Compare commits
341
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4d9a557190 | ||
|
|
4cc36f925c | ||
|
|
65ad25bb86 | ||
|
|
d0bc45be17 | ||
|
|
f269585de3 | ||
|
|
9936462f31 | ||
|
|
caf18da7f6 | ||
|
|
21eab267df | ||
|
|
bad5a523c2 | ||
|
|
b9f4ba19a6 | ||
|
|
70e9068432 | ||
|
|
d4163e2e97 | ||
|
|
ac1f0d9d61 | ||
|
|
952d7fde63 | ||
|
|
bfc041def1 | ||
|
|
38277ddb0b | ||
|
|
eb524d27d9 | ||
|
|
4b2911a45a | ||
|
|
76eac9a691 | ||
|
|
519b047362 | ||
|
|
ffb7ae8beb | ||
|
|
434c4e99f3 | ||
|
|
31264a7e00 | ||
|
|
3e912d9aa7 | ||
|
|
26a93d77aa | ||
|
|
011af4de71 | ||
|
|
afc7389ce8 | ||
|
|
545e1391fa | ||
|
|
8bbafeb5ef | ||
|
|
50e1bf3800 | ||
|
|
909dc1a1ab | ||
|
|
fa70fc8731 | ||
|
|
3b2850f4d9 | ||
|
|
3ce6708be2 | ||
|
|
6eed126051 | ||
|
|
6ce39f64d9 | ||
|
|
b8bb1e02ad | ||
|
|
2515825a2b | ||
|
|
8bdb5f586a | ||
|
|
d484b66ae1 | ||
|
|
00333a5c97 | ||
|
|
d6c5052f7e | ||
|
|
37354ee225 | ||
|
|
c4ad0466d6 | ||
|
|
0260d31d26 | ||
|
|
199bd6b623 | ||
|
|
b7a72b1667 | ||
|
|
751ad12dea | ||
|
|
3075445ed6 | ||
|
|
caf073dbe7 | ||
|
|
ab71b29098 | ||
|
|
444d742a94 | ||
|
|
eb21ecf55c | ||
|
|
e98157b7fe | ||
|
|
fdcd58d404 | ||
|
|
78685ed173 | ||
|
|
9113ed840c | ||
|
|
6030cadef0 | ||
|
|
58db2d1d18 | ||
|
|
cadbc158f0 | ||
|
|
7bd3205c61 | ||
|
|
cd3e34de8f | ||
|
|
d0a0c22433 | ||
|
|
512dadc8d1 | ||
|
|
081326929f | ||
|
|
b00360537e | ||
|
|
584c1da066 | ||
|
|
c727c59663 | ||
|
|
097328db7a | ||
|
|
4534fb5ec1 | ||
|
|
7d4d64340e | ||
|
|
0cda448248 | ||
|
|
7e6d76e7db | ||
|
|
b50ced528d | ||
|
|
304c1b6439 | ||
|
|
9b6e023f84 | ||
|
|
bcfc07e3d3 | ||
|
|
ca83a66618 | ||
|
|
6fe28d92c4 | ||
|
|
419aa15cd1 | ||
|
|
fcb6dbcdd7 | ||
|
|
eba576dddf | ||
|
|
a5189eefa5 | ||
|
|
55d82ced78 | ||
|
|
0946db13de | ||
|
|
c17bc7387c | ||
|
|
7d93371581 | ||
|
|
fa2f16db89 | ||
|
|
a48814906f | ||
|
|
767a2aef43 | ||
|
|
7c54199fe1 | ||
|
|
73cafd9d57 | ||
|
|
70f80a3ec7 | ||
|
|
62a8405fa2 | ||
|
|
6718a4ef8b | ||
|
|
123ee350dc | ||
|
|
20bb812148 | ||
|
|
0f9d8eb7b5 | ||
|
|
c5b6f21515 | ||
|
|
e95af30b23 | ||
|
|
dad10c0fd0 | ||
|
|
7b9084d45d | ||
|
|
6858ef9adc | ||
|
|
23964dbbbc | ||
|
|
76d1e95f4e | ||
|
|
00605058b4 | ||
|
|
c7b20f3c40 | ||
|
|
b88faee181 | ||
|
|
ac65f56774 | ||
|
|
d97e628f81 | ||
|
|
c29ccae2a6 | ||
|
|
54a682ea50 | ||
|
|
342cc9b168 | ||
|
|
edafbf1c0f | ||
|
|
8aaee26548 | ||
|
|
4d3ed3f4ea | ||
|
|
a8f89e9a9f | ||
|
|
854af5a353 | ||
|
|
1a8348e2b4 | ||
|
|
feba480527 | ||
|
|
3fede8a7e9 | ||
|
|
ac0d3c21c6 | ||
|
|
f75328b178 | ||
|
|
11cd9d86e4 | ||
|
|
692c879e3c | ||
|
|
3a4334636b | ||
|
|
9119dc25fe | ||
|
|
22aa668b7d | ||
|
|
9150688efd | ||
|
|
edc9c79c9c | ||
|
|
d0f8c50618 | ||
|
|
ea1d4d11fc | ||
|
|
3659cca624 | ||
|
|
54710873a7 | ||
|
|
6dc5343d6d | ||
|
|
61456d886e | ||
|
|
34d7776f14 | ||
|
|
32d1cc1562 | ||
|
|
95817d8bbb | ||
|
|
d50322ed95 | ||
|
|
abe8fa5253 | ||
|
|
72ca05c966 | ||
|
|
7101eae6f4 | ||
|
|
bd9f5c3c19 | ||
|
|
aca0f88750 | ||
|
|
2c3589e22a | ||
|
|
b9cb4c94fa | ||
|
|
8de64964a3 | ||
|
|
229b7d85e8 | ||
|
|
5ce4b04b50 | ||
|
|
3d92f5e95a | ||
|
|
c830a9116d | ||
|
|
b4a015ebcd | ||
|
|
d8768bd143 | ||
|
|
fadd39dc83 | ||
|
|
bd80969b11 | ||
|
|
e879490f10 | ||
|
|
d10fbdec84 | ||
|
|
9e2da86ab9 | ||
|
|
47e14c4d17 | ||
|
|
7df491e819 | ||
|
|
8729c56cd8 | ||
|
|
dfc312ac56 | ||
|
|
2f37ab1dac | ||
|
|
86b10eff81 | ||
|
|
f1cbdc5498 | ||
|
|
d6f68fc4f0 | ||
|
|
46eaa854d2 | ||
|
|
02050bc506 | ||
|
|
0480a95ddf | ||
|
|
25800c892f | ||
|
|
129fb63db6 | ||
|
|
24510a1fda | ||
|
|
b9a5508e52 | ||
|
|
53f0b6c34d | ||
|
|
33bf90331b | ||
|
|
a85a65f96e | ||
|
|
59c64fa4bd | ||
|
|
36ee430327 | ||
|
|
f188d00227 | ||
|
|
48d003edf7 | ||
|
|
70397f9d92 | ||
|
|
a8c814cb2f | ||
|
|
402969bf95 | ||
|
|
64e1a4a398 | ||
|
|
aa57fa7090 | ||
|
|
ae202e0e7c | ||
|
|
a5f8374400 | ||
|
|
949103c14f | ||
|
|
18c9a20f32 | ||
|
|
23ca0ec55b | ||
|
|
9841635b7f | ||
|
|
46df363a0d | ||
|
|
2f4877d11c | ||
|
|
6bd1f68bef | ||
|
|
1e22e052d0 | ||
|
|
69f8f65323 | ||
|
|
e17b7ee05a | ||
|
|
65860c8000 | ||
|
|
d5f00f8303 | ||
|
|
e9df8f4e8e | ||
|
|
88bfce0993 | ||
|
|
91498f8b9b | ||
|
|
ec9d6ab64c | ||
|
|
3a9de38eb6 | ||
|
|
8afcffaa86 | ||
|
|
45d6239829 | ||
|
|
18454a0b9d | ||
|
|
e7a9f52f50 | ||
|
|
bae0edbf02 | ||
|
|
5f464d15a0 | ||
|
|
ce1c1631b3 | ||
|
|
5eedd365d4 | ||
|
|
f11ce44818 | ||
|
|
70da58c871 | ||
|
|
c3e0ac865f | ||
|
|
2e46dcbbce | ||
|
|
1211c348bb | ||
|
|
29e6ec3181 | ||
|
|
9fbc869108 | ||
|
|
67033bfd3d | ||
|
|
6468ffc336 | ||
|
|
36c72bf3c3 | ||
|
|
c9f1ec8380 | ||
|
|
7c783ab909 | ||
|
|
c125b721ef | ||
|
|
fcf14b2b47 | ||
|
|
09990672d9 | ||
|
|
7e7aa5387c | ||
|
|
314b90dfdd | ||
|
|
1f0d6296a1 | ||
|
|
dcf79ce61f | ||
|
|
da0ae5299f | ||
|
|
53e76f888b | ||
|
|
72042a06d6 | ||
|
|
c55625b035 | ||
|
|
2924b19a9d | ||
|
|
09ac224c5c | ||
|
|
97a5698e06 | ||
|
|
77d2895a5a | ||
|
|
7f4d1dbddf | ||
|
|
68e8741c98 | ||
|
|
e6ee5486ca | ||
|
|
7bfac50336 | ||
|
|
1a9692f5c8 | ||
|
|
2829e29410 | ||
|
|
48ce026dc9 | ||
|
|
e9ccebd94e | ||
|
|
a50d707fdc | ||
|
|
1fbd8bb1b3 | ||
|
|
b7c5bfb203 | ||
|
|
c67379fb92 | ||
|
|
799e95b132 | ||
|
|
d0a3273d4d | ||
|
|
db670fcdc8 | ||
|
|
65a8b53bd0 | ||
|
|
89f874e6ee | ||
|
|
8bb7f1f2a1 | ||
|
|
54b92a04b1 | ||
|
|
00569e0dfa | ||
|
|
540b90fd6c | ||
|
|
6b2fd40269 | ||
|
|
7c7f5884e5 | ||
|
|
b4df5a6ecb | ||
|
|
3361247519 | ||
|
|
ebc61946b2 | ||
|
|
9abcff9ce3 | ||
|
|
ba3fe75e65 | ||
|
|
dd492b64d9 | ||
|
|
29be224a04 | ||
|
|
66fe8627de | ||
|
|
a544e2e300 | ||
|
|
eb5611a770 | ||
|
|
0fc98ef2d5 | ||
|
|
5d4182c945 | ||
|
|
7b10faf108 | ||
|
|
51fb42edcb | ||
|
|
2eaa75c380 | ||
|
|
fcd765a59d | ||
|
|
e0fe33506c | ||
|
|
ae33c75d06 | ||
|
|
56ef09c3a1 | ||
|
|
5fc8130822 | ||
|
|
e9acad638e | ||
|
|
6decd14592 | ||
|
|
64cf5144a6 | ||
|
|
309dca417c | ||
|
|
6bbb0b8e42 | ||
|
|
6bf364aec8 | ||
|
|
7aa7f8592c | ||
|
|
80b55d25de | ||
|
|
5f584310bc | ||
|
|
d2fdebe02e | ||
|
|
9de062ae76 | ||
|
|
b612e38af1 | ||
|
|
de368cdf1c | ||
|
|
a7bcca50c1 | ||
|
|
bebeadc8e6 | ||
|
|
ebbe199715 | ||
|
|
1b6419f8a7 | ||
|
|
b7ed939659 | ||
|
|
0d61b73958 | ||
|
|
ecdbc14035 | ||
|
|
e0618174b6 | ||
|
|
f7eea400a8 | ||
|
|
c6f91f8bd0 | ||
|
|
c5453ea328 | ||
|
|
1ea6aadf6f | ||
|
|
d8abf4f5b6 | ||
|
|
18dff8e031 | ||
|
|
36d3c66e4e | ||
|
|
fce3c93ea2 | ||
|
|
7346e6d3b5 | ||
|
|
6cd115994e | ||
|
|
9fd89c0587 | ||
|
|
3c29291842 | ||
|
|
cea2b533fe | ||
|
|
e6ef7858c3 | ||
|
|
8eb09f3232 | ||
|
|
c79077894a | ||
|
|
548f29a4d9 | ||
|
|
a87ccea032 | ||
|
|
89ee56e1c0 | ||
|
|
478831964e | ||
|
|
d091772279 | ||
|
|
cb9553d9e5 | ||
|
|
67166b7ddd | ||
|
|
82f07b2c6d | ||
|
|
4a778cfa45 | ||
|
|
fce5a01a63 | ||
|
|
800d7843af | ||
|
|
a20c42dca6 | ||
|
|
7abd918d73 | ||
|
|
a8910de835 | ||
|
|
35169151d3 | ||
|
|
dce1c05042 | ||
|
|
765312b655 | ||
|
|
918f020f9f | ||
|
|
20647657f9 | ||
|
|
e33f345c4b | ||
|
|
0706e626e0 |
@@ -10,6 +10,7 @@
|
|||||||
*.rej
|
*.rej
|
||||||
*.so
|
*.so
|
||||||
*_test
|
*_test
|
||||||
|
*.ipch # vscode/intellisense precompiled header
|
||||||
*~
|
*~
|
||||||
.ccache/
|
.ccache/
|
||||||
.cproject
|
.cproject
|
||||||
|
|||||||
+89
-22
@@ -16,6 +16,10 @@ variables:
|
|||||||
TEST_PARALLEL_JOBS: 6
|
TEST_PARALLEL_JOBS: 6
|
||||||
|
|
||||||
MAKE: make
|
MAKE: make
|
||||||
|
CONFIGURE: ./configure
|
||||||
|
SCAN_BUILD: scan-build-9
|
||||||
|
|
||||||
|
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- precheck
|
- precheck
|
||||||
@@ -68,6 +72,10 @@ stages:
|
|||||||
image: "$CI_REGISTRY_IMAGE:centos-centos7-amd64"
|
image: "$CI_REGISTRY_IMAGE:centos-centos7-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
|
|
||||||
|
.centos-centos8-amd64: ¢os_centos8_amd64_image
|
||||||
|
image: "$CI_REGISTRY_IMAGE:centos-centos8-amd64"
|
||||||
|
<<: *linux_amd64
|
||||||
|
|
||||||
# Debian
|
# Debian
|
||||||
|
|
||||||
.debian-jessie-amd64: &debian_jessie_amd64_image
|
.debian-jessie-amd64: &debian_jessie_amd64_image
|
||||||
@@ -84,7 +92,7 @@ stages:
|
|||||||
|
|
||||||
.debian-buster-amd64: &debian_buster_amd64_image
|
.debian-buster-amd64: &debian_buster_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-buster-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-buster-amd64"
|
||||||
<<: *linux_i386
|
<<: *linux_amd64
|
||||||
|
|
||||||
.debian-sid-amd64: &debian_sid_amd64_image
|
.debian-sid-amd64: &debian_sid_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
||||||
@@ -154,7 +162,7 @@ stages:
|
|||||||
expire_in: "1 week"
|
expire_in: "1 week"
|
||||||
|
|
||||||
.configure: &configure |
|
.configure: &configure |
|
||||||
./configure \
|
${CONFIGURE} \
|
||||||
--disable-maintainer-mode \
|
--disable-maintainer-mode \
|
||||||
--enable-developer \
|
--enable-developer \
|
||||||
--with-libtool \
|
--with-libtool \
|
||||||
@@ -304,6 +312,7 @@ misc:sid:amd64:
|
|||||||
|
|
||||||
🐞:sid:amd64:
|
🐞:sid:amd64:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
script:
|
script:
|
||||||
- util/check-cocci
|
- util/check-cocci
|
||||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||||
@@ -342,7 +351,7 @@ push:docs:sid:amd64:
|
|||||||
gcc:alpine3.10:amd64:
|
gcc:alpine3.10:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||||
<<: *alpine_3_10_amd64_image
|
<<: *alpine_3_10_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -366,7 +375,7 @@ unit:gcc:alpine3.10:amd64:
|
|||||||
gcc:centos6:amd64:
|
gcc:centos6:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error"
|
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error"
|
||||||
<<: *centos_centos6_amd64_image
|
<<: *centos_centos6_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -390,7 +399,7 @@ unit:gcc:centos6:amd64:
|
|||||||
gcc:centos7:amd64:
|
gcc:centos7:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
<<: *centos_centos7_amd64_image
|
<<: *centos_centos7_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -409,12 +418,36 @@ unit:gcc:centos7:amd64:
|
|||||||
- gcc:centos7:amd64
|
- gcc:centos7:amd64
|
||||||
needs: ["gcc:centos7:amd64"]
|
needs: ["gcc:centos7:amd64"]
|
||||||
|
|
||||||
|
# Jobs for regular GCC builds on CentOS 8 (amd64)
|
||||||
|
|
||||||
|
gcc:centos8:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
|
<<: *centos_centos8_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:gcc:centos8:amd64:
|
||||||
|
<<: *centos_centos8_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:centos8:amd64
|
||||||
|
needs: ["gcc:centos8:amd64"]
|
||||||
|
|
||||||
|
unit:gcc:centos8:amd64:
|
||||||
|
<<: *centos_centos8_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:centos8:amd64
|
||||||
|
needs: ["gcc:centos8:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian 8 Jessie (amd64)
|
# Jobs for regular GCC builds on Debian 8 Jessie (amd64)
|
||||||
|
|
||||||
gcc:jessie:amd64:
|
gcc:jessie:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
||||||
<<: *debian_jessie_amd64_image
|
<<: *debian_jessie_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -438,7 +471,7 @@ unit:gcc:jessie:amd64:
|
|||||||
gcc:stretch:amd64:
|
gcc:stretch:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
<<: *debian_stretch_amd64_image
|
<<: *debian_stretch_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -461,7 +494,7 @@ unit:gcc:stretch:amd64:
|
|||||||
gcc:buster:amd64:
|
gcc:buster:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
<<: *debian_buster_amd64_image
|
<<: *debian_buster_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -479,12 +512,44 @@ unit:gcc:buster:amd64:
|
|||||||
- gcc:buster:amd64
|
- gcc:buster:amd64
|
||||||
needs: ["gcc:buster:amd64"]
|
needs: ["gcc:buster:amd64"]
|
||||||
|
|
||||||
|
# Jobs for scan-build builds on Debian Buster (amd64)
|
||||||
|
|
||||||
|
.scan_build: &scan_build |
|
||||||
|
${SCAN_BUILD} --html-title="BIND 9 ($CI_COMMIT_SHORT_SHA)" \
|
||||||
|
--keep-cc \
|
||||||
|
--status-bugs \
|
||||||
|
--keep-going \
|
||||||
|
-o scan-build.reports \
|
||||||
|
make -j${BUILD_PARALLEL_JOBS:-1} all V=1
|
||||||
|
|
||||||
|
scan-build:buster:amd64:
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
stage: postcheck
|
||||||
|
variables:
|
||||||
|
CC: clang-9
|
||||||
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
|
CONFIGURE: "${SCAN_BUILD} ./configure"
|
||||||
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
|
script:
|
||||||
|
- *configure
|
||||||
|
- *scan_build
|
||||||
|
dependencies:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
|
needs:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- scan-build.reports/
|
||||||
|
expire_in: "1 week"
|
||||||
|
when: on_failure
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian Sid (amd64)
|
# Jobs for regular GCC builds on Debian Sid (amd64)
|
||||||
|
|
||||||
gcc:sid:amd64:
|
gcc:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O3"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
RUN_MAKE_INSTALL: 1
|
RUN_MAKE_INSTALL: 1
|
||||||
MAKE: bear make
|
MAKE: bear make
|
||||||
@@ -517,7 +582,7 @@ cppcheck:gcc:sid:amd64:
|
|||||||
gcc:sid:i386:
|
gcc:sid:i386:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
||||||
<<: *debian_sid_i386_image
|
<<: *debian_sid_i386_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -541,7 +606,7 @@ unit:gcc:sid:i386:
|
|||||||
gcc:fedora30:amd64:
|
gcc:fedora30:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O1"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *fedora_30_amd64_image
|
<<: *fedora_30_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -565,7 +630,7 @@ unit:gcc:fedora30:amd64:
|
|||||||
gcc:xenial:amd64:
|
gcc:xenial:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
EXTRA_CONFIGURE: "--disable-geoip"
|
EXTRA_CONFIGURE: "--disable-geoip"
|
||||||
<<: *ubuntu_xenial_amd64_image
|
<<: *ubuntu_xenial_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -589,7 +654,7 @@ unit:gcc:xenial:amd64:
|
|||||||
gcc:bionic:amd64:
|
gcc:bionic:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *ubuntu_bionic_amd64_image
|
<<: *ubuntu_bionic_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -613,7 +678,8 @@ unit:gcc:bionic:amd64:
|
|||||||
asan:sid:amd64:
|
asan:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
ASAN_OPTIONS: "detect_leaks=0"
|
||||||
|
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
LDFLAGS: "-fsanitize=address,undefined"
|
LDFLAGS: "-fsanitize=address,undefined"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
@@ -636,7 +702,7 @@ unit:asan:sid:amd64:
|
|||||||
rwlock:sid:amd64:
|
rwlock:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
CFLAGS: "${CFLAGS_COMMON} -Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -659,7 +725,7 @@ unit:rwlock:sid:amd64:
|
|||||||
mutexatomics:sid:amd64:
|
mutexatomics:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
CFLAGS: "${CFLAGS_COMMON} -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -684,7 +750,7 @@ mutexatomics:sid:amd64:
|
|||||||
clang:stretch:amd64:
|
clang:stretch:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: clang
|
CC: clang
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||||
EXTRA_CONFIGURE: "--with-python=python3"
|
EXTRA_CONFIGURE: "--with-python=python3"
|
||||||
<<: *debian_stretch_amd64_image
|
<<: *debian_stretch_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -701,7 +767,7 @@ unit:clang:stretch:amd64:
|
|||||||
clang:stretch:i386:
|
clang:stretch:i386:
|
||||||
variables:
|
variables:
|
||||||
CC: clang
|
CC: clang
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||||
EXTRA_CONFIGURE: "--with-python=python2"
|
EXTRA_CONFIGURE: "--with-python=python2"
|
||||||
<<: *debian_stretch_i386_image
|
<<: *debian_stretch_i386_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -711,7 +777,7 @@ clang:stretch:i386:
|
|||||||
pkcs11:sid:amd64:
|
pkcs11:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-native-pkcs11 --with-pkcs11=/usr/lib/softhsm/libsofthsm2.so"
|
EXTRA_CONFIGURE: "--enable-native-pkcs11 --with-pkcs11=/usr/lib/softhsm/libsofthsm2.so"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -734,7 +800,7 @@ unit:pkcs11:sid:amd64:
|
|||||||
|
|
||||||
clang:freebsd11.3:amd64:
|
clang:freebsd11.3:amd64:
|
||||||
variables:
|
variables:
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
<<: *freebsd_amd64
|
<<: *freebsd_amd64
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -756,7 +822,7 @@ unit:clang:freebsd11.3:amd64:
|
|||||||
|
|
||||||
clang:freebsd12.0:amd64:
|
clang:freebsd12.0:amd64:
|
||||||
variables:
|
variables:
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||||
<<: *freebsd_amd64
|
<<: *freebsd_amd64
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -798,7 +864,7 @@ system:clang:openbsd6.5:amd64:
|
|||||||
nolibtool:sid:amd64:
|
nolibtool:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -Og -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -839,6 +905,7 @@ msvc:windows:amd64:
|
|||||||
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
|
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
|
||||||
"with-openssl=C:/OpenSSL"
|
"with-openssl=C:/OpenSSL"
|
||||||
"with-libxml2=C:/libxml2"
|
"with-libxml2=C:/libxml2"
|
||||||
|
"with-libuv=C:/libuv"
|
||||||
"without-python"
|
"without-python"
|
||||||
"with-system-tests"
|
"with-system-tests"
|
||||||
x64'
|
x64'
|
||||||
|
|||||||
@@ -0,0 +1,65 @@
|
|||||||
|
## Release Schedule
|
||||||
|
|
||||||
|
**Tagging Deadline:**
|
||||||
|
|
||||||
|
**ASN Deadline:**
|
||||||
|
|
||||||
|
**Public Release:**
|
||||||
|
|
||||||
|
## Release Checklist
|
||||||
|
|
||||||
|
## 2 Working Days Before the Tagging Deadline
|
||||||
|
|
||||||
|
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
|
||||||
|
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
|
||||||
|
|
||||||
|
## Before the Tagging Deadline
|
||||||
|
|
||||||
|
- [ ] ***(QA)*** Inform Support/Marketing of impending release (and give estimated release dates).
