||||
R0801, # duplicate-code
|
|
||||||
C0103, # invalid-name
|
|
||||||
C0415,# import-outside-toplevel
|
|
||||||
-1434
File diff suppressed because it is too large
Load Diff
@@ -1,53 +0,0 @@
|
|||||||
Mark Andrews
|
|
||||||
Andreas Gustafsson
|
|
||||||
Evan Hunt
|
|
||||||
Brian Wellington
|
|
||||||
Bob Halley
|
|
||||||
David Lawrence
|
|
||||||
Michael Graff
|
|
||||||
Michael Sawyer
|
|
||||||
Ondřej Surý
|
|
||||||
James Brister
|
|
||||||
Tatuya JINMEI 神明達哉
|
|
||||||
Francis Dupont
|
|
||||||
Michał Kępień
|
|
||||||
Danny Mayer
|
|
||||||
Mukund Sivaraman
|
|
||||||
Jeremy C. Reed
|
|
||||||
William King
|
|
||||||
Stephen Morris
|
|
||||||
Witold Kręcicki
|
|
||||||
Curtis Blackburn
|
|
||||||
Scott Mann
|
|
||||||
Rob Austein
|
|
||||||
Jim Reid
|
|
||||||
Eric Luce
|
|
||||||
Olafur Gudmundsson
|
|
||||||
Stephen Jacob
|
|
||||||
Damien Neil
|
|
||||||
Tony Finch
|
|
||||||
Jakob Schlyter
|
|
||||||
Petr Menšík
|
|
||||||
Vernon Schryver
|
|
||||||
Matt Nelson
|
|
||||||
Shane Kerr
|
|
||||||
Paul Ebersman
|
|
||||||
Ray Bellis
|
|
||||||
Shawn Routhier
|
|
||||||
Ben Cottrell
|
|
||||||
Tomas Hozza
|
|
||||||
johnd
|
|
||||||
Bill Parker
|
|
||||||
李昶
|
|
||||||
Kevin Chen
|
|
||||||
Jonathan Casey
|
|
||||||
Mary Stahl
|
|
||||||
Mathieu Arnold
|
|
||||||
David Hankins
|
|
||||||
Paul Hoffman
|
|
||||||
Paul Vixie
|
|
||||||
Brian Conry
|
|
||||||
Anay Panvalkar
|
|
||||||
colleen
|
|
||||||
Robert Edmonds
|
|
||||||
João Damas
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
# BIND 9 Code of Conduct
|
|
||||||
|
|
||||||
Like the technical community as a whole, the BIND 9 team and community is made
|
|
||||||
up of a mixture of professionals and volunteers from all over the world, working
|
|
||||||
on every aspect of the mission - including mentorship, teaching, and connecting
|
|
||||||
people.
|
|
||||||
|
|
||||||
Diversity is one of our huge strengths, but it can also lead to communication
|
|
||||||
issues and unhappiness. To that end, we have a few ground rules that we ask
|
|
||||||
people to adhere to. This code applies equally to the core development team,
|
|
||||||
open source contributors and those seeking help and guidance.
|
|
||||||
|
|
||||||
This isn't an exhaustive list of things that you can't do. Rather, take it in
|
|
||||||
the spirit in which it's intended - a guide to make it easier to enrich all of
|
|
||||||
us and the technical communities in which we participate.
|
|
||||||
|
|
||||||
This code of conduct applies to all spaces managed by the BIND 9 project or
|
|
||||||
Internet Systems Consortium. This includes chat, the mailing lists, the issue
|
|
||||||
tracker, and any other fora created by the project team which the
|
|
||||||
community uses for communication. In addition, violations of this code outside
|
|
||||||
these spaces may affect a person's ability to participate within them.
|
|
||||||
|
|
||||||
If you believe someone is violating the code of conduct, we ask that you report
|
|
||||||
it by emailing [conduct@isc.org](conduct@isc.org). For more details please see
|
|
||||||
our [Reporting Guidelines](https://www.isc.org/conductreporting/).
|
|
||||||
|
|
||||||
* **Be friendly and patient.**
|
|
||||||
* **Be welcoming.** We strive to be a community that welcomes and supports
|
|
||||||
people of all backgrounds and identities. This includes, but is not limited to
|
|
||||||
members of any race, ethnicity, culture, national origin, colour, immigration
|
|
||||||
status, social and economic class, educational level, sex, sexual orientation,
|
|
||||||
gender identity and expression, age, size, family status, political belief,
|
|
||||||
religion, and mental and physical ability.
|
|
||||||
* **Be considerate.** Your work will be used by other people, and you in turn
|
|
||||||
will depend on the work of others. Any decision you take will affect users and
|
|
||||||
colleagues, and you should take those consequences into account when making
|
|
||||||
decisions. Remember that we're a world-wide community, so you might not be
|
|
||||||
communicating in someone else's primary language.
|
|
||||||
* **Be respectful.** Not all of us will agree all the time, but disagreement is
|
|
||||||
no excuse for poor behavior and poor manners. We might all experience some
|
|
||||||
frustration now and then, but we cannot allow that frustration to turn into a
|
|
||||||
personal attack. It's important to remember that a community where people feel
|
|
||||||
uncomfortable or threatened is not a productive one. Members of the BIND 9
|
|
||||||
community should be respectful when dealing with other members as well as with
|
|
||||||
people outside the BIND 9 community.
|
|
||||||
* **Be careful in the words that you choose.** We are a community of
|
|
||||||
professionals, and we conduct ourselves professionally. Be kind to others. Do
|
|
||||||
not insult or put down other participants. Harassment and other exclusionary
|
|
||||||
behavior aren't acceptable. This includes, but is not limited to:
|
|
||||||
* Violent threats or language directed against another person.
|
|
||||||
* Discriminatory jokes and language.
|
|
||||||
* Posting sexually explicit or violent material.
|
|
||||||
* Posting (or threatening to post) other people's personally identifying
|
|
||||||
information ("doxing").
|
|
||||||
* Personal insults, especially those using racist or sexist terms.
|
|
||||||
* Unwelcome sexual attention.
|
|
||||||
* Advocating for, or encouraging, any of the above behavior.
|
|
||||||
* Repeated harassment of others. In general, if someone asks you to stop, then
|
|
||||||
stop.
|
|
||||||
* **When we disagree, try to understand why.** Disagreements, both social and
|
|
||||||
technical, happen all the time and BIND 9 is no exception. It is important
|
|
||||||
that we resolve disagreements and differing views constructively. Remember
|
|
||||||
that we're different. The strength of BIND 9 comes from its varied community,
|
|
||||||
people from a wide range of backgrounds. Different people have different
|
|
||||||
perspectives on issues. Being unable to understand why someone holds a
|
|
||||||
viewpoint doesn't mean that they're wrong. Don't forget that it is human to
|
|
||||||
err and blaming each other doesn't get us anywhere. Instead, focus on helping
|
|
||||||
to resolve issues and learning from mistakes.
|
|
||||||
|
|
||||||
Original text courtesy of the [Django Code of Conduct](https://www.djangoproject.com/conduct/)
|
|
||||||
project.
|
|
||||||
-206
@@ -1,206 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
## BIND 9 Source Access and Contributor Guidelines
|
|
||||||
*May 28, 2020*
|
|
||||||
|
|
||||||
### Contents
|
|
||||||
|
|
||||||
1. [Access to source code](#access)
|
|
||||||
1. [Reporting bugs](#bugs)
|
|
||||||
1. [Contributing code](#contrib)
|
|
||||||
|
|
||||||
### Introduction
|
|
||||||
|
|
||||||
Thank you for using BIND 9!
|
|
||||||
|
|
||||||
BIND is open source software that implements the Domain Name System (DNS)
|
|
||||||
protocols for the Internet. It is a reference implementation of those
|
|
||||||
protocols, but it is also production-grade software, suitable for use in
|
|
||||||
high-volume and high-reliability applications. It is very
|
|
||||||
widely used DNS software, providing a robust and stable platform on top of
|
|
||||||
which organizations can build distributed computing systems with the
|
|
||||||
knowledge that those systems are fully compliant with published DNS
|
|
||||||
standards.
|
|
||||||
|
|
||||||
BIND is and will always remain free and openly available. It can be
|
|
||||||
used and modified in any way by anyone.
|
|
||||||
|
|
||||||
BIND is maintained by [Internet Systems Consortium](https://www.isc.org),
|
|
||||||
a public-benefit 501(c)(3) nonprofit, using a "managed open source" approach:
|
|
||||||
anyone can see the source, but only ISC employees have commit access.
|
|
||||||
In the past, the source could only be seen once ISC had published
|
|
||||||
a release; read access to the source repository was restricted just
|
|
||||||
as commit access was. That has changed, as ISC now provides a
|
|
||||||
public git repository of the BIND source tree (see below).
|
|
||||||
|
|
||||||
At ISC, we're committed to
|
|
||||||
building communities that are welcoming and inclusive: environments where people
|
|
||||||
are encouraged to share ideas, treat each other with respect, and collaborate
|
|
||||||
towards the best solutions. To reinforce our commitment, ISC
|
|
||||||
has adopted a slightly modified version of the Django
|
|
||||||
[Code of Conduct](https://gitlab.isc.org/isc-projects/bind9/-/blob/main/CODE_OF_CONDUCT.md)
|
|
||||||
for the BIND 9 project, as well as for the conduct of our developers throughout
|
|
||||||
the industry.
|
|
||||||
|
|
||||||
### <a name="access"></a>Access to source code
|
|
||||||
|
|
||||||
Public BIND releases are always available from the
|
|
||||||
[ISC FTP site](ftp://ftp.isc.org/isc/bind9).
|
|
||||||
|
|
||||||
A public-access git repository is also available at
|
|
||||||
[https://gitlab.isc.org](https://gitlab.isc.org). This repository
|
|
||||||
contains all public release branches. Upcoming releases can be viewed in
|
|
||||||
their current state at any time. Short-lived development branches
|
|
||||||
contain unreviewed work in progress. Commits which address security
|
|
||||||
vulnerablilities are withheld until after public disclosure.
|
|
||||||
|
|
||||||
You can browse the source online via
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9)
|
|
||||||
|
|
||||||
To clone the repository, use:
|
|
||||||
|
|
||||||
> $ git clone https://gitlab.isc.org/isc-projects/bind9.git
|
|
||||||
|
|
||||||
Release branch names are of the form `v9_X`, where X represents the second
|
|
||||||
number in the BIND 9 version number. So, to check out the BIND 9.12
|
|
||||||
branch, use:
|
|
||||||
|
|
||||||
> $ git checkout v9_12
|
|
||||||
|
|
||||||
Whenever a branch is ready for publication, a tag is placed of the
|
|
||||||
form `v9_X_Y`. The 9.12.0 release, for instance, is tagged as `v9_12_0`.
|
|
||||||
|
|
||||||
The branch in which the next major release is being developed is called
|
|
||||||
`main`.
|
|
||||||
|
|
||||||
### <a name="bugs"></a>Reporting bugs
|
|
||||||
|
|
||||||
Reports of flaws in the BIND package, including software bugs, errors
|
|
||||||
in the documentation, missing files in the tarball, suggested changes
|
|
||||||
or requests for new features, etc., can be filed using
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9/issues](https://gitlab.isc.org/isc-projects/bind9/issues).
|
|
||||||
|
|
||||||
Due to a large ticket backlog, we are sometimes slow to respond,
|
|
||||||
especially if a bug is cosmetic or if a feature request is vague or
|
|
||||||
low in priority, but we try at least to acknowledge legitimate
|
|
||||||
bug reports within a week.
|
|
||||||
|
|
||||||
ISC's GitLab system is publicly readable; however, you must have
|
|
||||||
an account to create a new issue. You can either register locally or
|
|
||||||
use credentials from an existing account at GitHub, GitLab, Google,
|
|
||||||
Twitter, or Facebook.
|
|
||||||
|
|
||||||
### Reporting possible security issues
|
|
||||||
|
|
||||||
If you think you may be seeing a potential security vulnerability in BIND
|
|
||||||
(for example, a crash with REQUIRE, INSIST, or ASSERT failure), please
|
|
||||||
report it immediately by emailing to security-officer@isc.org. Plain-text
|
|
||||||
e-mail is not a secure choice for communications concerning undisclosed
|
|
||||||
security issues so please encrypt your communications to us if possible,
|
|
||||||
using the [ISC Security Officer public key](https://www.isc.org/pgpkey/).
|
|
||||||
|
|
||||||
Do not discuss undisclosed security vulnerabilities on any public mailing list.
|
|
||||||
ISC has a long history of handling reported vulnerabilities promptly and
|
|
||||||
effectively and we respect and acknowledge responsible reporters.
|
|
||||||
|
|
||||||
ISC's Security Vulnerability Disclosure Policy is documented at
|
|
||||||
[https://kb.isc.org/docs/aa-00861](https://kb.isc.org/docs/aa-00861).
|
|
||||||
|
|
||||||
If you have a crash, you may want to consult
|
|
||||||
["What to do if your BIND or DHCP server has crashed."](https://kb.isc.org/docs/aa-00340)
|
|
||||||
|
|
||||||
### <a name="contrib"></a>Contributing code
|
|
||||||
|
|
||||||
BIND is licensed under the
|
|
||||||
[Mozilla Public License 2.0](https://www.mozilla.org/en-US/MPL/2.0/).
|
|
||||||
Earlier versions (BIND 9.10 and earlier) were licensed under the
|
|
||||||
[ISC License](https://www.isc.org/licenses/)
|
|
||||||
|
|
||||||
ISC does not require an explicit copyright assignment for patch
|
|
||||||
contributions. However, by submitting a patch to ISC, you implicitly
|
|
||||||
certify that you are the author of the code, that you intend to relinquish
|
|
||||||
exclusive copyright, and that you grant permission to publish your work
|
|
||||||
under the open source license used for the BIND version(s) to which your
|
|
||||||
patch will be applied.
|
|
||||||
|
|
||||||
#### <a name="bind"></a>BIND code
|
|
||||||
|
|
||||||
Patches for BIND may be submitted directly via merge requests in
|
|
||||||
[ISC's GitLab](https://gitlab.isc.org/isc-projects/bind9/) source
|
|
||||||
repository for BIND.
|
|
||||||
|
|
||||||
Patches can also be submitted as diffs against a specific version of
|
|
||||||
BIND -- preferably the current top of the `main` branch. Diffs may
|
|
||||||
be generated using either `git format-patch` or `git diff`.
|
|
||||||
|
|
||||||
Those wanting to write code for BIND may be interested in the
|
|
||||||
[developer information](doc/dev/dev.md) page, which includes information
|
|
||||||
about BIND design and coding practices, including discussion of internal
|
|
||||||
APIs and overall system architecture.
|
|
||||||
|
|
||||||
Every patch submitted is reviewed by ISC engineers following our
|
|
||||||
[code review process](doc/dev/dev.md#reviews) before it is merged.
|
|
||||||
|
|
||||||
It may take considerable time to review patch submissions, especially if
|
|
||||||
they don't meet ISC style and quality guidelines. If a patch is a good
|
|
||||||
idea, we can and will do additional work to bring it up to par, but if
|
|
||||||
we're busy with other work, it may take us a long time to get to it.
|
|
||||||
|
|
||||||
To ensure your patch is acted on as promptly as possible, please:
|
|
||||||
|
|
||||||
* Try to adhere to the [BIND 9 coding style](doc/dev/style.md).
|
|
||||||
* Run `make check` to ensure your change hasn't caused any
|
|
||||||
functional regressions.
|
|
||||||
* Document your work, both in the patch itself and in the
|
|
||||||
accompanying email.
|
|
||||||
* In patches that make non-trivial functional changes, include system
|
|
||||||
tests if possible; when introducing or substantially altering a
|
|
||||||
library API, include unit tests. See [Testing](doc/dev/dev.md#testing)
|
|
||||||
for more information.
|
|
||||||
|
|
||||||
##### Changes to `configure`
|
|
||||||
|
|
||||||
If you need to make changes to `configure`, you should not edit it
|
|
||||||
directly; instead, edit `configure.in`, then run `autoconf`. Similarly,
|
|
||||||
instead of editing `config.h.in` directly, edit `configure.in` and run
|
|
||||||
`autoheader`.
|
|
||||||
|
|
||||||
When submitting a patch as a diff, it's fine to omit the `configure`
|
|
||||||
diffs to save space. Just send the `configure.in` diffs and we'll
|
|
||||||
generate the new `configure` during the review process.
|
|
||||||
|
|
||||||
##### Documentation
|
|
||||||
|
|
||||||
All functional changes should be documented. There are three types
|
|
||||||
of documentation in the BIND source tree:
|
|
||||||
|
|
||||||
* Man pages are kept alongside the source code for the commands
|
|
||||||
they document, in files ending in `.rst`: for example, the
|
|
||||||
`named` man page is `bin/named/named.rst`.
|
|
||||||
* The *BIND 9 Administrator Reference Manual* is in the .rst files in
|
|
||||||
`doc/arm/`; the PDF and HTML versions are automatically generated from
|
|
||||||
the `.rst` files.
|
|
||||||
* API documentation is in the header file describing the API, in
|
|
||||||
Doxygen-formatted comments.
|
|
||||||
|
|
||||||
Patches to improve existing documentation are also very welcome!
|
|
||||||
|
|
||||||
##### Tests
|
|
||||||
|
|
||||||
BIND is a large and complex project. We rely heavily on continuous
|
|
||||||
automated testing and cannot merge new code without adequate test coverage.
|
|
||||||
Please see [the "Testing" section of doc/dev/dev.md](doc/dev/dev.md#testing)
|
|
||||||
for more information.
|
|
||||||
|
|
||||||
#### Thanks
|
|
||||||
|
|
||||||
Thank you for your interest in contributing to the ongoing development
|
|
||||||
of BIND 9.
|
|
||||||
@@ -1,18 +1,21 @@
|
|||||||
Copyright (C) 1996-2021 Internet Systems Consortium, Inc. ("ISC")
|
Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
Copyright (C) 1996-2003 Internet Software Consortium.
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
Permission to use, copy, modify, and/or distribute this software for any
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
purpose with or without fee is hereby granted, provided that the above
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
copyright notice and this permission notice appear in all copies.
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
Portions of this code release fall under one or more of the
|
$Id: COPYRIGHT,v 1.14.176.2 2010/01/07 23:47:36 tbox Exp $
|
||||||
following Copyright notices. Please see individual source
|
|
||||||
files for details.
|
|
||||||
|
|
||||||
For binary releases also see: OpenSSL-LICENSE.
|
Portions Copyright (C) 1996-2001 Nominum, Inc.
|
||||||
|
|
||||||
Copyright (C) 1996-2001 Nominum, Inc.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
Permission to use, copy, modify, and distribute this software for any
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
purpose with or without fee is hereby granted, provided that the above
|
||||||
@@ -25,367 +28,3 @@ ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|||||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
|
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
|
||||||
OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) 1995-2000 by Network Associates, Inc.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and/or distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND ISC AND NETWORK ASSOCIATES DISCLAIMS
|
|
||||||
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED
|
|
||||||
WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE
|
|
||||||
FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
||||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
|
||||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
|
|
||||||
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) 2002 Stichting NLnet, Netherlands, stichting@nlnet.nl.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the
|
|
||||||
above copyright notice and this permission notice appear in all
|
|
||||||
copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND STICHTING NLNET
|
|
||||||
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
|
|
||||||
STICHTING NLNET BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
|
|
||||||
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
|
|
||||||
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
|
||||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
|
|
||||||
USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
The development of Dynamically Loadable Zones (DLZ) for Bind 9 was
|
|
||||||
conceived and contributed by Rob Butler.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the
|
|
||||||
above copyright notice and this permission notice appear in all
|
|
||||||
copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND ROB BUTLER
|
|
||||||
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
|
|
||||||
ROB BUTLER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
|
|
||||||
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
|
|
||||||
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
|
||||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
|
|
||||||
USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1987, 1990, 1993, 1994
|
|
||||||
The Regents of the University of California. All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions
|
|
||||||
are met:
|
|
||||||
1. Redistributions of source code must retain the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer.
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
3. Neither the name of the University nor the names of its contributors
|
|
||||||
may be used to endorse or promote products derived from this software
|
|
||||||
without specific prior written permission.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
|
|
||||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
||||||
ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
|
|
||||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
||||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
||||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
||||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
||||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
||||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
||||||
SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) The Internet Society 2005. This version of
|
|
||||||
this module is part of RFC 4178; see the RFC itself for
|
|
||||||
full legal notices.
|
|
||||||
|
|
||||||
(The above copyright notice is per RFC 3978 5.6 (a), q.v.)
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 2004 Masarykova universita
|
|
||||||
(Masaryk University, Brno, Czech Republic)
|
|
||||||
All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions are met:
|
|
||||||
|
|
||||||
1. Redistributions of source code must retain the above copyright notice,
|
|
||||||
this list of conditions and the following disclaimer.
|
|
||||||
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
|
|
||||||
3. Neither the name of the University nor the names of its contributors may
|
|
||||||
be used to endorse or promote products derived from this software
|
|
||||||
without specific prior written permission.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
|
||||||
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
||||||
ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
|
|
||||||
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
|
||||||
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
|
||||||
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
|
||||||
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
|
||||||
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
|
||||||
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
|
||||||
POSSIBILITY OF SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1997 - 2003 Kungliga Tekniska Högskolan
|
|
||||||
(Royal Institute of Technology, Stockholm, Sweden).
|
|
||||||
All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions
|
|
||||||
are met:
|
|
||||||
|
|
||||||
1. Redistributions of source code must retain the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer.
|
|
||||||
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
|
|
||||||
3. Neither the name of the Institute nor the names of its contributors
|
|
||||||
may be used to endorse or promote products derived from this software
|
|
||||||
without specific prior written permission.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
|
|
||||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
||||||
ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
|
|
||||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
||||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
||||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
||||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
||||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
||||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
||||||
SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1993 by Digital Equipment Corporation.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies, and that
|
|
||||||
the name of Digital Equipment Corporation not be used in advertising or
|
|
||||||
publicity pertaining to distribution of the document or software without
|
|
||||||
specific, written prior permission.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND DIGITAL EQUIPMENT CORP. DISCLAIMS ALL
|
|
||||||
WARRANTIES WITH REGARD TO THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES
|
|
||||||
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL DIGITAL EQUIPMENT
|
|
||||||
CORPORATION BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
|
|
||||||
DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
|
|
||||||
PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
|
|
||||||
ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
|
|
||||||
All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions
|
|
||||||
are met:
|
|
||||||
1. Redistributions of source code must retain the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer.
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
3. Neither the name of the project nor the names of its contributors
|
|
||||||
may be used to endorse or promote products derived from this software
|
|
||||||
without specific prior written permission.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
|
|
||||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
||||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
||||||
ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
|
|
||||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
||||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
||||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
||||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
||||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
||||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
||||||
SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1999-2000 by Nortel Networks Corporation
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND NORTEL NETWORKS DISCLAIMS
|
|
||||||
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
|
|
||||||
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL NORTEL NETWORKS
|
|
||||||
BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES
|
|
||||||
OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,
|
|
||||||
WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,
|
|
||||||
ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
|
|
||||||
SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) 2004 Nominet, Ltd.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND NOMINET DISCLAIMS ALL WARRANTIES WITH
|
|
||||||
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
|
||||||
AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
|
||||||
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
|
||||||
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
|
||||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
|
||||||
PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1996, David Mazieres <dm@uun.org>
|
|
||||||
Copyright (c) 2008, Damien Miller <djm@openbsd.org>
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
|
||||||
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
|
||||||
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
|
||||||
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
||||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
|
||||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
|
||||||
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 1995, 1997, 1998 The NetBSD Foundation, Inc.
|
|
||||||
All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions
|
|
||||||
are met:
|
|
||||||
1. Redistributions of source code must retain the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer.
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
|
|
||||||
``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
|
||||||
TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
|
||||||
PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
|
|
||||||
BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
|
||||||
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
|
||||||
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
|
||||||
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
|
||||||
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
|
||||||
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
|
||||||
POSSIBILITY OF SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (C) 2008-2011 Red Hat, Inc.
|
|
||||||
|
|
||||||
Permission to use, copy, modify, and/or distribute this software for any
|
|
||||||
purpose with or without fee is hereby granted, provided that the above
|
|
||||||
copyright notice and this permission notice appear in all copies.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS" AND Red Hat DISCLAIMS ALL WARRANTIES WITH
|
|
||||||
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
|
||||||
AND FITNESS. IN NO EVENT SHALL Red Hat BE LIABLE FOR ANY SPECIAL, DIRECT,
|
|
||||||
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
|
||||||
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
|
||||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
|
||||||
PERFORMANCE OF THIS SOFTWARE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 2013-2014, Farsight Security, Inc.
|
|
||||||
All rights reserved.
|
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
|
||||||
modification, are permitted provided that the following conditions
|
|
||||||
are met:
|
|
||||||
|
|
||||||
1. Redistributions of source code must retain the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer.
|
|
||||||
|
|
||||||
2. Redistributions in binary form must reproduce the above copyright
|
|
||||||
notice, this list of conditions and the following disclaimer in the
|
|
||||||
documentation and/or other materials provided with the distribution.
|
|
||||||
|
|
||||||
3. Neither the name of the copyright holder nor the names of its
|
|
||||||
contributors may be used to endorse or promote products derived from
|
|
||||||
this software without specific prior written permission.
|
|
||||||
|
|
||||||
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
||||||
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
|
||||||
TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
|
||||||
PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR
|
|
||||||
CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
|
|
||||||
EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
|
|
||||||
PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
|
|
||||||
OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
|
|
||||||
WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
|
|
||||||
OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
|
|
||||||
ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright (c) 2014 by Farsight Security, Inc.
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
-----------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Copyright Joyent, Inc. and other Node contributors. All rights reserved.
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to
|
|
||||||
deal in the Software without restriction, including without limitation the
|
|
||||||
rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
|
||||||
sell copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in
|
|
||||||
all copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
|
||||||
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
|
||||||
IN THE SOFTWARE.
|
|
||||||
|
|||||||
@@ -0,0 +1,204 @@
|
|||||||
|
2796. [bug] Missing dns_rdataset_disassociate() call in
|
||||||
|
dns_nsec3_delnsec3sx(). [RT #20681]
|
||||||
|
|
||||||
|
2795. [cleanup] Add text to differentiate "update with no effect"
|
||||||
|
log messages. [RT #18889]
|
||||||
|
|
||||||
|
2794. [bug] Install <isc/namespace.h>. [RT #20677]
|
||||||
|
|
||||||
|
2791. [bug] The installation of isc-config.sh was broken.
|
||||||
|
[RT #20667]
|
||||||
|
|
||||||
|
2788. [bug] dnssec-signzone could sign with keys that were
|
||||||
|
not requested [RT #20625]
|
||||||
|
|
||||||
|
2787. [bug] Spurious log message when zone keys were
|
||||||
|
dynamically reconfigured. [RT #20659]
|
||||||
|
|
||||||
|
2785. [bug] Revoked keys could fail to self-sign [RT #20652]
|
||||||
|
|
||||||
|
2781. [bug] Inactive keys could be used for signing. [RT #20649]
|
||||||
|
|
||||||
|
2780. [bug] dnssec-keygen -A none didn't properly unset the
|
||||||
|
activation date in all cases. [RT #20648]
|
||||||
|
|
||||||
|
2779. [bug] Dynamic key revokation could fail. [RT #20644]
|
||||||
|
|
||||||
|
2778. [bug] dnssec-signzone could fail when a key was revoked
|
||||||
|
without deleting the unrevoked version. [RT #20638]
|
||||||
|
|
||||||
|
2763. [bug] "rndc sign" didn't create an NSEC chain. [RT #20591]
|
||||||
|
|
||||||
|
2761. [cleanup] Enable internal symbol table for backtrace only for
|
||||||
|
systems that are known to work. Currently, BSD
|
||||||
|
variants, Linux and Solaris are supported. [RT# 20202]
|
||||||
|
|
||||||
|
2775. [bug] Accept RSASHA256 and RSASHA512 as NSEC3 compatible
|
||||||
|
in dnssec-keyfromlabel. [RT #20643]
|
||||||
|
|
||||||
|
2773. [bug] In autosigned zones, the SOA could be signed
|
||||||
|
with the KSK. [RT #20628]
|
||||||
|
|
||||||
|
2771. [bug] dnssec-signzone: DNSKEY records could be
|
||||||
|
corrupted when importing from key files [RT #20624]
|
||||||
|
|
||||||
|
2770. [cleanup] Add log messages to resolver.c to indicate events
|
||||||
|
causing FORMERR responses. [RT #20526]
|
||||||
|
|
||||||
|
2769. [cleanup] Change #2742 was incomplete. [RT #19589]
|
||||||
|
|
||||||
|
2768. [bug] dnssec-signzone: -S no longer implies -g [RT #20568]
|
||||||
|
|
||||||
|
2767. [bug] named could crash on startup if a zone was
|
||||||
|
configured with auto-dnssec and there was no
|
||||||
|
key-directory. [RT #20615]
|
||||||
|
|
||||||
|
2766. [bug] isc_socket_fdwatchpoke() should only update the
|
||||||
|
socketmgr state if the socket is not pending on a
|
||||||
|
read or write. [RT #20603]
|
||||||
|
|
||||||
|
2764. [bug] "rndc-confgen -a" could trigger a REQUIRE. [RT #20610]
|
||||||
|
|
||||||
|
2756. [bug] Fixed corrupt logfile message in update.c. [RT# 20597]
|
||||||
|
|
||||||
|
2753. [bug] Removed an unnecessary warning that could appear when
|
||||||
|
building an NSEC chain. [RT #20589]
|
||||||
|
|
||||||
|
2752. [bug] Locking violation. [RT #20587]
|
||||||
|
|
||||||
|
2751. [bug] Fixed a memory leak in dnssec-keyfromlabel. [RT #20588]
|
||||||
|
|
||||||
|
2746. [port] hpux: address signed/unsigned expansion mismatch of
|
||||||
|
dns_rbtnode_t.nsec. [RT #20542]
|
||||||
|
|
||||||
|
2745. [bug] configure script didn't probe the return type of
|
||||||
|
gai_strerror(3) correctly. [RT #20573]
|
||||||
|
|
||||||
|
2774. [bug] Existing cache DB wasn't being reused after
|
||||||
|
reconfiguration. [RT #20629]
|
||||||
|
|
||||||
|
2742. [cleanup] Clarify some DNSSEC-related log messages in
|
||||||
|
validator.c. [RT #19589]
|
||||||
|
|
||||||
|
2739. [cleanup] Clean up API for initializing and clearing trust
|
||||||
|
anchors for a view. [RT #20211]
|
||||||
|
|
||||||
|
2735. [bug] dnssec-signzone could fail to read keys
|
||||||
|
that were specified on the command line with
|
||||||
|
full paths, but weren't in the current
|
||||||
|
directory. [RT #20421]
|
||||||
|
|
||||||
|
2734. [port] cygwin: arpaname did not compile. [RT #20473]
|
||||||
|
|
||||||
|
2733. [cleanup] Clean up coding style in pkcs11-* tools. [RT #20355]
|
||||||
|
|
||||||
|
2728. [bug] dssec-keygen, dnssec-keyfromlabel and
|
||||||
|
dnssec-signzone now warn immediately if asked to
|
||||||
|
write into a nonexistent directory. [RT #20278]
|
||||||
|
|
||||||
|
2725. [doc] Added information about the file "managed-keys.bind"
|
||||||
|
to the ARM. [RT #20235]
|
||||||
|
|
||||||
|
2724. [bug] Updates to a existing node in secure zone using NSEC
|
||||||
|
were failing. [RT #20448]
|
||||||
|
|
||||||
|
2720. [bug] RFC 5011 trust anchor updates could trigger an
|
||||||
|
assert if the DNSKEY record was unsigned. [RT #20406]
|
||||||
|
|
||||||
|
2717. [bug] named failed to update the NSEC/NSEC3 record when
|
||||||
|
the last private type record was removed as a result
|
||||||
|
of completing the signing the zone with a key.
|
||||||
|
[RT #20399]
|
||||||
|
|
||||||
|
2711. [port] win32: Add the bin/pkcs11 tools into the full
|
||||||
|
build. [RT #20372]
|
||||||
|
|
||||||
|
2694. [bug] Reduce default NSEC3 iterations from 100 to 10.
|
||||||
|
[RT #19970]
|
||||||
|
|
||||||
|
2693. [port] Add some noreturn attributes. [RT #20257]
|
||||||
|
|
||||||
|
2687. [bug] Fixed dnssec-signzone -S handling of revoked keys.
|
||||||
|
Also, added warnings when revoking a ZSK, as this is
|
||||||
|
not defined by protocol (but is legal). [RT #19943]
|
||||||
|
|
||||||
|
2684. [cleanup] dig: formalize +ad and +cd as synonyms for
|
||||||
|
+adflag and +cdflag. [RT #19305]
|
||||||
|
|
||||||
|
2682. [bug] "configure --enable-symtable=all" failed to
|
||||||
|
build. [RT #20282]
|
||||||
|
|
||||||
|
2676. [bug] --with-export-installdir should have been
|
||||||
|
--with-export-includedir. [RT #20252]
|
||||||
|
|
||||||
|
2675. [bug] dnssec-signzone could crash if the key directory
|
||||||
|
did not exist. [RT #20232]
|
||||||
|
|
||||||
|
2674. [bug] "dnssec-lookaside auto;" crashed if named was built
|
||||||
|
without openssl. [RT #20231]
|
||||||
|
|
||||||
|
2673. [bug] The managed-keys.bind zone file could fail to
|
||||||
|
load due to a spurious result from sync_keyzone()
|
||||||
|
[RT #20045]
|
||||||
|
|
||||||
|
2671. [bug] Add support for PKCS#11 providers not returning
|
||||||
|
the public exponent in RSA private keys
|
||||||
|
(OpenCryptoki for instance) in
|
||||||
|
dnssec-keyfromlabel. [RT #19294]
|
||||||
|
|
||||||
|
2664. [bug] create_keydata() and minimal_update() in zone.c
|
||||||
|
didn't properly check return values for some
|
||||||
|
functions. [RT #19956]
|
||||||
|
|
||||||
|
2658. [bug] dnssec-settime and dnssec-revoke didn't process
|
||||||
|
key file paths correctly. [RT #20078]
|
||||||
|
|
||||||
|
2657. [cleanup] Lower "journal file <path> does not exist, creating it"
|
||||||
|
log level to debug 1. [RT #20058]
|
||||||
|
|
||||||
|
2654. [bug] Improve error reporting on duplicated names for
|
||||||
|
deny-answer-xxx. [RT #20164]
|
||||||
|
|
||||||
|
2651. [bug] Dates could print incorrectly in K*.key files on
|
||||||
|
64-bit systems. [RT #20076]
|
||||||
|
|
||||||
|
2650. [bug] Assertion failure in dnssec-signzone when trying
|
||||||
|
to read keyset-* files. [RT #20075]
|
||||||
|
|
||||||
|
2644. [bug] Change #2628 caused a regression on some systems;
|
||||||
|
named was unable to write the PID file and would
|
||||||
|
fail on startup. [RT #20001]
|
||||||
|
|
||||||
|
2641. [bug] Fixed an error in parsing update-policy syntax,
|
||||||
|
added a regression test to check it. [RT #20007]
|
||||||
|
|
||||||
|
2638. [bug] Install arpaname. [RT #19957]
|
||||||
|
|
||||||
|
2634. [port] win32: Add support for libxml2, enable
|
||||||
|
statschannel. [RT #19773]
|
||||||
|
|
||||||
|
2631. [bug] Handle "//", "/./" and "/../" in mkdirpath().
|
||||||
|
[RT #19926 ]
|
||||||
|
|
||||||
|
2629. [port] Check for seteuid()/setegid(), use setresuid()/
|
||||||
|
setresgid() if not present. [RT #19932]
|
||||||
|
|
||||||
|
2628. [port] linux: Allow /var/run/named/named.pid to be opened
|
||||||
|
at startup with reduced capabilities in operation.
|
||||||
|
[RT #19884]
|
||||||
|
|
||||||
|
2627. [bug] Named aborted if the same key was included in
|
||||||
|
trusted-keys more than once. [RT #19918]
|
||||||
|
|
||||||
|
2626. [bug] Multiple trusted-keys could trigger an assertion
|
||||||
|
failure. [RT #19914]
|
||||||
|
|
||||||
|
2622. [bug] Printing of named.conf grammar was broken. [RT #19919]
|
||||||
|
|
||||||
|
2600. [doc] ARM: miscellaneous reformatting for different
|
||||||
|
page widths. [RT #19574]
|
||||||
|
|
||||||
|
2566. [cleanup] Clarify logged message when an insecure DNSSEC
|
||||||
|
response arrives from a zone thought to be secure:
|
||||||
|
"insecurity proof failed" instead of "not
|
||||||
|
insecure". [RT #19400]
|
||||||
@@ -0,0 +1,893 @@
|
|||||||
|
Frequently Asked Questions about BIND 9
|
||||||
|
|
||||||
|
Copyright © 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
|
||||||
|
Copyright © 2000-2003 Internet Software Consortium.
|
||||||
|
|
||||||
|
-----------------------------------------------------------------------
|
||||||
|
|
||||||
|
1. Compilation and Installation Questions
|
||||||
|
|
||||||
|
Q: I'm trying to compile BIND 9, and "make" is failing due to files not
|
||||||
|
being found. Why?
|
||||||
|
|
||||||
|
A: Using a parallel or distributed "make" to build BIND 9 is not
|
||||||
|
supported, and doesn't work. If you are using one of these, use normal
|
||||||
|
make or gmake instead.
|
||||||
|
|
||||||
|
Q: Isn't "make install" supposed to generate a default named.conf?
|
||||||
|
|
||||||
|
A: Short Answer: No.
|
||||||
|
|
||||||
|
Long Answer: There really isn't a default configuration which fits any
|
||||||
|
site perfectly. There are lots of decisions that need to be made and
|
||||||
|
there is no consensus on what the defaults should be. For example
|
||||||
|
FreeBSD uses /etc/namedb as the location where the configuration files
|
||||||
|
for named are stored. Others use /var/named.
|
||||||
|
|
||||||
|
What addresses to listen on? For a laptop on the move a lot you may
|
||||||
|
only want to listen on the loop back interfaces.
|
||||||
|
|
||||||
|
Who do you offer recursive service to? Is there are firewall to
|
||||||
|
consider? If so is it stateless or stateful. Are you directly on the
|
||||||
|
Internet? Are you on a private network? Are you on a NAT'd network? The
|
||||||
|
answers to all these questions change how you configure even a caching
|
||||||
|
name server.
|
||||||
|
|
||||||
|
2. Configuration and Setup Questions
|
||||||
|
|
||||||
|
Q: Why does named log the warning message "no TTL specified - using SOA
|
||||||
|
MINTTL instead"?
|
||||||
|
|
||||||
|
A: Your zone file is illegal according to RFC1035. It must either have a
|
||||||
|
line like:
|
||||||
|
|
||||||
|
$TTL 86400
|
||||||
|
|
||||||
|
at the beginning, or the first record in it must have a TTL field, like
|
||||||
|
the "84600" in this example:
|
||||||
|
|
||||||
|
example.com. 86400 IN SOA ns hostmaster ( 1 3600 1800 1814400 3600 )
|
||||||
|
|
||||||
|
Q: Why do I get errors like "dns_zone_load: zone foo/IN: loading master
|
||||||
|
file bar: ran out of space"?
|
||||||
|
|
||||||
|
A: This is often caused by TXT records with missing close quotes. Check
|
||||||
|
that all TXT records containing quoted strings have both open and close
|
||||||
|
quotes.
|
||||||
|
|
||||||
|
Q: How do I restrict people from looking up the server version?
|
||||||
|
|
||||||
|
A: Put a "version" option containing something other than the real version
|
||||||
|
in the "options" section of named.conf. Note doing this will not
|
||||||
|
prevent attacks and may impede people trying to diagnose problems with
|
||||||
|
your server. Also it is possible to "fingerprint" nameservers to
|
||||||
|
determine their version.
|
||||||
|
|
||||||
|
Q: How do I restrict only remote users from looking up the server version?
|
||||||
|
|
||||||
|
A: The following view statement will intercept lookups as the internal
|
||||||
|
view that holds the version information will be matched last. The
|
||||||
|
caveats of the previous answer still apply, of course.
|
||||||
|
|
||||||
|
view "chaos" chaos {
|
||||||
|
match-clients { <those to be refused>; };
|
||||||
|
allow-query { none; };
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "/dev/null"; // or any empty file
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
Q: What do "no source of entropy found" or "could not open entropy source
|
||||||
|
foo" mean?
|
||||||
|
|
||||||
|
A: The server requires a source of entropy to perform certain operations,
|
||||||
|
mostly DNSSEC related. These messages indicate that you have no source
|
||||||
|
of entropy. On systems with /dev/random or an equivalent, it is used by
|
||||||
|
default. A source of entropy can also be defined using the
|
||||||
|
random-device option in named.conf.
|
||||||
|
|
||||||
|
Q: I'm trying to use TSIG to authenticate dynamic updates or zone
|
||||||
|
transfers. I'm sure I have the keys set up correctly, but the server is
|
||||||
|
rejecting the TSIG. Why?
|
||||||
|
|
||||||
|
A: This may be a clock skew problem. Check that the the clocks on the
|
||||||
|
client and server are properly synchronised (e.g., using ntp).
|
||||||
|
|
||||||
|
Q: I see a log message like the following. Why?
|
||||||
|
|
||||||
|
couldn't open pid file '/var/run/named.pid': Permission denied
|
||||||
|
|
||||||
|
A: You are most likely running named as a non-root user, and that user
|
||||||
|
does not have permission to write in /var/run. The common ways of
|
||||||
|
fixing this are to create a /var/run/named directory owned by the named
|
||||||
|
user and set pid-file to "/var/run/named/named.pid", or set pid-file to
|
||||||
|
"named.pid", which will put the file in the directory specified by the
|
||||||
|
directory option (which, in this case, must be writable by the named
|
||||||
|
user).
|
||||||
|
|
||||||
|
Q: I can query the nameserver from the nameserver but not from other
|
||||||
|
machines. Why?
|
||||||
|
|
||||||
|
A: This is usually the result of the firewall configuration stopping the
|
||||||
|
queries and / or the replies.
|
||||||
|
|
||||||
|
Q: How can I make a server a slave for both an internal and an external
|
||||||
|
view at the same time? When I tried, both views on the slave were
|
||||||
|
transferred from the same view on the master.
|
||||||
|
|
||||||
|
A: You will need to give the master and slave multiple IP addresses and
|
||||||
|
use those to make sure you reach the correct view on the other machine.
|
||||||
|
|
||||||
|
Master: 10.0.1.1 (internal), 10.0.1.2 (external, IP alias)
|
||||||
|
internal:
|
||||||
|
match-clients { !10.0.1.2; !10.0.1.4; 10.0.1/24; };
|
||||||
|
notify-source 10.0.1.1;
|
||||||
|
transfer-source 10.0.1.1;
|
||||||
|
query-source address 10.0.1.1;
|
||||||
|
external:
|
||||||
|
match-clients { any; };
|
||||||
|
recursion no; // don't offer recursion to the world
|
||||||
|
notify-source 10.0.1.2;
|
||||||
|
transfer-source 10.0.1.2;
|
||||||
|
query-source address 10.0.1.2;
|
||||||
|
|
||||||
|
Slave: 10.0.1.3 (internal), 10.0.1.4 (external, IP alias)
|
||||||
|
internal:
|
||||||
|
match-clients { !10.0.1.2; !10.0.1.4; 10.0.1/24; };
|
||||||
|
notify-source 10.0.1.3;
|
||||||
|
transfer-source 10.0.1.3;
|
||||||
|
query-source address 10.0.1.3;
|
||||||
|
external:
|
||||||
|
match-clients { any; };
|
||||||
|
recursion no; // don't offer recursion to the world
|
||||||
|
notify-source 10.0.1.4;
|
||||||
|
transfer-source 10.0.1.4;
|
||||||
|
query-source address 10.0.1.4;
|
||||||
|
|
||||||
|
You put the external address on the alias so that all the other dns
|
||||||
|
clients on these boxes see the internal view by default.
|
||||||
|
|
||||||
|
A: BIND 9.3 and later: Use TSIG to select the appropriate view.
|
||||||
|
|
||||||
|
Master 10.0.1.1:
|
||||||
|
key "external" {
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
secret "xxxxxxxxxxxxxxxxxxxxxxxx";
|
||||||
|
};
|
||||||
|
view "internal" {
|
||||||
|
match-clients { !key external; // reject message ment for the
|
||||||
|
// external view.
|
||||||
|
10.0.1/24; }; // accept from these addresses.
|
||||||
|
...
|
||||||
|
};
|
||||||
|
view "external" {
|
||||||
|
match-clients { key external; any; };
|
||||||
|
server 10.0.1.2 { keys external; }; // tag messages from the
|
||||||
|
// external view to the
|
||||||
|
// other servers for the
|
||||||
|
// view.
|
||||||
|
recursion no;
|
||||||
|
...
|
||||||
|
};
|
||||||
|
|
||||||
|
Slave 10.0.1.2:
|
||||||
|
key "external" {
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
secret "xxxxxxxxxxxxxxxxxxxxxxxx";
|
||||||
|
};
|
||||||
|
view "internal" {
|
||||||
|
match-clients { !key external; 10.0.1/24; };
|
||||||
|
...
|
||||||
|
};
|
||||||
|
view "external" {
|
||||||
|
match-clients { key external; any; };
|
||||||
|
server 10.0.1.1 { keys external; };
|
||||||
|
recursion no;
|
||||||
|
...
|
||||||
|
};
|
||||||
|
|
||||||
|
Q: I get error messages like "multiple RRs of singleton type" and "CNAME
|
||||||
|
and other data" when transferring a zone. What does this mean?
|
||||||
|
|
||||||
|
A: These indicate a malformed master zone. You can identify the exact
|
||||||
|
records involved by transferring the zone using dig then running
|
||||||
|
named-checkzone on it.
|
||||||
|
|
||||||
|
dig axfr example.com @master-server > tmp
|
||||||
|
named-checkzone example.com tmp
|
||||||
|
|
||||||
|
A CNAME record cannot exist with the same name as another record except
|
||||||
|
for the DNSSEC records which prove its existence (NSEC).
|
||||||
|
|
||||||
|
RFC 1034, Section 3.6.2: "If a CNAME RR is present at a node, no other
|
||||||
|
data should be present; this ensures that the data for a canonical name
|
||||||
|
and its aliases cannot be different. This rule also insures that a
|
||||||
|
cached CNAME can be used without checking with an authoritative server
|
||||||
|
for other RR types."
|
||||||
|
|
||||||
|
Q: I get error messages like "named.conf:99: unexpected end of input"
|
||||||
|
where 99 is the last line of named.conf.
|
||||||
|
|
||||||
|
A: There are unbalanced quotes in named.conf.
|
||||||
|
|
||||||
|
A: Some text editors (notepad and wordpad) fail to put a line title
|
||||||
|
indication (e.g. CR/LF) on the last line of a text file. This can be
|
||||||
|
fixed by "adding" a blank line to the end of the file. Named expects to
|
||||||
|
see EOF immediately after EOL and treats text files where this is not
|
||||||
|
met as truncated.
|
||||||
|
|
||||||
|
Q: How do I share a dynamic zone between multiple views?
|
||||||
|
|
||||||
|
A: You choose one view to be master and the second a slave and transfer
|
||||||
|
the zone between views.
|
||||||
|
|
||||||
|
Master 10.0.1.1:
|
||||||
|
key "external" {
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
secret "xxxxxxxxxxxxxxxxxxxxxxxx";
|
||||||
|
};
|
||||||
|
|
||||||
|
key "mykey" {
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
secret "yyyyyyyyyyyyyyyyyyyyyyyy";
|
||||||
|
};
|
||||||
|
|
||||||
|
view "internal" {
|
||||||
|
match-clients { !key external; 10.0.1/24; };
|
||||||
|
server 10.0.1.1 {
|
||||||
|
/* Deliver notify messages to external view. */
|
||||||
|
keys { external; };
|
||||||
|
};
|
||||||
|
zone "example.com" {
|
||||||
|
type master;
|
||||||
|
file "internal/example.db";
|
||||||
|
allow-update { key mykey; };
|
||||||
|
also-notify { 10.0.1.1; };
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
view "external" {
|
||||||
|
match-clients { key external; any; };
|
||||||
|
zone "example.com" {
|
||||||
|
type slave;
|
||||||
|
file "external/example.db";
|
||||||
|
masters { 10.0.1.1; };
|
||||||
|
transfer-source 10.0.1.1;
|
||||||
|
// allow-update-forwarding { any; };
|
||||||
|
// allow-notify { ... };
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
Q: I get a error message like "zone wireless.ietf56.ietf.org/IN: loading
|
||||||
|
master file primaries/wireless.ietf56.ietf.org: no owner".
|
||||||
|
|
||||||
|
A: This error is produced when a line in the master file contains leading
|
||||||
|
white space (tab/space) but the is no current record owner name to
|
||||||
|
inherit the name from. Usually this is the result of putting white
|
||||||
|
space before a comment, forgetting the "@" for the SOA record, or
|
||||||
|
indenting the master file.
|
||||||
|
|
||||||
|
Q: Why are my logs in GMT (UTC).
|
||||||
|
|
||||||
|
A: You are running chrooted (-t) and have not supplied local timezone
|
||||||
|
information in the chroot area.
|
||||||
|
|
||||||
|
FreeBSD: /etc/localtime
|
||||||
|
Solaris: /etc/TIMEZONE and /usr/share/lib/zoneinfo
|
||||||
|
OSF: /etc/zoneinfo/localtime
|
||||||
|
|
||||||
|
See also tzset(3) and zic(8).
|
||||||
|
|
||||||
|
Q: I get "rndc: connect failed: connection refused" when I try to run
|
||||||
|
rndc.
|
||||||
|
|
||||||
|
A: This is usually a configuration error.
|
||||||
|
|
||||||
|
First ensure that named is running and no errors are being reported at
|
||||||
|
startup (/var/log/messages or equivalent). Running "named -g <usual
|
||||||
|
arguments>" from a title can help at this point.
|
||||||
|
|
||||||
|
Secondly ensure that named is configured to use rndc either by
|
||||||
|
"rndc-confgen -a", rndc-confgen or manually. The Administrators
|
||||||
|
Reference manual has details on how to do this.
|
||||||
|
|
||||||
|
Old versions of rndc-confgen used localhost rather than 127.0.0.1 in /
|
||||||
|
etc/rndc.conf for the default server. Update /etc/rndc.conf if
|
||||||
|
necessary so that the default server listed in /etc/rndc.conf matches
|
||||||
|
the addresses used in named.conf. "localhost" has two address
|
||||||
|
(127.0.0.1 and ::1).
|
||||||
|
|
||||||
|
If you use "rndc-confgen -a" and named is running with -t or -u ensure
|
||||||
|
that /etc/rndc.conf has the correct ownership and that a copy is in the
|
||||||
|
chroot area. You can do this by re-running "rndc-confgen -a" with
|
||||||
|
appropriate -t and -u arguments.
|
||||||
|
|
||||||
|
Q: I get "transfer of 'example.net/IN' from 192.168.4.12#53: failed while
|
||||||
|
receiving responses: permission denied" error messages.
|
||||||
|
|
||||||
|
A: These indicate a filesystem permission error preventing named creating
|
||||||
|
/ renaming the temporary file. These will usually also have other
|
||||||
|
associated error messages like
|
||||||
|
|
||||||
|
"dumping master file: sl/tmp-XXXX5il3sQ: open: permission denied"
|
||||||
|
|
||||||
|
Named needs write permission on the directory containing the file.
|
||||||
|
Named writes the new cache file to a temporary file then renames it to
|
||||||
|
the name specified in named.conf to ensure that the contents are always
|
||||||
|
complete. This is to prevent named loading a partial zone in the event
|
||||||
|
of power failure or similar interrupting the write of the master file.
|
||||||
|
|
||||||
|
Note file names are relative to the directory specified in options and
|
||||||
|
any chroot directory ([<chroot dir>/][<options dir>]).
|
||||||
|
|
||||||
|
If named is invoked as "named -t /chroot/DNS" with the following
|
||||||
|
named.conf then "/chroot/DNS/var/named/sl" needs to be writable by the
|
||||||
|
user named is running as.
|
||||||
|
|
||||||
|
options {
|
||||||
|
directory "/var/named";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "example.net" {
|
||||||
|
type slave;
|
||||||
|
file "sl/example.net";
|
||||||
|
masters { 192.168.4.12; };
|
||||||
|
};
|
||||||
|
|
||||||
|
Q: I want to forward all DNS queries from my caching nameserver to another
|
||||||
|
server. But there are some domains which have to be served locally, via
|
||||||
|
rbldnsd.
|
||||||
|
|
||||||
|
How do I achieve this ?
|
||||||
|
|
||||||
|
A: options {
|
||||||
|
forward only;
|
||||||
|
forwarders { <ip.of.primary.nameserver>; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "sbl-xbl.spamhaus.org" {
|
||||||
|
type forward; forward only;
|
||||||
|
forwarders { <ip.of.rbldns.server> port 530; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "list.dsbl.org" {
|
||||||
|
type forward; forward only;
|
||||||
|
forwarders { <ip.of.rbldns.server> port 530; };
|
||||||
|
};
|
||||||
|
|
||||||
|
|
||||||
|
Q: Can you help me understand how BIND 9 uses memory to store DNS zones?
|
||||||
|
|
||||||
|
Some times it seems to take several times the amount of memory it needs
|
||||||
|
to store the zone.
|
||||||
|
|
||||||
|
A: When reloading a zone named my have multiple copies of the zone in
|
||||||
|
memory at one time. The zone it is serving and the one it is loading.
|
||||||
|
If reloads are ultra fast it can have more still.
|
||||||
|
|
||||||
|
e.g. Ones that are transferring out, the one that it is serving and the
|
||||||
|
one that is loading.
|
||||||
|
|
||||||
|
BIND 8 destroyed the zone before loading and also killed off outgoing
|
||||||
|
transfers of the zone.
|
||||||
|
|
||||||
|
The new strategy allows slaves to get copies of the new zone regardless
|
||||||
|
of how often the master is loaded compared to the transfer time. The
|
||||||
|
slave might skip some intermediate versions but the transfers will
|
||||||
|
complete and it will keep reasonably in sync with the master.
|
||||||
|
|
||||||
|
The new strategy also allows the master to recover from syntax and
|
||||||
|
other errors in the master file as it still has an in-core copy of the
|
||||||
|
old contents.
|
||||||
|
|
||||||
|
Q: I want to use IPv6 locally but I don't have a external IPv6 connection.
|
||||||
|
External lookups are slow.
|
||||||
|
|
||||||
|
A: You can use server clauses to stop named making external lookups over
|
||||||
|
IPv6.
|
||||||
|
|
||||||
|
server fd81:ec6c:bd62::/48 { bogus no; }; // site ULA prefix
|
||||||
|
server ::/0 { bogus yes; };
|
||||||
|
|
||||||
|
3. Operations Questions
|
||||||
|
|
||||||
|
Q: How to change the nameservers for a zone?
|
||||||
|
|
||||||
|
A: Step 1: Ensure all nameservers, new and old, are serving the same zone
|
||||||
|
content.
|
||||||
|
|
||||||
|
Step 2: Work out the maximum TTL of the NS RRset in the parent and
|
||||||
|
child zones. This is the time it will take caches to be clear of a
|
||||||
|
particular version of the NS RRset. If you are just removing
|
||||||
|
nameservers you can skip to Step 6.
|
||||||
|
|
||||||
|
Step 3: Add new nameservers to the NS RRset for the zone and wait until
|
||||||
|
all the servers for the zone are answering with this new NS RRset.
|
||||||
|
|
||||||
|
Step 4: Inform the parent zone of the new NS RRset then wait for all
|
||||||
|
the parent servers to be answering with the new NS RRset.
|
||||||
|
|
||||||
|
Step 5: Wait for cache to be clear of the old NS RRset. See Step 2 for
|
||||||
|
how long. If you are just adding nameservers you are done.
|
||||||
|
|
||||||
|
Step 6: Remove any old nameservers from the zones NS RRset and wait for
|
||||||
|
all the servers for the zone to be serving the new NS RRset.
|
||||||
|
|
||||||
|
Step 7: Inform the parent zone of the new NS RRset then wait for all
|
||||||
|
the parent servers to be answering with the new NS RRset.
|
||||||
|
|
||||||
|
Step 8: Wait for cache to be clear of the old NS RRset. See Step 2 for
|
||||||
|
how long.
|
||||||
|
|
||||||
|
Step 9: Turn off the old nameservers or remove the zone entry from the
|
||||||
|
configuration of the old nameservers.
|
||||||
|
|
||||||
|
Step 10: Increment the serial number and wait for the change to be
|
||||||
|
visible in all nameservers for the zone. This ensures that zone
|
||||||
|
transfers are still working after the old servers are decommissioned.
|
||||||
|
|
||||||
|
Note: the above procedure is designed to be transparent to dns clients.
|
||||||
|
Decommissioning the old servers too early will result in some clients
|
||||||
|
not being able to look up answers in the zone.
|
||||||
|
|
||||||
|
Note: while it is possible to run the addition and removal stages
|
||||||
|
together it is not recommended.
|
||||||
|
|
||||||
|
4. General Questions
|
||||||
|
|
||||||
|
Q: I keep getting log messages like the following. Why?
|
||||||
|
|
||||||
|
Dec 4 23:47:59 client 10.0.0.1#1355: updating zone 'example.com/IN':
|
||||||
|
update failed: 'RRset exists (value dependent)' prerequisite not
|
||||||
|
satisfied (NXRRSET)
|
||||||
|
|
||||||
|
A: DNS updates allow the update request to test to see if certain
|
||||||
|
conditions are met prior to proceeding with the update. The message
|
||||||
|
above is saying that conditions were not met and the update is not
|
||||||
|
proceeding. See doc/rfc/rfc2136.txt for more details on prerequisites.
|
||||||
|
|
||||||
|
Q: I keep getting log messages like the following. Why?
|
||||||
|
|
||||||
|
Jun 21 12:00:00.000 client 10.0.0.1#1234: update denied
|
||||||
|
|
||||||
|
A: Someone is trying to update your DNS data using the RFC2136 Dynamic
|
||||||
|
Update protocol. Windows 2000 machines have a habit of sending dynamic
|
||||||
|
update requests to DNS servers without being specifically configured to
|
||||||
|
do so. If the update requests are coming from a Windows 2000 machine,
|
||||||
|
see <http://support.microsoft.com/support/kb/articles/q246/8/04.asp>
|
||||||
|
for information about how to turn them off.
|
||||||
|
|
||||||
|
Q: When I do a "dig . ns", many of the A records for the root servers are
|
||||||
|
missing. Why?
|
||||||
|
|
||||||
|
A: This is normal and harmless. It is a somewhat confusing side effect of
|
||||||
|
the way BIND 9 does RFC2181 trust ranking and of the efforts BIND 9
|
||||||
|
makes to avoid promoting glue into answers.
|
||||||
|
|
||||||
|
When BIND 9 first starts up and primes its cache, it receives the root
|
||||||
|
server addresses as additional data in an authoritative response from a
|
||||||
|
root server, and these records are eligible for inclusion as additional
|
||||||
|
data in responses. Subsequently it receives a subset of the root server
|
||||||
|
addresses as additional data in a non-authoritative (referral) response
|
||||||
|
from a root server. This causes the addresses to now be considered
|
||||||
|
non-authoritative (glue) data, which is not eligible for inclusion in
|
||||||
|
responses.
|
||||||
|
|
||||||
|
The server does have a complete set of root server addresses cached at
|
||||||
|
all times, it just may not include all of them as additional data,
|
||||||
|
depending on whether they were last received as answers or as glue. You
|
||||||
|
can always look up the addresses with explicit queries like "dig
|
||||||
|
a.root-servers.net A".
|
||||||
|
|
||||||
|
Q: Why don't my zones reload when I do an "rndc reload" or SIGHUP?
|
||||||
|
|
||||||
|
A: A zone can be updated either by editing zone files and reloading the
|
||||||
|
server or by dynamic update, but not both. If you have enabled dynamic
|
||||||
|
update for a zone using the "allow-update" option, you are not supposed
|
||||||
|
to edit the zone file by hand, and the server will not attempt to
|
||||||
|
reload it.
|
||||||
|
|
||||||
|
Q: Why is named listening on UDP port other than 53?
|
||||||
|
|
||||||
|
A: Named uses a system selected port to make queries of other nameservers.
|
||||||
|
This behaviour can be overridden by using query-source to lock down the
|
||||||
|
port and/or address. See also notify-source and transfer-source.
|
||||||
|
|
||||||
|
Q: I get warning messages like "zone example.com/IN: refresh: failure
|
||||||
|
trying master 1.2.3.4#53: timed out".
|
||||||
|
|
||||||
|
A: Check that you can make UDP queries from the slave to the master
|
||||||
|
|
||||||
|
dig +norec example.com soa @1.2.3.4
|
||||||
|
|
||||||
|
You could be generating queries faster than the slave can cope with.
|
||||||
|
Lower the serial query rate.
|
||||||
|
|
||||||
|
serial-query-rate 5; // default 20
|
||||||
|
|
||||||
|
Q: I don't get RRSIG's returned when I use "dig +dnssec".
|
||||||
|
|
||||||
|
A: You need to ensure DNSSEC is enabled (dnssec-enable yes;).
|
||||||
|
|
||||||
|
Q: Can a NS record refer to a CNAME.
|
||||||
|
|
||||||
|
A: No. The rules for glue (copies of the *address* records in the parent
|
||||||
|
zones) and additional section processing do not allow it to work.
|
||||||
|
|
||||||
|
You would have to add both the CNAME and address records (A/AAAA) as
|
||||||
|
glue to the parent zone and have CNAMEs be followed when doing
|
||||||
|
additional section processing to make it work. No nameserver
|
||||||
|
implementation supports either of these requirements.
|
||||||
|
|
||||||
|
Q: What does "RFC 1918 response from Internet for 0.0.0.10.IN-ADDR.ARPA"
|
||||||
|
mean?
|
||||||
|
|
||||||
|
A: If the IN-ADDR.ARPA name covered refers to a internal address space you
|
||||||
|
are using then you have failed to follow RFC 1918 usage rules and are
|
||||||
|
leaking queries to the Internet. You should establish your own zones
|
||||||
|
for these addresses to prevent you querying the Internet's name servers
|
||||||
|
for these addresses. Please see <http://as112.net/> for details of the
|
||||||
|
problems you are causing and the counter measures that have had to be
|
||||||
|
deployed.
|
||||||
|
|
||||||
|
If you are not using these private addresses then a client has queried
|
||||||
|
for them. You can just ignore the messages, get the offending client to
|
||||||
|
stop sending you these messages as they are most probably leaking them
|
||||||
|
or setup your own zones empty zones to serve answers to these queries.
|
||||||
|
|
||||||
|
zone "10.IN-ADDR.ARPA" {
|
||||||
|
type master;
|
||||||
|
file "empty";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "16.172.IN-ADDR.ARPA" {
|
||||||
|
type master;
|
||||||
|
file "empty";
|
||||||
|
};
|
||||||
|
|
||||||
|
...
|
||||||
|
|
||||||
|
zone "31.172.IN-ADDR.ARPA" {
|
||||||
|
type master;
|
||||||
|
file "empty";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "168.192.IN-ADDR.ARPA" {
|
||||||
|
type master;
|
||||||
|
file "empty";
|
||||||
|
};
|
||||||
|
|
||||||
|
empty:
|
||||||
|
@ 10800 IN SOA <name-of-server>. <contact-email>. (
|
||||||
|
1 3600 1200 604800 10800 )
|
||||||
|
@ 10800 IN NS <name-of-server>.
|
||||||
|
|
||||||
|
Note
|
||||||
|
|
||||||
|
Future versions of named are likely to do this automatically.
|
||||||
|
|
||||||
|
Q: Will named be affected by the 2007 changes to daylight savings rules in
|
||||||
|
the US.
|
||||||
|
|
||||||
|
A: No, so long as the machines internal clock (as reported by "date -u")
|
||||||
|
remains at UTC. The only visible change if you fail to upgrade your OS,
|
||||||
|
if you are in a affected area, will be that log messages will be a hour
|
||||||
|
out during the period where the old rules do not match the new rules.
|
||||||
|
|
||||||
|
For most OS's this change just means that you need to update the
|
||||||
|
conversion rules from UTC to local time. Normally this involves
|
||||||
|
updating a file in /etc (which sets the default timezone for the
|
||||||
|
machine) and possibly a directory which has all the conversion rules
|
||||||
|
for the world (e.g. /usr/share/zoneinfo). When updating the OS do not
|
||||||
|
forget to update any chroot areas as well. See your OS's documentation
|
||||||
|
for more details.
|
||||||
|
|
||||||
|
The local timezone conversion rules can also be done on a individual
|
||||||
|
basis by setting the TZ environment variable appropriately. See your
|
||||||
|
OS's documentation for more details.