|
||||||
|
- [ ] ***(QA)*** Check Perflab to ensure there has been no unexplained drop in performance for the versions being released.
|
||||||
|
- [ ] ***(SwEng)*** Update API files for libraries with new version information.
|
||||||
|
- [ ] ***(SwEng)*** Change software version and library versions in `configure.ac` (new major release only).
|
||||||
|
- [ ] ***(SwEng)*** Rebuild `configure` using Autoconf on `docs.isc.org`.
|
||||||
|
- [ ] ***(SwEng)*** Update `CHANGES`.
|
||||||
|
- [ ] ***(SwEng)*** Update `CHANGES.SE` (Subscription Edition only).
|
||||||
|
- [ ] ***(SwEng)*** Update `README.md`.
|
||||||
|
- [ ] ***(SwEng)*** Update `version`.
|
||||||
|
- [ ] ***(SwEng)*** Build documentation on `docs.isc.org`.
|
||||||
|
- [ ] ***(QA)*** Check that all the above steps were performed correctly.
|
||||||
|
- [ ] ***(QA)*** Check that the contents of release notes match the merge requests comprising the releases.
|
||||||
|
- [ ] ***(QA)*** Check that the formatting is correct for text, PDF, and HTML versions of release notes.
|
||||||
|
- [ ] ***(SwEng)*** Tag the releases[^2]. (Tags may only be pushed to the public repository for releases which are *not* security releases.)
|
||||||
|
- [ ] ***(SwEng)*** If this is the first tag for a release (e.g. beta), create a release branch named `release_v9_X_Y` to allow development to continue on the maintenance branch whilst release engineering continues.
|
||||||
|
|
||||||
|
## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
|
||||||
|
|
||||||
|
- [ ] ***(QA)*** Run the `make release` Jenkins jobs to produce the tarballs and zips.
|
||||||
|
- [ ] ***(QA)*** Verify the results of `make release` Jenkins jobs and prepare a QA report for the releases to be published.
|
||||||
|
- [ ] ***(QA)*** Request signatures for the tarballs.
|
||||||
|
- [ ] ***(Signers)*** Sign the tarballs.
|
||||||
|
- [ ] ***(QA)*** Check tarball signatures.
|
||||||
|
- [ ] ***(QA)*** Notify Support that the releases are ready for publication.
|
||||||
|
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
|
||||||
|
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
|
||||||
|
- [ ] ***(Support)*** Send out ASNs (if applicable).
|
||||||
|
|
||||||
|
## On the Day of Public Release
|
||||||
|
|
||||||
|
- [ ] ***(Support)*** Publish the releases according to the release schedule.
|
||||||
|
- [ ] ***(Support)*** Write release email to *bind9-announce*.
|
||||||
|
- [ ] ***(Support)*** Write email to *bind9-users* (if a major release).
|
||||||
|
- [ ] ***(Support)*** Update tickets in case of waiting support customers.
|
||||||
|
- [ ] ***(QA)*** Build and test any outstanding private packages.
|
||||||
|
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
|
||||||
|
- [ ] ***(QA)*** Inform Marketing of the release.
|
||||||
|
- [ ] ***(QA)*** Update the internal [BIND release dates wiki page](https://wiki.isc.org/bin/view/Main/BindReleaseDates) when public announcement has been made.
|
||||||
|
- [ ] ***(Marketing)*** Post short note to Twitter.
|
||||||
|
- [ ] ***(Marketing)*** Update [Wikipedia entry for BIND](https://en.wikipedia.org/wiki/BIND).
|
||||||
|
- [ ] ***(Marketing)*** Write blog article (if a major release).
|
||||||
|
- [ ] ***(QA)*** Ensure all new tags are annotated and signed.
|
||||||
|
- [ ] ***(SwEng)*** Push tags for the published releases to the public repository.
|
||||||
|
- [ ] ***(SwEng)*** Merge the automatically prepared `prep 9.X.Y` commit which updates `version` and documentation on the release branch into the relevant maintenance branch (`v9_X`).
|
||||||
|
|
||||||
|
[^1]: If not, use the time remaining until the tagging deadline to ensure all outstanding issues are either resolved or moved to a different milestone.
|
||||||
|
|
||||||
|
[^2]: Preferred command line: `git tag -u <DEVELOPER_KEYID> -a -s -m "BIND 9.X.Y[alphatag]" v9_X_Y[alphatag]`, where `[alphatag]` is an optional string such as `b1`, `rc1`, etc.
|
||||||
@@ -1,44 +0,0 @@
|
|||||||
## Release Checklist
|
|
||||||
|
|
||||||
- [ ] (Manager) Check for the presence of a milestone for the release:
|
|
||||||
- If there is a milestone, are all the issues for the milestone resolved? (other than this checklist).
|
|
||||||
- [ ] (Manager) Inform Support/Marketing of impending release (and give estimated release dates).
|
|
||||||
- (SwEng) Prepare the sources for tarball generation:
|
|
||||||
- [ ] Check perflab to ensure there has been no unexplained drop in performance for the version being released.
|
|
||||||
- [ ] Ensure that there are no outstanding merge requests in the private repository (subscription version only).
|
|
||||||
- [ ] Update API files for libraries with new version information.
|
|
||||||
- [ ] Change software version and library versions in configure.in (new major release only).
|
|
||||||
- [ ] Rebuild configure using autoconf on docs.isc.org.
|
|
||||||
- [ ] Update CHANGES.
|
|
||||||
- [ ] Update CHANGES.SE (subscription branch only).
|
|
||||||
- [ ] Update "version".
|
|
||||||
- [ ] Update "readme.md".
|
|
||||||
- Check the release notes are correct:
|
|
||||||
- [ ] Compare content with merge requests for the release.
|
|
||||||
- [ ] Check formatting.
|
|
||||||
- [ ] Build documentation on docs.isc.org.
|
|
||||||
- [ ] Commit changes and make sure the gitlab-ci tests are passing.
|
|
||||||
- [ ] Push the changes and tag ("alphatag" is an optional string such as "b1", "rc1" etc.). (```git tag -u <DEVELOPER_KEYID> -a -s -m "BIND 9.X.Y[alphatag]" v9_X_Y[alphatag]```)
|
|
||||||
- [ ] If this is the first tag for a release (e.g. beta), create a release branch named `release_v9_X_Y` (this allows development to continue on the release branch whilst release engineering continues).
|
|
||||||
- [ ] (SwEng) Run the "make release" Jenkins job to produce the tarballs and zips.
|
|
||||||
- [ ] (SwEng) Ask QA to sanity check the tarball and zips (passing to them the number of the Jenkins job).
|
|
||||||
- [ ] (QA) Sanity check the tarballs.
|
|
||||||
- [ ] (QA) Request the signature on the tarballs.
|
|
||||||
- [ ] (QA) Check signatures on tarballs.
|
|
||||||
- [ ] (QA) Tell Support to handle notification of release.
|
|
||||||
- [ ] (Manager) Inform Marketing of the release
|
|
||||||
- [ ] (Manager) Update the internal [BIND release dates wiki page](https://wiki.isc.org/bin/view/Main/BindReleaseDates) when public announcement has been made.
|
|
||||||
- [ ] (SwEng) Push tags for the published releases to the public repository.
|
|
||||||
- [ ] (SwEng) Update DEB and RPM packages.
|
|
||||||
- [ ] (SwEng) Merge the automatically prepared `prep 9.X.Y` commit which updates `version` and documentation on the release branch into the relevant maintenance branch (`v9_X`).
|
|
||||||
|
|
||||||
## Support
|
|
||||||
- [ ] Make tarballs and signatures available to download.
|
|
||||||
- [ ] Write release email to bind9-announce.
|
|
||||||
- [ ] Write email to bind9-users (if a major release).
|
|
||||||
- [ ] Update tickets in case of waiting support customers.
|
|
||||||
|
|
||||||
## Marketing
|
|
||||||
- [ ] Post short note to Twitter.
|
|
||||||
- [ ] Update [Wikipedia entry for BIND](http://en.wikipedia.org/wiki/BIND).
|
|
||||||
- [ ] Write blog article (if a major release).
|
|
||||||
@@ -1,5 +1,106 @@
|
|||||||
|
5326. [bug] Add python dependancy on 'distutils.core' to configure.
|
||||||
|
'distutils.core' is required for installation.
|
||||||
|
[GL #1397]
|
||||||
|
|
||||||
|
5325. [bug] Addressed several issues with TCP connections in
|
||||||
|
the netmgr: restored support for TCP connection
|
||||||
|
timeouts, restored TCP backlog support, actively
|
||||||
|
close all open sockets during shutdown. [GL #1312]
|
||||||
|
|
||||||
|
5324. [bug] Change the category of some log messages from general
|
||||||
|
to the more appopriate catergory of xfer-in. [GL #1394]
|
||||||
|
|
||||||
|
5323. [bug] Fix a bug in DNSSEC trust anchor verification.
|
||||||
|
[GL !2609]
|
||||||
|
|
||||||
|
5322. [placeholder]
|
||||||
|
|
||||||
|
5321. [bug] Obtain write lock before updating version->records
|
||||||
|
and version->bytes. [GL #1341]
|
||||||
|
|
||||||
|
5320. [cleanup] Silence TSAN on header->count. [GL #1344]
|
||||||
|
|
||||||
|
--- 9.15.6 released ---
|
||||||
|
|
||||||
|
5319. [func] Trust anchors can now be configured using DS
|
||||||
|
format to represent a key digest, by using the
|
||||||
|
new "initial-ds" or "static-ds" keywords in
|
||||||
|
the "dnssec-keys" statement.
|
||||||
|
|
||||||
|
Note: DNSKEY-format and DS-format trust anchors
|
||||||
|
cannot both be used for the same domain name.
|
||||||
|
[GL #622]
|
||||||
|
|
||||||
|
5318. [cleanup] The DNSSEC validation code has been refactored
|
||||||
|
for clarity and to reduce code duplication.
|
||||||
|
[GL #622]
|
||||||
|
|
||||||
|
5317. [func] A new asynchronous network communications system
|
||||||
|
based on libuv is now used for listening for
|
||||||
|
incoming requests and responding to them. (The
|
||||||
|
old isc_socket API remains in use for sending
|
||||||
|
iterative queries and processing responses; this
|
||||||
|
will be changed too in a later release.)
|
||||||
|
|
||||||
|
This change will make it easier to improve
|
||||||
|
performance and implement new protocol layers
|
||||||
|
(e.g., DNS over TLS) in the future. [GL #29]
|
||||||
|
|
||||||
|
5316. [func] A new "dnssec-policy" option has been added to
|
||||||
|
named.conf to implement a key and signing policy
|
||||||
|
(KASP) for zones. When this option is in use,
|
||||||
|
named can generate new keys as needed and
|
||||||
|
automatically roll both ZSK and KSK keys. (Note
|
||||||
|
that the syntax for this statement differs from
|
||||||
|
the dnssec policy used by dnssec-keymgr.)
|
||||||
|
|
||||||
|
See the ARM for configuration details. [GL #1134]
|
||||||
|
|
||||||
|
5315. [bug] Apply the inital RRSIG expiration spread fixed
|
||||||
|
to all dynamically created records in the zone
|
||||||
|
including NSEC3. Also fix the signature clusters
|
||||||
|
when the server has been offline for prolonged
|
||||||
|
period of times. [GL #1256]
|
||||||
|
|
||||||
|
5314. [func] Added a new statistics variable "tcp-highwater"
|
||||||
|
that reports the maximum number of simultaneous TCP
|
||||||
|
clients BIND has handled while running. [GL #1206]
|
||||||
|
|
||||||
|
5313. [bug] The default GeoIP2 database location did not match
|
||||||
|
the ARM. 'named -V' now reports the default
|
||||||
|
location. [GL #1301]
|
||||||
|
|
||||||
|
5312. [bug] Do not flush the cache for `rndc validation status`.
|
||||||
|
Thanks to Tony Finch. [GL !2462]
|
||||||
|
|
||||||
|
5311. [cleanup] Include all views in output of `rndc validation status`.
|
||||||
|
Thanks to Tony Finch. [GL !2461]
|
||||||
|
|
||||||
|
5310. [bug] TCP failures were affecting EDNS statistics. [GL #1059]
|
||||||
|
|
||||||
|
5309. [placeholder]
|
||||||
|
|
||||||
|
5308. [bug] Don't log DNS_R_UNCHANGED from sync_secure_journal()
|
||||||
|
at ERROR level in receive_secure_serial(). [GL #1288]
|
||||||
|
|
||||||
|
5307. [bug] Fix hang when named-compilezone output is sent to pipe.
|
||||||
|
Thanks to Tony Finch. [GL !2481]
|
||||||
|
|
||||||
|
5306. [security] Set a limit on number of simultaneous pipelined TCP
|
||||||
|
queries. (CVE-2019-6477) [GL #1264]
|
||||||
|
|
||||||
|
5305. [bug] NSEC Aggressive Cache ("synth-from-dnssec") has been
|
||||||
|
disabled by default because it was found to have
|
||||||
|
a significant performance impact on the recursive
|
||||||
|
service. [GL #1265]
|
||||||
|
|
||||||
|
5304. [bug] "dnskey-sig-validity 0;" was not being accepted.
|
||||||
|
[GL #876]
|
||||||
|
|
||||||
|
5303. [placeholder]
|
||||||
|
|
||||||
5302. [bug] Fix checking that "dnstap-output" is defined when
|
5302. [bug] Fix checking that "dnstap-output" is defined when
|
||||||
"dnstap" is specified" in a view. [GL #1281]
|
"dnstap" is specified in a view. [GL #1281]
|
||||||
|
|
||||||
5301. [bug] Detect partial prefixes / incomplete IPv4 address in
|
5301. [bug] Detect partial prefixes / incomplete IPv4 address in
|
||||||
acls. [GL #1143]
|
acls. [GL #1143]
|
||||||
|
|||||||
@@ -3,11 +3,18 @@ PLATFORMS
|
|||||||
Supported platforms
|
Supported platforms
|
||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
In general, this version of BIND will build and run on any POSIX-compliant
|
||||||
system with a C99-compliant C compiler, BSD-style sockets with
|
system with a C11-compliant C compiler, BSD-style sockets with
|
||||||
RFC-compliant IPv6 support, POSIX-compliant threads, and the OpenSSL
|
RFC-compliant IPv6 support, POSIX-compliant threads, the libuv
|
||||||
cryptography library. Atomic operations support from the compiler is
|
asynchronous I/O library, and the OpenSSL cryptography library. Atomic
|
||||||
needed, either in the form of builtin operations, C11 atomics or the
|
operations support from the compiler is needed, either in the form of
|
||||||
Interlocked family of functions on Windows.
|
builtin operations, C11 atomics, or the Interlocked family of functions on
|
||||||
|
Windows.
|
||||||
|
|
||||||
|
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x).
|
||||||
|
For some of the older systems listed below, you will have to install
|
||||||
|
updated libuv package from sources such as EPEL, PPA and other native
|
||||||
|
sources for updated packages. The other option is to install libuv from
|
||||||
|
sources.
|
||||||
|
|
||||||
ISC regularly tests BIND on many operating systems and architectures, but
|
ISC regularly tests BIND on many operating systems and architectures, but
|
||||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||||
@@ -15,15 +22,16 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
Regularly tested platforms
|
Regularly tested platforms
|
||||||
|
|
||||||
As of Feb 2019, BIND 9.15 is fully supported and regularly tested on the
|
As of Dec 2019, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 8, 9, 10
|
* Debian 9, 10
|
||||||
* Ubuntu 16.04, 18.04
|
* Ubuntu LTS 16.04, 18.04
|
||||||
* Fedora 28, 29
|
* Fedora 30
|
||||||
* Red Hat Enterprise Linux / CentOS 6, 7
|
* Red Hat Enterprise Linux / CentOS 7, 8
|
||||||
* FreeBSD 11.x
|
* FreeBSD 11.3, 12.0
|
||||||
* OpenBSD 6.2, 6.3
|
* OpenBSD 6.5
|
||||||
|
* Alpine Linux
|
||||||
|
|
||||||
The amd64, i386, armhf and arm64 CPU architectures are all fully
|
The amd64, i386, armhf and arm64 CPU architectures are all fully
|
||||||
supported.
|
supported.
|
||||||
@@ -40,17 +48,30 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
* Windows 10 / x64
|
* Windows 10 / x64
|
||||||
* macOS 10.12+
|
* macOS 10.12+
|
||||||
* Solaris 11
|
* Solaris 11
|
||||||
* FreeBSD 10.x, 12.0+
|
|
||||||
* OpenBSD 6.4+
|
|
||||||
* NetBSD
|
* NetBSD
|
||||||
* Other Linux distributions still supported by their vendors, such as:
|
* Other Linux distributions still supported by their vendors, such as:
|
||||||
+ Ubuntu 14.04, 18.10+
|
+ Ubuntu 19.04+
|
||||||
+ Gentoo
|
+ Gentoo
|
||||||
+ Arch Linux
|
+ Arch Linux
|
||||||
+ Alpine Linux
|
|
||||||
* OpenWRT/LEDE 17.01+
|
* OpenWRT/LEDE 17.01+
|
||||||
* Other CPU architectures (mips, mipsel, sparc, ...)
|
* Other CPU architectures (mips, mipsel, sparc, ...)
|
||||||
|
|
||||||
|
Community maintained
|
||||||
|
|
||||||
|
These systems may not all have easily available the required dependencies
|
||||||
|
for building BIND although it will be possible in many cases to compile
|
||||||
|
those directly from source. The community and interested parties may wish
|
||||||
|
to help with maintenance and we welcome patch contributions, although we
|
||||||
|
cannot guarantee that we will accept them. All contributions will be
|
||||||
|
assessed against the risk of adverse effect on officially supported
|
||||||
|
platforms.
|
||||||
|
|
||||||
|
* Platforms past or close to their respective EOL dates, such as:
|
||||||
|
+ Ubuntu 14.04, 18.10
|
||||||
|
+ CentOS 6
|
||||||
|
+ Debian Jessie
|
||||||
|
+ FreeBSD 10.x
|
||||||
|
|
||||||
Unsupported platforms
|
Unsupported platforms
|
||||||
|
|
||||||
These are platforms on which BIND 9.15 is known not to build or run:
|
These are platforms on which BIND 9.15 is known not to build or run:
|
||||||
@@ -63,13 +84,6 @@ These are platforms on which BIND 9.15 is known not to build or run:
|
|||||||
* Platforms that don't support atomic operations (via compiler or
|
* Platforms that don't support atomic operations (via compiler or
|
||||||
library)
|
library)
|
||||||
* Linux without NPTL (Native POSIX Thread Library)
|
* Linux without NPTL (Native POSIX Thread Library)
|
||||||
|
* Platforms where libuv cannot be compiled
|
||||||
|
|
||||||
Platform quirks
|
Platform quirks
|
||||||
|
|
||||||
NetBSD 6 i386
|
|
||||||
|
|
||||||
The i386 build of NetBSD requires the libatomic library, available from
|
|
||||||
the gcc5-libs package. Because this library is in a non-standard path, its
|
|
||||||
location must be specified in the configure command line:
|
|
||||||
|
|
||||||
LDFLAGS="-L/usr/pkg/gcc5/i486--netbsdelf/lib/ -Wl,-R/usr/pkg/gcc5/i486--netbsdelf/lib/" ./configure
|
|
||||||
|
|||||||
+35
-26
@@ -11,11 +11,16 @@
|
|||||||
## Supported platforms
|
## Supported platforms
|
||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
In general, this version of BIND will build and run on any POSIX-compliant
|
||||||
system with a C99-compliant C compiler, BSD-style sockets with RFC-compliant
|
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
||||||
IPv6 support, POSIX-compliant threads, and the OpenSSL cryptography library.
|
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
|
||||||
Atomic operations support from the compiler is needed, either in the form of
|
and the OpenSSL cryptography library. Atomic operations support from the
|
||||||
builtin operations, C11 atomics or the Interlocked family of functions on
|
compiler is needed, either in the form of builtin operations, C11 atomics,
|
||||||
Windows.
|
or the `Interlocked` family of functions on Windows.
|
||||||
|
|
||||||
|
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x). For
|
||||||
|
some of the older systems listed below, you will have to install updated libuv
|
||||||
|
package from sources such as EPEL, PPA and other native sources for updated
|
||||||
|
packages. The other option is to install libuv from sources.