|
||||||
|
|
||||||
|
Q: Is there a bugzilla (or other tool) database that mere mortals can have
|
||||||
|
(read-only) access to for bind?
|
||||||
|
|
||||||
|
A: No. The BIND 9 bug database is kept closed for a number of reasons.
|
||||||
|
These include, but are not limited to, that the database contains
|
||||||
|
proprietory information from people reporting bugs. The database has in
|
||||||
|
the past and may in future contain unfixed bugs which are capable of
|
||||||
|
bringing down most of the Internet's DNS infrastructure.
|
||||||
|
|
||||||
|
The release pages for each version contain up to date lists of bugs
|
||||||
|
that have been fixed post release. That is as close as we can get to
|
||||||
|
providing a bug database.
|
||||||
|
|
||||||
|
Q: Why do queries for NSEC3 records fail to return the NSEC3 record?
|
||||||
|
|
||||||
|
A: NSEC3 records are strictly meta data and can only be returned in the
|
||||||
|
authority section. This is done so that signing the zone using NSEC3
|
||||||
|
records does not bring names into existence that do not exist in the
|
||||||
|
unsigned version of the zone.
|
||||||
|
|
||||||
|
5. Operating-System Specific Questions
|
||||||
|
|
||||||
|
5.1. HPUX
|
||||||
|
|
||||||
|
Q: I get the following error trying to configure BIND:
|
||||||
|
|
||||||
|
checking if unistd.h or sys/types.h defines fd_set... no
|
||||||
|
configure: error: need either working unistd.h or sys/select.h
|
||||||
|
|
||||||
|
A: You have attempted to configure BIND with the bundled C compiler. This
|
||||||
|
compiler does not meet the minimum compiler requirements to for
|
||||||
|
building BIND. You need to install a ANSI C compiler and / or teach
|
||||||
|
configure how to find the ANSI C compiler. The later can be done by
|
||||||
|
adjusting the PATH environment variable and / or specifying the
|
||||||
|
compiler via CC.
|
||||||
|
|
||||||
|
./configure CC=<compiler> ...
|
||||||
|
|
||||||
|
5.2. Linux
|
||||||
|
|
||||||
|
Q: Why do I get the following errors:
|
||||||
|
|
||||||
|
general: errno2result.c:109: unexpected error:
|
||||||
|
general: unable to convert errno to isc_result: 14: Bad address
|
||||||
|
client: UDP client handler shutting down due to fatal receive error: unexpected error
|
||||||
|
|
||||||
|
A: This is the result of a Linux kernel bug.
|
||||||
|
|
||||||
|
See: <http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=
|
||||||
|
2>
|
||||||
|
|
||||||
|
Q: Why does named lock up when it attempts to connect over IPSEC tunnels?
|
||||||
|
|
||||||
|
A: This is due to a kernel bug where the fact that a socket is marked
|
||||||
|
non-blocking is ignored. It is reported that setting xfrm_larval_drop
|
||||||
|
to 1 helps but this may have negative side effects. See: <https://
|
||||||
|
bugzilla.redhat.com/show_bug.cgi?id=427629> and <http://lkml.org/lkml/
|
||||||
|
2007/12/4/260>.
|
||||||
|
|
||||||
|
xfrm_larval_drop can be set to 1 by the following procedure:
|
||||||
|
|
||||||
|
echo "1" > proc/sys/net/core/xfrm_larval_drop
|
||||||
|
|
||||||
|
Q: Why do I see 5 (or more) copies of named on Linux?
|
||||||
|
|
||||||
|
A: Linux threads each show up as a process under ps. The approximate
|
||||||
|
number of threads running is n+4, where n is the number of CPUs. Note
|
||||||
|
that the amount of memory used is not cumulative; if each process is
|
||||||
|
using 10M of memory, only a total of 10M is used.
|
||||||
|
|
||||||
|
Newer versions of Linux's ps command hide the individual threads and
|
||||||
|
require -L to display them.
|
||||||
|
|
||||||
|
Q: Why does BIND 9 log "permission denied" errors accessing its
|
||||||
|
configuration files or zones on my Linux system even though it is
|
||||||
|
running as root?
|
||||||
|
|
||||||
|
A: On Linux, BIND 9 drops most of its root privileges on startup. This
|
||||||
|
including the privilege to open files owned by other users. Therefore,
|
||||||
|
if the server is running as root, the configuration files and zone
|
||||||
|
files should also be owned by root.
|
||||||
|
|
||||||
|
Q: I get the error message "named: capset failed: Operation not permitted"
|
||||||
|
when starting named.
|
||||||
|
|
||||||
|
A: The capability module, part of "Linux Security Modules/LSM", has not
|
||||||
|
been loaded into the kernel. See insmod(8), modprobe(8).
|
||||||
|
|
||||||
|
The relevant modules can be loaded by running:
|
||||||
|
|
||||||
|
modprobe commoncap
|
||||||
|
modprobe capability
|
||||||
|
|
||||||
|
Q: I'm running BIND on Red Hat Enterprise Linux or Fedora Core -
|
||||||
|
|
||||||
|
Why can't named update slave zone database files?
|
||||||
|
|
||||||
|
Why can't named create DDNS journal files or update the master zones
|
||||||
|
from journals?
|
||||||
|
|
||||||
|
Why can't named create custom log files?
|
||||||
|
|
||||||
|
A: Red Hat Security Enhanced Linux (SELinux) policy security protections :
|
||||||
|
|
||||||
|
Red Hat have adopted the National Security Agency's SELinux security
|
||||||
|
policy (see <http://www.nsa.gov/selinux>) and recommendations for BIND
|
||||||
|
security , which are more secure than running named in a chroot and
|
||||||
|
make use of the bind-chroot environment unnecessary .
|
||||||
|
|
||||||
|
By default, named is not allowed by the SELinux policy to write, create
|
||||||
|
or delete any files EXCEPT in these directories:
|
||||||
|
|
||||||
|
$ROOTDIR/var/named/slaves
|
||||||
|
$ROOTDIR/var/named/data
|
||||||
|
$ROOTDIR/var/tmp
|
||||||
|
|
||||||
|
|
||||||
|
where $ROOTDIR may be set in /etc/sysconfig/named if bind-chroot is
|
||||||
|
installed.
|
||||||
|
|
||||||
|
The SELinux policy particularly does NOT allow named to modify the
|
||||||
|
$ROOTDIR/var/named directory, the default location for master zone
|
||||||
|
database files.
|
||||||
|
|
||||||
|
SELinux policy overrules file access permissions - so even if all the
|
||||||
|
files under /var/named have ownership named:named and mode rw-rw-r--,
|
||||||
|
named will still not be able to write or create files except in the
|
||||||
|
directories above, with SELinux in Enforcing mode.
|
||||||
|
|
||||||
|
So, to allow named to update slave or DDNS zone files, it is best to
|
||||||
|
locate them in $ROOTDIR/var/named/slaves, with named.conf zone
|
||||||
|
statements such as:
|
||||||
|
|
||||||
|
zone "slave.zone." IN {
|
||||||
|
type slave;
|
||||||
|
file "slaves/slave.zone.db";
|
||||||
|
...
|
||||||
|
};
|
||||||
|
zone "ddns.zone." IN {
|
||||||
|
type master;
|
||||||
|
allow-updates {...};
|
||||||
|
file "slaves/ddns.zone.db";
|
||||||
|
};
|
||||||
|
|
||||||
|
|
||||||
|
To allow named to create its cache dump and statistics files, for
|
||||||
|
example, you could use named.conf options statements such as:
|
||||||
|
|
||||||
|
options {
|
||||||
|
...
|
||||||
|
dump-file "/var/named/data/cache_dump.db";
|
||||||
|
statistics-file "/var/named/data/named_stats.txt";
|
||||||
|
...
|
||||||
|
};
|
||||||
|
|
||||||
|
|
||||||
|
You can also tell SELinux to allow named to update any zone database
|
||||||
|
files, by setting the SELinux tunable boolean parameter
|
||||||
|
'named_write_master_zones=1', using the system-config-securitylevel
|
||||||
|
GUI, using the 'setsebool' command, or in /etc/selinux/targeted/
|
||||||
|
booleans.
|
||||||
|
|
||||||
|
You can disable SELinux protection for named entirely by setting the
|
||||||
|
'named_disable_trans=1' SELinux tunable boolean parameter.
|
||||||
|
|
||||||
|
The SELinux named policy defines these SELinux contexts for named:
|
||||||
|
|
||||||
|
named_zone_t : for zone database files - $ROOTDIR/var/named/*
|
||||||
|
named_conf_t : for named configuration files - $ROOTDIR/etc/{named,rndc}.*
|
||||||
|
named_cache_t: for files modifiable by named - $ROOTDIR/var/{tmp,named/{slaves,data}}
|
||||||
|
|
||||||
|
|
||||||
|
If you want to retain use of the SELinux policy for named, and put
|
||||||
|
named files in different locations, you can do so by changing the
|
||||||
|
context of the custom file locations .
|
||||||
|
|
||||||
|
To create a custom configuration file location, e.g. '/root/
|
||||||
|
named.conf', to use with the 'named -c' option, do:
|
||||||
|
|
||||||
|
# chcon system_u:object_r:named_conf_t /root/named.conf
|
||||||
|
|
||||||
|
|
||||||
|
To create a custom modifiable named data location, e.g. '/var/log/
|
||||||
|
named' for a log file, do:
|
||||||
|
|
||||||
|
# chcon system_u:object_r:named_cache_t /var/log/named
|
||||||
|
|
||||||
|
|
||||||
|
To create a custom zone file location, e.g. /root/zones/, do:
|
||||||
|
|
||||||
|
# chcon system_u:object_r:named_zone_t /root/zones/{.,*}
|
||||||
|
|
||||||
|
|
||||||
|
See these man-pages for more information : selinux(8), named_selinux
|
||||||
|
(8), chcon(1), setsebool(8)
|
||||||
|
|
||||||
|
Q: I'm running BIND on Ubuntu -
|
||||||
|
|
||||||
|
Why can't named update slave zone database files?
|
||||||
|
|
||||||
|
Why can't named create DDNS journal files or update the master zones
|
||||||
|
from journals?
|
||||||
|
|
||||||
|
Why can't named create custom log files?
|
||||||
|
|
||||||
|
A: Ubuntu uses AppArmor <http://en.wikipedia.org/wiki/AppArmor> in
|
||||||
|
addition to normal file system permissions to protect the system.
|
||||||
|
|
||||||
|
Adjust the paths to use those specified in /etc/apparmor.d/
|
||||||
|
usr.sbin.named or adjust /etc/apparmor.d/usr.sbin.named to allow named
|
||||||
|
to write at the location specified in named.conf.
|
||||||
|
|
||||||
|
Q: Listening on individual IPv6 interfaces does not work.
|
||||||
|
|
||||||
|
A: This is usually due to "/proc/net/if_inet6" not being available in the
|
||||||
|
chroot file system. Mount another instance of "proc" in the chroot file
|
||||||
|
system.
|
||||||
|
|
||||||
|
This can be be made permanent by adding a second instance to /etc/
|
||||||
|
fstab.
|
||||||
|
|
||||||
|
proc /proc proc defaults 0 0
|
||||||
|
proc /var/named/proc proc defaults 0 0
|
||||||
|
|
||||||
|
5.3. Windows
|
||||||
|
|
||||||
|
Q: Zone transfers from my BIND 9 master to my Windows 2000 slave fail.
|
||||||
|
Why?
|
||||||
|
|
||||||
|
A: This may be caused by a bug in the Windows 2000 DNS server where DNS
|
||||||
|
messages larger than 16K are not handled properly. This can be worked
|
||||||
|
around by setting the option "transfer-format one-answer;". Also check
|
||||||
|
whether your zone contains domain names with embedded spaces or other
|
||||||
|
special characters, like "John\032Doe\213s\032Computer", since such
|
||||||
|
names have been known to cause Windows 2000 slaves to incorrectly
|
||||||
|
reject the zone.
|
||||||
|
|
||||||
|
Q: I get "Error 1067" when starting named under Windows.
|
||||||
|
|
||||||
|
A: This is the service manager saying that named exited. You need to
|
||||||
|
examine the Application log in the EventViewer to find out why.
|
||||||
|
|
||||||
|
Common causes are that you failed to create "named.conf" (usually "C:\
|
||||||
|
windows\dns\etc\named.conf") or failed to specify the directory in
|
||||||
|
named.conf.
|
||||||
|
|
||||||
|
options {
|
||||||
|
Directory "C:\windows\dns\etc";
|
||||||
|
};
|
||||||
|
|
||||||
|
5.4. FreeBSD
|
||||||
|
|
||||||
|
Q: I have FreeBSD 4.x and "rndc-confgen -a" just sits there.
|
||||||
|
|
||||||
|
A: /dev/random is not configured. Use rndcontrol(8) to tell the kernel to
|
||||||
|
use certain interrupts as a source of random events. You can make this
|
||||||
|
permanent by setting rand_irqs in /etc/rc.conf.
|
||||||
|
|
||||||
|
rand_irqs="3 14 15"
|
||||||
|
|
||||||
|
See also <http://people.freebsd.org/~dougb/randomness.html>.
|
||||||
|
|
||||||
|
5.5. Solaris
|
||||||
|
|
||||||
|
Q: How do I integrate BIND 9 and Solaris SMF
|
||||||
|
|
||||||
|
A: Sun has a blog entry describing how to do this.
|
||||||
|
|
||||||
|
<http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris>
|
||||||
|
|
||||||
|
5.6. Apple Mac OS X
|
||||||
|
|
||||||
|
Q: How do I run BIND 9 on Apple Mac OS X?
|
||||||
|
|
||||||
|
A: If you run Tiger(Mac OS 10.4) or later then this is all you need to do:
|
||||||
|
|
||||||
|
% sudo rndc-confgen > /etc/rndc.conf
|
||||||
|
|
||||||
|
Copy the key statement from /etc/rndc.conf into /etc/rndc.key, e.g.:
|
||||||
|
|
||||||
|
key "rndc-key" {
|
||||||
|
algorithm hmac-md5;
|
||||||
|
secret "uvceheVuqf17ZwIcTydddw==";
|
||||||
|
};
|
||||||
|
|
||||||
|
Then start the relevant service:
|
||||||
|
|
||||||
|
% sudo service org.isc.named start
|
||||||
|
|
||||||
|
This is persistent upon a reboot, so you will have to do it only once.
|
||||||
|
|
||||||
|
A: Alternatively you can just generate /etc/rndc.key by running:
|
||||||
|
|
||||||
|
% sudo rndc-confgen -a
|
||||||
|
|
||||||
|
Then start the relevant service:
|
||||||
|
|
||||||
|
% sudo service org.isc.named start
|
||||||
|
|
||||||
|
Named will look for /etc/rndc.key when it starts if it doesn't have a
|
||||||
|
controls section or the existing controls are missing keys sub-clauses.
|
||||||
|
This is persistent upon a reboot, so you will have to do it only once.
|
||||||
|
|
||||||
-632
@@ -1,632 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
### Functional enhancements from prior major releases of BIND 9
|
|
||||||
|
|
||||||
#### BIND 9.16
|
|
||||||
|
|
||||||
BIND 9.16 (a stable branch based on the 9.15 development branch)
|
|
||||||
includes a number of changes from BIND 9.14 and earlier releases.
|
|
||||||
New features include:
|
|
||||||
|
|
||||||
* New `dnssec-policy` statement to configure a key and signing policy
|
|
||||||
for zones, enabling automatic key regeneration and rollover.
|
|
||||||
* New network manager based on `libuv`.
|
|
||||||
* Added support for the new GeoIP2 geolocation API, `libmaxminddb`.
|
|
||||||
* Improved DNSSEC trust anchor configuration using the `trust-anchors`
|
|
||||||
statement, permitting configuration of trust anchors in DS as well as
|
|
||||||
DNSKEY format.
|
|
||||||
* YAML output for `dig`, `mdig`, and `delv`.
|
|
||||||
|
|
||||||
#### BIND 9.14
|
|
||||||
|
|
||||||
BIND 9.14 (a stable branch based on the 9.13 development branch)
|
|
||||||
includes a number of changes from BIND 9.12 and earlier releases.
|
|
||||||
New features include:
|
|
||||||
|
|
||||||
* A new "plugin" mechanism has been added to allow query functionality
|
|
||||||
to be extended using dynamically loadable libraries. The "filter-aaaa"
|
|
||||||
feature has been removed from named and is now implemented as a plugin.
|
|
||||||
* Socket and task code has been refactored to improve performance.
|
|
||||||
* QNAME minimization, as described in RFC 7816, is now supported.
|
|
||||||
* "Root key sentinel" support, enabling validating resolvers to indicate
|
|
||||||
via a special query which trust anchors are configured for the root zone.
|
|
||||||
* Secondary zones can now be configured as "mirror" zones; their contents
|
|
||||||
are transferred in as with traditional slave zones, but are subject to
|
|
||||||
DNSSEC validation and are not treated as authoritative data when
|
|
||||||
answering. This makes it easier to configure a local copy of the root
|
|
||||||
zone as described in RFC 7706.
|
|
||||||
* The "validate-except" option allows configuration of domains below which
|
|
||||||
DNSSEC validation should not be performed.
|
|
||||||
* The default value of "dnssec-validation" is now "auto".
|
|
||||||
* IDNA2008 is now supported when linking with `libidn2`.
|
|
||||||
* "named -V" now outputs the default paths for files used by named
|
|
||||||
and other tools.
|
|
||||||
|
|
||||||
In addition, workarounds that were formerly in place to enable resolution
|
|
||||||
of domains whose authoritative servers did not respond to EDNS queries
|
|
||||||
have been removed. See [https://dnsflagday.net](https://dnsflagday.net)
|
|
||||||
for more details.
|
|
||||||
|
|
||||||
Cryptographic support has been modernized. BIND now uses the
|
|
||||||
best available pseudo-random number generator for the platform on which
|
|
||||||
it's built. Very old versions of OpenSSL are no longer supported.
|
|
||||||
Cryptography is now mandatory: building BIND without DNSSEC is no
|
|
||||||
longer supported.
|
|
||||||
|
|
||||||
Special code to support certain legacy operating systems has also
|
|
||||||
been removed; see the file [PLATFORMS.md](PLATFORMS.md) for details
|
|
||||||
of supported platforms. In addition to OpenSSL, BIND now requires
|
|
||||||
support for IPv6, threads, and standard atomic operations provided
|
|
||||||
by the C compiler.
|
|
||||||
|
|
||||||
#### BIND 9.12
|
|
||||||
|
|
||||||
BIND 9.12 includes a number of changes from BIND 9.11 and earlier releases.
|
|
||||||
New features include:
|
|
||||||
|
|
||||||
* `named` and related libraries have been substantially refactored for
|
|
||||||
improved query performance -- particularly on delegation heavy zones --
|
|
||||||
and for improved readability, maintainability, and testability.
|
|
||||||
* Code implementing the name server query processing logic has been moved
|
|
||||||
into a new `libns` library, for easier testing and use in tools other
|
|
||||||
than `named`.
|
|
||||||
* Cached, validated NSEC and other records can now be used to synthesize
|
|
||||||
NXDOMAIN responses.
|
|
||||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
|
||||||
* Setting `'max-journal-size default'` now limits the size of journal files
|
|
||||||
to twice the size of the zone.
|
|
||||||
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
|
||||||
DNS message.
|
|
||||||
* `dnstap` output files can now be configured to roll automatically when
|
|
||||||
reaching a given size.
|
|
||||||
* Log file timestamps can now also be formatted in ISO 8601 (local) or ISO
|
|
||||||
8601 (UTC) formats.
|
|
||||||
* Logging channels and `dnstap` output files can now be configured to use a
|
|
||||||
timestamp as the suffix when rolling to a new file.
|
|
||||||
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
|
||||||
* Added support for the EDNS Padding and Keepalive options.
|
|
||||||
* 'new-zones-directory' option sets the location where the configuration
|
|
||||||
data for zones added by rndc addzone is stored.
|
|
||||||
* The default key algorithm in `rndc-confgen` is now hmac-sha256.
|
|
||||||
* `filter-aaaa-on-v4` and `filter-aaaa-on-v6` options are now available
|
|
||||||
by default without a configure option.
|
|
||||||
* The obsolete `isc-hmac-fixup` command has been removed.
|
|
||||||
|
|
||||||
#### BIND 9.11
|
|
||||||
|
|
||||||
BIND 9.11.0 includes a number of changes from BIND 9.10 and earlier
|
|
||||||
releases. New features include:
|
|
||||||
|
|
||||||
- Added support for Catalog Zones, a new method for provisioning servers: a
|
|
||||||
list of zones to be served is stored in a DNS zone, along with their
|
|
||||||
configuration parameters. Changes to the catalog zone are propagated to
|
|
||||||
slaves via normal AXFR/IXFR, whereupon the zones that are listed in it
|
|
||||||
are automatically added, deleted or reconfigured.
|
|
||||||
- Added support for "dnstap", a fast and flexible method of capturing and
|
|
||||||
logging DNS traffic.
|
|
||||||
- Added support for "dyndb", a new API for loading zone data from an
|
|
||||||
external database, developed by Red Hat for the FreeIPA project.
|
|
||||||
- "fetchlimit" quotas are now compiled in by default. These are for the
|
|
||||||
use of recursive resolvers that are are under high query load for domains
|
|
||||||
whose authoritative servers are nonresponsive or are experiencing a
|
|
||||||
denial of service attack:
|
|
||||||
- "fetches-per-server" limits the number of simultaneous queries that
|
|
||||||
can be sent to any single authoritative server. The configured value
|
|
||||||
is a starting point; it is automatically adjusted downward if the
|
|
||||||
server is partially or completely non-responsive. The algorithm used
|
|
||||||
to adjust the quota can be configured via the "fetch-quota-params"
|
|
||||||
option.
|
|
||||||
- "fetches-per-zone" limits the number of simultaneous queries that can
|
|
||||||
be sent for names within a single domain. (Note: Unlike
|
|
||||||
"fetches-per-server", this value is not self-tuning.)
|
|
||||||
- New stats counters have been added to count queries spilled due to
|
|
||||||
these quotas.
|
|
||||||
- Added a new "dnssec-keymgr" key mainenance utility, which can generate or
|
|
||||||
update keys as needed to ensure that a zone's keys match a defined DNSSEC
|
|
||||||
policy.
|
|
||||||
- The experimental "SIT" feature in BIND 9.10 has been renamed "COOKIE" and
|
|
||||||
is no longer optional. EDNS COOKIE is a mechanism enabling clients to
|
|
||||||
detect off-path spoofed responses, and servers to detect spoofed-source
|
|
||||||
queries. Clients that identify themselves using COOKIE options are not
|
|
||||||
subject to response rate limiting (RRL) and can receive larger UDP
|
|
||||||
responses.
|
|
||||||
- SERVFAIL responses can now be cached for a limited time (defaulting to 1
|
|
||||||
second, with an upper limit of 30). This can reduce the frequency of
|
|
||||||
retries when a query is persistently failing.
|
|
||||||
- Added an "nsip-wait-recurse" switch to RPZ. This causes NSIP rules to be
|
|
||||||
skipped if a name server IP address isn't in the cache yet; the address
|
|
||||||
will be looked up and the rule will be applied on future queries.
|
|
||||||
- Added a Python RNDC module. This allows multiple commands to sent over a
|
|
||||||
persistent RNDC channel, which saves time.
|
|
||||||
- The "controls" block in named.conf can now grant read-only "rndc" access
|
|
||||||
to specified clients or keys. Read-only clients could, for example, check
|
|
||||||
"rndc status" but could not reconfigure or shut down the server.
|
|
||||||
- "rndc" commands can now return arbitrarily large amounts of text to the
|
|
||||||
caller.
|
|
||||||
- The zone serial number of a dynamically updatable zone can now be set via
|
|
||||||
"rndc signing -serial <number> <zonename>". This allows inline-signing
|
|
||||||
zones to be set to a specific serial number.
|
|
||||||
- The new "rndc nta" command can be used to set a Negative Trust Anchor
|
|
||||||
(NTA), disabling DNSSEC validation for a specific domain; this can be
|
|
||||||
used when responses from a domain are known to be failing validation due
|
|
||||||
to administrative error rather than because of a spoofing attack.
|
|
||||||
Negative trust anchors are strictly temporary; by default they expire
|
|
||||||
after one hour, but can be configured to last up to one week.
|
|
||||||
- "rndc delzone" can now be used on zones that were not originally created
|
|
||||||
by "rndc addzone".
|
|
||||||
- "rndc modzone" reconfigures a single zone, without requiring the entire
|
|
||||||
server to be reconfigured.
|
|
||||||
- "rndc showzone" displays the current configuration of a zone.
|
|
||||||
- "rndc managed-keys" can be used to check the status of RFC 5011 managed
|
|
||||||
trust anchors, or to force trust anchors to be refreshed.
|
|
||||||
- "max-cache-size" can now be set to a percentage of available memory. The
|
|
||||||
default is 90%.
|
|
||||||
- Update forwarding performance has been improved by allowing a single TCP
|
|
||||||
connection to be shared by multiple updates.
|
|
||||||
- The EDNS Client Subnet (ECS) option is now supported for authoritative
|
|
||||||
servers; if a query contains an ECS option then ACLs containing "geoip"
|
|
||||||
or "ecs" elements can match against the the address encoded in the
|
|
||||||
option. This can be used to select a view for a query, so that different
|
|
||||||
answers can be provided depending on the client network.
|
|
||||||
- The EDNS EXPIRE option has been implemented on the client side, allowing
|
|
||||||
a slave server to set the expiration timer correctly when transferring
|
|
||||||
zone data from another slave server.
|
|
||||||
- The key generation and manipulation tools (dnssec-keygen, dnssec-settime,
|
|
||||||
dnssec-importkey, dnssec-keyfromlabel) now take "-Psync" and "-Dsync"
|
|
||||||
options to set the publication and deletion times of CDS and CDNSKEY
|
|
||||||
parent-synchronization records. Both named and dnssec-signzone can now
|
|
||||||
publish and remove these records at the scheduled times.
|
|
||||||
- A new "minimal-any" option reduces the size of UDP responses for query
|
|
||||||
type ANY by returning a single arbitrarily selected RRset instead of all
|
|
||||||
RRsets.
|
|
||||||
- A new "masterfile-style" zone option controls the formatting of text zone
|
|
||||||
files: When set to "full", a zone file is dumped in
|
|
||||||
single-line-per-record format.
|
|
||||||
- "serial-update-method" can now be set to "date". On update, the serial
|
|
||||||
number will be set to the current date in YYYYMMDDNN format.
|
|
||||||
- "dnssec-signzone -N date" sets the serial number to YYYYMMDDNN.
|
|
||||||
- "named -L <filename>" causes named to send log messages to the specified
|
|
||||||
file by default instead of to the system log.
|
|
||||||
- "dig +ttlunits" prints TTL values with time-unit suffixes: w, d, h, m, s
|
|
||||||
for weeks, days, hours, minutes, and seconds.
|
|
||||||
- "dig +unknownformat" prints dig output in RFC 3597 "unknown record"
|
|
||||||
presentation format.
|
|
||||||
- "dig +ednsopt" allows dig to set arbitrary EDNS options on requests.
|
|
||||||
- "dig +ednsflags" allows dig to set yet-to-be-defined EDNS flags on
|
|
||||||
requests.
|
|
||||||
- "mdig" is an alternate version of dig which sends multiple pipelined TCP
|
|
||||||
queries to a server. Instead of waiting for a response after sending a
|
|
||||||
query, it sends all queries immediately and displays responses in the
|
|
||||||
order received.
|
|
||||||
- "serial-query-rate" no longer controls NOTIFY messages. These are
|
|
||||||
separately controlled by "notify-rate" and "startup-notify-rate".
|
|
||||||
- "nsupdate" now performs "check-names" processing by default on records to
|
|
||||||
be added. This can be disabled with "check-names no".
|
|
||||||
- The statistics channel now supports DEFLATE compression, reducing the
|
|
||||||
size of the data sent over the network when querying statistics.
|
|
||||||
- New counters have been added to the statistics channel to track the sizes
|
|
||||||
of incoming queries and outgoing responses in histogram buckets, as
|
|
||||||
specified in RSSAC002.
|
|
||||||
- A new NXDOMAIN redirect method (option "nxdomain-redirect") has been
|
|
||||||
added, allowing redirection to a specified DNS namespace instead of a
|
|
||||||
single redirect zone.
|
|
||||||
- When starting up, named now ensures that no other named process is
|
|
||||||
already running.
|
|
||||||
- Files created by named to store information, including "mkeys" and "nzf"
|
|
||||||
files, are now named after their corresponding views unless the view name
|
|
||||||
contains characters incompatible with use as a filename. Old style
|
|
||||||
filenames (based on the hash of the view name) will still work.
|
|
||||||
|
|
||||||
#### BIND 9.10.0
|
|
||||||
|
|
||||||
BIND 9.10.0 includes a number of changes from BIND 9.9 and earlier
|
|
||||||
releases. New features include:
|
|
||||||
|
|
||||||
- DNS Response-rate limiting (DNS RRL), which blunts the
|
|
||||||
impact of reflection and amplification attacks, is always
|
|
||||||
compiled in and no longer requires a compile-time option
|
|
||||||
to enable it.
|
|
||||||
- An experimental "Source Identity Token" (SIT) EDNS option
|
|
||||||
is now available. Similar to DNS Cookies as invented by
|
|
||||||
Donald Eastlake 3rd, these are designed to enable clients
|
|
||||||
to detect off-path spoofed responses, and to enable servers
|
|
||||||
to detect spoofed-source queries. Servers can be configured
|
|
||||||
to send smaller responses to clients that have not identified
|
|
||||||
themselves using a SIT option, reducing the effectiveness of
|
|
||||||
amplification attacks. RRL processing has also been updated;
|
|
||||||
clients proven to be legitimate via SIT are not subject to
|
|
||||||
rate limiting. Use "configure --enable-sit" to enable this
|
|
||||||
feature in BIND.
|
|
||||||
- A new zone file format, "map", stores zone data in a
|
|
||||||
format that can be mapped directly into memory, allowing
|
|
||||||
significantly faster zone loading.
|
|
||||||
- "delv" (domain entity lookup and validation) is a new tool
|
|
||||||
with dig-like semantics for looking up DNS data and performing
|
|
||||||
internal DNSSEC validation. This allows easy validation in
|
|
||||||
environments where the resolver may not be trustworthy, and
|
|
||||||
assists with troubleshooting of DNSSEC problems. (NOTE:
|
|
||||||
In previous development releases of BIND 9.10, this utility
|
|
||||||
was called "delve". The spelling has been changed to avoid
|
|
||||||
confusion with the "delve" utility included with the Xapian
|
|
||||||
search engine.)
|
|
||||||
- Improved EDNS(0) processing for better resolver performance
|
|
||||||
and reliability over slow or lossy connections.
|
|
||||||
- A new "configure --with-tuning=large" option tunes certain
|
|
||||||
compiled-in constants and default settings to values better
|
|
||||||
suited to large servers with abundant memory. This can
|
|
||||||
improve performance on such servers, but will consume more
|
|
||||||
memory and may degrade performance on smaller systems.
|
|
||||||
- Substantial improvement in response-policy zone (RPZ)
|
|
||||||
performance. Up to 32 response-policy zones can be
|
|
||||||
configured with minimal performance loss.
|
|
||||||
- To improve recursive resolver performance, cache records
|
|
||||||
which are still being requested by clients can now be
|
|
||||||
automatically refreshed from the authoritative server
|
|
||||||
before they expire, reducing or eliminating the time
|
|
||||||
window in which no answer is available in the cache.
|
|
||||||
- New "rpz-client-ip" triggers and drop policies allowing
|
|
||||||
response policies based on the IP address of the client.
|
|
||||||
- ACLs can now be specified based on geographic location
|
|
||||||
using the MaxMind GeoIP databases. Use "configure
|
|
||||||
--with-geoip" to enable.
|
|
||||||
- Zone data can now be shared between views, allowing
|
|
||||||
multiple views to serve the same zones authoritatively
|
|
||||||
without storing multiple copies in memory.
|
|
||||||
- New XML schema (version 3) for the statistics channel
|
|
||||||
includes many new statistics and uses a flattened XML tree
|
|
||||||
for faster parsing. The older schema is now deprecated.
|
|
||||||
- A new stylesheet, based on the Google Charts API, displays
|
|
||||||
XML statistics in charts and graphs on javascript-enabled
|
|
||||||
browsers.
|
|
||||||
- The statistics channel can now provide data in JSON
|
|
||||||
format as well as XML.
|
|
||||||
- New stats counters track TCP and UDP queries received
|
|
||||||
per zone, and EDNS options received in total.
|
|
||||||
- The internal and export versions of the BIND libraries
|
|
||||||
(libisc, libdns, etc) have been unified so that external
|
|
||||||
library clients can use the same libraries as BIND itself.
|
|
||||||
- A new compile-time option, "configure --enable-native-pkcs11",
|
|
||||||
allows BIND 9 cryptography functions to use the PKCS#11 API
|
|
||||||
natively, so that BIND can drive a cryptographic hardware
|
|
||||||
service module (HSM) directly instead of using a modified
|
|
||||||
OpenSSL as an intermediary. (Note: This feature requires an
|
|
||||||
HSM to have a full implementation of the PKCS#11 API; many
|
|
||||||
current HSMs only have partial implementations. The new
|
|
||||||
"pkcs11-tokens" command can be used to check API completeness.
|
|
||||||
Native PKCS#11 is known to work with the Thales nShield HSM
|
|
||||||
and with SoftHSM version 2 from the Open DNSSEC project.)
|
|
||||||
- The new "max-zone-ttl" option enforces maximum TTLs for
|
|
||||||
zones. This can simplify the process of rolling DNSSEC keys
|
|
||||||
by guaranteeing that cached signatures will have expired
|
|
||||||
within the specified amount of time.
|
|
||||||
- "dig +subnet" sends an EDNS CLIENT-SUBNET option when
|
|
||||||
querying.
|
|
||||||
- "dig +expire" sends an EDNS EXPIRE option when querying.
|
|
||||||
When this option is sent with an SOA query to a server
|
|
||||||
that supports it, it will report the expiry time of
|
|
||||||
a slave zone.
|
|
||||||
- New "dnssec-coverage" tool to check DNSSEC key coverage
|
|
||||||
for a zone and report if a lapse in signing coverage has
|
|
||||||
been inadvertently scheduled.
|
|
||||||
- Signing algorithm flexibility and other improvements
|
|
||||||
for the "rndc" control channel.
|
|
||||||
- "named-checkzone" and "named-compilezone" can now read
|
|
||||||
journal files, allowing them to process dynamic zones.
|
|
||||||
- Multiple DLZ databases can now be configured. Individual
|
|
||||||
zones can be configured to be served from a specific DLZ
|
|
||||||
database. DLZ databases now serve zones of type "master"
|
|
||||||
and "redirect".
|
|
||||||
- "rndc zonestatus" reports information about a specified zone.
|
|
||||||
- "named" now listens on IPv6 as well as IPv4 interfaces
|
|
||||||
by default.
|
|
||||||
- "named" now preserves the capitalization of names
|
|
||||||
when responding to queries: for instance, a query for
|
|
||||||
"example.com" may be answered with "example.COM" if the
|
|
||||||
name was configured that way in the zone file. Some
|
|
||||||
clients have a bug causing them to depend on the older
|
|
||||||
behavior, in which the case of the answer always matched
|
|
||||||
the case of the query, rather than the case of the name
|
|
||||||
configured in the DNS. Such clients can now be specified
|
|
||||||
in the new "no-case-compress" ACL; this will restore the
|
|
||||||
older behavior of "named" for those clients only.
|
|
||||||
- new "dnssec-importkey" command allows the use of offline
|
|
||||||
DNSSEC keys with automatic DNSKEY management.
|
|
||||||
- New "named-rrchecker" tool to verify the syntactic
|
|
||||||
correctness of individual resource records.
|
|
||||||
- When re-signing a zone, the new "dnssec-signzone -Q" option
|
|
||||||
drops signatures from keys that are still published but are
|
|
||||||
no longer active.
|
|
||||||
- "named-checkconf -px" will print the contents of configuration
|
|
||||||
files with the shared secrets obscured, making it easier to
|
|
||||||
share configuration (e.g. when submitting a bug report)
|
|
||||||
without revealing private information.
|
|
||||||
- "rndc scan" causes named to re-scan network interfaces for
|
|
||||||
changes in local addresses.
|
|
||||||
- On operating systems with support for routing sockets,
|
|
||||||
network interfaces are re-scanned automatically whenever
|
|
||||||
they change.
|
|
||||||
- "tsig-keygen" is now available as an alternate command
|
|
||||||
name to use for "ddns-confgen".
|
|
||||||
|
|
||||||
#### BIND 9.9.0
|
|
||||||
|
|
||||||
BIND 9.9.0 includes a number of changes from BIND 9.8 and earlier
|
|
||||||
releases. New features include:
|
|
||||||
|
|
||||||
- Inline signing, allowing automatic DNSSEC signing of
|
|
||||||
master zones without modification of the zonefile, or
|
|
||||||
"bump in the wire" signing in slaves.
|
|
||||||
- NXDOMAIN redirection.
|
|
||||||
- New 'rndc flushtree' command clears all data under a given
|
|
||||||
name from the DNS cache.
|
|
||||||
- New 'rndc sync' command dumps pending changes in a dynamic
|
|
||||||
zone to disk without a freeze/thaw cycle.
|
|
||||||
- New 'rndc signing' command displays or clears signing status
|
|
||||||
records in 'auto-dnssec' zones.
|
|
||||||
- NSEC3 parameters for 'auto-dnssec' zones can now be set prior
|
|
||||||
to signing, eliminating the need to initially sign with NSEC.
|
|
||||||
- Startup time improvements on large authoritative servers.
|
|
||||||
- Slave zones are now saved in raw format by default.
|
|
||||||
- Several improvements to response policy zones (RPZ).
|
|
||||||
- Improved hardware scalability by using multiple threads
|
|
||||||
to listen for queries and using finer-grained client locking
|
|
||||||
- The 'also-notify' option now takes the same syntax as
|
|
||||||
'masters', so it can used named masterlists and TSIG keys.
|
|
||||||
- 'dnssec-signzone -D' writes an output file containing only DNSSEC
|
|
||||||
data, which can be included by the primary zone file.
|
|
||||||
- 'dnssec-signzone -R' forces removal of signatures that are
|
|
||||||
not expired but were created by a key which no longer exists.
|
|
||||||
- 'dnssec-signzone -X' allows a separate expiration date to
|
|
||||||
be specified for DNSKEY signatures from other signatures.
|
|
||||||
- New '-L' option to dnssec-keygen, dnssec-settime, and
|
|
||||||
dnssec-keyfromlabel sets the default TTL for the key.
|
|
||||||
- dnssec-dsfromkey now supports reading from standard input,
|
|
||||||
to make it easier to convert DNSKEY to DS.
|
|
||||||
- RFC 1918 reverse zones have been added to the empty-zones
|
|
||||||
table per RFC 6303.
|
|
||||||
- Dynamic updates can now optionally set the zone's SOA serial
|
|
||||||
number to the current UNIX time.
|
|
||||||
- DLZ modules can now retrieve the source IP address of
|
|
||||||
the querying client.
|
|
||||||
- 'request-ixfr' option can now be set at the per-zone level.
|
|
||||||
- 'dig +rrcomments' turns on comments about DNSKEY records,
|
|
||||||
indicating their key ID, algorithm and function
|
|
||||||
- Simplified nsupdate syntax and added readline support
|
|
||||||
|
|
||||||
#### BIND 9.8.0
|
|
||||||
|
|
||||||
BIND 9.8.0 includes a number of changes from BIND 9.7 and earlier
|
|
||||||
releases. New features include:
|
|
||||||
|
|
||||||
- Built-in trust anchor for the root zone, which can be
|
|
||||||
switched on via "dnssec-validation auto;"
|
|
||||||
- Support for DNS64.
|
|
||||||
- Support for response policy zones (RPZ).
|
|
||||||
- Support for writable DLZ zones.
|
|
||||||
- Improved ease of configuration of GSS/TSIG for
|
|
||||||
interoperability with Active Directory
|
|
||||||
- Support for GOST signing algorithm for DNSSEC.
|
|
||||||
- Removed RTT Banding from server selection algorithm.
|
|
||||||
- New "static-stub" zone type.
|
|
||||||
- Allow configuration of resolver timeouts via
|
|
||||||
"resolver-query-timeout" option.
|
|
||||||
- The DLZ "dlopen" driver is now built by default.
|
|
||||||
- Added a new include file with function typedefs
|
|
||||||
for the DLZ "dlopen" driver.
|
|
||||||
- Made "--with-gssapi" default.
|
|
||||||
- More verbose error reporting from DLZ LDAP.
|
|
||||||
|
|
||||||
#### BIND 9.7.0
|
|
||||||
|
|
||||||
BIND 9.7.0 includes a number of changes from BIND 9.6 and earlier
|
|
||||||
releases. Most are intended to simplify DNSSEC configuration.
|
|
||||||
New features include:
|
|
||||||
|
|
||||||
- Fully automatic signing of zones by "named".
|
|
||||||
- Simplified configuration of DNSSEC Lookaside Validation (DLV).
|
|
||||||
- Simplified configuration of Dynamic DNS, using the "ddns-confgen"
|
|
||||||
command line tool or the "local" update-policy option. (As a side
|
|
||||||
effect, this also makes it easier to configure automatic zone
|
|
||||||
re-signing.)
|
|
||||||
- New named option "attach-cache" that allows multiple views to
|
|
||||||
share a single cache.
|
|
||||||
- DNS rebinding attack prevention.
|
|
||||||
- New default values for dnssec-keygen parameters.
|
|
||||||
- Support for RFC 5011 automated trust anchor maintenance
|
|
||||||
- Smart signing: simplified tools for zone signing and key
|
|
||||||
maintenance.
|
|
||||||
- The "statistics-channels" option is now available on Windows.
|
|
||||||
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
|
|
||||||
- On some platforms, named and other binaries can now print out
|
|
||||||
a stack backtrace on assertion failure, to aid in debugging.
|
|
||||||
- A "tools only" installation mode on Windows, which only installs
|
|
||||||
dig, host, nslookup and nsupdate.
|
|
||||||
- Improved PKCS#11 support, including Keyper support and explicit
|
|
||||||
OpenSSL engine selection.
|
|
||||||
|
|
||||||
#### BIND 9.6.0
|
|
||||||
|
|
||||||
- Full NSEC3 support
|
|
||||||
- Automatic zone re-signing
|
|
||||||
- New update-policy methods tcp-self and 6to4-self
|
|
||||||
- The BIND 8 resolver library, libbind, has been removed from the BIND 9
|
|
||||||
distribution and is now available as a separate download.
|
|
||||||
- Change the default pid file location from /var/run to
|
|
||||||
/var/run/{named,lwresd} for improved chroot/setuid support.
|
|
||||||
|
|
||||||
#### BIND 9.5.0
|
|
||||||
|
|
||||||
- GSS-TSIG support (RFC 3645).
|
|
||||||
- DHCID support.
|
|
||||||
- Experimental http server and statistics support for named via xml.
|
|
||||||
- More detailed statistics counters including those supported in BIND 8.
|
|
||||||
- Faster ACL processing.
|
|
||||||
- Use Doxygen to generate internal documentation.
|
|
||||||
- Efficient LRU cache-cleaning mechanism.
|
|
||||||
- NSID support.
|
|
||||||
|
|
||||||
BIND 9.4.0
|
|
||||||
|
|
||||||
- Implemented "additional section caching (or acache)", an internal cache
|
|
||||||
framework for additional section content to improve response performance.
|
|
||||||
Several configuration options were provided to control the behavior.
|
|
||||||
- New notify type 'master-only'. Enable notify for master zones only.
|
|
||||||
- Accept 'notify-source' style syntax for query-source.
|
|
||||||
- rndc now allows addresses to be set in the server clauses.
|
|
||||||
- New option "allow-query-cache". This lets "allow-query" be used to
|
|
||||||
specify the default zone access level rather than having to have every
|
|
||||||
zone override the global value. "allow-query-cache" can be set at both
|
|
||||||
the options and view levels. If "allow-query-cache" is not set then
|
|
||||||
"allow-recursion" is used if set, otherwise "allow-query" is used if set
|
|
||||||
unless "recursion no;" is set in which case "none;" is used, otherwise
|
|
||||||
the default (localhost; localnets;) is used.
|
|
||||||
- rndc: the source address can now be specified.
|
|
||||||
- ixfr-from-differences now takes master and slave in addition to yes and
|
|
||||||
no at the options and view levels.
|
|
||||||
- Allow the journal's name to be changed via named.conf.
|
|
||||||
- 'rndc notify zone [class [view]]' resend the NOTIFY messages for the
|
|
||||||
specified zone.
|
|
||||||
- 'dig +trace' now randomly selects the next servers to try. Report if
|
|
||||||
there is a bad delegation.
|
|
||||||
- Improve check-names error messages.
|
|
||||||
- Make public the function to read a key file, dst_key_read_public().
|
|
||||||
- dig now returns the byte count for axfr/ixfr.
|
|
||||||
- allow-update is now settable at the options / view level.
|
|
||||||
- named-checkconf now checks the logging configuration.
|
|
||||||
- host now can turn on memory debugging flags with '-m'.
|
|
||||||
- Don't send notify messages to self.
|
|
||||||
- Perform sanity checks on NS records which refer to 'in zone' names.
|
|
||||||
- New zone option "notify-delay". Specify a minimum delay between sets of
|
|
||||||
NOTIFY messages.
|
|
||||||
- Extend adjusting TTL warning messages.
|
|
||||||
- Named and named-checkzone can now both check for non-terminal wildcard
|
|
||||||
records.
|
|
||||||
- "rndc freeze/thaw" now freezes/thaws all zones.
|
|
||||||
- named-checkconf now check acls to verify that they only refer to existing
|
|
||||||
acls.
|
|
||||||
- The server syntax has been extended to support a range of servers.
|
|
||||||
- Report differences between hints and real NS rrset and associated address
|
|
||||||
records.
|
|
||||||
- Preserve the case of domain names in rdata during zone transfers.
|
|
||||||
- Restructured the data locking framework using architecture dependent
|
|
||||||
atomic operations (when available), improving response performance on
|
|
||||||
multi-processor machines significantly. x86, x86_64, alpha, powerpc, and
|
|
||||||
mips are currently supported.
|
|
||||||
- UNIX domain controls are now supported.
|
|
||||||
- Add support for additional zone file formats for improving loading
|
|
||||||
performance. The masterfile-format option in named.conf can be used to
|
|
||||||
specify a non-default format. A separate command named-compilezone was
|
|
||||||
provided to generate zone files in the new format. Additionally, the -I
|
|
||||||
and -O options for dnssec-signzone specify the input and output formats.
|
|
||||||
- dnssec-signzone can now randomize signature end times (dnssec-signzone -j
|
|
||||||
jitter).
|
|
||||||
- Add support for CH A record.
|
|
||||||
- Add additional zone data constancy checks. named-checkzone has extended
|
|
||||||
checking of NS, MX and SRV record and the hosts they reference. named
|
|
||||||
has extended post zone load checks. New zone options: check-mx and
|
|
||||||
integrity-check.
|
|
||||||
- edns-udp-size can now be overridden on a per server basis.
|
|
||||||
- dig can now specify the EDNS version when making a query.
|
|
||||||
- Added framework for handling multiple EDNS versions.
|
|
||||||
- Additional memory debugging support to track size and mctx arguments.
|
|
||||||
- Detect duplicates of UDP queries we are recursing on and drop them. New
|
|
||||||
stats category "duplicates".
|
|
||||||
- "USE INTERNAL MALLOC" is now runtime selectable.
|
|
||||||
- The lame cache is now done on a <qname,qclass,qtype> basis as some
|
|
||||||
servers only appear to be lame for certain query types.
|
|
||||||
- Limit the number of recursive clients that can be waiting for a single
|
|
||||||
query (<qname,qtype,qclass>) to resolve. New options clients-per-query
|
|
||||||
and max-clients-per-query.
|
|
||||||
- dig: report the number of extra bytes still left in the packet after
|
|
||||||
processing all the records.
|
|
||||||
- Support for IPSECKEY rdata type.
|
|
||||||
- Raise the UDP receive buffer size to 32k if it is less than 32k.
|
|
||||||
- x86 and x86_64 now have separate atomic locking implementations.
|
|
||||||
- named-checkconf now validates update-policy entries.
|
|
||||||
- Attempt to make the amount of work performed in a iteration self tuning.
|
|
||||||
The covers nodes clean from the cache per iteration, nodes written to
|
|
||||||
disk when rewriting a master file and nodes destroyed per iteration when
|
|
||||||
destroying a zone or a cache.
|
|
||||||
- ISC string copy API.
|
|
||||||
- Automatic empty zone creation for D.F.IP6.ARPA and friends. Note: RFC
|
|
||||||
1918 zones are not yet covered by this but are likely to be in a future
|
|
||||||
release.
|
|
||||||
- New options: empty-server, empty-contact, empty-zones-enable and
|
|
||||||
disable-empty-zone.
|
|
||||||
- dig now has a '-q queryname' and '+showsearch' options.
|
|
||||||
- host/nslookup now continue (default)/fail on SERVFAIL.
|
|
||||||
- dig now warns if 'RA' is not set in the answer when 'RD' was set in the
|
|
||||||
query. host/nslookup skip servers that fail to set 'RA' when 'RD' is set
|
|
||||||
unless a server is explicitly set.
|
|
||||||
- Integrate contributed DLZ code into named.
|
|
||||||
- Integrate contributed IDN code from JPNIC.
|
|
||||||
- libbind: corresponds to that from BIND 8.4.7.
|
|
||||||
|
|
||||||
#### BIND 9.3.0
|
|
||||||
|
|
||||||
- DNSSEC is now DS based (RFC 3658).
|
|
||||||
- DNSSEC lookaside validation.
|
|
||||||
- check-names is now implemented.
|
|
||||||
- rrset-order is more complete.
|
|
||||||
- IPv4/IPv6 transition support, dual-stack-servers.
|
|
||||||
- IXFR deltas can now be generated when loading master files,
|
|
||||||
ixfr-from-differences.
|
|
||||||
- It is now possible to specify the size of a journal, max-journal-size.
|
|
||||||
- It is now possible to define a named set of master servers to be used in
|
|
||||||
masters clause, masters.
|
|
||||||
- The advertised EDNS UDP size can now be set, edns-udp-size.
|
|
||||||
- allow-v6-synthesis has been obsoleted.
|
|
||||||
- Zones containing MD and MF will now be rejected.
|
|
||||||
- dig, nslookup name. now report "Not Implemented" as NOTIMP rather than
|
|
||||||
NOTIMPL. This will have impact on scripts that are looking for NOTIMPL.
|
|
||||||
- libbind: corresponds to that from BIND 8.4.5.
|
|
||||||
|
|
||||||
#### BIND 9.2.0
|
|
||||||
|
|
||||||
- The size of the cache can now be limited using the "max-cache-size"
|
|
||||||
option.
|
|
||||||
- The server can now automatically convert RFC1886-style recursive lookup
|
|
||||||
requests into RFC2874-style lookups, when enabled using the new option
|
|
||||||
"allow-v6-synthesis". This allows stub resolvers that support AAAA
|
|
||||||
records but not A6 record chains or binary labels to perform lookups in
|
|
||||||
domains that make use of these IPv6 DNS features.
|
|
||||||
- Performance has been improved.
|
|
||||||
- The man pages now use the more portable "man" macros rather than the
|
|
||||||
"mandoc" macros, and are installed by "make install".
|
|
||||||
- The named.conf parser has been completely rewritten. It now supports
|
|
||||||
"include" directives in more places such as inside "view" statements, and
|
|
||||||
it no longer has any reserved words.
|
|
||||||
- The "rndc status" command is now implemented.
|
|
||||||
- rndc can now be configured automatically.
|
|
||||||
- A BIND 8 compatible stub resolver library is now included in lib/bind.
|
|
||||||
- OpenSSL has been removed from the distribution. This means that to use
|
|
||||||
DNSSEC, OpenSSL must be installed and the --with-openssl option must be
|
|
||||||
supplied to configure. This does not apply to the use of TSIG, which
|
|
||||||
does not require OpenSSL.
|
|
||||||
- The source distribution now builds on Windows. See
|
|
||||||
win32utils/readme1.txt and win32utils/win32-build.txt for details.
|
|
||||||
- This distribution also includes a new lightweight stub resolver library
|
|
||||||
and associated resolver daemon that fully support forward and reverse
|
|
||||||
lookups of both IPv4 and IPv6 addresses. This library is considered
|
|
||||||
experimental and is not a complete replacement for the BIND 8 resolver
|
|
||||||
library. Applications that use the BIND 8 `res_*` functions to perform
|
|
||||||
DNS lookups or dynamic updates still need to be linked against the BIND 8
|
|
||||||
libraries. For DNS lookups, they can also use the new "getrrsetbyname()"
|
|
||||||
API.
|
|
||||||
- BIND 9.2 is capable of acting as an authoritative server for DNSSEC
|
|
||||||
secured zones. This functionality is believed to be stable and complete
|
|
||||||
except for lacking support for verifications involving wildcard records
|
|
||||||
in secure zones.
|
|
||||||
- When acting as a caching server, BIND 9.2 can be configured to perform
|
|
||||||
DNSSEC secure resolution on behalf of its clients. This part of the
|
|
||||||
DNSSEC implementation is still considered experimental. For detailed
|
|
||||||
information about the state of the DNSSEC implementation, see the file
|
|
||||||
doc/misc/dnssec.
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
dnssec-signzone was designed so that it could sign a zone partially, using
|
||||||
|
only a subset of the DNSSEC keys needed to produce a fully-signed zone.
|
||||||
|
This permits a zone administrator, for example, to sign a zone with one
|
||||||
|
key on one machine, move the resulting partially-signed zone to a second
|
||||||
|
machine, and sign it again with a second key.
|
||||||
|
|
||||||
|
An unfortunate side-effect of this flexibility is that dnssec-signzone
|
||||||
|
does not check to make sure it's signing a zone with any valid keys at
|
||||||
|
all. An attempt to sign a zone without any keys will appear to succeed,
|
||||||
|
producing a "signed" zone with no signatures. There is no warning issued
|
||||||
|
when a zone is not signed.
|
||||||
|
|
||||||
|
This will be corrected in a future release. In the meantime, ISC
|
||||||
|
recommends examining the output of dnssec-signzone to confirm that
|
||||||
|
the zone is properly signed by all keys before using it.
|
||||||
@@ -1,362 +0,0 @@
|
|||||||
Mozilla Public License, version 2.0
|
|
||||||
|
|
||||||
1. Definitions
|
|
||||||
|
|
||||||
1.1. "Contributor"
|
|
||||||
|
|
||||||
means each individual or legal entity that creates, contributes to the
|
|
||||||
creation of, or owns Covered Software.
|
|
||||||
|
|
||||||
1.2. "Contributor Version"
|
|
||||||
|
|
||||||
means the combination of the Contributions of others (if any) used by a
|
|
||||||
Contributor and that particular Contributor's Contribution.
|
|
||||||
|
|
||||||
1.3. "Contribution"
|
|
||||||
|
|
||||||
means Covered Software of a particular Contributor.
|
|
||||||
|
|
||||||
1.4. "Covered Software"
|
|
||||||
|
|
||||||
means Source Code Form to which the initial Contributor has attached the
|
|
||||||
notice in Exhibit A, the Executable Form of such Source Code Form, and
|
|
||||||
Modifications of such Source Code Form, in each case including portions
|
|
||||||
thereof.
|
|
||||||
|
|
||||||
1.5. "Incompatible With Secondary Licenses"
|
|
||||||
means
|
|
||||||
|
|
||||||
a. that the initial Contributor has attached the notice described in
|
|
||||||
Exhibit B to the Covered Software; or
|
|
||||||
|
|
||||||
b. that the Covered Software was made available under the terms of
|
|
||||||
version 1.1 or earlier of the License, but not also under the terms of
|
|
||||||
a Secondary License.
|
|
||||||
|
|
||||||
1.6. "Executable Form"
|
|
||||||
|
|
||||||
means any form of the work other than Source Code Form.
|
|
||||||
|
|
||||||
1.7. "Larger Work"
|
|
||||||
|
|
||||||
means a work that combines Covered Software with other material, in a
|
|
||||||
separate file or files, that is not Covered Software.
|
|
||||||
|
|
||||||
1.8. "License"
|
|
||||||
|
|
||||||
means this document.
|
|
||||||
|
|
||||||
1.9. "Licensable"
|
|
||||||
|
|
||||||
means having the right to grant, to the maximum extent possible, whether
|
|
||||||
at the time of the initial grant or subsequently, any and all of the
|
|
||||||
rights conveyed by this License.
|
|
||||||
|
|
||||||
1.10. "Modifications"
|
|
||||||
|
|
||||||
means any of the following:
|
|
||||||
|
|
||||||
a. any file in Source Code Form that results from an addition to,
|
|
||||||
deletion from, or modification of the contents of Covered Software; or
|
|
||||||
|
|
||||||
b. any new file in Source Code Form that contains any Covered Software.
|
|
||||||
|
|
||||||
1.11. "Patent Claims" of a Contributor
|
|
||||||
|
|
||||||
means any patent claim(s), including without limitation, method,
|
|
||||||
process, and apparatus claims, in any patent Licensable by such
|
|
||||||
Contributor that would be infringed, but for the grant of the License,
|
|
||||||
by the making, using, selling, offering for sale, having made, import,
|
|
||||||
or transfer of either its Contributions or its Contributor Version.
|
|
||||||
|
|
||||||
1.12. "Secondary License"
|
|
||||||
|
|
||||||
means either the GNU General Public License, Version 2.0, the GNU Lesser
|
|
||||||
General Public License, Version 2.1, the GNU Affero General Public
|
|
||||||
License, Version 3.0, or any later versions of those licenses.
|
|
||||||
|
|
||||||
1.13. "Source Code Form"
|
|
||||||
|
|
||||||
means the form of the work preferred for making modifications.
|
|
||||||
|
|
||||||
1.14. "You" (or "Your")
|
|
||||||
|
|
||||||
means an individual or a legal entity exercising rights under this
|
|
||||||
License. For legal entities, "You" includes any entity that controls, is
|
|
||||||
controlled by, or is under common control with You. For purposes of this
|
|
||||||
definition, "control" means (a) the power, direct or indirect, to cause
|
|
||||||
the direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (b) ownership of more than fifty percent (50%) of the
|
|
||||||
outstanding shares or beneficial ownership of such entity.
|
|
||||||
|
|
||||||
|
|
||||||
2. License Grants and Conditions
|
|
||||||
|
|
||||||
2.1. Grants
|
|
||||||
|
|
||||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
|
||||||
non-exclusive license:
|
|
||||||
|
|
||||||
a. under intellectual property rights (other than patent or trademark)
|
|
||||||
Licensable by such Contributor to use, reproduce, make available,
|
|
||||||
modify, display, perform, distribute, and otherwise exploit its
|
|
||||||
Contributions, either on an unmodified basis, with Modifications, or
|
|
||||||
as part of a Larger Work; and
|
|
||||||
|
|
||||||
b. under Patent Claims of such Contributor to make, use, sell, offer for
|
|
||||||
sale, have made, import, and otherwise transfer either its
|
|
||||||
Contributions or its Contributor Version.
|
|
||||||
|
|
||||||
2.2. Effective Date
|
|
||||||
|
|
||||||
The licenses granted in Section 2.1 with respect to any Contribution
|
|
||||||
become effective for each Contribution on the date the Contributor first
|
|
||||||
distributes such Contribution.
|
|
||||||
|
|
||||||
2.3. Limitations on Grant Scope
|
|
||||||
|
|
||||||
The licenses granted in this Section 2 are the only rights granted under
|
|
||||||
this License. No additional rights or licenses will be implied from the
|
|
||||||
distribution or licensing of Covered Software under this License.
|
|
||||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
|
||||||
Contributor:
|
|
||||||
|
|
||||||
a. for any code that a Contributor has removed from Covered Software; or
|
|
||||||
|
|
||||||
b. for infringements caused by: (i) Your and any other third party's
|
|
||||||
modifications of Covered Software, or (ii) the combination of its
|
|
||||||
Contributions with other software (except as part of its Contributor
|
|
||||||
Version); or
|
|
||||||
|
|
||||||
c. under Patent Claims infringed by Covered Software in the absence of
|
|
||||||
its Contributions.
|
|
||||||
|
|
||||||
This License does not grant any rights in the trademarks, service marks,
|
|
||||||
or logos of any Contributor (except as may be necessary to comply with
|
|
||||||
the notice requirements in Section 3.4).
|
|
||||||
|
|
||||||
2.4. Subsequent Licenses
|
|
||||||
|
|
||||||
No Contributor makes additional grants as a result of Your choice to
|
|
||||||
distribute the Covered Software under a subsequent version of this
|
|
||||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
|
||||||
permitted under the terms of Section 3.3).
|
|
||||||
|
|
||||||
2.5. Representation
|
|
||||||
|
|
||||||
Each Contributor represents that the Contributor believes its
|
|
||||||
Contributions are its original creation(s) or it has sufficient rights to
|
|
||||||
grant the rights to its Contributions conveyed by this License.
|
|
||||||
|
|
||||||
2.6. Fair Use
|
|
||||||
|
|
||||||
This License is not intended to limit any rights You have under
|
|
||||||
applicable copyright doctrines of fair use, fair dealing, or other
|
|
||||||
equivalents.
|
|
||||||
|
|
||||||
2.7. Conditions
|
|
||||||
|
|
||||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted in
|
|
||||||
Section 2.1.
|
|
||||||
|
|
||||||
|
|
||||||
3. Responsibilities
|
|
||||||
|
|
||||||
3.1. Distribution of Source Form
|
|
||||||
|
|
||||||
All distribution of Covered Software in Source Code Form, including any
|
|
||||||
Modifications that You create or to which You contribute, must be under
|
|
||||||
the terms of this License. You must inform recipients that the Source
|
|
||||||
Code Form of the Covered Software is governed by the terms of this
|
|
||||||
License, and how they can obtain a copy of this License. You may not
|
|
||||||
attempt to alter or restrict the recipients' rights in the Source Code
|
|
||||||
Form.
|
|
||||||
|
|
||||||
3.2. Distribution of Executable Form
|
|
||||||
|
|
||||||
If You distribute Covered Software in Executable Form then:
|
|
||||||
|
|
||||||
a. such Covered Software must also be made available in Source Code Form,
|
|
||||||
as described in Section 3.1, and You must inform recipients of the
|
|
||||||
Executable Form how they can obtain a copy of such Source Code Form by
|
|
||||||
reasonable means in a timely manner, at a charge no more than the cost
|
|
||||||
of distribution to the recipient; and
|
|
||||||
|
|
||||||
b. You may distribute such Executable Form under the terms of this
|
|
||||||
License, or sublicense it under different terms, provided that the
|
|
||||||
license for the Executable Form does not attempt to limit or alter the
|
|
||||||
recipients' rights in the Source Code Form under this License.
|
|
||||||
|
|
||||||
3.3. Distribution of a Larger Work
|
|
||||||
|
|
||||||
You may create and distribute a Larger Work under terms of Your choice,
|
|
||||||
provided that You also comply with the requirements of this License for
|
|
||||||
the Covered Software. If the Larger Work is a combination of Covered
|
|
||||||
Software with a work governed by one or more Secondary Licenses, and the
|
|
||||||
Covered Software is not Incompatible With Secondary Licenses, this
|
|
||||||
License permits You to additionally distribute such Covered Software
|
|
||||||
under the terms of such Secondary License(s), so that the recipient of
|
|
||||||
the Larger Work may, at their option, further distribute the Covered
|
|
||||||
Software under the terms of either this License or such Secondary
|
|
||||||
License(s).
|
|
||||||
|
|
||||||
3.4. Notices
|
|
||||||
|
|
||||||
You may not remove or alter the substance of any license notices
|
|
||||||
(including copyright notices, patent notices, disclaimers of warranty, or
|
|
||||||
limitations of liability) contained within the Source Code Form of the
|
|
||||||
Covered Software, except that You may alter any license notices to the
|
|
||||||
extent required to remedy known factual inaccuracies.
|
|
||||||
|
|
||||||
3.5. Application of Additional Terms
|
|
||||||
|
|
||||||
You may choose to offer, and to charge a fee for, warranty, support,
|
|
||||||
indemnity or liability obligations to one or more recipients of Covered
|
|
||||||
Software. However, You may do so only on Your own behalf, and not on
|
|
||||||
behalf of any Contributor. You must make it absolutely clear that any
|
|
||||||
such warranty, support, indemnity, or liability obligation is offered by
|
|
||||||
You alone, and You hereby agree to indemnify every Contributor for any
|
|
||||||
liability incurred by such Contributor as a result of warranty, support,
|
|
||||||
indemnity or liability terms You offer. You may include additional
|
|
||||||
disclaimers of warranty and limitations of liability specific to any
|
|
||||||
jurisdiction.
|
|
||||||
|
|
||||||
4. Inability to Comply Due to Statute or Regulation
|
|
||||||
|
|
||||||
If it is impossible for You to comply with any of the terms of this License
|
|
||||||
with respect to some or all of the Covered Software due to statute,
|
|
||||||
judicial order, or regulation then You must: (a) comply with the terms of
|
|
||||||
this License to the maximum extent possible; and (b) describe the
|
|
||||||
limitations and the code they affect. Such description must be placed in a
|
|
||||||
text file included with all distributions of the Covered Software under
|
|
||||||
this License. Except to the extent prohibited by statute or regulation,
|
|
||||||
such description must be sufficiently detailed for a recipient of ordinary
|
|
||||||
skill to be able to understand it.
|
|
||||||
|
|
||||||
5. Termination
|
|
||||||
|
|
||||||
5.1. The rights granted under this License will terminate automatically if You
|
|
||||||
fail to comply with any of its terms. However, if You become compliant,
|
|
||||||
then the rights granted under this License from a particular Contributor
|
|
||||||
are reinstated (a) provisionally, unless and until such Contributor
|
|
||||||
explicitly and finally terminates Your grants, and (b) on an ongoing
|
|
||||||
basis, if such Contributor fails to notify You of the non-compliance by
|
|
||||||
some reasonable means prior to 60 days after You have come back into
|
|
||||||
compliance. Moreover, Your grants from a particular Contributor are
|
|
||||||
reinstated on an ongoing basis if such Contributor notifies You of the
|
|
||||||
non-compliance by some reasonable means, this is the first time You have
|
|
||||||
received notice of non-compliance with this License from such
|
|
||||||
Contributor, and You become compliant prior to 30 days after Your receipt
|
|
||||||
of the notice.
|
|
||||||
|
|
||||||
5.2. If You initiate litigation against any entity by asserting a patent
|
|
||||||
infringement claim (excluding declaratory judgment actions,
|
|
||||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
|
||||||
directly or indirectly infringes any patent, then the rights granted to
|
|
||||||
You by any and all Contributors for the Covered Software under Section
|
|
||||||
2.1 of this License shall terminate.
|
|
||||||
|
|
||||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all end user
|
|
||||||
license agreements (excluding distributors and resellers) which have been
|
|
||||||
validly granted by You or Your distributors under this License prior to
|
|
||||||
termination shall survive termination.
|
|
||||||
|
|
||||||
6. Disclaimer of Warranty
|
|
||||||
|
|
||||||
Covered Software is provided under this License on an "as is" basis,
|
|
||||||
without warranty of any kind, either expressed, implied, or statutory,
|
|
||||||
including, without limitation, warranties that the Covered Software is free
|
|
||||||
of defects, merchantable, fit for a particular purpose or non-infringing.
|
|
||||||
The entire risk as to the quality and performance of the Covered Software
|
|
||||||
is with You. Should any Covered Software prove defective in any respect,
|
|
||||||
You (not any Contributor) assume the cost of any necessary servicing,
|
|
||||||
repair, or correction. This disclaimer of warranty constitutes an essential
|
|
||||||
part of this License. No use of any Covered Software is authorized under
|
|
||||||
this License except under this disclaimer.
|
|
||||||
|
|
||||||
7. Limitation of Liability
|
|
||||||
|
|
||||||
Under no circumstances and under no legal theory, whether tort (including
|
|
||||||
negligence), contract, or otherwise, shall any Contributor, or anyone who
|
|
||||||
distributes Covered Software as permitted above, be liable to You for any
|
|
||||||
direct, indirect, special, incidental, or consequential damages of any
|
|
||||||
character including, without limitation, damages for lost profits, loss of
|
|
||||||
goodwill, work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses, even if such party shall have been
|
|
||||||
informed of the possibility of such damages. This limitation of liability
|
|
||||||
shall not apply to liability for death or personal injury resulting from
|
|
||||||
such party's negligence to the extent applicable law prohibits such
|
|
||||||
limitation. Some jurisdictions do not allow the exclusion or limitation of
|
|
||||||
incidental or consequential damages, so this exclusion and limitation may
|
|
||||||
not apply to You.
|
|
||||||
|
|
||||||
8. Litigation
|
|
||||||
|
|
||||||
Any litigation relating to this License may be brought only in the courts
|
|
||||||
of a jurisdiction where the defendant maintains its principal place of
|
|
||||||
business and such litigation shall be governed by laws of that
|
|
||||||
jurisdiction, without reference to its conflict-of-law provisions. Nothing
|
|
||||||
in this Section shall prevent a party's ability to bring cross-claims or
|
|
||||||
counter-claims.
|
|
||||||
|
|
||||||
9. Miscellaneous
|
|
||||||
|
|
||||||
This License represents the complete agreement concerning the subject
|
|
||||||
matter hereof. If any provision of this License is held to be
|
|
||||||
unenforceable, such provision shall be reformed only to the extent
|
|
||||||
necessary to make it enforceable. Any law or regulation which provides that
|
|
||||||
the language of a contract shall be construed against the drafter shall not
|
|
||||||
be used to construe this License against a Contributor.
|
|
||||||
|
|
||||||
|
|
||||||
10. Versions of the License
|
|
||||||
|
|
||||||
10.1. New Versions
|
|
||||||
|
|
||||||
Mozilla Foundation is the license steward. Except as provided in Section
|
|
||||||
10.3, no one other than the license steward has the right to modify or
|
|
||||||
publish new versions of this License. Each version will be given a
|
|
||||||
distinguishing version number.
|
|
||||||
|
|
||||||
10.2. Effect of New Versions
|
|
||||||
|
|
||||||
You may distribute the Covered Software under the terms of the version
|
|
||||||
of the License under which You originally received the Covered Software,
|
|
||||||
or under the terms of any subsequent version published by the license
|
|
||||||
steward.
|
|
||||||
|
|
||||||
10.3. Modified Versions
|
|
||||||
|
|
||||||
If you create software not governed by this License, and you want to
|
|
||||||
create a new license for such software, you may create and use a
|
|
||||||
modified version of this License if you rename the license and remove
|
|
||||||
any references to the name of the license steward (except to note that
|
|
||||||
such modified license differs from this License).
|
|
||||||
|
|
||||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
|
||||||
Licenses If You choose to distribute Source Code Form that is
|
|
||||||
Incompatible With Secondary Licenses under the terms of this version of
|
|
||||||
the License, the notice described in Exhibit B of this License must be
|
|
||||||
attached.
|
|
||||||
|
|
||||||
Exhibit A - Source Code Form License Notice
|
|
||||||
|
|
||||||
This Source Code Form is subject to the
|
|
||||||
terms of the Mozilla Public License, v.
|
|
||||||
2.0. If a copy of the MPL was not
|
|
||||||
distributed with this file, You can
|
|
||||||
obtain one at
|
|
||||||
http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
If it is not possible or desirable to put the notice in a particular file,
|
|
||||||
then You may include the notice in a location (such as a LICENSE file in a
|
|
||||||
relevant directory) where a recipient would be likely to look for such a
|
|
||||||
notice.
|
|
||||||
|
|
||||||
You may add additional accurate notices of copyright ownership.
|
|
||||||
|
|
||||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
|
||||||
|
|
||||||
This Source Code Form is "Incompatible
|
|
||||||
With Secondary Licenses", as defined by
|
|
||||||
the Mozilla Public License, v. 2.0.
|
|
||||||
-25
@@ -1,25 +0,0 @@
|
|||||||
include $(top_srcdir)/Makefile.top
|
|
||||||
|
|
||||||
SUBDIRS = . lib doc bin fuzz
|
|
||||||
|
|
||||||
BUILT_SOURCES = bind.keys.h
|
|
||||||
CLEANFILES = bind.keys.h
|
|
||||||
|
|
||||||
bind.keys.h: bind.keys Makefile
|
|
||||||
${PERL} ${top_srcdir}/util/bindkeys.pl ${top_srcdir}/bind.keys > $@
|
|
||||||
|
|
||||||
dist_sysconf_DATA = bind.keys
|
|
||||||
|
|
||||||
.PHONY: doc
|
|
||||||
|
|
||||||
EXTRA_DIST = \
|
|
||||||
util/bindkeys.pl \
|
|
||||||
contrib \
|
|
||||||
CHANGES \
|
|
||||||
COPYRIGHT \
|
|
||||||
LICENSE \
|
|
||||||
*.md
|
|
||||||
|
|
||||||
dist-hook:
|
|
||||||
find $(distdir) -type f -name .gitignore -delete
|
|
||||||
git rev-parse --short HEAD | cut -b1-7 > $(distdir)/srcid
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
SPHINX_V = $(SPHINX_V_@AM_V@)
|
|
||||||
SPHINX_V_ = $(SPHINX_V_@AM_DEFAULT_V@)
|
|
||||||
SPHINX_V_0 = -q
|
|
||||||
SPHINX_V_1 = -n
|
|
||||||
|
|
||||||
AM_V_SPHINX = $(AM_V_SPHINX_@AM_V@)
|
|
||||||
AM_V_SPHINX_ = $(AM_V_SPHINX_@AM_DEFAULT_V@)
|
|
||||||
AM_V_SPHINX_0 = @echo " SPHINX $@";
|
|
||||||
|
|
||||||
SPHINXBUILDDIR = $(builddir)/_build
|
|
||||||
|
|
||||||
common_SPHINXOPTS = \
|
|
||||||
-W \
|
|
||||||
-c $(srcdir) \
|
|
||||||
-a \
|
|
||||||
$(SPHINX_V)
|
|
||||||
|
|
||||||
ALLSPHINXOPTS = \
|
|
||||||
$(common_SPHINXOPTS) \
|
|
||||||
-D version="$(PACKAGE_VERSION)" \
|
|
||||||
-D today="$(RELEASE_DATE)" \
|
|
||||||
-D release="$(PACKAGE_VERSION)" \
|
|
||||||
$(SPHINXOPTS) \
|
|
||||||
$(srcdir)
|
|
||||||
|
|
||||||
man_SPHINXOPTS = \
|
|
||||||
$(common_SPHINXOPTS) \
|
|
||||||
-D version="@""PACKAGE_VERSION@"\
|
|
||||||
-D today="@""RELEASE_DATE@" \
|
|
||||||
-D release="@""PACKAGE_VERSION@"\
|
|
||||||
$(SPHINXOPTS) \
|
|
||||||
$(srcdir)
|
|
||||||
|
|
||||||
AM_V_SED = $(AM_V_SED_@AM_V@)
|
|
||||||
AM_V_SED_ = $(AM_V_SED_@AM_DEFAULT_V@)
|
|
||||||
AM_V_SED_0 = @echo " SED $@";
|
|
||||||
|
|
||||||
AM_V_CFG_TEST = $(AM_V_CFG_TEST_@AM_V@)
|
|
||||||
AM_V_CFG_TEST_ = $(AM_V_CFG_TEST_@AM_DEFAULT_V@)
|
|
||||||
AM_V_CFG_TEST_0 = @echo " CFG_GEN $@";
|
|
||||||
|
|
||||||
AM_V_RST_OPTIONS = $(AM_V_CFG_TEST_@AM_V@)
|
|
||||||
AM_V_RST_OPTIONS_ = $(AM_V_RST_OPTIONS_@AM_DEFAULT_V@)
|
|
||||||
AM_V_RST_OPTIONS_0 = @echo " RST_OPTIONS $@";
|
|
||||||
|
|
||||||
AM_V_RST_ZONEOPT = $(AM_V_CFG_TEST_@AM_V@)
|
|
||||||
AM_V_RST_ZONEOPT_ = $(AM_V_RST_ZONEOPT_@AM_DEFAULT_V@)
|
|
||||||
AM_V_RST_ZONEOPT_0 = @echo " RST_ZONEOPT $@";
|
|
||||||
|
|
||||||
AM_V_RST_GRAMMARS = $(AM_V_CFG_TEST_@AM_V@)
|
|
||||||
AM_V_RST_GRAMMARS_ = $(AM_V_RST_GRAMMARS_@AM_DEFAULT_V@)
|
|
||||||
AM_V_RST_GRAMMARS_0 = @echo " RST_GRAMMARS $@";
|
|
||||||
+74
@@ -0,0 +1,74 @@
|
|||||||
|
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
# Copyright (C) 1998-2002 Internet Software Consortium.
|
||||||
|
#
|
||||||
|
# Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
# purpose with or without fee is hereby granted, provided that the above
|
||||||
|
# copyright notice and this permission notice appear in all copies.
|
||||||
|
#
|
||||||
|
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
# PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
# $Id: Makefile.in,v 1.52.48.2 2009/02/20 23:47:23 tbox Exp $
|
||||||
|
|
||||||
|
srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
@BIND9_VERSION@
|
||||||
|
|
||||||
|
SUBDIRS = make lib bin doc
|
||||||
|
TARGETS =
|
||||||
|
|
||||||
|
MANPAGES = isc-config.sh.1
|
||||||
|
|
||||||
|
HTMLPAGES = isc-config.sh.html
|
||||||
|
|
||||||
|
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
distclean::
|
||||||
|
rm -f config.cache config.h config.log config.status TAGS
|
||||||
|
rm -f libtool isc-config.sh configure.lineno
|
||||||
|
rm -f util/conf.sh docutil/docbook2man-wrapper.sh
|
||||||
|
|
||||||
|
# XXX we should clean libtool stuff too. Only do this after we add rules
|
||||||
|
# to make it.
|
||||||
|
maintainer-clean::
|
||||||
|
rm -f configure
|
||||||
|
|
||||||
|
docclean manclean maintainer-clean::
|
||||||
|
rm -f ${MANOBJS}
|
||||||
|
|
||||||
|
doc man:: ${MANOBJS}
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${bindir} \
|
||||||
|
${DESTDIR}${localstatedir}/run ${DESTDIR}${sysconfdir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
install:: isc-config.sh installdirs
|
||||||
|
${INSTALL_SCRIPT} isc-config.sh ${DESTDIR}${bindir}
|
||||||
|
${INSTALL_DATA} ${srcdir}/isc-config.sh.1 ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
tags:
|
||||||
|
rm -f TAGS
|
||||||
|
find lib bin -name "*.[ch]" -print | @ETAGS@ -
|
||||||
|
|
||||||
|
check: test
|
||||||
|
|
||||||
|
test:
|
||||||
|
(cd bin/tests && ${MAKE} ${MAKEDEFS} test)
|
||||||
|
|
||||||
|
FAQ: FAQ.xml
|
||||||
|
${XSLTPROC} doc/xsl/isc-docbook-text.xsl FAQ.xml | \
|
||||||
|
LC_ALL=C ${W3M} -T text/html -dump -cols 72 >$@.tmp
|
||||||
|
mv $@.tmp $@
|
||||||
|
|
||||||
|
clean::
|
||||||
|
rm -f FAQ.tmp
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
# Hey Emacs, this is -*- makefile-automake -*- file!
|
|
||||||
# vim: filetype=automake
|
|
||||||
|
|
||||||
AM_CPPFLAGS += \
|
|
||||||
$(CMOCKA_CFLAGS) \
|
|
||||||
-DNAMED_PLUGINDIR=\"$(libdir)/named\" \
|
|
||||||
-DSKIPPED_TEST_EXIT_CODE=77 \
|
|
||||||
-DTESTS_DIR=\"$(abs_srcdir)\"
|
|
||||||
|
|
||||||
LDADD = \
|
|
||||||
$(CMOCKA_LIBS)
|
|
||||||
@@ -1,65 +0,0 @@
|
|||||||
# Hey Emacs, this is -*- makefile-automake -*- file!
|
|
||||||
# vim: filetype=automake
|
|
||||||
|
|
||||||
ACLOCAL_AMFLAGS = -I $(top_srcdir)/m4
|
|
||||||
|
|
||||||
AM_CFLAGS = \
|
|
||||||
$(STD_CFLAGS)
|
|
||||||
|
|
||||||
AM_CPPFLAGS = \
|
|
||||||
$(STD_CPPFLAGS) \
|
|
||||||
-include $(top_builddir)/config.h \
|
|
||||||
-I$(srcdir)/include
|
|
||||||
|
|
||||||
AM_LDFLAGS =
|
|
||||||
|
|
||||||
if HOST_MACOS
|
|
||||||
AM_LDFLAGS += \
|
|
||||||
-Wl,-flat_namespace
|
|
||||||
endif HOST_MACOS
|
|
||||||
|
|
||||||
LIBISC_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/include \
|
|
||||||
-I$(top_srcdir)/lib/isc/unix/include \
|
|
||||||
-I$(top_srcdir)/lib/isc/pthreads/include \
|
|
||||||
-I$(top_srcdir)/lib/isc/include \
|
|
||||||
-I$(top_builddir)/lib/isc/include
|
|
||||||
|
|
||||||
LIBISC_LIBS = $(top_builddir)/lib/isc/libisc.la
|
|
||||||
|
|
||||||
LIBDNS_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/dns/include \
|
|
||||||
-I$(top_builddir)/lib/dns/include
|
|
||||||
|
|
||||||
LIBDNS_LIBS = \
|
|
||||||
$(top_builddir)/lib/dns/libdns.la
|
|
||||||
|
|
||||||
LIBNS_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/ns/include
|
|
||||||
|
|
||||||
LIBNS_LIBS = \
|
|
||||||
$(top_builddir)/lib/ns/libns.la
|
|
||||||
|
|
||||||
LIBIRS_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/irs/include
|
|
||||||
|
|
||||||
LIBIRS_LIBS = \
|
|
||||||
$(top_builddir)/lib/irs/libirs.la
|
|
||||||
|
|
||||||
LIBISCCFG_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/isccfg/include
|
|
||||||
|
|
||||||
LIBISCCFG_LIBS = \
|
|
||||||
$(top_builddir)/lib/isccfg/libisccfg.la
|
|
||||||
|
|
||||||
LIBISCCC_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/isccc/include/
|
|
||||||
|
|
||||||
LIBISCCC_LIBS = \
|
|
||||||
$(top_builddir)/lib/isccc/libisccc.la
|
|
||||||
|
|
||||||
LIBBIND9_CFLAGS = \
|
|
||||||
-I$(top_srcdir)/lib/bind9/include
|
|
||||||
|
|
||||||
LIBBIND9_LIBS = \
|
|
||||||
$(top_builddir)/lib/bind9/libbind9.la
|
|
||||||
+128
@@ -0,0 +1,128 @@
|
|||||||
|
|
||||||
|
DNSSEC and UPDATE
|
||||||
|
|
||||||
|
Converting from insecure to secure
|
||||||
|
|
||||||
|
As of BIND 9.6.0 it is possible to move a zone between being insecure
|
||||||
|
to secure and back again. A secure zone can be using NSEC or NSEC3.
|
||||||
|
|
||||||
|
To move a zone from insecure to secure you need to configure named
|
||||||
|
so that it can see the K* files which contain the public and private
|
||||||
|
parts of the keys that will be used to sign the zone. These files
|
||||||
|
will have been generated by dnssec-keygen. You can do this by
|
||||||
|
placing them in the key-directory as specified in named.conf.
|
||||||
|
|
||||||
|
zone example.net {
|
||||||
|
type master;
|
||||||
|
allow-update { .... };
|
||||||
|
file "dynamic/example.net/example.net";
|
||||||
|
key-directory "dynamic/example.net";
|
||||||
|
};
|
||||||
|
|
||||||
|
Assuming one KSK and one ZSK DNSKEY key have been generated. Then
|
||||||
|
this will cause the zone to be signed with the ZSK and the DNSKEY
|
||||||
|
RRset to be signed with the KSK DNSKEY. A NSEC chain will also be
|
||||||
|
generated as part of the initial signing process.
|
||||||
|
|
||||||
|
% nsupdate
|
||||||
|
> ttl 3600
|
||||||
|
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
|
||||||
|
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
|
||||||
|
> send
|
||||||
|
|
||||||
|
While the update request will complete almost immediately the zone
|
||||||
|
will not be completely signed until named has had time to walk the
|
||||||
|
zone and generate the NSEC and RRSIG records. Initially the NSEC
|
||||||
|
record at the zone apex will have the OPT bit set. When the NSEC
|
||||||
|
chain is complete the OPT bit will be cleared. Additionally when
|
||||||
|
the zone is fully signed the private type (default TYPE65534) records
|
||||||
|
will have a non zero value for the final octet.
|
||||||
|
|
||||||
|
The private type record has 5 octets.
|
||||||
|
algorithm (octet 1)
|
||||||
|
key id in network order (octet 2 and 3)
|
||||||
|
removal flag (octet 4)
|
||||||
|
complete flag (octet 5)
|
||||||
|
|
||||||
|
If you wish to go straight to a secure zone using NSEC3 you should
|
||||||
|
also add a NSEC3PARAM record to the update request with the flags
|
||||||
|
field set to indicate whether the NSEC3 chain will have the OPTOUT
|
||||||
|
bit set or not.
|
||||||
|
|
||||||
|
% nsupdate
|
||||||
|
> ttl 3600
|
||||||
|
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
|
||||||
|
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
|
||||||
|
> update add example.net NSEC3PARAM 1 1 100 1234567890
|
||||||
|
> send
|
||||||
|
|
||||||
|
Again the update request will complete almost immediately however the
|
||||||
|
NSEC3PARAM record will have additional flag bits set indicating that the
|
||||||
|
NSEC3 chain is under construction. When the NSEC3 chain is complete the
|
||||||
|
flags field will be set to zero.
|
||||||
|
|
||||||
|
While the initial signing and NSEC/NSEC3 chain generation is happening
|
||||||
|
other updates are possible.
|
||||||
|
|
||||||
|
DNSKEY roll overs via UPDATE
|
||||||
|
|
||||||
|
It is possible to perform key rollovers via update. You need to
|
||||||
|
add the K* files for the new keys so that named can find them. You
|
||||||
|
can then add the new DNSKEY RRs via update. Named will then cause
|
||||||
|
the zone to be signed with the new keys. When the signing is
|
||||||
|
complete the private type records will be updated so that the last
|
||||||
|
octet is non zero.
|
||||||
|
|
||||||
|
If this is for a KSK you need to inform the parent and any trust
|
||||||
|
anchor repositories of the new KSK.
|
||||||
|
|
||||||
|
You should then wait for the maximum TLL in the zone before removing the
|
||||||
|
old DNSKEY. If it is a KSK that is being updated you also need to wait
|
||||||
|
for the DS RRset in the parent to be updated and its TTL to expire.
|
||||||
|
This ensures that all clients will be able to verify at least a signature
|
||||||
|
when you remove the old DNSKEY.
|
||||||
|
|
||||||
|
The old DNSKEY can be removed via UPDATE. Take care to specify
|
||||||
|
the correct key. Named will clean out any signatures generated by
|
||||||
|
the old key after the update completes.
|
||||||
|
|
||||||
|
NSEC3PARAM rollovers via UPDATE.
|
||||||
|
|
||||||
|
Add the new NSEC3PARAM record via update. When the new NSEC3 chain
|
||||||
|
has been generated the NSEC3PARAM flag field will be zero. At this
|
||||||
|
point you can remove the old NSEC3PARAM record. The old chain will
|
||||||
|
be removed after the update request completes.
|
||||||
|
|
||||||
|
Converting from NSEC to NSEC3
|
||||||
|
|
||||||
|
To do this you just need to add a NSEC3PARAM record. When the
|
||||||
|
conversion is complete the NSEC chain will have been removed and
|
||||||
|
the NSEC3PARAM record will have a zero flag field. The NSEC3 chain
|
||||||
|
will be generated before the NSEC chain is destroyed.
|
||||||
|
|
||||||
|
Converting from NSEC3 to NSEC
|
||||||
|
|
||||||
|
To do this remove all NSEC3PARAM records with a zero flag field. The
|
||||||
|
NSEC chain will be generated before the NSEC3 chain is removed.
|
||||||
|
|
||||||
|
Converting from secure to insecure
|
||||||
|
|
||||||
|
To do this remove all the DNSKEY records. Any NSEC or NSEC3 chains
|
||||||
|
will be removed as well as associated NSEC3PARAM records. This will
|
||||||
|
take place after the update requests completes.
|
||||||
|
|
||||||
|
Periodic re-signing.
|
||||||
|
|
||||||
|
Named will periodically re-sign RRsets which have not been re-signed
|
||||||
|
as a result of some update action. The signature lifetimes will
|
||||||
|
be adjusted so as to spread the re-sign load over time rather than
|
||||||
|
all at once.
|
||||||
|
|
||||||
|
NSEC3 and OPTOUT
|
||||||
|
|
||||||
|
Named only supports creating new NSEC3 chains where all the NSEC3
|
||||||
|
records in the zone have the same OPTOUT state. Named supports
|
||||||
|
UPDATES to zones where the NSEC3 records in the chain have mixed
|
||||||
|
OPTOUT state. Named does not support changing the OPTOUT state of
|
||||||
|
an individual NSEC3 record, the entire chain needs to be changed if
|
||||||
|
the OPTOUT state of an individual NSEC3 needs to be changed.
|
||||||
-26
@@ -1,26 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
Setting the `CPPFLAGS` environment variable before running `configure`
|
|
||||||
can be used to enable certain compile-time options that are not
|
|
||||||
explicitly defined in `configure`.
|
|
||||||
|
|
||||||
Some of these settings are:
|
|
||||||
|
|
||||||
| Setting | Description |
|
|
||||||
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
|
|
||||||
| `-DCHECK_LOCAL=0` | Don't check out-of-zone addresses in `named-checkzone` |
|
|
||||||
| `-DCHECK_SIBLING=0` | Don't check sibling glue in `named-checkzone` |
|
|
||||||
| `-DISC_FACILITY=LOG_LOCAL0` | Change the default syslog facility for `named` |
|
|
||||||
| `-DISC_HEAP_CHECK` | Test heap consistency after every heap operation; used when debugging |
|
|
||||||
| `-DISC_MEM_DEFAULTFILL=1` | Overwrite memory with tag values when allocating or freeing it; this impairs performance but makes debugging of memory problems easier |
|
|
||||||
| `-DISC_MEM_TRACKLINES=0` | Don't track memory allocations by file and line number; this improves performance but makes debugging more difficult |
|
|
||||||
| `-DNAMED_RUN_PID_DIR=0` | Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/` |
|
|
||||||
| `-DNS_CLIENT_DROPPORT=0` | Disable dropping queries from particular well-known ports |
|
|
||||||
-105
@@ -1,105 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
## Supported platforms
|
|
||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
|
||||||
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
|
||||||
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
|
|
||||||
the OpenSSL cryptography library, and the `nghttp2` HTTP/2 library.
|
|
||||||
|
|
||||||
The following C11 features are used in BIND 9:
|
|
||||||
|
|
||||||
* Atomic operations support from the compiler is needed, either in the form of
|
|
||||||
builtin operations, C11 atomics, or the `Interlocked` family of functions on
|
|
||||||
Windows.
|
|
||||||
|
|
||||||
* Thread Local Storage support from the compiler is needed, either in the form
|
|
||||||
of C11 `_Thread_local`/`thread_local`, the `__thread` GCC extension, or
|
|
||||||
the `__declspec(thread)` MSVC extension on Windows.
|
|
||||||
|
|
||||||
BIND 9.17 requires a fairly recent version of `libuv` (at least 1.x). For
|
|
||||||
some of the older systems listed below, you will have to install an updated
|
|
||||||
`libuv` package from sources such as EPEL, PPA, or other native sources for
|
|
||||||
updated packages. The other option is to build and install `libuv` from
|
|
||||||
source.
|
|
||||||
|
|
||||||
Certain optional BIND features have additional library dependencies.
|
|
||||||
These include `libxml2` and `libjson-c` for statistics, `libmaxminddb` for
|
|
||||||
geolocation, `libfstrm` and `libprotobuf-c` for DNSTAP, and `libidn2` for
|
|
||||||
internationalized domain name conversion.
|
|
||||||
|
|
||||||
ISC regularly tests BIND on many operating systems and architectures, but
|
|
||||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
|
||||||
offer support on a "best effort" basis for some.
|
|
||||||
|
|
||||||
### Regularly tested platforms
|
|
||||||
|
|
||||||
As of Nov 2020, BIND 9.17 is fully supported and regularly tested on the
|
|
||||||
following systems:
|
|
||||||
|
|
||||||
* Debian 9, 10
|
|
||||||
* Ubuntu LTS 18.04, 20.04
|
|
||||||
* Fedora 34
|
|
||||||
* Red Hat Enterprise Linux / CentOS 7, 8
|
|
||||||
* FreeBSD 11.4, 12.2, 13.0
|
|
||||||
* OpenBSD 6.9
|
|
||||||
* Alpine Linux 3.13
|
|
||||||
|
|
||||||
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
|
||||||
|
|
||||||
### Best effort
|
|
||||||
|
|
||||||
The following are platforms on which BIND is known to build and run.
|
|
||||||
ISC makes every effort to fix bugs on these platforms, but may be unable to
|
|
||||||
do so quickly due to lack of hardware, less familiarity on the part of
|
|
||||||
engineering staff, and other constraints. With the exception of Windows
|
|
||||||
Server 2016, none of these are tested regularly by ISC.
|
|
||||||
|
|
||||||
* Windows Server 2012 R2, 2016 / x64
|
|
||||||
* Windows 10 / x64
|
|
||||||
* macOS 10.12+
|
|
||||||
* Solaris 11
|
|
||||||
* NetBSD
|
|
||||||
* Other Linux distributions still supported by their vendors, such as:
|
|
||||||
* Ubuntu 20.10+
|
|
||||||
* Gentoo
|
|
||||||
* Arch Linux
|
|
||||||
* OpenWRT/LEDE 17.01+
|
|
||||||
* Other CPU architectures (mips, mipsel, sparc, ...)
|
|
||||||
|
|
||||||
### Community maintained
|
|
||||||
|
|
||||||
These systems may not all have the required dependencies for building BIND
|
|
||||||
easily available, although it will be possible in many cases to compile
|
|
||||||
those directly from source. The community and interested parties may wish
|
|
||||||
to help with maintenance, and we welcome patch contributions, although we
|
|
||||||
cannot guarantee that we will accept them. All contributions will be
|
|
||||||
assessed against the risk of adverse effect on officially supported
|
|
||||||
platforms.
|
|
||||||
|
|
||||||
* Platforms past or close to their respective EOL dates, such as:
|
|
||||||
* Ubuntu 14.04, 16.04 (Ubuntu ESM releases are not supported)
|
|
||||||
* CentOS 6
|
|
||||||
* Debian Jessie
|
|
||||||
* FreeBSD 10.x
|
|
||||||
|
|
||||||
## Unsupported platforms
|
|
||||||
|
|
||||||
These are platforms on which BIND 9.17 is known *not* to build or run:
|
|
||||||
|
|
||||||
* Platforms without at least OpenSSL 1.0.2
|
|
||||||
* Windows 10 / x86
|
|
||||||
* Windows Server 2012 and older
|
|
||||||
* Solaris 10 and older
|
|
||||||
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
|
||||||
* Platforms that don't support atomic operations (via compiler or library)
|
|
||||||
* Linux without NPTL (Native POSIX Thread Library)
|
|
||||||
* Platforms on which `libuv` cannot be compiled
|
|
||||||
@@ -0,0 +1,620 @@
|
|||||||
|
BIND 9
|
||||||
|
|
||||||
|
BIND version 9 is a major rewrite of nearly all aspects of the
|
||||||
|
underlying BIND architecture. Some of the important features of
|
||||||
|
BIND 9 are:
|
||||||
|
|
||||||
|
- DNS Security
|
||||||
|
DNSSEC (signed zones)
|
||||||
|
TSIG (signed DNS requests)
|
||||||
|
|
||||||
|
- IP version 6
|
||||||
|
Answers DNS queries on IPv6 sockets
|
||||||
|
IPv6 resource records (AAAA)
|
||||||
|
Experimental IPv6 Resolver Library
|
||||||
|
|
||||||
|
- DNS Protocol Enhancements
|
||||||
|
IXFR, DDNS, Notify, EDNS0
|
||||||
|
Improved standards conformance
|
||||||
|
|
||||||
|
- Views
|
||||||
|
One server process can provide multiple "views" of
|
||||||
|
the DNS namespace, e.g. an "inside" view to certain
|
||||||
|
clients, and an "outside" view to others.
|
||||||
|
|
||||||
|
- Multiprocessor Support
|
||||||
|
|
||||||
|
- Improved Portability Architecture
|
||||||
|
|
||||||
|
|
||||||
|
BIND version 9 development has been underwritten by the following
|
||||||
|
organizations:
|
||||||
|
|
||||||
|
Sun Microsystems, Inc.
|
||||||
|
Hewlett Packard
|
||||||
|
Compaq Computer Corporation
|
||||||
|
IBM
|
||||||
|
Process Software Corporation
|
||||||
|
Silicon Graphics, Inc.
|
||||||
|
Network Associates, Inc.
|
||||||
|
U.S. Defense Information Systems Agency
|
||||||
|
USENIX Association
|
||||||
|
Stichting NLnet - NLnet Foundation
|
||||||
|
Nominum, Inc.
|
||||||
|
|
||||||
|
BIND 9.6-ESV (Extended Support Version)
|
||||||
|
|
||||||
|
BIND 9.6-ESV will be supported until March 31, 2013, at
|
||||||
|
which time you will need to upgrade to the current release
|
||||||
|
of BIND.
|
||||||
|
|
||||||
|
BIND 9.6.2
|
||||||
|
|
||||||
|
BIND 9.6.2 is a maintenance release, fixing bugs in 9.6.1.
|
||||||
|
It also introduces support for the SHA-2 DNSSEC algorithms,
|
||||||
|
RSASHA256 and RSASHA512.
|
||||||
|
|
||||||
|
Known issues in this release:
|
||||||
|
|
||||||
|
- A validating resolver that has been incorrectly configured with
|
||||||
|
an invalid trust anchor will be unable to resolve names covered
|
||||||
|
by that trust anchor. In all current versions of BIND 9, such a
|
||||||
|
resolver will also generate significant unnecessary DNS traffic
|
||||||
|
while trying to validate. The latter problem will be addressed
|
||||||
|
in future BIND 9 releases. In the meantime, to avoid these
|
||||||
|
problems, exercise caution when configuring "trusted-keys":
|
||||||
|
make sure all keys are correct and current when you add them,
|
||||||
|
and update your configuration in a timely manner when keys
|
||||||
|
roll over.
|
||||||
|
|
||||||
|
BIND 9.6.1
|
||||||
|
|
||||||
|
BIND 9.6.1 is a maintenance release, fixing bugs in 9.6.0.
|
||||||
|
|
||||||
|
BIND 9.6.0
|
||||||
|
|
||||||
|
BIND 9.6.0 includes a number of changes from BIND 9.5 and earlier
|
||||||
|
releases, including:
|
||||||
|
|
||||||
|
Full NSEC3 support
|
||||||
|
|
||||||
|
Automatic zone re-signing
|
||||||
|
|
||||||
|
New update-policy methods tcp-self and 6to4-self
|
||||||
|
|
||||||
|
The BIND 8 resolver library, libbind, has been removed from the
|
||||||
|
BIND 9 distribution and is now available as a separate download.
|
||||||
|
|
||||||
|
Change the default pid file location from /var/run to
|
||||||
|
/var/run/{named,lwresd} for improved chroot/setuid support.
|
||||||
|
|
||||||
|
BIND 9.5.0
|
||||||
|
|
||||||
|
BIND 9.5.0 has a number of new features over 9.4,
|
||||||
|
including:
|
||||||
|
|
||||||
|
GSS-TSIG support (RFC 3645).
|
||||||
|
|
||||||
|
DHCID support.
|
||||||
|
|
||||||
|
Experimental http server and statistics support for named via xml.
|
||||||
|
|
||||||
|
More detailed statistics counters including those supported in BIND 8.
|
||||||
|
|
||||||
|
Faster ACL processing.
|
||||||
|
|
||||||
|
Use Doxygen to generate internal documentation.
|
||||||
|
|
||||||
|
Efficient LRU cache-cleaning mechanism.
|
||||||
|
|
||||||
|
NSID support.
|
||||||
|
|
||||||
|
BIND 9.4.0
|
||||||
|
|
||||||
|
BIND 9.4.0 has a number of new features over 9.3,
|
||||||
|
including:
|
||||||
|
|
||||||
|
Implemented "additional section caching (or acache)", an
|
||||||
|
internal cache framework for additional section content to
|
||||||
|
improve response performance. Several configuration options
|
||||||
|
were provided to control the behavior.
|
||||||
|
|
||||||
|
New notify type 'master-only'. Enable notify for master
|
||||||
|
zones only.
|
||||||
|
|
||||||
|
Accept 'notify-source' style syntax for query-source.
|
||||||
|
|
||||||
|
rndc now allows addresses to be set in the server clauses.
|
||||||
|
|
||||||
|
New option "allow-query-cache". This lets "allow-query"
|
||||||
|
be used to specify the default zone access level rather
|
||||||
|
than having to have every zone override the global value.
|
||||||
|
"allow-query-cache" can be set at both the options and view
|
||||||
|
levels. If "allow-query-cache" is not set then "allow-recursion"
|
||||||
|
is used if set, otherwise "allow-query" is used if set
|
||||||
|
unless "recursion no;" is set in which case "none;" is used,
|
||||||
|
otherwise the default (localhost; localnets;) is used.
|
||||||
|
|
||||||
|
rndc: the source address can now be specified.
|
||||||
|
|
||||||
|
ixfr-from-differences now takes master and slave in addition
|
||||||
|
to yes and no at the options and view levels.
|
||||||
|
|
||||||
|
Allow the journal's name to be changed via named.conf.
|
||||||
|
|
||||||
|
'rndc notify zone [class [view]]' resend the NOTIFY messages
|
||||||
|
for the specified zone.
|
||||||
|
|
||||||
|
'dig +trace' now randomly selects the next servers to try.
|
||||||
|
Report if there is a bad delegation.
|
||||||
|
|
||||||
|
Improve check-names error messages.
|
||||||
|
|
||||||
|
Make public the function to read a key file, dst_key_read_public().
|
||||||
|
|
||||||
|
dig now returns the byte count for axfr/ixfr.
|
||||||
|
|
||||||
|
allow-update is now settable at the options / view level.
|
||||||
|
|
||||||
|
named-checkconf now checks the logging configuration.
|
||||||
|
|
||||||
|
host now can turn on memory debugging flags with '-m'.
|
||||||
|
|
||||||
|
Don't send notify messages to self.
|
||||||
|
|
||||||
|
Perform sanity checks on NS records which refer to 'in zone' names.
|
||||||
|
|
||||||
|
New zone option "notify-delay". Specify a minimum delay
|
||||||
|
between sets of NOTIFY messages.
|
||||||
|
|
||||||
|
Extend adjusting TTL warning messages.
|
||||||
|
|
||||||
|
Named and named-checkzone can now both check for non-terminal
|
||||||
|
wildcard records.
|
||||||
|
|
||||||
|
"rndc freeze/thaw" now freezes/thaws all zones.
|
||||||
|
|
||||||
|
named-checkconf now check acls to verify that they only
|
||||||
|
refer to existing acls.
|
||||||
|
|
||||||
|
The server syntax has been extended to support a range of
|
||||||
|
servers.
|
||||||
|
|
||||||
|
Report differences between hints and real NS rrset and
|
||||||
|
associated address records.
|
||||||
|
|
||||||
|
Preserve the case of domain names in rdata during zone
|
||||||
|
transfers.
|
||||||
|
|
||||||
|
Restructured the data locking framework using architecture
|
||||||
|
dependent atomic operations (when available), improving
|
||||||
|
response performance on multi-processor machines significantly.
|
||||||
|
x86, x86_64, alpha, powerpc, and mips are currently supported.
|
||||||
|
|
||||||
|
UNIX domain controls are now supported.
|
||||||
|
|
||||||
|
Add support for additional zone file formats for improving
|
||||||
|
loading performance. The masterfile-format option in
|
||||||
|
named.conf can be used to specify a non-default format. A
|
||||||
|
separate command named-compilezone was provided to generate
|
||||||
|
zone files in the new format. Additionally, the -I and -O
|
||||||
|
options for dnssec-signzone specify the input and output
|
||||||
|
formats.
|
||||||
|
|
||||||
|
dnssec-signzone can now randomize signature end times
|
||||||
|
(dnssec-signzone -j jitter).
|
||||||
|
|
||||||
|
Add support for CH A record.
|
||||||
|
|
||||||
|
Add additional zone data constancy checks. named-checkzone
|
||||||
|
has extended checking of NS, MX and SRV record and the hosts
|
||||||
|
they reference. named has extended post zone load checks.
|
||||||
|
New zone options: check-mx and integrity-check.
|
||||||
|
|
||||||
|
|
||||||
|
edns-udp-size can now be overridden on a per server basis.
|
||||||
|
|
||||||
|
dig can now specify the EDNS version when making a query.
|
||||||
|
|
||||||
|
Added framework for handling multiple EDNS versions.
|
||||||
|
|
||||||
|
Additional memory debugging support to track size and mctx
|
||||||
|
arguments.
|
||||||
|
|
||||||
|
Detect duplicates of UDP queries we are recursing on and
|
||||||
|
drop them. New stats category "duplicates".
|
||||||
|
|
||||||
|
"USE INTERNAL MALLOC" is now runtime selectable.
|
||||||
|
|
||||||
|
The lame cache is now done on a <qname,qclass,qtype> basis
|
||||||
|
as some servers only appear to be lame for certain query
|
||||||
|
types.
|
||||||
|
|
||||||
|
Limit the number of recursive clients that can be waiting
|
||||||
|
for a single query (<qname,qtype,qclass>) to resolve. New
|
||||||
|
options clients-per-query and max-clients-per-query.
|
||||||
|
|
||||||
|
dig: report the number of extra bytes still left in the
|
||||||
|
packet after processing all the records.
|
||||||
|
|
||||||
|
Support for IPSECKEY rdata type.
|
||||||
|
|
||||||
|
Raise the UDP recieve buffer size to 32k if it is less than 32k.
|
||||||
|
|
||||||
|
x86 and x86_64 now have seperate atomic locking implementations.
|
||||||
|
|
||||||
|
named-checkconf now validates update-policy entries.
|
||||||
|
|
||||||
|
Attempt to make the amount of work performed in a iteration
|
||||||
|
self tuning. The covers nodes clean from the cache per
|
||||||
|
iteration, nodes written to disk when rewriting a master
|
||||||
|
file and nodes destroyed per iteration when destroying a
|
||||||
|
zone or a cache.
|
||||||
|
|
||||||
|
ISC string copy API.
|
||||||
|
|
||||||
|
Automatic empty zone creation for D.F.IP6.ARPA and friends.
|
||||||
|
Note: RFC 1918 zones are not yet covered by this but are
|
||||||
|
likely to be in a future release.
|
||||||
|
|
||||||
|
New options: empty-server, empty-contact, empty-zones-enable
|
||||||
|
and disable-empty-zone.
|
||||||
|
|
||||||
|
dig now has a '-q queryname' and '+showsearch' options.
|
||||||
|
|
||||||
|
host/nslookup now continue (default)/fail on SERVFAIL.
|
||||||
|
|
||||||
|
dig now warns if 'RA' is not set in the answer when 'RD'
|
||||||
|
was set in the query. host/nslookup skip servers that fail
|
||||||
|
to set 'RA' when 'RD' is set unless a server is explicitly
|
||||||
|
set.
|
||||||
|
|
||||||
|
Integrate contibuted DLZ code into named.
|
||||||
|
|
||||||
|
Integrate contibuted IDN code from JPNIC.
|
||||||
|
|
||||||
|
libbind: corresponds to that from BIND 8.4.7.
|
||||||
|
|
||||||
|
BIND 9.3.0
|
||||||
|
|
||||||
|
BIND 9.3.0 has a number of new features over 9.2,
|
||||||
|
including:
|
||||||
|
|
||||||
|
DNSSEC is now DS based (RFC 3658).
|
||||||
|
See also RFC 3845, doc/draft/draft-ietf-dnsext-dnssec-*.
|
||||||
|
|
||||||
|
DNSSEC lookaside validation.
|
||||||
|
|
||||||
|
check-names is now implemented.
|
||||||
|
rrset-order in more complete.
|
||||||
|
|
||||||
|
IPv4/IPv6 transition support, dual-stack-servers.
|
||||||
|
|
||||||
|
IXFR deltas can now be generated when loading master files,
|
||||||
|
ixfr-from-differences.
|
||||||
|
|
||||||
|
It is now possible to specify the size of a journal, max-journal-size.
|
||||||
|
|
||||||
|
It is now possible to define a named set of master servers to be
|
||||||
|
used in masters clause, masters.
|
||||||
|
|
||||||
|
The advertised EDNS UDP size can now be set, edns-udp-size.
|
||||||
|
|
||||||
|
allow-v6-synthesis has been obsoleted.
|
||||||
|
|
||||||
|
NOTE:
|
||||||
|
* Zones containing MD and MF will now be rejected.
|
||||||
|
* dig, nslookup name. now report "Not Implemented" as
|
||||||
|
NOTIMP rather than NOTIMPL. This will have impact on scripts
|
||||||
|
that are looking for NOTIMPL.
|
||||||
|
|
||||||
|
libbind: corresponds to that from BIND 8.4.5.
|
||||||
|
|
||||||
|
BIND 9.2.0
|
||||||
|
|
||||||
|
BIND 9.2.0 has a number of new features over 9.1,
|
||||||
|
including:
|
||||||
|
|
||||||
|
- The size of the cache can now be limited using the
|
||||||
|
"max-cache-size" option.
|
||||||
|
|
||||||
|
- The server can now automatically convert RFC1886-style
|
||||||
|
recursive lookup requests into RFC2874-style lookups,
|
||||||
|
when enabled using the new option "allow-v6-synthesis".
|
||||||
|
This allows stub resolvers that support AAAA records
|
||||||
|
but not A6 record chains or binary labels to perform
|
||||||
|
lookups in domains that make use of these IPv6 DNS
|
||||||
|
features.
|
||||||
|
|
||||||
|
- Performance has been improved.
|
||||||
|
|
||||||
|
- The man pages now use the more portable "man" macros
|
||||||
|
rather than the "mandoc" macros, and are installed
|
||||||
|
by "make install".
|
||||||
|
|
||||||
|
- The named.conf parser has been completely rewritten.
|
||||||
|
It now supports "include" directives in more
|
||||||
|
places such as inside "view" statements, and it no
|
||||||
|
longer has any reserved words.
|
||||||
|
|
||||||
|
- The "rndc status" command is now implemented.
|
||||||
|
|
||||||
|
- rndc can now be configured automatically.
|
||||||
|
|
||||||
|
- A BIND 8 compatible stub resolver library is now
|
||||||
|
included in lib/bind.
|
||||||
|
|
||||||
|
- OpenSSL has been removed from the distribution. This
|
||||||
|
means that to use DNSSEC, OpenSSL must be installed and
|
||||||
|
the --with-openssl option must be supplied to configure.
|
||||||
|
This does not apply to the use of TSIG, which does not
|
||||||
|
require OpenSSL.
|
||||||
|
|
||||||
|
- The source distribution now builds on Windows.
|
||||||
|
See win32utils/readme1.txt and win32utils/win32-build.txt
|
||||||
|
for details.
|
||||||
|
|
||||||
|
This distribution also includes a new lightweight stub
|
||||||
|
resolver library and associated resolver daemon that fully
|
||||||
|
support forward and reverse lookups of both IPv4 and IPv6
|
||||||
|
addresses. This library is considered experimental and
|
||||||
|
is not a complete replacement for the BIND 8 resolver library.
|
||||||
|
Applications that use the BIND 8 res_* functions to perform
|
||||||
|
DNS lookups or dynamic updates still need to be linked against
|
||||||
|
the BIND 8 libraries. For DNS lookups, they can also use the
|
||||||
|
new "getrrsetbyname()" API.
|
||||||
|
|
||||||
|
BIND 9.2 is capable of acting as an authoritative server
|
||||||
|
for DNSSEC secured zones. This functionality is believed to
|
||||||
|
be stable and complete except for lacking support for
|
||||||
|
verifications involving wildcard records in secure zones.
|
||||||
|
|
||||||
|
When acting as a caching server, BIND 9.2 can be configured
|
||||||
|
to perform DNSSEC secure resolution on behalf of its clients.
|
||||||
|
This part of the DNSSEC implementation is still considered
|
||||||
|
experimental. For detailed information about the state of the
|
||||||
|
DNSSEC implementation, see the file doc/misc/dnssec.
|
||||||
|
|
||||||
|
There are a few known bugs:
|
||||||
|
|
||||||
|
On some systems, IPv6 and IPv4 sockets interact in
|
||||||
|
unexpected ways. For details, see doc/misc/ipv6.
|
||||||
|
To reduce the impact of these problems, the server
|
||||||
|
no longer listens for requests on IPv6 addresses
|
||||||
|
by default. If you need to accept DNS queries over
|
||||||
|
IPv6, you must specify "listen-on-v6 { any; };"
|
||||||
|
in the named.conf options statement.
|
||||||
|
|
||||||
|
FreeBSD prior to 4.2 (and 4.2 if running as non-root)
|
||||||
|
and OpenBSD prior to 2.8 log messages like
|
||||||
|
"fcntl(8, F_SETFL, 4): Inappropriate ioctl for device".
|
||||||
|
This is due to a bug in "/dev/random" and impacts the
|
||||||
|
server's DNSSEC support.
|
||||||
|
|
||||||
|
OS X 10.1.4 (Darwin 5.4), OS X 10.1.5 (Darwin 5.5) and
|
||||||
|
OS X 10.2 (Darwin 6.0) reports errors like
|
||||||
|
"fcntl(3, F_SETFL, 4): Operation not supported by device".
|
||||||
|
This is due to a bug in "/dev/random" and impacts the
|
||||||
|
server's DNSSEC support.
|
||||||
|
|
||||||
|
--with-libtool does not work on AIX.
|
||||||
|
|
||||||
|
A bug in some versions of the Microsoft DNS server can cause zone
|
||||||
|
transfers from a BIND 9 server to a W2K server to fail. For details,
|
||||||
|
see the "Zone Transfers" section in doc/misc/migration.
|
||||||
|
|
||||||
|
For a detailed list of user-visible changes from
|
||||||
|
previous releases, see the CHANGES file.
|
||||||
|
|
||||||
|
|
||||||
|
Building
|
||||||
|
|
||||||
|
BIND 9 currently requires a UNIX system with an ANSI C compiler,
|
||||||
|
basic POSIX support, and a 64 bit integer type.
|
||||||
|
|
||||||
|
We've had successful builds and tests on the following systems:
|
||||||
|
|
||||||
|
COMPAQ Tru64 UNIX 5.1B
|
||||||
|
Fedora Core 6
|
||||||
|
FreeBSD 4.10, 5.2.1, 6.2
|
||||||
|
HP-UX 11.11
|
||||||
|
Mac OS X 10.5
|
||||||
|
NetBSD 3.x and 4.0-beta
|
||||||
|
OpenBSD 3.3 and up
|
||||||
|
Solaris 8, 9, 9 (x86), 10
|
||||||
|
Ubuntu 7.04, 7.10
|
||||||
|
Windows XP/2003/2008
|
||||||
|
|
||||||
|
NOTE: As of BIND 9.5.1, 9.4.3, and 9.3.6, older versions of
|
||||||
|
Windows, including Windows NT and Windows 2000, are no longer
|
||||||
|
supported.
|
||||||
|
|
||||||
|
We have recent reports from the user community that a supported
|
||||||
|
version of BIND will build and run on the following systems:
|
||||||
|
|
||||||
|
AIX 4.3, 5L
|
||||||
|
CentOS 4, 4.5, 5
|
||||||
|
Darwin 9.0.0d1/ARM
|
||||||
|
Debian 4
|
||||||
|
Fedora Core 5, 7
|
||||||
|
FreeBSD 6.1
|
||||||
|
HP-UX 11.23 PA
|
||||||
|
MacOS X 10.4, 10.5
|
||||||
|
Red Hat Enterprise Linux 4, 5
|
||||||
|
SCO OpenServer 5.0.6
|
||||||
|
Slackware 9, 10
|
||||||
|
SuSE 9, 10
|
||||||
|
|
||||||
|
To build, just
|
||||||
|
|
||||||
|
./configure
|
||||||
|
make
|
||||||
|
|
||||||
|
Do not use a parallel "make".
|
||||||
|
|
||||||
|
Several environment variables that can be set before running
|
||||||
|
configure will affect compilation:
|
||||||
|
|
||||||
|
CC
|
||||||
|
The C compiler to use. configure tries to figure
|
||||||
|
out the right one for supported systems.
|
||||||
|
|
||||||
|
CFLAGS
|
||||||
|
C compiler flags. Defaults to include -g and/or -O2
|
||||||
|
as supported by the compiler.
|
||||||
|
|
||||||
|
STD_CINCLUDES
|
||||||
|
System header file directories. Can be used to specify
|
||||||
|
where add-on thread or IPv6 support is, for example.
|
||||||
|
Defaults to empty string.
|
||||||
|
|
||||||
|
STD_CDEFINES
|
||||||
|
Any additional preprocessor symbols you want defined.
|
||||||
|
Defaults to empty string.
|
||||||
|
|
||||||
|
Possible settings:
|
||||||
|
Change the default syslog facility of named/lwresd.
|
||||||
|
-DISC_FACILITY=LOG_LOCAL0
|
||||||
|
Enable DNSSEC signature chasing support in dig.
|
||||||
|
-DDIG_SIGCHASE=1 (sets -DDIG_SIGCHASE_TD=1 and
|
||||||
|
-DDIG_SIGCHASE_BU=1)
|
||||||
|
Disable dropping queries from particular well known ports.
|
||||||
|
-DNS_CLIENT_DROPPORT=0
|
||||||
|
Sibling glue checking in named-checkzone is enabled by default.
|
||||||
|
To disable the default check set. -DCHECK_SIBLING=0
|
||||||
|
named-checkzone checks out-of-zone addresses by default.
|
||||||
|
To disable this default set. -DCHECK_LOCAL=0
|
||||||
|
To create the default pid files in ${localstatedir}/run rather
|
||||||
|
than ${localstatedir}/run/{named,lwresd}/ set.
|
||||||
|
-DNS_RUN_PID_DIR=0
|
||||||
|
Enable workaround for Solaris kernel bug about /dev/poll
|
||||||
|
-DISC_SOCKET_USE_POLLWATCH=1
|
||||||
|
The watch timeout is also configurable, e.g.,
|
||||||
|
-DISC_SOCKET_POLLWATCH_TIMEOUT=20
|
||||||
|
|
||||||
|
LDFLAGS
|
||||||
|
Linker flags. Defaults to empty string.
|
||||||
|
|
||||||
|
The following need to be set when cross compiling.
|
||||||
|
|
||||||
|
BUILD_CC
|
||||||
|
The native C compiler.
|
||||||
|
BUILD_CFLAGS (optional)
|
||||||
|
BUILD_CPPFLAGS (optional)
|
||||||
|
Possible Settings:
|
||||||
|
-DNEED_OPTARG=1 (optarg is not declared in <unistd.h>)
|
||||||
|
BUILD_LDFLAGS (optional)
|
||||||
|
BUILD_LIBS (optional)
|
||||||
|
|
||||||
|
To build shared libraries, specify "--with-libtool" on the
|
||||||
|
configure command line.
|
||||||
|
|
||||||
|
For the server to support DNSSEC, you need to build it
|
||||||
|
with crypto support. You must have OpenSSL 0.9.5a
|
||||||
|
or newer installed and specify "--with-openssl" on the
|
||||||
|
configure command line. If OpenSSL is installed under
|
||||||
|
a nonstandard prefix, you can tell configure where to
|
||||||
|
look for it using "--with-openssl=/prefix".
|
||||||
|
|
||||||
|
On some platforms it is necessary to explictly request large
|
||||||
|
file support to handle files bigger than 2GB. This can be
|
||||||
|
done by "--enable-largefile" on the configure command line.
|
||||||
|
|
||||||
|
On some platforms, BIND 9 can be built with multithreading
|
||||||
|
support, allowing it to take advantage of multiple CPUs.
|
||||||
|
You can specify whether to build a multithreaded BIND 9
|
||||||
|
by specifying "--enable-threads" or "--disable-threads"
|
||||||
|
on the configure command line. The default is operating
|
||||||
|
system dependent.
|
||||||
|
|
||||||
|
Support for the "fixed" rrset-order option can be enabled
|
||||||
|
or disabled by specifying "--enable-fixed-rrset" or
|
||||||
|
"--disable-fixed-rrset" on the configure command line.
|
||||||
|
The default is "disabled", to reduce memory footprint.
|
||||||
|
|
||||||
|
If your operating system has integrated support for IPv6, it
|
||||||
|
will be used automatically. If you have installed KAME IPv6
|
||||||
|
separately, use "--with-kame[=PATH]" to specify its location.
|
||||||
|
|
||||||
|
"make install" will install "named" and the various BIND 9 libraries.
|
||||||
|
By default, installation is into /usr/local, but this can be changed
|
||||||
|
with the "--prefix" option when running "configure".
|
||||||
|
|
||||||
|
You may specify the option "--sysconfdir" to set the directory
|
||||||
|
where configuration files like "named.conf" go by default,
|
||||||
|
and "--localstatedir" to set the default parent directory
|
||||||
|
of "run/named.pid". For backwards compatibility with BIND 8,
|
||||||
|
--sysconfdir defaults to "/etc" and --localstatedir defaults to
|
||||||
|
"/var" if no --prefix option is given. If there is a --prefix
|
||||||
|
option, sysconfdir defaults to "$prefix/etc" and localstatedir
|
||||||
|
defaults to "$prefix/var".
|
||||||
|
|
||||||
|
To see additional configure options, run "configure --help".
|
||||||
|
Note that the help message does not reflect the BIND 8
|
||||||
|
compatibility defaults for sysconfdir and localstatedir.
|
||||||
|
|
||||||
|
If you're planning on making changes to the BIND 9 source, you
|
||||||
|
should also "make depend". If you're using Emacs, you might find
|
||||||
|
"make tags" helpful.
|
||||||
|
|
||||||
|
If you need to re-run configure please run "make distclean" first.
|
||||||
|
This will ensure that all the option changes take.
|
||||||
|
|
||||||
|
Building with gcc is not supported, unless gcc is the vendor's usual
|
||||||
|
compiler (e.g. the various BSD systems, Linux).
|
||||||
|
|
||||||
|
Known compiler issues:
|
||||||
|
* gcc-3.2.1 and gcc-3.1.1 is known to cause problems with solaris-x86.
|
||||||
|
* gcc prior to gcc-3.2.3 ultrasparc generates incorrect code at -02.
|
||||||
|
* gcc-3.3.5 powerpc generates incorrect code at -02.
|
||||||
|
* Irix, MipsPRO 7.4.1m is known to cause problems.
|
||||||
|
|
||||||
|
A limited test suite can be run with "make test". Many of
|
||||||
|
the tests require you to configure a set of virtual IP addresses
|
||||||
|
on your system, and some require Perl; see bin/tests/system/README
|
||||||
|
for details.
|
||||||
|
|
||||||
|
SunOS 4 requires "printf" to be installed to make the shared
|
||||||
|
libraries. sh-utils-1.16 provides a "printf" which compiles
|
||||||
|
on SunOS 4.
|
||||||
|
|
||||||
|
Documentation
|
||||||
|
|
||||||
|
The BIND 9 Administrator Reference Manual is included with the
|
||||||
|
source distribution in DocBook XML and HTML format, in the
|
||||||
|
doc/arm directory.
|
||||||
|
|
||||||
|
Some of the programs in the BIND 9 distribution have man pages
|
||||||
|
in their directories. In particular, the command line
|
||||||
|
options of "named" are documented in /bin/named/named.8.
|
||||||
|
There is now also a set of man pages for the lwres library.
|
||||||
|
|
||||||
|
If you are upgrading from BIND 8, please read the migration
|
||||||
|
notes in doc/misc/migration. If you are upgrading from
|
||||||
|
BIND 4, read doc/misc/migration-4to9.
|
||||||
|
|
||||||
|
Frequently asked questions and their answers can be found in
|
||||||
|
FAQ.
|
||||||
|
|
||||||
|
|
||||||
|
Bug Reports and Mailing Lists
|
||||||
|
|
||||||
|
Bugs reports should be sent to
|
||||||
|
|
||||||
|
bind9-bugs@isc.org
|
||||||
|
|
||||||
|
To join the BIND Users mailing list, send mail to
|
||||||
|
|
||||||
|
bind-users-request@isc.org
|
||||||
|
|
||||||
|
archives of which can be found via
|
||||||
|
|
||||||
|
http://www.isc.org/ops/lists/
|
||||||
|
|
||||||
|
If you're planning on making changes to the BIND 9 source
|
||||||
|
code, you might want to join the BIND Workers mailing list.
|
||||||
|
Send mail to
|
||||||
|
|
||||||
|
bind-workers-request@isc.org
|
||||||
|
|
||||||
|
|
||||||
+112
@@ -0,0 +1,112 @@
|
|||||||
|
|
||||||
|
BIND-9 IDN patch
|
||||||
|
|
||||||
|
Japan Network Information Center (JPNIC)
|
||||||
|
|
||||||
|
|
||||||
|
* What is this patch for?
|
||||||
|
|
||||||
|
This patch adds internationalized domain name (IDN) support to BIND-9.
|
||||||
|
You'll get internationalized version of dig/host/nslookup commands.
|
||||||
|
|
||||||
|
+ internationalized dig/host/nslookup
|
||||||
|
dig/host/nslookup accepts non-ASCII domain names in the local
|
||||||
|
codeset (such as Shift JIS, Big5 or ISO8859-1) determined by
|
||||||
|
the locale information. The domain names are normalized and
|
||||||
|
converted to the encoding on the DNS protocol, and sent to DNS
|
||||||
|
servers. The replies are converted back to the local codeset
|
||||||
|
and displayed.
|
||||||
|
|
||||||
|
|
||||||
|
* Compilation & installation
|
||||||
|
|
||||||
|
0. Prerequisite
|
||||||
|
|
||||||
|
You have to build and install idnkit before building this patched version
|
||||||
|
of bind-9.
|
||||||
|
|
||||||
|
1. Running configure script
|
||||||
|
|
||||||
|
Run `configure' in the top directory. See `README' for the
|
||||||
|
configuration options.
|
||||||
|
|
||||||
|
This patch adds the following 4 options to `configure'. You should
|
||||||
|
at least specify `--with-idn' option to enable IDN support.
|
||||||
|
|
||||||
|
--with-idn[=IDN_PREFIX]
|
||||||
|
To enable IDN support, you have to specify `--with-idn' option.
|
||||||
|
The argument IDN_PREFIX is the install prefix of idnkit. If
|
||||||
|
IDN_PREFIX is omitted, PREFIX (derived from `--prefix=PREFIX')
|
||||||
|
is assumed.
|
||||||
|
|
||||||
|
--with-libiconv[=LIBICONV_PREFIX]
|
||||||
|
Specify this option if idnkit you have installed links GNU
|
||||||
|
libiconv. The argument LIBICONV_PREFIX is install prefix of
|
||||||
|
GNU libiconv. If the argument is omitted, PREFIX (derived
|
||||||
|
from `--prefix=PREFIX') is assumed.
|
||||||
|
|
||||||
|
`--with-libiconv' is shorthand option for GNU libiconv.
|
||||||
|
|
||||||
|
--with-libiconv=/usr/local
|
||||||
|
|
||||||
|
This is equivalent to:
|
||||||
|
|
||||||
|
--with-iconv='-L/usr/local/lib -R/usr/local/lib -liconv'
|
||||||
|
|
||||||
|
`--with-libiconv' assumes that your C compiler has `-R'
|
||||||
|
option, and that the option adds the specified run-time path
|
||||||
|
to an executable binary. If `-R' option of your compiler has
|
||||||
|
different meaning, or your compiler lacks the option, you
|
||||||
|
should use `--with-iconv' option instead. Binary command
|
||||||
|
without run-time path information might be unexecutable.
|
||||||
|
In that case, you would see an error message like:
|
||||||
|
|
||||||
|
error in loading shared libraries: libiconv.so.2: cannot
|
||||||
|
open shared object file
|
||||||
|
|
||||||
|
If both `--with-libiconv' and `--with-iconv' options are
|
||||||
|
specified, `--with-iconv' is prior to `--with-libiconv'.
|
||||||
|
|
||||||
|
--with-iconv=ICONV_LIBSPEC
|
||||||
|
If your libc doesn't provide iconv(), you need to specify the
|
||||||
|
library containing iconv() with this option. `ICONV_LIBSPEC'
|
||||||
|
is the argument(s) to `cc' or `ld' to link the library, for
|
||||||
|
example, `--with-iconv="-L/usr/local/lib -liconv"'.
|
||||||
|
You don't need to specify the header file directory for "iconv.h"
|
||||||
|
to the compiler, as it isn't included directly by bind-9 with
|
||||||
|
this patch.