|
||||||
|
|
||||||
ISC regularly tests BIND on many operating systems and architectures, but
|
ISC regularly tests BIND on many operating systems and architectures, but
|
||||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||||
@@ -23,15 +28,16 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
### Regularly tested platforms
|
### Regularly tested platforms
|
||||||
|
|
||||||
As of Feb 2019, BIND 9.15 is fully supported and regularly tested on the
|
As of Dec 2019, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 8, 9, 10
|
* Debian 9, 10
|
||||||
* Ubuntu 16.04, 18.04
|
* Ubuntu LTS 16.04, 18.04
|
||||||
* Fedora 28, 29
|
* Fedora 30
|
||||||
* Red Hat Enterprise Linux / CentOS 6, 7
|
* Red Hat Enterprise Linux / CentOS 7, 8
|
||||||
* FreeBSD 11.x
|
* FreeBSD 11.3, 12.0
|
||||||
* OpenBSD 6.2, 6.3
|
* OpenBSD 6.5
|
||||||
|
* Alpine Linux
|
||||||
|
|
||||||
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
||||||
|
|
||||||
@@ -47,17 +53,29 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
* Windows 10 / x64
|
* Windows 10 / x64
|
||||||
* macOS 10.12+
|
* macOS 10.12+
|
||||||
* Solaris 11
|
* Solaris 11
|
||||||
* FreeBSD 10.x, 12.0+
|
|
||||||
* OpenBSD 6.4+
|
|
||||||
* NetBSD
|
* NetBSD
|
||||||
* Other Linux distributions still supported by their vendors, such as:
|
* Other Linux distributions still supported by their vendors, such as:
|
||||||
* Ubuntu 14.04, 18.10+
|
* Ubuntu 19.04+
|
||||||
* Gentoo
|
* Gentoo
|
||||||
* Arch Linux
|
* Arch Linux
|
||||||
* Alpine Linux
|
|
||||||
* OpenWRT/LEDE 17.01+
|
* OpenWRT/LEDE 17.01+
|
||||||
* Other CPU architectures (mips, mipsel, sparc, ...)
|
* Other CPU architectures (mips, mipsel, sparc, ...)
|
||||||
|
|
||||||
|
### Community maintained
|
||||||
|
|
||||||
|
These systems may not all have easily available the required dependencies for
|
||||||
|
building BIND although it will be possible in many cases to compile those
|
||||||
|
directly from source. The community and interested parties may wish to help with
|
||||||
|
maintenance and we welcome patch contributions, although we cannot guarantee
|
||||||
|
that we will accept them. All contributions will be assessed against the risk
|
||||||
|
of adverse effect on officially supported platforms.
|
||||||
|
|
||||||
|
* Platforms past or close to their respective EOL dates, such as:
|
||||||
|
* Ubuntu 14.04, 18.10
|
||||||
|
* CentOS 6
|
||||||
|
* Debian Jessie
|
||||||
|
* FreeBSD 10.x
|
||||||
|
|
||||||
## Unsupported platforms
|
## Unsupported platforms
|
||||||
|
|
||||||
These are platforms on which BIND 9.15 is known *not* to build or run:
|
These are platforms on which BIND 9.15 is known *not* to build or run:
|
||||||
@@ -69,15 +87,6 @@ These are platforms on which BIND 9.15 is known *not* to build or run:
|
|||||||
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
||||||
* Platforms that don't support atomic operations (via compiler or library)
|
* Platforms that don't support atomic operations (via compiler or library)
|
||||||
* Linux without NPTL (Native POSIX Thread Library)
|
* Linux without NPTL (Native POSIX Thread Library)
|
||||||
|
* Platforms where libuv cannot be compiled
|
||||||
|
|
||||||
## Platform quirks
|
## Platform quirks
|
||||||
|
|
||||||
### NetBSD 6 i386
|
|
||||||
|
|
||||||
The i386 build of NetBSD requires the `libatomic` library, available from
|
|
||||||
the `gcc5-libs` package. Because this library is in a non-standard path,
|
|
||||||
its location must be specified in the `configure` command line:
|
|
||||||
|
|
||||||
```
|
|
||||||
LDFLAGS="-L/usr/pkg/gcc5/i486--netbsdelf/lib/ -Wl,-R/usr/pkg/gcc5/i486--netbsdelf/lib/" ./configure
|
|
||||||
```
|
|
||||||
|
|||||||
@@ -48,8 +48,8 @@ the file HISTORY.
|
|||||||
For a detailed list of changes made throughout the history of BIND 9, see
|
For a detailed list of changes made throughout the history of BIND 9, see
|
||||||
the file CHANGES. See below for details on the CHANGES file format.
|
the file CHANGES. See below for details on the CHANGES file format.
|
||||||
|
|
||||||
For up-to-date release notes and errata, see http://www.isc.org/software/
|
For up-to-date versions and release notes, see https://www.isc.org/
|
||||||
bind9/releasenotes
|
download/.
|
||||||
|
|
||||||
For information about supported platforms, see PLATFORMS.
|
For information about supported platforms, see PLATFORMS.
|
||||||
|
|
||||||
@@ -111,25 +111,30 @@ BIND 9.15 features
|
|||||||
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
||||||
of changes from BIND 9.14 and earlier releases. New features include:
|
of changes from BIND 9.14 and earlier releases. New features include:
|
||||||
|
|
||||||
|
* New "dnssec-policy" statement to configure a key and signing policy
|
||||||
|
for zones, enabling automatic key regeneration and rollover.
|
||||||
|
* New new network manager based on libuv.
|
||||||
* Support for the new GeoIP2 geolocation API
|
* Support for the new GeoIP2 geolocation API
|
||||||
* Improved DNSSEC key configuration using dnssec-keys
|
* Improved DNSSEC trust anchor configuration using dnssec-keys,
|
||||||
|
permitting configuration of trust anchors in DS as well as DNSKEY
|
||||||
|
format.
|
||||||
* YAML output for dig, mdig, and delv.
|
* YAML output for dig, mdig, and delv.
|
||||||
|
|
||||||
Building BIND
|
Building BIND
|
||||||
|
|
||||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||||
basic POSIX support, and a 64-bit integer type. Successful builds have
|
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||||
been observed on many versions of Linux and UNIX, including RHEL/CentOS,
|
libuv asynchronous I/O library, and a cryptography provider library such
|
||||||
Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD,
|
as OpenSSL or a hardware service module supporting PKCS#11. On Linux, BIND
|
||||||
NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and
|
requires the libcap library to set process privileges, though this
|
||||||
OpenWRT.
|
requirement can be overridden by disabling capability support at compile
|
||||||
|
time. See Compile-time options below for details on other libraries that
|
||||||
|
may be required to support optional features.
|
||||||
|
|
||||||
BIND requires a cryptography provider library such as OpenSSL or a
|
Successful builds have been observed on many versions of Linux and UNIX,
|
||||||
hardware service module supporting PKCS#11. On Linux, BIND requires the
|
including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware,
|
||||||
libcap library to set process privileges, though this requirement can be
|
Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE,
|
||||||
overridden by disabling capability support at compile time. See
|
HP-UX, and OpenWRT.
|
||||||
Compile-time options below for details on other libraries that may be
|
|
||||||
required to support optional features.
|
|
||||||
|
|
||||||
BIND is also available for Windows Server 2008 and higher. See win32utils/
|
BIND is also available for Windows Server 2008 and higher. See win32utils/
|
||||||
build.txt for details on building for Windows systems.
|
build.txt for details on building for Windows systems.
|
||||||
|
|||||||
@@ -57,8 +57,8 @@ For a detailed list of changes made throughout the history of BIND 9, see
|
|||||||
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
||||||
CHANGES file format.
|
CHANGES file format.
|
||||||
|
|
||||||
For up-to-date release notes and errata, see
|
For up-to-date versions and release notes, see
|
||||||
[http://www.isc.org/software/bind9/releasenotes](http://www.isc.org/software/bind9/releasenotes)
|
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||||
|
|
||||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
||||||
|
|
||||||
@@ -127,24 +127,31 @@ BIND 9.15 is the newest development branch of BIND 9. It includes a
|
|||||||
number of changes from BIND 9.14 and earlier releases. New features
|
number of changes from BIND 9.14 and earlier releases. New features
|
||||||
include:
|
include:
|
||||||
|
|
||||||
|
* New "dnssec-policy" statement to configure a key and signing policy
|
||||||
|
for zones, enabling automatic key regeneration and rollover.
|
||||||
|
* New new network manager based on libuv.
|
||||||
* Support for the new GeoIP2 geolocation API
|
* Support for the new GeoIP2 geolocation API
|
||||||
* Improved DNSSEC key configuration using `dnssec-keys`
|
* Improved DNSSEC trust anchor configuration using `dnssec-keys`,
|
||||||
|
permitting configuration of trust anchors in DS as well as
|
||||||
|
DNSKEY format.
|
||||||
* YAML output for `dig`, `mdig`, and `delv`.
|
* YAML output for `dig`, `mdig`, and `delv`.
|
||||||
|
|
||||||
### <a name="build"/> Building BIND
|
### <a name="build"/> Building BIND
|
||||||
|
|
||||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||||
basic POSIX support, and a 64-bit integer type. Successful builds have been
|
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||||
observed on many versions of Linux and UNIX, including RHEL/CentOS, Fedora,
|
`libuv` asynchronous I/O library, and a cryptography provider library
|
||||||
Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD, NetBSD,
|
such as OpenSSL or a hardware service module supporting PKCS#11. On
|
||||||
OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
Linux, BIND requires the `libcap` library to set process privileges,
|
||||||
|
though this requirement can be overridden by disabling capability
|
||||||
|
support at compile time. See [Compile-time options](#opts) below
|
||||||
|
for details on other libraries that may be required to support
|
||||||
|
optional features.
|
||||||
|
|
||||||
BIND requires a cryptography provider library such as OpenSSL or a
|
Successful builds have been observed on many versions of Linux and
|
||||||
hardware service module supporting PKCS#11. On Linux, BIND requires
|
UNIX, including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
||||||
the `libcap` library to set process privileges, though this requirement
|
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris,
|
||||||
can be overridden by disabling capability support at compile time.
|
OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
||||||
See [Compile-time options](#opts) below for details on other libraries
|
|
||||||
that may be required to support optional features.
|
|
||||||
|
|
||||||
BIND is also available for Windows Server 2008 and higher. See
|
BIND is also available for Windows Server 2008 and higher. See
|
||||||
`win32utils/build.txt` for details on building for Windows
|
`win32utils/build.txt` for details on building for Windows
|
||||||
@@ -184,9 +191,11 @@ or if you have Xcode already installed you can run `xcode-select --install`.
|
|||||||
|
|
||||||
Portions of BIND that are written in Python, including
|
Portions of BIND that are written in Python, including
|
||||||
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||||
system tests, require the `argparse` and `ply` modules to be available.
|
system tests, require the `argparse`, `ply` and `distutils.core` modules
|
||||||
|
to be available.
|
||||||
`argparse` is a standard module as of Python 2.7 and Python 3.2.
|
`argparse` is a standard module as of Python 2.7 and Python 3.2.
|
||||||
`ply` is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
`ply` is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||||
|
`distutils.core` is required for installation.
|
||||||
|
|
||||||
#### <a name="opts"/> Compile-time options
|
#### <a name="opts"/> Compile-time options
|
||||||
|
|
||||||
|
|||||||
@@ -716,7 +716,7 @@ dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
|||||||
FILE *output = stdout;
|
FILE *output = stdout;
|
||||||
const char *flags;
|
const char *flags;
|
||||||
|
|
||||||
flags = (fileformat == dns_masterformat_text) ? "w+" : "wb+";
|
flags = (fileformat == dns_masterformat_text) ? "w" : "wb";
|
||||||
|
|
||||||
if (debug) {
|
if (debug) {
|
||||||
if (filename != NULL && strcmp(filename, "-") != 0)
|
if (filename != NULL && strcmp(filename, "-") != 0)
|
||||||
|
|||||||
@@ -421,7 +421,7 @@ configure_zone(const char *vclass, const char *view,
|
|||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "max-zone-ttl", &obj)) {
|
if (get_maps(maps, "max-zone-ttl", &obj)) {
|
||||||
maxttl = cfg_obj_asuint32(obj);
|
maxttl = cfg_obj_asduration(obj);
|
||||||
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+142
-58
@@ -33,8 +33,10 @@
|
|||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
|
#include <isc/md.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#ifdef WIN32
|
#ifdef WIN32
|
||||||
#include <isc/ntpaths.h>
|
#include <isc/ntpaths.h>
|
||||||
@@ -158,43 +160,44 @@ usage(void) {
|
|||||||
" q-class is one of (in,hs,ch,...) [default: in]\n"
|
" q-class is one of (in,hs,ch,...) [default: in]\n"
|
||||||
" q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n"
|
" q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n"
|
||||||
" q-opt is one of:\n"
|
" q-opt is one of:\n"
|
||||||
" -x dot-notation (shortcut for reverse lookups)\n"
|
" -4 (use IPv4 query transport only)\n"
|
||||||
" -d level (set debugging level)\n"
|
" -6 (use IPv6 query transport only)\n"
|
||||||
" -a anchor-file (specify root trust anchor)\n"
|
" -a anchor-file (specify root trust anchor)\n"
|
||||||
" -b address[#port] (bind to source address/port)\n"
|
" -b address[#port] (bind to source address/port)\n"
|
||||||
|
" -c class (option included for compatibility;\n"
|
||||||
|
" -d level (set debugging level)\n"
|
||||||
|
" -h (print help and exit)\n"
|
||||||
|
" -i (disable DNSSEC validation)\n"
|
||||||
|
" -m (enable memory usage debugging)\n"
|
||||||
" -p port (specify port number)\n"
|
" -p port (specify port number)\n"
|
||||||
" -q name (specify query name)\n"
|
" -q name (specify query name)\n"
|
||||||
" -t type (specify query type)\n"
|
" -t type (specify query type)\n"
|
||||||
" -c class (option included for compatibility;\n"
|
|
||||||
" only IN is supported)\n"
|
" only IN is supported)\n"
|
||||||
" -4 (use IPv4 query transport only)\n"
|
" -v (print version and exit)\n"
|
||||||
" -6 (use IPv6 query transport only)\n"
|
" -x dot-notation (shortcut for reverse lookups)\n"
|
||||||
" -i (disable DNSSEC validation)\n"
|
|
||||||
" -m (enable memory usage debugging)\n"
|
|
||||||
" d-opt is of the form +keyword[=value], where keyword is:\n"
|
" d-opt is of the form +keyword[=value], where keyword is:\n"
|
||||||
" +[no]all (Set or clear all display flags)\n"
|
" +[no]all (Set or clear all display flags)\n"
|
||||||
" +[no]class (Control display of class)\n"
|
" +[no]class (Control display of class)\n"
|
||||||
|
" +[no]comments (Control display of comment lines)\n"
|
||||||
" +[no]crypto (Control display of cryptographic\n"
|
" +[no]crypto (Control display of cryptographic\n"
|
||||||
" fields in records)\n"
|
" fields in records)\n"
|
||||||
|
" +[no]dlv (Obsolete)\n"
|
||||||
|
" +[no]dnssec (Display DNSSEC records)\n"
|
||||||
|
" +[no]mtrace (Trace messages received)\n"
|
||||||
" +[no]multiline (Print records in an expanded format)\n"
|
" +[no]multiline (Print records in an expanded format)\n"
|
||||||
" +[no]comments (Control display of comment lines)\n"
|
" +[no]root (DNSSEC validation trust anchor)\n"
|
||||||
" +[no]rrcomments (Control display of per-record "
|
" +[no]rrcomments (Control display of per-record "
|
||||||
"comments)\n"
|
"comments)\n"
|
||||||
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
" +[no]rtrace (Trace resolver fetches)\n"
|
||||||
"\"unknown\" format)\n"
|
|
||||||
" +[no]short (Short form answer)\n"
|
" +[no]short (Short form answer)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||||
" +[no]tcp (TCP mode)\n"
|
" +[no]tcp (TCP mode)\n"
|
||||||
" +[no]ttl (Control display of ttls in records)\n"
|
" +[no]ttl (Control display of ttls in records)\n"
|
||||||
" +[no]trust (Control display of trust level)\n"
|
" +[no]trust (Control display of trust level)\n"
|
||||||
" +[no]rtrace (Trace resolver fetches)\n"
|
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
||||||
" +[no]mtrace (Trace messages received)\n"
|
"\"unknown\" format)\n"
|
||||||
" +[no]vtrace (Trace validation process)\n"
|
" +[no]vtrace (Trace validation process)\n"
|
||||||
" +[no]dlv (Obsolete)\n"
|
" +[no]yaml (Present the results as YAML)\n",
|
||||||
" +[no]root (DNSSEC validation trust anchor)\n"
|
|
||||||
" +[no]dnssec (Display DNSSEC records)\n"
|
|
||||||
" -h (print help and exit)\n"
|
|
||||||
" -v (print version and exit)\n",
|
|
||||||
stderr);
|
stderr);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
@@ -495,14 +498,17 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
|||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
dns_indent_t indent = { " ", 2 };
|
||||||
if (!yaml && (rdataset->attributes &
|
if (!yaml && (rdataset->attributes &
|
||||||
DNS_RDATASETATTR_NEGATIVE) != 0)
|
DNS_RDATASETATTR_NEGATIVE) != 0)
|
||||||
{
|
{
|
||||||
isc_buffer_putstr(&target, "; ");
|
isc_buffer_putstr(&target, "; ");
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_master_rdatasettotext(owner, rdataset,
|
result = dns_master_rdatasettotext(owner, rdataset,
|
||||||
style, &target);
|
style,
|
||||||
|
yaml ? &indent :
|
||||||
|
NULL,
|
||||||
|
&target);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
@@ -534,8 +540,6 @@ setup_style(dns_master_style_t **stylep) {
|
|||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
styleflags |= DNS_STYLEFLAG_YAML;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
dns_master_indentstr = " ";
|
|
||||||
dns_master_indent = 2;
|
|
||||||
} else {
|
} else {
|
||||||
if (showcomments) {
|
if (showcomments) {
|
||||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||||
@@ -608,11 +612,12 @@ convert_name(dns_fixedname_t *fn, dns_name_t **name, const char *text) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||||
dns_rdata_dnskey_t keystruct;
|
dns_rdata_dnskey_t dnskey;
|
||||||
uint32_t flags, proto, alg;
|
dns_rdata_ds_t ds;
|
||||||
const char *keystr, *keynamestr;
|
uint32_t n1, n2, n3;
|
||||||
unsigned char keydata[4096];
|
const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL;
|
||||||
isc_buffer_t keydatabuf;
|
unsigned char data[4096];
|
||||||
|
isc_buffer_t databuf;
|
||||||
unsigned char rrdata[4096];
|
unsigned char rrdata[4096];
|
||||||
isc_buffer_t rrdatabuf;
|
isc_buffer_t rrdatabuf;
|
||||||
isc_region_t r;
|
isc_region_t r;
|
||||||
@@ -620,6 +625,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
dns_name_t *keyname;
|
dns_name_t *keyname;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool match_root = false;
|
bool match_root = false;
|
||||||
|
enum {
|
||||||
|
INITIAL_KEY,
|
||||||
|
STATIC_KEY,
|
||||||
|
INITIAL_DS,
|
||||||
|
STATIC_DS,
|
||||||
|
TRUSTED
|
||||||
|
} anchortype;
|
||||||
|
|
||||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||||
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
||||||
@@ -642,46 +654,118 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
|
|
||||||
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
|
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
|
||||||
|
|
||||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
/* if DNSKEY, flags; if DS, key tag */
|
||||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
|
||||||
alg = cfg_obj_asuint32(cfg_tuple_get(key, "algorithm"));
|
|
||||||
|
|
||||||
keystruct.common.rdclass = dns_rdataclass_in;
|
/* if DNSKEY, protocol; if DS, algorithm */
|
||||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
|
||||||
/*
|
|
||||||
* The key data in keystruct is not dynamically allocated.