|
||||||
|
|
||||||
|
--with-idnlib=IDN_LIBSPEC
|
||||||
|
With this option, you can explicitly specify the argument(s)
|
||||||
|
to `cc' or `ld' to link the idnkit's library, `libidnkit'. If
|
||||||
|
this option is not specified, `-L${PREFIX}/lib -lidnkit' is
|
||||||
|
assumed, where ${PREFIX} is the installation prefix specified
|
||||||
|
with `--with-idn' option above. You may need to use this
|
||||||
|
option to specify extra arguments, for example,
|
||||||
|
`--with-idnlib="-L/usr/local/lib -R/usr/local/lib -lidnkit"'.
|
||||||
|
|
||||||
|
Please consult `README' for other configuration options.
|
||||||
|
|
||||||
|
Note that if you want to specify some extra header file directories,
|
||||||
|
you should use the environment variable STD_CINCLUDES instead of
|
||||||
|
CFLAGS, as described in README.
|
||||||
|
|
||||||
|
2. Compilation and installation
|
||||||
|
|
||||||
|
After running "configure", just do
|
||||||
|
|
||||||
|
make
|
||||||
|
make install
|
||||||
|
|
||||||
|
for compiling and installing.
|
||||||
|
|
||||||
|
|
||||||
|
* Contact information
|
||||||
|
|
||||||
|
Please see http//www.nic.ad.jp/en/idn/ for the latest news
|
||||||
|
about idnkit and this patch.
|
||||||
|
|
||||||
|
Bug reports and comments on this kit should be sent to
|
||||||
|
mdnkit-bugs@nic.ad.jp and idn-cmt@nic.ad.jp, respectively.
|
||||||
|
|
||||||
|
; $Id: README.idnkit,v 1.2.762.1 2009/01/18 23:25:14 marka Exp $
|
||||||
@@ -1,373 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
# BIND 9
|
|
||||||
|
|
||||||
### Contents
|
|
||||||
|
|
||||||
1. [Introduction](#intro)
|
|
||||||
1. [Reporting bugs and getting help](#help)
|
|
||||||
1. [Contributing to BIND](#contrib)
|
|
||||||
1. [Building BIND](#build)
|
|
||||||
1. [macOS](#macos)
|
|
||||||
1. [Dependencies](#dependencies)
|
|
||||||
1. [Compile-time options](#opts)
|
|
||||||
1. [Automated testing](#testing)
|
|
||||||
1. [Documentation](#doc)
|
|
||||||
1. [Change log](#changes)
|
|
||||||
1. [Acknowledgments](#ack)
|
|
||||||
|
|
||||||
### <a name="intro"/> Introduction
|
|
||||||
|
|
||||||
BIND (Berkeley Internet Name Domain) is a complete, highly portable
|
|
||||||
implementation of the Domain Name System (DNS) protocol.
|
|
||||||
|
|
||||||
The BIND name server, `named`, can act as an authoritative name
|
|
||||||
server, recursive resolver, DNS forwarder, or all three simultaneously. It
|
|
||||||
implements views for split-horizon DNS, automatic DNSSEC zone signing and
|
|
||||||
key management, catalog zones to facilitate provisioning of zone data
|
|
||||||
throughout a name server constellation, response policy zones (RPZ) to
|
|
||||||
protect clients from malicious data, response rate limiting (RRL) and
|
|
||||||
recursive query limits to reduce distributed denial of service attacks,
|
|
||||||
and many other advanced DNS features. BIND also includes a suite of
|
|
||||||
administrative tools, including the `dig` and `delv` DNS lookup tools,
|
|
||||||
`nsupdate` for dynamic DNS zone updates, `rndc` for remote name server
|
|
||||||
administration, and more.
|
|
||||||
|
|
||||||
BIND 9 began as a complete rewrite of the BIND architecture that was
|
|
||||||
used in versions 4 and 8. Internet Systems Consortium
|
|
||||||
([https://www.isc.org](https://www.isc.org)), a 501(c)(3) US public benefit
|
|
||||||
corporation dedicated to providing software and services in support of the
|
|
||||||
Internet infrastructure, developed BIND 9 and is responsible for its
|
|
||||||
ongoing maintenance and improvement. BIND is open source software
|
|
||||||
licensed under the terms of the Mozilla Public License, version 2.0.
|
|
||||||
|
|
||||||
For a summary of features introduced in past major releases of BIND,
|
|
||||||
see the file [HISTORY](HISTORY.md).
|
|
||||||
|
|
||||||
For a detailed list of changes made throughout the history of BIND 9, see
|
|
||||||
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
|
||||||
CHANGES file format.
|
|
||||||
|
|
||||||
For up-to-date versions and release notes, see
|
|
||||||
[https://www.isc.org/download/](https://www.isc.org/download/).
|
|
||||||
|
|
||||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
|
||||||
|
|
||||||
### <a name="help"/> Reporting bugs and getting help
|
|
||||||
|
|
||||||
To report non-security-sensitive bugs or request new features, you may
|
|
||||||
open an issue in the BIND 9 project on the
|
|
||||||
[ISC GitLab server](https://gitlab.isc.org) at
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9).
|
|
||||||
|
|
||||||
Please note that, unless you explicitly mark the newly created issue as
|
|
||||||
"confidential," it will be publicly readable. Please do not include any
|
|
||||||
information in bug reports that you consider to be confidential unless
|
|
||||||
the issue has been marked as such. In particular, if submitting the
|
|
||||||
contents of your configuration file in a non-confidential issue, it is
|
|
||||||
advisable to obscure key secrets; this can be done automatically by
|
|
||||||
using `named-checkconf -px`.
|
|
||||||
|
|
||||||
If you are reporting a bug that is a potential security issue, such as an
|
|
||||||
assertion failure or other crash in `named`, please do *NOT* use GitLab to
|
|
||||||
report it. Instead, send mail to
|
|
||||||
[security-officer@isc.org](mailto:security-officer@isc.org) using our
|
|
||||||
OpenPGP key to secure your message. (Information about OpenPGP and links
|
|
||||||
to our key can be found at
|
|
||||||
[https://www.isc.org/pgpkey](https://www.isc.org/pgpkey).) Please do not
|
|
||||||
discuss the bug on any public mailing list.
|
|
||||||
|
|
||||||
For a general overview of ISC security policies, read the Knowledgebase
|
|
||||||
article at [https://kb.isc.org/docs/aa-00861](https://kb.isc.org/docs/aa-00861).
|
|
||||||
|
|
||||||
Professional support and training for BIND are available from
|
|
||||||
ISC. Contact us at [https://www.isc.org/contact](https://www.isc.org/contact)
|
|
||||||
for more information.
|
|
||||||
|
|
||||||
To join the __BIND Users__ mailing list, or view the archives, visit
|
|
||||||
[https://lists.isc.org/mailman/listinfo/bind-users](https://lists.isc.org/mailman/listinfo/bind-users).
|
|
||||||
|
|
||||||
If you're planning on making changes to the BIND 9 source code, you
|
|
||||||
may also want to join the __BIND Workers__ mailing list, at
|
|
||||||
[https://lists.isc.org/mailman/listinfo/bind-workers](https://lists.isc.org/mailman/listinfo/bind-workers).
|
|
||||||
|
|
||||||
### <a name="contrib"/> Contributing to BIND
|
|
||||||
|
|
||||||
ISC maintains a public git repository for BIND; details can be found
|
|
||||||
at [https://www.isc.org/sourceaccess/](https://www.isc.org/sourceaccess/).
|
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files:
|
|
||||||
- General information: [CONTRIBUTING.md](CONTRIBUTING.md)
|
|
||||||
- Code of Conduct: [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md)
|
|
||||||
- BIND 9 code style: [doc/dev/style.md](doc/dev/style.md)
|
|
||||||
- BIND architecture and developer guide: [doc/dev/dev.md](doc/dev/dev.md)
|
|
||||||
|
|
||||||
Patches for BIND may be submitted as
|
|
||||||
[merge requests](https://gitlab.isc.org/isc-projects/bind9/merge_requests)
|
|
||||||
on the [ISC GitLab server](https://gitlab.isc.org).
|
|
||||||
|
|
||||||
By default, external contributors do not have the ability to fork BIND on the
|
|
||||||
GitLab server; if you wish to contribute code to BIND, you may request
|
|
||||||
permission to do so. Thereafter, you can create git branches and directly
|
|
||||||
submit requests that they be reviewed and merged.
|
|
||||||
|
|
||||||
If you prefer, you may also submit code by opening a
|
|
||||||
[GitLab issue](https://gitlab.isc.org/isc-projects/bind9/issues) and
|
|
||||||
including your patch as an attachment, preferably generated by
|
|
||||||
`git format-patch`.
|
|
||||||
|
|
||||||
### <a name="build"/> Building BIND 9
|
|
||||||
|
|
||||||
At a minimum, BIND requires a Unix or Linux system with an ANSI C compiler,
|
|
||||||
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
|
||||||
`libuv` asynchronous I/O library, the `nghttp2` HTTP/2 library, and a
|
|
||||||
cryptography provider library such as OpenSSL or a hardware service
|
|
||||||
module supporting PKCS#11. On Linux, BIND requires the `libcap` library
|
|
||||||
to set process privileges, though this requirement can be overridden by
|
|
||||||
disabling capability support at compile time. See [Compile-time
|
|
||||||
options](#opts) below for details on other libraries that may be
|
|
||||||
required to support optional features.
|
|
||||||
|
|
||||||
Successful builds have been observed on many versions of Linux and
|
|
||||||
Unix, including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
|
||||||
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris,
|
|
||||||
OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
|
||||||
|
|
||||||
BIND 9 is also available for Windows Server 2012 R2 and higher. See
|
|
||||||
`win32utils/build.txt` for details on building for Windows
|
|
||||||
systems.
|
|
||||||
|
|
||||||
To build on a Unix or Linux system, use:
|
|
||||||
|
|
||||||
$ autoreconf -fi (if you are building in the git repository)
|
|
||||||
$ ./configure
|
|
||||||
$ make
|
|
||||||
|
|
||||||
If you're using Emacs, you might find `make tags` helpful.
|
|
||||||
|
|
||||||
Several environment variables, which can be set before running `configure`,
|
|
||||||
affect compilation. Significant ones are:
|
|
||||||
|
|
||||||
|Variable|Description |
|
|
||||||
|--------------------|-----------------------------------------------|
|
|
||||||
|`CC`|The C compiler to use. `configure` tries to figure out the right one for supported systems.|
|
|
||||||
|`CFLAGS`|C compiler flags. Defaults to include -g and/or -O2 as supported by the compiler. Please include '-g' if you need to set `CFLAGS`. |
|
|
||||||
|`LDFLAGS`|Linker flags. Defaults to empty string.|
|
|
||||||
|
|
||||||
Additional environment variables affecting the build are listed at the
|
|
||||||
end of the `configure` help text, which can be obtained by running the
|
|
||||||
command:
|
|
||||||
|
|
||||||
$ ./configure --help
|
|
||||||
|
|
||||||
#### <a name="macos"> macOS
|
|
||||||
|
|
||||||
Building on macOS assumes that the "Command Tools for Xcode" are installed.
|
|
||||||
These can be downloaded from
|
|
||||||
[https://developer.apple.com/download/more/](https://developer.apple.com/download/more/)
|
|
||||||
or, if you have Xcode already installed, you can run `xcode-select --install`.
|
|
||||||
(Note that an Apple ID may be required to access the download page.)
|
|
||||||
|
|
||||||
#### <a name="dependencies"> Dependencies
|
|
||||||
|
|
||||||
To build BIND you need to have the following packages installed:
|
|
||||||
|
|
||||||
libuv
|
|
||||||
pkg-config / pkgconfig / pkgconf
|
|
||||||
|
|
||||||
To build BIND from the git repository, you need the following tools
|
|
||||||
installed:
|
|
||||||
|
|
||||||
autoconf (includes autoreconf)
|
|
||||||
automake
|
|
||||||
libtool
|
|
||||||
|
|
||||||
#### <a name="opts"/> Compile-time options
|
|
||||||
|
|
||||||
To see a full list of configuration options, run `configure --help`.
|
|
||||||
|
|
||||||
For the server to support DNSSEC, you need to build it with crypto support.
|
|
||||||
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
|
||||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
|
||||||
using `--with-openssl=<PREFIX>` on the configure command line. To use a
|
|
||||||
PKCS#11 hardware service module for cryptographic operations, specify the
|
|
||||||
path to the PKCS#11 provider library using `--with-pkcs11=<PREFIX>`, and
|
|
||||||
configure BIND with `--enable-native-pkcs11`.
|
|
||||||
|
|
||||||
To support the HTTP statistics channel, the server must be linked with at
|
|
||||||
least one of the following libraries: `libxml2`
|
|
||||||
[http://xmlsoft.org](http://xmlsoft.org) or `json-c`
|
|
||||||
[https://github.com/json-c/json-c](https://github.com/json-c/json-c).
|
|
||||||
If these are installed at a nonstandard location, then:
|
|
||||||
|
|
||||||
* for `libxml2`, specify the prefix using `--with-libxml2=/prefix`.
|
|
||||||
* for `json-c`, adjust `PKG_CONFIG_PATH`.
|
|
||||||
|
|
||||||
To support compression on the HTTP statistics channel, the server must be
|
|
||||||
linked against `libzlib`. If this is installed in a nonstandard location,
|
|
||||||
specify the prefix using `--with-zlib=/prefix`.
|
|
||||||
|
|
||||||
To support storing configuration data for runtime-added zones in an LMDB
|
|
||||||
database, the server must be linked with `liblmdb`. If this is installed in a
|
|
||||||
nonstandard location, specify the prefix using `with-lmdb=/prefix`.
|
|
||||||
|
|
||||||
To support MaxMind GeoIP2 location-based ACLs, the server must be linked
|
|
||||||
with `libmaxminddb`. This is turned on by default if the library is
|
|
||||||
found; if the library is installed in a nonstandard location,
|
|
||||||
specify the prefix using `--with-maxminddb=/prefix`. GeoIP2 support
|
|
||||||
can be switched off with `--disable-geoip`.
|
|
||||||
|
|
||||||
For DNSTAP packet logging, you must have installed `libfstrm`
|
|
||||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
|
||||||
and `libprotobuf-c`
|
|
||||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
|
||||||
and BIND must be configured with `--enable-dnstap`.
|
|
||||||
|
|
||||||
Certain compiled-in constants and default settings can be decreased to
|
|
||||||
values better suited to small machines, e.g. OpenWRT boxes, by specifying
|
|
||||||
`--with-tuning=small` on the `configure` command line. This decreases
|
|
||||||
memory usage by using smaller structures, but degrades performance.
|
|
||||||
|
|
||||||
On Linux, process capabilities are managed in user space using
|
|
||||||
the `libcap` library, which can be installed on most Linux systems via
|
|
||||||
the `libcap-dev` or `libcap-devel` package. Process capability support can
|
|
||||||
also be disabled by configuring with `--disable-linux-caps`.
|
|
||||||
|
|
||||||
On some platforms it is necessary to explicitly request large file support
|
|
||||||
to handle files bigger than 2GB. This can be done by using
|
|
||||||
`--enable-largefile` on the `configure` command line.
|
|
||||||
|
|
||||||
Support for the "fixed" rrset-order option can be enabled or disabled by
|
|
||||||
specifying `--enable-fixed-rrset` or `--disable-fixed-rrset` on the
|
|
||||||
configure command line. By default, fixed rrset-order is disabled to
|
|
||||||
reduce memory footprint.
|
|
||||||
|
|
||||||
The `--enable-querytrace` option causes `named` to log every step of
|
|
||||||
processing every query. The `--enable-singletrace` option turns on the
|
|
||||||
same verbose tracing, but allows an individual query to be separately
|
|
||||||
traced by setting its query ID to 0. These options should only be enabled
|
|
||||||
when debugging, because they have a significant negative impact on query
|
|
||||||
performance.
|
|
||||||
|
|
||||||
`make install` installs `named` and the various BIND 9 libraries. By
|
|
||||||
default, installation is into /usr/local, but this can be changed with the
|
|
||||||
`--prefix` option when running `configure`.
|
|
||||||
|
|
||||||
You may specify the option `--sysconfdir` to set the directory where
|
|
||||||
configuration files like `named.conf` go by default, and `--localstatedir`
|
|
||||||
to set the default parent directory of `run/named.pid`. `--sysconfdir`
|
|
||||||
defaults to `$prefix/etc` and `--localstatedir` defaults to `$prefix/var`.
|
|
||||||
|
|
||||||
### <a name="testing"/> Automated testing
|
|
||||||
|
|
||||||
A system test suite can be run with `make check`. The system tests require
|
|
||||||
you to configure a set of virtual IP addresses on your system (this allows
|
|
||||||
multiple servers to run locally and communicate with each other). These
|
|
||||||
IP addresses can be configured by running the command
|
|
||||||
`bin/tests/system/ifconfig.sh up` as root.
|
|
||||||
|
|
||||||
Some tests require Perl and the `Net::DNS` and/or `IO::Socket::INET6` modules,
|
|
||||||
and are skipped if these are not available. Some tests require Python
|
|
||||||
and the `dnspython` module and are skipped if these are not available.
|
|
||||||
See bin/tests/system/README for further details.
|
|
||||||
|
|
||||||
Unit tests are implemented using the CMocka unit testing framework. To build
|
|
||||||
them, use `configure --with-cmocka`. Execution of tests is done by the automake
|
|
||||||
parallel test driver; unit tests are also run by `make check`.
|
|
||||||
|
|
||||||
### <a name="doc"/> Documentation
|
|
||||||
|
|
||||||
The *BIND 9 Administrator Reference Manual* (ARM) is included with the source
|
|
||||||
distribution, and in .rst format, in the `doc/arm`
|
|
||||||
directory. HTML and PDF versions are automatically generated and can
|
|
||||||
be viewed at [https://bind9.readthedocs.io/en/latest/index.html](https://bind9.readthedocs.io/en/latest/index.html).
|
|
||||||
|
|
||||||
Man pages for some of the programs in the BIND 9 distribution
|
|
||||||
are also included in the BIND ARM.
|
|
||||||
|
|
||||||
Frequently (and not-so-frequently) asked questions and their answers
|
|
||||||
can be found in the ISC Knowledgebase at
|
|
||||||
[https://kb.isc.org](https://kb.isc.org).
|
|
||||||
|
|
||||||
Additional information on various subjects can be found in other
|
|
||||||
`README` files throughout the source tree.
|
|
||||||
|
|
||||||
### <a name="changes"/> Change log
|
|
||||||
|
|
||||||
A detailed list of all changes that have been made throughout the
|
|
||||||
development of BIND 9 is included in the file CHANGES, with the most recent
|
|
||||||
changes listed first. Change notes include tags indicating the category of
|
|
||||||
the change that was made; these categories are:
|
|
||||||
|
|
||||||
|Category |Description |
|
|
||||||
|-------------- |-----------------------------------------------|
|
|
||||||
| [func] | New feature |
|
|
||||||
| [bug] | General bug fix |
|
|
||||||
| [security] | Fix for a significant security flaw |
|
|
||||||
| [experimental] | Used for new features when the syntax or other aspects of the design are still in flux and may change |
|
|
||||||
| [port] | Portability enhancement |
|
|
||||||
| [maint] | Updates to built-in data such as root server addresses and keys |
|
|
||||||
| [tuning] | Changes to built-in configuration defaults and constants to improve performance |
|
|
||||||
| [performance] | Other changes to improve server performance |
|
|
||||||
| [protocol] | Updates to the DNS protocol such as new RR types |
|
|
||||||
| [test] | Changes to the automatic tests, not affecting server functionality |
|
|
||||||
| [cleanup] | Minor corrections and refactoring |
|
|
||||||
| [doc] | Documentation |
|
|
||||||
| [contrib] | Changes to the contributed tools and libraries in the 'contrib' subdirectory |
|
|
||||||
| [placeholder] | Used in the main development branch to reserve change numbers for use in other branches, e.g., when fixing a bug that only exists in older releases |
|
|
||||||
|
|
||||||
In general, [func] and [experimental] tags only appear in new-feature
|
|
||||||
releases (i.e., those with version numbers ending in zero). Some new
|
|
||||||
functionality may be backported to older releases on a case-by-case basis.
|
|
||||||
All other change types may be applied to all currently supported releases.
|
|
||||||
|
|
||||||
#### Bug report identifiers
|
|
||||||
|
|
||||||
Most notes in the CHANGES file include a reference to a bug report or
|
|
||||||
issue number. Prior to 2018, these were usually of the form `[RT #NNN]`
|
|
||||||
and referred to entries in the "bind9-bugs" RT database, which was not open
|
|
||||||
to the public. More recent entries use the form `[GL #NNN]` or, less often,
|
|
||||||
`[GL !NNN]`, which, respectively, refer to issues or merge requests in the
|
|
||||||
GitLab database. Most of these are publicly readable, unless they include
|
|
||||||
information which is confidential or security-sensitive.
|
|
||||||
|
|
||||||
To look up a GitLab issue by its number, use the URL
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9/issues/NNN](https://gitlab.isc.org/isc-projects/bind9/issues).
|
|
||||||
To look up a merge request, use
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9/merge_requests/NNN](https://gitlab.isc.org/isc-projects/bind9/merge_requests).
|
|
||||||
|
|
||||||
In rare cases, an issue or merge request number may be followed with the
|
|
||||||
letter "P". This indicates that the information is in the private ISC
|
|
||||||
GitLab instance, which is not visible to the public.
|
|
||||||
|
|
||||||
### <a name="ack"/> Acknowledgments
|
|
||||||
|
|
||||||
* The original development of BIND 9 was underwritten by the
|
|
||||||
following organizations:
|
|
||||||
|
|
||||||
Sun Microsystems, Inc.
|
|
||||||
Hewlett Packard
|
|
||||||
Compaq Computer Corporation
|
|
||||||
IBM
|
|
||||||
Process Software Corporation
|
|
||||||
Silicon Graphics, Inc.
|
|
||||||
Network Associates, Inc.
|
|
||||||
U.S. Defense Information Systems Agency
|
|
||||||
USENIX Association
|
|
||||||
Stichting NLnet - NLnet Foundation
|
|
||||||
Nominum, Inc.
|
|
||||||
|
|
||||||
* This product includes software developed by the OpenSSL Project for use
|
|
||||||
in the OpenSSL Toolkit.
|
|
||||||
[https://www.OpenSSL.org/](https://www.OpenSSL.org/)
|
|
||||||
* This product includes cryptographic software written by Eric Young
|
|
||||||
(eay@cryptsoft.com).
|
|
||||||
* This product includes software written by Tim Hudson (tjh@cryptsoft.com).
|
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
|
||||||
|
BIND-9 PKCS#11 support
|
||||||
|
|
||||||
|
Prerequisite
|
||||||
|
|
||||||
|
The PKCS#11 support needs a PKCS#11 OpenSSL engine based on the Solaris one,
|
||||||
|
released the 2007-11-21 for OpenSSL 0.9.8g, with a bug fix (call to free)
|
||||||
|
and some improvements, including user friendly PIN management.
|
||||||
|
|
||||||
|
Compilation
|
||||||
|
|
||||||
|
"configure --with-pkcs11 ..."
|
||||||
|
|
||||||
|
PKCS#11 Libraries
|
||||||
|
|
||||||
|
Tested with Solaris one with a SCA board and with openCryptoki with the
|
||||||
|
software token.
|
||||||
|
|
||||||
|
OpenSSL Engines
|
||||||
|
|
||||||
|
With PKCS#11 support the PKCS#11 engine is statically loaded but at its
|
||||||
|
initialization it dynamically loads the PKCS#11 objects.
|
||||||
|
Even the pre commands are therefore unused they are defined with:
|
||||||
|
SO_PATH:
|
||||||
|
define: PKCS11_SO_PATH
|
||||||
|
default: /usr/local/lib/engines/engine_pkcs11.so
|
||||||
|
MODULE_PATH:
|
||||||
|
define: PKCS11_MODULE_PATH
|
||||||
|
default: /usr/lib/libpkcs11.so
|
||||||
|
Without PKCS#11 support, a specific OpenSSL engine can be still used
|
||||||
|
by defining ENGINE_ID at compile time.
|
||||||
|
|
||||||
|
PKCS#11 tools
|
||||||
|
|
||||||
|
The contrib/pkcs11-keygen directory contains a set of experimental tools
|
||||||
|
to handle keys stored in a Hardware Security Module at the benefit of BIND.
|
||||||
|
|
||||||
|
The patch for OpenSSL 0.9.8g is in this directory. Read its README.pkcs11
|
||||||
|
for the way to use it (these are the original notes so with the original
|
||||||
|
path, etc. Define OPENCRYPTOKI to use it with openCryptoki.)
|
||||||
|
|
||||||
|
PIN management
|
||||||
|
|
||||||
|
With the just fixed PKCS#11 OpenSSL engine, the PIN should be entered
|
||||||
|
each time it is required. With the improved engine, the PIN should be
|
||||||
|
entered the first time it is required or can be configured in the
|
||||||
|
OpenSSL configuration file (aka. openssl.cnf) by adding in it:
|
||||||
|
- at the beginning:
|
||||||
|
openssl_conf = openssl_def
|
||||||
|
- at any place these sections:
|
||||||
|
[ openssl_def ]
|
||||||
|
engines = engine_section
|
||||||
|
[ engine_section ]
|
||||||
|
pkcs11 = pkcs11_section
|
||||||
|
[ pkcs11_section ]
|
||||||
|
PIN = put__your__pin__value__here
|
||||||
|
|
||||||
|
Note
|
||||||
|
|
||||||
|
Some names here are registered trademarks, at least Solaris is a trademark
|
||||||
|
of Sun Microsystems Inc...
|
||||||
@@ -0,0 +1,225 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||||||
|
<!--
|
||||||
|
- Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
-
|
||||||
|
- Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
- purpose with or without fee is hereby granted, provided that the above
|
||||||
|
- copyright notice and this permission notice appear in all copies.
|
||||||
|
-
|
||||||
|
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
- PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
-->
|
||||||
|
|
||||||
|
<!-- $Id: RELEASE-NOTES-BIND-9.6-ESV.html,v 1.1.2.2 2010/11/29 01:16:39 tbox Exp $ -->
|
||||||
|
|
||||||
|
<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title></title><link rel="stylesheet" type="text/css" href="release-notes.css" /><meta name="generator" content="DocBook XSL Stylesheets V1.76.1" /></head><body><div class="article"><div class="titlepage"><hr /></div>
|
||||||
|
|
||||||
|
<div class="section" title="Introduction"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36111950"></a>Introduction</h2></div></div></div>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
BIND 9.6-ESV-R3 is a maintenance release for BIND 9.6-ESV.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
This document summarizes changes from BIND 9.6-ESV-R1 to BIND 9.6-ESV-R3.
|
||||||
|
Please see the CHANGES file in the source code release for a
|
||||||
|
complete list of all changes.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Download"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112014"></a>Download</h2></div></div></div>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
The latest release of BIND 9 software can always be found
|
||||||
|
on our web site at
|
||||||
|
<a class="ulink" href="http://www.isc.org/software/bind" target="_top">http://www.isc.org/software/bind</a>.
|
||||||
|
There you will find additional information about each release,
|
||||||
|
source code, and some pre-compiled versions for certain operating
|
||||||
|
systems.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Support"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112037"></a>Support</h2></div></div></div>
|
||||||
|
|
||||||
|
<p>Product support information is available on
|
||||||
|
<a class="ulink" href="http://www.isc.org/services/support" target="_top">http://www.isc.org/services/support</a>
|
||||||
|
for paid support options. Free support is provided by our user
|
||||||
|
community via a mailing list. Information on all public email
|
||||||
|
lists is available at
|
||||||
|
<a class="ulink" href="https://lists.isc.org/mailman/listinfo" target="_top">https://lists.isc.org/mailman/listinfo</a>.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="New Features"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36111986"></a>New Features</h2></div></div></div>
|
||||||
|
|
||||||
|
<div class="section" title="9.6-ESV-R2"><div class="titlepage"><div><div><h3 class="title"><a id="id36112025"></a>9.6-ESV-R2</h3></div></div></div>
|
||||||
|
|
||||||
|
<p>None.</p>
|
||||||
|
</div>
|
||||||
|
<div class="section" title="9.6-ESV-R3"><div class="titlepage"><div><div><h3 class="title"><a id="id36112098"></a>9.6-ESV-R3</h3></div></div></div>
|
||||||
|
|
||||||
|
<p>None.</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Feature Changes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112120"></a>Feature Changes</h2></div></div></div>
|
||||||
|
|
||||||
|
<div class="section" title="9.6-ESV-R2"><div class="titlepage"><div><div><h3 class="title"><a id="id36112125"></a>9.6-ESV-R2</h3></div></div></div>
|
||||||
|
|
||||||
|
<p>None.</p>
|
||||||
|
</div>
|
||||||
|
<div class="section" title="9.6-ESV-R3"><div class="titlepage"><div><div><h3 class="title"><a id="id36112135"></a>9.6-ESV-R3</h3></div></div></div>
|
||||||
|
|
||||||
|
<p>None.</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Security Fixes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112146"></a>Security Fixes</h2></div></div></div>
|
||||||
|
|
||||||
|
<div class="section" title="9.6-ESV-R2"><div class="titlepage"><div><div><h3 class="title"><a id="id36112151"></a>9.6-ESV-R2</h3></div></div></div>
|
||||||
|
|
||||||
|
<p>None.</p>
|
||||||
|
</div>
|
||||||
|
<div class="section" title="9.6-ESV-R3"><div class="titlepage"><div><div><h3 class="title"><a id="id36112160"></a>9.6-ESV-R3</h3></div></div></div>
|
||||||
|
|
||||||
|
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
|
||||||
|
Adding a NO DATA signed negative response to cache failed to clear
|
||||||
|
any matching RRSIG records already in cache. A subsequent lookup
|
||||||
|
of the cached NO DATA entry could crash named (INSIST) when the
|
||||||
|
unexpected RRSIG was also returned with the NO DATA cache entry.
|
||||||
|
[RT #22288] [CVE-2010-3613] [VU#706148]
|
||||||
|
</li><li class="listitem">
|
||||||
|
BIND, acting as a DNSSEC validator, was determining if the NS RRset
|
||||||
|
is insecure based on a value that could mean either that the RRset
|
||||||
|
is actually insecure or that there wasn't a matching key for the RRSIG
|
||||||
|
in the DNSKEY RRset when resuming from validating the DNSKEY RRset.
|
||||||
|
This can happen when in the middle of a DNSKEY algorithm rollover,
|
||||||
|
when two different algorithms were used to sign a zone but only the
|
||||||
|
new set of keys are in the zone DNSKEY RRset.
|
||||||
|
[RT #22309] [CVE-2010-3614] [VU#837744]
|
||||||
|
</li></ul></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Bug Fixes"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112186"></a>Bug Fixes</h2></div></div></div>
|
||||||
|
|
||||||
|
<div class="section" title="9.6-ESV-R2"><div class="titlepage"><div><div><h3 class="title"><a id="id36112191"></a>9.6-ESV-R2</h3></div></div></div>
|
||||||
|
|
||||||
|
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
|
||||||
|
Check that named successfully skips NSEC3 records
|
||||||
|
that fail to match the NSEC3PARAM record currently
|
||||||
|
in use.
|
||||||
|
[RT #21868]
|
||||||
|
</li><li class="listitem">
|
||||||
|
Worked around a race condition in the cache database memory
|
||||||
|
handling. Without this fix a DNS cache DB or ADB could
|
||||||
|
incorrectly stay in an over memory state, effectively refusing
|
||||||
|
further caching, which subsequently made a BIND 9 caching
|
||||||
|
server unworkable.
|
||||||
|
[RT #21818]
|
||||||
|
</li><li class="listitem">
|
||||||
|
BIND did not properly handle non-cacheable negative responses
|
||||||
|
from insecure zones. This caused several non-protocol-compliant
|
||||||
|
zones to become unresolvable. BIND is now more accepting of
|
||||||
|
responses it receives from less strict servers.
|
||||||
|
[RT #21555]
|
||||||
|
</li><li class="listitem">
|
||||||
|
The resolver could attempt to destroy a fetch context too
|
||||||
|
soon, resulting in a crash.
|
||||||
|
[RT #19878]
|
||||||
|
</li><li class="listitem">
|
||||||
|
The placeholder negative caching element was not
|
||||||
|
properly constructed triggering a crash (INSIST) in
|
||||||
|
dns_ncache_towire().
|
||||||
|
[RT #21346]
|
||||||
|
</li><li class="listitem">
|
||||||
|
Handle the introduction of new trusted-keys and
|
||||||
|
DS, DLV RRsets better.
|
||||||
|
[RT #21097]
|
||||||
|
</li><li class="listitem">
|
||||||
|
Fix arguments to dns_keytable_findnextkeynode() call.
|
||||||
|
[RT #20877]
|
||||||
|
</li></ul></div>
|
||||||
|
</div>
|
||||||
|
<div class="section" title="9.6-ESV-R3"><div class="titlepage"><div><div><h3 class="title"><a id="id36112232"></a>9.6-ESV-R3</h3></div></div></div>
|
||||||
|
|
||||||
|
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
|
||||||
|
Microsoft changed the behavior of sockets between NT/XP based
|
||||||
|
stacks vs Vista/windows7 stacks. Server 2003/2008 have the older
|
||||||
|
behavior, 2008r2 has the new behavior. With the change, different
|
||||||
|
error results are possible, so ISC adapted BIND to handle the new
|
||||||
|
error results.
|
||||||
|
This resolves an issue where sockets would shut down on
|
||||||
|
Windows servers causing named to stop responding to queries.
|
||||||
|
[RT #21906]
|
||||||
|
</li><li class="listitem">
|
||||||
|
Windows has non-POSIX compliant behavior in its rename() and unlink()
|
||||||
|
calls. This caused journal compaction to fail on Windows BIND servers
|
||||||
|
with the log error: "dns_journal_compact failed: failure".
|
||||||
|
[RT #22434]
|
||||||
|
</li><li class="listitem">
|
||||||
|
'host -D' now turns on debugging messages earlier.
|
||||||
|
[RT #22361]
|
||||||
|
</li><li class="listitem">
|
||||||
|
isc_print_vsnprintf() failed to check if there was
|
||||||
|
space available in the buffer when adding a left
|
||||||
|
justified character with a non zero width,
|
||||||
|
(e.g. "%-1c").
|
||||||
|
[RT #22270]
|
||||||
|
</li><li class="listitem">
|
||||||
|
view->queryacl was being overloaded. Seperate the
|
||||||
|
usage into view->queryacl, view->cacheacl and
|
||||||
|
view->queryonacl.
|
||||||
|
[RT #22114]
|
||||||
|
</li><li class="listitem">
|
||||||
|
win32: add more dependencies to BINDBuild.dsw.
|
||||||
|
[RT #22062]
|
||||||
|
</li><li class="listitem">
|
||||||
|
win32: named-checkzone and named-checkconf failed
|
||||||
|
to initialise winsock.
|
||||||
|
[RT #21932]
|
||||||
|
</li><li class="listitem">
|
||||||
|
named failed to generate a correct signed response
|
||||||
|
in a optout, delegation only zone with no secure
|
||||||
|
delegations.
|
||||||
|
[RT #22007]
|
||||||
|
</li></ul></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Known issues in this release"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112280"></a>Known issues in this release</h2></div></div></div>
|
||||||
|
|
||||||
|
<div class="itemizedlist"><ul class="itemizedlist" type="disc"><li class="listitem">
|
||||||
|
<p>
|
||||||
|
"make test" will fail on OSX and possibly other operating systems.
|
||||||
|
The failure occurs in a new test to check for allow-query ACLs.
|
||||||
|
The failure is caused because the source address is not specified on
|
||||||
|
the dig commands issued in the test.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
If running "make test" is part of your usual acceptance process,
|
||||||
|
please edit the file <code class="code">bin/tests/system/allow_query/test.sh</code>
|
||||||
|
and add
|
||||||
|
</p><p>
|
||||||
|
<code class="code">-b 10.53.0.2</code>
|
||||||
|
</p><p>
|
||||||
|
to the <code class="code">DIGOPTS</code> line.
|
||||||
|
</p>
|
||||||
|
</li></ul></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="section" title="Thank You"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id36112315"></a>Thank You</h2></div></div></div>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
Thank you to everyone who assisted us in making this release possible.
|
||||||
|
If you would like to contribute to ISC to assist us in continuing to make
|
||||||
|
quality open source software, please visit our donations page at
|
||||||
|
<a class="ulink" href="http://www.isc.org/supportisc" target="_top">http://www.isc.org/supportisc</a>.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div></body></html>
|
||||||
Binary file not shown.
@@ -0,0 +1,133 @@
|
|||||||
|
__________________________________________________________________
|
||||||
|
|
||||||
|
Introduction
|
||||||
|
|
||||||
|
BIND 9.6-ESV-R3 is a maintenance release for BIND 9.6-ESV.
|
||||||
|
|
||||||
|
This document summarizes changes from BIND 9.6-ESV-R1 to BIND
|
||||||
|
9.6-ESV-R3. Please see the CHANGES file in the source code release for
|
||||||
|
a complete list of all changes.
|
||||||
|
|
||||||
|
Download
|
||||||
|
|
||||||
|
The latest release of BIND 9 software can always be found on our web
|
||||||
|
site at http://www.isc.org/software/bind. There you will find
|
||||||
|
additional information about each release, source code, and some
|
||||||
|
pre-compiled versions for certain operating systems.
|
||||||
|
|
||||||
|
Support
|
||||||
|
|
||||||
|
Product support information is available on
|
||||||
|
http://www.isc.org/services/support for paid support options. Free
|
||||||
|
support is provided by our user community via a mailing list.
|
||||||
|
Information on all public email lists is available at
|
||||||
|
https://lists.isc.org/mailman/listinfo.
|
||||||
|
|
||||||
|
New Features
|
||||||
|
|
||||||
|
9.6-ESV-R2
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
9.6-ESV-R3
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
Feature Changes
|
||||||
|
|
||||||
|
9.6-ESV-R2
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
9.6-ESV-R3
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
Security Fixes
|
||||||
|
|
||||||
|
9.6-ESV-R2
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
9.6-ESV-R3
|
||||||
|
|
||||||
|
* Adding a NO DATA signed negative response to cache failed to clear
|
||||||
|
any matching RRSIG records already in cache. A subsequent lookup of
|
||||||
|
the cached NO DATA entry could crash named (INSIST) when the
|
||||||
|
unexpected RRSIG was also returned with the NO DATA cache entry.
|
||||||
|
[RT #22288] [CVE-2010-3613] [VU#706148]
|
||||||
|
* BIND, acting as a DNSSEC validator, was determining if the NS RRset
|
||||||
|
is insecure based on a value that could mean either that the RRset
|
||||||
|
is actually insecure or that there wasn't a matching key for the
|
||||||
|
RRSIG in the DNSKEY RRset when resuming from validating the DNSKEY
|
||||||
|
RRset. This can happen when in the middle of a DNSKEY algorithm
|
||||||
|
rollover, when two different algorithms were used to sign a zone
|
||||||
|
but only the new set of keys are in the zone DNSKEY RRset. [RT
|
||||||
|
#22309] [CVE-2010-3614] [VU#837744]
|
||||||
|
|
||||||
|
Bug Fixes
|
||||||
|
|
||||||
|
9.6-ESV-R2
|
||||||
|
|
||||||
|
* Check that named successfully skips NSEC3 records that fail to
|
||||||
|
match the NSEC3PARAM record currently in use. [RT #21868]
|
||||||
|
* Worked around a race condition in the cache database memory
|
||||||
|
handling. Without this fix a DNS cache DB or ADB could incorrectly
|
||||||
|
stay in an over memory state, effectively refusing further caching,
|
||||||
|
which subsequently made a BIND 9 caching server unworkable. [RT
|
||||||
|
#21818]
|
||||||
|
* BIND did not properly handle non-cacheable negative responses from
|
||||||
|
insecure zones. This caused several non-protocol-compliant zones to
|
||||||
|
become unresolvable. BIND is now more accepting of responses it
|
||||||
|
receives from less strict servers. [RT #21555]
|
||||||
|
* The resolver could attempt to destroy a fetch context too soon,
|
||||||
|
resulting in a crash. [RT #19878]
|
||||||
|
* The placeholder negative caching element was not properly
|
||||||
|
constructed triggering a crash (INSIST) in dns_ncache_towire(). [RT
|
||||||
|
#21346]
|
||||||
|
* Handle the introduction of new trusted-keys and DS, DLV RRsets
|
||||||
|
better. [RT #21097]
|
||||||
|
* Fix arguments to dns_keytable_findnextkeynode() call. [RT #20877]
|
||||||
|
|
||||||
|
9.6-ESV-R3
|
||||||
|
|
||||||
|
* Microsoft changed the behavior of sockets between NT/XP based
|
||||||
|
stacks vs Vista/windows7 stacks. Server 2003/2008 have the older
|
||||||
|
behavior, 2008r2 has the new behavior. With the change, different
|
||||||
|
error results are possible, so ISC adapted BIND to handle the new
|
||||||
|
error results. This resolves an issue where sockets would shut down
|
||||||
|
on Windows servers causing named to stop responding to queries. [RT
|
||||||
|
#21906]
|
||||||
|
* Windows has non-POSIX compliant behavior in its rename() and
|
||||||
|
unlink() calls. This caused journal compaction to fail on Windows
|
||||||
|
BIND servers with the log error: "dns_journal_compact failed:
|
||||||
|
failure". [RT #22434]
|
||||||
|
* 'host -D' now turns on debugging messages earlier. [RT #22361]
|
||||||
|
* isc_print_vsnprintf() failed to check if there was space available
|
||||||
|
in the buffer when adding a left justified character with a non
|
||||||
|
zero width, (e.g. "%-1c"). [RT #22270]
|
||||||
|
* view->queryacl was being overloaded. Seperate the usage into
|
||||||
|
view->queryacl, view->cacheacl and view->queryonacl. [RT #22114]
|
||||||
|
* win32: add more dependencies to BINDBuild.dsw. [RT #22062]
|
||||||
|
* win32: named-checkzone and named-checkconf failed to initialise
|
||||||
|
winsock. [RT #21932]
|
||||||
|
* named failed to generate a correct signed response in a optout,
|
||||||
|
delegation only zone with no secure delegations. [RT #22007]
|
||||||
|
|
||||||
|
Known issues in this release
|
||||||
|
|
||||||
|
* "make test" will fail on OSX and possibly other operating systems.
|
||||||
|
The failure occurs in a new test to check for allow-query ACLs. The
|
||||||
|
failure is caused because the source address is not specified on
|
||||||
|
the dig commands issued in the test.
|
||||||
|
If running "make test" is part of your usual acceptance process,
|
||||||
|
please edit the file bin/tests/system/allow_query/test.sh and add
|
||||||
|
-b 10.53.0.2
|
||||||
|
to the DIGOPTS line.
|
||||||
|
|
||||||
|
Thank You
|
||||||
|
|
||||||
|
Thank you to everyone who assisted us in making this release possible.
|
||||||
|
If you would like to contribute to ISC to assist us in continuing to
|
||||||
|
make quality open source software, please visit our donations page at
|
||||||
|
http://www.isc.org/supportisc.
|
||||||
+145
@@ -0,0 +1,145 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||||
|
*
|
||||||
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
|
* copyright notice and this permission notice appear in all copies.
|
||||||
|
*
|
||||||
|
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
* PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/* $Id: acconfig.h,v 1.51.334.2 2009/02/16 23:47:15 tbox Exp $ */
|
||||||
|
|
||||||
|
/*! \file */
|
||||||
|
|
||||||
|
/***
|
||||||
|
*** This file is not to be included by any public header files, because
|
||||||
|
*** it does not get installed.
|
||||||
|
***/
|
||||||
|
@TOP@
|
||||||
|
|
||||||
|
/** define on DEC OSF to enable 4.4BSD style sa_len support */
|
||||||
|
#undef _SOCKADDR_LEN
|
||||||
|
|
||||||
|
/** define if your system needs pthread_init() before using pthreads */
|
||||||
|
#undef NEED_PTHREAD_INIT
|
||||||
|
|
||||||
|
/** define if your system has sigwait() */
|
||||||
|
#undef HAVE_SIGWAIT
|
||||||
|
|
||||||
|
/** define if sigwait() is the UnixWare flavor */
|
||||||
|
#undef HAVE_UNIXWARE_SIGWAIT
|
||||||
|
|
||||||
|
/** define on Solaris to get sigwait() to work using pthreads semantics */
|
||||||
|
#undef _POSIX_PTHREAD_SEMANTICS
|
||||||
|
|
||||||
|
/** define if LinuxThreads is in use */
|
||||||
|
#undef HAVE_LINUXTHREADS
|
||||||
|
|
||||||
|
/** define if sysconf() is available */
|
||||||
|
#undef HAVE_SYSCONF
|
||||||
|
|
||||||
|
/** define if sysctlbyname() is available */
|
||||||
|
#undef HAVE_SYSCTLBYNAME
|
||||||
|
|
||||||
|
/** define if catgets() is available */
|
||||||
|
#undef HAVE_CATGETS
|
||||||
|
|
||||||
|
/** define if getifaddrs() exists */
|
||||||
|
#undef HAVE_GETIFADDRS
|
||||||
|
|
||||||
|
/** define if you have the NET_RT_IFLIST sysctl variable and sys/sysctl.h */
|
||||||
|
#undef HAVE_IFLIST_SYSCTL
|
||||||
|
|
||||||
|
/** define if tzset() is available */
|
||||||
|
#undef HAVE_TZSET
|
||||||
|
|
||||||
|
/** define if struct addrinfo exists */
|
||||||
|
#undef HAVE_ADDRINFO
|
||||||
|
|
||||||
|
/** define if getaddrinfo() exists */
|
||||||
|
#undef HAVE_GETADDRINFO
|
||||||
|
|
||||||
|
/** define if gai_strerror() exists */
|
||||||
|
#undef HAVE_GAISTRERROR
|
||||||
|
|
||||||
|
/** define if arc4random() exists */
|
||||||
|
#undef HAVE_ARC4RANDOM
|
||||||
|
|
||||||
|
/**
|
||||||
|
* define if pthread_setconcurrency() should be called to tell the
|
||||||
|
* OS how many threads we might want to run.
|
||||||
|
*/
|
||||||
|
#undef CALL_PTHREAD_SETCONCURRENCY
|
||||||
|
|
||||||
|
/** define if IPv6 is not disabled */
|
||||||
|
#undef WANT_IPV6
|
||||||
|
|
||||||
|
/** define if flockfile() is available */
|
||||||
|
#undef HAVE_FLOCKFILE
|
||||||
|
|
||||||
|
/** define if getc_unlocked() is available */
|
||||||
|
#undef HAVE_GETCUNLOCKED
|
||||||
|
|
||||||
|
/** Shut up warnings about sputaux in stdio.h on BSD/OS pre-4.1 */
|
||||||
|
#undef SHUTUP_SPUTAUX
|
||||||
|
#ifdef SHUTUP_SPUTAUX
|
||||||
|
struct __sFILE;
|
||||||
|
extern __inline int __sputaux(int _c, struct __sFILE *_p);
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/** Shut up warnings about missing sigwait prototype on BSD/OS 4.0* */
|
||||||
|
#undef SHUTUP_SIGWAIT
|
||||||
|
#ifdef SHUTUP_SIGWAIT
|
||||||
|
int sigwait(const unsigned int *set, int *sig);
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/** Shut up warnings from gcc -Wcast-qual on BSD/OS 4.1. */
|
||||||
|
#undef SHUTUP_STDARG_CAST
|
||||||
|
#if defined(SHUTUP_STDARG_CAST) && defined(__GNUC__)
|
||||||
|
#include <stdarg.h> /** Grr. Must be included *every time*. */
|
||||||
|
/**
|
||||||
|
* The silly continuation line is to keep configure from
|
||||||
|
* commenting out the #undef.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#undef \
|
||||||
|
va_start
|
||||||
|
#define va_start(ap, last) \
|
||||||
|
do { \
|
||||||
|
union { const void *konst; long *var; } _u; \
|
||||||
|
_u.konst = &(last); \
|
||||||
|
ap = (va_list)(_u.var + __va_words(__typeof(last))); \
|
||||||
|
} while (0)
|
||||||
|
#endif /** SHUTUP_STDARG_CAST && __GNUC__ */
|
||||||
|
|
||||||
|
/** define if the system has a random number generating device */
|
||||||
|
#undef PATH_RANDOMDEV
|
||||||
|
|
||||||
|
/** define if pthread_attr_getstacksize() is available */
|
||||||
|
#undef HAVE_PTHREAD_ATTR_GETSTACKSIZE
|
||||||
|
|
||||||
|
/** define if pthread_attr_setstacksize() is available */
|
||||||
|
#undef HAVE_PTHREAD_ATTR_SETSTACKSIZE
|
||||||
|
|
||||||
|
/** define if you have strerror in the C library. */
|
||||||
|
#undef HAVE_STRERROR
|
||||||
|
|
||||||
|
/** Define if you are running under Compaq TruCluster. */
|
||||||
|
#undef HAVE_TRUCLUSTER
|
||||||
|
|
||||||
|
/* Define if OpenSSL includes DSA support */
|
||||||
|
#undef HAVE_OPENSSL_DSA
|
||||||
|
|
||||||
|
/* Define to the length type used by the socket API (socklen_t, size_t, int). */
|
||||||
|
#undef ISC_SOCKADDR_LEN_T
|
||||||
|
|
||||||
|
/* Define if threads need PTHREAD_SCOPE_SYSTEM */
|
||||||
|
#undef NEED_PTHREAD_SCOPE_SYSTEM
|
||||||
Vendored
+2
@@ -0,0 +1,2 @@
|
|||||||
|
sinclude(./libtool.m4)dnl
|
||||||
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
SUBDIRS = named rndc dig delv dnssec tools nsupdate check confgen tests plugins
|
|
||||||
|
|
||||||
if HAVE_PKCS11
|
|
||||||
SUBDIRS += pkcs11
|
|
||||||
endif
|
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
# Copyright (C) 1998-2001 Internet Software Consortium.
|
||||||
|
#
|
||||||
|
# Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
# purpose with or without fee is hereby granted, provided that the above
|
||||||
|
# copyright notice and this permission notice appear in all copies.
|
||||||
|
#
|
||||||
|
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
# PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
# $Id: Makefile.in,v 1.25 2007/06/19 23:46:59 tbox Exp $
|
||||||
|
|
||||||
|
srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
SUBDIRS = named rndc dig dnssec tests nsupdate check
|
||||||
|
TARGETS =
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
Makefile
|
||||||
|
.libs
|
||||||
|
*.la
|
||||||
|
*.lo
|
||||||
|
named-checkconf
|
||||||
|
named-checkzone
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
.libs
|
|
||||||
named-checkconf
|
|
||||||
named-checkzone
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
include $(top_srcdir)/Makefile.top
|
|
||||||
|
|
||||||
AM_CPPFLAGS += \
|
|
||||||
$(LIBISC_CFLAGS) \
|
|
||||||
$(LIBDNS_CFLAGS) \
|
|
||||||
$(LIBNS_CFLAGS) \
|
|
||||||
$(LIBISCCFG_CFLAGS) \
|
|
||||||
$(LIBBIND9_CFLAGS)
|
|
||||||
|
|
||||||
AM_CPPFLAGS += \
|
|
||||||
-DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
|
||||||
|
|
||||||
noinst_LTLIBRARIES = libcheck-tool.la
|
|
||||||
|
|
||||||
libcheck_tool_la_SOURCES = \
|
|
||||||
check-tool.h \
|
|
||||||
check-tool.c
|
|
||||||
|
|
||||||
LDADD = \
|
|
||||||
libcheck-tool.la \
|
|
||||||
$(LIBISC_LIBS) \
|
|
||||||
$(LIBDNS_LIBS) \
|
|
||||||
$(LIBNS_LIBS) \
|
|
||||||
$(LIBISCCFG_LIBS) \
|
|
||||||
$(LIBBIND9_LIBS)
|
|
||||||
|
|
||||||
bin_PROGRAMS = named-checkconf named-checkzone
|
|
||||||
|
|
||||||
install-exec-hook:
|
|
||||||
ln -f $(DESTDIR)$(bindir)/named-checkzone \
|
|
||||||
$(DESTDIR)$(bindir)/named-compilezone
|
|
||||||
|
|
||||||
uninstall-hook:
|
|
||||||
-rm -f $(DESTDIR)$(bindir)/named-compilezone
|
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
# Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
# Copyright (C) 2000-2003 Internet Software Consortium.
|
||||||
|
#
|
||||||
|
# Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
# purpose with or without fee is hereby granted, provided that the above
|
||||||
|
# copyright notice and this permission notice appear in all copies.
|
||||||
|
#
|
||||||
|
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
# PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
# $Id: Makefile.in,v 1.32 2007/06/19 23:46:59 tbox Exp $
|
||||||
|
|
||||||
|
srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
@BIND9_VERSION@
|
||||||
|
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
CINCLUDES = ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
|
${ISC_INCLUDES}
|
||||||
|
|
||||||
|
CDEFINES = -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@
|
||||||
|
|
||||||
|
SUBDIRS =
|
||||||
|
|
||||||
|
# Alphabetically
|
||||||
|
TARGETS = named-checkconf@EXEEXT@ named-checkzone@EXEEXT@
|
||||||
|
|
||||||
|
# Alphabetically
|
||||||
|
SRCS = named-checkconf.c named-checkzone.c check-tool.c
|
||||||
|
|
||||||
|
MANPAGES = named-checkconf.8 named-checkzone.8
|
||||||
|
|
||||||
|
HTMLPAGES = named-checkconf.html named-checkzone.html
|
||||||
|
|
||||||
|
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
named-checkconf.@O@: named-checkconf.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-DVERSION=\"${VERSION}\" \
|
||||||
|
-c ${srcdir}/named-checkconf.c
|
||||||
|
|
||||||
|
named-checkzone.@O@: named-checkzone.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-DVERSION=\"${VERSION}\" \
|
||||||
|
-c ${srcdir}/named-checkzone.c
|
||||||
|
|
||||||
|
named-checkconf@EXEEXT@: named-checkconf.@O@ check-tool.@O@ ${ISCDEPLIBS} \
|
||||||
|
${ISCCFGDEPLIBS} ${BIND9DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
|
named-checkconf.@O@ check-tool.@O@ ${BIND9LIBS} ${ISCCFGLIBS} \
|
||||||
|
${DNSLIBS} ${ISCLIBS} ${LIBS}
|
||||||
|
|
||||||
|
named-checkzone@EXEEXT@: named-checkzone.@O@ check-tool.@O@ ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
|
named-checkzone.@O@ check-tool.@O@ ${ISCCFGLIBS} ${DNSLIBS} \
|
||||||
|
${ISCLIBS} ${LIBS}
|
||||||
|
|
||||||
|
doc man:: ${MANOBJS}
|
||||||
|
|
||||||
|
docclean manclean maintainer-clean::
|
||||||
|
rm -f ${MANOBJS}
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
install:: named-checkconf@EXEEXT@ named-checkzone@EXEEXT@ installdirs
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkconf@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkzone@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
(cd ${DESTDIR}${sbindir}; rm -f named-compilezone@EXEEXT@; ${LINK_PROGRAM} named-checkzone@EXEEXT@ named-compilezone@EXEEXT@)
|
||||||
|
for m in ${MANPAGES}; do ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man8; done
|
||||||
|
(cd ${DESTDIR}${mandir}/man8; rm -f named-compilezone.8; ${LINK_PROGRAM} named-checkzone.8 named-compilezone.8)
|
||||||
|
|
||||||
|
clean distclean::
|
||||||
|
rm -f ${TARGETS} r1.htm
|
||||||
+218
-339
@@ -1,30 +1,38 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
* Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
* copyright notice and this permission notice appear in all copies.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
* information regarding copyright ownership.
|
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
* PERFORMANCE OF THIS SOFTWARE.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: check-tool.c,v 1.35.36.3.24.2 2010/09/07 23:46:25 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <config.h>
|
||||||
#include <stdbool.h>
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
#include <Winsock2.h>
|
#include <Winsock2.h>
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
|
#include "check-tool.h"
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/net.h>
|
|
||||||
#include <isc/netdb.h>
|
#include <isc/netdb.h>
|
||||||
#include <isc/print.h>
|
#include <isc/net.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
#include <isc/stdio.h>
|
#include <isc/stdio.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
@@ -32,79 +40,88 @@
|
|||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/db.h>
|
|
||||||
#include <dns/dbiterator.h>
|
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
#include <dns/log.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdata.h>
|
#include <dns/rdata.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
#include <dns/rdataset.h>
|
#include <dns/rdataset.h>
|
||||||
#include <dns/rdatasetiter.h>
|
|
||||||
#include <dns/rdatatype.h>
|
|
||||||
#include <dns/result.h>
|
|
||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
#include <dns/zone.h>
|
#include <dns/zone.h>
|
||||||
|
|
||||||
#include <isccfg/log.h>
|
#include <isccfg/log.h>
|
||||||
|
|
||||||
#include <ns/log.h>
|
|
||||||
|
|
||||||
#include "check-tool.h"
|
|
||||||
|
|
||||||
#ifndef CHECK_SIBLING
|
#ifndef CHECK_SIBLING
|
||||||
#define CHECK_SIBLING 1
|
#define CHECK_SIBLING 1
|
||||||
#endif /* ifndef CHECK_SIBLING */
|
#endif
|
||||||
|
|
||||||
#ifndef CHECK_LOCAL
|
#ifndef CHECK_LOCAL
|
||||||
#define CHECK_LOCAL 1
|
#define CHECK_LOCAL 1
|
||||||
#endif /* ifndef CHECK_LOCAL */
|
#endif
|
||||||
|
|
||||||
#define CHECK(r) \
|
#ifdef HAVE_ADDRINFO
|
||||||
do { \
|
#ifdef HAVE_GETADDRINFO
|
||||||
result = (r); \
|
#ifdef HAVE_GAISTRERROR
|
||||||
|
#define USE_GETADDRINFO
|
||||||
|
#endif
|
||||||
|
#endif
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#define CHECK(r) \
|
||||||
|
do { \
|
||||||
|
result = (r); \
|
||||||
if (result != ISC_R_SUCCESS) \
|
if (result != ISC_R_SUCCESS) \
|
||||||
goto cleanup; \
|
goto cleanup; \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
#define ERR_IS_CNAME 1
|
#define ERR_IS_CNAME 1
|
||||||
#define ERR_NO_ADDRESSES 2
|
#define ERR_NO_ADDRESSES 2
|
||||||
#define ERR_LOOKUP_FAILURE 3
|
#define ERR_LOOKUP_FAILURE 3
|
||||||
#define ERR_EXTRA_A 4
|
#define ERR_EXTRA_A 4
|
||||||
#define ERR_EXTRA_AAAA 5
|
#define ERR_EXTRA_AAAA 5
|
||||||
#define ERR_MISSING_GLUE 5
|
#define ERR_MISSING_GLUE 5
|
||||||
#define ERR_IS_MXCNAME 6
|
#define ERR_IS_MXCNAME 6
|
||||||
#define ERR_IS_SRVCNAME 7
|
#define ERR_IS_SRVCNAME 7
|
||||||
|
|
||||||
static const char *dbtype[] = { "rbt" };
|
static const char *dbtype[] = { "rbt" };
|
||||||
|
|
||||||
int debug = 0;
|
int debug = 0;
|
||||||
const char *journal = NULL;
|
isc_boolean_t nomerge = ISC_TRUE;
|
||||||
bool nomerge = true;
|
|
||||||
#if CHECK_LOCAL
|
#if CHECK_LOCAL
|
||||||
bool docheckmx = true;
|
isc_boolean_t docheckmx = ISC_TRUE;
|
||||||
bool dochecksrv = true;
|
isc_boolean_t dochecksrv = ISC_TRUE;
|
||||||
bool docheckns = true;
|
isc_boolean_t docheckns = ISC_TRUE;
|
||||||
#else /* if CHECK_LOCAL */
|
#else
|
||||||
bool docheckmx = false;
|
isc_boolean_t docheckmx = ISC_FALSE;
|
||||||
bool dochecksrv = false;
|
isc_boolean_t dochecksrv = ISC_FALSE;
|
||||||
bool docheckns = false;
|
isc_boolean_t docheckns = ISC_FALSE;
|
||||||
#endif /* if CHECK_LOCAL */
|
#endif
|
||||||
dns_zoneopt_t zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_CHECKMX |
|
unsigned int zone_options = DNS_ZONEOPT_CHECKNS |
|
||||||
DNS_ZONEOPT_MANYERRORS | DNS_ZONEOPT_CHECKNAMES |
|
DNS_ZONEOPT_CHECKMX |
|
||||||
DNS_ZONEOPT_CHECKINTEGRITY |
|
DNS_ZONEOPT_MANYERRORS |
|
||||||
|
DNS_ZONEOPT_CHECKNAMES |
|
||||||
|
DNS_ZONEOPT_CHECKINTEGRITY |
|
||||||
#if CHECK_SIBLING
|
#if CHECK_SIBLING
|
||||||
DNS_ZONEOPT_CHECKSIBLING |
|
DNS_ZONEOPT_CHECKSIBLING |
|
||||||
#endif /* if CHECK_SIBLING */
|
#endif
|
||||||
DNS_ZONEOPT_CHECKWILDCARD |
|
DNS_ZONEOPT_CHECKWILDCARD |
|
||||||
DNS_ZONEOPT_WARNMXCNAME | DNS_ZONEOPT_WARNSRVCNAME;
|
DNS_ZONEOPT_WARNMXCNAME |
|
||||||
|
DNS_ZONEOPT_WARNSRVCNAME;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* This needs to match the list in bin/named/log.c.
|
* This needs to match the list in bin/named/log.c.
|
||||||
*/
|
*/
|
||||||
static isc_logcategory_t categories[] = { { "", 0 },
|
static isc_logcategory_t categories[] = {
|
||||||
{ "unmatched", 0 },
|
{ "", 0 },
|
||||||
{ NULL, 0 } };
|
{ "client", 0 },
|
||||||
|
{ "network", 0 },
|
||||||
|
{ "update", 0 },
|
||||||
|
{ "queries", 0 },
|
||||||
|
{ "unmatched", 0 },
|
||||||
|
{ "update-security", 0 },
|
||||||
|
{ "query-errors", 0 },
|
||||||
|
{ NULL, 0 }
|
||||||
|
};
|
||||||
|
|
||||||
static isc_symtab_t *symtab = NULL;
|
static isc_symtab_t *symtab = NULL;
|
||||||
static isc_mem_t *sym_mctx;
|
static isc_mem_t *sym_mctx;
|
||||||
@@ -122,53 +139,55 @@ add(char *key, int value) {
|
|||||||
isc_symvalue_t symvalue;
|
isc_symvalue_t symvalue;
|
||||||
|
|
||||||
if (sym_mctx == NULL) {
|
if (sym_mctx == NULL) {
|
||||||
isc_mem_create(&sym_mctx);
|
result = isc_mem_create(0, 0, &sym_mctx);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (symtab == NULL) {
|
if (symtab == NULL) {
|
||||||
result = isc_symtab_create(sym_mctx, 100, freekey, sym_mctx,
|
result = isc_symtab_create(sym_mctx, 100, freekey, sym_mctx,
|
||||||
false, &symtab);
|
ISC_FALSE, &symtab);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
return;
|
return;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
key = isc_mem_strdup(sym_mctx, key);
|
key = isc_mem_strdup(sym_mctx, key);
|
||||||
|
if (key == NULL)
|
||||||
|
return;
|
||||||
|
|
||||||
symvalue.as_pointer = NULL;
|
symvalue.as_pointer = NULL;
|
||||||
result = isc_symtab_define(symtab, key, value, symvalue,
|
result = isc_symtab_define(symtab, key, value, symvalue,
|
||||||
isc_symexists_reject);
|
isc_symexists_reject);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
isc_mem_free(sym_mctx, key);
|
isc_mem_free(sym_mctx, key);
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
logged(char *key, int value) {
|
logged(char *key, int value) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
if (symtab == NULL) {
|
if (symtab == NULL)
|
||||||
return (false);
|
return (ISC_FALSE);
|
||||||
}
|
|
||||||
|
|
||||||
result = isc_symtab_lookup(symtab, key, value, NULL);
|
result = isc_symtab_lookup(symtab, key, value, NULL);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS)
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
return (ISC_FALSE);
|
||||||
return (false);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
checkns(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner,
|
||||||
dns_rdataset_t *a, dns_rdataset_t *aaaa) {
|
dns_rdataset_t *a, dns_rdataset_t *aaaa)
|
||||||
|
{
|
||||||
|
#ifdef USE_GETADDRINFO
|
||||||
dns_rdataset_t *rdataset;
|
dns_rdataset_t *rdataset;
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
struct addrinfo hints, *ai, *cur;
|
struct addrinfo hints, *ai, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
char addrbuf[sizeof("xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:123.123.123.123")];
|
char addrbuf[sizeof("xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:123.123.123.123")];
|
||||||
bool answer = true;
|
isc_boolean_t answer = ISC_TRUE;
|
||||||
bool match;
|
isc_boolean_t match;
|
||||||
const char *type;
|
const char *type;
|
||||||
void *ptr = NULL;
|
void *ptr = NULL;
|
||||||
int result;
|
int result;
|
||||||
@@ -177,11 +196,6 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
a->type == dns_rdatatype_a);
|
a->type == dns_rdatatype_a);
|
||||||
REQUIRE(aaaa == NULL || !dns_rdataset_isassociated(aaaa) ||
|
REQUIRE(aaaa == NULL || !dns_rdataset_isassociated(aaaa) ||
|
||||||
aaaa->type == dns_rdatatype_aaaa);
|
aaaa->type == dns_rdatatype_aaaa);
|
||||||
|
|
||||||
if (a == NULL || aaaa == NULL) {
|
|
||||||
return (answer);
|
|
||||||
}
|
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
memset(&hints, 0, sizeof(hints));
|
||||||
hints.ai_flags = AI_CANONNAME;
|
hints.ai_flags = AI_CANONNAME;
|
||||||
hints.ai_family = PF_UNSPEC;
|
hints.ai_family = PF_UNSPEC;
|
||||||
@@ -192,9 +206,8 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
*/
|
*/
|
||||||
if (dns_name_countlabels(name) > 1U) {
|
if (dns_name_countlabels(name) > 1U)
|
||||||
strlcat(namebuf, ".", sizeof(namebuf));
|
strcat(namebuf, ".");
|
||||||
}
|
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
@@ -207,26 +220,25 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
*/
|
*/
|
||||||
cur = ai;
|
cur = ai;
|
||||||
while (cur != NULL && cur->ai_canonname == NULL &&
|
while (cur != NULL && cur->ai_canonname == NULL &&
|
||||||
cur->ai_next != NULL) {
|
cur->ai_next != NULL)
|
||||||
cur = cur->ai_next;
|
cur = cur->ai_next;
|
||||||
}
|
|
||||||
if (cur != NULL && cur->ai_canonname != NULL &&
|
if (cur != NULL && cur->ai_canonname != NULL &&
|
||||||
strcasecmp(cur->ai_canonname, namebuf) != 0 &&
|
strcasecmp(cur->ai_canonname, namebuf) != 0 &&
|
||||||
!logged(namebuf, ERR_IS_CNAME))
|
!logged(namebuf, ERR_IS_CNAME)) {
|
||||||
{
|
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||||
"%s/NS '%s' (out of zone) "
|
"%s/NS '%s' (out of zone) "
|
||||||
"is a CNAME '%s' (illegal)",
|
"is a CNAME '%s' (illegal)",
|
||||||
ownerbuf, namebuf, cur->ai_canonname);
|
ownerbuf, namebuf,
|
||||||
|
cur->ai_canonname);
|
||||||
/* XXX950 make fatal for 9.5.0 */
|
/* XXX950 make fatal for 9.5.0 */
|
||||||
/* answer = false; */
|
/* answer = ISC_FALSE; */
|
||||||
add(namebuf, ERR_IS_CNAME);
|
add(namebuf, ERR_IS_CNAME);
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case EAI_NONAME:
|
case EAI_NONAME:
|
||||||
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
||||||
case EAI_NODATA:
|
case EAI_NODATA:
|
||||||
#endif /* if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME) */
|
#endif
|
||||||
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||||
"%s/NS '%s' (out of zone) "
|
"%s/NS '%s' (out of zone) "
|
||||||
@@ -235,154 +247,144 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
|||||||
add(namebuf, ERR_NO_ADDRESSES);
|
add(namebuf, ERR_NO_ADDRESSES);
|
||||||
}
|
}
|
||||||
/* XXX950 make fatal for 9.5.0 */
|
/* XXX950 make fatal for 9.5.0 */
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
|
|
||||||
default:
|
default:
|
||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s",
|
||||||
gai_strerror(result));
|
namebuf, gai_strerror(result));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
|
if (a == NULL || aaaa == NULL)
|
||||||
|
return (answer);
|
||||||
/*
|
/*
|
||||||
* Check that all glue records really exist.
|
* Check that all glue records really exist.
|
||||||
*/
|
*/
|
||||||
if (!dns_rdataset_isassociated(a)) {
|
if (!dns_rdataset_isassociated(a))
|
||||||
goto checkaaaa;
|
goto checkaaaa;
|
||||||
}
|
|
||||||
result = dns_rdataset_first(a);
|
result = dns_rdataset_first(a);
|
||||||
while (result == ISC_R_SUCCESS) {
|
while (result == ISC_R_SUCCESS) {
|
||||||
dns_rdataset_current(a, &rdata);
|
dns_rdataset_current(a, &rdata);
|
||||||
match = false;
|
match = ISC_FALSE;
|
||||||
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
||||||
if (cur->ai_family != AF_INET) {
|
if (cur->ai_family != AF_INET)
|
||||||
continue;
|
continue;
|
||||||
}
|
|
||||||
ptr = &((struct sockaddr_in *)(cur->ai_addr))->sin_addr;
|
ptr = &((struct sockaddr_in *)(cur->ai_addr))->sin_addr;
|
||||||
if (memcmp(ptr, rdata.data, rdata.length) == 0) {
|
if (memcmp(ptr, rdata.data, rdata.length) == 0) {
|
||||||
match = true;
|
match = ISC_TRUE;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (!match && !logged(namebuf, ERR_EXTRA_A)) {
|
if (!match && !logged(namebuf, ERR_EXTRA_A)) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR, "%s/NS '%s' "
|
||||||
"%s/NS '%s' "
|
|
||||||
"extra GLUE A record (%s)",
|
"extra GLUE A record (%s)",
|
||||||
ownerbuf, namebuf,
|
ownerbuf, namebuf,
|
||||||
inet_ntop(AF_INET, rdata.data, addrbuf,
|
inet_ntop(AF_INET, rdata.data,
|
||||||
sizeof(addrbuf)));
|
addrbuf, sizeof(addrbuf)));
|
||||||
add(namebuf, ERR_EXTRA_A);
|
add(namebuf, ERR_EXTRA_A);
|
||||||
/* XXX950 make fatal for 9.5.0 */
|
/* XXX950 make fatal for 9.5.0 */
|
||||||
/* answer = false; */
|
/* answer = ISC_FALSE; */
|
||||||
}
|
}
|
||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
result = dns_rdataset_next(a);
|
result = dns_rdataset_next(a);
|
||||||
}
|
}
|
||||||
|
|
||||||
checkaaaa:
|
checkaaaa:
|
||||||
if (!dns_rdataset_isassociated(aaaa)) {
|
if (!dns_rdataset_isassociated(aaaa))
|
||||||
goto checkmissing;
|
goto checkmissing;
|
||||||
}
|
|
||||||
result = dns_rdataset_first(aaaa);
|
result = dns_rdataset_first(aaaa);
|
||||||
while (result == ISC_R_SUCCESS) {
|
while (result == ISC_R_SUCCESS) {
|
||||||
dns_rdataset_current(aaaa, &rdata);
|
dns_rdataset_current(aaaa, &rdata);
|
||||||
match = false;
|
match = ISC_FALSE;
|
||||||
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
||||||
if (cur->ai_family != AF_INET6) {
|
if (cur->ai_family != AF_INET6)
|
||||||
continue;
|
continue;
|
||||||
}
|
ptr = &((struct sockaddr_in6 *)(cur->ai_addr))->sin6_addr;
|
||||||
ptr = &((struct sockaddr_in6 *)(cur->ai_addr))
|
|
||||||
->sin6_addr;
|
|
||||||
if (memcmp(ptr, rdata.data, rdata.length) == 0) {
|
if (memcmp(ptr, rdata.data, rdata.length) == 0) {
|
||||||
match = true;
|
match = ISC_TRUE;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (!match && !logged(namebuf, ERR_EXTRA_AAAA)) {
|
if (!match && !logged(namebuf, ERR_EXTRA_AAAA)) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR, "%s/NS '%s' "
|
||||||
"%s/NS '%s' "
|
|
||||||
"extra GLUE AAAA record (%s)",
|
"extra GLUE AAAA record (%s)",
|
||||||
ownerbuf, namebuf,
|
ownerbuf, namebuf,
|
||||||
inet_ntop(AF_INET6, rdata.data, addrbuf,
|
inet_ntop(AF_INET6, rdata.data,
|
||||||
sizeof(addrbuf)));
|
addrbuf, sizeof(addrbuf)));
|
||||||
add(namebuf, ERR_EXTRA_AAAA);
|
add(namebuf, ERR_EXTRA_AAAA);
|
||||||
/* XXX950 make fatal for 9.5.0. */
|
/* XXX950 make fatal for 9.5.0. */
|
||||||
/* answer = false; */
|
/* answer = ISC_FALSE; */
|
||||||
}
|
}
|
||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
result = dns_rdataset_next(aaaa);
|
result = dns_rdataset_next(aaaa);
|
||||||
}
|
}
|
||||||
|
|
||||||
checkmissing:
|
checkmissing:
|
||||||
/*
|
/*
|
||||||
* Check that all addresses appear in the glue.
|
* Check that all addresses appear in the glue.
|
||||||
*/
|
*/
|
||||||
if (!logged(namebuf, ERR_MISSING_GLUE)) {
|
if (!logged(namebuf, ERR_MISSING_GLUE)) {
|
||||||
bool missing_glue = false;
|
isc_boolean_t missing_glue = ISC_FALSE;
|
||||||
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
for (cur = ai; cur != NULL; cur = cur->ai_next) {
|
||||||
switch (cur->ai_family) {
|
switch (cur->ai_family) {
|
||||||
case AF_INET:
|
case AF_INET:
|
||||||
rdataset = a;
|
rdataset = a;
|
||||||
ptr = &((struct sockaddr_in *)(cur->ai_addr))
|
ptr = &((struct sockaddr_in *)(cur->ai_addr))->sin_addr;
|
||||||
->sin_addr;
|
|
||||||
type = "A";
|
type = "A";
|
||||||
break;
|
break;
|
||||||
case AF_INET6:
|
case AF_INET6:
|
||||||
rdataset = aaaa;
|
rdataset = aaaa;
|
||||||
ptr = &((struct sockaddr_in6 *)(cur->ai_addr))
|
ptr = &((struct sockaddr_in6 *)(cur->ai_addr))->sin6_addr;
|
||||||
->sin6_addr;
|
|
||||||
type = "AAAA";
|
type = "AAAA";
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
match = false;
|
match = ISC_FALSE;
|
||||||
if (dns_rdataset_isassociated(rdataset)) {
|
if (dns_rdataset_isassociated(rdataset))
|
||||||
result = dns_rdataset_first(rdataset);
|
result = dns_rdataset_first(rdataset);
|
||||||
} else {
|
else
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
}
|
|
||||||
while (result == ISC_R_SUCCESS && !match) {
|
while (result == ISC_R_SUCCESS && !match) {
|
||||||
dns_rdataset_current(rdataset, &rdata);
|
dns_rdataset_current(rdataset, &rdata);
|
||||||
if (memcmp(ptr, rdata.data, rdata.length) == 0)
|
if (memcmp(ptr, rdata.data, rdata.length) == 0)
|
||||||
{
|
match = ISC_TRUE;
|
||||||
match = true;
|
|
||||||
}
|
|
||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
result = dns_rdataset_next(rdataset);
|
result = dns_rdataset_next(rdataset);
|
||||||
}
|
}
|
||||||
if (!match) {
|
if (!match) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR, "%s/NS '%s' "
|
||||||
"%s/NS '%s' "
|
|
||||||
"missing GLUE %s record (%s)",
|
"missing GLUE %s record (%s)",
|
||||||
ownerbuf, namebuf, type,
|
ownerbuf, namebuf, type,
|
||||||
inet_ntop(cur->ai_family, ptr,
|
inet_ntop(cur->ai_family, ptr,
|
||||||
addrbuf,
|
addrbuf, sizeof(addrbuf)));
|
||||||
sizeof(addrbuf)));
|
|
||||||
/* XXX950 make fatal for 9.5.0. */
|
/* XXX950 make fatal for 9.5.0. */
|
||||||
/* answer = false; */
|
/* answer = ISC_FALSE; */
|
||||||
missing_glue = true;
|
missing_glue = ISC_TRUE;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (missing_glue) {
|
if (missing_glue)
|
||||||
add(namebuf, ERR_MISSING_GLUE);
|
add(namebuf, ERR_MISSING_GLUE);
|
||||||
}
|
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
freeaddrinfo(ai);
|
||||||
return (answer);
|
return (answer);
|
||||||
|
#else
|
||||||
|
return (ISC_TRUE);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
checkmx(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||||
|
#ifdef USE_GETADDRINFO
|
||||||
struct addrinfo hints, *ai, *cur;
|
struct addrinfo hints, *ai, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
int result;
|
int result;
|
||||||
int level = ISC_LOG_ERROR;
|
int level = ISC_LOG_ERROR;
|
||||||
bool answer = true;
|
isc_boolean_t answer = ISC_TRUE;
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
memset(&hints, 0, sizeof(hints));
|
||||||
hints.ai_flags = AI_CANONNAME;
|
hints.ai_flags = AI_CANONNAME;
|
||||||
@@ -394,9 +396,8 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
*/
|
*/
|
||||||
if (dns_name_countlabels(name) > 1U) {
|
if (dns_name_countlabels(name) > 1U)
|
||||||
strlcat(namebuf, ".", sizeof(namebuf));
|
strcat(namebuf, ".");
|
||||||
}
|
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
@@ -409,15 +410,12 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
*/
|
*/
|
||||||
cur = ai;
|
cur = ai;
|
||||||
while (cur != NULL && cur->ai_canonname == NULL &&
|
while (cur != NULL && cur->ai_canonname == NULL &&
|
||||||
cur->ai_next != NULL) {
|
cur->ai_next != NULL)
|
||||||
cur = cur->ai_next;
|
cur = cur->ai_next;
|
||||||
}
|
|
||||||
if (cur != NULL && cur->ai_canonname != NULL &&
|
if (cur != NULL && cur->ai_canonname != NULL &&
|
||||||
strcasecmp(cur->ai_canonname, namebuf) != 0)
|
strcasecmp(cur->ai_canonname, namebuf) != 0) {
|
||||||
{
|
if ((zone_options & DNS_ZONEOPT_WARNMXCNAME) != 0)
|
||||||
if ((zone_options & DNS_ZONEOPT_WARNMXCNAME) != 0) {
|
|
||||||
level = ISC_LOG_WARNING;
|
level = ISC_LOG_WARNING;
|
||||||
}
|
|
||||||
if ((zone_options & DNS_ZONEOPT_IGNOREMXCNAME) == 0) {
|
if ((zone_options & DNS_ZONEOPT_IGNOREMXCNAME) == 0) {
|
||||||
if (!logged(namebuf, ERR_IS_MXCNAME)) {
|
if (!logged(namebuf, ERR_IS_MXCNAME)) {
|
||||||
dns_zone_log(zone, level,
|
dns_zone_log(zone, level,
|
||||||
@@ -428,9 +426,8 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
cur->ai_canonname);
|
cur->ai_canonname);
|
||||||
add(namebuf, ERR_IS_MXCNAME);
|
add(namebuf, ERR_IS_MXCNAME);
|
||||||
}
|
}
|
||||||
if (level == ISC_LOG_ERROR) {
|
if (level == ISC_LOG_ERROR)
|
||||||
answer = false;
|
answer = ISC_FALSE;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
freeaddrinfo(ai);
|
||||||
@@ -439,7 +436,7 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
case EAI_NONAME:
|
case EAI_NONAME:
|
||||||
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
||||||
case EAI_NODATA:
|
case EAI_NODATA:
|
||||||
#endif /* if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME) */
|
#endif
|
||||||
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||||
"%s/MX '%s' (out of zone) "
|
"%s/MX '%s' (out of zone) "
|
||||||
@@ -448,27 +445,31 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
add(namebuf, ERR_NO_ADDRESSES);
|
add(namebuf, ERR_NO_ADDRESSES);
|
||||||
}
|
}
|
||||||
/* XXX950 make fatal for 9.5.0. */
|
/* XXX950 make fatal for 9.5.0. */
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
|
|
||||||
default:
|
default:
|
||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s",
|
||||||
gai_strerror(result));
|
namebuf, gai_strerror(result));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
|
#else
|
||||||
|
return (ISC_TRUE);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
checksrv(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||||
|
#ifdef USE_GETADDRINFO
|
||||||
struct addrinfo hints, *ai, *cur;
|
struct addrinfo hints, *ai, *cur;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
char namebuf[DNS_NAME_FORMATSIZE + 1];
|
||||||
char ownerbuf[DNS_NAME_FORMATSIZE];
|
char ownerbuf[DNS_NAME_FORMATSIZE];
|
||||||
int result;
|
int result;
|
||||||
int level = ISC_LOG_ERROR;
|
int level = ISC_LOG_ERROR;
|
||||||
bool answer = true;
|
isc_boolean_t answer = ISC_TRUE;
|
||||||
|
|
||||||
memset(&hints, 0, sizeof(hints));
|
memset(&hints, 0, sizeof(hints));
|
||||||
hints.ai_flags = AI_CANONNAME;
|
hints.ai_flags = AI_CANONNAME;
|
||||||
@@ -480,9 +481,8 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
/*
|
/*
|
||||||
* Turn off search.
|
* Turn off search.
|
||||||
*/
|
*/
|
||||||
if (dns_name_countlabels(name) > 1U) {
|
if (dns_name_countlabels(name) > 1U)
|
||||||
strlcat(namebuf, ".", sizeof(namebuf));
|
strcat(namebuf, ".");
|
||||||
}
|
|
||||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||||
|
|
||||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||||
@@ -495,28 +495,23 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
*/
|
*/
|
||||||
cur = ai;
|
cur = ai;
|
||||||
while (cur != NULL && cur->ai_canonname == NULL &&
|
while (cur != NULL && cur->ai_canonname == NULL &&
|
||||||
cur->ai_next != NULL) {
|
cur->ai_next != NULL)
|
||||||
cur = cur->ai_next;
|
cur = cur->ai_next;
|
||||||
}
|
|
||||||
if (cur != NULL && cur->ai_canonname != NULL &&
|
if (cur != NULL && cur->ai_canonname != NULL &&
|
||||||
strcasecmp(cur->ai_canonname, namebuf) != 0)
|
strcasecmp(cur->ai_canonname, namebuf) != 0) {
|
||||||
{
|
if ((zone_options & DNS_ZONEOPT_WARNSRVCNAME) != 0)
|
||||||
if ((zone_options & DNS_ZONEOPT_WARNSRVCNAME) != 0) {
|
|
||||||
level = ISC_LOG_WARNING;
|
level = ISC_LOG_WARNING;
|
||||||
}
|
|
||||||
if ((zone_options & DNS_ZONEOPT_IGNORESRVCNAME) == 0) {
|
if ((zone_options & DNS_ZONEOPT_IGNORESRVCNAME) == 0) {
|
||||||
if (!logged(namebuf, ERR_IS_SRVCNAME)) {
|
if (!logged(namebuf, ERR_IS_SRVCNAME)) {
|
||||||
dns_zone_log(zone, level,
|
dns_zone_log(zone, level, "%s/SRV '%s'"
|
||||||
"%s/SRV '%s'"
|
|
||||||
" (out of zone) is a "
|
" (out of zone) is a "
|
||||||
"CNAME '%s' (illegal)",
|
"CNAME '%s' (illegal)",
|
||||||
ownerbuf, namebuf,
|
ownerbuf, namebuf,
|
||||||
cur->ai_canonname);
|
cur->ai_canonname);
|
||||||
add(namebuf, ERR_IS_SRVCNAME);
|
add(namebuf, ERR_IS_SRVCNAME);
|
||||||
}
|
}
|
||||||
if (level == ISC_LOG_ERROR) {
|
if (level == ISC_LOG_ERROR)
|
||||||
answer = false;
|
answer = ISC_FALSE;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
freeaddrinfo(ai);
|
freeaddrinfo(ai);
|
||||||
@@ -525,7 +520,7 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
case EAI_NONAME:
|
case EAI_NONAME:
|
||||||
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
#if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME)
|
||||||
case EAI_NODATA:
|
case EAI_NODATA:
|
||||||
#endif /* if defined(EAI_NODATA) && (EAI_NODATA != EAI_NONAME) */
|
#endif
|
||||||
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
if (!logged(namebuf, ERR_NO_ADDRESSES)) {
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||||
"%s/SRV '%s' (out of zone) "
|
"%s/SRV '%s' (out of zone) "
|
||||||
@@ -534,17 +529,20 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
|||||||
add(namebuf, ERR_NO_ADDRESSES);
|
add(namebuf, ERR_NO_ADDRESSES);
|
||||||
}
|
}
|
||||||
/* XXX950 make fatal for 9.5.0. */
|
/* XXX950 make fatal for 9.5.0. */
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
|
|
||||||
default:
|
default:
|
||||||
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
if (!logged(namebuf, ERR_LOOKUP_FAILURE)) {
|
||||||
dns_zone_log(zone, ISC_LOG_WARNING,
|
dns_zone_log(zone, ISC_LOG_WARNING,
|
||||||
"getaddrinfo(%s) failed: %s", namebuf,
|
"getaddrinfo(%s) failed: %s",
|
||||||
gai_strerror(result));
|
namebuf, gai_strerror(result));
|
||||||
add(namebuf, ERR_LOOKUP_FAILURE);
|
add(namebuf, ERR_LOOKUP_FAILURE);
|
||||||
}
|
}
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
|
#else
|
||||||
|
return (ISC_TRUE);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
@@ -553,123 +551,34 @@ setup_logging(isc_mem_t *mctx, FILE *errout, isc_log_t **logp) {
|
|||||||
isc_logconfig_t *logconfig = NULL;
|
isc_logconfig_t *logconfig = NULL;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
|
||||||
isc_log_create(mctx, &log, &logconfig);
|
RUNTIME_CHECK(isc_log_create(mctx, &log, &logconfig) == ISC_R_SUCCESS);
|
||||||
isc_log_registercategories(log, categories);
|
isc_log_registercategories(log, categories);
|
||||||
isc_log_setcontext(log);
|
isc_log_setcontext(log);
|
||||||
dns_log_init(log);
|
dns_log_init(log);
|
||||||
dns_log_setcontext(log);
|
dns_log_setcontext(log);
|
||||||
cfg_log_init(log);
|
cfg_log_init(log);
|
||||||
ns_log_init(log);
|
|
||||||
|
|
||||||
destination.file.stream = errout;
|
destination.file.stream = errout;
|
||||||
destination.file.name = NULL;
|
destination.file.name = NULL;
|
||||||
destination.file.versions = ISC_LOG_ROLLNEVER;
|
destination.file.versions = ISC_LOG_ROLLNEVER;
|
||||||
destination.file.maximum_size = 0;
|
destination.file.maximum_size = 0;
|
||||||
isc_log_createchannel(logconfig, "stderr", ISC_LOG_TOFILEDESC,
|
RUNTIME_CHECK(isc_log_createchannel(logconfig, "stderr",
|
||||||
ISC_LOG_DYNAMIC, &destination, 0);
|
ISC_LOG_TOFILEDESC,
|
||||||
|
ISC_LOG_DYNAMIC,
|
||||||
RUNTIME_CHECK(isc_log_usechannel(logconfig, "stderr", NULL, NULL) ==
|
&destination, 0) == ISC_R_SUCCESS);
|
||||||
ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_log_usechannel(logconfig, "stderr",
|
||||||
|
NULL, NULL) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
*logp = log;
|
*logp = log;
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% scan the zone for oversize TTLs */
|
|
||||||
static isc_result_t
|
|
||||||
check_ttls(dns_zone_t *zone, dns_ttl_t maxttl) {
|
|
||||||
isc_result_t result;
|
|
||||||
dns_db_t *db = NULL;
|
|
||||||
dns_dbversion_t *version = NULL;
|
|
||||||
dns_dbnode_t *node = NULL;
|
|
||||||
dns_dbiterator_t *dbiter = NULL;
|
|
||||||
dns_rdatasetiter_t *rdsiter = NULL;
|
|
||||||
dns_rdataset_t rdataset;
|
|
||||||
dns_fixedname_t fname;
|
|
||||||
dns_name_t *name;
|
|
||||||
name = dns_fixedname_initname(&fname);
|
|
||||||
dns_rdataset_init(&rdataset);
|
|
||||||
|
|
||||||
CHECK(dns_zone_getdb(zone, &db));
|
|
||||||
INSIST(db != NULL);
|
|
||||||
|
|
||||||
CHECK(dns_db_newversion(db, &version));
|
|
||||||
CHECK(dns_db_createiterator(db, 0, &dbiter));
|
|
||||||
|
|
||||||
for (result = dns_dbiterator_first(dbiter); result == ISC_R_SUCCESS;
|
|
||||||
result = dns_dbiterator_next(dbiter))
|
|
||||||
{
|
|
||||||
result = dns_dbiterator_current(dbiter, &node, name);
|
|
||||||
if (result == DNS_R_NEWORIGIN) {
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
CHECK(result);
|
|
||||||
|
|
||||||
CHECK(dns_db_allrdatasets(db, node, version, 0, &rdsiter));
|
|
||||||
for (result = dns_rdatasetiter_first(rdsiter);
|
|
||||||
result == ISC_R_SUCCESS;
|
|
||||||
result = dns_rdatasetiter_next(rdsiter))
|
|
||||||
{
|
|
||||||
dns_rdatasetiter_current(rdsiter, &rdataset);
|
|
||||||
if (rdataset.ttl > maxttl) {
|
|
||||||
char nbuf[DNS_NAME_FORMATSIZE];
|
|
||||||
char tbuf[255];
|
|
||||||
isc_buffer_t b;
|
|
||||||
isc_region_t r;
|
|
||||||
|
|
||||||
dns_name_format(name, nbuf, sizeof(nbuf));
|
|
||||||
isc_buffer_init(&b, tbuf, sizeof(tbuf) - 1);
|
|
||||||
CHECK(dns_rdatatype_totext(rdataset.type, &b));
|
|
||||||
isc_buffer_usedregion(&b, &r);
|
|
||||||
r.base[r.length] = 0;
|
|
||||||
|
|
||||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
|
||||||
"%s/%s TTL %d exceeds "
|
|
||||||
"maximum TTL %d",
|
|
||||||
nbuf, tbuf, rdataset.ttl, maxttl);
|
|
||||||
dns_rdataset_disassociate(&rdataset);
|
|
||||||
CHECK(ISC_R_RANGE);
|
|
||||||
}
|
|
||||||
dns_rdataset_disassociate(&rdataset);
|
|
||||||
}
|
|
||||||
if (result == ISC_R_NOMORE) {
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
CHECK(result);
|
|
||||||
|
|
||||||
dns_rdatasetiter_destroy(&rdsiter);
|
|
||||||
dns_db_detachnode(db, &node);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (result == ISC_R_NOMORE) {
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
cleanup:
|
|
||||||
if (node != NULL) {
|
|
||||||
dns_db_detachnode(db, &node);
|
|
||||||
}
|
|
||||||
if (rdsiter != NULL) {
|
|
||||||
dns_rdatasetiter_destroy(&rdsiter);
|
|
||||||
}
|
|
||||||
if (dbiter != NULL) {
|
|
||||||
dns_dbiterator_destroy(&dbiter);
|
|
||||||
}
|
|
||||||
if (version != NULL) {
|
|
||||||
dns_db_closeversion(db, &version, false);
|
|
||||||
}
|
|
||||||
if (db != NULL) {
|
|
||||||
dns_db_detach(&db);
|
|
||||||
}
|
|
||||||
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*% load the zone */
|
/*% load the zone */
|
||||||
isc_result_t
|
isc_result_t
|
||||||
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||||
dns_masterformat_t fileformat, const char *classname,
|
dns_masterformat_t fileformat, const char *classname,
|
||||||
dns_ttl_t maxttl, dns_zone_t **zonep) {
|
dns_zone_t **zonep)
|
||||||
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
isc_textregion_t region;
|
isc_textregion_t region;
|
||||||
@@ -680,111 +589,80 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
|
|
||||||
REQUIRE(zonep == NULL || *zonep == NULL);
|
REQUIRE(zonep == NULL || *zonep == NULL);
|
||||||
|
|
||||||
if (debug) {
|
if (debug)
|
||||||
fprintf(stderr, "loading \"%s\" from \"%s\" class \"%s\"\n",
|
fprintf(stderr, "loading \"%s\" from \"%s\" class \"%s\"\n",
|
||||||
zonename, filename, classname);
|
zonename, filename, classname);
|
||||||
}
|
|
||||||
|
|
||||||
CHECK(dns_zone_create(&zone, mctx));
|
CHECK(dns_zone_create(&zone, mctx));
|
||||||
|
|
||||||
dns_zone_settype(zone, dns_zone_master);
|
dns_zone_settype(zone, dns_zone_master);
|
||||||
|
|
||||||
isc_buffer_constinit(&buffer, zonename, strlen(zonename));
|
isc_buffer_init(&buffer, zonename, strlen(zonename));
|
||||||
isc_buffer_add(&buffer, strlen(zonename));
|
isc_buffer_add(&buffer, strlen(zonename));
|
||||||
origin = dns_fixedname_initname(&fixorigin);
|
dns_fixedname_init(&fixorigin);
|
||||||
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
origin = dns_fixedname_name(&fixorigin);
|
||||||
|
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname,
|
||||||
|
ISC_FALSE, NULL));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
CHECK(dns_zone_setorigin(zone, origin));
|
||||||
dns_zone_setdbtype(zone, 1, (const char *const *)dbtype);
|
CHECK(dns_zone_setdbtype(zone, 1, (const char * const *) dbtype));
|
||||||
if (strcmp(filename, "-") == 0) {
|
CHECK(dns_zone_setfile2(zone, filename, fileformat));
|
||||||
CHECK(dns_zone_setstream(zone, stdin, fileformat,
|
|
||||||
&dns_master_style_default));
|
|
||||||
} else {
|
|
||||||
CHECK(dns_zone_setfile(zone, filename, fileformat,
|
|
||||||
&dns_master_style_default));
|
|
||||||
}
|
|
||||||
if (journal != NULL) {
|
|
||||||
CHECK(dns_zone_setjournal(zone, journal));
|
|
||||||
}
|
|
||||||
|
|
||||||
DE_CONST(classname, region.base);
|
DE_CONST(classname, region.base);
|
||||||
region.length = strlen(classname);
|
region.length = strlen(classname);
|
||||||
CHECK(dns_rdataclass_fromtext(&rdclass, ®ion));
|
CHECK(dns_rdataclass_fromtext(&rdclass, ®ion));
|
||||||
|
|
||||||
dns_zone_setclass(zone, rdclass);
|
dns_zone_setclass(zone, rdclass);
|
||||||
dns_zone_setoption(zone, zone_options, true);
|
dns_zone_setoption(zone, zone_options, ISC_TRUE);
|
||||||
dns_zone_setoption(zone, DNS_ZONEOPT_NOMERGE, nomerge);
|
dns_zone_setoption(zone, DNS_ZONEOPT_NOMERGE, nomerge);
|
||||||
|
if (docheckmx)
|
||||||
dns_zone_setmaxttl(zone, maxttl);
|
|
||||||
|
|
||||||
if (docheckmx) {
|
|
||||||
dns_zone_setcheckmx(zone, checkmx);
|
dns_zone_setcheckmx(zone, checkmx);
|
||||||
}
|
if (docheckns)
|
||||||
if (docheckns) {
|
|
||||||
dns_zone_setcheckns(zone, checkns);
|
dns_zone_setcheckns(zone, checkns);
|
||||||
}
|
if (dochecksrv)
|
||||||
if (dochecksrv) {
|
|
||||||
dns_zone_setchecksrv(zone, checksrv);
|
dns_zone_setchecksrv(zone, checksrv);
|
||||||
}
|
|
||||||
|
|
||||||
CHECK(dns_zone_load(zone, false));
|
|
||||||
|
|
||||||
/*
|
|
||||||
* When loading map files we can't catch oversize TTLs during
|
|
||||||
* load, so we check for them here.
|
|
||||||
*/
|
|
||||||
if (fileformat == dns_masterformat_map && maxttl != 0) {
|
|
||||||
CHECK(check_ttls(zone, maxttl));
|
|
||||||
}
|
|
||||||
|
|
||||||
|
CHECK(dns_zone_load(zone));
|
||||||
if (zonep != NULL) {
|
if (zonep != NULL) {
|
||||||
*zonep = zone;
|
*zonep = zone;
|
||||||
zone = NULL;
|
zone = NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (zone != NULL) {
|
if (zone != NULL)
|
||||||
dns_zone_detach(&zone);
|
dns_zone_detach(&zone);
|
||||||
}
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% dump the zone */
|
/*% dump the zone */
|
||||||
isc_result_t
|
isc_result_t
|
||||||
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
||||||
dns_masterformat_t fileformat, const dns_master_style_t *style,
|
dns_masterformat_t fileformat, const dns_master_style_t *style)
|
||||||
const uint32_t rawversion) {
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
FILE *output = stdout;
|
FILE *output = stdout;
|
||||||
const char *flags;
|
|
||||||
|
|
||||||
flags = (fileformat == dns_masterformat_text) ? "w" : "wb";
|
|
||||||
|
|
||||||
if (debug) {
|
if (debug) {
|
||||||
if (filename != NULL && strcmp(filename, "-") != 0) {
|
if (filename != NULL && strcmp(filename, "-") != 0)
|
||||||
fprintf(stderr, "dumping \"%s\" to \"%s\"\n", zonename,
|
fprintf(stderr, "dumping \"%s\" to \"%s\"\n",
|
||||||
filename);
|
zonename, filename);
|
||||||
} else {
|
else
|
||||||
fprintf(stderr, "dumping \"%s\"\n", zonename);
|
fprintf(stderr, "dumping \"%s\"\n", zonename);
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (filename != NULL && strcmp(filename, "-") != 0) {
|
if (filename != NULL && strcmp(filename, "-") != 0) {
|
||||||
result = isc_stdio_open(filename, flags, &output);
|
result = isc_stdio_open(filename, "w+", &output);
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fprintf(stderr,
|
fprintf(stderr, "could not open output "
|
||||||
"could not open output "
|
"file \"%s\" for writing\n", filename);
|
||||||
"file \"%s\" for writing\n",
|
|
||||||
filename);
|
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_zone_dumptostream(zone, output, fileformat, style,
|
result = dns_zone_dumptostream2(zone, output, fileformat, style);
|
||||||
rawversion);
|
|
||||||
if (output != stdout) {
|
if (output != stdout)
|
||||||
(void)isc_stdio_close(output);
|
(void)isc_stdio_close(output);
|
||||||
}
|
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -798,7 +676,7 @@ InitSockets(void) {
|
|||||||
|
|
||||||
wVersionRequested = MAKEWORD(2, 0);
|
wVersionRequested = MAKEWORD(2, 0);
|
||||||
|
|
||||||
err = WSAStartup(wVersionRequested, &wsaData);
|
err = WSAStartup( wVersionRequested, &wsaData );
|
||||||
if (err != 0) {
|
if (err != 0) {
|
||||||
fprintf(stderr, "WSAStartup() failed: %d\n", err);
|
fprintf(stderr, "WSAStartup() failed: %d\n", err);
|
||||||
exit(1);
|
exit(1);
|
||||||
@@ -809,4 +687,5 @@ void
|
|||||||
DestroySockets(void) {
|
DestroySockets(void) {
|
||||||
WSACleanup();
|
WSACleanup();
|
||||||
}
|
}
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
|
|||||||
+25
-25
@@ -1,29 +1,33 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2004, 2005, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
* Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
* copyright notice and this permission notice appear in all copies.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
* information regarding copyright ownership.
|
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
* PERFORMANCE OF THIS SOFTWARE.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: check-tool.h,v 1.14.628.2 2010/09/07 23:46:26 tbox Exp $ */
|
||||||
|
|
||||||
#ifndef CHECK_TOOL_H
|
#ifndef CHECK_TOOL_H
|
||||||
#define CHECK_TOOL_H
|
#define CHECK_TOOL_H
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <inttypes.h>
|
|
||||||
#include <stdbool.h>
|
|
||||||
|
|
||||||
#include <isc/lang.h>
|
#include <isc/lang.h>
|
||||||
#include <isc/stdio.h>
|
#include <isc/stdio.h>
|
||||||
#include <isc/types.h>
|
#include <isc/types.h>
|
||||||
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
#include <dns/zone.h>
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
@@ -33,28 +37,24 @@ setup_logging(isc_mem_t *mctx, FILE *errout, isc_log_t **logp);
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||||
dns_masterformat_t fileformat, const char *classname,
|
dns_masterformat_t fileformat, const char *classname,
|
||||||
dns_ttl_t maxttl, dns_zone_t **zonep);
|
dns_zone_t **zonep);
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
||||||
dns_masterformat_t fileformat, const dns_master_style_t *style,
|
dns_masterformat_t fileformat, const dns_master_style_t *style);
|
||||||
const uint32_t rawversion);
|
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
void
|
void InitSockets(void);
|
||||||
InitSockets(void);
|
void DestroySockets(void);
|
||||||
void
|
#endif
|
||||||
DestroySockets(void);
|
|
||||||
#endif /* ifdef _WIN32 */
|
|
||||||
|
|
||||||
extern int debug;
|
extern int debug;
|
||||||
extern const char *journal;
|
extern isc_boolean_t nomerge;
|
||||||
extern bool nomerge;
|
extern isc_boolean_t docheckmx;
|
||||||
extern bool docheckmx;
|
extern isc_boolean_t docheckns;
|
||||||
extern bool docheckns;
|
extern isc_boolean_t dochecksrv;
|
||||||
extern bool dochecksrv;
|
extern unsigned int zone_options;
|
||||||
extern dns_zoneopt_t zone_options;
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
ISC_LANG_ENDDECLS
|
||||||
|
|
||||||
#endif /* ifndef CHECK_TOOL_H */
|
#endif
|
||||||
|
|||||||
@@ -0,0 +1,94 @@
|
|||||||
|
.\" Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
.\" Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
.\"
|
||||||
|
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
.\" purpose with or without fee is hereby granted, provided that the above
|
||||||
|
.\" copyright notice and this permission notice appear in all copies.
|
||||||
|
.\"
|
||||||
|
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
.\"
|
||||||
|
.\" $Id: named-checkconf.8,v 1.30.334.1 2009/07/11 01:55:20 tbox Exp $
|
||||||
|
.\"
|
||||||
|
.hy 0
|
||||||
|
.ad l
|
||||||
|
.\" Title: named\-checkconf
|
||||||
|
.\" Author:
|
||||||
|
.\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>
|
||||||
|
.\" Date: June 14, 2000
|
||||||
|
.\" Manual: BIND9
|
||||||
|
.\" Source: BIND9
|
||||||
|
.\"
|
||||||
|
.TH "NAMED\-CHECKCONF" "8" "June 14, 2000" "BIND9" "BIND9"
|
||||||
|
.\" disable hyphenation
|
||||||
|
.nh
|
||||||
|
.\" disable justification (adjust text to left margin only)
|
||||||
|
.ad l
|
||||||
|
.SH "NAME"
|
||||||
|
named\-checkconf \- named configuration file syntax checking tool
|
||||||
|
.SH "SYNOPSIS"
|
||||||
|
.HP 16
|
||||||
|
\fBnamed\-checkconf\fR [\fB\-h\fR] [\fB\-v\fR] [\fB\-j\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] {filename} [\fB\-z\fR]
|
||||||
|
.SH "DESCRIPTION"
|
||||||
|
.PP
|
||||||
|
\fBnamed\-checkconf\fR
|
||||||
|
checks the syntax, but not the semantics, of a named configuration file.
|
||||||
|
.SH "OPTIONS"
|
||||||
|
.PP
|
||||||
|
\-h
|
||||||
|
.RS 4
|
||||||
|
Print the usage summary and exit.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-t \fIdirectory\fR
|
||||||
|
.RS 4
|
||||||
|
Chroot to
|
||||||
|
\fIdirectory\fR
|
||||||
|
so that include directives in the configuration file are processed as if run by a similarly chrooted named.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-v
|
||||||
|
.RS 4
|
||||||
|
Print the version of the
|
||||||
|
\fBnamed\-checkconf\fR
|
||||||
|
program and exit.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-z
|
||||||
|
.RS 4
|
||||||
|
Perform a test load of all master zones found in
|
||||||
|
\fInamed.conf\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-j
|
||||||
|
.RS 4
|
||||||
|
When loading a zonefile read the journal if it exists.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
filename
|
||||||
|
.RS 4
|
||||||
|
The name of the configuration file to be checked. If not specified, it defaults to
|
||||||
|
\fI/etc/named.conf\fR.
|
||||||
|
.RE
|
||||||
|
.SH "RETURN VALUES"
|
||||||
|
.PP
|
||||||
|
\fBnamed\-checkconf\fR
|
||||||
|
returns an exit status of 1 if errors were detected and 0 otherwise.
|
||||||
|
.SH "SEE ALSO"
|
||||||
|
.PP
|
||||||
|
\fBnamed\fR(8),
|
||||||
|
\fBnamed\-checkzone\fR(8),
|
||||||
|
BIND 9 Administrator Reference Manual.
|
||||||
|
.SH "AUTHOR"
|
||||||
|
.PP
|
||||||
|
Internet Systems Consortium
|
||||||
|
.SH "COPYRIGHT"
|
||||||
|
Copyright \(co 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
.br
|
||||||
|
Copyright \(co 2000\-2002 Internet Software Consortium.
|
||||||
|
.br
|
||||||
+146
-406
@@ -1,71 +1,68 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
* copyright notice and this permission notice appear in all copies.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
* information regarding copyright ownership.
|
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
* PERFORMANCE OF THIS SOFTWARE.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: named-checkconf.c,v 1.46.222.2.24.2 2010/09/07 23:46:26 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
|
#include <config.h>
|
||||||
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <stdbool.h>
|
#include <stdlib.h>
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/attributes.h>
|
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/result.h>
|
#include <isc/result.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/db.h>
|
|
||||||
#include <dns/fixedname.h>
|
|
||||||
#include <dns/log.h>
|
|
||||||
#include <dns/name.h>
|
|
||||||
#include <dns/rdataclass.h>
|
|
||||||
#include <dns/result.h>
|
|
||||||
#include <dns/rootns.h>
|
|
||||||
#include <dns/zone.h>
|
|
||||||
|
|
||||||
#include <isccfg/grammar.h>
|
|
||||||
#include <isccfg/namedconf.h>
|
#include <isccfg/namedconf.h>
|
||||||
|
|
||||||
#include <bind9/check.h>
|
#include <bind9/check.h>
|
||||||
|
|
||||||
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/log.h>
|
||||||
|
#include <dns/name.h>
|
||||||
|
#include <dns/result.h>
|
||||||
|
#include <dns/zone.h>
|
||||||
|
|
||||||
#include "check-tool.h"
|
#include "check-tool.h"
|
||||||
|
|
||||||
static const char *program = "named-checkconf";
|
static const char *program = "named-checkconf";
|
||||||
|
|
||||||
static bool loadplugins = true;
|
|
||||||
|
|
||||||
isc_log_t *logc = NULL;
|
isc_log_t *logc = NULL;
|
||||||
|
|
||||||
#define CHECK(r) \
|
#define CHECK(r)\
|
||||||
do { \
|
do { \
|
||||||
result = (r); \
|
result = (r); \
|
||||||
if (result != ISC_R_SUCCESS) \
|
if (result != ISC_R_SUCCESS) \
|
||||||
goto cleanup; \
|
goto cleanup; \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
/*% usage */
|
/*% usage */
|
||||||
ISC_NORETURN static void
|
|
||||||
usage(void);
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
usage(void) {
|
usage(void) {
|
||||||
fprintf(stderr,
|
fprintf(stderr, "usage: %s [-h] [-j] [-v] [-z] [-t directory] "
|
||||||
"usage: %s [-chijlvz] [-p [-x]] [-t directory] "
|
"[named.conf]\n", program);
|
||||||
"[named.conf]\n",
|
|
||||||
program);
|
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -87,28 +84,26 @@ directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
|
|||||||
result = isc_dir_chdir(directory);
|
result = isc_dir_chdir(directory);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
cfg_obj_log(obj, logc, ISC_LOG_ERROR,
|
cfg_obj_log(obj, logc, ISC_LOG_ERROR,
|
||||||
"change directory to '%s' failed: %s\n", directory,
|
"change directory to '%s' failed: %s\n",
|
||||||
isc_result_totext(result));
|
directory, isc_result_totext(result));
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
get_maps(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
|
get_maps(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
|
||||||
int i;
|
int i;
|
||||||
for (i = 0;; i++) {
|
for (i = 0;; i++) {
|
||||||
if (maps[i] == NULL) {
|
if (maps[i] == NULL)
|
||||||
return (false);
|
return (ISC_FALSE);
|
||||||
}
|
if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
|
||||||
if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS) {
|
return (ISC_TRUE);
|
||||||
return (true);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static isc_boolean_t
|
||||||
get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
|
get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
|
||||||
const cfg_listelt_t *element;
|
const cfg_listelt_t *element;
|
||||||
const cfg_obj_t *checknames;
|
const cfg_obj_t *checknames;
|
||||||
@@ -118,200 +113,94 @@ get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
|
|||||||
int i;
|
int i;
|
||||||
|
|
||||||
for (i = 0;; i++) {
|
for (i = 0;; i++) {
|
||||||
if (maps[i] == NULL) {
|
if (maps[i] == NULL)
|
||||||
return (false);
|
return (ISC_FALSE);
|
||||||
}
|
|
||||||
checknames = NULL;
|
checknames = NULL;
|
||||||
result = cfg_map_get(maps[i], "check-names", &checknames);
|
result = cfg_map_get(maps[i], "check-names", &checknames);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
continue;
|
continue;
|
||||||
}
|
|
||||||
if (checknames != NULL && !cfg_obj_islist(checknames)) {
|
if (checknames != NULL && !cfg_obj_islist(checknames)) {
|
||||||
*obj = checknames;
|
*obj = checknames;
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
for (element = cfg_list_first(checknames); element != NULL;
|
for (element = cfg_list_first(checknames);
|
||||||
element = cfg_list_next(element))
|
element != NULL;
|
||||||
{
|
element = cfg_list_next(element)) {
|
||||||
value = cfg_listelt_value(element);
|
value = cfg_listelt_value(element);
|
||||||
type = cfg_tuple_get(value, "type");
|
type = cfg_tuple_get(value, "type");
|
||||||
if ((strcasecmp(cfg_obj_asstring(type), "primary") !=
|
if (strcasecmp(cfg_obj_asstring(type), "master") != 0)
|
||||||
0) &&
|
|
||||||
(strcasecmp(cfg_obj_asstring(type), "master") != 0))
|
|
||||||
{
|
|
||||||
continue;
|
continue;
|
||||||
}
|
|
||||||
*obj = cfg_tuple_get(value, "mode");
|
*obj = cfg_tuple_get(value, "mode");
|
||||||
return (true);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
configure_hint(const char *zfile, const char *zclass, isc_mem_t *mctx) {
|
config_get(const cfg_obj_t **maps, const char *name, const cfg_obj_t **obj) {
|
||||||
isc_result_t result;
|
int i;
|
||||||
dns_db_t *db = NULL;
|
|
||||||
dns_rdataclass_t rdclass;
|
|
||||||
isc_textregion_t r;
|
|
||||||
|
|
||||||
if (zfile == NULL) {
|
for (i = 0;; i++) {
|
||||||
return (ISC_R_FAILURE);
|
if (maps[i] == NULL)
|
||||||
|
return (ISC_R_NOTFOUND);
|
||||||
|
if (cfg_map_get(maps[i], name, obj) == ISC_R_SUCCESS)
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
DE_CONST(zclass, r.base);
|
|
||||||
r.length = strlen(zclass);
|
|
||||||
result = dns_rdataclass_fromtext(&rdclass, &r);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
result = dns_rootns_create(mctx, rdclass, zfile, &db);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return (result);
|
|
||||||
}
|
|
||||||
|
|
||||||
dns_db_detach(&db);
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% configure the zone */
|
/*% configure the zone */
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
configure_zone(const char *vclass, const char *view,
|
||||||
const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||||
isc_mem_t *mctx, bool list) {
|
const cfg_obj_t *config, isc_mem_t *mctx)
|
||||||
|
{
|
||||||
int i = 0;
|
int i = 0;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *zclass;
|
const char *zclass;
|
||||||
const char *zname;
|
const char *zname;
|
||||||
const char *zfile = NULL;
|
const char *zfile;
|
||||||
const cfg_obj_t *maps[4];
|
const cfg_obj_t *maps[4];
|
||||||
const cfg_obj_t *primariesobj = NULL;
|
|
||||||
const cfg_obj_t *inviewobj = NULL;
|
|
||||||
const cfg_obj_t *zoptions = NULL;
|
const cfg_obj_t *zoptions = NULL;
|
||||||
const cfg_obj_t *classobj = NULL;
|
const cfg_obj_t *classobj = NULL;
|
||||||
const cfg_obj_t *typeobj = NULL;
|
const cfg_obj_t *typeobj = NULL;
|
||||||
const cfg_obj_t *fileobj = NULL;
|
const cfg_obj_t *fileobj = NULL;
|
||||||
const cfg_obj_t *dlzobj = NULL;
|
|
||||||
const cfg_obj_t *dbobj = NULL;
|
const cfg_obj_t *dbobj = NULL;
|
||||||
const cfg_obj_t *obj = NULL;
|
const cfg_obj_t *obj = NULL;
|
||||||
const cfg_obj_t *fmtobj = NULL;
|
const cfg_obj_t *fmtobj = NULL;
|
||||||
dns_masterformat_t masterformat;
|
dns_masterformat_t masterformat;
|
||||||
dns_ttl_t maxttl = 0;
|
|
||||||
|
|
||||||
zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_MANYERRORS;
|
zone_options = DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_MANYERRORS;
|
||||||
|
|
||||||
zname = cfg_obj_asstring(cfg_tuple_get(zconfig, "name"));
|
zname = cfg_obj_asstring(cfg_tuple_get(zconfig, "name"));
|
||||||
classobj = cfg_tuple_get(zconfig, "class");
|
classobj = cfg_tuple_get(zconfig, "class");
|
||||||
if (!cfg_obj_isstring(classobj)) {
|
if (!cfg_obj_isstring(classobj))
|
||||||
zclass = vclass;
|
zclass = vclass;
|
||||||
} else {
|
else
|
||||||
zclass = cfg_obj_asstring(classobj);
|
zclass = cfg_obj_asstring(classobj);
|
||||||
}
|
|
||||||
|
|
||||||
zoptions = cfg_tuple_get(zconfig, "options");
|
zoptions = cfg_tuple_get(zconfig, "options");
|
||||||
maps[i++] = zoptions;
|
maps[i++] = zoptions;
|
||||||
if (vconfig != NULL) {
|
if (vconfig != NULL)
|
||||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
maps[i++] = cfg_tuple_get(vconfig, "options");
|
||||||
}
|
|
||||||
if (config != NULL) {
|
if (config != NULL) {
|
||||||
cfg_map_get(config, "options", &obj);
|
cfg_map_get(config, "options", &obj);
|
||||||
if (obj != NULL) {
|
if (obj != NULL)
|
||||||
maps[i++] = obj;
|
maps[i++] = obj;
|
||||||
}
|
|
||||||
}
|
|
||||||
maps[i] = NULL;
|
|
||||||
|
|
||||||
cfg_map_get(zoptions, "in-view", &inviewobj);
|
|
||||||
if (inviewobj != NULL && list) {
|
|
||||||
const char *inview = cfg_obj_asstring(inviewobj);
|
|
||||||
printf("%s %s %s in-view %s\n", zname, zclass, view, inview);
|
|
||||||
}
|
|
||||||
if (inviewobj != NULL) {
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
}
|
||||||
|
maps[i++] = NULL;
|
||||||
|
|
||||||
cfg_map_get(zoptions, "type", &typeobj);
|
cfg_map_get(zoptions, "type", &typeobj);
|
||||||
if (typeobj == NULL) {
|
if (typeobj == NULL)
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
if (strcasecmp(cfg_obj_asstring(typeobj), "master") != 0)
|
||||||
|
|
||||||
if (list) {
|
|
||||||
const char *ztype = cfg_obj_asstring(typeobj);
|
|
||||||
printf("%s %s %s %s\n", zname, zclass, view, ztype);
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Skip checks when using an alternate data source.
|
|
||||||
*/
|
|
||||||
cfg_map_get(zoptions, "database", &dbobj);
|
cfg_map_get(zoptions, "database", &dbobj);
|
||||||
if (dbobj != NULL && strcmp("rbt", cfg_obj_asstring(dbobj)) != 0 &&
|
if (dbobj != NULL)
|
||||||
strcmp("rbt64", cfg_obj_asstring(dbobj)) != 0)
|
|
||||||
{
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
|
||||||
|
|
||||||
cfg_map_get(zoptions, "dlz", &dlzobj);
|
|
||||||
if (dlzobj != NULL) {
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
cfg_map_get(zoptions, "file", &fileobj);
|
cfg_map_get(zoptions, "file", &fileobj);
|
||||||
if (fileobj != NULL) {
|
if (fileobj == NULL)
|
||||||
zfile = cfg_obj_asstring(fileobj);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Check hints files for hint zones.
|
|
||||||
* Skip loading checks for any type other than
|
|
||||||
* master and redirect
|
|
||||||
*/
|
|
||||||
if (strcasecmp(cfg_obj_asstring(typeobj), "hint") == 0) {
|
|
||||||
return (configure_hint(zfile, zclass, mctx));
|
|
||||||
} else if ((strcasecmp(cfg_obj_asstring(typeobj), "primary") != 0) &&
|
|
||||||
(strcasecmp(cfg_obj_asstring(typeobj), "master") != 0) &&
|
|
||||||
(strcasecmp(cfg_obj_asstring(typeobj), "redirect") != 0))
|
|
||||||
{
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Is the redirect zone configured as a slave?
|
|
||||||
*/
|
|
||||||
if (strcasecmp(cfg_obj_asstring(typeobj), "redirect") == 0) {
|
|
||||||
cfg_map_get(zoptions, "primaries", &primariesobj);
|
|
||||||
if (primariesobj == NULL) {
|
|
||||||
cfg_map_get(zoptions, "masters", &primariesobj);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (primariesobj != NULL) {
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (zfile == NULL) {
|
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
zfile = cfg_obj_asstring(fileobj);
|
||||||
|
|
||||||
obj = NULL;
|
|
||||||
if (get_maps(maps, "check-dup-records", &obj)) {
|
|
||||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR;
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "fail") == 0) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR;
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRR;
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
} else {
|
|
||||||
INSIST(0);
|
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR;
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
}
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "check-mx", &obj)) {
|
if (get_maps(maps, "check-mx", &obj)) {
|
||||||
@@ -324,10 +213,8 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKMX;
|
zone_options &= ~DNS_ZONEOPT_CHECKMX;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
|
zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
|
||||||
} else {
|
} else
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKMX;
|
zone_options |= DNS_ZONEOPT_CHECKMX;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
|
zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
|
||||||
@@ -335,14 +222,12 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "check-integrity", &obj)) {
|
if (get_maps(maps, "check-integrity", &obj)) {
|
||||||
if (cfg_obj_asboolean(obj)) {
|
if (cfg_obj_asboolean(obj))
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
} else {
|
else
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
}
|
} else
|
||||||
} else {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
}
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "check-mx-cname", &obj)) {
|
if (get_maps(maps, "check-mx-cname", &obj)) {
|
||||||
@@ -355,10 +240,8 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||||
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
||||||
zone_options |= DNS_ZONEOPT_IGNOREMXCNAME;
|
zone_options |= DNS_ZONEOPT_IGNOREMXCNAME;
|
||||||
} else {
|
} else
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
||||||
zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
|
zone_options &= ~DNS_ZONEOPT_IGNOREMXCNAME;
|
||||||
@@ -375,10 +258,8 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||||
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
||||||
zone_options |= DNS_ZONEOPT_IGNORESRVCNAME;
|
zone_options |= DNS_ZONEOPT_IGNORESRVCNAME;
|
||||||
} else {
|
} else
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
||||||
zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
|
zone_options &= ~DNS_ZONEOPT_IGNORESRVCNAME;
|
||||||
@@ -386,25 +267,10 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "check-sibling", &obj)) {
|
if (get_maps(maps, "check-sibling", &obj)) {
|
||||||
if (cfg_obj_asboolean(obj)) {
|
if (cfg_obj_asboolean(obj))
|
||||||
zone_options |= DNS_ZONEOPT_CHECKSIBLING;
|
zone_options |= DNS_ZONEOPT_CHECKSIBLING;
|
||||||
} else {
|
else
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
obj = NULL;
|
|
||||||
if (get_maps(maps, "check-spf", &obj)) {
|
|
||||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKSPF;
|
|
||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSPF;
|
|
||||||
} else {
|
|
||||||
INSIST(0);
|
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKSPF;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
@@ -418,50 +284,38 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
|||||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKNAMES;
|
zone_options &= ~DNS_ZONEOPT_CHECKNAMES;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
|
zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
|
||||||
} else {
|
} else
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKNAMES;
|
zone_options |= DNS_ZONEOPT_CHECKNAMES;
|
||||||
zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
|
zone_options |= DNS_ZONEOPT_CHECKNAMESFAIL;
|
||||||
}
|
}
|
||||||
|
|
||||||
masterformat = dns_masterformat_text;
|
masterformat = dns_masterformat_text;
|
||||||
fmtobj = NULL;
|
fmtobj = NULL;
|
||||||
if (get_maps(maps, "masterfile-format", &fmtobj)) {
|
result = config_get(maps, "masterfile-format", &fmtobj);
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
const char *masterformatstr = cfg_obj_asstring(fmtobj);
|
const char *masterformatstr = cfg_obj_asstring(fmtobj);
|
||||||
if (strcasecmp(masterformatstr, "text") == 0) {
|
if (strcasecmp(masterformatstr, "text") == 0)
|
||||||
masterformat = dns_masterformat_text;
|
masterformat = dns_masterformat_text;
|
||||||
} else if (strcasecmp(masterformatstr, "raw") == 0) {
|
else if (strcasecmp(masterformatstr, "raw") == 0)
|
||||||
masterformat = dns_masterformat_raw;
|
masterformat = dns_masterformat_raw;
|
||||||
} else if (strcasecmp(masterformatstr, "map") == 0) {
|
else
|
||||||
masterformat = dns_masterformat_map;
|
|
||||||
} else {
|
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
obj = NULL;
|
result = load_zone(mctx, zname, zfile, masterformat, zclass, NULL);
|
||||||
if (get_maps(maps, "max-zone-ttl", &obj)) {
|
if (result != ISC_R_SUCCESS)
|
||||||
maxttl = cfg_obj_asduration(obj);
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
|
||||||
}
|
|
||||||
|
|
||||||
result = load_zone(mctx, zname, zfile, masterformat, zclass, maxttl,
|
|
||||||
NULL);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fprintf(stderr, "%s/%s/%s: %s\n", view, zname, zclass,
|
fprintf(stderr, "%s/%s/%s: %s\n", view, zname, zclass,
|
||||||
dns_result_totext(result));
|
dns_result_totext(result));
|
||||||
}
|
return(result);
|
||||||
return (result);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% configure a view */
|
/*% configure a view */
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
|
configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
|
||||||
const cfg_obj_t *vconfig, isc_mem_t *mctx, bool list) {
|
const cfg_obj_t *vconfig, isc_mem_t *mctx)
|
||||||
|
{
|
||||||
const cfg_listelt_t *element;
|
const cfg_listelt_t *element;
|
||||||
const cfg_obj_t *voptions;
|
const cfg_obj_t *voptions;
|
||||||
const cfg_obj_t *zonelist;
|
const cfg_obj_t *zonelist;
|
||||||
@@ -469,111 +323,70 @@ configure_view(const char *vclass, const char *view, const cfg_obj_t *config,
|
|||||||
isc_result_t tresult;
|
isc_result_t tresult;
|
||||||
|
|
||||||
voptions = NULL;
|
voptions = NULL;
|
||||||
if (vconfig != NULL) {
|
if (vconfig != NULL)
|
||||||
voptions = cfg_tuple_get(vconfig, "options");
|
voptions = cfg_tuple_get(vconfig, "options");
|
||||||
}
|
|
||||||
|
|
||||||
zonelist = NULL;
|
zonelist = NULL;
|
||||||
if (voptions != NULL) {
|
if (voptions != NULL)
|
||||||
(void)cfg_map_get(voptions, "zone", &zonelist);
|
(void)cfg_map_get(voptions, "zone", &zonelist);
|
||||||
} else {
|
else
|
||||||
(void)cfg_map_get(config, "zone", &zonelist);
|
(void)cfg_map_get(config, "zone", &zonelist);
|
||||||
}
|
|
||||||
|
|
||||||
for (element = cfg_list_first(zonelist); element != NULL;
|
for (element = cfg_list_first(zonelist);
|
||||||
|
element != NULL;
|
||||||
element = cfg_list_next(element))
|
element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
const cfg_obj_t *zconfig = cfg_listelt_value(element);
|
const cfg_obj_t *zconfig = cfg_listelt_value(element);
|
||||||
tresult = configure_zone(vclass, view, zconfig, vconfig, config,
|
tresult = configure_zone(vclass, view, zconfig, vconfig,
|
||||||
mctx, list);
|
config, mctx);
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
if (tresult != ISC_R_SUCCESS)
|
||||||
result = tresult;
|
result = tresult;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
|
||||||
config_getclass(const cfg_obj_t *classobj, dns_rdataclass_t defclass,
|
|
||||||
dns_rdataclass_t *classp) {
|
|
||||||
isc_textregion_t r;
|
|
||||||
|
|
||||||
if (!cfg_obj_isstring(classobj)) {
|
|
||||||
*classp = defclass;
|
|
||||||
return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
DE_CONST(cfg_obj_asstring(classobj), r.base);
|
|
||||||
r.length = strlen(r.base);
|
|
||||||
return (dns_rdataclass_fromtext(classp, &r));
|
|
||||||
}
|
|
||||||
|
|
||||||
/*% load zones from the configuration */
|
/*% load zones from the configuration */
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
load_zones_fromconfig(const cfg_obj_t *config, isc_mem_t *mctx,
|
load_zones_fromconfig(const cfg_obj_t *config, isc_mem_t *mctx) {
|
||||||
bool list_zones) {
|
|
||||||
const cfg_listelt_t *element;
|
const cfg_listelt_t *element;
|
||||||
|
const cfg_obj_t *classobj;
|
||||||
const cfg_obj_t *views;
|
const cfg_obj_t *views;
|
||||||
const cfg_obj_t *vconfig;
|
const cfg_obj_t *vconfig;
|
||||||
|
const char *vclass;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
isc_result_t tresult;
|
isc_result_t tresult;
|
||||||
|
|
||||||
views = NULL;
|
views = NULL;
|
||||||
|
|
||||||
(void)cfg_map_get(config, "view", &views);
|
(void)cfg_map_get(config, "view", &views);
|
||||||
for (element = cfg_list_first(views); element != NULL;
|
for (element = cfg_list_first(views);
|
||||||
|
element != NULL;
|
||||||
element = cfg_list_next(element))
|
element = cfg_list_next(element))
|
||||||
{
|
{
|
||||||
const cfg_obj_t *classobj;
|
|
||||||
dns_rdataclass_t viewclass;
|
|
||||||
const char *vname;
|
const char *vname;
|
||||||
char buf[sizeof("CLASS65535")];
|
|
||||||
|
|
||||||
|
vclass = "IN";
|
||||||
vconfig = cfg_listelt_value(element);
|
vconfig = cfg_listelt_value(element);
|
||||||
if (vconfig == NULL) {
|
if (vconfig != NULL) {
|
||||||
continue;
|
classobj = cfg_tuple_get(vconfig, "class");
|
||||||
|
if (cfg_obj_isstring(classobj))
|
||||||
|
vclass = cfg_obj_asstring(classobj);
|
||||||
}
|
}
|
||||||
|
|
||||||
classobj = cfg_tuple_get(vconfig, "class");
|
|
||||||
tresult = config_getclass(classobj, dns_rdataclass_in,
|
|
||||||
&viewclass);
|
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
|
||||||
CHECK(tresult);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (dns_rdataclass_ismeta(viewclass)) {
|
|
||||||
CHECK(ISC_R_FAILURE);
|
|
||||||
}
|
|
||||||
|
|
||||||
dns_rdataclass_format(viewclass, buf, sizeof(buf));
|
|
||||||
vname = cfg_obj_asstring(cfg_tuple_get(vconfig, "name"));
|
vname = cfg_obj_asstring(cfg_tuple_get(vconfig, "name"));
|
||||||
tresult = configure_view(buf, vname, config, vconfig, mctx,
|
tresult = configure_view(vclass, vname, config, vconfig, mctx);
|
||||||
list_zones);
|
if (tresult != ISC_R_SUCCESS)
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
|
||||||
result = tresult;
|
result = tresult;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (views == NULL) {
|
if (views == NULL) {
|
||||||
tresult = configure_view("IN", "_default", config, NULL, mctx,
|
tresult = configure_view("IN", "_default", config, NULL, mctx);
|
||||||
list_zones);
|
if (tresult != ISC_R_SUCCESS)
|
||||||
if (tresult != ISC_R_SUCCESS) {
|
|
||||||
result = tresult;
|
result = tresult;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
|
||||||
output(void *closure, const char *text, int textlen) {
|
|
||||||
UNUSED(closure);
|
|
||||||
if (fwrite(text, 1, textlen, stdout) != (size_t)textlen) {
|
|
||||||
perror("fwrite");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/*% The main processing routine */
|
/*% The main processing routine */
|
||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
@@ -584,71 +397,19 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
int exit_status = 0;
|
int exit_status = 0;
|
||||||
bool load_zones = false;
|
isc_entropy_t *ectx = NULL;
|
||||||
bool list_zones = false;
|
isc_boolean_t load_zones = ISC_FALSE;
|
||||||
bool print = false;
|
|
||||||
bool nodeprecate = false;
|
|
||||||
unsigned int flags = 0;
|
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = ISC_FALSE;
|
||||||
|
|
||||||
/*
|
while ((c = isc_commandline_parse(argc, argv, "dhjt:vz")) != EOF) {
|
||||||
* Process memory debugging argument first.