|
|
||||||
*/
|
|
||||||
keystruct.mctx = NULL;
|
|
||||||
|
|
||||||
ISC_LINK_INIT(&keystruct.common, link);
|
/* if DNSKEY, algorithm; if DS, digest type */
|
||||||
|
n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
|
||||||
|
|
||||||
if (flags > 0xffff)
|
/* What type of trust anchor is this? */
|
||||||
CHECK(ISC_R_RANGE);
|
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||||
if (proto > 0xff)
|
if (strcasecmp(atstr, "static-key") == 0) {
|
||||||
CHECK(ISC_R_RANGE);
|
anchortype = STATIC_KEY;
|
||||||
if (alg > 0xff)
|
} else if (strcasecmp(atstr, "static-ds") == 0) {
|
||||||
CHECK(ISC_R_RANGE);
|
anchortype = STATIC_DS;
|
||||||
|
} else if (strcasecmp(atstr, "initial-key") == 0) {
|
||||||
|
anchortype = INITIAL_KEY;
|
||||||
|
} else if (strcasecmp(atstr, "initial-ds") == 0) {
|
||||||
|
anchortype = INITIAL_DS;
|
||||||
|
} else {
|
||||||
|
delv_log(ISC_LOG_ERROR,
|
||||||
|
"key '%s': invalid initialization method '%s'",
|
||||||
|
keynamestr, atstr);
|
||||||
|
result = ISC_R_FAILURE;
|
||||||
|
goto cleanup;
|
||||||
|
}
|
||||||
|
|
||||||
keystruct.flags = (uint16_t)flags;
|
isc_buffer_init(&databuf, data, sizeof(data));
|
||||||
keystruct.protocol = (uint8_t)proto;
|
|
||||||
keystruct.algorithm = (uint8_t)alg;
|
|
||||||
|
|
||||||
isc_buffer_init(&keydatabuf, keydata, sizeof(keydata));
|
|
||||||
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
||||||
|
|
||||||
keystr = cfg_obj_asstring(cfg_tuple_get(key, "key"));
|
if (n1 > 0xffff) {
|
||||||
CHECK(isc_base64_decodestring(keystr, &keydatabuf));
|
CHECK(ISC_R_RANGE);
|
||||||
isc_buffer_usedregion(&keydatabuf, &r);
|
}
|
||||||
keystruct.datalen = r.length;
|
if (n2 > 0xff) {
|
||||||
keystruct.data = r.base;
|
CHECK(ISC_R_RANGE);
|
||||||
|
}
|
||||||
|
if (n3 > 0xff) {
|
||||||
|
CHECK(ISC_R_RANGE);
|
||||||
|
}
|
||||||
|
|
||||||
CHECK(dns_rdata_fromstruct(NULL,
|
switch (anchortype) {
|
||||||
keystruct.common.rdclass,
|
case STATIC_KEY:
|
||||||
keystruct.common.rdtype,
|
case INITIAL_KEY:
|
||||||
&keystruct, &rrdatabuf));
|
case TRUSTED:
|
||||||
|
dnskey.common.rdclass = dns_rdataclass_in;
|
||||||
|
dnskey.common.rdtype = dns_rdatatype_dnskey;
|
||||||
|
dnskey.mctx = NULL;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(&dnskey.common, link);
|
||||||
|
|
||||||
|
dnskey.flags = (uint16_t)n1;
|
||||||
|
dnskey.protocol = (uint8_t)n2;
|
||||||
|
dnskey.algorithm = (uint8_t)n3;
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_base64_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
dnskey.datalen = r.length;
|
||||||
|
dnskey.data = r.base;
|
||||||
|
|
||||||
|
CHECK(dns_rdata_fromstruct(NULL, dnskey.common.rdclass,
|
||||||
|
dnskey.common.rdtype,
|
||||||
|
&dnskey, &rrdatabuf));
|
||||||
|
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||||
|
dns_rdatatype_dnskey,
|
||||||
|
keyname, &rrdatabuf));
|
||||||
|
break;
|
||||||
|
case INITIAL_DS:
|
||||||
|
case STATIC_DS:
|
||||||
|
ds.common.rdclass = dns_rdataclass_in;
|
||||||
|
ds.common.rdtype = dns_rdatatype_ds;
|
||||||
|
ds.mctx = NULL;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(&ds.common, link);
|
||||||
|
|
||||||
|
ds.key_tag = (uint16_t)n1;
|
||||||
|
ds.algorithm = (uint8_t)n2;
|
||||||
|
ds.digest_type = (uint8_t)n3;
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_hex_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
|
||||||
|
switch (ds.digest_type) {
|
||||||
|
case DNS_DSDIGEST_SHA1:
|
||||||
|
if (r.length != ISC_SHA1_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA256:
|
||||||
|
if (r.length != ISC_SHA256_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA384:
|
||||||
|
if (r.length != ISC_SHA384_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
ds.length = r.length;
|
||||||
|
ds.digest = r.base;
|
||||||
|
|
||||||
|
CHECK(dns_rdata_fromstruct(NULL, ds.common.rdclass,
|
||||||
|
ds.common.rdtype,
|
||||||
|
&ds, &rrdatabuf));
|
||||||
|
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||||
|
dns_rdatatype_ds,
|
||||||
|
keyname, &rrdatabuf));
|
||||||
|
};
|
||||||
|
|
||||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
|
||||||
keyname, &rrdatabuf));
|
|
||||||
num_keys++;
|
num_keys++;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
|
|||||||
+3
-2
@@ -239,6 +239,7 @@ help(void) {
|
|||||||
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
||||||
"format)\n"
|
"format)\n"
|
||||||
" +[no]vc (TCP mode (+[no]tcp))\n"
|
" +[no]vc (TCP mode (+[no]tcp))\n"
|
||||||
|
" +[no]yaml (Present the results as YAML)\n"
|
||||||
" +[no]zflag (Set Z flag in query)\n"
|
" +[no]zflag (Set Z flag in query)\n"
|
||||||
" global d-opts and servers (before host name) affect all queries.\n"
|
" global d-opts and servers (before host name) affect all queries.\n"
|
||||||
" local d-opts and servers (after host name) affect only that lookup.\n"
|
" local d-opts and servers (after host name) affect only that lookup.\n"
|
||||||
@@ -486,8 +487,8 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
|||||||
|
|
||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
dns_master_indentstr = " ";
|
msg->indent.string = " ";
|
||||||
dns_master_indent = 3;
|
msg->indent.count = 3;
|
||||||
styleflags |= DNS_STYLEFLAG_YAML;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
} else {
|
} else {
|
||||||
if (query->lookup->comments) {
|
if (query->lookup->comments) {
|
||||||
|
|||||||
+1
-1
@@ -1379,7 +1379,7 @@ setup_libs(void) {
|
|||||||
|
|
||||||
isc_log_setdebuglevel(lctx, 0);
|
isc_log_setdebuglevel(lctx, 0);
|
||||||
|
|
||||||
result = isc_taskmgr_create(mctx, 1, 0, &taskmgr);
|
result = isc_taskmgr_create(mctx, 1, 0, NULL, &taskmgr);
|
||||||
check_result(result, "isc_taskmgr_create");
|
check_result(result, "isc_taskmgr_create");
|
||||||
|
|
||||||
result = isc_task_create(taskmgr, 0, &global_task);
|
result = isc_task_create(taskmgr, 0, &global_task);
|
||||||
|
|||||||
@@ -15,24 +15,26 @@ VERSION=@BIND9_VERSION@
|
|||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
${OPENSSL_CFLAGS}
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\"
|
CDEFINES = -DVERSION=\"${VERSION}\" -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
|
|
||||||
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
|
||||||
DEPLIBS = ${DNSDEPLIBS} ${ISCDEPLIBS}
|
DEPLIBS = ${DNSDEPLIBS} ${ISCCFGDEPLIBS} ${ISCDEPLIBS}
|
||||||
|
|
||||||
LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
LIBS = ${DNSLIBS} ${ISCCFGLIBS} ${ISCLIBS} @LIBS@
|
||||||
|
|
||||||
NOSYMLIBS = ${DNSLIBS} ${ISCNOSYMLIBS} @LIBS@
|
NOSYMLIBS = ${DNSLIBS} ${ISCCFGLIBS} ${ISCNOSYMLIBS} @LIBS@
|
||||||
|
|
||||||
# Alphabetically
|
# Alphabetically
|
||||||
TARGETS = dnssec-cds@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
TARGETS = dnssec-cds@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
||||||
@@ -48,7 +50,7 @@ SRCS = dnssec-cds.c dnssec-dsfromkey.c dnssec-importkey.c \
|
|||||||
dnssec-settime.c dnssec-signzone.c dnssec-verify.c \
|
dnssec-settime.c dnssec-signzone.c dnssec-verify.c \
|
||||||
dnssectool.c
|
dnssectool.c
|
||||||
|
|
||||||
MANPAGES = dnssec-cds.8 dnssec-dsfromkey.8 dnssec-importkey.8 \
|
MANPAGES = dnssec-cds.8 dnssec-dsfromkey.8 dnssec-importkey.8 \
|
||||||
dnssec-keyfromlabel.8 dnssec-keygen.8 dnssec-revoke.8 \
|
dnssec-keyfromlabel.8 dnssec-keygen.8 dnssec-revoke.8 \
|
||||||
dnssec-settime.8 dnssec-signzone.8 dnssec-verify.8
|
dnssec-settime.8 dnssec-signzone.8 dnssec-verify.8
|
||||||
|
|
||||||
|
|||||||
@@ -372,7 +372,7 @@ formatset(dns_rdataset_t *rdataset) {
|
|||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
||||||
check_result(result, "printing DS records");
|
check_result(result, "printing DS records");
|
||||||
result = dns_master_rdatasettotext(name, rdataset, style, buf);
|
result = dns_master_rdatasettotext(name, rdataset, style, NULL, buf);
|
||||||
|
|
||||||
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
|
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
|
||||||
result = ISC_R_NOSPACE;
|
result = ISC_R_NOSPACE;
|
||||||
|
|||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-keygen \- DNSSEC key generation tool
|
dnssec-keygen \- DNSSEC key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
||||||
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-d\ \fR\fB\fIbits\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIpolicy\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-l\ \fR\fB\fIfile\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-T\ \fR\fB\fIrrtype\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-keygen\fR
|
\fBdnssec\-keygen\fR
|
||||||
@@ -109,6 +109,11 @@ option suppresses them\&.
|
|||||||
Indicates that the DNS record containing the key should have the specified class\&. If not specified, class IN is used\&.
|
Indicates that the DNS record containing the key should have the specified class\&. If not specified, class IN is used\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-d \fIbits\fR
|
||||||
|
.RS 4
|
||||||
|
Key size in bits\&. For the algorithms RSASHA1, NSEC3RSASA1, RSASHA256 and RSASHA512 the key size must be in range 1024\-4096\&. DH size is between 128 and 4096\&. This option is ignored for algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-E \fIengine\fR
|
\-E \fIengine\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the cryptographic hardware to use, when applicable\&.
|
Specifies the cryptographic hardware to use, when applicable\&.
|
||||||
@@ -142,6 +147,17 @@ Prints a short summary of the options and arguments to
|
|||||||
Sets the directory in which the key files are to be written\&.
|
Sets the directory in which the key files are to be written\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-k \fIpolicy\fR
|
||||||
|
.RS 4
|
||||||
|
Create keys for a specific dnssec\-policy\&. If a policy uses multiple keys,
|
||||||
|
\fBdnssec\-keygen\fR
|
||||||
|
will generate multiple keys\&. This will also create a "\&.state" file to keep track of the key state\&.
|
||||||
|
.sp
|
||||||
|
This option creates keys according to the dnssec\-policy configuration, hence it cannot be used together with many of the other options that
|
||||||
|
\fBdnssec\-keygen\fR
|
||||||
|
provides\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-L \fIttl\fR
|
\-L \fIttl\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
||||||
@@ -151,6 +167,12 @@ none
|
|||||||
is the same as leaving it unset\&.
|
is the same as leaving it unset\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-l \fIfile\fR
|
||||||
|
.RS 4
|
||||||
|
Provide a configuration file that contains a dnssec\-policy statement (matching the policy set with
|
||||||
|
\fB\-k\fR)\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-n \fInametype\fR
|
\-n \fInametype\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the owner type of the key\&. The value of
|
Specifies the owner type of the key\&. The value of
|
||||||
|
|||||||
+816
-542
File diff suppressed because it is too large
Load Diff
@@ -66,6 +66,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">bits</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">flag</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">flag</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-G</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-G</option></arg>
|
||||||
@@ -74,8 +75,9 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-k</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">policy</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">file</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
@@ -84,6 +86,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">rrtype</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||||
@@ -207,6 +210,18 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-d <replaceable class="parameter">bits</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Key size in bits. For the algorithms RSASHA1, NSEC3RSASA1,
|
||||||
|
RSASHA256 and RSASHA512 the key size must be in range 1024-4096.
|
||||||
|
DH size is between 128 and 4096. This option is ignored for
|
||||||
|
algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-E <replaceable class="parameter">engine</replaceable></term>
|
<term>-E <replaceable class="parameter">engine</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -275,6 +290,24 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-k <replaceable class="parameter">policy</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Create keys for a specific dnssec-policy. If a policy uses
|
||||||
|
multiple keys, <command>dnssec-keygen</command> will generate
|
||||||
|
multiple keys. This will also create a ".state" file to keep
|
||||||
|
track of the key state.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
This option creates keys according to the dnssec-policy
|
||||||
|
configuration, hence it cannot be used together with many of
|
||||||
|
the other options that <command>dnssec-keygen</command>
|
||||||
|
provides.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-L <replaceable class="parameter">ttl</replaceable></term>
|
<term>-L <replaceable class="parameter">ttl</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -291,6 +324,16 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-l <replaceable class="parameter">file</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Provide a configuration file that contains a dnssec-policy
|
||||||
|
statement (matching the policy set with <command>-k</command>).
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-n <replaceable class="parameter">nametype</replaceable></term>
|
<term>-n <replaceable class="parameter">nametype</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -41,6 +41,7 @@
|
|||||||
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
||||||
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-d <em class="replaceable"><code>bits</code></em></code>]
|
||||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||||
[<code class="option">-f <em class="replaceable"><code>flag</code></em></code>]
|
[<code class="option">-f <em class="replaceable"><code>flag</code></em></code>]
|
||||||
[<code class="option">-G</code>]
|
[<code class="option">-G</code>]
|
||||||
@@ -49,8 +50,9 @@
|
|||||||
[<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||||
[<code class="option">-k</code>]
|
[<code class="option">-k <em class="replaceable"><code>policy</code></em></code>]
|
||||||
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
||||||
|
[<code class="option">-l <em class="replaceable"><code>file</code></em></code>]
|
||||||
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
||||||
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
@@ -59,6 +61,7 @@
|
|||||||
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
||||||
|
[<code class="option">-T <em class="replaceable"><code>rrtype</code></em></code>]
|
||||||
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
@@ -168,6 +171,15 @@
|
|||||||
the specified class. If not specified, class IN is used.
|
the specified class. If not specified, class IN is used.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-d <em class="replaceable"><code>bits</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Key size in bits. For the algorithms RSASHA1, NSEC3RSASA1,
|
||||||
|
RSASHA256 and RSASHA512 the key size must be in range 1024-4096.
|
||||||
|
DH size is between 128 and 4096. This option is ignored for
|
||||||
|
algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
|
<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -218,6 +230,21 @@
|
|||||||
Sets the directory in which the key files are to be written.
|
Sets the directory in which the key files are to be written.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-k <em class="replaceable"><code>policy</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Create keys for a specific dnssec-policy. If a policy uses
|
||||||
|
multiple keys, <span class="command"><strong>dnssec-keygen</strong></span> will generate
|
||||||
|
multiple keys. This will also create a ".state" file to keep
|
||||||
|
track of the key state.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
This option creates keys according to the dnssec-policy
|
||||||
|
configuration, hence it cannot be used together with many of
|
||||||
|
the other options that <span class="command"><strong>dnssec-keygen</strong></span>
|
||||||
|
provides.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -231,6 +258,13 @@
|
|||||||
or <code class="literal">none</code> is the same as leaving it unset.
|
or <code class="literal">none</code> is the same as leaving it unset.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-l <em class="replaceable"><code>file</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Provide a configuration file that contains a dnssec-policy
|
||||||
|
statement (matching the policy set with <span class="command"><strong>-k</strong></span>).
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-settime \- set the key timing metadata for a DNSSEC key
|
dnssec-settime \- set the key timing metadata for a DNSSEC key
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-settime\fR\ 'u
|
.HP \w'\fBdnssec\-settime\fR\ 'u
|
||||||
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] {keyfile}
|
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-s\fR] [\fB\-g\ \fR\fB\fIstate\fR\fR] [\fB\-d\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-k\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-z\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] {keyfile}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-settime\fR
|
\fBdnssec\-settime\fR
|
||||||
@@ -59,7 +59,25 @@ simply prints the key timing metadata already stored in the key\&.
|
|||||||
.PP
|
.PP
|
||||||
When key metadata fields are changed, both files of a key pair (Knnnn\&.+aaa+iiiii\&.key
|
When key metadata fields are changed, both files of a key pair (Knnnn\&.+aaa+iiiii\&.key
|
||||||
and
|
and
|
||||||
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&. Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&.
|
||||||
|
.PP
|
||||||
|
Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
||||||
|
.PP
|
||||||
|
When working with state files, it is possible to update the timing metadata in those files as well with
|
||||||
|
\fB\-s\fR\&. If this option is used you can also update key states with
|
||||||
|
\fB\-d\fR
|
||||||
|
(DS),
|
||||||
|
\fB\-k\fR
|
||||||
|
(DNSKEY),
|
||||||
|
\fB\-r\fR
|
||||||
|
(RRSIG of KSK), or
|
||||||
|
\fB\-z\fR
|
||||||
|
(RRSIG of ZSK)\&. Allowed states are HIDDEN, RUMOURED, OMNIPRESENT, and UNRETENTIVE\&.
|
||||||
|
.PP
|
||||||
|
You can also set the goal state of the key with
|
||||||
|
\fB\-g\fR\&. This should be either HIDDEN or OMNIPRESENT (representing whether the key should be removed from the zone, or published)\&.
|
||||||
|
.PP
|
||||||
|
It is NOT RECOMMENDED to manipulate state files manually except for testing purposes\&.
|
||||||
.SH "OPTIONS"
|
.SH "OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
\-f
|
\-f
|
||||||
@@ -156,6 +174,39 @@ If the key is being set to be an explicit successor to another key, then the def
|
|||||||
.sp
|
.sp
|
||||||
As with date offsets, if the argument is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the interval is measured in years, months, weeks, days, hours, or minutes, respectively\&. Without a suffix, the interval is measured in seconds\&.
|
As with date offsets, if the argument is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the interval is measured in years, months, weeks, days, hours, or minutes, respectively\&. Without a suffix, the interval is measured in seconds\&.
|
||||||
.RE
|
.RE
|
||||||
|
.SH "KEY STATE OPTIONS"
|
||||||
|
.PP
|
||||||
|
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE\&. These should not be set manually except for testing purposes\&.
|
||||||
|
.PP
|
||||||
|
\-s
|
||||||
|
.RS 4
|
||||||
|
When setting key timing data, also update the state file\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-g
|
||||||
|
.RS 4
|
||||||
|
Set the goal state for this key\&. Must be HIDDEN or OMNIPRESENT\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-d
|
||||||
|
.RS 4
|
||||||
|
Set the DS state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-k
|
||||||
|
.RS 4
|
||||||
|
Set the DNSKEY state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-r
|
||||||
|
.RS 4
|
||||||
|
Set the RRSIG (KSK) state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-z
|
||||||
|
.RS 4
|
||||||
|
Set the RRSIG (ZSK) state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
.SH "PRINTING OPTIONS"
|
.SH "PRINTING OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-settime\fR
|
\fBdnssec\-settime\fR
|
||||||
|
|||||||
+334
-158
@@ -88,6 +88,15 @@ usage(void) {
|
|||||||
fprintf(stderr, " -i <interval>: prepublication interval for "
|
fprintf(stderr, " -i <interval>: prepublication interval for "
|
||||||
"successor key "
|
"successor key "
|
||||||
"(default: 30 days)\n");
|
"(default: 30 days)\n");
|
||||||
|
fprintf(stderr, "Key state options:\n");
|
||||||
|
fprintf(stderr, " -s: update key state file (default no)\n");
|
||||||
|
fprintf(stderr, " -g state: set the goal state for this key\n");
|
||||||
|
fprintf(stderr, " -d state date/[+-]offset: set the DS state\n");
|
||||||
|
fprintf(stderr, " -k state date/[+-]offset: set the DNSKEY state\n");
|
||||||
|
fprintf(stderr, " -r state date/[+-]offset: set the RRSIG (KSK) "
|
||||||
|
"state\n");
|
||||||
|
fprintf(stderr, " -z state date/[+-]offset: set the RRSIG (ZSK) "
|
||||||
|
"state\n");
|
||||||
fprintf(stderr, "Printing options:\n");
|
fprintf(stderr, "Printing options:\n");
|
||||||
fprintf(stderr, " -p C/P/Psync/A/R/I/D/Dsync/all: print a "
|
fprintf(stderr, " -p C/P/Psync/A/R/I/D/Dsync/all: print a "
|
||||||
"particular time value or values\n");
|
"particular time value or values\n");
|
||||||
@@ -123,29 +132,87 @@ printtime(dst_key_t *key, int type, const char *tag, bool epoch,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
writekey(dst_key_t *key, const char *directory, bool write_state)
|
||||||
|
{
|
||||||
|
char newname[1024];
|
||||||
|
char keystr[DST_KEY_FORMATSIZE];
|
||||||
|
isc_buffer_t buf;
|
||||||
|
isc_result_t result;
|
||||||
|
int options = DST_TYPE_PUBLIC|DST_TYPE_PRIVATE;
|
||||||
|
|
||||||
|
if (write_state) {
|
||||||
|
options |= DST_TYPE_STATE;
|
||||||
|
}
|
||||||
|
|
||||||
|
isc_buffer_init(&buf, newname, sizeof(newname));
|
||||||
|
result = dst_key_buildfilename(key, DST_TYPE_PUBLIC, directory, &buf);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("Failed to build public key filename: %s",
|
||||||
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
|
||||||
|
result = dst_key_tofile(key, options, directory);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
dst_key_format(key, keystr, sizeof(keystr));
|
||||||
|
fatal("Failed to write key %s: %s", keystr,
|
||||||
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
printf("%s\n", newname);
|
||||||
|
|
||||||
|
isc_buffer_clear(&buf);
|
||||||
|
result = dst_key_buildfilename(key, DST_TYPE_PRIVATE, directory, &buf);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("Failed to build private key filename: %s",
|
||||||
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
printf("%s\n", newname);
|
||||||
|
|
||||||
|
if (write_state) {
|
||||||
|
isc_buffer_clear(&buf);
|
||||||
|
result = dst_key_buildfilename(key, DST_TYPE_STATE, directory,
|
||||||
|
&buf);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("Failed to build key state filename: %s",
|
||||||
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
printf("%s\n", newname);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *engine = NULL;
|
const char *engine = NULL;
|
||||||
const char *filename = NULL;
|
const char *filename = NULL;
|
||||||
char *directory = NULL;
|
char *directory = NULL;
|
||||||
char newname[1024];
|
|
||||||
char keystr[DST_KEY_FORMATSIZE];
|
char keystr[DST_KEY_FORMATSIZE];
|
||||||
char *endp, *p;
|
char *endp, *p;
|
||||||
int ch;
|
int ch;
|
||||||
const char *predecessor = NULL;
|
const char *predecessor = NULL;
|
||||||
dst_key_t *prevkey = NULL;
|
dst_key_t *prevkey = NULL;
|
||||||
dst_key_t *key = NULL;
|
dst_key_t *key = NULL;
|
||||||
isc_buffer_t buf;
|
|
||||||
dns_name_t *name = NULL;
|
dns_name_t *name = NULL;
|
||||||
dns_secalg_t alg = 0;
|
dns_secalg_t alg = 0;
|
||||||
unsigned int size = 0;
|
unsigned int size = 0;
|
||||||
uint16_t flags = 0;
|
uint16_t flags = 0;
|
||||||
int prepub = -1;
|
int prepub = -1;
|
||||||
|
int options;
|
||||||
dns_ttl_t ttl = 0;
|
dns_ttl_t ttl = 0;
|
||||||
isc_stdtime_t now;
|
isc_stdtime_t now;
|
||||||
|
isc_stdtime_t dstime = 0, dnskeytime = 0;
|
||||||
|
isc_stdtime_t krrsigtime = 0, zrrsigtime = 0;
|
||||||
isc_stdtime_t pub = 0, act = 0, rev = 0, inact = 0, del = 0;
|
isc_stdtime_t pub = 0, act = 0, rev = 0, inact = 0, del = 0;
|
||||||
isc_stdtime_t prevact = 0, previnact = 0, prevdel = 0;
|
isc_stdtime_t prevact = 0, previnact = 0, prevdel = 0;
|
||||||
|
dst_key_state_t goal = DST_KEY_STATE_NA;
|
||||||
|
dst_key_state_t ds = DST_KEY_STATE_NA;
|
||||||
|
dst_key_state_t dnskey = DST_KEY_STATE_NA;
|
||||||
|
dst_key_state_t krrsig = DST_KEY_STATE_NA;
|
||||||
|
dst_key_state_t zrrsig = DST_KEY_STATE_NA;
|
||||||
|
bool setgoal = false, setds = false, setdnskey = false;
|
||||||
|
bool setkrrsig = false, setzrrsig = false;
|
||||||
|
bool setdstime = false, setdnskeytime = false;
|
||||||
|
bool setkrrsigtime = false, setzrrsigtime = false;
|
||||||
bool setpub = false, setact = false;
|
bool setpub = false, setact = false;
|
||||||
bool setrev = false, setinact = false;
|
bool setrev = false, setinact = false;
|
||||||
bool setdel = false, setttl = false;
|
bool setdel = false, setttl = false;
|
||||||
@@ -156,14 +223,17 @@ main(int argc, char **argv) {
|
|||||||
bool printact = false, printrev = false;
|
bool printact = false, printrev = false;
|
||||||
bool printinact = false, printdel = false;
|
bool printinact = false, printdel = false;
|
||||||
bool force = false;
|
bool force = false;
|
||||||
bool epoch = false;
|
bool epoch = false;
|
||||||
bool changed = false;
|
bool changed = false;
|
||||||
|
bool write_state = false;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
isc_stdtime_t syncadd = 0, syncdel = 0;
|
isc_stdtime_t syncadd = 0, syncdel = 0;
|
||||||
bool unsetsyncadd = false, setsyncadd = false;
|
bool unsetsyncadd = false, setsyncadd = false;
|
||||||
bool unsetsyncdel = false, setsyncdel = false;
|
bool unsetsyncdel = false, setsyncdel = false;
|
||||||
bool printsyncadd = false, printsyncdel = false;
|
bool printsyncadd = false, printsyncdel = false;
|
||||||
|
|
||||||
|
options = DST_TYPE_PUBLIC|DST_TYPE_PRIVATE|DST_TYPE_STATE;
|
||||||
|
|
||||||
if (argc == 1)
|
if (argc == 1)
|
||||||
usage();
|
usage();
|
||||||
|
|
||||||
@@ -180,109 +250,9 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_stdtime_get(&now);
|
isc_stdtime_get(&now);
|
||||||
|
|
||||||
#define CMDLINE_FLAGS "A:D:E:fhI:i:K:L:P:p:R:S:uv:V"
|
#define CMDLINE_FLAGS "A:D:d:E:fg:hI:i:K:k:L:P:p:R:r:S:suv:Vz:"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case 'E':
|
|
||||||
engine = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'f':
|
|
||||||
force = true;
|
|
||||||
break;
|
|
||||||
case 'p':
|
|
||||||
p = isc_commandline_argument;
|
|
||||||
if (!strcasecmp(p, "all")) {
|
|
||||||
printcreate = true;
|
|
||||||
printpub = true;
|
|
||||||
printact = true;
|
|
||||||
printrev = true;
|
|
||||||
printinact = true;
|
|
||||||
printdel = true;
|
|
||||||
printsyncadd = true;
|
|
||||||
printsyncdel = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
do {
|
|
||||||
switch (*p++) {
|
|
||||||
case 'C':
|
|
||||||
printcreate = true;
|
|
||||||
break;
|
|
||||||
case 'P':
|
|
||||||
if (!strncmp(p, "sync", 4)) {
|
|
||||||
p += 4;
|
|
||||||
printsyncadd = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
printpub = true;
|
|
||||||
break;
|
|
||||||
case 'A':
|
|
||||||
printact = true;
|
|
||||||
break;
|
|
||||||
case 'R':
|
|
||||||
printrev = true;
|
|
||||||
break;
|
|
||||||
case 'I':
|
|
||||||
printinact = true;
|
|
||||||
break;
|
|
||||||
case 'D':
|
|
||||||
if (!strncmp(p, "sync", 4)) {
|
|
||||||
p += 4;
|
|
||||||
printsyncdel = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
printdel = true;
|
|
||||||
break;
|
|
||||||
case ' ':
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
usage();
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
} while (*p != '\0');
|
|
||||||
break;
|
|
||||||
case 'u':
|
|
||||||
epoch = true;
|
|
||||||
break;
|
|
||||||
case 'K':
|
|
||||||
/*
|
|
||||||
* We don't have to copy it here, but do it to
|
|
||||||
* simplify cleanup later
|
|
||||||
*/
|
|
||||||
directory = isc_mem_strdup(mctx,
|
|
||||||
isc_commandline_argument);
|
|
||||||
break;
|
|
||||||
case 'L':
|
|
||||||
ttl = strtottl(isc_commandline_argument);
|
|
||||||
setttl = true;
|
|
||||||
break;
|
|
||||||
case 'v':
|
|
||||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
|
||||||
if (*endp != '\0')
|
|
||||||
fatal("-v must be followed by a number");
|
|
||||||
break;
|
|
||||||
case 'P':
|
|
||||||
/* -Psync ? */
|
|
||||||
if (isoptarg("sync", argv, usage)) {
|
|
||||||
if (unsetsyncadd || setsyncadd)
|
|
||||||
fatal("-P sync specified more than "
|
|
||||||
"once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
syncadd = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setsyncadd);
|
|
||||||
unsetsyncadd = !setsyncadd;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
(void)isoptarg("dnskey", argv, usage);
|
|
||||||
if (setpub || unsetpub)
|
|
||||||
fatal("-P specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
pub = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setpub);
|
|
||||||
unsetpub = !setpub;
|
|
||||||
break;
|
|
||||||
case 'A':
|
case 'A':
|
||||||
if (setact || unsetact)
|
if (setact || unsetact)
|
||||||
fatal("-A specified more than once");
|
fatal("-A specified more than once");
|
||||||
@@ -292,24 +262,6 @@ main(int argc, char **argv) {
|
|||||||
now, now, &setact);
|
now, now, &setact);
|
||||||
unsetact = !setact;
|
unsetact = !setact;
|
||||||
break;
|
break;
|
||||||
case 'R':
|
|
||||||
if (setrev || unsetrev)
|
|
||||||
fatal("-R specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
rev = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setrev);
|
|
||||||
unsetrev = !setrev;
|
|
||||||
break;
|
|
||||||
case 'I':
|
|
||||||
if (setinact || unsetinact)
|
|
||||||
fatal("-I specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
inact = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setinact);
|
|
||||||
unsetinact = !setinact;
|
|
||||||
break;
|
|
||||||
case 'D':
|
case 'D':
|
||||||
/* -Dsync ? */
|
/* -Dsync ? */
|
||||||
if (isoptarg("sync", argv, usage)) {
|
if (isoptarg("sync", argv, usage)) {
|
||||||
@@ -333,11 +285,37 @@ main(int argc, char **argv) {
|
|||||||
now, now, &setdel);
|
now, now, &setdel);
|
||||||
unsetdel = !setdel;
|
unsetdel = !setdel;
|
||||||
break;
|
break;
|
||||||
case 'S':
|
case 'd':
|
||||||
predecessor = isc_commandline_argument;
|
if (setds) {
|
||||||
|
fatal("-d specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
ds = strtokeystate(isc_commandline_argument);
|
||||||
|
setds = true;
|
||||||
|
/* time */
|
||||||
|
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||||
|
dstime = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setdstime);
|
||||||
break;
|
break;
|
||||||
case 'i':
|
case 'E':
|
||||||
prepub = strtottl(isc_commandline_argument);
|
engine = isc_commandline_argument;
|
||||||
|
break;
|
||||||
|
case 'f':
|
||||||
|
force = true;
|
||||||
|
break;
|
||||||
|
case 'g':
|
||||||
|
if (setgoal) {
|
||||||
|
fatal("-g specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
goal = strtokeystate(isc_commandline_argument);
|
||||||
|
if (goal != DST_KEY_STATE_NA &&
|
||||||
|
goal != DST_KEY_STATE_HIDDEN &&
|
||||||
|
goal != DST_KEY_STATE_OMNIPRESENT) {
|
||||||
|
fatal("-g must be either none, hidden, or "
|
||||||
|
"omnipresent");
|
||||||
|
}
|
||||||
|
setgoal = true;
|
||||||
break;
|
break;
|
||||||
case '?':
|
case '?':
|
||||||
if (isc_commandline_option != '?')
|
if (isc_commandline_option != '?')
|
||||||
@@ -347,10 +325,165 @@ main(int argc, char **argv) {
|
|||||||
case 'h':
|
case 'h':
|
||||||
/* Does not return. */
|
/* Does not return. */
|
||||||
usage();
|
usage();
|
||||||
|
case 'I':
|
||||||
|
if (setinact || unsetinact)
|
||||||
|
fatal("-I specified more than once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
inact = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setinact);
|
||||||
|
unsetinact = !setinact;
|
||||||
|
break;
|
||||||
|
case 'i':
|
||||||
|
prepub = strtottl(isc_commandline_argument);
|
||||||
|
break;
|
||||||
|
case 'K':
|
||||||
|
/*
|
||||||
|
* We don't have to copy it here, but do it to
|
||||||
|
* simplify cleanup later
|
||||||
|
*/
|
||||||
|
directory = isc_mem_strdup(mctx,
|
||||||
|
isc_commandline_argument);
|
||||||
|
break;
|
||||||
|
case 'k':
|
||||||
|
if (setdnskey) {
|
||||||
|
fatal("-k specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
dnskey = strtokeystate(isc_commandline_argument);
|
||||||
|
setdnskey = true;
|
||||||
|
/* time */
|
||||||
|
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||||
|
dnskeytime = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setdnskeytime);
|
||||||
|
break;
|
||||||
|
case 'L':
|
||||||
|
ttl = strtottl(isc_commandline_argument);
|
||||||
|
setttl = true;
|
||||||
|
break;
|
||||||
|
case 'P':
|
||||||
|
/* -Psync ? */
|
||||||
|
if (isoptarg("sync", argv, usage)) {
|
||||||
|
if (unsetsyncadd || setsyncadd)
|
||||||
|
fatal("-P sync specified more than "
|
||||||
|
"once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
syncadd = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setsyncadd);
|
||||||
|
unsetsyncadd = !setsyncadd;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
(void)isoptarg("dnskey", argv, usage);
|
||||||
|
if (setpub || unsetpub)
|
||||||
|
fatal("-P specified more than once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
pub = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setpub);
|
||||||
|
unsetpub = !setpub;
|
||||||
|
break;
|
||||||
|
case 'p':
|
||||||
|
p = isc_commandline_argument;
|
||||||
|
if (!strcasecmp(p, "all")) {
|
||||||
|
printcreate = true;
|
||||||
|
printpub = true;
|
||||||
|
printact = true;
|
||||||
|
printrev = true;
|
||||||
|
printinact = true;
|
||||||
|
printdel = true;
|
||||||
|
printsyncadd = true;
|
||||||
|
printsyncdel = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
do {
|
||||||
|
switch (*p++) {
|
||||||
|
case 'A':
|
||||||
|
printact = true;
|
||||||
|
break;
|
||||||
|
case 'C':
|
||||||
|
printcreate = true;
|
||||||
|
break;
|
||||||
|
case 'D':
|
||||||
|
if (!strncmp(p, "sync", 4)) {
|
||||||
|
p += 4;
|
||||||
|
printsyncdel = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
printdel = true;
|
||||||
|
break;
|
||||||
|
case 'I':
|
||||||
|
printinact = true;
|
||||||
|
break;
|
||||||
|
case 'P':
|
||||||
|
if (!strncmp(p, "sync", 4)) {
|
||||||
|
p += 4;
|
||||||
|
printsyncadd = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
printpub = true;
|
||||||
|
break;
|
||||||
|
case 'R':
|
||||||
|
printrev = true;
|
||||||
|
break;
|
||||||
|
case ' ':
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
usage();
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
} while (*p != '\0');
|
||||||
|
break;
|
||||||
|
case 'R':
|
||||||
|
if (setrev || unsetrev)
|
||||||
|
fatal("-R specified more than once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
rev = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setrev);
|
||||||
|
unsetrev = !setrev;
|
||||||
|
break;
|
||||||
|
case 'r':
|
||||||
|
if (setkrrsig) {
|
||||||
|
fatal("-r specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
krrsig = strtokeystate(isc_commandline_argument);
|
||||||
|
setkrrsig = true;
|
||||||
|
/* time */
|
||||||
|
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||||
|
krrsigtime = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setkrrsigtime);
|
||||||
|
break;
|
||||||
|
case 'S':
|
||||||
|
predecessor = isc_commandline_argument;
|
||||||
|
break;
|
||||||
|
case 's':
|
||||||
|
write_state = true;
|
||||||
|
break;
|
||||||
|
case 'u':
|
||||||
|
epoch = true;
|
||||||
|
break;
|
||||||
case 'V':
|
case 'V':
|
||||||
/* Does not return. */
|
/* Does not return. */
|
||||||
version(program);
|
version(program);
|
||||||
|
case 'v':
|
||||||
|
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||||
|
if (*endp != '\0')
|
||||||
|
fatal("-v must be followed by a number");
|
||||||
|
break;
|
||||||
|
case 'z':
|
||||||
|
if (setzrrsig) {
|
||||||
|
fatal("-z specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
zrrsig = strtokeystate(isc_commandline_argument);
|
||||||
|
setzrrsig = true;
|
||||||
|
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||||
|
zrrsigtime = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setzrrsigtime);
|
||||||
|
break;
|
||||||
|
|
||||||
default:
|
default:
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n",
|
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||||
@@ -365,6 +498,12 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("Extraneous arguments");
|
fatal("Extraneous arguments");
|
||||||
|
|
||||||
|
if ((setgoal || setds || setdnskey || setkrrsig || setzrrsig) &&
|
||||||
|
!write_state)
|
||||||
|
{
|
||||||
|
fatal("Options -g, -d, -k, -r and -z require -s to be set");
|
||||||
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
result = dst_lib_init(mctx, engine);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Could not initialize dst: %s",
|
fatal("Could not initialize dst: %s",
|
||||||
@@ -381,9 +520,7 @@ main(int argc, char **argv) {
|
|||||||
if (setact || unsetact)
|
if (setact || unsetact)
|
||||||
fatal("-S and -A cannot be used together");
|
fatal("-S and -A cannot be used together");
|
||||||
|
|
||||||
result = dst_key_fromnamedfile(predecessor, directory,
|
result = dst_key_fromnamedfile(predecessor, directory, options,
|
||||||
DST_TYPE_PUBLIC |
|
|
||||||
DST_TYPE_PRIVATE,
|
|
||||||
mctx, &prevkey);
|
mctx, &prevkey);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Invalid keyfile %s: %s",
|
fatal("Invalid keyfile %s: %s",
|
||||||
@@ -475,9 +612,8 @@ main(int argc, char **argv) {
|
|||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_key_fromnamedfile(filename, directory,
|
result = dst_key_fromnamedfile(filename, directory, options, mctx,
|
||||||
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE,
|
&key);
|
||||||
mctx, &key);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Invalid keyfile %s: %s",
|
fatal("Invalid keyfile %s: %s",
|
||||||
filename, isc_result_totext(result));
|
filename, isc_result_totext(result));
|
||||||
@@ -578,6 +714,11 @@ main(int argc, char **argv) {
|
|||||||
if (setttl)
|
if (setttl)
|
||||||
dst_key_setttl(key, ttl);
|
dst_key_setttl(key, ttl);
|
||||||
|
|
||||||
|
if (predecessor != NULL && prevkey != NULL) {
|
||||||
|
dst_key_setnum(prevkey, DST_NUM_SUCCESSOR, dst_key_id(key));
|
||||||
|
dst_key_setnum(key, DST_NUM_PREDECESSOR, dst_key_id(prevkey));
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* No metadata changes were made but we're forcing an upgrade
|
* No metadata changes were made but we're forcing an upgrade
|
||||||
* to the new format anyway: use "-P now -A now" as the default
|
* to the new format anyway: use "-P now -A now" as the default
|
||||||
@@ -588,6 +729,63 @@ main(int argc, char **argv) {
|
|||||||
changed = true;
|
changed = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Make sure the key state goals are written.
|
||||||
|
*/
|
||||||
|
if (write_state) {
|
||||||
|
if (setgoal) {
|
||||||
|
if (goal == DST_KEY_STATE_NA) {
|
||||||
|
dst_key_unsetstate(key, DST_KEY_GOAL);
|
||||||
|
} else {
|
||||||
|
dst_key_setstate(key, DST_KEY_GOAL, goal);
|
||||||
|
}
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
if (setds) {
|
||||||
|
if (ds == DST_KEY_STATE_NA) {
|
||||||
|
dst_key_unsetstate(key, DST_KEY_DS);
|
||||||
|
dst_key_unsettime(key, DST_TIME_DS);
|
||||||
|
} else {
|
||||||
|
dst_key_setstate(key, DST_KEY_DS, ds);
|
||||||
|
dst_key_settime(key, DST_TIME_DS, dstime);
|
||||||
|
}
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
if (setdnskey) {
|
||||||
|
if (dnskey == DST_KEY_STATE_NA) {
|
||||||
|
dst_key_unsetstate(key, DST_KEY_DNSKEY);
|
||||||
|
dst_key_unsettime(key, DST_TIME_DNSKEY);
|
||||||
|
} else {
|
||||||
|
dst_key_setstate(key, DST_KEY_DNSKEY, dnskey);
|
||||||
|
dst_key_settime(key, DST_TIME_DNSKEY,
|
||||||
|
dnskeytime);
|
||||||
|
}
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
if (setkrrsig) {
|
||||||
|
if (krrsig == DST_KEY_STATE_NA) {
|
||||||
|
dst_key_unsetstate(key, DST_KEY_KRRSIG);
|
||||||
|
dst_key_unsettime(key, DST_TIME_KRRSIG);
|
||||||
|
} else {
|
||||||
|
dst_key_setstate(key, DST_KEY_KRRSIG, krrsig);
|
||||||
|
dst_key_settime(key, DST_TIME_KRRSIG,
|
||||||
|
krrsigtime);
|
||||||
|
}
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
if (setzrrsig) {
|
||||||
|
if (zrrsig == DST_KEY_STATE_NA) {
|
||||||
|
dst_key_unsetstate(key, DST_KEY_ZRRSIG);
|
||||||
|
dst_key_unsettime(key, DST_TIME_ZRRSIG);
|
||||||
|
} else {
|
||||||
|
dst_key_setstate(key, DST_KEY_ZRRSIG, zrrsig);
|
||||||
|
dst_key_settime(key, DST_TIME_ZRRSIG,
|
||||||
|
zrrsigtime);
|
||||||
|
}
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (!changed && setttl)
|
if (!changed && setttl)
|
||||||
changed = true;
|
changed = true;
|
||||||
|
|
||||||
@@ -621,32 +819,10 @@ main(int argc, char **argv) {
|
|||||||
epoch, stdout);
|
epoch, stdout);
|
||||||
|
|
||||||
if (changed) {
|
if (changed) {
|
||||||
isc_buffer_init(&buf, newname, sizeof(newname));
|
writekey(key, directory, write_state);
|
||||||
result = dst_key_buildfilename(key, DST_TYPE_PUBLIC, directory,
|
if (predecessor != NULL && prevkey != NULL) {
|
||||||
&buf);
|
writekey(prevkey, directory, write_state);
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Failed to build public key filename: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_key_tofile(key, DST_TYPE_PUBLIC|DST_TYPE_PRIVATE,
|
|
||||||
directory);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
dst_key_format(key, keystr, sizeof(keystr));
|
|
||||||
fatal("Failed to write key %s: %s", keystr,
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
|
|
||||||
printf("%s\n", newname);
|
|
||||||
|
|
||||||
isc_buffer_clear(&buf);
|
|
||||||
result = dst_key_buildfilename(key, DST_TYPE_PRIVATE, directory,
|
|
||||||
&buf);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
fatal("Failed to build private key filename: %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
}
|
|
||||||
printf("%s\n", newname);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (prevkey != NULL)
|
if (prevkey != NULL)
|
||||||
|
|||||||
@@ -64,6 +64,12 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-s</option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-g <replaceable class="parameter">state</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">state</replaceable> <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">state</replaceable> <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">state</replaceable> <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-z <replaceable class="parameter">state</replaceable> <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="req" rep="norepeat">keyfile</arg>
|
<arg choice="req" rep="norepeat">keyfile</arg>
|
||||||
</cmdsynopsis>
|
</cmdsynopsis>
|
||||||
</refsynopsisdiv>
|
</refsynopsisdiv>
|
||||||
@@ -88,11 +94,30 @@
|
|||||||
When key metadata fields are changed, both files of a key
|
When key metadata fields are changed, both files of a key
|
||||||
pair (<filename>Knnnn.+aaa+iiiii.key</filename> and
|
pair (<filename>Knnnn.+aaa+iiiii.key</filename> and
|
||||||
<filename>Knnnn.+aaa+iiiii.private</filename>) are regenerated.
|
<filename>Knnnn.+aaa+iiiii.private</filename>) are regenerated.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
Metadata fields are stored in the private file. A human-readable
|
Metadata fields are stored in the private file. A human-readable
|
||||||
description of the metadata is also placed in comments in the key
|
description of the metadata is also placed in comments in the key
|
||||||
file. The private file's permissions are always set to be
|
file. The private file's permissions are always set to be
|
||||||
inaccessible to anyone other than the owner (mode 0600).
|
inaccessible to anyone other than the owner (mode 0600).
|
||||||
</para>
|
</para>
|
||||||
|
<para>
|
||||||
|
When working with state files, it is possible to update the timing
|
||||||
|
metadata in those files as well with <option>-s</option>. If this
|
||||||
|
option is used you can also update key states with <option>-d</option>
|
||||||
|
(DS), <option>-k</option> (DNSKEY), <option>-r</option> (RRSIG of KSK),
|
||||||
|
or <option>-z</option> (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||||
|
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
You can also set the goal state of the key with <option>-g</option>.
|
||||||
|
This should be either HIDDEN or OMNIPRESENT (representing whether the
|
||||||
|
key should be removed from the zone, or published).