|
|
||||||
*/
|
|
||||||
#define CMDLINE_FLAGS "cdhijlm:t:pvxz"
|
|
||||||
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
|
||||||
switch (c) {
|
switch (c) {
|
||||||
case 'm':
|
|
||||||
if (strcasecmp(isc_commandline_argument, "record") == 0)
|
|
||||||
{
|
|
||||||
isc_mem_debugging |= ISC_MEM_DEBUGRECORD;
|
|
||||||
}
|
|
||||||
if (strcasecmp(isc_commandline_argument, "trace") == 0)
|
|
||||||
{
|
|
||||||
isc_mem_debugging |= ISC_MEM_DEBUGTRACE;
|
|
||||||
}
|
|
||||||
if (strcasecmp(isc_commandline_argument, "usage") == 0)
|
|
||||||
{
|
|
||||||
isc_mem_debugging |= ISC_MEM_DEBUGUSAGE;
|
|
||||||
}
|
|
||||||
if (strcasecmp(isc_commandline_argument, "size") == 0) {
|
|
||||||
isc_mem_debugging |= ISC_MEM_DEBUGSIZE;
|
|
||||||
}
|
|
||||||
if (strcasecmp(isc_commandline_argument, "mctx") == 0) {
|
|
||||||
isc_mem_debugging |= ISC_MEM_DEBUGCTX;
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
isc_commandline_reset = true;
|
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
|
||||||
|
|
||||||
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != EOF) {
|
|
||||||
switch (c) {
|
|
||||||
case 'c':
|
|
||||||
loadplugins = false;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'd':
|
case 'd':
|
||||||
debug++;
|
debug++;
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'i':
|
|
||||||
nodeprecate = true;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'j':
|
case 'j':
|
||||||
nomerge = false;
|
nomerge = ISC_FALSE;
|
||||||
break;
|
|
||||||
|
|
||||||
case 'l':
|
|
||||||
list_zones = true;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'm':
|
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 't':
|
case 't':
|
||||||
@@ -660,107 +421,86 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'p':
|
|
||||||
print = true;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'v':
|
case 'v':
|
||||||
printf("%s\n", PACKAGE_VERSION);
|
printf(VERSION "\n");
|
||||||
exit(0);
|
exit(0);
|
||||||
|
|
||||||
case 'x':
|
|
||||||
flags |= CFG_PRINTER_XKEY;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'z':
|
case 'z':
|
||||||
load_zones = true;
|
load_zones = ISC_TRUE;
|
||||||
docheckmx = false;
|
docheckmx = ISC_FALSE;
|
||||||
docheckns = false;
|
docheckns = ISC_FALSE;
|
||||||
dochecksrv = false;
|
dochecksrv = ISC_FALSE;
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case '?':
|
case '?':
|
||||||
if (isc_commandline_option != '?') {
|
if (isc_commandline_option != '?')
|
||||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||||
program, isc_commandline_option);
|
program, isc_commandline_option);
|
||||||
}
|
|
||||||
/* FALLTHROUGH */
|
|
||||||
case 'h':
|
case 'h':
|
||||||
usage();
|
usage();
|
||||||
|
|
||||||
default:
|
default:
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n", program,
|
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||||
isc_commandline_option);
|
program, isc_commandline_option);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (((flags & CFG_PRINTER_XKEY) != 0) && !print) {
|
if (isc_commandline_index + 1 < argc)
|
||||||
fprintf(stderr, "%s: -x cannot be used without -p\n", program);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
if (print && list_zones) {
|
|
||||||
fprintf(stderr, "%s: -l cannot be used with -p\n", program);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (isc_commandline_index + 1 < argc) {
|
|
||||||
usage();
|
usage();
|
||||||
}
|
if (argv[isc_commandline_index] != NULL)
|
||||||
if (argv[isc_commandline_index] != NULL) {
|
|
||||||
conffile = argv[isc_commandline_index];
|
conffile = argv[isc_commandline_index];
|
||||||
}
|
if (conffile == NULL || conffile[0] == '\0')
|
||||||
if (conffile == NULL || conffile[0] == '\0') {
|
|
||||||
conffile = NAMED_CONFFILE;
|
conffile = NAMED_CONFFILE;
|
||||||
}
|
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
InitSockets();
|
InitSockets();
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
|
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
|
||||||
|
RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
|
||||||
|
== ISC_R_SUCCESS);
|
||||||
|
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
|
|
||||||
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
if (nodeprecate) {
|
|
||||||
cfg_parser_setflags(parser, CFG_PCTX_NODEPRECATED, true);
|
|
||||||
}
|
|
||||||
cfg_parser_setcallback(parser, directory_callback, NULL);
|
cfg_parser_setcallback(parser, directory_callback, NULL);
|
||||||
|
|
||||||
if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
|
if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
|
||||||
ISC_R_SUCCESS)
|
ISC_R_SUCCESS)
|
||||||
{
|
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
|
||||||
|
|
||||||
result = bind9_check_namedconf(config, loadplugins, logc, mctx);
|
result = bind9_check_namedconf(config, logc, mctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
exit_status = 1;
|
exit_status = 1;
|
||||||
}
|
|
||||||
|
|
||||||
if (result == ISC_R_SUCCESS && (load_zones || list_zones)) {
|
if (result == ISC_R_SUCCESS && load_zones) {
|
||||||
result = load_zones_fromconfig(config, mctx, list_zones);
|
result = load_zones_fromconfig(config, mctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
exit_status = 1;
|
exit_status = 1;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (print && exit_status == 0) {
|
|
||||||
cfg_printx(config, flags, output, NULL);
|
|
||||||
}
|
|
||||||
cfg_obj_destroy(parser, &config);
|
cfg_obj_destroy(parser, &config);
|
||||||
|
|
||||||
cfg_parser_destroy(&parser);
|
cfg_parser_destroy(&parser);
|
||||||
|
|
||||||
|
dns_name_destroy();
|
||||||
|
|
||||||
isc_log_destroy(&logc);
|
isc_log_destroy(&logc);
|
||||||
|
|
||||||
|
isc_hash_destroy();
|
||||||
|
isc_entropy_detach(&ectx);
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
DestroySockets();
|
DestroySockets();
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
return (exit_status);
|
return (exit_status);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,171 @@
|
|||||||
|
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||||
|
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||||
|
[<!ENTITY mdash "—">]>
|
||||||
|
<!--
|
||||||
|
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
- Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
-
|
||||||
|
- Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
- purpose with or without fee is hereby granted, provided that the above
|
||||||
|
- copyright notice and this permission notice appear in all copies.
|
||||||
|
-
|
||||||
|
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
- PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
-->
|
||||||
|
|
||||||
|
<!-- $Id: named-checkconf.docbook,v 1.19 2007/06/19 06:58:03 marka Exp $ -->
|
||||||
|
<refentry id="man.named-checkconf">
|
||||||
|
<refentryinfo>
|
||||||
|
<date>June 14, 2000</date>
|
||||||
|
</refentryinfo>
|
||||||
|
|
||||||
|
<refmeta>
|
||||||
|
<refentrytitle><application>named-checkconf</application></refentrytitle>
|
||||||
|
<manvolnum>8</manvolnum>
|
||||||
|
<refmiscinfo>BIND9</refmiscinfo>
|
||||||
|
</refmeta>
|
||||||
|
|
||||||
|
<docinfo>
|
||||||
|
<copyright>
|
||||||
|
<year>2004</year>
|
||||||
|
<year>2005</year>
|
||||||
|
<year>2007</year>
|
||||||
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
|
</copyright>
|
||||||
|
<copyright>
|
||||||
|
<year>2000</year>
|
||||||
|
<year>2001</year>
|
||||||
|
<year>2002</year>
|
||||||
|
<holder>Internet Software Consortium.</holder>
|
||||||
|
</copyright>
|
||||||
|
</docinfo>
|
||||||
|
|
||||||
|
<refnamediv>
|
||||||
|
<refname><application>named-checkconf</application></refname>
|
||||||
|
<refpurpose>named configuration file syntax checking tool</refpurpose>
|
||||||
|
</refnamediv>
|
||||||
|
|
||||||
|
<refsynopsisdiv>
|
||||||
|
<cmdsynopsis>
|
||||||
|
<command>named-checkconf</command>
|
||||||
|
<arg><option>-h</option></arg>
|
||||||
|
<arg><option>-v</option></arg>
|
||||||
|
<arg><option>-j</option></arg>
|
||||||
|
<arg><option>-t <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
|
<arg choice="req">filename</arg>
|
||||||
|
<arg><option>-z</option></arg>
|
||||||
|
</cmdsynopsis>
|
||||||
|
</refsynopsisdiv>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>DESCRIPTION</title>
|
||||||
|
<para><command>named-checkconf</command>
|
||||||
|
checks the syntax, but not the semantics, of a named
|
||||||
|
configuration file.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>OPTIONS</title>
|
||||||
|
|
||||||
|
<variablelist>
|
||||||
|
<varlistentry>
|
||||||
|
<term>-h</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print the usage summary and exit.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Chroot to <filename>directory</filename> so that
|
||||||
|
include
|
||||||
|
directives in the configuration file are processed as if
|
||||||
|
run by a similarly chrooted named.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-v</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print the version of the <command>named-checkconf</command>
|
||||||
|
program and exit.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-z</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Perform a test load of all master zones found in
|
||||||
|
<filename>named.conf</filename>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-j</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
When loading a zonefile read the journal if it exists.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>filename</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
The name of the configuration file to be checked. If not
|
||||||
|
specified, it defaults to <filename>/etc/named.conf</filename>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
</variablelist>
|
||||||
|
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>RETURN VALUES</title>
|
||||||
|
<para><command>named-checkconf</command>
|
||||||
|
returns an exit status of 1 if
|
||||||
|
errors were detected and 0 otherwise.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>SEE ALSO</title>
|
||||||
|
<para><citerefentry>
|
||||||
|
<refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
|
||||||
|
</citerefentry>,
|
||||||
|
<citerefentry>
|
||||||
|
<refentrytitle>named-checkzone</refentrytitle><manvolnum>8</manvolnum>
|
||||||
|
</citerefentry>,
|
||||||
|
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>AUTHOR</title>
|
||||||
|
<para><corpauthor>Internet Systems Consortium</corpauthor>
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
</refentry><!--
|
||||||
|
- Local variables:
|
||||||
|
- mode: sgml
|
||||||
|
- End:
|
||||||
|
-->
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
<!--
|
||||||
|
- Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
- Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
-
|
||||||
|
- Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
- purpose with or without fee is hereby granted, provided that the above
|
||||||
|
- copyright notice and this permission notice appear in all copies.
|
||||||
|
-
|
||||||
|
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
- PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
-->
|
||||||
|
<!-- $Id: named-checkconf.html,v 1.30.334.1 2009/07/11 01:55:20 tbox Exp $ -->
|
||||||
|
<html>
|
||||||
|
<head>
|
||||||
|
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||||
|
<title>named-checkconf</title>
|
||||||
|
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
|
||||||
|
</head>
|
||||||
|
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
|
||||||
|
<a name="man.named-checkconf"></a><div class="titlepage"></div>
|
||||||
|
<div class="refnamediv">
|
||||||
|
<h2>Name</h2>
|
||||||
|
<p><span class="application">named-checkconf</span> — named configuration file syntax checking tool</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsynopsisdiv">
|
||||||
|
<h2>Synopsis</h2>
|
||||||
|
<div class="cmdsynopsis"><p><code class="command">named-checkconf</code> [<code class="option">-h</code>] [<code class="option">-v</code>] [<code class="option">-j</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] {filename} [<code class="option">-z</code>]</p></div>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543387"></a><h2>DESCRIPTION</h2>
|
||||||
|
<p><span><strong class="command">named-checkconf</strong></span>
|
||||||
|
checks the syntax, but not the semantics, of a named
|
||||||
|
configuration file.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543399"></a><h2>OPTIONS</h2>
|
||||||
|
<div class="variablelist"><dl>
|
||||||
|
<dt><span class="term">-h</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Print the usage summary and exit.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Chroot to <code class="filename">directory</code> so that
|
||||||
|
include
|
||||||
|
directives in the configuration file are processed as if
|
||||||
|
run by a similarly chrooted named.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-v</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Print the version of the <span><strong class="command">named-checkconf</strong></span>
|
||||||
|
program and exit.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-z</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Perform a test load of all master zones found in
|
||||||
|
<code class="filename">named.conf</code>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-j</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
When loading a zonefile read the journal if it exists.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">filename</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
The name of the configuration file to be checked. If not
|
||||||
|
specified, it defaults to <code class="filename">/etc/named.conf</code>.
|
||||||
|
</p></dd>
|
||||||
|
</dl></div>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543507"></a><h2>RETURN VALUES</h2>
|
||||||
|
<p><span><strong class="command">named-checkconf</strong></span>
|
||||||
|
returns an exit status of 1 if
|
||||||
|
errors were detected and 0 otherwise.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543518"></a><h2>SEE ALSO</h2>
|
||||||
|
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||||
|
<span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
|
||||||
|
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543548"></a><h2>AUTHOR</h2>
|
||||||
|
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div></body>
|
||||||
|
</html>
|
||||||
@@ -1,105 +0,0 @@
|
|||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
|
|
||||||
.. highlight: console
|
|
||||||
|
|
||||||
.. _man_named-checkconf:
|
|
||||||
|
|
||||||
named-checkconf - named configuration file syntax checking tool
|
|
||||||
---------------------------------------------------------------
|
|
||||||
|
|
||||||
Synopsis
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:program:`named-checkconf` [**-chjlvz**] [**-p** [**-x** ]] [**-t** directory] {filename}
|
|
||||||
|
|
||||||
Description
|
|
||||||
~~~~~~~~~~~
|
|
||||||
|
|
||||||
``named-checkconf`` checks the syntax, but not the semantics, of a
|
|
||||||
``named`` configuration file. The file, along with all files included by it, is parsed and checked for syntax
|
|
||||||
errors. If no file is specified,
|
|
||||||
``/etc/named.conf`` is read by default.
|
|
||||||
|
|
||||||
Note: files that ``named`` reads in separate parser contexts, such as
|
|
||||||
``rndc.key`` and ``bind.keys``, are not automatically read by
|
|
||||||
``named-checkconf``. Configuration errors in these files may cause
|
|
||||||
``named`` to fail to run, even if ``named-checkconf`` was successful.
|
|
||||||
However, ``named-checkconf`` can be run on these files explicitly.
|
|
||||||
|
|
||||||
Options
|
|
||||||
~~~~~~~
|
|
||||||
|
|
||||||
``-h``
|
|
||||||
This option prints the usage summary and exits.
|
|
||||||
|
|
||||||
``-j``
|
|
||||||
When loading a zonefile, this option instructs ``named`` to read the journal if it exists.
|
|
||||||
|
|
||||||
``-l``
|
|
||||||
This option lists all the configured zones. Each line of output contains the zone
|
|
||||||
name, class (e.g. IN), view, and type (e.g. primary or secondary).
|
|
||||||
|
|
||||||
``-c``
|
|
||||||
This option specifies that only the "core" configuration should be checked. This suppresses the loading of
|
|
||||||
plugin modules, and causes all parameters to ``plugin`` statements to
|
|
||||||
be ignored.
|
|
||||||
|
|
||||||
``-i``
|
|
||||||
This option ignores warnings on deprecated options.
|
|
||||||
|
|
||||||
``-p``
|
|
||||||
This option prints out the ``named.conf`` and included files in canonical form if
|
|
||||||
no errors were detected. See also the ``-x`` option.
|
|
||||||
|
|
||||||
``-t directory``
|
|
||||||
This option instructs ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
|
||||||
configuration file are processed as if run by a similarly chrooted
|
|
||||||
``named``.
|
|
||||||
|
|
||||||
``-v``
|
|
||||||
This option prints the version of the ``named-checkconf`` program and exits.
|
|
||||||
|
|
||||||
``-x``
|
|
||||||
When printing the configuration files in canonical form, this option obscures
|
|
||||||
shared secrets by replacing them with strings of question marks
|
|
||||||
(``?``). This allows the contents of ``named.conf`` and related files
|
|
||||||
to be shared - for example, when submitting bug reports -
|
|
||||||
without compromising private data. This option cannot be used without
|
|
||||||
``-p``.
|
|
||||||
|
|
||||||
``-z``
|
|
||||||
This option performs a test load of all zones of type ``primary`` found in ``named.conf``.
|
|
||||||
|
|
||||||
``filename``
|
|
||||||
This indicates the name of the configuration file to be checked. If not specified,
|
|
||||||
it defaults to ``/etc/named.conf``.
|
|
||||||
|
|
||||||
Return Values
|
|
||||||
~~~~~~~~~~~~~
|
|
||||||
|
|
||||||
``named-checkconf`` returns an exit status of 1 if errors were detected
|
|
||||||
and 0 otherwise.
|
|
||||||
|
|
||||||
See Also
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:manpage:`named(8)`, :manpage:`named-checkzone(8)`, BIND 9 Administrator Reference Manual.
|
|
||||||
@@ -0,0 +1,278 @@
|
|||||||
|
.\" Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
.\" Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
.\"
|
||||||
|
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
.\" purpose with or without fee is hereby granted, provided that the above
|
||||||
|
.\" copyright notice and this permission notice appear in all copies.
|
||||||
|
.\"
|
||||||
|
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
.\"
|
||||||
|
.\" $Id: named-checkzone.8,v 1.42.334.3 2009/11/11 01:56:22 tbox Exp $
|
||||||
|
.\"
|
||||||
|
.hy 0
|
||||||
|
.ad l
|
||||||
|
.\" Title: named\-checkzone
|
||||||
|
.\" Author:
|
||||||
|
.\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>
|
||||||
|
.\" Date: June 13, 2000
|
||||||
|
.\" Manual: BIND9
|
||||||
|
.\" Source: BIND9
|
||||||
|
.\"
|
||||||
|
.TH "NAMED\-CHECKZONE" "8" "June 13, 2000" "BIND9" "BIND9"
|
||||||
|
.\" disable hyphenation
|
||||||
|
.nh
|
||||||
|
.\" disable justification (adjust text to left margin only)
|
||||||
|
.ad l
|
||||||
|
.SH "NAME"
|
||||||
|
named\-checkzone, named\-compilezone \- zone file validity checking or converting tool
|
||||||
|
.SH "SYNOPSIS"
|
||||||
|
.HP 16
|
||||||
|
\fBnamed\-checkzone\fR [\fB\-d\fR] [\fB\-h\fR] [\fB\-j\fR] [\fB\-q\fR] [\fB\-v\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-f\ \fR\fB\fIformat\fR\fR] [\fB\-F\ \fR\fB\fIformat\fR\fR] [\fB\-i\ \fR\fB\fImode\fR\fR] [\fB\-k\ \fR\fB\fImode\fR\fR] [\fB\-m\ \fR\fB\fImode\fR\fR] [\fB\-M\ \fR\fB\fImode\fR\fR] [\fB\-n\ \fR\fB\fImode\fR\fR] [\fB\-s\ \fR\fB\fIstyle\fR\fR] [\fB\-S\ \fR\fB\fImode\fR\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-w\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-W\ \fR\fB\fImode\fR\fR] {zonename} {filename}
|
||||||
|
.HP 18
|
||||||
|
\fBnamed\-compilezone\fR [\fB\-d\fR] [\fB\-j\fR] [\fB\-q\fR] [\fB\-v\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-C\ \fR\fB\fImode\fR\fR] [\fB\-f\ \fR\fB\fIformat\fR\fR] [\fB\-F\ \fR\fB\fIformat\fR\fR] [\fB\-i\ \fR\fB\fImode\fR\fR] [\fB\-k\ \fR\fB\fImode\fR\fR] [\fB\-m\ \fR\fB\fImode\fR\fR] [\fB\-n\ \fR\fB\fImode\fR\fR] [\fB\-o\ \fR\fB\fIfilename\fR\fR] [\fB\-s\ \fR\fB\fIstyle\fR\fR] [\fB\-t\ \fR\fB\fIdirectory\fR\fR] [\fB\-w\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-W\ \fR\fB\fImode\fR\fR] {\fB\-o\ \fR\fB\fIfilename\fR\fR} {zonename} {filename}
|
||||||
|
.SH "DESCRIPTION"
|
||||||
|
.PP
|
||||||
|
\fBnamed\-checkzone\fR
|
||||||
|
checks the syntax and integrity of a zone file. It performs the same checks as
|
||||||
|
\fBnamed\fR
|
||||||
|
does when loading a zone. This makes
|
||||||
|
\fBnamed\-checkzone\fR
|
||||||
|
useful for checking zone files before configuring them into a name server.
|
||||||
|
.PP
|
||||||
|
\fBnamed\-compilezone\fR
|
||||||
|
is similar to
|
||||||
|
\fBnamed\-checkzone\fR, but it always dumps the zone contents to a specified file in a specified format. Additionally, it applies stricter check levels by default, since the dump output will be used as an actual zone file loaded by
|
||||||
|
\fBnamed\fR. When manually specified otherwise, the check levels must at least be as strict as those specified in the
|
||||||
|
\fBnamed\fR
|
||||||
|
configuration file.
|
||||||
|
.SH "OPTIONS"
|
||||||
|
.PP
|
||||||
|
\-d
|
||||||
|
.RS 4
|
||||||
|
Enable debugging.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-h
|
||||||
|
.RS 4
|
||||||
|
Print the usage summary and exit.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-q
|
||||||
|
.RS 4
|
||||||
|
Quiet mode \- exit code only.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-v
|
||||||
|
.RS 4
|
||||||
|
Print the version of the
|
||||||
|
\fBnamed\-checkzone\fR
|
||||||
|
program and exit.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-j
|
||||||
|
.RS 4
|
||||||
|
When loading the zone file read the journal if it exists.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-c \fIclass\fR
|
||||||
|
.RS 4
|
||||||
|
Specify the class of the zone. If not specified, "IN" is assumed.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-i \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Perform post\-load zone integrity checks. Possible modes are
|
||||||
|
\fB"full"\fR
|
||||||
|
(default),
|
||||||
|
\fB"full\-sibling"\fR,
|
||||||
|
\fB"local"\fR,
|
||||||
|
\fB"local\-sibling"\fR
|
||||||
|
and
|
||||||
|
\fB"none"\fR.
|
||||||
|
.sp
|
||||||
|
Mode
|
||||||
|
\fB"full"\fR
|
||||||
|
checks that MX records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames). Mode
|
||||||
|
\fB"local"\fR
|
||||||
|
only checks MX records which refer to in\-zone hostnames.
|
||||||
|
.sp
|
||||||
|
Mode
|
||||||
|
\fB"full"\fR
|
||||||
|
checks that SRV records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames). Mode
|
||||||
|
\fB"local"\fR
|
||||||
|
only checks SRV records which refer to in\-zone hostnames.
|
||||||
|
.sp
|
||||||
|
Mode
|
||||||
|
\fB"full"\fR
|
||||||
|
checks that delegation NS records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames). It also checks that glue address records in the zone match those advertised by the child. Mode
|
||||||
|
\fB"local"\fR
|
||||||
|
only checks NS records which refer to in\-zone hostnames or that some required glue exists, that is when the nameserver is in a child zone.
|
||||||
|
.sp
|
||||||
|
Mode
|
||||||
|
\fB"full\-sibling"\fR
|
||||||
|
and
|
||||||
|
\fB"local\-sibling"\fR
|
||||||
|
disable sibling glue checks but are otherwise the same as
|
||||||
|
\fB"full"\fR
|
||||||
|
and
|
||||||
|
\fB"local"\fR
|
||||||
|
respectively.
|
||||||
|
.sp
|
||||||
|
Mode
|
||||||
|
\fB"none"\fR
|
||||||
|
disables the checks.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-f \fIformat\fR
|
||||||
|
.RS 4
|
||||||
|
Specify the format of the zone file. Possible formats are
|
||||||
|
\fB"text"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"raw"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-F \fIformat\fR
|
||||||
|
.RS 4
|
||||||
|
Specify the format of the output file specified. Possible formats are
|
||||||
|
\fB"text"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"raw"\fR. For
|
||||||
|
\fBnamed\-checkzone\fR, this does not cause any effects unless it dumps the zone contents.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-k \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Perform
|
||||||
|
\fB"check\-names"\fR
|
||||||
|
checks with the specified failure mode. Possible modes are
|
||||||
|
\fB"fail"\fR
|
||||||
|
(default for
|
||||||
|
\fBnamed\-compilezone\fR),
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default for
|
||||||
|
\fBnamed\-checkzone\fR) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-m \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Specify whether MX records should be checked to see if they are addresses. Possible modes are
|
||||||
|
\fB"fail"\fR,
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-M \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Check if a MX record refers to a CNAME. Possible modes are
|
||||||
|
\fB"fail"\fR,
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-n \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Specify whether NS records should be checked to see if they are addresses. Possible modes are
|
||||||
|
\fB"fail"\fR
|
||||||
|
(default for
|
||||||
|
\fBnamed\-compilezone\fR),
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default for
|
||||||
|
\fBnamed\-checkzone\fR) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-o \fIfilename\fR
|
||||||
|
.RS 4
|
||||||
|
Write zone output to
|
||||||
|
\fIfilename\fR. If
|
||||||
|
\fIfilename\fR
|
||||||
|
is
|
||||||
|
\fI\-\fR
|
||||||
|
then write to standard out. This is mandatory for
|
||||||
|
\fBnamed\-compilezone\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-s \fIstyle\fR
|
||||||
|
.RS 4
|
||||||
|
Specify the style of the dumped zone file. Possible styles are
|
||||||
|
\fB"full"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"relative"\fR. The full format is most suitable for processing automatically by a separate script. On the other hand, the relative format is more human\-readable and is thus suitable for editing by hand. For
|
||||||
|
\fBnamed\-checkzone\fR
|
||||||
|
this does not cause any effects unless it dumps the zone contents. It also does not have any meaning if the output format is not text.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-S \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Check if a SRV record refers to a CNAME. Possible modes are
|
||||||
|
\fB"fail"\fR,
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-t \fIdirectory\fR
|
||||||
|
.RS 4
|
||||||
|
Chroot to
|
||||||
|
\fIdirectory\fR
|
||||||
|
so that include directives in the configuration file are processed as if run by a similarly chrooted named.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-w \fIdirectory\fR
|
||||||
|
.RS 4
|
||||||
|
chdir to
|
||||||
|
\fIdirectory\fR
|
||||||
|
so that relative filenames in master file $INCLUDE directives work. This is similar to the directory clause in
|
||||||
|
\fInamed.conf\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-D
|
||||||
|
.RS 4
|
||||||
|
Dump zone file in canonical format. This is always enabled for
|
||||||
|
\fBnamed\-compilezone\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-W \fImode\fR
|
||||||
|
.RS 4
|
||||||
|
Specify whether to check for non\-terminal wildcards. Non\-terminal wildcards are almost always the result of a failure to understand the wildcard matching algorithm (RFC 1034). Possible modes are
|
||||||
|
\fB"warn"\fR
|
||||||
|
(default) and
|
||||||
|
\fB"ignore"\fR.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
zonename
|
||||||
|
.RS 4
|
||||||
|
The domain name of the zone being checked.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
filename
|
||||||
|
.RS 4
|
||||||
|
The name of the zone file.
|
||||||
|
.RE
|
||||||
|
.SH "RETURN VALUES"
|
||||||
|
.PP
|
||||||
|
\fBnamed\-checkzone\fR
|
||||||
|
returns an exit status of 1 if errors were detected and 0 otherwise.
|
||||||
|
.SH "SEE ALSO"
|
||||||
|
.PP
|
||||||
|
\fBnamed\fR(8),
|
||||||
|
\fBnamed\-checkconf\fR(8),
|
||||||
|
RFC 1035,
|
||||||
|
BIND 9 Administrator Reference Manual.
|
||||||
|
.SH "AUTHOR"
|
||||||
|
.PP
|
||||||
|
Internet Systems Consortium
|
||||||
|
.SH "COPYRIGHT"
|
||||||
|
Copyright \(co 2004\-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
.br
|
||||||
|
Copyright \(co 2000\-2002 Internet Software Consortium.
|
||||||
|
.br
|
||||||
+123
-239
@@ -1,29 +1,35 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
* copyright notice and this permission notice appear in all copies.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
* information regarding copyright ownership.
|
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
* PERFORMANCE OF THIS SOFTWARE.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: named-checkzone.c,v 1.51.34.4.10.2 2010/09/07 23:46:26 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <config.h>
|
||||||
#include <stdbool.h>
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
|
|
||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/attributes.h>
|
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/socket.h>
|
#include <isc/socket.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/task.h>
|
#include <isc/task.h>
|
||||||
@@ -33,7 +39,6 @@
|
|||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/log.h>
|
#include <dns/log.h>
|
||||||
#include <dns/master.h>
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/rdataclass.h>
|
#include <dns/rdataclass.h>
|
||||||
@@ -46,49 +51,46 @@
|
|||||||
|
|
||||||
static int quiet = 0;
|
static int quiet = 0;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
static isc_entropy_t *ectx = NULL;
|
||||||
dns_zone_t *zone = NULL;
|
dns_zone_t *zone = NULL;
|
||||||
dns_zonetype_t zonetype = dns_zone_master;
|
dns_zonetype_t zonetype = dns_zone_master;
|
||||||
static int dumpzone = 0;
|
static int dumpzone = 0;
|
||||||
static const char *output_filename;
|
static const char *output_filename;
|
||||||
static const char *prog_name = NULL;
|
static char *prog_name = NULL;
|
||||||
static const dns_master_style_t *outputstyle = NULL;
|
static const dns_master_style_t *outputstyle = NULL;
|
||||||
static enum { progmode_check, progmode_compile } progmode;
|
static enum { progmode_check, progmode_compile } progmode;
|
||||||
|
|
||||||
#define ERRRET(result, function) \
|
#define ERRRET(result, function) \
|
||||||
do { \
|
do { \
|
||||||
if (result != ISC_R_SUCCESS) { \
|
if (result != ISC_R_SUCCESS) { \
|
||||||
if (!quiet) \
|
if (!quiet) \
|
||||||
fprintf(stderr, "%s() returned %s\n", \
|
fprintf(stderr, "%s() returned %s\n", \
|
||||||
function, dns_result_totext(result)); \
|
function, dns_result_totext(result)); \
|
||||||
return (result); \
|
return (result); \
|
||||||
} \
|
} \
|
||||||
} while (0)
|
} while (0)
|
||||||
|
|
||||||
ISC_NORETURN static void
|
|
||||||
usage(void);
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
usage(void) {
|
usage(void) {
|
||||||
fprintf(stderr,
|
fprintf(stderr,
|
||||||
"usage: %s [-djqvD] [-c class] "
|
"usage: %s [-djqvD] [-c class] "
|
||||||
"[-f inputformat] [-F outputformat] [-J filename] "
|
"[-f inputformat] [-F outputformat] "
|
||||||
"[-s (full|relative)] [-t directory] [-w directory] "
|
"[-t directory] [-w directory] [-k (ignore|warn|fail)] "
|
||||||
"[-k (ignore|warn|fail)] [-m (ignore|warn|fail)] "
|
"[-n (ignore|warn|fail)] [-m (ignore|warn|fail)] "
|
||||||
"[-n (ignore|warn|fail)] [-r (ignore|warn|fail)] "
|
|
||||||
"[-i (full|full-sibling|local|local-sibling|none)] "
|
"[-i (full|full-sibling|local|local-sibling|none)] "
|
||||||
"[-M (ignore|warn|fail)] [-S (ignore|warn|fail)] "
|
"[-M (ignore|warn|fail)] [-S (ignore|warn|fail)] "
|
||||||
"[-W (ignore|warn)] "
|
"[-W (ignore|warn)] "
|
||||||
"%s zonename [ (filename|-) ]\n",
|
"%s zonename filename\n",
|
||||||
prog_name,
|
prog_name,
|
||||||
progmode == progmode_check ? "[-o filename]" : "-o filename");
|
progmode == progmode_check ? "[-o filename]" : "{-o filename}");
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
destroy(void) {
|
destroy(void) {
|
||||||
if (zone != NULL) {
|
if (zone != NULL)
|
||||||
dns_zone_detach(&zone);
|
dns_zone_detach(&zone);
|
||||||
}
|
dns_name_destroy();
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% main processing routine */
|
/*% main processing routine */
|
||||||
@@ -96,7 +98,7 @@ int
|
|||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
int c;
|
int c;
|
||||||
char *origin = NULL;
|
char *origin = NULL;
|
||||||
const char *filename = NULL;
|
char *filename = NULL;
|
||||||
isc_log_t *lctx = NULL;
|
isc_log_t *lctx = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
char classname_in[] = "IN";
|
char classname_in[] = "IN";
|
||||||
@@ -106,69 +108,50 @@ main(int argc, char **argv) {
|
|||||||
const char *outputformatstr = NULL;
|
const char *outputformatstr = NULL;
|
||||||
dns_masterformat_t inputformat = dns_masterformat_text;
|
dns_masterformat_t inputformat = dns_masterformat_text;
|
||||||
dns_masterformat_t outputformat = dns_masterformat_text;
|
dns_masterformat_t outputformat = dns_masterformat_text;
|
||||||
dns_masterrawheader_t header;
|
|
||||||
uint32_t rawversion = 1, serialnum = 0;
|
|
||||||
dns_ttl_t maxttl = 0;
|
|
||||||
bool snset = false;
|
|
||||||
bool logdump = false;
|
|
||||||
FILE *errout = stdout;
|
FILE *errout = stdout;
|
||||||
char *endp;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Uncomment the following line if memory debugging is needed:
|
|
||||||
* isc_mem_debugging |= ISC_MEM_DEBUGRECORD;
|
|
||||||
*/
|
|
||||||
|
|
||||||
outputstyle = &dns_master_style_full;
|
outputstyle = &dns_master_style_full;
|
||||||
|
|
||||||
prog_name = strrchr(argv[0], '/');
|
prog_name = strrchr(argv[0], '/');
|
||||||
if (prog_name == NULL) {
|
if (prog_name == NULL)
|
||||||
prog_name = strrchr(argv[0], '\\');
|
prog_name = strrchr(argv[0], '\\');
|
||||||
}
|
if (prog_name != NULL)
|
||||||
if (prog_name != NULL) {
|
|
||||||
prog_name++;
|
prog_name++;
|
||||||
} else {
|
else
|
||||||
prog_name = argv[0];
|
prog_name = argv[0];
|
||||||
}
|
|
||||||
/*
|
/*
|
||||||
* Libtool doesn't preserve the program name prior to final
|
* Libtool doesn't preserve the program name prior to final
|
||||||
* installation. Remove the libtool prefix ("lt-").
|
* installation. Remove the libtool prefix ("lt-").
|
||||||
*/
|
*/
|
||||||
if (strncmp(prog_name, "lt-", 3) == 0) {
|
if (strncmp(prog_name, "lt-", 3) == 0)
|
||||||
prog_name += 3;
|
prog_name += 3;
|
||||||
}
|
|
||||||
|
|
||||||
#define PROGCMP(X) \
|
#define PROGCMP(X) \
|
||||||
(strcasecmp(prog_name, X) == 0 || strcasecmp(prog_name, X ".exe") == 0)
|
(strcasecmp(prog_name, X) == 0 || strcasecmp(prog_name, X ".exe") == 0)
|
||||||
|
|
||||||
if (PROGCMP("named-checkzone")) {
|
if (PROGCMP("named-checkzone"))
|
||||||
progmode = progmode_check;
|
progmode = progmode_check;
|
||||||
} else if (PROGCMP("named-compilezone")) {
|
else if (PROGCMP("named-compilezone"))
|
||||||
progmode = progmode_compile;
|
progmode = progmode_compile;
|
||||||
} else {
|
else
|
||||||
INSIST(0);
|
INSIST(0);
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Compilation specific defaults */
|
/* Compilation specific defaults */
|
||||||
if (progmode == progmode_compile) {
|
if (progmode == progmode_compile) {
|
||||||
zone_options |= (DNS_ZONEOPT_CHECKNS | DNS_ZONEOPT_FATALNS |
|
zone_options |= (DNS_ZONEOPT_CHECKNS |
|
||||||
DNS_ZONEOPT_CHECKSPF | DNS_ZONEOPT_CHECKDUPRR |
|
DNS_ZONEOPT_FATALNS |
|
||||||
DNS_ZONEOPT_CHECKNAMES |
|
DNS_ZONEOPT_CHECKNAMES |
|
||||||
DNS_ZONEOPT_CHECKNAMESFAIL |
|
DNS_ZONEOPT_CHECKNAMESFAIL |
|
||||||
DNS_ZONEOPT_CHECKWILDCARD);
|
DNS_ZONEOPT_CHECKWILDCARD);
|
||||||
} else {
|
|
||||||
zone_options |= (DNS_ZONEOPT_CHECKDUPRR | DNS_ZONEOPT_CHECKSPF);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#define ARGCMP(X) (strcmp(isc_commandline_argument, X) == 0)
|
#define ARGCMP(X) (strcmp(isc_commandline_argument, X) == 0)
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = ISC_FALSE;
|
||||||
|
|
||||||
while ((c = isc_commandline_parse(argc, argv,
|
while ((c = isc_commandline_parse(argc, argv,
|
||||||
"c:df:hi:jJ:k:L:l:m:n:qr:s:t:o:vw:DF:"
|
"c:df:hi:jk:m:n:qs:t:o:vw:DF:M:S:W:"))
|
||||||
"M:S:T:W:")) != EOF)
|
!= EOF) {
|
||||||
{
|
|
||||||
switch (c) {
|
switch (c) {
|
||||||
case 'c':
|
case 'c':
|
||||||
classname = isc_commandline_argument;
|
classname = isc_commandline_argument;
|
||||||
@@ -182,33 +165,33 @@ main(int argc, char **argv) {
|
|||||||
if (ARGCMP("full")) {
|
if (ARGCMP("full")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY |
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY |
|
||||||
DNS_ZONEOPT_CHECKSIBLING;
|
DNS_ZONEOPT_CHECKSIBLING;
|
||||||
docheckmx = true;
|
docheckmx = ISC_TRUE;
|
||||||
docheckns = true;
|
docheckns = ISC_TRUE;
|
||||||
dochecksrv = true;
|
dochecksrv = ISC_TRUE;
|
||||||
} else if (ARGCMP("full-sibling")) {
|
} else if (ARGCMP("full-sibling")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
||||||
docheckmx = true;
|
docheckmx = ISC_TRUE;
|
||||||
docheckns = true;
|
docheckns = ISC_TRUE;
|
||||||
dochecksrv = true;
|
dochecksrv = ISC_TRUE;
|
||||||
} else if (ARGCMP("local")) {
|
} else if (ARGCMP("local")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
zone_options |= DNS_ZONEOPT_CHECKSIBLING;
|
zone_options |= DNS_ZONEOPT_CHECKSIBLING;
|
||||||
docheckmx = false;
|
docheckmx = ISC_FALSE;
|
||||||
docheckns = false;
|
docheckns = ISC_FALSE;
|
||||||
dochecksrv = false;
|
dochecksrv = ISC_FALSE;
|
||||||
} else if (ARGCMP("local-sibling")) {
|
} else if (ARGCMP("local-sibling")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options |= DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
||||||
docheckmx = false;
|
docheckmx = ISC_FALSE;
|
||||||
docheckns = false;
|
docheckns = ISC_FALSE;
|
||||||
dochecksrv = false;
|
dochecksrv = ISC_FALSE;
|
||||||
} else if (ARGCMP("none")) {
|
} else if (ARGCMP("none")) {
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
|
zone_options &= ~DNS_ZONEOPT_CHECKINTEGRITY;
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
zone_options &= ~DNS_ZONEOPT_CHECKSIBLING;
|
||||||
docheckmx = false;
|
docheckmx = ISC_FALSE;
|
||||||
docheckns = false;
|
docheckns = ISC_FALSE;
|
||||||
dochecksrv = false;
|
dochecksrv = ISC_FALSE;
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "invalid argument to -i: %s\n",
|
fprintf(stderr, "invalid argument to -i: %s\n",
|
||||||
isc_commandline_argument);
|
isc_commandline_argument);
|
||||||
@@ -225,12 +208,7 @@ main(int argc, char **argv) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'j':
|
case 'j':
|
||||||
nomerge = false;
|
nomerge = ISC_FALSE;
|
||||||
break;
|
|
||||||
|
|
||||||
case 'J':
|
|
||||||
journal = isc_commandline_argument;
|
|
||||||
nomerge = false;
|
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'k':
|
case 'k':
|
||||||
@@ -250,37 +228,15 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'L':
|
|
||||||
snset = true;
|
|
||||||
endp = NULL;
|
|
||||||
serialnum = strtol(isc_commandline_argument, &endp, 0);
|
|
||||||
if (*endp != '\0') {
|
|
||||||
fprintf(stderr, "source serial number "
|
|
||||||
"must be numeric");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'l':
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
|
||||||
endp = NULL;
|
|
||||||
maxttl = strtol(isc_commandline_argument, &endp, 0);
|
|
||||||
if (*endp != '\0') {
|
|
||||||
fprintf(stderr, "maximum TTL "
|
|
||||||
"must be numeric");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'n':
|
case 'n':
|
||||||
if (ARGCMP("ignore")) {
|
if (ARGCMP("ignore")) {
|
||||||
zone_options &= ~(DNS_ZONEOPT_CHECKNS |
|
zone_options &= ~(DNS_ZONEOPT_CHECKNS|
|
||||||
DNS_ZONEOPT_FATALNS);
|
DNS_ZONEOPT_FATALNS);
|
||||||
} else if (ARGCMP("warn")) {
|
} else if (ARGCMP("warn")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKNS;
|
zone_options |= DNS_ZONEOPT_CHECKNS;
|
||||||
zone_options &= ~DNS_ZONEOPT_FATALNS;
|
zone_options &= ~DNS_ZONEOPT_FATALNS;
|
||||||
} else if (ARGCMP("fail")) {
|
} else if (ARGCMP("fail")) {
|
||||||
zone_options |= DNS_ZONEOPT_CHECKNS |
|
zone_options |= DNS_ZONEOPT_CHECKNS|
|
||||||
DNS_ZONEOPT_FATALNS;
|
DNS_ZONEOPT_FATALNS;
|
||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "invalid argument to -n: %s\n",
|
fprintf(stderr, "invalid argument to -n: %s\n",
|
||||||
@@ -306,44 +262,10 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'o':
|
|
||||||
output_filename = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'q':
|
case 'q':
|
||||||
quiet++;
|
quiet++;
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'r':
|
|
||||||
if (ARGCMP("warn")) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR;
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
} else if (ARGCMP("fail")) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR |
|
|
||||||
DNS_ZONEOPT_CHECKDUPRRFAIL;
|
|
||||||
} else if (ARGCMP("ignore")) {
|
|
||||||
zone_options &= ~(DNS_ZONEOPT_CHECKDUPRR |
|
|
||||||
DNS_ZONEOPT_CHECKDUPRRFAIL);
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "invalid argument to -r: %s\n",
|
|
||||||
isc_commandline_argument);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 's':
|
|
||||||
if (ARGCMP("full")) {
|
|
||||||
outputstyle = &dns_master_style_full;
|
|
||||||
} else if (ARGCMP("relative")) {
|
|
||||||
outputstyle = &dns_master_style_default;
|
|
||||||
} else {
|
|
||||||
fprintf(stderr,
|
|
||||||
"unknown or unsupported style: %s\n",
|
|
||||||
isc_commandline_argument);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 't':
|
case 't':
|
||||||
result = isc_dir_chroot(isc_commandline_argument);
|
result = isc_dir_chroot(isc_commandline_argument);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -354,8 +276,25 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case 's':
|
||||||
|
if (ARGCMP("full"))
|
||||||
|
outputstyle = &dns_master_style_full;
|
||||||
|
else if (ARGCMP("relative")) {
|
||||||
|
outputstyle = &dns_master_style_default;
|
||||||
|
} else {
|
||||||
|
fprintf(stderr,
|
||||||
|
"unknown or unsupported style: %s\n",
|
||||||
|
isc_commandline_argument);
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
|
||||||
|
case 'o':
|
||||||
|
output_filename = isc_commandline_argument;
|
||||||
|
break;
|
||||||
|
|
||||||
case 'v':
|
case 'v':
|
||||||
printf("%s\n", PACKAGE_VERSION);
|
printf(VERSION "\n");
|
||||||
exit(0);
|
exit(0);
|
||||||
|
|
||||||
case 'w':
|
case 'w':
|
||||||
@@ -400,38 +339,23 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'T':
|
|
||||||
if (ARGCMP("warn")) {
|
|
||||||
zone_options |= DNS_ZONEOPT_CHECKSPF;
|
|
||||||
} else if (ARGCMP("ignore")) {
|
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKSPF;
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "invalid argument to -T: %s\n",
|
|
||||||
isc_commandline_argument);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'W':
|
case 'W':
|
||||||
if (ARGCMP("warn")) {
|
if (ARGCMP("warn"))
|
||||||
zone_options |= DNS_ZONEOPT_CHECKWILDCARD;
|
zone_options |= DNS_ZONEOPT_CHECKWILDCARD;
|
||||||
} else if (ARGCMP("ignore")) {
|
else if (ARGCMP("ignore"))
|
||||||
zone_options &= ~DNS_ZONEOPT_CHECKWILDCARD;
|
zone_options &= ~DNS_ZONEOPT_CHECKWILDCARD;
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case '?':
|
case '?':
|
||||||
if (isc_commandline_option != '?') {
|
if (isc_commandline_option != '?')
|
||||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||||
prog_name, isc_commandline_option);
|
prog_name, isc_commandline_option);
|
||||||
}
|
|
||||||
/* FALLTHROUGH */
|
|
||||||
case 'h':
|
case 'h':
|
||||||
usage();
|
usage();
|
||||||
|
|
||||||
default:
|
default:
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n", prog_name,
|
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||||
isc_commandline_option);
|
prog_name, isc_commandline_option);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -439,48 +363,30 @@ main(int argc, char **argv) {
|
|||||||
if (workdir != NULL) {
|
if (workdir != NULL) {
|
||||||
result = isc_dir_chdir(workdir);
|
result = isc_dir_chdir(workdir);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fprintf(stderr, "isc_dir_chdir: %s: %s\n", workdir,
|
fprintf(stderr, "isc_dir_chdir: %s: %s\n",
|
||||||
isc_result_totext(result));
|
workdir, isc_result_totext(result));
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (inputformatstr != NULL) {
|
if (inputformatstr != NULL) {
|
||||||
if (strcasecmp(inputformatstr, "text") == 0) {
|
if (strcasecmp(inputformatstr, "text") == 0)
|
||||||
inputformat = dns_masterformat_text;
|
inputformat = dns_masterformat_text;
|
||||||
} else if (strcasecmp(inputformatstr, "raw") == 0) {
|
else if (strcasecmp(inputformatstr, "raw") == 0)
|
||||||
inputformat = dns_masterformat_raw;
|
inputformat = dns_masterformat_raw;
|
||||||
} else if (strncasecmp(inputformatstr, "raw=", 4) == 0) {
|
else {
|
||||||
inputformat = dns_masterformat_raw;
|
|
||||||
fprintf(stderr, "WARNING: input format raw, version "
|
|
||||||
"ignored\n");
|
|
||||||
} else if (strcasecmp(inputformatstr, "map") == 0) {
|
|
||||||
inputformat = dns_masterformat_map;
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "unknown file format: %s\n",
|
fprintf(stderr, "unknown file format: %s\n",
|
||||||
inputformatstr);
|
inputformatstr);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (outputformatstr != NULL) {
|
if (outputformatstr != NULL) {
|
||||||
if (strcasecmp(outputformatstr, "text") == 0) {
|
if (strcasecmp(outputformatstr, "text") == 0)
|
||||||
outputformat = dns_masterformat_text;
|
outputformat = dns_masterformat_text;
|
||||||
} else if (strcasecmp(outputformatstr, "raw") == 0) {
|
else if (strcasecmp(outputformatstr, "raw") == 0)
|
||||||
outputformat = dns_masterformat_raw;
|
outputformat = dns_masterformat_raw;
|
||||||
} else if (strncasecmp(outputformatstr, "raw=", 4) == 0) {
|
else {
|
||||||
char *end;
|
|
||||||
|
|
||||||
outputformat = dns_masterformat_raw;
|
|
||||||
rawversion = strtol(outputformatstr + 4, &end, 10);
|
|
||||||
if (end == outputformatstr + 4 || *end != '\0' ||
|
|
||||||
rawversion > 1U) {
|
|
||||||
fprintf(stderr, "unknown raw format version\n");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
} else if (strcasecmp(outputformatstr, "map") == 0) {
|
|
||||||
outputformat = dns_masterformat_map;
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "unknown file format: %s\n",
|
fprintf(stderr, "unknown file format: %s\n",
|
||||||
outputformatstr);
|
outputformatstr);
|
||||||
exit(1);
|
exit(1);
|
||||||
@@ -488,93 +394,71 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (progmode == progmode_compile) {
|
if (progmode == progmode_compile) {
|
||||||
dumpzone = 1; /* always dump */
|
dumpzone = 1; /* always dump */
|
||||||
logdump = !quiet;
|
|
||||||
if (output_filename == NULL) {
|
if (output_filename == NULL) {
|
||||||
fprintf(stderr, "output file required, but not "
|
fprintf(stderr,
|
||||||
"specified\n");
|
"output file required, but not specified\n");
|
||||||
usage();
|
usage();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (output_filename != NULL) {
|
if (output_filename != NULL)
|
||||||
dumpzone = 1;
|
dumpzone = 1;
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* If we are printing to stdout then send the informational
|
* If we are outputing to stdout then send the informational
|
||||||
* output to stderr.
|
* output to stderr.
|
||||||
*/
|
*/
|
||||||
if (dumpzone &&
|
if (dumpzone &&
|
||||||
(output_filename == NULL || strcmp(output_filename, "-") == 0 ||
|
(output_filename == NULL ||
|
||||||
|
strcmp(output_filename, "-") == 0 ||
|
||||||
strcmp(output_filename, "/dev/fd/1") == 0 ||
|
strcmp(output_filename, "/dev/fd/1") == 0 ||
|
||||||
strcmp(output_filename, "/dev/stdout") == 0))
|
strcmp(output_filename, "/dev/stdout") == 0))
|
||||||
{
|
|
||||||
errout = stderr;
|
errout = stderr;
|
||||||
logdump = false;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (argc - isc_commandline_index < 1 ||
|
if (isc_commandline_index + 2 != argc)
|
||||||
argc - isc_commandline_index > 2) {
|
|
||||||
usage();
|
usage();
|
||||||
}
|
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
InitSockets();
|
InitSockets();
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||||
if (!quiet) {
|
if (!quiet)
|
||||||
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx) ==
|
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx)
|
||||||
ISC_R_SUCCESS);
|
== ISC_R_SUCCESS);
|
||||||
}
|
RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
|
||||||
|
RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
|
||||||
|
== ISC_R_SUCCESS);
|
||||||
|
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
|
|
||||||
origin = argv[isc_commandline_index++];
|
origin = argv[isc_commandline_index++];
|
||||||
|
filename = argv[isc_commandline_index++];
|
||||||
if (isc_commandline_index == argc) {
|
|
||||||
/* "-" will be interpreted as stdin */
|
|
||||||
filename = "-";
|
|
||||||
} else {
|
|
||||||
filename = argv[isc_commandline_index];
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_commandline_index++;
|
|
||||||
|
|
||||||
result = load_zone(mctx, origin, filename, inputformat, classname,
|
result = load_zone(mctx, origin, filename, inputformat, classname,
|
||||||
maxttl, &zone);
|
&zone);
|
||||||
|
|
||||||
if (snset) {
|
|
||||||
dns_master_initrawheader(&header);
|
|
||||||
header.flags = DNS_MASTERRAW_SOURCESERIALSET;
|
|
||||||
header.sourceserial = serialnum;
|
|
||||||
dns_zone_setrawdata(zone, &header);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (result == ISC_R_SUCCESS && dumpzone) {
|
if (result == ISC_R_SUCCESS && dumpzone) {
|
||||||
if (logdump) {
|
if (!quiet && progmode == progmode_compile) {
|
||||||
fprintf(errout, "dump zone to %s...", output_filename);
|
fprintf(errout, "dump zone to %s...", output_filename);
|
||||||
fflush(errout);
|
fflush(errout);
|
||||||
}
|
}
|
||||||
result = dump_zone(origin, zone, output_filename, outputformat,
|
result = dump_zone(origin, zone, output_filename,
|
||||||
outputstyle, rawversion);
|
outputformat, outputstyle);
|
||||||
if (logdump) {
|
if (!quiet && progmode == progmode_compile)
|
||||||
fprintf(errout, "done\n");
|
fprintf(errout, "done\n");
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!quiet && result == ISC_R_SUCCESS) {
|
if (!quiet && result == ISC_R_SUCCESS)
|
||||||
fprintf(errout, "OK\n");
|
fprintf(errout, "OK\n");
|
||||||
}
|
|
||||||
destroy();
|
destroy();
|
||||||
if (lctx != NULL) {
|
if (lctx != NULL)
|
||||||
isc_log_destroy(&lctx);
|
isc_log_destroy(&lctx);
|
||||||
}
|
isc_hash_destroy();
|
||||||
|
isc_entropy_detach(&ectx);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
DestroySockets();
|
DestroySockets();
|
||||||
#endif /* ifdef _WIN32 */
|
#endif
|
||||||
|
|
||||||
return ((result == ISC_R_SUCCESS) ? 0 : 1);
|
return ((result == ISC_R_SUCCESS) ? 0 : 1);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,456 @@
|
|||||||
|
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||||
|
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||||
|
[<!ENTITY mdash "—">]>
|
||||||
|
<!--
|
||||||
|
- Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
- Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
-
|
||||||
|
- Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
- purpose with or without fee is hereby granted, provided that the above
|
||||||
|
- copyright notice and this permission notice appear in all copies.
|
||||||
|
-
|
||||||
|
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
- PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
-->
|
||||||
|
|
||||||
|
<!-- $Id: named-checkzone.docbook,v 1.34.334.3 2009/11/10 20:01:41 each Exp $ -->
|
||||||
|
<refentry id="man.named-checkzone">
|
||||||
|
<refentryinfo>
|
||||||
|
<date>June 13, 2000</date>
|
||||||
|
</refentryinfo>
|
||||||
|
|
||||||
|
<refmeta>
|
||||||
|
<refentrytitle><application>named-checkzone</application></refentrytitle>
|
||||||
|
<manvolnum>8</manvolnum>
|
||||||
|
<refmiscinfo>BIND9</refmiscinfo>
|
||||||
|
</refmeta>
|
||||||
|
|
||||||
|
<docinfo>
|
||||||
|
<copyright>
|
||||||
|
<year>2004</year>
|
||||||
|
<year>2005</year>
|
||||||
|
<year>2006</year>
|
||||||
|
<year>2007</year>
|
||||||
|
<year>2009</year>
|
||||||
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
|
</copyright>
|
||||||
|
<copyright>
|
||||||
|
<year>2000</year>
|
||||||
|
<year>2001</year>
|
||||||
|
<year>2002</year>
|
||||||
|
<holder>Internet Software Consortium.</holder>
|
||||||
|
</copyright>
|
||||||
|
</docinfo>
|
||||||
|
|
||||||
|
<refnamediv>
|
||||||
|
<refname><application>named-checkzone</application></refname>
|
||||||
|
<refname><application>named-compilezone</application></refname>
|
||||||
|
<refpurpose>zone file validity checking or converting tool</refpurpose>
|
||||||
|
</refnamediv>
|
||||||
|
|
||||||
|
<refsynopsisdiv>
|
||||||
|
<cmdsynopsis>
|
||||||
|
<command>named-checkzone</command>
|
||||||
|
<arg><option>-d</option></arg>
|
||||||
|
<arg><option>-h</option></arg>
|
||||||
|
<arg><option>-j</option></arg>
|
||||||
|
<arg><option>-q</option></arg>
|
||||||
|
<arg><option>-v</option></arg>
|
||||||
|
<arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||||
|
<arg><option>-f <replaceable class="parameter">format</replaceable></option></arg>
|
||||||
|
<arg><option>-F <replaceable class="parameter">format</replaceable></option></arg>
|
||||||
|
<arg><option>-i <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-k <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-m <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-M <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-n <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-s <replaceable class="parameter">style</replaceable></option></arg>
|
||||||
|
<arg><option>-S <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-t <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
|
<arg><option>-w <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
|
<arg><option>-D</option></arg>
|
||||||
|
<arg><option>-W <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg choice="req">zonename</arg>
|
||||||
|
<arg choice="req">filename</arg>
|
||||||
|
</cmdsynopsis>
|
||||||
|
<cmdsynopsis>
|
||||||
|
<command>named-compilezone</command>
|
||||||
|
<arg><option>-d</option></arg>
|
||||||
|
<arg><option>-j</option></arg>
|
||||||
|
<arg><option>-q</option></arg>
|
||||||
|
<arg><option>-v</option></arg>
|
||||||
|
<arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||||
|
<arg><option>-C <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-f <replaceable class="parameter">format</replaceable></option></arg>
|
||||||
|
<arg><option>-F <replaceable class="parameter">format</replaceable></option></arg>
|
||||||
|
<arg><option>-i <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-k <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-m <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-n <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg><option>-o <replaceable class="parameter">filename</replaceable></option></arg>
|
||||||
|
<arg><option>-s <replaceable class="parameter">style</replaceable></option></arg>
|
||||||
|
<arg><option>-t <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
|
<arg><option>-w <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
|
<arg><option>-D</option></arg>
|
||||||
|
<arg><option>-W <replaceable class="parameter">mode</replaceable></option></arg>
|
||||||
|
<arg choice="req"><option>-o <replaceable class="parameter">filename</replaceable></option></arg>
|
||||||
|
<arg choice="req">zonename</arg>
|
||||||
|
<arg choice="req">filename</arg>
|
||||||
|
</cmdsynopsis>
|
||||||
|
</refsynopsisdiv>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>DESCRIPTION</title>
|
||||||
|
<para><command>named-checkzone</command>
|
||||||
|
checks the syntax and integrity of a zone file. It performs the
|
||||||
|
same checks as <command>named</command> does when loading a
|
||||||
|
zone. This makes <command>named-checkzone</command> useful for
|
||||||
|
checking zone files before configuring them into a name server.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
<command>named-compilezone</command> is similar to
|
||||||
|
<command>named-checkzone</command>, but it always dumps the
|
||||||
|
zone contents to a specified file in a specified format.
|
||||||
|
Additionally, it applies stricter check levels by default,
|
||||||
|
since the dump output will be used as an actual zone file
|
||||||
|
loaded by <command>named</command>.
|
||||||
|
When manually specified otherwise, the check levels must at
|
||||||
|
least be as strict as those specified in the
|
||||||
|
<command>named</command> configuration file.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>OPTIONS</title>
|
||||||
|
|
||||||
|
<variablelist>
|
||||||
|
<varlistentry>
|
||||||
|
<term>-d</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Enable debugging.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-h</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print the usage summary and exit.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-q</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Quiet mode - exit code only.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-v</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print the version of the <command>named-checkzone</command>
|
||||||
|
program and exit.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-j</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
When loading the zone file read the journal if it exists.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-c <replaceable class="parameter">class</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify the class of the zone. If not specified, "IN" is assumed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-i <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Perform post-load zone integrity checks. Possible modes are
|
||||||
|
<command>"full"</command> (default),
|
||||||
|
<command>"full-sibling"</command>,
|
||||||
|
<command>"local"</command>,
|
||||||
|
<command>"local-sibling"</command> and
|
||||||
|
<command>"none"</command>.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Mode <command>"full"</command> checks that MX records
|
||||||
|
refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). Mode <command>"local"</command> only
|
||||||
|
checks MX records which refer to in-zone hostnames.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Mode <command>"full"</command> checks that SRV records
|
||||||
|
refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). Mode <command>"local"</command> only
|
||||||
|
checks SRV records which refer to in-zone hostnames.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Mode <command>"full"</command> checks that delegation NS
|
||||||
|
records refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). It also checks that glue address records
|
||||||
|
in the zone match those advertised by the child.
|
||||||
|
Mode <command>"local"</command> only checks NS records which
|
||||||
|
refer to in-zone hostnames or that some required glue exists,
|
||||||
|
that is when the nameserver is in a child zone.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Mode <command>"full-sibling"</command> and
|
||||||
|
<command>"local-sibling"</command> disable sibling glue
|
||||||
|
checks but are otherwise the same as <command>"full"</command>
|
||||||
|
and <command>"local"</command> respectively.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Mode <command>"none"</command> disables the checks.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-f <replaceable class="parameter">format</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify the format of the zone file.
|
||||||
|
Possible formats are <command>"text"</command> (default)
|
||||||
|
and <command>"raw"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-F <replaceable class="parameter">format</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify the format of the output file specified.
|
||||||
|
Possible formats are <command>"text"</command> (default)
|
||||||
|
and <command>"raw"</command>.
|
||||||
|
For <command>named-checkzone</command>,
|
||||||
|
this does not cause any effects unless it dumps the zone
|
||||||
|
contents.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-k <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Perform <command>"check-names"</command> checks with the
|
||||||
|
specified failure mode.
|
||||||
|
Possible modes are <command>"fail"</command>
|
||||||
|
(default for <command>named-compilezone</command>),
|
||||||
|
<command>"warn"</command>
|
||||||
|
(default for <command>named-checkzone</command>) and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-m <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify whether MX records should be checked to see if they
|
||||||
|
are addresses. Possible modes are <command>"fail"</command>,
|
||||||
|
<command>"warn"</command> (default) and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-M <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Check if a MX record refers to a CNAME.
|
||||||
|
Possible modes are <command>"fail"</command>,
|
||||||
|
<command>"warn"</command> (default) and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-n <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify whether NS records should be checked to see if they
|
||||||
|
are addresses.
|
||||||
|
Possible modes are <command>"fail"</command>
|
||||||
|
(default for <command>named-compilezone</command>),
|
||||||
|
<command>"warn"</command>
|
||||||
|
(default for <command>named-checkzone</command>) and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-o <replaceable class="parameter">filename</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Write zone output to <filename>filename</filename>.
|
||||||
|
If <filename>filename</filename> is <filename>-</filename> then
|
||||||
|
write to standard out.
|
||||||
|
This is mandatory for <command>named-compilezone</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-s <replaceable class="parameter">style</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify the style of the dumped zone file.
|
||||||
|
Possible styles are <command>"full"</command> (default)
|
||||||
|
and <command>"relative"</command>.
|
||||||
|
The full format is most suitable for processing
|
||||||
|
automatically by a separate script.
|
||||||
|
On the other hand, the relative format is more
|
||||||
|
human-readable and is thus suitable for editing by hand.
|
||||||
|
For <command>named-checkzone</command>
|
||||||
|
this does not cause any effects unless it dumps the zone
|
||||||
|
contents.
|
||||||
|
It also does not have any meaning if the output format
|
||||||
|
is not text.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-S <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Check if a SRV record refers to a CNAME.
|
||||||
|
Possible modes are <command>"fail"</command>,
|
||||||
|
<command>"warn"</command> (default) and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-t <replaceable class="parameter">directory</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Chroot to <filename>directory</filename> so that
|
||||||
|
include
|
||||||
|
directives in the configuration file are processed as if
|
||||||
|
run by a similarly chrooted named.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-w <replaceable class="parameter">directory</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
chdir to <filename>directory</filename> so that
|
||||||
|
relative
|
||||||
|
filenames in master file $INCLUDE directives work. This
|
||||||
|
is similar to the directory clause in
|
||||||
|
<filename>named.conf</filename>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-D</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Dump zone file in canonical format.
|
||||||
|
This is always enabled for <command>named-compilezone</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-W <replaceable class="parameter">mode</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specify whether to check for non-terminal wildcards.
|
||||||
|
Non-terminal wildcards are almost always the result of a
|
||||||
|
failure to understand the wildcard matching algorithm (RFC 1034).