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
It is NOT RECOMMENDED to manipulate state files manually except for
|
||||||
|
testing purposes.
|
||||||
|
</para>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>OPTIONS</title></info>
|
<refsection><info><title>OPTIONS</title></info>
|
||||||
@@ -319,6 +344,74 @@
|
|||||||
</variablelist>
|
</variablelist>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
|
<refsection><info><title>KEY STATE OPTIONS</title></info>
|
||||||
|
|
||||||
|
<para>
|
||||||
|
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE.
|
||||||
|
These should not be set manually except for testing purposes.
|
||||||
|
</para>
|
||||||
|
|
||||||
|
<variablelist>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-s</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
When setting key timing data, also update the state file.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-g</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Set the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-d</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Set the DS state for this key, and when it was last changed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-k</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Set the DNSKEY state for this key, and when it was last changed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-r</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Set the RRSIG (KSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-z</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Set the RRSIG (ZSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
</variablelist>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>PRINTING OPTIONS</title></info>
|
<refsection><info><title>PRINTING OPTIONS</title></info>
|
||||||
|
|
||||||
<para>
|
<para>
|
||||||
|
|||||||
@@ -49,6 +49,12 @@
|
|||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||||
|
[<code class="option">-s</code>]
|
||||||
|
[<code class="option">-g <em class="replaceable"><code>state</code></em></code>]
|
||||||
|
[<code class="option">-d <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-k <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-z <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
{keyfile}
|
{keyfile}
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
@@ -74,11 +80,30 @@
|
|||||||
When key metadata fields are changed, both files of a key
|
When key metadata fields are changed, both files of a key
|
||||||
pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
|
pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
|
||||||
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
|
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
Metadata fields are stored in the private file. A human-readable
|
Metadata fields are stored in the private file. A human-readable
|
||||||
description of the metadata is also placed in comments in the key
|
description of the metadata is also placed in comments in the key
|
||||||
file. The private file's permissions are always set to be
|
file. The private file's permissions are always set to be
|
||||||
inaccessible to anyone other than the owner (mode 0600).
|
inaccessible to anyone other than the owner (mode 0600).
|
||||||
</p>
|
</p>
|
||||||
|
<p>
|
||||||
|
When working with state files, it is possible to update the timing
|
||||||
|
metadata in those files as well with <code class="option">-s</code>. If this
|
||||||
|
option is used you can also update key states with <code class="option">-d</code>
|
||||||
|
(DS), <code class="option">-k</code> (DNSKEY), <code class="option">-r</code> (RRSIG of KSK),
|
||||||
|
or <code class="option">-z</code> (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||||
|
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
You can also set the goal state of the key with <code class="option">-g</code>.
|
||||||
|
This should be either HIDDEN or OMNIPRESENT (representing whether the
|
||||||
|
key should be removed from the zone, or published).
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
It is NOT RECOMMENDED to manipulate state files manually except for
|
||||||
|
testing purposes.
|
||||||
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
@@ -262,7 +287,57 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.10"></a><h2>PRINTING OPTIONS</h2>
|
<a name="id-1.10"></a><h2>KEY STATE OPTIONS</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE.
|
||||||
|
These should not be set manually except for testing purposes.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<div class="variablelist"><dl class="variablelist">
|
||||||
|
<dt><span class="term">-s</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
When setting key timing data, also update the state file.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-g</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-d</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the DS state for this key, and when it was last changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-k</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the DNSKEY state for this key, and when it was last changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-r</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the RRSIG (KSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-z</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the RRSIG (ZSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
</dl></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="refsection">
|
||||||
|
<a name="id-1.11"></a><h2>PRINTING OPTIONS</h2>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
<span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
|
<span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
|
||||||
@@ -298,7 +373,7 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.11"></a><h2>SEE ALSO</h2>
|
<a name="id-1.12"></a><h2>SEE ALSO</h2>
|
||||||
|
|
||||||
<p><span class="citerefentry">
|
<p><span class="citerefentry">
|
||||||
<span class="refentrytitle">dnssec-keygen</span>(8)
|
<span class="refentrytitle">dnssec-keygen</span>(8)
|
||||||
|
|||||||
@@ -246,7 +246,8 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
|
|||||||
|
|
||||||
for (;;) {
|
for (;;) {
|
||||||
result = dns_master_rdatasettotext(name, &rds,
|
result = dns_master_rdatasettotext(name, &rds,
|
||||||
masterstyle, buffer);
|
masterstyle, NULL,
|
||||||
|
buffer);
|
||||||
if (result != ISC_R_NOSPACE)
|
if (result != ISC_R_NOSPACE)
|
||||||
break;
|
break;
|
||||||
|
|
||||||
@@ -787,7 +788,10 @@ hashlist_comp(const void *a, const void *b) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
hashlist_sort(hashlist_t *l) {
|
hashlist_sort(hashlist_t *l) {
|
||||||
qsort(l->hashbuf, l->entries, l->length, hashlist_comp);
|
INSIST(l->hashbuf != NULL || l->length == 0);
|
||||||
|
if (l->length > 0) {
|
||||||
|
qsort(l->hashbuf, l->entries, l->length, hashlist_comp);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static bool
|
static bool
|
||||||
@@ -2714,7 +2718,7 @@ build_final_keylist(void) {
|
|||||||
* Update keylist with information from from the key repository.
|
* Update keylist with information from from the key repository.
|
||||||
*/
|
*/
|
||||||
dns_dnssec_updatekeys(&keylist, &matchkeys, NULL, gorigin, keyttl,
|
dns_dnssec_updatekeys(&keylist, &matchkeys, NULL, gorigin, keyttl,
|
||||||
&diff, ignore_kskflag, mctx, report);
|
&diff, mctx, report);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Update keylist with sync records.
|
* Update keylist with sync records.
|
||||||
@@ -3794,7 +3798,7 @@ main(int argc, char *argv[]) {
|
|||||||
print_time(outfp);
|
print_time(outfp);
|
||||||
print_version(outfp);
|
print_version(outfp);
|
||||||
|
|
||||||
result = isc_taskmgr_create(mctx, ntasks, 0, &taskmgr);
|
result = isc_taskmgr_create(mctx, ntasks, 0, NULL, &taskmgr);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("failed to create task manager: %s",
|
fatal("failed to create task manager: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|||||||
@@ -57,6 +57,11 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
|
#define KEYSTATES_NVALUES 4
|
||||||
|
static const char *keystates[KEYSTATES_NVALUES] = {
|
||||||
|
"hidden", "rumoured", "omnipresent", "unretentive",
|
||||||
|
};
|
||||||
|
|
||||||
int verbose = 0;
|
int verbose = 0;
|
||||||
bool quiet = false;
|
bool quiet = false;
|
||||||
uint8_t dtype[8];
|
uint8_t dtype[8];
|
||||||
@@ -244,6 +249,21 @@ strtottl(const char *str) {
|
|||||||
return (ttl);
|
return (ttl);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
dst_key_state_t
|
||||||
|
strtokeystate(const char *str) {
|
||||||
|
if (isnone(str)) {
|
||||||
|
return (DST_KEY_STATE_NA);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (int i = 0; i < KEYSTATES_NVALUES; i++) {
|
||||||
|
if (keystates[i] != NULL &&
|
||||||
|
strcasecmp(str, keystates[i]) == 0) {
|
||||||
|
return (dst_key_state_t) i;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fatal("unknown key state");
|
||||||
|
}
|
||||||
|
|
||||||
isc_stdtime_t
|
isc_stdtime_t
|
||||||
strtotime(const char *str, int64_t now, int64_t base,
|
strtotime(const char *str, int64_t now, int64_t base,
|
||||||
bool *setp)
|
bool *setp)
|
||||||
|
|||||||
@@ -17,14 +17,11 @@
|
|||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
|
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
|
#include <isc/platform.h>
|
||||||
#include <isc/stdtime.h>
|
#include <isc/stdtime.h>
|
||||||
#include <dns/rdatastruct.h>
|
#include <dns/rdatastruct.h>
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#ifndef PATH_MAX
|
|
||||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/*! verbosity: set by -v and -q option in each program, defined in dnssectool.c */
|
/*! verbosity: set by -v and -q option in each program, defined in dnssectool.c */
|
||||||
extern int verbose;
|
extern int verbose;
|
||||||
extern bool quiet;
|
extern bool quiet;
|
||||||
@@ -71,6 +68,8 @@ cleanup_logging(isc_log_t **logp);
|
|||||||
|
|
||||||
dns_ttl_t strtottl(const char *str);
|
dns_ttl_t strtottl(const char *str);
|
||||||
|
|
||||||
|
dst_key_state_t strtokeystate(const char *str);
|
||||||
|
|
||||||
isc_stdtime_t
|
isc_stdtime_t
|
||||||
strtotime(const char *str, int64_t now, int64_t base,
|
strtotime(const char *str, int64_t now, int64_t base,
|
||||||
bool *setp);
|
bool *setp);
|
||||||
|
|||||||
@@ -66,15 +66,15 @@
|
|||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\win32;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<Link>
|
<Link>
|
||||||
<SubSystem>Console</SubSystem>
|
<SubSystem>Console</SubSystem>
|
||||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||||
<AdditionalDependencies>@OPENSSL_LIB@dnssectool.lib;libisc.lib;libdns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
<AdditionalDependencies>@OPENSSL_LIB@dnssectool.lib;libisc.lib;libisccfg.lib;libdns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||||
</Link>
|
</Link>
|
||||||
</ItemDefinitionGroup>
|
</ItemDefinitionGroup>
|
||||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||||
@@ -94,7 +94,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\win32;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<Link>
|
<Link>
|
||||||
@@ -104,8 +104,8 @@
|
|||||||
<OptimizeReferences>true</OptimizeReferences>
|
<OptimizeReferences>true</OptimizeReferences>
|
||||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
||||||
<AdditionalDependencies>@OPENSSL_LIB@dnssectool.lib;libisc.lib;libdns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
<AdditionalDependencies>@OPENSSL_LIB@dnssectool.lib;libisc.lib;libisccfg.lib;libdns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||||
</Link>
|
</Link>
|
||||||
</ItemDefinitionGroup>
|
</ItemDefinitionGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
|
|||||||
+3
-2
@@ -58,6 +58,7 @@ options {\n\
|
|||||||
"\
|
"\
|
||||||
# deallocate-on-exit <obsolete>;\n\
|
# deallocate-on-exit <obsolete>;\n\
|
||||||
# directory <none>\n\
|
# directory <none>\n\
|
||||||
|
dnssec-policy \"none\";\n\
|
||||||
dump-file \"named_dump.db\";\n\
|
dump-file \"named_dump.db\";\n\
|
||||||
edns-udp-size 4096;\n\
|
edns-udp-size 4096;\n\
|
||||||
# fake-iquery <obsolete>;\n"
|
# fake-iquery <obsolete>;\n"
|
||||||
@@ -65,7 +66,7 @@ options {\n\
|
|||||||
" files unlimited;\n"
|
" files unlimited;\n"
|
||||||
#endif
|
#endif
|
||||||
#if defined(HAVE_GEOIP2) && !defined(WIN32)
|
#if defined(HAVE_GEOIP2) && !defined(WIN32)
|
||||||
" geoip-directory \"" MAXMINDDB_PREFIX "/share/GeoIP2\";\n"
|
" geoip-directory \"" MAXMINDDB_PREFIX "/share/GeoIP\";\n"
|
||||||
#elif defined(HAVE_GEOIP2)
|
#elif defined(HAVE_GEOIP2)
|
||||||
" geoip-directory \".\";\n"
|
" geoip-directory \".\";\n"
|
||||||
#endif
|
#endif
|
||||||
@@ -193,7 +194,7 @@ options {\n\
|
|||||||
# sortlist <none>\n\
|
# sortlist <none>\n\
|
||||||
stale-answer-enable false;\n\
|
stale-answer-enable false;\n\
|
||||||
stale-answer-ttl 1; /* 1 second */\n\
|
stale-answer-ttl 1; /* 1 second */\n\
|
||||||
synth-from-dnssec yes;\n\
|
synth-from-dnssec no;\n\
|
||||||
# topology <none>\n\
|
# topology <none>\n\
|
||||||
transfer-format many-answers;\n\
|
transfer-format many-answers;\n\
|
||||||
v6-bias 50;\n\
|
v6-bias 50;\n\
|
||||||
|
|||||||
@@ -19,6 +19,7 @@
|
|||||||
#include <isc/rwlock.h>
|
#include <isc/rwlock.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/net.h>
|
#include <isc/net.h>
|
||||||
|
#include <isc/netmgr.h>
|
||||||
|
|
||||||
#include <isccfg/aclconf.h>
|
#include <isccfg/aclconf.h>
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
@@ -62,6 +63,7 @@ EXTERN bool named_g_run_done INIT(false);
|
|||||||
*/
|
*/
|
||||||
EXTERN isc_timermgr_t * named_g_timermgr INIT(NULL);
|
EXTERN isc_timermgr_t * named_g_timermgr INIT(NULL);
|
||||||
EXTERN isc_socketmgr_t * named_g_socketmgr INIT(NULL);
|
EXTERN isc_socketmgr_t * named_g_socketmgr INIT(NULL);
|
||||||
|
EXTERN isc_nm_t * named_g_nm INIT(NULL);
|
||||||
EXTERN cfg_parser_t * named_g_parser INIT(NULL);
|
EXTERN cfg_parser_t * named_g_parser INIT(NULL);
|
||||||
EXTERN cfg_parser_t * named_g_addparser INIT(NULL);
|
EXTERN cfg_parser_t * named_g_addparser INIT(NULL);
|
||||||
EXTERN const char * named_g_version INIT(VERSION);
|
EXTERN const char * named_g_version INIT(VERSION);
|
||||||
@@ -135,14 +137,6 @@ EXTERN const char * named_g_defaultpidfile INIT(NAMED_LOCALSTATEDIR
|
|||||||
"/run/named.pid");
|
"/run/named.pid");
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifdef HAVE_DNSTAP
|
|
||||||
EXTERN const char * named_g_defaultdnstap
|
|
||||||
INIT(NAMED_LOCALSTATEDIR "/run/named/"
|
|
||||||
"dnstap.sock");
|
|
||||||
#else
|
|
||||||
EXTERN const char * named_g_defaultdnstap INIT(NULL);
|
|
||||||
#endif /* HAVE_DNSTAP */
|
|
||||||
|
|
||||||
EXTERN const char * named_g_username INIT(NULL);
|
EXTERN const char * named_g_username INIT(NULL);
|
||||||
|
|
||||||
EXTERN const char * named_g_engine INIT(NULL);
|
EXTERN const char * named_g_engine INIT(NULL);
|
||||||
|
|||||||
@@ -64,6 +64,7 @@ struct named_server {
|
|||||||
dns_loadmgr_t * loadmgr;
|
dns_loadmgr_t * loadmgr;
|
||||||
dns_zonemgr_t * zonemgr;
|
dns_zonemgr_t * zonemgr;
|
||||||
dns_viewlist_t viewlist;
|
dns_viewlist_t viewlist;
|
||||||
|
dns_kasplist_t kasplist;
|
||||||
ns_interfacemgr_t * interfacemgr;
|
ns_interfacemgr_t * interfacemgr;
|
||||||
dns_db_t * in_roothints;
|
dns_db_t * in_roothints;
|
||||||
|
|
||||||
|
|||||||
@@ -27,19 +27,18 @@ ISC_LANG_BEGINDECLS
|
|||||||
isc_result_t
|
isc_result_t
|
||||||
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
||||||
dns_zone_t *zone, dns_zone_t *raw);
|
dns_kasplist_t* kasplist, dns_zone_t *zone,
|
||||||
|
dns_zone_t *raw);
|
||||||
/*%<
|
/*%<
|
||||||
* Configure or reconfigure a zone according to the named.conf
|
* Configure or reconfigure a zone according to the named.conf
|
||||||
* data in 'cctx' and 'czone'.
|
* data.
|
||||||
*
|
*
|
||||||
* The zone origin is not configured, it is assumed to have been set
|
* The zone origin is not configured, it is assumed to have been set
|
||||||
* at zone creation time.
|
* at zone creation time.
|
||||||
*
|
*
|
||||||
* Require:
|
* Require:
|
||||||
* \li 'lctx' to be initialized or NULL.
|
|
||||||
* \li 'cctx' to be initialized or NULL.
|
|
||||||
* \li 'ac' to point to an initialized cfg_aclconfctx_t.
|
* \li 'ac' to point to an initialized cfg_aclconfctx_t.
|
||||||
* \li 'czone' to be initialized.
|
* \li 'kasplist' to be initialized.
|
||||||
* \li 'zone' to be initialized.
|
* \li 'zone' to be initialized.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
|||||||
+46
-12
@@ -24,6 +24,7 @@
|
|||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/httpd.h>
|
#include <isc/httpd.h>
|
||||||
|
#include <isc/netmgr.h>
|
||||||
#include <isc/os.h>
|
#include <isc/os.h>
|
||||||
#include <isc/platform.h>
|
#include <isc/platform.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
@@ -67,6 +68,7 @@
|
|||||||
#include <ns/interfacemgr.h>
|
#include <ns/interfacemgr.h>
|
||||||
|
|
||||||
#include <named/builtin.h>
|
#include <named/builtin.h>
|
||||||
|
#include <named/config.h>
|
||||||
#include <named/control.h>
|
#include <named/control.h>
|
||||||
#include <named/fuzz.h>
|
#include <named/fuzz.h>
|
||||||
#include <named/globals.h> /* Explicit, though named/log.h includes it. */
|
#include <named/globals.h> /* Explicit, though named/log.h includes it. */
|
||||||
@@ -123,7 +125,6 @@ static int maxudp = 0;
|
|||||||
/*
|
/*
|
||||||
* -T options:
|
* -T options:
|
||||||
*/
|
*/
|
||||||
static bool clienttest = false;
|
|
||||||
static bool dropedns = false;
|
static bool dropedns = false;
|
||||||
static bool ednsformerr = false;
|
static bool ednsformerr = false;
|
||||||
static bool ednsnotimp = false;
|
static bool ednsnotimp = false;
|
||||||
@@ -483,6 +484,12 @@ set_flags(const char *arg, struct flag_def *defs, unsigned int *ret) {
|
|||||||
static void
|
static void
|
||||||
printversion(bool verbose) {
|
printversion(bool verbose) {
|
||||||
char rndcconf[PATH_MAX], *dot = NULL;
|
char rndcconf[PATH_MAX], *dot = NULL;
|
||||||
|
#if defined(HAVE_GEOIP2)
|
||||||
|
isc_mem_t *mctx = NULL;
|
||||||
|
cfg_parser_t *parser = NULL;
|
||||||
|
cfg_obj_t *config = NULL;
|
||||||
|
const cfg_obj_t *defaults = NULL, *obj = NULL;
|
||||||
|
#endif
|
||||||
|
|
||||||
printf("%s %s%s%s <id:%s>\n",
|
printf("%s %s%s%s <id:%s>\n",
|
||||||
named_g_product, named_g_version,
|
named_g_product, named_g_version,
|
||||||
@@ -569,7 +576,20 @@ OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
|
|||||||
printf(" nsupdate session key: %s\n", named_g_defaultsessionkeyfile);
|
printf(" nsupdate session key: %s\n", named_g_defaultsessionkeyfile);
|
||||||
printf(" named PID file: %s\n", named_g_defaultpidfile);
|
printf(" named PID file: %s\n", named_g_defaultpidfile);
|
||||||
printf(" named lock file: %s\n", named_g_defaultlockfile);
|
printf(" named lock file: %s\n", named_g_defaultlockfile);
|
||||||
|
#if defined(HAVE_GEOIP2)
|
||||||
|
#define RTC(x) RUNTIME_CHECK((x) == ISC_R_SUCCESS)
|
||||||
|
isc_mem_create(&mctx);
|
||||||
|
RTC(cfg_parser_create(mctx, named_g_lctx, &parser));
|
||||||
|
RTC(named_config_parsedefaults(parser, &config));
|
||||||
|
RTC(cfg_map_get(config, "options", &defaults));
|
||||||
|
RTC(cfg_map_get(defaults, "geoip-directory", &obj));
|
||||||
|
if (cfg_obj_isstring(obj)) {
|
||||||
|
printf(" geoip-directory: %s\n", cfg_obj_asstring(obj));
|
||||||
|
}
|
||||||
|
cfg_obj_destroy(parser, &config);
|
||||||
|
cfg_parser_destroy(&parser);
|
||||||
|
isc_mem_detach(&mctx);
|
||||||
|
#endif /* HAVE_GEOIP2 */
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -602,17 +622,12 @@ parse_T_opt(char *option) {
|
|||||||
/*
|
/*
|
||||||
* force the server to behave (or misbehave) in
|
* force the server to behave (or misbehave) in
|
||||||
* specified ways for testing purposes.
|
* specified ways for testing purposes.
|
||||||
*
|
|
||||||
* clienttest: make clients single shot with their
|
|
||||||
* own memory context.
|
|
||||||
* delay=xxxx: delay client responses by xxxx ms to
|
* delay=xxxx: delay client responses by xxxx ms to
|
||||||
* simulate remote servers.
|
* simulate remote servers.
|
||||||
* dscp=x: check that dscp values are as
|
* dscp=x: check that dscp values are as
|
||||||
* expected and assert otherwise.
|
* expected and assert otherwise.
|
||||||
*/
|
*/
|
||||||
if (!strcmp(option, "clienttest")) {
|
if (!strncmp(option, "delay=", 6)) {
|
||||||
clienttest = true;
|
|
||||||
} else if (!strncmp(option, "delay=", 6)) {
|
|
||||||
delay = atoi(option + 6);
|
delay = atoi(option + 6);
|
||||||
} else if (!strcmp(option, "dropedns")) {
|
} else if (!strcmp(option, "dropedns")) {
|
||||||
dropedns = true;
|
dropedns = true;
|
||||||
@@ -877,8 +892,15 @@ create_managers(void) {
|
|||||||
"using %u UDP listener%s per interface",
|
"using %u UDP listener%s per interface",
|
||||||
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
|
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
|
||||||
|
|
||||||
|
named_g_nm = isc_nm_start(named_g_mctx, named_g_cpus);
|
||||||
|
if (named_g_nm == NULL) {
|
||||||
|
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
||||||
|
"isc_nm_start() failed");
|
||||||
|
return (ISC_R_UNEXPECTED);
|
||||||
|
}
|
||||||
|
|
||||||
result = isc_taskmgr_create(named_g_mctx, named_g_cpus, 0,
|
result = isc_taskmgr_create(named_g_mctx, named_g_cpus, 0,
|
||||||
&named_g_taskmgr);
|
named_g_nm, &named_g_taskmgr);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
||||||
"isc_taskmgr_create() failed: %s",
|
"isc_taskmgr_create() failed: %s",
|
||||||
@@ -903,6 +925,7 @@ create_managers(void) {
|
|||||||
return (ISC_R_UNEXPECTED);
|
return (ISC_R_UNEXPECTED);
|
||||||
}
|
}
|
||||||
isc_socketmgr_maxudp(named_g_socketmgr, maxudp);
|
isc_socketmgr_maxudp(named_g_socketmgr, maxudp);
|
||||||
|
isc_nm_maxudp(named_g_nm, maxudp);
|
||||||
result = isc_socketmgr_getmaxsockets(named_g_socketmgr, &socks);
|
result = isc_socketmgr_getmaxsockets(named_g_socketmgr, &socks);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
@@ -916,11 +939,24 @@ create_managers(void) {
|
|||||||
static void
|
static void
|
||||||
destroy_managers(void) {
|
destroy_managers(void) {
|
||||||
/*
|
/*
|
||||||
* isc_taskmgr_destroy() will block until all tasks have exited,
|
* isc_nm_closedown() closes all active connections, freeing
|
||||||
|
* attached clients and other resources and preventing new
|
||||||
|
* connections from being established, but it not does not
|
||||||
|
* stop all processing or destroy the netmgr yet.
|
||||||
|
*/
|
||||||
|
isc_nm_closedown(named_g_nm);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* isc_taskmgr_destroy() will block until all tasks have exited.
|
||||||
*/
|
*/
|
||||||
isc_taskmgr_destroy(&named_g_taskmgr);
|
isc_taskmgr_destroy(&named_g_taskmgr);
|
||||||
isc_timermgr_destroy(&named_g_timermgr);
|
isc_timermgr_destroy(&named_g_timermgr);
|
||||||
isc_socketmgr_destroy(&named_g_socketmgr);
|
isc_socketmgr_destroy(&named_g_socketmgr);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* At this point is safe to destroy the netmgr.
|
||||||
|
*/
|
||||||
|
isc_nm_destroy(&named_g_nm);
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -1234,8 +1270,6 @@ setup(void) {
|
|||||||
/*
|
/*
|
||||||
* Modify server context according to command line options
|
* Modify server context according to command line options
|
||||||
*/
|
*/
|
||||||
if (clienttest)
|
|
||||||
ns_server_setoption(sctx, NS_SERVER_CLIENTTEST, true);
|
|
||||||
if (disable4)
|
if (disable4)
|
||||||
ns_server_setoption(sctx, NS_SERVER_DISABLE4, true);
|
ns_server_setoption(sctx, NS_SERVER_DISABLE4, true);
|
||||||
if (disable6)
|
if (disable6)
|
||||||
|
|||||||
+73
-44
@@ -10,12 +10,12 @@
|
|||||||
.\" Title: named.conf
|
.\" Title: named.conf
|
||||||
.\" Author:
|
.\" Author:
|
||||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||||
.\" Date: 2019-08-07
|
.\" Date: 2019-08-12
|
||||||
.\" Manual: BIND9
|
.\" Manual: BIND9
|
||||||
.\" Source: ISC
|
.\" Source: ISC
|
||||||
.\" Language: English
|
.\" Language: English
|
||||||
.\"
|
.\"
|
||||||
.TH "NAMED\&.CONF" "5" "2019\-08\-07" "ISC" "BIND9"
|
.TH "NAMED\&.CONF" "5" "2019\-08\-12" "ISC" "BIND9"
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
.\" * Define some portability stuff
|
.\" * Define some portability stuff
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
@@ -104,7 +104,8 @@ dlz \fIstring\fR {
|
|||||||
.\}
|
.\}
|
||||||
.nf
|
.nf
|
||||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
dnssec\-keys { \fIstring\fR ( static\-key |
|
||||||
initial\-key ) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
initial\-key | static\-ds | initial\-ds )
|
||||||
|
\fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||||
\fIquoted_string\fR; \&.\&.\&. };
|
\fIquoted_string\fR; \&.\&.\&. };
|
||||||
.fi
|
.fi
|
||||||
.if n \{\
|
.if n \{\
|
||||||
@@ -170,9 +171,9 @@ Deprecated \- see DNSSEC\-KEYS\&.
|
|||||||
.\}
|
.\}
|
||||||
.nf
|
.nf
|
||||||
managed\-keys { \fIstring\fR ( static\-key
|
managed\-keys { \fIstring\fR ( static\-key
|
||||||
| initial\-key ) \fIinteger\fR
|
| initial\-key | static\-ds |
|
||||||
\fIinteger\fR \fIinteger\fR
|
initial\-ds ) \fIinteger\fR \fIinteger\fR
|
||||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||||
.fi
|
.fi
|
||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
@@ -230,7 +231,7 @@ options {
|
|||||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||||
check\-dup\-records ( fail | warn | ignore );
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
check\-integrity \fIboolean\fR;
|
check\-integrity \fIboolean\fR;
|
||||||
check\-mx ( fail | warn | ignore );
|
check\-mx ( fail | warn | ignore );
|
||||||
@@ -312,18 +313,18 @@ options {
|
|||||||
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
|
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
|
||||||
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
|
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
|
||||||
fstrm\-set\-output\-queue\-size \fIinteger\fR;
|
fstrm\-set\-output\-queue\-size \fIinteger\fR;
|
||||||
fstrm\-set\-reopen\-interval \fIttlval\fR;
|
fstrm\-set\-reopen\-interval \fIduration\fR;
|
||||||
geoip\-directory ( \fIquoted_string\fR | none );
|
geoip\-directory ( \fIquoted_string\fR | none );
|
||||||
glue\-cache \fIboolean\fR;
|
glue\-cache \fIboolean\fR;
|
||||||
heartbeat\-interval \fIinteger\fR;
|
heartbeat\-interval \fIinteger\fR;
|
||||||
hostname ( \fIquoted_string\fR | none );
|
hostname ( \fIquoted_string\fR | none );
|
||||||
inline\-signing \fIboolean\fR;
|
inline\-signing \fIboolean\fR;
|
||||||
interface\-interval \fIttlval\fR;
|
interface\-interval \fIduration\fR;
|
||||||
ixfr\-from\-differences ( primary | master | secondary | slave |
|
ixfr\-from\-differences ( primary | master | secondary | slave |
|
||||||
\fIboolean\fR );
|
\fIboolean\fR );
|
||||||
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
|
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
key\-directory \fIquoted_string\fR;
|
key\-directory \fIquoted_string\fR;
|
||||||
lame\-ttl \fIttlval\fR;
|
lame\-ttl \fIduration\fR;
|
||||||
listen\-on [ port \fIinteger\fR ] [ dscp
|
listen\-on [ port \fIinteger\fR ] [ dscp
|
||||||
\fIinteger\fR ] {
|
\fIinteger\fR ] {
|
||||||
\fIaddress_match_element\fR; \&.\&.\&. };
|
\fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
@@ -337,28 +338,28 @@ options {
|
|||||||
masterfile\-style ( full | relative );
|
masterfile\-style ( full | relative );
|
||||||
match\-mapped\-addresses \fIboolean\fR;
|
match\-mapped\-addresses \fIboolean\fR;
|
||||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||||
max\-cache\-ttl \fIttlval\fR;
|
max\-cache\-ttl \fIduration\fR;
|
||||||
max\-clients\-per\-query \fIinteger\fR;
|
max\-clients\-per\-query \fIinteger\fR;
|
||||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||||
max\-ncache\-ttl \fIttlval\fR;
|
max\-ncache\-ttl \fIduration\fR;
|
||||||
max\-records \fIinteger\fR;
|
max\-records \fIinteger\fR;
|
||||||
max\-recursion\-depth \fIinteger\fR;
|
max\-recursion\-depth \fIinteger\fR;
|
||||||
max\-recursion\-queries \fIinteger\fR;
|
max\-recursion\-queries \fIinteger\fR;
|
||||||
max\-refresh\-time \fIinteger\fR;
|
max\-refresh\-time \fIinteger\fR;
|
||||||
max\-retry\-time \fIinteger\fR;
|
max\-retry\-time \fIinteger\fR;
|
||||||
max\-rsa\-exponent\-size \fIinteger\fR;
|
max\-rsa\-exponent\-size \fIinteger\fR;
|
||||||
max\-stale\-ttl \fIttlval\fR;
|
max\-stale\-ttl \fIduration\fR;
|
||||||
max\-transfer\-idle\-in \fIinteger\fR;
|
max\-transfer\-idle\-in \fIinteger\fR;
|
||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-udp\-size \fIinteger\fR;
|
max\-udp\-size \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
memstatistics \fIboolean\fR;
|
memstatistics \fIboolean\fR;
|
||||||
memstatistics\-file \fIquoted_string\fR;
|
memstatistics\-file \fIquoted_string\fR;
|
||||||
message\-compression \fIboolean\fR;
|
message\-compression \fIboolean\fR;
|
||||||
min\-cache\-ttl \fIttlval\fR;
|
min\-cache\-ttl \fIduration\fR;
|
||||||
min\-ncache\-ttl \fIttlval\fR;
|
min\-ncache\-ttl \fIduration\fR;
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
minimal\-any \fIboolean\fR;
|
minimal\-any \fIboolean\fR;
|
||||||
@@ -375,8 +376,8 @@ options {
|
|||||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||||
[ dscp \fIinteger\fR ];
|
[ dscp \fIinteger\fR ];
|
||||||
notify\-to\-soa \fIboolean\fR;
|
notify\-to\-soa \fIboolean\fR;
|
||||||
nta\-lifetime \fIttlval\fR;
|
nta\-lifetime \fIduration\fR;
|
||||||
nta\-recheck \fIttlval\fR;
|
nta\-recheck \fIduration\fR;
|
||||||
nxdomain\-redirect \fIstring\fR;
|
nxdomain\-redirect \fIstring\fR;
|
||||||
pid\-file ( \fIquoted_string\fR | none );
|
pid\-file ( \fIquoted_string\fR | none );
|
||||||
port \fIinteger\fR;
|
port \fIinteger\fR;
|
||||||
@@ -423,13 +424,13 @@ options {
|
|||||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||||
\fIinteger\fR;
|
\fIinteger\fR;
|
||||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||||
@@ -443,7 +444,7 @@ options {
|
|||||||
serial\-query\-rate \fIinteger\fR;
|
serial\-query\-rate \fIinteger\fR;
|
||||||
serial\-update\-method ( date | increment | unixtime );
|
serial\-update\-method ( date | increment | unixtime );
|
||||||
server\-id ( \fIquoted_string\fR | none | hostname );
|
server\-id ( \fIquoted_string\fR | none | hostname );
|
||||||
servfail\-ttl \fIttlval\fR;
|
servfail\-ttl \fIduration\fR;
|
||||||
session\-keyalg \fIstring\fR;
|
session\-keyalg \fIstring\fR;
|
||||||
session\-keyfile ( \fIquoted_string\fR | none );
|
session\-keyfile ( \fIquoted_string\fR | none );
|
||||||
session\-keyname \fIstring\fR;
|
session\-keyname \fIstring\fR;
|
||||||
@@ -454,7 +455,7 @@ options {
|
|||||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
stacksize ( default | unlimited | \fIsizeval\fR );
|
stacksize ( default | unlimited | \fIsizeval\fR );
|
||||||
stale\-answer\-enable \fIboolean\fR;
|
stale\-answer\-enable \fIboolean\fR;
|
||||||
stale\-answer\-ttl \fIttlval\fR;
|
stale\-answer\-ttl \fIduration\fR;
|
||||||
startup\-notify\-rate \fIinteger\fR;
|
startup\-notify\-rate \fIinteger\fR;
|
||||||
statistics\-file \fIquoted_string\fR;
|
statistics\-file \fIquoted_string\fR;
|
||||||
synth\-from\-dnssec \fIboolean\fR;
|
synth\-from\-dnssec \fIboolean\fR;
|
||||||
@@ -612,7 +613,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||||
check\-dup\-records ( fail | warn | ignore );
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
check\-integrity \fIboolean\fR;
|
check\-integrity \fIboolean\fR;
|
||||||
check\-mx ( fail | warn | ignore );
|
check\-mx ( fail | warn | ignore );
|
||||||
@@ -655,8 +656,9 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnssec\-accept\-expired \fIboolean\fR;
|
dnssec\-accept\-expired \fIboolean\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
dnssec\-keys { \fIstring\fR ( static\-key |
|
||||||
initial\-key ) \fIinteger\fR \fIinteger\fR
|
initial\-key | static\-ds | initial\-ds
|
||||||
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. };
|
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||||
|
\fIquoted_string\fR; \&.\&.\&. };
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
|
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
@@ -690,10 +692,11 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
secret \fIstring\fR;
|
secret \fIstring\fR;
|
||||||
};
|
};
|
||||||
key\-directory \fIquoted_string\fR;
|
key\-directory \fIquoted_string\fR;
|
||||||
lame\-ttl \fIttlval\fR;
|
lame\-ttl \fIduration\fR;
|
||||||
lmdb\-mapsize \fIsizeval\fR;
|
lmdb\-mapsize \fIsizeval\fR;
|
||||||
managed\-keys { \fIstring\fR (
|
managed\-keys { \fIstring\fR (
|
||||||
static\-key | initial\-key
|
static\-key | initial\-key
|
||||||
|
| static\-ds | initial\-ds
|
||||||
) \fIinteger\fR \fIinteger\fR
|
) \fIinteger\fR \fIinteger\fR
|
||||||
\fIinteger\fR
|
\fIinteger\fR
|
||||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||||
@@ -703,25 +706,25 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
|
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
match\-recursive\-only \fIboolean\fR;
|
match\-recursive\-only \fIboolean\fR;
|
||||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||||
max\-cache\-ttl \fIttlval\fR;
|
max\-cache\-ttl \fIduration\fR;
|
||||||
max\-clients\-per\-query \fIinteger\fR;
|
max\-clients\-per\-query \fIinteger\fR;
|
||||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||||
max\-ncache\-ttl \fIttlval\fR;
|
max\-ncache\-ttl \fIduration\fR;
|
||||||
max\-records \fIinteger\fR;
|
max\-records \fIinteger\fR;
|
||||||
max\-recursion\-depth \fIinteger\fR;
|
max\-recursion\-depth \fIinteger\fR;
|
||||||
max\-recursion\-queries \fIinteger\fR;
|
max\-recursion\-queries \fIinteger\fR;
|
||||||
max\-refresh\-time \fIinteger\fR;
|
max\-refresh\-time \fIinteger\fR;
|
||||||
max\-retry\-time \fIinteger\fR;
|
max\-retry\-time \fIinteger\fR;
|
||||||
max\-stale\-ttl \fIttlval\fR;
|
max\-stale\-ttl \fIduration\fR;
|
||||||
max\-transfer\-idle\-in \fIinteger\fR;
|
max\-transfer\-idle\-in \fIinteger\fR;
|
||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-udp\-size \fIinteger\fR;
|
max\-udp\-size \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
message\-compression \fIboolean\fR;
|
message\-compression \fIboolean\fR;
|
||||||
min\-cache\-ttl \fIttlval\fR;
|
min\-cache\-ttl \fIduration\fR;
|
||||||
min\-ncache\-ttl \fIttlval\fR;
|
min\-ncache\-ttl \fIduration\fR;
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
minimal\-any \fIboolean\fR;
|
minimal\-any \fIboolean\fR;
|
||||||
@@ -737,8 +740,8 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||||
[ dscp \fIinteger\fR ];
|
[ dscp \fIinteger\fR ];
|
||||||
notify\-to\-soa \fIboolean\fR;
|
notify\-to\-soa \fIboolean\fR;
|
||||||
nta\-lifetime \fIttlval\fR;
|
nta\-lifetime \fIduration\fR;
|
||||||
nta\-recheck \fIttlval\fR;
|
nta\-recheck \fIduration\fR;
|
||||||
nxdomain\-redirect \fIstring\fR;
|
nxdomain\-redirect \fIstring\fR;
|
||||||
plugin ( query ) \fIstring\fR [ {
|
plugin ( query ) \fIstring\fR [ {
|
||||||
\fIunspecified\-text\fR } ];
|
\fIunspecified\-text\fR } ];
|
||||||
@@ -780,13 +783,13 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||||
\fIinteger\fR;
|
\fIinteger\fR;
|
||||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||||
@@ -831,14 +834,14 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
\fIinteger\fR | * ) ] [ dscp \fIinteger\fR ];
|
\fIinteger\fR | * ) ] [ dscp \fIinteger\fR ];
|
||||||
transfers \fIinteger\fR;
|
transfers \fIinteger\fR;
|
||||||
};
|
};
|
||||||
servfail\-ttl \fIttlval\fR;
|
servfail\-ttl \fIduration\fR;
|
||||||
sig\-signing\-nodes \fIinteger\fR;
|
sig\-signing\-nodes \fIinteger\fR;
|
||||||
sig\-signing\-signatures \fIinteger\fR;
|
sig\-signing\-signatures \fIinteger\fR;
|
||||||
sig\-signing\-type \fIinteger\fR;
|
sig\-signing\-type \fIinteger\fR;
|
||||||
sig\-validity\-interval \fIinteger\fR [ \fIinteger\fR ];
|
sig\-validity\-interval \fIinteger\fR [ \fIinteger\fR ];
|
||||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
stale\-answer\-enable \fIboolean\fR;
|
stale\-answer\-enable \fIboolean\fR;
|
||||||
stale\-answer\-ttl \fIttlval\fR;
|
stale\-answer\-ttl \fIduration\fR;
|
||||||
synth\-from\-dnssec \fIboolean\fR;
|
synth\-from\-dnssec \fIboolean\fR;
|
||||||
transfer\-format ( many\-answers | one\-answer );
|
transfer\-format ( many\-answers | one\-answer );
|
||||||
transfer\-source ( \fIipv4_address\fR | * ) [ port ( \fIinteger\fR | * ) ] [
|
transfer\-source ( \fIipv4_address\fR | * ) [ port ( \fIinteger\fR | * ) ] [
|
||||||
@@ -890,6 +893,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnskey\-sig\-validity \fIinteger\fR;
|
dnskey\-sig\-validity \fIinteger\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
|
dnssec\-policy \fIstring\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
dnssec\-update\-mode ( maintain | no\-resign );
|
dnssec\-update\-mode ( maintain | no\-resign );
|
||||||
file \fIquoted_string\fR;
|
file \fIquoted_string\fR;
|
||||||
@@ -915,7 +919,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
multi\-master \fIboolean\fR;
|
multi\-master \fIboolean\fR;
|
||||||
@@ -996,6 +1000,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnskey\-sig\-validity \fIinteger\fR;
|
dnskey\-sig\-validity \fIinteger\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
|
dnssec\-policy \fIstring\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
dnssec\-update\-mode ( maintain | no\-resign );
|
dnssec\-update\-mode ( maintain | no\-resign );
|
||||||
file \fIquoted_string\fR;
|
file \fIquoted_string\fR;
|
||||||
@@ -1020,7 +1025,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
multi\-master \fIboolean\fR;
|
multi\-master \fIboolean\fR;
|
||||||
@@ -1062,6 +1067,30 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
.\}
|
.\}
|
||||||
|
.SH "DNSSEC-POLICY"
|
||||||
|
.sp
|
||||||
|
.if n \{\
|
||||||
|
.RS 4
|
||||||
|
.\}
|
||||||
|
.nf
|
||||||
|
dnssec\-policy \fIstring\fR {
|
||||||
|
dnskey\-ttl \fIttlval\fR;
|
||||||
|
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
|
||||||
|
parent\-ds\-ttl \fIduration\fR;
|
||||||
|
parent\-propagation\-delay \fIduration\fR;
|
||||||
|
parent\-registration\-delay \fIduration\fR;
|
||||||
|
publish\-safety \fIduration\fR;
|
||||||
|
retire\-safety \fIduration\fR;
|
||||||
|
signatures\-refresh \fIduration\fR;
|
||||||
|
signatures\-validity \fIduration\fR;
|
||||||
|
signatures\-validity\-dnskey \fIduration\fR;
|
||||||
|
zone\-max\-ttl \fIduration\fR;
|
||||||
|
zone\-propagation\-delay \fIduration\fR;
|
||||||
|
};
|
||||||
|
.fi
|
||||||
|
.if n \{\
|
||||||
|
.RE
|
||||||
|
.\}
|
||||||
.SH "FILES"
|
.SH "FILES"
|
||||||
.PP
|
.PP
|
||||||
/etc/named\&.conf
|
/etc/named\&.conf
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
|
|
||||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
||||||
<info>
|
<info>
|
||||||
<date>2019-08-07</date>
|
<date>2019-08-12</date>
|
||||||
</info>
|
</info>
|
||||||
<refentryinfo>
|
<refentryinfo>
|
||||||
<corpname>ISC</corpname>
|
<corpname>ISC</corpname>
|
||||||
@@ -113,7 +113,8 @@ dlz <replaceable>string</replaceable> {
|
|||||||
<refsection><info><title>DNSSEC-KEYS</title></info>
|
<refsection><info><title>DNSSEC-KEYS</title></info>
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
||||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
initial-key | static-ds | initial-ds )
|
||||||
|
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>quoted_string</replaceable>; ... };
|
<replaceable>quoted_string</replaceable>; ... };
|
||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
@@ -158,9 +159,9 @@ logging {
|
|||||||
<para>Deprecated - see DNSSEC-KEYS.</para>
|
<para>Deprecated - see DNSSEC-KEYS.</para>
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
managed-keys { <replaceable>string</replaceable> ( static-key
|
managed-keys { <replaceable>string</replaceable> ( static-key
|
||||||
| initial-key ) <replaceable>integer</replaceable>
|
| initial-key | static-ds |
|
||||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
initial-ds ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
@@ -208,7 +209,7 @@ options {
|
|||||||
[ dscp <replaceable>integer</replaceable> ] { ( <replaceable>masters</replaceable> | <replaceable>ipv4_address</replaceable> [ port
|
[ dscp <replaceable>integer</replaceable> ] { ( <replaceable>masters</replaceable> | <replaceable>ipv4_address</replaceable> [ port
|
||||||
<replaceable>integer</replaceable> ] | <replaceable>ipv6_address</replaceable> [ port <replaceable>integer</replaceable> ] ) [ key
|
<replaceable>integer</replaceable> ] | <replaceable>ipv6_address</replaceable> [ port <replaceable>integer</replaceable> ] ) [ key
|
||||||
<replaceable>string</replaceable> ]; ... } ] [ zone-directory <replaceable>quoted_string</replaceable> ] [
|
<replaceable>string</replaceable> ]; ... } ] [ zone-directory <replaceable>quoted_string</replaceable> ] [
|
||||||
in-memory <replaceable>boolean</replaceable> ] [ min-update-interval <replaceable>ttlval</replaceable> ]; ... };
|
in-memory <replaceable>boolean</replaceable> ] [ min-update-interval <replaceable>duration</replaceable> ]; ... };
|
||||||
check-dup-records ( fail | warn | ignore );
|
check-dup-records ( fail | warn | ignore );
|
||||||
check-integrity <replaceable>boolean</replaceable>;
|
check-integrity <replaceable>boolean</replaceable>;
|
||||||
check-mx ( fail | warn | ignore );
|
check-mx ( fail | warn | ignore );
|
||||||
@@ -290,18 +291,18 @@ options {
|
|||||||
fstrm-set-output-notify-threshold <replaceable>integer</replaceable>;
|
fstrm-set-output-notify-threshold <replaceable>integer</replaceable>;
|
||||||
fstrm-set-output-queue-model ( mpsc | spsc );
|
fstrm-set-output-queue-model ( mpsc | spsc );
|
||||||
fstrm-set-output-queue-size <replaceable>integer</replaceable>;
|
fstrm-set-output-queue-size <replaceable>integer</replaceable>;
|
||||||
fstrm-set-reopen-interval <replaceable>ttlval</replaceable>;
|
fstrm-set-reopen-interval <replaceable>duration</replaceable>;
|
||||||
geoip-directory ( <replaceable>quoted_string</replaceable> | none );
|
geoip-directory ( <replaceable>quoted_string</replaceable> | none );
|
||||||
glue-cache <replaceable>boolean</replaceable>;
|
glue-cache <replaceable>boolean</replaceable>;
|
||||||
heartbeat-interval <replaceable>integer</replaceable>;
|
heartbeat-interval <replaceable>integer</replaceable>;
|
||||||
hostname ( <replaceable>quoted_string</replaceable> | none );
|
hostname ( <replaceable>quoted_string</replaceable> | none );
|
||||||
inline-signing <replaceable>boolean</replaceable>;
|
inline-signing <replaceable>boolean</replaceable>;
|
||||||
interface-interval <replaceable>ttlval</replaceable>;
|
interface-interval <replaceable>duration</replaceable>;
|
||||||
ixfr-from-differences ( primary | master | secondary | slave |