|
||||||
|
Possible modes are <command>"warn"</command> (default)
|
||||||
|
and
|
||||||
|
<command>"ignore"</command>.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>zonename</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
The domain name of the zone being checked.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>filename</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
The name of the zone file.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
</variablelist>
|
||||||
|
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>RETURN VALUES</title>
|
||||||
|
<para><command>named-checkzone</command>
|
||||||
|
returns an exit status of 1 if
|
||||||
|
errors were detected and 0 otherwise.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>SEE ALSO</title>
|
||||||
|
<para><citerefentry>
|
||||||
|
<refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
|
||||||
|
</citerefentry>,
|
||||||
|
<citerefentry>
|
||||||
|
<refentrytitle>named-checkconf</refentrytitle><manvolnum>8</manvolnum>
|
||||||
|
</citerefentry>,
|
||||||
|
<citetitle>RFC 1035</citetitle>,
|
||||||
|
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
<refsect1>
|
||||||
|
<title>AUTHOR</title>
|
||||||
|
<para><corpauthor>Internet Systems Consortium</corpauthor>
|
||||||
|
</para>
|
||||||
|
</refsect1>
|
||||||
|
|
||||||
|
</refentry><!--
|
||||||
|
- Local variables:
|
||||||
|
- mode: sgml
|
||||||
|
- End:
|
||||||
|
-->
|
||||||
@@ -0,0 +1,262 @@
|
|||||||
|
<!--
|
||||||
|
- Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
- Copyright (C) 2000-2002 Internet Software Consortium.
|
||||||
|
-
|
||||||
|
- Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
- purpose with or without fee is hereby granted, provided that the above
|
||||||
|
- copyright notice and this permission notice appear in all copies.
|
||||||
|
-
|
||||||
|
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||||
|
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
- PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
-->
|
||||||
|
<!-- $Id: named-checkzone.html,v 1.42.334.3 2009/11/11 01:56:22 tbox Exp $ -->
|
||||||
|
<html>
|
||||||
|
<head>
|
||||||
|
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||||
|
<title>named-checkzone</title>
|
||||||
|
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
|
||||||
|
</head>
|
||||||
|
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
|
||||||
|
<a name="man.named-checkzone"></a><div class="titlepage"></div>
|
||||||
|
<div class="refnamediv">
|
||||||
|
<h2>Name</h2>
|
||||||
|
<p><span class="application">named-checkzone</span>, <span class="application">named-compilezone</span> — zone file validity checking or converting tool</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsynopsisdiv">
|
||||||
|
<h2>Synopsis</h2>
|
||||||
|
<div class="cmdsynopsis"><p><code class="command">named-checkzone</code> [<code class="option">-d</code>] [<code class="option">-h</code>] [<code class="option">-j</code>] [<code class="option">-q</code>] [<code class="option">-v</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-f <em class="replaceable"><code>format</code></em></code>] [<code class="option">-F <em class="replaceable"><code>format</code></em></code>] [<code class="option">-i <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-k <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-m <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-M <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-n <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-s <em class="replaceable"><code>style</code></em></code>] [<code class="option">-S <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-w <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-W <em class="replaceable"><code>mode</code></em></code>] {zonename} {filename}</p></div>
|
||||||
|
<div class="cmdsynopsis"><p><code class="command">named-compilezone</code> [<code class="option">-d</code>] [<code class="option">-j</code>] [<code class="option">-q</code>] [<code class="option">-v</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-C <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-f <em class="replaceable"><code>format</code></em></code>] [<code class="option">-F <em class="replaceable"><code>format</code></em></code>] [<code class="option">-i <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-k <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-m <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-n <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-o <em class="replaceable"><code>filename</code></em></code>] [<code class="option">-s <em class="replaceable"><code>style</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-w <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-W <em class="replaceable"><code>mode</code></em></code>] {<code class="option">-o <em class="replaceable"><code>filename</code></em></code>} {zonename} {filename}</p></div>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543674"></a><h2>DESCRIPTION</h2>
|
||||||
|
<p><span><strong class="command">named-checkzone</strong></span>
|
||||||
|
checks the syntax and integrity of a zone file. It performs the
|
||||||
|
same checks as <span><strong class="command">named</strong></span> does when loading a
|
||||||
|
zone. This makes <span><strong class="command">named-checkzone</strong></span> useful for
|
||||||
|
checking zone files before configuring them into a name server.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
<span><strong class="command">named-compilezone</strong></span> is similar to
|
||||||
|
<span><strong class="command">named-checkzone</strong></span>, but it always dumps the
|
||||||
|
zone contents to a specified file in a specified format.
|
||||||
|
Additionally, it applies stricter check levels by default,
|
||||||
|
since the dump output will be used as an actual zone file
|
||||||
|
loaded by <span><strong class="command">named</strong></span>.
|
||||||
|
When manually specified otherwise, the check levels must at
|
||||||
|
least be as strict as those specified in the
|
||||||
|
<span><strong class="command">named</strong></span> configuration file.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2543709"></a><h2>OPTIONS</h2>
|
||||||
|
<div class="variablelist"><dl>
|
||||||
|
<dt><span class="term">-d</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Enable debugging.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-h</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Print the usage summary and exit.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-q</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Quiet mode - exit code only.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-v</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Print the version of the <span><strong class="command">named-checkzone</strong></span>
|
||||||
|
program and exit.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-j</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
When loading the zone file read the journal if it exists.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify the class of the zone. If not specified, "IN" is assumed.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-i <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Perform post-load zone integrity checks. Possible modes are
|
||||||
|
<span><strong class="command">"full"</strong></span> (default),
|
||||||
|
<span><strong class="command">"full-sibling"</strong></span>,
|
||||||
|
<span><strong class="command">"local"</strong></span>,
|
||||||
|
<span><strong class="command">"local-sibling"</strong></span> and
|
||||||
|
<span><strong class="command">"none"</strong></span>.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Mode <span><strong class="command">"full"</strong></span> checks that MX records
|
||||||
|
refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). Mode <span><strong class="command">"local"</strong></span> only
|
||||||
|
checks MX records which refer to in-zone hostnames.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Mode <span><strong class="command">"full"</strong></span> checks that SRV records
|
||||||
|
refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). Mode <span><strong class="command">"local"</strong></span> only
|
||||||
|
checks SRV records which refer to in-zone hostnames.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Mode <span><strong class="command">"full"</strong></span> checks that delegation NS
|
||||||
|
records refer to A or AAAA record (both in-zone and out-of-zone
|
||||||
|
hostnames). It also checks that glue address records
|
||||||
|
in the zone match those advertised by the child.
|
||||||
|
Mode <span><strong class="command">"local"</strong></span> only checks NS records which
|
||||||
|
refer to in-zone hostnames or that some required glue exists,
|
||||||
|
that is when the nameserver is in a child zone.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Mode <span><strong class="command">"full-sibling"</strong></span> and
|
||||||
|
<span><strong class="command">"local-sibling"</strong></span> disable sibling glue
|
||||||
|
checks but are otherwise the same as <span><strong class="command">"full"</strong></span>
|
||||||
|
and <span><strong class="command">"local"</strong></span> respectively.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Mode <span><strong class="command">"none"</strong></span> disables the checks.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-f <em class="replaceable"><code>format</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify the format of the zone file.
|
||||||
|
Possible formats are <span><strong class="command">"text"</strong></span> (default)
|
||||||
|
and <span><strong class="command">"raw"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-F <em class="replaceable"><code>format</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify the format of the output file specified.
|
||||||
|
Possible formats are <span><strong class="command">"text"</strong></span> (default)
|
||||||
|
and <span><strong class="command">"raw"</strong></span>.
|
||||||
|
For <span><strong class="command">named-checkzone</strong></span>,
|
||||||
|
this does not cause any effects unless it dumps the zone
|
||||||
|
contents.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-k <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Perform <span><strong class="command">"check-names"</strong></span> checks with the
|
||||||
|
specified failure mode.
|
||||||
|
Possible modes are <span><strong class="command">"fail"</strong></span>
|
||||||
|
(default for <span><strong class="command">named-compilezone</strong></span>),
|
||||||
|
<span><strong class="command">"warn"</strong></span>
|
||||||
|
(default for <span><strong class="command">named-checkzone</strong></span>) and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-m <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify whether MX records should be checked to see if they
|
||||||
|
are addresses. Possible modes are <span><strong class="command">"fail"</strong></span>,
|
||||||
|
<span><strong class="command">"warn"</strong></span> (default) and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-M <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Check if a MX record refers to a CNAME.
|
||||||
|
Possible modes are <span><strong class="command">"fail"</strong></span>,
|
||||||
|
<span><strong class="command">"warn"</strong></span> (default) and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-n <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify whether NS records should be checked to see if they
|
||||||
|
are addresses.
|
||||||
|
Possible modes are <span><strong class="command">"fail"</strong></span>
|
||||||
|
(default for <span><strong class="command">named-compilezone</strong></span>),
|
||||||
|
<span><strong class="command">"warn"</strong></span>
|
||||||
|
(default for <span><strong class="command">named-checkzone</strong></span>) and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-o <em class="replaceable"><code>filename</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Write zone output to <code class="filename">filename</code>.
|
||||||
|
If <code class="filename">filename</code> is <code class="filename">-</code> then
|
||||||
|
write to standard out.
|
||||||
|
This is mandatory for <span><strong class="command">named-compilezone</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-s <em class="replaceable"><code>style</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify the style of the dumped zone file.
|
||||||
|
Possible styles are <span><strong class="command">"full"</strong></span> (default)
|
||||||
|
and <span><strong class="command">"relative"</strong></span>.
|
||||||
|
The full format is most suitable for processing
|
||||||
|
automatically by a separate script.
|
||||||
|
On the other hand, the relative format is more
|
||||||
|
human-readable and is thus suitable for editing by hand.
|
||||||
|
For <span><strong class="command">named-checkzone</strong></span>
|
||||||
|
this does not cause any effects unless it dumps the zone
|
||||||
|
contents.
|
||||||
|
It also does not have any meaning if the output format
|
||||||
|
is not text.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-S <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Check if a SRV record refers to a CNAME.
|
||||||
|
Possible modes are <span><strong class="command">"fail"</strong></span>,
|
||||||
|
<span><strong class="command">"warn"</strong></span> (default) and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Chroot to <code class="filename">directory</code> so that
|
||||||
|
include
|
||||||
|
directives in the configuration file are processed as if
|
||||||
|
run by a similarly chrooted named.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-w <em class="replaceable"><code>directory</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
chdir to <code class="filename">directory</code> so that
|
||||||
|
relative
|
||||||
|
filenames in master file $INCLUDE directives work. This
|
||||||
|
is similar to the directory clause in
|
||||||
|
<code class="filename">named.conf</code>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-D</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Dump zone file in canonical format.
|
||||||
|
This is always enabled for <span><strong class="command">named-compilezone</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">-W <em class="replaceable"><code>mode</code></em></span></dt>
|
||||||
|
<dd><p>
|
||||||
|
Specify whether to check for non-terminal wildcards.
|
||||||
|
Non-terminal wildcards are almost always the result of a
|
||||||
|
failure to understand the wildcard matching algorithm (RFC 1034).
|
||||||
|
Possible modes are <span><strong class="command">"warn"</strong></span> (default)
|
||||||
|
and
|
||||||
|
<span><strong class="command">"ignore"</strong></span>.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">zonename</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
The domain name of the zone being checked.
|
||||||
|
</p></dd>
|
||||||
|
<dt><span class="term">filename</span></dt>
|
||||||
|
<dd><p>
|
||||||
|
The name of the zone file.
|
||||||
|
</p></dd>
|
||||||
|
</dl></div>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2544330"></a><h2>RETURN VALUES</h2>
|
||||||
|
<p><span><strong class="command">named-checkzone</strong></span>
|
||||||
|
returns an exit status of 1 if
|
||||||
|
errors were detected and 0 otherwise.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2544342"></a><h2>SEE ALSO</h2>
|
||||||
|
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||||
|
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||||
|
<em class="citetitle">RFC 1035</em>,
|
||||||
|
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<div class="refsect1" lang="en">
|
||||||
|
<a name="id2544375"></a><h2>AUTHOR</h2>
|
||||||
|
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div></body>
|
||||||
|
</html>
|
||||||
@@ -1,213 +0,0 @@
|
|||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
|
|
||||||
.. highlight: console
|
|
||||||
|
|
||||||
named-checkzone, named-compilezone - zone file validity checking or converting tool
|
|
||||||
-----------------------------------------------------------------------------------
|
|
||||||
|
|
||||||
Synopsis
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:program:`named-checkzone` [**-d**] [**-h**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-M** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-o** filename] [**-r** mode] [**-s** style] [**-S** mode] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {zonename} {filename}
|
|
||||||
|
|
||||||
:program:`named-compilezone` [**-d**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-C** mode] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-r** mode] [**-s** style] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {**-o** filename} {zonename} {filename}
|
|
||||||
|
|
||||||
Description
|
|
||||||
~~~~~~~~~~~
|
|
||||||
|
|
||||||
``named-checkzone`` checks the syntax and integrity of a zone file. It
|
|
||||||
performs the same checks as ``named`` does when loading a zone. This
|
|
||||||
makes ``named-checkzone`` useful for checking zone files before
|
|
||||||
configuring them into a name server.
|
|
||||||
|
|
||||||
``named-compilezone`` is similar to ``named-checkzone``, but it always
|
|
||||||
dumps the zone contents to a specified file in a specified format.
|
|
||||||
It also applies stricter check levels by default, since the
|
|
||||||
dump output is used as an actual zone file loaded by ``named``.
|
|
||||||
When manually specified otherwise, the check levels must at least be as
|
|
||||||
strict as those specified in the ``named`` configuration file.
|
|
||||||
|
|
||||||
Options
|
|
||||||
~~~~~~~
|
|
||||||
|
|
||||||
``-d``
|
|
||||||
This option enables debugging.
|
|
||||||
|
|
||||||
``-h``
|
|
||||||
This option prints the usage summary and exits.
|
|
||||||
|
|
||||||
``-q``
|
|
||||||
This option sets quiet mode, which only sets an exit code to indicate
|
|
||||||
successful or failed completion.
|
|
||||||
|
|
||||||
``-v``
|
|
||||||
This option prints the version of the ``named-checkzone`` program and exits.
|
|
||||||
|
|
||||||
``-j``
|
|
||||||
When loading a zone file, this option tells ``named`` to read the journal if it exists. The journal
|
|
||||||
file name is assumed to be the zone file name with the
|
|
||||||
string ``.jnl`` appended.
|
|
||||||
|
|
||||||
``-J filename``
|
|
||||||
When loading the zone file, this option tells ``named`` to read the journal from the given file, if
|
|
||||||
it exists. This implies ``-j``.
|
|
||||||
|
|
||||||
``-c class``
|
|
||||||
This option specifies the class of the zone. If not specified, ``IN`` is assumed.
|
|
||||||
|
|
||||||
``-i mode``
|
|
||||||
This option performs post-load zone integrity checks. Possible modes are
|
|
||||||
``full`` (the default), ``full-sibling``, ``local``,
|
|
||||||
``local-sibling``, and ``none``.
|
|
||||||
|
|
||||||
Mode ``full`` checks that MX records refer to A or AAAA records
|
|
||||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
|
||||||
checks MX records which refer to in-zone hostnames.
|
|
||||||
|
|
||||||
Mode ``full`` checks that SRV records refer to A or AAAA records
|
|
||||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
|
||||||
checks SRV records which refer to in-zone hostnames.
|
|
||||||
|
|
||||||
Mode ``full`` checks that delegation NS records refer to A or AAAA
|
|
||||||
records (both in-zone and out-of-zone hostnames). It also checks that
|
|
||||||
glue address records in the zone match those advertised by the child.
|
|
||||||
Mode ``local`` only checks NS records which refer to in-zone
|
|
||||||
hostnames or verifies that some required glue exists, i.e., when the
|
|
||||||
name server is in a child zone.
|
|
||||||
|
|
||||||
Modes ``full-sibling`` and ``local-sibling`` disable sibling glue
|
|
||||||
checks, but are otherwise the same as ``full`` and ``local``,
|
|
||||||
respectively.
|
|
||||||
|
|
||||||
Mode ``none`` disables the checks.
|
|
||||||
|
|
||||||
``-f format``
|
|
||||||
This option specifies the format of the zone file. Possible formats are ``text``
|
|
||||||
(the default), ``raw``, and ``map``.
|
|
||||||
|
|
||||||
``-F format``
|
|
||||||
This option specifies the format of the output file specified. For
|
|
||||||
``named-checkzone``, this does not have any effect unless it dumps
|
|
||||||
the zone contents.
|
|
||||||
|
|
||||||
Possible formats are ``text`` (the default), which is the standard
|
|
||||||
textual representation of the zone, and ``map``, ``raw``, and
|
|
||||||
``raw=N``, which store the zone in a binary format for rapid
|
|
||||||
loading by ``named``. ``raw=N`` specifies the format version of the
|
|
||||||
raw zone file: if ``N`` is 0, the raw file can be read by any version of
|
|
||||||
``named``; if N is 1, the file can only be read by release 9.9.0 or
|
|
||||||
higher. The default is 1.
|
|
||||||
|
|
||||||
``-k mode``
|
|
||||||
This option performs ``check-names`` checks with the specified failure mode.
|
|
||||||
Possible modes are ``fail`` (the default for ``named-compilezone``),
|
|
||||||
``warn`` (the default for ``named-checkzone``), and ``ignore``.
|
|
||||||
|
|
||||||
``-l ttl``
|
|
||||||
This option sets a maximum permissible TTL for the input file. Any record with a
|
|
||||||
TTL higher than this value causes the zone to be rejected. This
|
|
||||||
is similar to using the ``max-zone-ttl`` option in ``named.conf``.
|
|
||||||
|
|
||||||
``-L serial``
|
|
||||||
When compiling a zone to ``raw`` or ``map`` format, this option sets the "source
|
|
||||||
serial" value in the header to the specified serial number. This is
|
|
||||||
expected to be used primarily for testing purposes.
|
|
||||||
|
|
||||||
``-m mode``
|
|
||||||
This option specifies whether MX records should be checked to see if they are
|
|
||||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and
|
|
||||||
``ignore``.
|
|
||||||
|
|
||||||
``-M mode``
|
|
||||||
This option checks whether a MX record refers to a CNAME. Possible modes are
|
|
||||||
``fail``, ``warn`` (the default), and ``ignore``.
|
|
||||||
|
|
||||||
``-n mode``
|
|
||||||
This option specifies whether NS records should be checked to see if they are
|
|
||||||
addresses. Possible modes are ``fail`` (the default for
|
|
||||||
``named-compilezone``), ``warn`` (the default for ``named-checkzone``),
|
|
||||||
and ``ignore``.
|
|
||||||
|
|
||||||
``-o filename``
|
|
||||||
This option writes the zone output to ``filename``. If ``filename`` is ``-``, then
|
|
||||||
the zone output is written to standard output. This is mandatory for ``named-compilezone``.
|
|
||||||
|
|
||||||
``-r mode``
|
|
||||||
This option checks for records that are treated as different by DNSSEC but are
|
|
||||||
semantically equal in plain DNS. Possible modes are ``fail``,
|
|
||||||
``warn`` (the default), and ``ignore``.
|
|
||||||
|
|
||||||
``-s style``
|
|
||||||
This option specifies the style of the dumped zone file. Possible styles are
|
|
||||||
``full`` (the default) and ``relative``. The ``full`` format is most
|
|
||||||
suitable for processing automatically by a separate script.
|
|
||||||
The relative format is more human-readable and is thus
|
|
||||||
suitable for editing by hand. For ``named-checkzone``, this does not
|
|
||||||
have any effect unless it dumps the zone contents. It also does not
|
|
||||||
have any meaning if the output format is not text.
|
|
||||||
|
|
||||||
``-S mode``
|
|
||||||
This option checks whether an SRV record refers to a CNAME. Possible modes are
|
|
||||||
``fail``, ``warn`` (the default), and ``ignore``.
|
|
||||||
|
|
||||||
``-t directory``
|
|
||||||
This option tells ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
|
||||||
configuration file are processed as if run by a similarly chrooted
|
|
||||||
``named``.
|
|
||||||
|
|
||||||
``-T mode``
|
|
||||||
This option checks whether Sender Policy Framework (SPF) records exist and issues a
|
|
||||||
warning if an SPF-formatted TXT record is not also present. Possible
|
|
||||||
modes are ``warn`` (the default) and ``ignore``.
|
|
||||||
|
|
||||||
``-w directory``
|
|
||||||
This option instructs ``named`` to chdir to ``directory``, so that relative filenames in master file
|
|
||||||
``$INCLUDE`` directives work. This is similar to the directory clause in
|
|
||||||
``named.conf``.
|
|
||||||
|
|
||||||
``-D``
|
|
||||||
This option dumps the zone file in canonical format. This is always enabled for
|
|
||||||
``named-compilezone``.
|
|
||||||
|
|
||||||
``-W mode``
|
|
||||||
This option specifies whether to check for non-terminal wildcards. Non-terminal
|
|
||||||
wildcards are almost always the result of a failure to understand the
|
|
||||||
wildcard matching algorithm (:rfc:`1034`). Possible modes are ``warn``
|
|
||||||
(the default) and ``ignore``.
|
|
||||||
|
|
||||||
``zonename``
|
|
||||||
This indicates the domain name of the zone being checked.
|
|
||||||
|
|
||||||
``filename``
|
|
||||||
This is the name of the zone file.
|
|
||||||
|
|
||||||
Return Values
|
|
||||||
~~~~~~~~~~~~~
|
|
||||||
|
|
||||||
``named-checkzone`` returns an exit status of 1 if errors were detected
|
|
||||||
and 0 otherwise.
|
|
||||||
|
|
||||||
See Also
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:manpage:`named(8)`, :manpage:`named-checkconf(8)`, :rfc:`1035`, BIND 9 Administrator Reference
|
|
||||||
Manual.
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup>
|
|
||||||
<Filter Include="Source Files">
|
|
||||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
|
||||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Header Files">
|
|
||||||
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
|
|
||||||
<Extensions>h;hpp;hxx;hm;inl;inc;xsd</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
|
||||||
</Filter>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\check-tool.h">
|
|
||||||
<Filter>Header Files</Filter>
|
|
||||||
</ClInclude>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\named-checkconf.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
</ItemGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,144 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project DefaultTargets="Build" ToolsVersion="@TOOLS_VERSION@" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup Label="ProjectConfigurations">
|
|
||||||
<ProjectConfiguration Include="Debug|@PLATFORM@">
|
|
||||||
<Configuration>Debug</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
<ProjectConfiguration Include="Release|@PLATFORM@">
|
|
||||||
<Configuration>Release</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
</ItemGroup>
|
|
||||||
<PropertyGroup Label="Globals">
|
|
||||||
<ProjectGuid>{03A96113-CB14-43AA-AEB2-48950E3915C5}</ProjectGuid>
|
|
||||||
<Keyword>Win32Proj</Keyword>
|
|
||||||
<RootNamespace>checkconf</RootNamespace>
|
|
||||||
@WINDOWS_TARGET_PLATFORM_VERSION@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>Application</ConfigurationType>
|
|
||||||
<UseDebugLibraries>true</UseDebugLibraries>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>Application</ConfigurationType>
|
|
||||||
<UseDebugLibraries>false</UseDebugLibraries>
|
|
||||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
|
||||||
<ImportGroup Label="ExtensionSettings">
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<PropertyGroup Label="UserMacros" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<LinkIncremental>true</LinkIncremental>
|
|
||||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
<TargetName>named-$(ProjectName)</TargetName>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<LinkIncremental>false</LinkIncremental>
|
|
||||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
<TargetName>named-$(ProjectName)</TargetName>
|
|
||||||
</PropertyGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<WarningLevel>Level4</WarningLevel>
|
|
||||||
<TreatWarningAsError>false</TreatWarningAsError>
|
|
||||||
<Optimization>Disabled</Optimization>
|
|
||||||
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<BrowseInformation>true</BrowseInformation>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
|
||||||
<AdditionalDependencies>@OPENSSL_LIBCRYPTO@@OPENSSL_LIBSSL@checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
|
||||||
</Link>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<WarningLevel>Level1</WarningLevel>
|
|
||||||
<TreatWarningAsError>true</TreatWarningAsError>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<Optimization>MaxSpeed</Optimization>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<IntrinsicFunctions>@INTRINSIC@</IntrinsicFunctions>
|
|
||||||
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<InlineFunctionExpansion>OnlyExplicitInline</InlineFunctionExpansion>
|
|
||||||
<WholeProgramOptimization>false</WholeProgramOptimization>
|
|
||||||
<StringPooling>true</StringPooling>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>false</GenerateDebugInformation>
|
|
||||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
|
||||||
<OptimizeReferences>true</OptimizeReferences>
|
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
|
||||||
<AdditionalDependencies>@OPENSSL_LIBCRYPTO@@OPENSSL_LIBSSL@checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
|
||||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
|
||||||
</Link>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\check-tool.h" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\named-checkconf.c" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isc\win32\libisc.vcxproj">
|
|
||||||
<Project>{3840E563-D180-4761-AA9C-E6155F02EAFF}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\dns\win32\libdns.vcxproj">
|
|
||||||
<Project>{5FEBFD4E-CCB0-48B9-B733-E15EEB85C16A}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\ns\win32\libns.vcxproj">
|
|
||||||
<Project>{82ACD33C-E75F-45B8-BB6D-42643A10D7EE}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isccfg\win32\libisccfg.vcxproj">
|
|
||||||
<Project>{B2DFA58C-6347-478E-81E8-01E06999D4F1}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\bind9\win32\libbind9.vcxproj">
|
|
||||||
<Project>{E741C10B-B075-4206-9596-46765B665E03}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\bin\check\win32\checktool.vcxproj">
|
|
||||||
<Project>{2C1F7096-C5B5-48D4-846F-A7ACA454335D}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
</ItemGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
|
||||||
<ImportGroup Label="ExtensionTargets">
|
|
||||||
</ImportGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
</Project>
|
|
||||||
@@ -0,0 +1,113 @@
|
|||||||
|
# Microsoft Developer Studio Project File - Name="checktool" - Package Owner=<4>
|
||||||
|
# Microsoft Developer Studio Generated Build File, Format Version 6.00
|
||||||
|
# ** DO NOT EDIT **
|
||||||
|
|
||||||
|
# TARGTYPE "Win32 (x86) Static-Link Library" 0x0104
|
||||||
|
|
||||||
|
CFG=checktool - Win32 Debug
|
||||||
|
!MESSAGE This is not a valid makefile. To build this project using NMAKE,
|
||||||
|
!MESSAGE use the Export Makefile command and run
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "checktool.mak".
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE You can specify a configuration when running NMAKE
|
||||||
|
!MESSAGE by defining the macro CFG on the command line. For example:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "checktool.mak" CFG="checktool - Win32 Debug"
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE Possible choices for configuration are:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE "checktool - Win32 Release" (based on "Win32 (x86) Static-Link Library")
|
||||||
|
!MESSAGE "checktool - Win32 Debug" (based on "Win32 (x86) Static-Link Library")
|
||||||
|
!MESSAGE
|
||||||
|
|
||||||
|
# Begin Project
|
||||||
|
# PROP AllowPerConfigDependencies 0
|
||||||
|
# PROP Scc_ProjName ""
|
||||||
|
# PROP Scc_LocalPath ""
|
||||||
|
CPP=cl.exe
|
||||||
|
MTL=midl.exe
|
||||||
|
RSC=rc.exe
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "checktool - Win32 Release"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 0
|
||||||
|
# PROP BASE Output_Dir "Release"
|
||||||
|
# PROP BASE Intermediate_Dir "Release"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 0
|
||||||
|
# PROP Output_Dir "Release"
|
||||||
|
# PROP Intermediate_Dir "Release"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /MT /W3 /GX /O2 /D "WIN32" /D "NDEBUG" /D "_WINDOWS" /D "_MBCS" /D "_USRDLL" /YX /FD /c
|
||||||
|
# ADD CPP /nologo /MD /W3 /GX /O2 /I "./" /I "../../../" /I "../include" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isccfg/include" /I "../../../lib/dns/include" /D "NDEBUG" /D "WIN32" /D "_WINDOWS" /D "__STDC__" /D "_MBCS" /YX /FD /c /Fdchecktool
|
||||||
|
# SUBTRACT CPP /X
|
||||||
|
# ADD BASE MTL /nologo /D "NDEBUG" /mktyplib203 /win32
|
||||||
|
# ADD MTL /nologo /D "NDEBUG" /mktyplib203 /win32
|
||||||
|
# ADD BASE RSC /l 0x409 /d "NDEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "NDEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32
|
||||||
|
# ADD LINK32 /out:"Release/checktool.lib"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "checktool - Win32 Debug"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 1
|
||||||
|
# PROP BASE Output_Dir "Debug"
|
||||||
|
# PROP BASE Intermediate_Dir "Debug"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 1
|
||||||
|
# PROP Output_Dir "Debug"
|
||||||
|
# PROP Intermediate_Dir "Debug"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /MTd /W3 /Gm /GX /ZI /Od /D "WIN32" /D "_DEBUG" /D "_WINDOWS" /D "_MBCS" /YX /FD /GZ /c
|
||||||
|
# ADD CPP /nologo /MDd /W3 /Gm /GX /ZI /Od /I "./" /I "../../../" /I "../include" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isccfg/include" /I "../../../lib/dns/include" /D "_DEBUG" /D "WIN32" /D "_WINDOWS" /D "__STDC__" /D "_MBCS" /FR /YX /FD /GZ /c /Fdchecktool
|
||||||
|
# SUBTRACT CPP /X
|
||||||
|
# ADD BASE MTL /nologo /D "_DEBUG" /mktyplib203 /win32
|
||||||
|
# ADD MTL /nologo /D "_DEBUG" /mktyplib203 /win32
|
||||||
|
# ADD BASE RSC /l 0x409 /d "_DEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "_DEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32
|
||||||
|
# ADD LINK32 /debug out:"Debug/checktool.lib"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
# Begin Target
|
||||||
|
|
||||||
|
# Name "checktool - Win32 Release"
|
||||||
|
# Name "checktool - Win32 Debug"
|
||||||
|
# Begin Group "Source Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "cpp;c;cxx;rc;def;r;odl;idl;hpj;bat"
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Header Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "h;hpp;hxx;hm;inl"
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Resource Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe"
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Main Dns Lib"
|
||||||
|
|
||||||
|
# PROP Default_Filter "c"
|
||||||
|
# Begin Source File
|
||||||
|
|
||||||
|
SOURCE=..\check-tool.c
|
||||||
|
# End Source File
|
||||||
|
# End Group
|
||||||
|
# End Target
|
||||||
|
# End Project
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
Microsoft Developer Studio Workspace File, Format Version 6.00
|
||||||
|
# WARNING: DO NOT EDIT OR DELETE THIS WORKSPACE FILE!
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Project: "checktool"=".\checktool.dsp" - Package Owner=<4>
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<4>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Global:
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<3>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup>
|
|
||||||
<Filter Include="Source Files">
|
|
||||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
|
||||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
|
||||||
</Filter>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\check-tool.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
</ItemGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,124 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project DefaultTargets="Build" ToolsVersion="@TOOLS_VERSION@" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup Label="ProjectConfigurations">
|
|
||||||
<ProjectConfiguration Include="Debug|@PLATFORM@">
|
|
||||||
<Configuration>Debug</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
<ProjectConfiguration Include="Release|@PLATFORM@">
|
|
||||||
<Configuration>Release</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\check-tool.c" />
|
|
||||||
</ItemGroup>
|
|
||||||
<PropertyGroup Label="Globals">
|
|
||||||
<ProjectGuid>{2C1F7096-C5B5-48D4-846F-A7ACA454335D}</ProjectGuid>
|
|
||||||
<Keyword>Win32Proj</Keyword>
|
|
||||||
<RootNamespace>checktool</RootNamespace>
|
|
||||||
@WINDOWS_TARGET_PLATFORM_VERSION@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>StaticLibrary</ConfigurationType>
|
|
||||||
<UseDebugLibraries>true</UseDebugLibraries>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>StaticLibrary</ConfigurationType>
|
|
||||||
<UseDebugLibraries>false</UseDebugLibraries>
|
|
||||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
|
||||||
<ImportGroup Label="ExtensionSettings">
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<PropertyGroup Label="UserMacros" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<OutDir>.\$(Configuration)\</OutDir>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<OutDir>.\$(Configuration)\</OutDir>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
</PropertyGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<WarningLevel>Level4</WarningLevel>
|
|
||||||
<TreatWarningAsError>false</TreatWarningAsError>
|
|
||||||
<Optimization>Disabled</Optimization>
|
|
||||||
<PreprocessorDefinitions>WIN32;_DEBUG;_LIB;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(TargetName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<BrowseInformation>true</BrowseInformation>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Lib>
|
|
||||||
<OutputFile>.\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
</Lib>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<WarningLevel>Level1</WarningLevel>
|
|
||||||
<TreatWarningAsError>true</TreatWarningAsError>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<Optimization>MaxSpeed</Optimization>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<IntrinsicFunctions>@INTRINSIC@</IntrinsicFunctions>
|
|
||||||
<PreprocessorDefinitions>WIN32;NDEBUG;_LIB;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<InlineFunctionExpansion>OnlyExplicitInline</InlineFunctionExpansion>
|
|
||||||
<WholeProgramOptimization>false</WholeProgramOptimization>
|
|
||||||
<StringPooling>true</StringPooling>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(TargetName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Lib>
|
|
||||||
<OutputFile>.\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
</Lib>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isc\win32\libisc.vcxproj">
|
|
||||||
<Project>{3840E563-D180-4761-AA9C-E6155F02EAFF}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\dns\win32\libdns.vcxproj">
|
|
||||||
<Project>{5FEBFD4E-CCB0-48B9-B733-E15EEB85C16A}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\ns\win32\libns.vcxproj">
|
|
||||||
<Project>{82ACD33C-E75F-45B8-BB6D-42643A10D7EE}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isccfg\win32\libisccfg.vcxproj">
|
|
||||||
<Project>{B2DFA58C-6347-478E-81E8-01E06999D4F1}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
</ItemGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
|
||||||
<ImportGroup Label="ExtensionTargets">
|
|
||||||
</ImportGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
</Project>
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup>
|
|
||||||
<Filter Include="Source Files">
|
|
||||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
|
||||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Header Files">
|
|
||||||
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
|
|
||||||
<Extensions>h;hpp;hxx;hm;inl;inc;xsd</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
|
||||||
</Filter>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\check-tool.h">
|
|
||||||
<Filter>Header Files</Filter>
|
|
||||||
</ClInclude>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\named-checkzone.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
</ItemGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,152 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project DefaultTargets="Build" ToolsVersion="@TOOLS_VERSION@" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup Label="ProjectConfigurations">
|
|
||||||
<ProjectConfiguration Include="Debug|@PLATFORM@">
|
|
||||||
<Configuration>Debug</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
<ProjectConfiguration Include="Release|@PLATFORM@">
|
|
||||||
<Configuration>Release</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
</ItemGroup>
|
|
||||||
<PropertyGroup Label="Globals">
|
|
||||||
<ProjectGuid>{66028555-7DD5-4016-B601-9EF9A1EE8BFA}</ProjectGuid>
|
|
||||||
<Keyword>Win32Proj</Keyword>
|
|
||||||
<RootNamespace>checkzone</RootNamespace>
|
|
||||||
@WINDOWS_TARGET_PLATFORM_VERSION@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>Application</ConfigurationType>
|
|
||||||
<UseDebugLibraries>true</UseDebugLibraries>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>Application</ConfigurationType>
|
|
||||||
<UseDebugLibraries>false</UseDebugLibraries>
|
|
||||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
|
||||||
<ImportGroup Label="ExtensionSettings">
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<PropertyGroup Label="UserMacros" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<LinkIncremental>true</LinkIncremental>
|
|
||||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
<TargetName>named-$(ProjectName)</TargetName>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<LinkIncremental>false</LinkIncremental>
|
|
||||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
<TargetName>named-$(ProjectName)</TargetName>
|
|
||||||
</PropertyGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<WarningLevel>Level4</WarningLevel>
|
|
||||||
<TreatWarningAsError>false</TreatWarningAsError>
|
|
||||||
<Optimization>Disabled</Optimization>
|
|
||||||
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<BrowseInformation>true</BrowseInformation>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
|
||||||
<AdditionalDependencies>@OPENSSL_LIBCRYPTO@@OPENSSL_LIBSSL@checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
|
||||||
</Link>
|
|
||||||
<PostBuildEvent>
|
|
||||||
<Command>cd ..\..\..\Build\$(Configuration)
|
|
||||||
copy /Y named-checkzone.exe named-compilezone.exe
|
|
||||||
copy /Y named-checkzone.ilk named-compilezone.ilk
|
|
||||||
</Command>
|
|
||||||
</PostBuildEvent>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<WarningLevel>Level1</WarningLevel>
|
|
||||||
<TreatWarningAsError>true</TreatWarningAsError>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<Optimization>MaxSpeed</Optimization>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<IntrinsicFunctions>@INTRINSIC@</IntrinsicFunctions>
|
|
||||||
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<InlineFunctionExpansion>OnlyExplicitInline</InlineFunctionExpansion>
|
|
||||||
<WholeProgramOptimization>false</WholeProgramOptimization>
|
|
||||||
<StringPooling>true</StringPooling>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>false</GenerateDebugInformation>
|
|
||||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
|
||||||
<OptimizeReferences>true</OptimizeReferences>
|
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
|
||||||
<AdditionalDependencies>@OPENSSL_LIBCRYPTO@@OPENSSL_LIBSSL@checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
|
||||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
|
||||||
</Link>
|
|
||||||
<PostBuildEvent>
|
|
||||||
<Command>cd ..\..\..\Build\$(Configuration)
|
|
||||||
copy /Y named-checkzone.exe named-compilezone.exe
|
|
||||||
</Command>
|
|
||||||
</PostBuildEvent>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\check-tool.h" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\named-checkzone.c" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isc\win32\libisc.vcxproj">
|
|
||||||
<Project>{3840E563-D180-4761-AA9C-E6155F02EAFF}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\dns\win32\libdns.vcxproj">
|
|
||||||
<Project>{5FEBFD4E-CCB0-48B9-B733-E15EEB85C16A}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\ns\win32\libns.vcxproj">
|
|
||||||
<Project>{82ACD33C-E75F-45B8-BB6D-42643A10D7EE}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isccfg\win32\libisccfg.vcxproj">
|
|
||||||
<Project>{B2DFA58C-6347-478E-81E8-01E06999D4F1}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\bin\check\win32\checktool.vcxproj">
|
|
||||||
<Project>{2C1F7096-C5B5-48D4-846F-A7ACA454335D}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
</ItemGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
|
||||||
<ImportGroup Label="ExtensionTargets">
|
|
||||||
</ImportGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
</Project>
|
|
||||||
@@ -0,0 +1,107 @@
|
|||||||
|
# Microsoft Developer Studio Project File - Name="namedcheckconf" - Package Owner=<4>
|
||||||
|
# Microsoft Developer Studio Generated Build File, Format Version 6.00
|
||||||
|
# ** DO NOT EDIT **
|
||||||
|
|
||||||
|
# TARGTYPE "Win32 (x86) Console Application" 0x0103
|
||||||
|
|
||||||
|
CFG=namedcheckconf - Win32 Debug
|
||||||
|
!MESSAGE This is not a valid makefile. To build this project using NMAKE,
|
||||||
|
!MESSAGE use the Export Makefile command and run
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckconf.mak".
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE You can specify a configuration when running NMAKE
|
||||||
|
!MESSAGE by defining the macro CFG on the command line. For example:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckconf.mak" CFG="namedcheckconf - Win32 Debug"
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE Possible choices for configuration are:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE "namedcheckconf - Win32 Release" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE "namedcheckconf - Win32 Debug" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE
|
||||||
|
|
||||||
|
# Begin Project
|
||||||
|
# PROP AllowPerConfigDependencies 0
|
||||||
|
# PROP Scc_ProjName ""
|
||||||
|
# PROP Scc_LocalPath ""
|
||||||
|
CPP=cl.exe
|
||||||
|
RSC=rc.exe
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 0
|
||||||
|
# PROP BASE Output_Dir "Release"
|
||||||
|
# PROP BASE Intermediate_Dir "Release"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 0
|
||||||
|
# PROP Output_Dir "Release"
|
||||||
|
# PROP Intermediate_Dir "Release"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /W3 /GX /O2 /D "WIN32" /D "NDEBUG" /D "_CONSOLE" /D "_MBCS" /YX /FD /c
|
||||||
|
# ADD CPP /nologo /MD /W3 /GX /O2 /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/bind9/include" /I "../../../lib/isccfg/include" /D "NDEBUG" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /D "__STDC__" /FR /YX /FD /c
|
||||||
|
# ADD BASE RSC /l 0x409 /d "NDEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "NDEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32 kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib /nologo /subsystem:console /machine:I386
|
||||||
|
# ADD LINK32 user32.lib advapi32.lib ws2_32.lib Release/checktool.lib ../../../lib/isc/win32/Release/libisc.lib ../../../lib/dns/win32/Release/libdns.lib ../../../lib/isccfg/win32/Release/libisccfg.lib ../../../lib/bind9/win32/Release/libbind9.lib /nologo /subsystem:console /machine:I386 /out:"../../../Build/Release/named-checkconf.exe"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 1
|
||||||
|
# PROP BASE Output_Dir "Debug"
|
||||||
|
# PROP BASE Intermediate_Dir "Debug"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 1
|
||||||
|
# PROP Output_Dir "Debug"
|
||||||
|
# PROP Intermediate_Dir "Debug"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /W3 /Gm /GX /ZI /Od /D "WIN32" /D "_DEBUG" /D "_CONSOLE" /D "_MBCS" /YX /FD /GZ /c
|
||||||
|
# ADD CPP /nologo /MDd /W3 /Gm /GX /ZI /Od /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/bind9/include" /I "../../../lib/isccfg/include" /D "_DEBUG" /D "__STDC__" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /FR /FD /GZ /c
|
||||||
|
# SUBTRACT CPP /X /YX
|
||||||
|
# ADD BASE RSC /l 0x409 /d "_DEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "_DEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32 kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib /nologo /subsystem:console /debug /machine:I386 /pdbtype:sept
|
||||||
|
# ADD LINK32 user32.lib advapi32.lib ws2_32.lib Debug/checktool.lib ../../../lib/isc/win32/Debug/libisc.lib ../../../lib/dns/win32/Debug/libdns.lib ../../../lib/isccfg/win32/Debug/libisccfg.lib ../../../lib/bind9/win32/Debug/libbind9.lib ../../../lib/bind9/win32/Debug/libbind9.lib /nologo /subsystem:console /debug /machine:I386 /out:"../../../Build/Debug/named-checkconf.exe" /pdbtype:sept
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
# Begin Target
|
||||||
|
|
||||||
|
# Name "namedcheckconf - Win32 Release"
|
||||||
|
# Name "namedcheckconf - Win32 Debug"
|
||||||
|
# Begin Group "Source Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "cpp;c;cxx;rc;def;r;odl;idl;hpj;bat"
|
||||||
|
# Begin Source File
|
||||||
|
|
||||||
|
SOURCE="..\named-checkconf.c"
|
||||||
|
# End Source File
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Header Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "h;hpp;hxx;hm;inl"
|
||||||
|
# Begin Source File
|
||||||
|
|
||||||
|
SOURCE="..\check-tool.h"
|
||||||
|
# End Source File
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Resource Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe"
|
||||||
|
# End Group
|
||||||
|
# End Target
|
||||||
|
# End Project
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
Microsoft Developer Studio Workspace File, Format Version 6.00
|
||||||
|
# WARNING: DO NOT EDIT OR DELETE THIS WORKSPACE FILE!
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Project: "namedcheckconf"=".\namedcheckconf.dsp" - Package Owner=<4>
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<4>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Global:
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<3>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
@@ -0,0 +1,404 @@
|
|||||||
|
# Microsoft Developer Studio Generated NMAKE File, Based on namedcheckconf.dsp
|
||||||
|
!IF "$(CFG)" == ""
|
||||||
|
CFG=namedcheckconf - Win32 Debug
|
||||||
|
!MESSAGE No configuration specified. Defaulting to namedcheckconf - Win32 Debug.
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" != "namedcheckconf - Win32 Release" && "$(CFG)" != "namedcheckconf - Win32 Debug"
|
||||||
|
!MESSAGE Invalid configuration "$(CFG)" specified.
|
||||||
|
!MESSAGE You can specify a configuration when running NMAKE
|
||||||
|
!MESSAGE by defining the macro CFG on the command line. For example:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckconf.mak" CFG="namedcheckconf - Win32 Debug"
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE Possible choices for configuration are:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE "namedcheckconf - Win32 Release" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE "namedcheckconf - Win32 Debug" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE
|
||||||
|
!ERROR An invalid configuration is specified.
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(OS)" == "Windows_NT"
|
||||||
|
NULL=
|
||||||
|
!ELSE
|
||||||
|
NULL=nul
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
CPP=cl.exe
|
||||||
|
RSC=rc.exe
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
_VC_MANIFEST_INC=0
|
||||||
|
_VC_MANIFEST_BASENAME=__VC80
|
||||||
|
!ELSE
|
||||||
|
_VC_MANIFEST_INC=1
|
||||||
|
_VC_MANIFEST_BASENAME=__VC80.Debug
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# Specifying name of temporary resource file used only in incremental builds:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
_VC_MANIFEST_AUTO_RES=$(_VC_MANIFEST_BASENAME).auto.res
|
||||||
|
!else
|
||||||
|
_VC_MANIFEST_AUTO_RES=
|
||||||
|
!endif
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_EMBED_EXE - command to embed manifest in EXE:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
#MT_SPECIAL_RETURN=1090650113
|
||||||
|
#MT_SPECIAL_SWITCH=-notify_resource_update
|
||||||
|
MT_SPECIAL_RETURN=0
|
||||||
|
MT_SPECIAL_SWITCH=
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -out:$(_VC_MANIFEST_BASENAME).auto.manifest $(MT_SPECIAL_SWITCH) & \
|
||||||
|
if "%ERRORLEVEL%" == "$(MT_SPECIAL_RETURN)" \
|
||||||
|
rc /r $(_VC_MANIFEST_BASENAME).auto.rc & \
|
||||||
|
link $** /out:$@ $(LFLAGS)
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -outputresource:$@;1
|
||||||
|
|
||||||
|
!endif
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_EMBED_DLL - command to embed manifest in DLL:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
#MT_SPECIAL_RETURN=1090650113
|
||||||
|
#MT_SPECIAL_SWITCH=-notify_resource_update
|
||||||
|
MT_SPECIAL_RETURN=0
|
||||||
|
MT_SPECIAL_SWITCH=
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -out:$(_VC_MANIFEST_BASENAME).auto.manifest $(MT_SPECIAL_SWITCH) & \
|
||||||
|
if "%ERRORLEVEL%" == "$(MT_SPECIAL_RETURN)" \
|
||||||
|
rc /r $(_VC_MANIFEST_BASENAME).auto.rc & \
|
||||||
|
link $** /out:$@ $(LFLAGS)
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -outputresource:$@;2
|
||||||
|
|
||||||
|
!endif
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_CLEAN - command to clean resources files generated temporarily:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
_VC_MANIFEST_CLEAN=-del $(_VC_MANIFEST_BASENAME).auto.res \
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.rc \
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.manifest
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_CLEAN=
|
||||||
|
|
||||||
|
!endif
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
|
||||||
|
OUTDIR=.\Release
|
||||||
|
INTDIR=.\Release
|
||||||
|
# Begin Custom Macros
|
||||||
|
OutDir=.\Release
|
||||||
|
# End Custom Macros
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "0"
|
||||||
|
|
||||||
|
ALL : "..\..\..\Build\Release\named-checkconf.exe" "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
|
||||||
|
!ELSE
|
||||||
|
|
||||||
|
ALL : "libdns - Win32 Release" "libisccfg - Win32 Release" "libisc - Win32 Release" "..\..\..\Build\Release\named-checkconf.exe" "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "1"
|
||||||
|
CLEAN :"libisc - Win32 ReleaseCLEAN" "libisccfg - Win32 ReleaseCLEAN" "libdns - Win32 ReleaseCLEAN"
|
||||||
|
!ELSE
|
||||||
|
CLEAN :
|
||||||
|
!ENDIF
|
||||||
|
-@erase "$(INTDIR)\check-tool.obj"
|
||||||
|
-@erase "$(INTDIR)\check-tool.sbr"
|
||||||
|
-@erase "$(INTDIR)\named-checkconf.obj"
|
||||||
|
-@erase "$(INTDIR)\named-checkconf.sbr"
|
||||||
|
-@erase "$(INTDIR)\vc60.idb"
|
||||||
|
-@erase "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
-@erase "..\..\..\Build\Release\named-checkconf.exe"
|
||||||
|
-@$(_VC_MANIFEST_CLEAN)
|
||||||
|
|
||||||
|
"$(OUTDIR)" :
|
||||||
|
if not exist "$(OUTDIR)/$(NULL)" mkdir "$(OUTDIR)"
|
||||||
|
|
||||||
|
CPP_PROJ=/nologo /MD /W3 /GX /O2 /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/bind9/include" /I "../../../lib/isccfg/include" /D "NDEBUG" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /D "__STDC__" /FR"$(INTDIR)\\" /Fp"$(INTDIR)\namedcheckconf.pch" /YX /Fo"$(INTDIR)\\" /Fd"$(INTDIR)\\" /FD /c
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
BSC32_FLAGS=/nologo /o"$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
BSC32_SBRS= \
|
||||||
|
"$(INTDIR)\check-tool.sbr" \
|
||||||
|
"$(INTDIR)\named-checkconf.sbr"
|
||||||
|
|
||||||
|
"$(OUTDIR)\namedcheckconf.bsc" : "$(OUTDIR)" $(BSC32_SBRS)
|
||||||
|
$(BSC32) @<<
|
||||||
|
$(BSC32_FLAGS) $(BSC32_SBRS)
|
||||||
|
<<
|
||||||
|
|
||||||
|
LINK32=link.exe
|
||||||
|
LINK32_FLAGS=user32.lib advapi32.lib ws2_32.lib ../../../lib/isc/win32/Release/libisc.lib ../../../lib/dns/win32/Release/libdns.lib ../../../lib/isccfg/win32/Release/libisccfg.lib ../../../lib/bind9/win32/Release/libbind9.lib /nologo /subsystem:console /incremental:no /pdb:"$(OUTDIR)\named-checkconf.pdb" /machine:I386 /out:"../../../Build/Release/named-checkconf.exe"
|
||||||
|
LINK32_OBJS= \
|
||||||
|
"$(INTDIR)\check-tool.obj" \
|
||||||
|
"$(INTDIR)\named-checkconf.obj" \
|
||||||
|
"..\..\..\lib\isc\win32\Release\libisc.lib" \
|
||||||
|
"..\..\..\lib\isccfg\win32\Release\libisccfg.lib" \
|
||||||
|
"..\..\..\lib\dns\win32\Release\libdns.lib"
|
||||||
|
|
||||||
|
"..\..\..\Build\Release\named-checkconf.exe" : "$(OUTDIR)" $(DEF_FILE) $(LINK32_OBJS)
|
||||||
|
$(LINK32) @<<
|
||||||
|
$(LINK32_FLAGS) $(LINK32_OBJS)
|
||||||
|
<<
|
||||||
|
$(_VC_MANIFEST_EMBED_EXE)
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
|
||||||
|
OUTDIR=.\Debug
|
||||||
|
INTDIR=.\Debug
|
||||||
|
# Begin Custom Macros
|
||||||
|
OutDir=.\Debug
|
||||||
|
# End Custom Macros
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "0"
|
||||||
|
|
||||||
|
ALL : "..\..\..\Build\Debug\named-checkconf.exe" "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
|
||||||
|
!ELSE
|
||||||
|
|
||||||
|
ALL : "libdns - Win32 Debug" "libisccfg - Win32 Debug" "libisc - Win32 Debug" "..\..\..\Build\Debug\named-checkconf.exe" "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "1"
|
||||||
|
CLEAN :"libisc - Win32 DebugCLEAN" "libisccfg - Win32 DebugCLEAN" "libdns - Win32 DebugCLEAN"
|
||||||
|
!ELSE
|
||||||
|
CLEAN :
|
||||||
|
!ENDIF
|
||||||
|
-@erase "$(INTDIR)\check-tool.obj"
|
||||||
|
-@erase "$(INTDIR)\check-tool.sbr"
|
||||||
|
-@erase "$(INTDIR)\named-checkconf.obj"
|
||||||
|
-@erase "$(INTDIR)\named-checkconf.sbr"
|
||||||
|
-@erase "$(INTDIR)\vc60.idb"
|
||||||
|
-@erase "$(INTDIR)\vc60.pdb"
|
||||||
|
-@erase "$(OUTDIR)\named-checkconf.pdb"
|
||||||
|
-@erase "$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
-@erase "..\..\..\Build\Debug\named-checkconf.exe"
|
||||||
|
-@erase "..\..\..\Build\Debug\named-checkconf.ilk"
|
||||||
|
-@$(_VC_MANIFEST_CLEAN)
|
||||||
|
|
||||||
|
"$(OUTDIR)" :
|
||||||
|
if not exist "$(OUTDIR)/$(NULL)" mkdir "$(OUTDIR)"
|
||||||
|
|
||||||
|
CPP_PROJ=/nologo /MDd /W3 /Gm /GX /ZI /Od /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/bind9/include" /I "../../../lib/isccfg/include" /D "_DEBUG" /D "__STDC__" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /FR"$(INTDIR)\\" /Fo"$(INTDIR)\\" /Fd"$(INTDIR)\\" /FD /GZ /c
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
BSC32_FLAGS=/nologo /o"$(OUTDIR)\namedcheckconf.bsc"
|
||||||
|
BSC32_SBRS= \
|
||||||
|
"$(INTDIR)\check-tool.sbr" \
|
||||||
|
"$(INTDIR)\named-checkconf.sbr"
|
||||||
|
|
||||||
|
"$(OUTDIR)\namedcheckconf.bsc" : "$(OUTDIR)" $(BSC32_SBRS)
|
||||||
|
$(BSC32) @<<
|
||||||
|
$(BSC32_FLAGS) $(BSC32_SBRS)
|
||||||
|
<<
|
||||||
|
|
||||||
|
LINK32=link.exe
|
||||||
|
LINK32_FLAGS=user32.lib advapi32.lib ws2_32.lib ../../../lib/isc/win32/Debug/libisc.lib ../../../lib/dns/win32/Debug/libdns.lib ../../../lib/isccfg/win32/Debug/libisccfg.lib ../../../lib/bind9/win32/Debug/libbind9.lib ../../../lib/bind9/win32/Debug/libbind9.lib /nologo /subsystem:console /incremental:yes /pdb:"$(OUTDIR)\named-checkconf.pdb" /debug /machine:I386 /out:"../../../Build/Debug/named-checkconf.exe" /pdbtype:sept
|
||||||
|
LINK32_OBJS= \
|
||||||
|
"$(INTDIR)\check-tool.obj" \
|
||||||
|
"$(INTDIR)\named-checkconf.obj" \
|
||||||
|
"..\..\..\lib\isc\win32\Debug\libisc.lib" \
|
||||||
|
"..\..\..\lib\isccfg\win32\Debug\libisccfg.lib" \
|
||||||
|
"..\..\..\lib\dns\win32\Debug\libdns.lib"
|
||||||
|
|
||||||
|
"..\..\..\Build\Debug\named-checkconf.exe" : "$(OUTDIR)" $(DEF_FILE) $(LINK32_OBJS)
|
||||||
|
$(LINK32) @<<
|
||||||
|
$(LINK32_FLAGS) $(LINK32_OBJS)
|
||||||
|
<<
|
||||||
|
$(_VC_MANIFEST_EMBED_EXE)
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
|
||||||
|
!IF "$(NO_EXTERNAL_DEPS)" != "1"
|
||||||
|
!IF EXISTS("namedcheckconf.dep")
|
||||||
|
!INCLUDE "namedcheckconf.dep"
|
||||||
|
!ELSE
|
||||||
|
!MESSAGE Warning: cannot find "namedcheckconf.dep"
|
||||||
|
!ENDIF
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release" || "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
SOURCE="..\check-tool.c"
|
||||||
|
|
||||||
|
"$(INTDIR)\check-tool.obj" "$(INTDIR)\check-tool.sbr" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
SOURCE="..\named-checkconf.c"
|
||||||
|
|
||||||
|
"$(INTDIR)\named-checkconf.obj" "$(INTDIR)\named-checkconf.sbr" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
|
||||||
|
"libisc - Win32 Release" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Release"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisc - Win32 ReleaseCLEAN" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Release" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
|
||||||
|
"libisc - Win32 Debug" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Debug"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisc - Win32 DebugCLEAN" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Debug" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
|
||||||
|
"libisccfg - Win32 Release" :
|
||||||
|
cd "..\..\..\lib\isccfg\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisccfg.mak" CFG="libisccfg - Win32 Release"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisccfg - Win32 ReleaseCLEAN" :
|
||||||
|
cd "..\..\..\lib\isccfg\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisccfg.mak" CFG="libisccfg - Win32 Release" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
|
||||||
|
"libisccfg - Win32 Debug" :
|
||||||
|
cd "..\..\..\lib\isccfg\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisccfg.mak" CFG="libisccfg - Win32 Debug"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisccfg - Win32 DebugCLEAN" :
|
||||||
|
cd "..\..\..\lib\isccfg\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisccfg.mak" CFG="libisccfg - Win32 Debug" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckconf - Win32 Release"
|
||||||
|
|
||||||
|
"libdns - Win32 Release" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Release"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libdns - Win32 ReleaseCLEAN" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Release" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckconf - Win32 Debug"
|
||||||
|
|
||||||
|
"libdns - Win32 Debug" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Debug"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libdns - Win32 DebugCLEAN" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Debug" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# Commands to generate initial empty manifest file and the RC file
|
||||||
|
# that references it, and for generating the .res file:
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.res : $(_VC_MANIFEST_BASENAME).auto.rc
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.rc : $(_VC_MANIFEST_BASENAME).auto.manifest
|
||||||
|
type <<$@
|
||||||
|
#include <winuser.h>
|
||||||
|
1RT_MANIFEST"$(_VC_MANIFEST_BASENAME).auto.manifest"
|
||||||
|
<< KEEP
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.manifest :
|
||||||
|
type <<$@
|
||||||
|
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
|
||||||
|
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
|
||||||
|
</assembly>
|
||||||
|
<< KEEP
|
||||||
|
####################################################
|
||||||
|
# Commands to generate initial empty manifest file and the RC file
|
||||||
|
# that references it, and for generating the .res file:
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.res : $(_VC_MANIFEST_BASENAME).auto.rc
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.rc : $(_VC_MANIFEST_BASENAME).auto.manifest
|
||||||
|
type <<$@
|
||||||
|
#include <winuser.h>
|
||||||
|
1RT_MANIFEST"$(_VC_MANIFEST_BASENAME).auto.manifest"
|
||||||
|
<< KEEP
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.manifest :
|
||||||
|
type <<$@
|
||||||
|
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
|
||||||
|
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
|
||||||
|
</assembly>
|
||||||
|
<< KEEP
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
# Microsoft Developer Studio Project File - Name="namedcheckzone" - Package Owner=<4>
|
||||||
|
# Microsoft Developer Studio Generated Build File, Format Version 6.00
|
||||||
|
# ** DO NOT EDIT **
|
||||||
|
|
||||||
|
# TARGTYPE "Win32 (x86) Console Application" 0x0103
|
||||||
|
|
||||||
|
CFG=namedcheckzone - Win32 Debug
|
||||||
|
!MESSAGE This is not a valid makefile. To build this project using NMAKE,
|
||||||
|
!MESSAGE use the Export Makefile command and run
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckzone.mak".
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE You can specify a configuration when running NMAKE
|
||||||
|
!MESSAGE by defining the macro CFG on the command line. For example:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckzone.mak" CFG="namedcheckzone - Win32 Debug"
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE Possible choices for configuration are:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE "namedcheckzone - Win32 Release" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE "namedcheckzone - Win32 Debug" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE
|
||||||
|
|
||||||
|
# Begin Project
|
||||||
|
# PROP AllowPerConfigDependencies 0
|
||||||
|
# PROP Scc_ProjName ""
|
||||||
|
# PROP Scc_LocalPath ""
|
||||||
|
CPP=cl.exe
|
||||||
|
RSC=rc.exe
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 0
|
||||||
|
# PROP BASE Output_Dir "Release"
|
||||||
|
# PROP BASE Intermediate_Dir "Release"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 0
|
||||||
|
# PROP Output_Dir "Release"
|
||||||
|
# PROP Intermediate_Dir "Release"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /W3 /GX /O2 /D "WIN32" /D "NDEBUG" /D "_CONSOLE" /D "_MBCS" /YX /FD /c
|
||||||
|
# ADD CPP /nologo /MD /W3 /GX /O2 /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/isccfg/include" /D "NDEBUG" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /D "__STDC__" /YX /FD /c
|
||||||
|
# SUBTRACT CPP /Fr
|
||||||
|
# ADD BASE RSC /l 0x409 /d "NDEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "NDEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32 kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib /nologo /subsystem:console /machine:I386
|
||||||
|
# ADD LINK32 user32.lib advapi32.lib ws2_32.lib Release/checktool.lib ../../../lib/isc/win32/Release/libisc.lib ../../../lib/isccfg/win32/Release/libisccfg.lib ../../../lib/dns/win32/Release/libdns.lib /nologo /subsystem:console /machine:I386 /out:"../../../Build/Release/named-checkzone.exe"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
# PROP BASE Use_MFC 0
|
||||||
|
# PROP BASE Use_Debug_Libraries 1
|
||||||
|
# PROP BASE Output_Dir "Debug"
|
||||||
|
# PROP BASE Intermediate_Dir "Debug"
|
||||||
|
# PROP BASE Target_Dir ""
|
||||||
|
# PROP Use_MFC 0
|
||||||
|
# PROP Use_Debug_Libraries 1
|
||||||
|
# PROP Output_Dir "Debug"
|
||||||
|
# PROP Intermediate_Dir "Debug"
|
||||||
|
# PROP Ignore_Export_Lib 0
|
||||||
|
# PROP Target_Dir ""
|
||||||
|
# ADD BASE CPP /nologo /W3 /Gm /GX /ZI /Od /D "WIN32" /D "_DEBUG" /D "_CONSOLE" /D "_MBCS" /YX /FD /GZ /c
|
||||||
|
# ADD CPP /nologo /MDd /W3 /Gm /GX /ZI /Od /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/isccfg/include" /D "_DEBUG" /D "__STDC__" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /FR /FD /GZ /c
|
||||||
|
# SUBTRACT CPP /X /YX
|
||||||
|
# ADD BASE RSC /l 0x409 /d "_DEBUG"
|
||||||
|
# ADD RSC /l 0x409 /d "_DEBUG"
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
# ADD BASE BSC32 /nologo
|
||||||
|
# ADD BSC32 /nologo
|
||||||
|
LINK32=link.exe
|
||||||
|
# ADD BASE LINK32 kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib kernel32.lib user32.lib gdi32.lib winspool.lib comdlg32.lib advapi32.lib shell32.lib ole32.lib oleaut32.lib uuid.lib odbc32.lib odbccp32.lib /nologo /subsystem:console /debug /machine:I386 /pdbtype:sept
|
||||||
|
# ADD LINK32 user32.lib advapi32.lib ws2_32.lib Debug/checktool.lib ../../../lib/isc/win32/Debug/libisc.lib ../../../lib/isccfg/win32/Debug/libisccfg.lib ../../../lib/dns/win32/Debug/libdns.lib /nologo /subsystem:console /debug /machine:I386 /out:"../../../Build/Debug/named-checkzone.exe" /pdbtype:sept
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
# Begin Target
|
||||||
|
|
||||||
|
# Name "namedcheckzone - Win32 Release"
|
||||||
|
# Name "namedcheckzone - Win32 Debug"
|
||||||
|
# Begin Group "Source Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "cpp;c;cxx;rc;def;r;odl;idl;hpj;bat"
|
||||||
|
# Begin Source File
|
||||||
|
|
||||||
|
SOURCE="..\named-checkzone.c"
|
||||||
|
# End Source File
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Header Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "h;hpp;hxx;hm;inl"
|
||||||
|
# Begin Source File
|
||||||
|
|
||||||
|
SOURCE="..\check-tool.h"
|
||||||
|
# End Source File
|
||||||
|
# End Group
|
||||||
|
# Begin Group "Resource Files"
|
||||||
|
|
||||||
|
# PROP Default_Filter "ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe"
|
||||||
|
# End Group
|
||||||
|
# End Target
|
||||||
|
# End Project
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
Microsoft Developer Studio Workspace File, Format Version 6.00
|
||||||
|
# WARNING: DO NOT EDIT OR DELETE THIS WORKSPACE FILE!
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Project: "namedcheckzone"=".\namedcheckzone.dsp" - Package Owner=<4>
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<4>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
|
Global:
|
||||||
|
|
||||||
|
Package=<5>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
Package=<3>
|
||||||
|
{{{
|
||||||
|
}}}
|
||||||
|
|
||||||
|
###############################################################################
|
||||||
|
|
||||||
@@ -0,0 +1,404 @@
|
|||||||
|
# Microsoft Developer Studio Generated NMAKE File, Based on namedcheckzone.dsp
|
||||||
|
!IF "$(CFG)" == ""
|
||||||
|
CFG=namedcheckzone - Win32 Debug
|
||||||
|
!MESSAGE No configuration specified. Defaulting to namedcheckzone - Win32 Debug.
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" != "namedcheckzone - Win32 Release" && "$(CFG)" != "namedcheckzone - Win32 Debug"
|
||||||
|
!MESSAGE Invalid configuration "$(CFG)" specified.
|
||||||
|
!MESSAGE You can specify a configuration when running NMAKE
|
||||||
|
!MESSAGE by defining the macro CFG on the command line. For example:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE NMAKE /f "namedcheckzone.mak" CFG="namedcheckzone - Win32 Debug"
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE Possible choices for configuration are:
|
||||||
|
!MESSAGE
|
||||||
|
!MESSAGE "namedcheckzone - Win32 Release" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE "namedcheckzone - Win32 Debug" (based on "Win32 (x86) Console Application")
|
||||||
|
!MESSAGE
|
||||||
|
!ERROR An invalid configuration is specified.
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(OS)" == "Windows_NT"
|
||||||
|
NULL=
|
||||||
|
!ELSE
|
||||||
|
NULL=nul
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
_VC_MANIFEST_INC=0
|
||||||
|
_VC_MANIFEST_BASENAME=__VC80
|
||||||
|
!ELSE
|
||||||
|
_VC_MANIFEST_INC=1
|
||||||
|
_VC_MANIFEST_BASENAME=__VC80.Debug
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# Specifying name of temporary resource file used only in incremental builds:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
_VC_MANIFEST_AUTO_RES=$(_VC_MANIFEST_BASENAME).auto.res
|
||||||
|
!else
|
||||||
|
_VC_MANIFEST_AUTO_RES=
|
||||||
|
!endif
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_EMBED_EXE - command to embed manifest in EXE:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
#MT_SPECIAL_RETURN=1090650113
|
||||||
|
#MT_SPECIAL_SWITCH=-notify_resource_update
|
||||||
|
MT_SPECIAL_RETURN=0
|
||||||
|
MT_SPECIAL_SWITCH=
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -out:$(_VC_MANIFEST_BASENAME).auto.manifest $(MT_SPECIAL_SWITCH) & \
|
||||||
|
if "%ERRORLEVEL%" == "$(MT_SPECIAL_RETURN)" \
|
||||||
|
rc /r $(_VC_MANIFEST_BASENAME).auto.rc & \
|
||||||
|
link $** /out:$@ $(LFLAGS)
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -outputresource:$@;1
|
||||||
|
|
||||||
|
!endif
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_EMBED_DLL - command to embed manifest in DLL:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
#MT_SPECIAL_RETURN=1090650113
|
||||||
|
#MT_SPECIAL_SWITCH=-notify_resource_update
|
||||||
|
MT_SPECIAL_RETURN=0
|
||||||
|
MT_SPECIAL_SWITCH=
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -out:$(_VC_MANIFEST_BASENAME).auto.manifest $(MT_SPECIAL_SWITCH) & \
|
||||||
|
if "%ERRORLEVEL%" == "$(MT_SPECIAL_RETURN)" \
|
||||||
|
rc /r $(_VC_MANIFEST_BASENAME).auto.rc & \
|
||||||
|
link $** /out:$@ $(LFLAGS)
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_EMBED_EXE= \
|
||||||
|
if exist $@.manifest mt.exe -manifest $@.manifest -outputresource:$@;2
|
||||||
|
|
||||||
|
!endif
|
||||||
|
####################################################
|
||||||
|
# _VC_MANIFEST_CLEAN - command to clean resources files generated temporarily:
|
||||||
|
|
||||||
|
!if "$(_VC_MANIFEST_INC)" == "1"
|
||||||
|
|
||||||
|
_VC_MANIFEST_CLEAN=-del $(_VC_MANIFEST_BASENAME).auto.res \
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.rc \
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.manifest
|
||||||
|
|
||||||
|
!else
|
||||||
|
|
||||||
|
_VC_MANIFEST_CLEAN=
|
||||||
|
|
||||||
|
!endif
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
OUTDIR=.\Release
|
||||||
|
INTDIR=.\Release
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "0"
|
||||||
|
|
||||||
|
ALL : "..\..\..\Build\Release\named-checkzone.exe"
|
||||||
|
|
||||||
|
!ELSE
|
||||||
|
|
||||||
|
ALL : "libisc - Win32 Release" "libdns - Win32 Release" "..\..\..\Build\Release\named-checkzone.exe"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "1"
|
||||||
|
CLEAN :"libdns - Win32 ReleaseCLEAN" "libisc - Win32 ReleaseCLEAN"
|
||||||
|
!ELSE
|
||||||
|
CLEAN :
|
||||||
|
!ENDIF
|
||||||
|
-@erase "$(INTDIR)\check-tool.obj"
|
||||||
|
-@erase "$(INTDIR)\named-checkzone.obj"
|
||||||
|
-@erase "$(INTDIR)\vc60.idb"
|
||||||
|
-@erase "..\..\..\Build\Release\named-checkzone.exe"
|
||||||
|
-@$(_VC_MANIFEST_CLEAN)
|
||||||
|
|
||||||
|
"$(OUTDIR)" :
|
||||||
|
if not exist "$(OUTDIR)/$(NULL)" mkdir "$(OUTDIR)"
|
||||||
|
|
||||||
|
CPP=cl.exe
|
||||||
|
CPP_PROJ=/nologo /MD /W3 /GX /O2 /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/isccfg/include" /D "NDEBUG" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /D "__STDC__" /Fp"$(INTDIR)\namedcheckzone.pch" /YX /Fo"$(INTDIR)\\" /Fd"$(INTDIR)\\" /FD /c
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
RSC=rc.exe
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
BSC32_FLAGS=/nologo /o"$(OUTDIR)\namedcheckzone.bsc"
|
||||||
|
BSC32_SBRS= \
|
||||||
|
|
||||||
|
LINK32=link.exe
|
||||||
|
LINK32_FLAGS=user32.lib advapi32.lib ws2_32.lib ../../../lib/isc/win32/Release/libisc.lib ../../../lib/isccfg/win32/Release/libisccfg.lib ../../../lib/dns/win32/Release/libdns.lib /nologo /subsystem:console /incremental:no /pdb:"$(OUTDIR)\named-checkzone.pdb" /machine:I386 /out:"../../../Build/Release/named-checkzone.exe"
|
||||||
|
LINK32_OBJS= \
|
||||||
|
"$(INTDIR)\check-tool.obj" \
|
||||||
|
"$(INTDIR)\named-checkzone.obj" \
|
||||||
|
"..\..\..\lib\dns\win32\Release\libdns.lib" \
|
||||||
|
"..\..\..\lib\isccfg\win32\Release\libisccfg.lib" \
|
||||||
|
"..\..\..\lib\isc\win32\Release\libisc.lib"
|
||||||
|
|
||||||
|
"..\..\..\Build\Release\named-checkzone.exe" : "$(OUTDIR)" $(DEF_FILE) $(LINK32_OBJS)
|
||||||
|
$(LINK32) @<<
|
||||||
|
$(LINK32_FLAGS) $(LINK32_OBJS)
|
||||||
|
<<
|
||||||
|
$(_VC_MANIFEST_EMBED_EXE)
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
OUTDIR=.\Debug
|
||||||
|
INTDIR=.\Debug
|
||||||
|
# Begin Custom Macros
|
||||||
|
OutDir=.\Debug
|
||||||
|
# End Custom Macros
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "0"
|
||||||
|
|
||||||
|
ALL : "..\..\..\Build\Debug\named-checkzone.exe" "$(OUTDIR)\namedcheckzone.bsc"
|
||||||
|
|
||||||
|
!ELSE
|
||||||
|
|
||||||
|
ALL : "libisc - Win32 Debug" "libdns - Win32 Debug" "..\..\..\Build\Debug\named-checkzone.exe" "$(OUTDIR)\namedcheckzone.bsc"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(RECURSE)" == "1"
|
||||||
|
CLEAN :"libdns - Win32 DebugCLEAN" "libisc - Win32 DebugCLEAN"
|
||||||
|
!ELSE
|
||||||
|
CLEAN :
|
||||||
|
!ENDIF
|
||||||
|
-@erase "$(INTDIR)\check-tool.obj"
|
||||||
|
-@erase "$(INTDIR)\check-tool.sbr"
|
||||||
|
-@erase "$(INTDIR)\named-checkzone.obj"
|
||||||
|
-@erase "$(INTDIR)\named-checkzone.sbr"
|
||||||
|
-@erase "$(INTDIR)\vc60.idb"
|
||||||
|
-@erase "$(INTDIR)\vc60.pdb"
|
||||||
|
-@erase "$(OUTDIR)\named-checkzone.pdb"
|
||||||
|
-@erase "$(OUTDIR)\namedcheckzone.bsc"
|
||||||
|
-@erase "..\..\..\Build\Debug\named-checkzone.exe"
|
||||||
|
-@erase "..\..\..\Build\Debug\named-checkzone.ilk"
|
||||||
|
-@$(_VC_MANIFEST_CLEAN)
|
||||||
|
|
||||||
|
"$(OUTDIR)" :
|
||||||
|
if not exist "$(OUTDIR)/$(NULL)" mkdir "$(OUTDIR)"
|
||||||
|
|
||||||
|
CPP=cl.exe
|
||||||
|
CPP_PROJ=/nologo /MDd /W3 /Gm /GX /ZI /Od /I "./" /I "../../../" /I "../../../lib/isc/win32" /I "../../../lib/isc/win32/include" /I "../../../lib/isc/include" /I "../../../lib/isc/noatomic/include" /I "../../../lib/dns/include" /I "../../../lib/isccfg/include" /D "_DEBUG" /D "__STDC__" /D "WIN32" /D "_CONSOLE" /D "_MBCS" /FR"$(INTDIR)\\" /Fo"$(INTDIR)\\" /Fd"$(INTDIR)\\" /FD /GZ /c
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.obj::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.c{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cpp{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
.cxx{$(INTDIR)}.sbr::
|
||||||
|
$(CPP) @<<
|
||||||
|
$(CPP_PROJ) $<
|
||||||
|
<<
|
||||||
|
|
||||||
|
RSC=rc.exe
|
||||||
|
BSC32=bscmake.exe
|
||||||
|
BSC32_FLAGS=/nologo /o"$(OUTDIR)\namedcheckzone.bsc"
|
||||||
|
BSC32_SBRS= \
|
||||||
|
"$(INTDIR)\check-tool.sbr" \
|
||||||
|
"$(INTDIR)\named-checkzone.sbr"
|
||||||
|
|
||||||
|
"$(OUTDIR)\namedcheckzone.bsc" : "$(OUTDIR)" $(BSC32_SBRS)
|
||||||
|
$(BSC32) @<<
|
||||||
|
$(BSC32_FLAGS) $(BSC32_SBRS)
|
||||||
|
<<
|
||||||
|
|
||||||
|
LINK32=link.exe
|
||||||
|
LINK32_FLAGS=user32.lib advapi32.lib ws2_32.lib ../../../lib/isc/win32/Debug/libisc.lib ../../../lib/isccfg/win32/Debug/libisccfg.lib ../../../lib/dns/win32/Debug/libdns.lib /nologo /subsystem:console /incremental:yes /pdb:"$(OUTDIR)\named-checkzone.pdb" /debug /machine:I386 /out:"../../../Build/Debug/named-checkzone.exe" /pdbtype:sept
|
||||||
|
LINK32_OBJS= \
|
||||||
|
"$(INTDIR)\check-tool.obj" \
|
||||||
|
"$(INTDIR)\named-checkzone.obj" \
|
||||||
|
"..\..\..\lib\dns\win32\Debug\libdns.lib" \
|
||||||
|
"..\..\..\lib\isccfg\win32\Debug\libisccfg.lib" \
|
||||||
|
"..\..\..\lib\isc\win32\Debug\libisc.lib"
|
||||||
|
|
||||||
|
"..\..\..\Build\Debug\named-checkzone.exe" : "$(OUTDIR)" $(DEF_FILE) $(LINK32_OBJS)
|
||||||
|
$(LINK32) @<<
|
||||||
|
$(LINK32_FLAGS) $(LINK32_OBJS)
|
||||||
|
<<
|
||||||
|
$(_VC_MANIFEST_EMBED_EXE)
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
|
||||||
|
!IF "$(NO_EXTERNAL_DEPS)" != "1"
|
||||||
|
!IF EXISTS("namedcheckzone.dep")
|
||||||
|
!INCLUDE "namedcheckzone.dep"
|
||||||
|
!ELSE
|
||||||
|
!MESSAGE Warning: cannot find "namedcheckzone.dep"
|
||||||
|
!ENDIF
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release" || "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
SOURCE="..\check-tool.c"
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
|
||||||
|
"$(INTDIR)\check-tool.obj" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
|
||||||
|
"$(INTDIR)\check-tool.obj" "$(INTDIR)\check-tool.sbr" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
SOURCE="..\named-checkzone.c"
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
|
||||||
|
"$(INTDIR)\named-checkzone.obj" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
|
||||||
|
"$(INTDIR)\named-checkzone.obj" "$(INTDIR)\named-checkzone.sbr" : $(SOURCE) "$(INTDIR)"
|
||||||
|
$(CPP) $(CPP_PROJ) $(SOURCE)
|
||||||
|
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
"libdns - Win32 Release" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Release"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libdns - Win32 ReleaseCLEAN" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Release" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
"libdns - Win32 Debug" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Debug"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libdns - Win32 DebugCLEAN" :
|
||||||
|
cd "..\..\..\lib\dns\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libdns.mak" CFG="libdns - Win32 Debug" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
!IF "$(CFG)" == "namedcheckzone - Win32 Release"
|
||||||
|
|
||||||
|
"libisc - Win32 Release" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Release"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisc - Win32 ReleaseCLEAN" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Release" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ELSEIF "$(CFG)" == "namedcheckzone - Win32 Debug"
|
||||||
|
|
||||||
|
"libisc - Win32 Debug" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Debug"
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
"libisc - Win32 DebugCLEAN" :
|
||||||
|
cd "..\..\..\lib\isc\win32"
|
||||||
|
$(MAKE) /$(MAKEFLAGS) /F ".\libisc.mak" CFG="libisc - Win32 Debug" RECURSE=1 CLEAN
|
||||||
|
cd "..\..\..\bin\check\win32"
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
|
||||||
|
!ENDIF
|
||||||
|
|
||||||
|
####################################################
|
||||||
|
# Commands to generate initial empty manifest file and the RC file
|
||||||
|
# that references it, and for generating the .res file:
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.res : $(_VC_MANIFEST_BASENAME).auto.rc
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.rc : $(_VC_MANIFEST_BASENAME).auto.manifest
|
||||||
|
type <<$@
|
||||||
|
#include <winuser.h>
|
||||||
|
1RT_MANIFEST"$(_VC_MANIFEST_BASENAME).auto.manifest"
|
||||||
|
<< KEEP
|
||||||
|
|
||||||
|
$(_VC_MANIFEST_BASENAME).auto.manifest :
|
||||||
|
type <<$@
|
||||||
|
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
|
||||||
|
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
|
||||||
|
</assembly>
|
||||||
|
<< KEEP
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
ddns-confgen
|
|
||||||
rndc-confgen
|
|
||||||
tsig-keygen
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
include $(top_srcdir)/Makefile.top
|
|
||||||
|
|
||||||
AM_CPPFLAGS += \
|
|
||||||
$(LIBISC_CFLAGS) \
|
|
||||||
$(LIBDNS_CFLAGS) \
|
|
||||||
-DRNDC_KEYFILE=\"${sysconfdir}/rndc.key\"
|
|
||||||
|
|
||||||
LDADD = \
|
|
||||||
libconfgen.la \
|
|
||||||
$(LIBISC_LIBS) \
|
|
||||||
$(LIBDNS_LIBS)
|
|
||||||
|
|
||||||
noinst_LTLIBRARIES = libconfgen.la
|
|
||||||
|
|
||||||
libconfgen_la_SOURCES = \
|
|
||||||
include/confgen/os.h \
|
|
||||||
keygen.h \
|
|
||||||
keygen.c \
|
|
||||||
util.h \
|
|
||||||
util.c \
|
|
||||||
unix/os.c
|
|
||||||
|
|
||||||
sbin_PROGRAMS = tsig-keygen rndc-confgen
|
|
||||||
|
|
||||||
install-exec-hook:
|
|
||||||
ln -f $(DESTDIR)$(sbindir)/tsig-keygen \
|
|
||||||
$(DESTDIR)$(sbindir)/ddns-confgen
|
|
||||||
|
|
||||||
uninstall-hook:
|
|
||||||
-rm -f $(DESTDIR)$(sbindir)/ddns-confgen
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
../../../.clang-format.headers
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#ifndef RNDC_OS_H
|
|
||||||
#define RNDC_OS_H 1
|
|
||||||
|
|
||||||
#include <stdio.h>
|
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
int
|
|
||||||
set_user(FILE *fd, const char *user);
|
|
||||||
/*%<
|
|
||||||
* Set the owner of the file referenced by 'fd' to 'user'.
|
|
||||||
* Returns:
|
|
||||||
* 0 success
|
|
||||||
* -1 insufficient permissions, or 'user' does not exist.
|
|
||||||
*/
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* ifndef RNDC_OS_H */
|
|
||||||
@@ -1,201 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#include "keygen.h"
|
|
||||||
#include <stdarg.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/base64.h>
|
|
||||||
#include <isc/buffer.h>
|
|
||||||
#include <isc/file.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/result.h>
|
|
||||||
#include <isc/string.h>
|
|
||||||
|
|
||||||
#include <pk11/site.h>
|
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
|
||||||
#include <dns/name.h>
|
|
||||||
|
|
||||||
#include <dst/dst.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
|
||||||
|
|
||||||
#include "util.h"
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Convert algorithm type to string.
|
|
||||||
*/
|
|
||||||
const char *
|
|
||||||
alg_totext(dns_secalg_t alg) {
|
|
||||||
switch (alg) {
|
|
||||||
case DST_ALG_HMACMD5:
|
|
||||||
return ("hmac-md5");
|
|
||||||
case DST_ALG_HMACSHA1:
|
|
||||||
return ("hmac-sha1");
|
|
||||||
case DST_ALG_HMACSHA224:
|
|
||||||
return ("hmac-sha224");
|
|
||||||
case DST_ALG_HMACSHA256:
|
|
||||||
return ("hmac-sha256");
|
|
||||||
case DST_ALG_HMACSHA384:
|
|
||||||
return ("hmac-sha384");
|
|
||||||
case DST_ALG_HMACSHA512:
|
|
||||||
return ("hmac-sha512");
|
|
||||||
default:
|
|
||||||
return ("(unknown)");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Convert string to algorithm type.
|
|
||||||
*/
|
|
||||||
dns_secalg_t
|
|
||||||
alg_fromtext(const char *name) {
|
|
||||||
const char *p = name;
|
|
||||||
if (strncasecmp(p, "hmac-", 5) == 0) {
|
|
||||||
p = &name[5];
|
|
||||||
}
|
|
||||||
|
|
||||||
if (strcasecmp(p, "md5") == 0) {
|
|
||||||
return (DST_ALG_HMACMD5);
|
|
||||||
}
|
|
||||||
if (strcasecmp(p, "sha1") == 0) {
|
|
||||||
return (DST_ALG_HMACSHA1);
|
|
||||||
}
|
|
||||||
if (strcasecmp(p, "sha224") == 0) {
|
|
||||||
return (DST_ALG_HMACSHA224);
|
|
||||||
}
|
|
||||||
if (strcasecmp(p, "sha256") == 0) {
|
|
||||||
return (DST_ALG_HMACSHA256);
|
|
||||||
}
|
|
||||||
if (strcasecmp(p, "sha384") == 0) {
|
|
||||||
return (DST_ALG_HMACSHA384);
|
|
||||||
}
|
|
||||||
if (strcasecmp(p, "sha512") == 0) {
|
|
||||||
return (DST_ALG_HMACSHA512);
|
|
||||||
}
|
|
||||||
return (DST_ALG_UNKNOWN);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Return default keysize for a given algorithm type.
|
|
||||||
*/
|
|
||||||
int
|
|
||||||
alg_bits(dns_secalg_t alg) {
|
|
||||||
switch (alg) {
|
|
||||||
case DST_ALG_HMACMD5:
|
|
||||||
return (128);
|
|
||||||
case DST_ALG_HMACSHA1:
|
|
||||||
return (160);
|
|
||||||
case DST_ALG_HMACSHA224:
|
|
||||||
return (224);
|
|
||||||
case DST_ALG_HMACSHA256:
|
|
||||||
return (256);
|
|
||||||
case DST_ALG_HMACSHA384:
|
|
||||||
return (384);
|
|
||||||
case DST_ALG_HMACSHA512:
|
|
||||||
return (512);
|
|
||||||
default:
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Generate a key of size 'keysize' and place it in 'key_txtbuffer'
|
|
||||||
*/
|
|
||||||
void
|
|
||||||
generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|
||||||
isc_buffer_t *key_txtbuffer) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
isc_buffer_t key_rawbuffer;
|
|
||||||
isc_region_t key_rawregion;
|
|
||||||
char key_rawsecret[64];
|
|
||||||
dst_key_t *key = NULL;
|
|
||||||
|
|
||||||
switch (alg) {
|
|
||||||
case DST_ALG_HMACMD5:
|
|
||||||
case DST_ALG_HMACSHA1:
|
|
||||||
case DST_ALG_HMACSHA224:
|
|
||||||
case DST_ALG_HMACSHA256:
|
|
||||||
if (keysize < 1 || keysize > 512) {
|
|
||||||
fatal("keysize %d out of range (must be 1-512)\n",
|
|
||||||
keysize);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case DST_ALG_HMACSHA384:
|
|
||||||
case DST_ALG_HMACSHA512:
|
|
||||||
if (keysize < 1 || keysize > 1024) {
|
|
||||||
fatal("keysize %d out of range (must be 1-1024)\n",
|
|
||||||
keysize);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
fatal("unsupported algorithm %d\n", alg);
|
|
||||||
}
|
|
||||||
|
|
||||||
DO("initialize dst library", dst_lib_init(mctx, NULL));
|
|
||||||
|
|
||||||
DO("generate key",
|
|
||||||
dst_key_generate(dns_rootname, alg, keysize, 0, 0, DNS_KEYPROTO_ANY,
|
|
||||||
dns_rdataclass_in, mctx, &key, NULL));
|
|
||||||
|
|
||||||
isc_buffer_init(&key_rawbuffer, &key_rawsecret, sizeof(key_rawsecret));
|
|
||||||
|
|
||||||
DO("dump key to buffer", dst_key_tobuffer(key, &key_rawbuffer));
|
|
||||||
|
|
||||||
isc_buffer_usedregion(&key_rawbuffer, &key_rawregion);
|
|
||||||
|
|
||||||
DO("bsse64 encode secret",
|
|
||||||
isc_base64_totext(&key_rawregion, -1, "", key_txtbuffer));
|
|
||||||
|
|
||||||
if (key != NULL) {
|
|
||||||
dst_key_free(&key);
|
|
||||||
}
|
|
||||||
|
|
||||||
dst_lib_destroy();
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
|
||||||
* Write a key file to 'keyfile'. If 'user' is non-NULL,
|
|
||||||
* make that user the owner of the file. The key will have
|
|
||||||
* the name 'keyname' and the secret in the buffer 'secret'.
|
|
||||||
*/
|
|
||||||
void
|
|
||||||
write_key_file(const char *keyfile, const char *user, const char *keyname,
|
|
||||||
isc_buffer_t *secret, dns_secalg_t alg) {
|
|
||||||
isc_result_t result;
|
|
||||||
const char *algname = alg_totext(alg);
|
|
||||||
FILE *fd = NULL;
|
|
||||||
|
|
||||||
DO("create keyfile", isc_file_safecreate(keyfile, &fd));
|
|
||||||
|
|
||||||
if (user != NULL) {
|
|
||||||
if (set_user(fd, user) == -1) {
|
|
||||||
fatal("unable to set file owner\n");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fprintf(fd,
|
|
||||||
"key \"%s\" {\n\talgorithm %s;\n"
|
|
||||||
"\tsecret \"%.*s\";\n};\n",
|
|
||||||
keyname, algname, (int)isc_buffer_usedlength(secret),
|
|
||||||
(char *)isc_buffer_base(secret));
|
|
||||||
fflush(fd);
|
|
||||||
if (ferror(fd)) {
|
|
||||||
fatal("write to %s failed\n", keyfile);
|
|
||||||
}
|
|
||||||
if (fclose(fd)) {
|
|
||||||
fatal("fclose(%s) failed\n", keyfile);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#ifndef RNDC_KEYGEN_H
|
|
||||||
#define RNDC_KEYGEN_H 1
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#include <isc/buffer.h>
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
|
|
||||||
#include <dns/secalg.h>
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
void
|
|
||||||
generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|
||||||
isc_buffer_t *key_txtbuffer);
|
|
||||||
|
|
||||||
void
|
|
||||||
write_key_file(const char *keyfile, const char *user, const char *keyname,
|
|
||||||
isc_buffer_t *secret, dns_secalg_t alg);
|
|
||||||
|
|
||||||
const char *
|
|
||||||
alg_totext(dns_secalg_t alg);
|
|
||||||
dns_secalg_t
|
|
||||||
alg_fromtext(const char *name);
|
|
||||||
int
|
|
||||||
alg_bits(dns_secalg_t alg);
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* RNDC_KEYGEN_H */
|
|
||||||
@@ -1,294 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
/**
|
|
||||||
* rndc-confgen generates configuration files for rndc. It can be used
|
|
||||||
* as a convenient alternative to writing the rndc.conf file and the
|
|
||||||
* corresponding controls and key statements in named.conf by hand.
|
|
||||||
* Alternatively, it can be run with the -a option to set up a
|
|
||||||
* rndc.key file and avoid the need for a rndc.conf file and a
|
|
||||||
* controls statement altogether.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <stdarg.h>
|
|
||||||
#include <stdbool.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/assertions.h>
|
|
||||||
#include <isc/attributes.h>
|
|
||||||
#include <isc/base64.h>
|
|
||||||
#include <isc/buffer.h>
|
|
||||||
#include <isc/commandline.h>
|
|
||||||
#include <isc/file.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
#include <isc/net.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/result.h>
|
|
||||||
#include <isc/string.h>
|
|
||||||
#include <isc/time.h>
|
|
||||||
#include <isc/util.h>
|
|
||||||
|
|
||||||
#include <pk11/site.h>
|
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
|
||||||
#include <dns/name.h>
|
|
||||||
|
|
||||||
#include <dst/dst.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
|
||||||
|
|
||||||
#include "keygen.h"
|
|
||||||
#include "util.h"
|
|
||||||
|
|
||||||
#define DEFAULT_KEYNAME "rndc-key"
|
|
||||||
#define DEFAULT_SERVER "127.0.0.1"
|
|
||||||
#define DEFAULT_PORT 953
|
|
||||||
|
|
||||||
static char program[256];
|
|
||||||
const char *progname;
|
|
||||||
|
|
||||||
bool verbose = false;
|
|
||||||
|
|
||||||
const char *keyfile, *keydef;
|
|
||||||
|
|
||||||
ISC_NORETURN static void
|
|
||||||
usage(int status);
|
|
||||||
|
|
||||||
static void
|
|
||||||
usage(int status) {
|
|
||||||
fprintf(stderr, "\
|
|
||||||
Usage:\n\
|
|
||||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] \
|
|
||||||
[-s addr] [-t chrootdir] [-u user]\n\
|
|
||||||
-a: generate just the key clause and write it to keyfile (%s)\n\
|
|
||||||
-A alg: algorithm (default hmac-sha256)\n\
|
|
||||||
-b bits: from 1 through 512, default 256; total length of the secret\n\
|
|
||||||
-c keyfile: specify an alternate key file (requires -a)\n\
|
|
||||||
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
|
||||||
-p port: the port named will listen on and rndc will connect to\n\
|
|
||||||
-q: suppress printing written key path\n\
|
|
||||||
-s addr: the address to which rndc should connect\n\
|
|
||||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
|
||||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
|
||||||
progname, keydef);
|
|
||||||
|
|
||||||
exit(status);
|
|
||||||
}
|
|
||||||
|
|
||||||
int
|
|
||||||
main(int argc, char **argv) {
|
|
||||||
bool show_final_mem = false;
|
|
||||||
isc_buffer_t key_txtbuffer;
|
|
||||||
char key_txtsecret[256];
|
|
||||||
isc_mem_t *mctx = NULL;
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
const char *keyname = NULL;
|
|
||||||
const char *serveraddr = NULL;
|
|
||||||
dns_secalg_t alg;
|
|
||||||
const char *algname;
|
|
||||||
char *p;
|
|
||||||
int ch;
|
|
||||||
int port;
|
|
||||||
int keysize = -1;
|
|
||||||
struct in_addr addr4_dummy;
|
|
||||||
struct in6_addr addr6_dummy;
|
|
||||||
char *chrootdir = NULL;
|
|
||||||
char *user = NULL;
|
|
||||||
bool keyonly = false;
|
|
||||||
bool quiet = false;
|
|
||||||
int len;
|
|
||||||
|
|
||||||
keydef = keyfile = RNDC_KEYFILE;
|
|
||||||
|
|
||||||
result = isc_file_progname(*argv, program, sizeof(program));
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
memmove(program, "rndc-confgen", 13);
|
|
||||||
}
|
|
||||||
progname = program;
|
|
||||||
|
|
||||||
keyname = DEFAULT_KEYNAME;
|
|
||||||
alg = DST_ALG_HMACSHA256;
|
|
||||||
serveraddr = DEFAULT_SERVER;
|
|
||||||
port = DEFAULT_PORT;
|
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
|
||||||
|
|
||||||
while ((ch = isc_commandline_parse(argc, argv,
|
|
||||||
"aA:b:c:hk:Mmp:r:s:t:u:Vy")) != -1)
|
|
||||||
{
|
|
||||||
switch (ch) {
|
|
||||||
case 'a':
|
|
||||||
keyonly = true;
|
|
||||||
break;
|
|
||||||
case 'A':
|
|
||||||
algname = isc_commandline_argument;
|
|
||||||
alg = alg_fromtext(algname);
|
|
||||||
if (alg == DST_ALG_UNKNOWN) {
|
|
||||||
fatal("Unsupported algorithm '%s'", algname);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'b':
|
|
||||||
keysize = strtol(isc_commandline_argument, &p, 10);
|
|
||||||
if (*p != '\0' || keysize < 0) {
|
|
||||||
fatal("-b requires a non-negative number");
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'c':
|
|
||||||
keyfile = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'h':
|
|
||||||
usage(0);
|
|
||||||
case 'k':
|
|
||||||
case 'y': /* Compatible with rndc -y. */
|
|
||||||
keyname = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'M':
|
|
||||||
isc_mem_debugging = ISC_MEM_DEBUGTRACE;
|
|
||||||
break;
|
|
||||||
|
|
||||||
case 'm':
|
|
||||||
show_final_mem = true;
|
|
||||||
break;
|
|
||||||
case 'p':
|
|
||||||
port = strtol(isc_commandline_argument, &p, 10);
|
|
||||||
if (*p != '\0' || port < 0 || port > 65535) {
|
|
||||||
fatal("port '%s' out of range",
|
|
||||||
isc_commandline_argument);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'q':
|
|
||||||
quiet = true;
|
|
||||||
break;
|
|
||||||
case 'r':
|
|
||||||
fatal("The -r option has been deprecated.");
|
|
||||||
break;
|
|
||||||
case 's':
|
|
||||||
serveraddr = isc_commandline_argument;
|
|
||||||
if (inet_pton(AF_INET, serveraddr, &addr4_dummy) != 1 &&
|
|
||||||
inet_pton(AF_INET6, serveraddr, &addr6_dummy) != 1)
|
|
||||||
{
|
|
||||||
fatal("-s should be an IPv4 or IPv6 address");
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 't':
|
|
||||||
chrootdir = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'u':
|
|
||||||
user = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'V':
|
|
||||||
verbose = true;
|
|
||||||
break;
|
|
||||||
case '?':
|
|
||||||
if (isc_commandline_option != '?') {
|
|
||||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
|
||||||
program, isc_commandline_option);
|
|
||||||
usage(1);
|
|
||||||
} else {
|
|
||||||
usage(0);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n", program,
|
|
||||||
isc_commandline_option);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
argc -= isc_commandline_index;
|
|
||||||
argv += isc_commandline_index;
|
|
||||||
POST(argv);
|
|
||||||
|
|
||||||
if (argc > 0) {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (alg == DST_ALG_HMACMD5) {
|
|
||||||
fprintf(stderr, "warning: use of hmac-md5 for RNDC keys "
|
|
||||||
"is deprecated; hmac-sha256 is now "
|
|
||||||
"recommended.\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (keysize < 0) {
|
|
||||||
keysize = alg_bits(alg);
|
|
||||||
}
|
|
||||||
algname = alg_totext(alg);
|
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
|
||||||
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
|
||||||
|
|
||||||
generate_key(mctx, alg, keysize, &key_txtbuffer);
|
|
||||||
|
|
||||||
if (keyonly) {
|
|
||||||
write_key_file(keyfile, chrootdir == NULL ? user : NULL,
|
|
||||||
keyname, &key_txtbuffer, alg);
|
|
||||||
if (!quiet) {
|
|
||||||
printf("wrote key file \"%s\"\n", keyfile);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (chrootdir != NULL) {
|
|
||||||
char *buf;
|
|
||||||
len = strlen(chrootdir) + strlen(keyfile) + 2;
|
|
||||||
buf = isc_mem_get(mctx, len);
|
|
||||||
snprintf(buf, len, "%s%s%s", chrootdir,
|
|
||||||
(*keyfile != '/') ? "/" : "", keyfile);
|
|
||||||
|
|
||||||
write_key_file(buf, user, keyname, &key_txtbuffer, alg);
|
|
||||||
if (!quiet) {
|
|
||||||
printf("wrote key file \"%s\"\n", buf);
|
|
||||||
}
|
|
||||||
isc_mem_put(mctx, buf, len);
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
printf("\
|
|
||||||
# Start of rndc.conf\n\
|
|
||||||
key \"%s\" {\n\
|
|
||||||
algorithm %s;\n\
|
|
||||||
secret \"%.*s\";\n\
|
|
||||||
};\n\
|
|
||||||
\n\
|
|
||||||
options {\n\
|
|
||||||
default-key \"%s\";\n\
|
|
||||||
default-server %s;\n\
|
|
||||||
default-port %d;\n\
|
|
||||||
};\n\
|
|
||||||
# End of rndc.conf\n\
|
|
||||||
\n\
|
|
||||||
# Use with the following in named.conf, adjusting the allow list as needed:\n\
|
|
||||||
# key \"%s\" {\n\
|
|
||||||
# algorithm %s;\n\
|
|
||||||
# secret \"%.*s\";\n\
|
|
||||||
# };\n\
|
|
||||||
# \n\
|
|
||||||
# controls {\n\
|
|
||||||
# inet %s port %d\n\
|
|
||||||
# allow { %s; } keys { \"%s\"; };\n\
|
|
||||||
# };\n\
|
|
||||||
# End of named.conf\n",
|
|
||||||
keyname, algname,
|
|
||||||
(int)isc_buffer_usedlength(&key_txtbuffer),
|
|
||||||
(char *)isc_buffer_base(&key_txtbuffer), keyname,
|
|
||||||
serveraddr, port, keyname, algname,
|
|
||||||
(int)isc_buffer_usedlength(&key_txtbuffer),
|
|
||||||
(char *)isc_buffer_base(&key_txtbuffer), serveraddr,
|
|
||||||
port, serveraddr, keyname);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (show_final_mem) {
|
|
||||||
isc_mem_stats(mctx, stderr);
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
|
||||||
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
@@ -1,119 +0,0 @@
|
|||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
|
|
||||||
.. highlight: console
|
|
||||||
|
|
||||||
.. _man_rndc-confgen:
|
|
||||||
|
|
||||||
rndc-confgen - rndc key generation tool
|
|
||||||
---------------------------------------
|
|
||||||
|
|
||||||
Synopsis
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:program:`rndc-confgen` [**-a**] [**-A** algorithm] [**-b** keysize] [**-c** keyfile] [**-h**] [**-k** keyname] [**-p** port] [**-s** address] [**-t** chrootdir] [**-u** user]
|
|
||||||
|
|
||||||
Description
|
|
||||||
~~~~~~~~~~~
|
|
||||||
|
|
||||||
``rndc-confgen`` generates configuration files for ``rndc``. It can be
|
|
||||||
used as a convenient alternative to writing the ``rndc.conf`` file and
|
|
||||||
the corresponding ``controls`` and ``key`` statements in ``named.conf``
|
|
||||||
by hand. Alternatively, it can be run with the ``-a`` option to set up a
|
|
||||||
``rndc.key`` file and avoid the need for a ``rndc.conf`` file and a
|
|
||||||
``controls`` statement altogether.
|
|
||||||
|
|
||||||
Options
|
|
||||||
~~~~~~~
|
|
||||||
|
|
||||||
``-a``
|
|
||||||
This option sets automatic ``rndc`` configuration, which creates a file ``rndc.key``
|
|
||||||
in ``/etc`` (or a different ``sysconfdir`` specified when BIND
|
|
||||||
was built) that is read by both ``rndc`` and ``named`` on startup.
|
|
||||||
The ``rndc.key`` file defines a default command channel and
|
|
||||||
authentication key allowing ``rndc`` to communicate with ``named`` on
|
|
||||||
the local host with no further configuration.
|
|
||||||
|
|
||||||
If a more elaborate configuration than that generated by
|
|
||||||
``rndc-confgen -a`` is required, for example if rndc is to be used
|
|
||||||
remotely, run ``rndc-confgen`` without the ``-a`` option
|
|
||||||
and set up ``rndc.conf`` and ``named.conf`` as directed.
|
|
||||||
|
|
||||||
``-A algorithm``
|
|
||||||
This option specifies the algorithm to use for the TSIG key. Available choices
|
|
||||||
are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384, and
|
|
||||||
hmac-sha512. The default is hmac-sha256.
|
|
||||||
|
|
||||||
``-b keysize``
|
|
||||||
This option specifies the size of the authentication key in bits. The size must be between
|
|
||||||
1 and 512 bits; the default is the hash size.
|
|
||||||
|
|
||||||
``-c keyfile``
|
|
||||||
This option is used with the ``-a`` option to specify an alternate location for
|
|
||||||
``rndc.key``.
|
|
||||||
|
|
||||||
``-h``
|
|
||||||
This option prints a short summary of the options and arguments to
|
|
||||||
``rndc-confgen``.
|
|
||||||
|
|
||||||
``-k keyname``
|
|
||||||
This option specifies the key name of the ``rndc`` authentication key. This must be a
|
|
||||||
valid domain name. The default is ``rndc-key``.
|
|
||||||
|
|
||||||
``-p port``
|
|
||||||
This option specifies the command channel port where ``named`` listens for
|
|
||||||
connections from ``rndc``. The default is 953.
|
|
||||||
|
|
||||||
``-q``
|
|
||||||
This option prevets printing the written path in automatic configuration mode.
|
|
||||||
|
|
||||||
``-s address``
|
|
||||||
This option specifies the IP address where ``named`` listens for command-channel
|
|
||||||
connections from ``rndc``. The default is the loopback address
|
|
||||||
127.0.0.1.
|
|
||||||
|
|
||||||
``-t chrootdir``
|
|
||||||
This option is used with the ``-a`` option to specify a directory where ``named``
|
|
||||||
runs chrooted. An additional copy of the ``rndc.key`` is
|
|
||||||
written relative to this directory, so that it is found by the
|
|
||||||
chrooted ``named``.
|
|
||||||
|
|
||||||
``-u user``
|
|
||||||
This option is used with the ``-a`` option to set the owner of the generated ``rndc.key`` file.
|
|
||||||
If ``-t`` is also specified, only the file in the chroot
|
|
||||||
area has its owner changed.
|
|
||||||
|
|
||||||
Examples
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
To allow ``rndc`` to be used with no manual configuration, run:
|
|
||||||
|
|
||||||
``rndc-confgen -a``
|
|
||||||
|
|
||||||
To print a sample ``rndc.conf`` file and the corresponding ``controls`` and
|
|
||||||
``key`` statements to be manually inserted into ``named.conf``, run:
|
|
||||||
|
|
||||||
``rndc-confgen``
|
|
||||||
|
|
||||||
See Also
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:manpage:`rndc(8)`, :manpage:`rndc.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
|
||||||
@@ -1,309 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
/**
|
|
||||||
* tsig-keygen generates TSIG keys that can be used in named configuration
|
|
||||||
* files for dynamic DNS.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <stdarg.h>
|
|
||||||
#include <stdbool.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/assertions.h>
|
|
||||||
#include <isc/attributes.h>
|
|
||||||
#include <isc/base64.h>
|
|
||||||
#include <isc/buffer.h>
|
|
||||||
#include <isc/commandline.h>
|
|
||||||
#include <isc/file.h>
|
|
||||||
#include <isc/mem.h>
|
|
||||||
#include <isc/net.h>
|
|
||||||
#include <isc/print.h>
|
|
||||||
#include <isc/result.h>
|
|
||||||
#include <isc/string.h>
|
|
||||||
#include <isc/time.h>
|
|
||||||
#include <isc/util.h>
|
|
||||||
|
|
||||||
#if USE_PKCS11
|
|
||||||
#include <pk11/result.h>
|
|
||||||
#endif /* if USE_PKCS11 */
|
|
||||||
|
|
||||||
#include <dns/keyvalues.h>
|
|
||||||
#include <dns/name.h>
|
|
||||||
#include <dns/result.h>
|
|
||||||
|
|
||||||
#include <dst/dst.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
|
||||||
|
|
||||||
#include "keygen.h"
|
|
||||||
#include "util.h"
|
|
||||||
|
|
||||||
#define KEYGEN_DEFAULT "tsig-key"
|
|
||||||
#define CONFGEN_DEFAULT "ddns-key"
|
|
||||||
|
|
||||||
static char program[256];
|
|
||||||
const char *progname;
|
|
||||||
static enum { progmode_keygen, progmode_confgen } progmode;
|
|
||||||
bool verbose = false; /* needed by util.c but not used here */
|
|
||||||
|
|
||||||
ISC_NORETURN static void
|
|
||||||
usage(int status);
|
|
||||||
|
|
||||||
static void
|
|
||||||
usage(int status) {
|
|
||||||
if (progmode == progmode_confgen) {
|
|
||||||
fprintf(stderr, "\
|
|
||||||
Usage:\n\
|
|
||||||
%s [-a alg] [-k keyname] [-q] [-s name | -z zone]\n\
|
|
||||||
-a alg: algorithm (default hmac-sha256)\n\
|
|
||||||
-k keyname: name of the key as it will be used in named.conf\n\
|
|
||||||
-s name: domain name to be updated using the created key\n\
|
|
||||||
-z zone: name of the zone as it will be used in named.conf\n\
|
|
||||||
-q: quiet mode: print the key, with no explanatory text\n",
|
|
||||||
progname);
|
|
||||||
} else {
|
|
||||||
fprintf(stderr, "\
|
|
||||||
Usage:\n\
|
|
||||||
%s [-a alg] [keyname]\n\
|
|
||||||
-a alg: algorithm (default hmac-sha256)\n\n",
|
|
||||||
progname);
|
|
||||||
}
|
|
||||||
|
|
||||||
exit(status);
|
|
||||||
}
|
|
||||||
|
|
||||||
int
|
|
||||||
main(int argc, char **argv) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
bool show_final_mem = false;
|
|
||||||
bool quiet = false;
|
|
||||||
isc_buffer_t key_txtbuffer;
|
|
||||||
char key_txtsecret[256];
|
|
||||||
isc_mem_t *mctx = NULL;
|
|
||||||
const char *keyname = NULL;
|
|
||||||
const char *zone = NULL;
|
|
||||||
const char *self_domain = NULL;
|
|
||||||
char *keybuf = NULL;
|
|
||||||
dns_secalg_t alg = DST_ALG_HMACSHA256;
|
|
||||||
const char *algname;
|
|
||||||
int keysize = 256;
|
|
||||||
int len = 0;
|
|
||||||
int ch;
|
|
||||||
|
|
||||||
#if USE_PKCS11
|
|
||||||
pk11_result_register();
|
|
||||||
#endif /* if USE_PKCS11 */
|
|
||||||
dns_result_register();
|
|
||||||
|
|
||||||
result = isc_file_progname(*argv, program, sizeof(program));
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
memmove(program, "tsig-keygen", 11);
|
|
||||||
}
|
|
||||||
progname = program;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Libtool doesn't preserve the program name prior to final
|
|
||||||
* installation. Remove the libtool prefix ("lt-").
|
|
||||||
*/
|
|
||||||
if (strncmp(progname, "lt-", 3) == 0) {
|
|
||||||
progname += 3;
|
|
||||||
}
|
|
||||||
|
|
||||||
#define PROGCMP(X) \
|
|
||||||
(strcasecmp(progname, X) == 0 || strcasecmp(progname, X ".exe") == 0)
|
|
||||||
|
|
||||||
if (PROGCMP("tsig-keygen")) {
|
|
||||||
progmode = progmode_keygen;
|
|
||||||
quiet = true;
|
|
||||||
} else if (PROGCMP("ddns-confgen")) {
|
|
||||||
progmode = progmode_confgen;
|
|
||||||
} else {
|
|
||||||
INSIST(0);
|
|
||||||
ISC_UNREACHABLE();
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
|
||||||
|
|
||||||
while ((ch = isc_commandline_parse(argc, argv, "a:hk:Mmr:qs:y:z:")) !=
|
|
||||||
-1) {
|
|
||||||
switch (ch) {
|
|
||||||
case 'a':
|
|
||||||
algname = isc_commandline_argument;
|
|
||||||
alg = alg_fromtext(algname);
|
|
||||||
if (alg == DST_ALG_UNKNOWN) {
|
|
||||||
fatal("Unsupported algorithm '%s'", algname);
|
|
||||||
}
|
|
||||||
keysize = alg_bits(alg);
|
|
||||||
break;
|
|
||||||
case 'h':
|
|
||||||
usage(0);
|
|
||||||
case 'k':
|
|
||||||
case 'y':
|
|
||||||
if (progmode == progmode_confgen) {
|
|
||||||
keyname = isc_commandline_argument;
|
|
||||||
} else {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'M':
|
|
||||||
isc_mem_debugging = ISC_MEM_DEBUGTRACE;
|
|
||||||
break;
|
|
||||||
case 'm':
|
|
||||||
show_final_mem = true;
|
|
||||||
break;
|
|
||||||
case 'q':
|
|
||||||
if (progmode == progmode_confgen) {
|
|
||||||
quiet = true;
|
|
||||||
} else {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'r':
|
|
||||||
fatal("The -r option has been deprecated.");
|
|
||||||
break;
|
|
||||||
case 's':
|
|
||||||
if (progmode == progmode_confgen) {
|
|
||||||
self_domain = isc_commandline_argument;
|
|
||||||
} else {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case 'z':
|
|
||||||
if (progmode == progmode_confgen) {
|
|
||||||
zone = isc_commandline_argument;
|
|
||||||
} else {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
case '?':
|
|
||||||
if (isc_commandline_option != '?') {
|
|
||||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
|
||||||
program, isc_commandline_option);
|
|
||||||
usage(1);
|
|
||||||
} else {
|
|
||||||
usage(0);
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n", program,
|
|
||||||
isc_commandline_option);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (progmode == progmode_keygen) {
|
|
||||||
keyname = argv[isc_commandline_index++];
|
|
||||||
}
|
|
||||||
|
|
||||||
POST(argv);
|
|
||||||
|
|
||||||
if (self_domain != NULL && zone != NULL) {
|
|
||||||
usage(1); /* -s and -z cannot coexist */
|
|
||||||
}
|
|
||||||
|
|
||||||
if (argc > isc_commandline_index) {
|
|
||||||
usage(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Use canonical algorithm name */
|
|
||||||
algname = alg_totext(alg);
|
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
|
||||||
|
|
||||||
if (keyname == NULL) {
|
|
||||||
const char *suffix = NULL;
|
|
||||||
|
|
||||||
keyname = ((progmode == progmode_keygen) ? KEYGEN_DEFAULT
|
|
||||||
: CONFGEN_DEFAULT);
|
|
||||||
if (self_domain != NULL) {
|
|
||||||
suffix = self_domain;
|
|
||||||
} else if (zone != NULL) {
|
|
||||||
suffix = zone;
|
|
||||||
}
|
|
||||||
if (suffix != NULL) {
|
|
||||||
len = strlen(keyname) + strlen(suffix) + 2;
|
|
||||||
keybuf = isc_mem_get(mctx, len);
|
|
||||||
snprintf(keybuf, len, "%s.%s", keyname, suffix);
|
|
||||||
keyname = (const char *)keybuf;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
|
||||||
|
|
||||||
generate_key(mctx, alg, keysize, &key_txtbuffer);
|
|
||||||
|
|
||||||
if (!quiet) {
|
|
||||||
printf("\
|
|
||||||
# To activate this key, place the following in named.conf, and\n\
|
|
||||||
# in a separate keyfile on the system or systems from which nsupdate\n\
|
|
||||||
# will be run:\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
printf("\
|
|
||||||
key \"%s\" {\n\
|
|
||||||
algorithm %s;\n\
|
|
||||||
secret \"%.*s\";\n\
|
|
||||||
};\n",
|
|
||||||
keyname, algname, (int)isc_buffer_usedlength(&key_txtbuffer),
|
|
||||||
(char *)isc_buffer_base(&key_txtbuffer));
|
|
||||||
|
|
||||||
if (!quiet) {
|
|
||||||
if (self_domain != NULL) {
|
|
||||||
printf("\n\
|
|
||||||
# Then, in the \"zone\" statement for the zone containing the\n\
|
|
||||||
# name \"%s\", place an \"update-policy\" statement\n\
|
|
||||||
# like this one, adjusted as needed for your preferred permissions:\n\
|
|
||||||
update-policy {\n\
|
|
||||||
grant %s name %s ANY;\n\
|
|
||||||
};\n",
|
|
||||||
self_domain, keyname, self_domain);
|
|
||||||
} else if (zone != NULL) {
|
|
||||||
printf("\n\
|
|
||||||
# Then, in the \"zone\" definition statement for \"%s\",\n\
|
|
||||||
# place an \"update-policy\" statement like this one, adjusted as \n\
|
|
||||||
# needed for your preferred permissions:\n\
|
|
||||||
update-policy {\n\
|
|
||||||
grant %s zonesub ANY;\n\
|
|
||||||
};\n",
|
|
||||||
zone, keyname);
|
|
||||||
} else {
|
|
||||||
printf("\n\
|
|
||||||
# Then, in the \"zone\" statement for each zone you wish to dynamically\n\
|
|
||||||
# update, place an \"update-policy\" statement granting update permission\n\
|
|
||||||
# to this key. For example, the following statement grants this key\n\
|
|
||||||
# permission to update any name within the zone:\n\
|
|
||||||
update-policy {\n\
|
|
||||||
grant %s zonesub ANY;\n\
|
|
||||||
};\n",
|
|
||||||
keyname);
|
|
||||||
}
|
|
||||||
|
|
||||||
printf("\n\
|
|
||||||
# After the keyfile has been placed, the following command will\n\
|
|
||||||
# execute nsupdate using this key:\n\
|
|
||||||
nsupdate -k <keyfile>\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (keybuf != NULL) {
|
|
||||||
isc_mem_put(mctx, keybuf, len);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (show_final_mem) {
|
|
||||||
isc_mem_stats(mctx, stderr);
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
|
||||||
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
@@ -1,101 +0,0 @@
|
|||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
..
|
|
||||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
See the COPYRIGHT file distributed with this work for additional
|
|
||||||
information regarding copyright ownership.
|
|
||||||
|
|
||||||
|
|
||||||
.. highlight: console
|
|
||||||
|
|
||||||
tsig-keygen, ddns-confgen - TSIG key generation tool
|
|
||||||
----------------------------------------------------
|
|
||||||
|
|
||||||
Synopsis
|
|
||||||
~~~~~~~~
|
|
||||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [**-r** randomfile] [name]
|
|
||||||
|
|
||||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-r** randomfile] [**-s** name] [**-z** zone]
|
|
||||||
|
|
||||||
Description
|
|
||||||
~~~~~~~~~~~
|
|
||||||
|
|
||||||
``tsig-keygen`` and ``ddns-confgen`` are invocation methods for a
|
|
||||||
utility that generates keys for use in TSIG signing. The resulting keys
|
|
||||||
can be used, for example, to secure dynamic DNS updates to a zone, or for
|
|
||||||
the ``rndc`` command channel.
|
|
||||||
|
|
||||||
When run as ``tsig-keygen``, a domain name can be specified on the
|
|
||||||
command line to be used as the name of the generated key. If no
|
|
||||||
name is specified, the default is ``tsig-key``.
|
|
||||||
|
|
||||||
When run as ``ddns-confgen``, the key name can specified using ``-k``
|
|
||||||
parameter and defaults to ``ddns-key``. The generated key is accompanied
|
|
||||||
by configuration text and instructions that can be used with ``nsupdate``
|
|
||||||
and ``named`` when setting up dynamic DNS, including an example
|
|
||||||
``update-policy`` statement. (This usage is similar to the ``rndc-confgen``
|
|
||||||
command for setting up command-channel security.)
|
|
||||||
|
|
||||||
Note that ``named`` itself can configure a local DDNS key for use with
|
|
||||||
``nsupdate -l``; it does this when a zone is configured with
|
|
||||||
``update-policy local;``. ``ddns-confgen`` is only needed when a more
|
|
||||||
elaborate configuration is required: for instance, if ``nsupdate`` is to
|
|
||||||
be used from a remote system.
|
|
||||||
|
|
||||||
Options
|
|
||||||
~~~~~~~
|
|
||||||
|
|
||||||
``-a algorithm``
|
|
||||||
This option specifies the algorithm to use for the TSIG key. Available
|
|
||||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384,
|
|
||||||
and hmac-sha512. The default is hmac-sha256. Options are
|
|
||||||
case-insensitive, and the "hmac-" prefix may be omitted.
|
|
||||||
|
|
||||||
``-h``
|
|
||||||
This option prints a short summary of options and arguments.
|
|
||||||
|
|
||||||
``-k keyname``
|
|
||||||
This option specifies the key name of the DDNS authentication key. The
|
|
||||||
default is ``ddns-key`` when neither the ``-s`` nor ``-z`` option is
|
|
||||||
specified; otherwise, the default is ``ddns-key`` as a separate label
|
|
||||||
followed by the argument of the option, e.g., ``ddns-key.example.com.``
|
|
||||||
The key name must have the format of a valid domain name, consisting of
|
|
||||||
letters, digits, hyphens, and periods.
|
|
||||||
|
|
||||||
``-q`` (``ddns-confgen`` only)
|
|
||||||
This option enables quiet mode, which prints only the key, with no
|
|
||||||
explanatory text or usage examples. This is essentially identical to
|
|
||||||
``tsig-keygen``.
|
|
||||||
|
|
||||||
``-s name`` (``ddns-confgen`` only)
|
|
||||||
This option generates a configuration example to allow dynamic updates
|
|
||||||
of a single hostname. The example ``named.conf`` text shows how to set
|
|
||||||
an update policy for the specified name using the "name" nametype. The
|
|
||||||
default key name is ``ddns-key.name``. Note that the "self" nametype
|
|
||||||
cannot be used, since the name to be updated may differ from the key
|
|
||||||
name. This option cannot be used with the ``-z`` option.
|
|
||||||
|
|
||||||
``-z zone`` (``ddns-confgen`` only)
|
|
||||||
This option generates a configuration example to allow
|
|
||||||
dynamic updates of a zone. The example ``named.conf`` text shows how
|
|
||||||
to set an update policy for the specified zone using the "zonesub"
|
|
||||||
nametype, allowing updates to all subdomain names within that zone.
|
|
||||||
This option cannot be used with the ``-s`` option.
|
|
||||||
|
|
||||||
See Also
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
:manpage:`nsupdate(1)`, :manpage:`named.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#include <errno.h>
|
|
||||||
#include <fcntl.h>
|
|
||||||
#include <pwd.h>
|
|
||||||
#include <stdio.h>
|
|
||||||
#include <sys/stat.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <unistd.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
|
||||||
|
|
||||||
int
|
|
||||||
set_user(FILE *fd, const char *user) {
|
|
||||||
struct passwd *pw;
|
|
||||||
|
|
||||||
pw = getpwnam(user);
|
|
||||||
if (pw == NULL) {
|
|
||||||
errno = EINVAL;
|
|
||||||
return (-1);
|
|
||||||
}
|
|
||||||
return (fchown(fileno(fd), pw->pw_uid, -1));
|
|
||||||
}
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#include "util.h"
|
|
||||||
#include <stdarg.h>
|
|
||||||
#include <stdbool.h>
|
|
||||||
#include <stdio.h>
|
|
||||||
#include <stdlib.h>
|
|
||||||
|
|
||||||
#include <isc/print.h>
|
|
||||||
|
|
||||||
extern bool verbose;
|
|
||||||
extern const char *progname;
|
|
||||||
|
|
||||||
void
|
|
||||||
notify(const char *fmt, ...) {
|
|
||||||
va_list ap;
|
|
||||||
|
|
||||||
if (verbose) {
|
|
||||||
va_start(ap, fmt);
|
|
||||||
vfprintf(stderr, fmt, ap);
|
|
||||||
va_end(ap);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
fatal(const char *format, ...) {
|
|
||||||
va_list args;
|
|
||||||
|
|
||||||
fprintf(stderr, "%s: ", progname);
|
|
||||||
va_start(args, format);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
va_end(args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
@@ -1,44 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#ifndef RNDC_UTIL_H
|
|
||||||
#define RNDC_UTIL_H 1
|
|
||||||
|
|
||||||
/*! \file */
|
|
||||||
|
|
||||||
#include <isc/attributes.h>
|
|
||||||
#include <isc/formatcheck.h>
|
|
||||||
#include <isc/lang.h>
|
|
||||||
#include <isc/platform.h>
|
|
||||||
|
|
||||||
#define NS_CONTROL_PORT 953
|
|
||||||
|
|
||||||
#undef DO
|
|
||||||
#define DO(name, function) \
|
|
||||||
do { \
|
|
||||||
result = function; \
|
|
||||||
if (result != ISC_R_SUCCESS) \
|
|
||||||
fatal("%s: %s", name, isc_result_totext(result)); \
|
|
||||||
else \
|
|
||||||
notify("%s", name); \
|
|
||||||
} while (0)
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
|
||||||
|
|
||||||
void
|
|
||||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
|
||||||
|
|
||||||
ISC_NORETURN void
|
|
||||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
|
|
||||||
#endif /* RNDC_UTIL_H */
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup>
|
|
||||||
<Filter Include="Source Files">
|
|
||||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
|
||||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Header Files">
|
|
||||||
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
|
|
||||||
<Extensions>h;hpp;hxx;hm;inl;inc;xsd</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
|
||||||
</Filter>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\keygen.h">
|
|
||||||
<Filter>Header Files</Filter>
|
|
||||||
</ClInclude>
|
|
||||||
<ClInclude Include="..\util.h">
|
|
||||||
<Filter>Header Files</Filter>
|
|
||||||
</ClInclude>
|
|
||||||
<ClInclude Include="..\include\confgen\os.h">
|
|
||||||
<Filter>Header Files</Filter>
|
|
||||||
</ClInclude>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\keygen.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
<ClCompile Include="..\util.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
<ClCompile Include="os.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
</ItemGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,128 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project DefaultTargets="Build" ToolsVersion="@TOOLS_VERSION@" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup Label="ProjectConfigurations">
|
|
||||||
<ProjectConfiguration Include="Debug|@PLATFORM@">
|
|
||||||
<Configuration>Debug</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
<ProjectConfiguration Include="Release|@PLATFORM@">
|
|
||||||
<Configuration>Release</Configuration>
|
|
||||||
<Platform>@PLATFORM@</Platform>
|
|
||||||
</ProjectConfiguration>
|
|
||||||
</ItemGroup>
|
|
||||||
<PropertyGroup Label="Globals">
|
|
||||||
<ProjectGuid>{64964B03-4815-41F0-9057-E766A94AF197}</ProjectGuid>
|
|
||||||
<Keyword>Win32Proj</Keyword>
|
|
||||||
<RootNamespace>confgentool</RootNamespace>
|
|
||||||
@WINDOWS_TARGET_PLATFORM_VERSION@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>StaticLibrary</ConfigurationType>
|
|
||||||
<UseDebugLibraries>true</UseDebugLibraries>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'" Label="Configuration">
|
|
||||||
<ConfigurationType>StaticLibrary</ConfigurationType>
|
|
||||||
<UseDebugLibraries>false</UseDebugLibraries>
|
|
||||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
|
||||||
<CharacterSet>MultiByte</CharacterSet>
|
|
||||||
@PLATFORM_TOOLSET@
|
|
||||||
</PropertyGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
|
||||||
<ImportGroup Label="ExtensionSettings">
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
|
||||||
</ImportGroup>
|
|
||||||
<PropertyGroup Label="UserMacros" />
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<LinkIncremental>true</LinkIncremental>
|
|
||||||
<OutDir>.\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
</PropertyGroup>
|
|
||||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<LinkIncremental>false</LinkIncremental>
|
|
||||||
<OutDir>.\$(Configuration)\</OutDir>
|
|
||||||
<IntDir>.\$(Configuration)\</IntDir>
|
|
||||||
<IntDirSharingDetected>None</IntDirSharingDetected>
|
|
||||||
</PropertyGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<WarningLevel>Level4</WarningLevel>
|
|
||||||
<TreatWarningAsError>false</TreatWarningAsError>
|
|
||||||
<Optimization>Disabled</Optimization>
|
|
||||||
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(TargetName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<BrowseInformation>true</BrowseInformation>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
|
||||||
</Link>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
|
||||||
<ClCompile>
|
|
||||||
<WarningLevel>Level1</WarningLevel>
|
|
||||||
<TreatWarningAsError>true</TreatWarningAsError>
|
|
||||||
<PrecompiledHeader>
|
|
||||||
</PrecompiledHeader>
|
|
||||||
<Optimization>MaxSpeed</Optimization>
|
|
||||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
|
||||||
<IntrinsicFunctions>@INTRINSIC@</IntrinsicFunctions>
|
|
||||||
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
|
||||||
<InlineFunctionExpansion>OnlyExplicitInline</InlineFunctionExpansion>
|
|
||||||
<WholeProgramOptimization>false</WholeProgramOptimization>
|
|
||||||
<StringPooling>true</StringPooling>
|
|
||||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(TargetName).pch</PrecompiledHeaderOutputFile>
|
|
||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
|
||||||
</ClCompile>
|
|
||||||
<Link>
|
|
||||||
<SubSystem>Console</SubSystem>
|
|
||||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
|
||||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
|
||||||
<OptimizeReferences>true</OptimizeReferences>
|
|
||||||
<LinkTimeCodeGeneration>false</LinkTimeCodeGeneration>
|
|
||||||
</Link>
|
|
||||||
</ItemDefinitionGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClInclude Include="..\include\confgen\os.h" />
|
|
||||||
<ClInclude Include="..\keygen.h" />
|
|
||||||
<ClInclude Include="..\util.h" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\keygen.c" />
|
|
||||||
<ClCompile Include="..\util.c" />
|
|
||||||
<ClCompile Include="os.c" />
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ProjectReference Include="..\..\..\lib\isc\win32\libisc.vcxproj">
|
|
||||||
<Project>{3840E563-D180-4761-AA9C-E6155F02EAFF}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
<ProjectReference Include="..\..\..\lib\dns\win32\libdns.vcxproj">
|
|
||||||
<Project>{5FEBFD4E-CCB0-48B9-B733-E15EEB85C16A}</Project>
|
|
||||||
</ProjectReference>
|
|
||||||
</ItemGroup>
|
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
|
||||||
<ImportGroup Label="ExtensionTargets">
|
|
||||||
</ImportGroup>
|
|
||||||
</Project>
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
</Project>
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
*
|
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <errno.h>
|
|
||||||
#include <fcntl.h>
|
|
||||||
#include <io.h>
|
|
||||||
#include <stdio.h>
|
|
||||||
#include <sys/stat.h>
|
|
||||||
#include <sys/types.h>
|
|
||||||
#include <unistd.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
|
||||||
|
|
||||||
int
|
|
||||||
set_user(FILE *fd, const char *user) {
|
|
||||||
return (0);
|
|
||||||
}
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
|
||||||
<ItemGroup>
|
|
||||||
<Filter Include="Source Files">
|
|
||||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
|
||||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
|
||||||
</Filter>
|
|
||||||
</ItemGroup>
|
|
||||||
<ItemGroup>
|
|
||||||
<ClCompile Include="..\rndc-confgen.c">
|
|
||||||
<Filter>Source Files</Filter>
|
|
||||||
</ClCompile>
|
|
||||||
</ItemGroup>
|
|
||||||
</Project>
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user