|
ixfr-from-differences ( primary | master | secondary | slave |
|
||||||
<replaceable>boolean</replaceable> );
|
<replaceable>boolean</replaceable> );
|
||||||
keep-response-order { <replaceable>address_match_element</replaceable>; ... };
|
keep-response-order { <replaceable>address_match_element</replaceable>; ... };
|
||||||
key-directory <replaceable>quoted_string</replaceable>;
|
key-directory <replaceable>quoted_string</replaceable>;
|
||||||
lame-ttl <replaceable>ttlval</replaceable>;
|
lame-ttl <replaceable>duration</replaceable>;
|
||||||
listen-on [ port <replaceable>integer</replaceable> ] [ dscp
|
listen-on [ port <replaceable>integer</replaceable> ] [ dscp
|
||||||
<replaceable>integer</replaceable> ] {
|
<replaceable>integer</replaceable> ] {
|
||||||
<replaceable>address_match_element</replaceable>; ... };
|
<replaceable>address_match_element</replaceable>; ... };
|
||||||
@@ -315,28 +316,28 @@ options {
|
|||||||
masterfile-style ( full | relative );
|
masterfile-style ( full | relative );
|
||||||
match-mapped-addresses <replaceable>boolean</replaceable>;
|
match-mapped-addresses <replaceable>boolean</replaceable>;
|
||||||
max-cache-size ( default | unlimited | <replaceable>sizeval</replaceable> | <replaceable>percentage</replaceable> );
|
max-cache-size ( default | unlimited | <replaceable>sizeval</replaceable> | <replaceable>percentage</replaceable> );
|
||||||
max-cache-ttl <replaceable>ttlval</replaceable>;
|
max-cache-ttl <replaceable>duration</replaceable>;
|
||||||
max-clients-per-query <replaceable>integer</replaceable>;
|
max-clients-per-query <replaceable>integer</replaceable>;
|
||||||
max-journal-size ( default | unlimited | <replaceable>sizeval</replaceable> );
|
max-journal-size ( default | unlimited | <replaceable>sizeval</replaceable> );
|
||||||
max-ncache-ttl <replaceable>ttlval</replaceable>;
|
max-ncache-ttl <replaceable>duration</replaceable>;
|
||||||
max-records <replaceable>integer</replaceable>;
|
max-records <replaceable>integer</replaceable>;
|
||||||
max-recursion-depth <replaceable>integer</replaceable>;
|
max-recursion-depth <replaceable>integer</replaceable>;
|
||||||
max-recursion-queries <replaceable>integer</replaceable>;
|
max-recursion-queries <replaceable>integer</replaceable>;
|
||||||
max-refresh-time <replaceable>integer</replaceable>;
|
max-refresh-time <replaceable>integer</replaceable>;
|
||||||
max-retry-time <replaceable>integer</replaceable>;
|
max-retry-time <replaceable>integer</replaceable>;
|
||||||
max-rsa-exponent-size <replaceable>integer</replaceable>;
|
max-rsa-exponent-size <replaceable>integer</replaceable>;
|
||||||
max-stale-ttl <replaceable>ttlval</replaceable>;
|
max-stale-ttl <replaceable>duration</replaceable>;
|
||||||
max-transfer-idle-in <replaceable>integer</replaceable>;
|
max-transfer-idle-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-idle-out <replaceable>integer</replaceable>;
|
max-transfer-idle-out <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-in <replaceable>integer</replaceable>;
|
max-transfer-time-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-out <replaceable>integer</replaceable>;
|
max-transfer-time-out <replaceable>integer</replaceable>;
|
||||||
max-udp-size <replaceable>integer</replaceable>;
|
max-udp-size <replaceable>integer</replaceable>;
|
||||||
max-zone-ttl ( unlimited | <replaceable>ttlval</replaceable> );
|
max-zone-ttl ( unlimited | <replaceable>duration</replaceable> );
|
||||||
memstatistics <replaceable>boolean</replaceable>;
|
memstatistics <replaceable>boolean</replaceable>;
|
||||||
memstatistics-file <replaceable>quoted_string</replaceable>;
|
memstatistics-file <replaceable>quoted_string</replaceable>;
|
||||||
message-compression <replaceable>boolean</replaceable>;
|
message-compression <replaceable>boolean</replaceable>;
|
||||||
min-cache-ttl <replaceable>ttlval</replaceable>;
|
min-cache-ttl <replaceable>duration</replaceable>;
|
||||||
min-ncache-ttl <replaceable>ttlval</replaceable>;
|
min-ncache-ttl <replaceable>duration</replaceable>;
|
||||||
min-refresh-time <replaceable>integer</replaceable>;
|
min-refresh-time <replaceable>integer</replaceable>;
|
||||||
min-retry-time <replaceable>integer</replaceable>;
|
min-retry-time <replaceable>integer</replaceable>;
|
||||||
minimal-any <replaceable>boolean</replaceable>;
|
minimal-any <replaceable>boolean</replaceable>;
|
||||||
@@ -353,8 +354,8 @@ options {
|
|||||||
notify-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ]
|
notify-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ]
|
||||||
[ dscp <replaceable>integer</replaceable> ];
|
[ dscp <replaceable>integer</replaceable> ];
|
||||||
notify-to-soa <replaceable>boolean</replaceable>;
|
notify-to-soa <replaceable>boolean</replaceable>;
|
||||||
nta-lifetime <replaceable>ttlval</replaceable>;
|
nta-lifetime <replaceable>duration</replaceable>;
|
||||||
nta-recheck <replaceable>ttlval</replaceable>;
|
nta-recheck <replaceable>duration</replaceable>;
|
||||||
nxdomain-redirect <replaceable>string</replaceable>;
|
nxdomain-redirect <replaceable>string</replaceable>;
|
||||||
pid-file ( <replaceable>quoted_string</replaceable> | none );
|
pid-file ( <replaceable>quoted_string</replaceable> | none );
|
||||||
port <replaceable>integer</replaceable>;
|
port <replaceable>integer</replaceable>;
|
||||||
@@ -401,13 +402,13 @@ options {
|
|||||||
response-padding { <replaceable>address_match_element</replaceable>; ... } block-size
|
response-padding { <replaceable>address_match_element</replaceable>; ... } block-size
|
||||||
<replaceable>integer</replaceable>;
|
<replaceable>integer</replaceable>;
|
||||||
response-policy { zone <replaceable>string</replaceable> [ add-soa <replaceable>boolean</replaceable> ] [ log
|
response-policy { zone <replaceable>string</replaceable> [ add-soa <replaceable>boolean</replaceable> ] [ log
|
||||||
<replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>ttlval</replaceable> ] [ min-update-interval
|
<replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>duration</replaceable> ] [ min-update-interval
|
||||||
<replaceable>ttlval</replaceable> ] [ policy ( cname | disabled | drop | given | no-op |
|
<replaceable>duration</replaceable> ] [ policy ( cname | disabled | drop | given | no-op |
|
||||||
nodata | nxdomain | passthru | tcp-only <replaceable>quoted_string</replaceable> ) ] [
|
nodata | nxdomain | passthru | tcp-only <replaceable>quoted_string</replaceable> ) ] [
|
||||||
recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
||||||
nsdname-enable <replaceable>boolean</replaceable> ]; ... } [ add-soa <replaceable>boolean</replaceable> ] [
|
nsdname-enable <replaceable>boolean</replaceable> ]; ... } [ add-soa <replaceable>boolean</replaceable> ] [
|
||||||
break-dnssec <replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>ttlval</replaceable> ] [
|
break-dnssec <replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>duration</replaceable> ] [
|
||||||
min-update-interval <replaceable>ttlval</replaceable> ] [ min-ns-dots <replaceable>integer</replaceable> ] [
|
min-update-interval <replaceable>duration</replaceable> ] [ min-ns-dots <replaceable>integer</replaceable> ] [
|
||||||
nsip-wait-recurse <replaceable>boolean</replaceable> ] [ qname-wait-recurse <replaceable>boolean</replaceable> ]
|
nsip-wait-recurse <replaceable>boolean</replaceable> ] [ qname-wait-recurse <replaceable>boolean</replaceable> ]
|
||||||
[ recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
[ recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
||||||
nsdname-enable <replaceable>boolean</replaceable> ] [ dnsrps-enable <replaceable>boolean</replaceable> ] [
|
nsdname-enable <replaceable>boolean</replaceable> ] [ dnsrps-enable <replaceable>boolean</replaceable> ] [
|
||||||
@@ -421,7 +422,7 @@ options {
|
|||||||
serial-query-rate <replaceable>integer</replaceable>;
|
serial-query-rate <replaceable>integer</replaceable>;
|
||||||
serial-update-method ( date | increment | unixtime );
|
serial-update-method ( date | increment | unixtime );
|
||||||
server-id ( <replaceable>quoted_string</replaceable> | none | hostname );
|
server-id ( <replaceable>quoted_string</replaceable> | none | hostname );
|
||||||
servfail-ttl <replaceable>ttlval</replaceable>;
|
servfail-ttl <replaceable>duration</replaceable>;
|
||||||
session-keyalg <replaceable>string</replaceable>;
|
session-keyalg <replaceable>string</replaceable>;
|
||||||
session-keyfile ( <replaceable>quoted_string</replaceable> | none );
|
session-keyfile ( <replaceable>quoted_string</replaceable> | none );
|
||||||
session-keyname <replaceable>string</replaceable>;
|
session-keyname <replaceable>string</replaceable>;
|
||||||
@@ -432,7 +433,7 @@ options {
|
|||||||
sortlist { <replaceable>address_match_element</replaceable>; ... };
|
sortlist { <replaceable>address_match_element</replaceable>; ... };
|
||||||
stacksize ( default | unlimited | <replaceable>sizeval</replaceable> );
|
stacksize ( default | unlimited | <replaceable>sizeval</replaceable> );
|
||||||
stale-answer-enable <replaceable>boolean</replaceable>;
|
stale-answer-enable <replaceable>boolean</replaceable>;
|
||||||
stale-answer-ttl <replaceable>ttlval</replaceable>;
|
stale-answer-ttl <replaceable>duration</replaceable>;
|
||||||
startup-notify-rate <replaceable>integer</replaceable>;
|
startup-notify-rate <replaceable>integer</replaceable>;
|
||||||
statistics-file <replaceable>quoted_string</replaceable>;
|
statistics-file <replaceable>quoted_string</replaceable>;
|
||||||
synth-from-dnssec <replaceable>boolean</replaceable>;
|
synth-from-dnssec <replaceable>boolean</replaceable>;
|
||||||
@@ -564,7 +565,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
[ dscp <replaceable>integer</replaceable> ] { ( <replaceable>masters</replaceable> | <replaceable>ipv4_address</replaceable> [ port
|
[ dscp <replaceable>integer</replaceable> ] { ( <replaceable>masters</replaceable> | <replaceable>ipv4_address</replaceable> [ port
|
||||||
<replaceable>integer</replaceable> ] | <replaceable>ipv6_address</replaceable> [ port <replaceable>integer</replaceable> ] ) [ key
|
<replaceable>integer</replaceable> ] | <replaceable>ipv6_address</replaceable> [ port <replaceable>integer</replaceable> ] ) [ key
|
||||||
<replaceable>string</replaceable> ]; ... } ] [ zone-directory <replaceable>quoted_string</replaceable> ] [
|
<replaceable>string</replaceable> ]; ... } ] [ zone-directory <replaceable>quoted_string</replaceable> ] [
|
||||||
in-memory <replaceable>boolean</replaceable> ] [ min-update-interval <replaceable>ttlval</replaceable> ]; ... };
|
in-memory <replaceable>boolean</replaceable> ] [ min-update-interval <replaceable>duration</replaceable> ]; ... };
|
||||||
check-dup-records ( fail | warn | ignore );
|
check-dup-records ( fail | warn | ignore );
|
||||||
check-integrity <replaceable>boolean</replaceable>;
|
check-integrity <replaceable>boolean</replaceable>;
|
||||||
check-mx ( fail | warn | ignore );
|
check-mx ( fail | warn | ignore );
|
||||||
@@ -607,8 +608,9 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
dnssec-accept-expired <replaceable>boolean</replaceable>;
|
dnssec-accept-expired <replaceable>boolean</replaceable>;
|
||||||
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
||||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
||||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
initial-key | static-ds | initial-ds
|
||||||
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... };
|
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
|
<replaceable>quoted_string</replaceable>; ... };
|
||||||
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
||||||
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
|
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
|
||||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||||
@@ -642,10 +644,11 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
secret <replaceable>string</replaceable>;
|
secret <replaceable>string</replaceable>;
|
||||||
};
|
};
|
||||||
key-directory <replaceable>quoted_string</replaceable>;
|
key-directory <replaceable>quoted_string</replaceable>;
|
||||||
lame-ttl <replaceable>ttlval</replaceable>;
|
lame-ttl <replaceable>duration</replaceable>;
|
||||||
lmdb-mapsize <replaceable>sizeval</replaceable>;
|
lmdb-mapsize <replaceable>sizeval</replaceable>;
|
||||||
managed-keys { <replaceable>string</replaceable> (
|
managed-keys { <replaceable>string</replaceable> (
|
||||||
static-key | initial-key
|
static-key | initial-key
|
||||||
|
| static-ds | initial-ds
|
||||||
) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>integer</replaceable>
|
<replaceable>integer</replaceable>
|
||||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||||
@@ -655,25 +658,25 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
match-destinations { <replaceable>address_match_element</replaceable>; ... };
|
match-destinations { <replaceable>address_match_element</replaceable>; ... };
|
||||||
match-recursive-only <replaceable>boolean</replaceable>;
|
match-recursive-only <replaceable>boolean</replaceable>;
|
||||||
max-cache-size ( default | unlimited | <replaceable>sizeval</replaceable> | <replaceable>percentage</replaceable> );
|
max-cache-size ( default | unlimited | <replaceable>sizeval</replaceable> | <replaceable>percentage</replaceable> );
|
||||||
max-cache-ttl <replaceable>ttlval</replaceable>;
|
max-cache-ttl <replaceable>duration</replaceable>;
|
||||||
max-clients-per-query <replaceable>integer</replaceable>;
|
max-clients-per-query <replaceable>integer</replaceable>;
|
||||||
max-journal-size ( default | unlimited | <replaceable>sizeval</replaceable> );
|
max-journal-size ( default | unlimited | <replaceable>sizeval</replaceable> );
|
||||||
max-ncache-ttl <replaceable>ttlval</replaceable>;
|
max-ncache-ttl <replaceable>duration</replaceable>;
|
||||||
max-records <replaceable>integer</replaceable>;
|
max-records <replaceable>integer</replaceable>;
|
||||||
max-recursion-depth <replaceable>integer</replaceable>;
|
max-recursion-depth <replaceable>integer</replaceable>;
|
||||||
max-recursion-queries <replaceable>integer</replaceable>;
|
max-recursion-queries <replaceable>integer</replaceable>;
|
||||||
max-refresh-time <replaceable>integer</replaceable>;
|
max-refresh-time <replaceable>integer</replaceable>;
|
||||||
max-retry-time <replaceable>integer</replaceable>;
|
max-retry-time <replaceable>integer</replaceable>;
|
||||||
max-stale-ttl <replaceable>ttlval</replaceable>;
|
max-stale-ttl <replaceable>duration</replaceable>;
|
||||||
max-transfer-idle-in <replaceable>integer</replaceable>;
|
max-transfer-idle-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-idle-out <replaceable>integer</replaceable>;
|
max-transfer-idle-out <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-in <replaceable>integer</replaceable>;
|
max-transfer-time-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-out <replaceable>integer</replaceable>;
|
max-transfer-time-out <replaceable>integer</replaceable>;
|
||||||
max-udp-size <replaceable>integer</replaceable>;
|
max-udp-size <replaceable>integer</replaceable>;
|
||||||
max-zone-ttl ( unlimited | <replaceable>ttlval</replaceable> );
|
max-zone-ttl ( unlimited | <replaceable>duration</replaceable> );
|
||||||
message-compression <replaceable>boolean</replaceable>;
|
message-compression <replaceable>boolean</replaceable>;
|
||||||
min-cache-ttl <replaceable>ttlval</replaceable>;
|
min-cache-ttl <replaceable>duration</replaceable>;
|
||||||
min-ncache-ttl <replaceable>ttlval</replaceable>;
|
min-ncache-ttl <replaceable>duration</replaceable>;
|
||||||
min-refresh-time <replaceable>integer</replaceable>;
|
min-refresh-time <replaceable>integer</replaceable>;
|
||||||
min-retry-time <replaceable>integer</replaceable>;
|
min-retry-time <replaceable>integer</replaceable>;
|
||||||
minimal-any <replaceable>boolean</replaceable>;
|
minimal-any <replaceable>boolean</replaceable>;
|
||||||
@@ -689,8 +692,8 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
notify-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ]
|
notify-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ]
|
||||||
[ dscp <replaceable>integer</replaceable> ];
|
[ dscp <replaceable>integer</replaceable> ];
|
||||||
notify-to-soa <replaceable>boolean</replaceable>;
|
notify-to-soa <replaceable>boolean</replaceable>;
|
||||||
nta-lifetime <replaceable>ttlval</replaceable>;
|
nta-lifetime <replaceable>duration</replaceable>;
|
||||||
nta-recheck <replaceable>ttlval</replaceable>;
|
nta-recheck <replaceable>duration</replaceable>;
|
||||||
nxdomain-redirect <replaceable>string</replaceable>;
|
nxdomain-redirect <replaceable>string</replaceable>;
|
||||||
plugin ( query ) <replaceable>string</replaceable> [ {
|
plugin ( query ) <replaceable>string</replaceable> [ {
|
||||||
<replaceable>unspecified-text</replaceable> } ];
|
<replaceable>unspecified-text</replaceable> } ];
|
||||||
@@ -732,13 +735,13 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
response-padding { <replaceable>address_match_element</replaceable>; ... } block-size
|
response-padding { <replaceable>address_match_element</replaceable>; ... } block-size
|
||||||
<replaceable>integer</replaceable>;
|
<replaceable>integer</replaceable>;
|
||||||
response-policy { zone <replaceable>string</replaceable> [ add-soa <replaceable>boolean</replaceable> ] [ log
|
response-policy { zone <replaceable>string</replaceable> [ add-soa <replaceable>boolean</replaceable> ] [ log
|
||||||
<replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>ttlval</replaceable> ] [ min-update-interval
|
<replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>duration</replaceable> ] [ min-update-interval
|
||||||
<replaceable>ttlval</replaceable> ] [ policy ( cname | disabled | drop | given | no-op |
|
<replaceable>duration</replaceable> ] [ policy ( cname | disabled | drop | given | no-op |
|
||||||
nodata | nxdomain | passthru | tcp-only <replaceable>quoted_string</replaceable> ) ] [
|
nodata | nxdomain | passthru | tcp-only <replaceable>quoted_string</replaceable> ) ] [
|
||||||
recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
||||||
nsdname-enable <replaceable>boolean</replaceable> ]; ... } [ add-soa <replaceable>boolean</replaceable> ] [
|
nsdname-enable <replaceable>boolean</replaceable> ]; ... } [ add-soa <replaceable>boolean</replaceable> ] [
|
||||||
break-dnssec <replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>ttlval</replaceable> ] [
|
break-dnssec <replaceable>boolean</replaceable> ] [ max-policy-ttl <replaceable>duration</replaceable> ] [
|
||||||
min-update-interval <replaceable>ttlval</replaceable> ] [ min-ns-dots <replaceable>integer</replaceable> ] [
|
min-update-interval <replaceable>duration</replaceable> ] [ min-ns-dots <replaceable>integer</replaceable> ] [
|
||||||
nsip-wait-recurse <replaceable>boolean</replaceable> ] [ qname-wait-recurse <replaceable>boolean</replaceable> ]
|
nsip-wait-recurse <replaceable>boolean</replaceable> ] [ qname-wait-recurse <replaceable>boolean</replaceable> ]
|
||||||
[ recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
[ recursive-only <replaceable>boolean</replaceable> ] [ nsip-enable <replaceable>boolean</replaceable> ] [
|
||||||
nsdname-enable <replaceable>boolean</replaceable> ] [ dnsrps-enable <replaceable>boolean</replaceable> ] [
|
nsdname-enable <replaceable>boolean</replaceable> ] [ dnsrps-enable <replaceable>boolean</replaceable> ] [
|
||||||
@@ -783,14 +786,14 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
<replaceable>integer</replaceable> | * ) ] [ dscp <replaceable>integer</replaceable> ];
|
<replaceable>integer</replaceable> | * ) ] [ dscp <replaceable>integer</replaceable> ];
|
||||||
transfers <replaceable>integer</replaceable>;
|
transfers <replaceable>integer</replaceable>;
|
||||||
};
|
};
|
||||||
servfail-ttl <replaceable>ttlval</replaceable>;
|
servfail-ttl <replaceable>duration</replaceable>;
|
||||||
sig-signing-nodes <replaceable>integer</replaceable>;
|
sig-signing-nodes <replaceable>integer</replaceable>;
|
||||||
sig-signing-signatures <replaceable>integer</replaceable>;
|
sig-signing-signatures <replaceable>integer</replaceable>;
|
||||||
sig-signing-type <replaceable>integer</replaceable>;
|
sig-signing-type <replaceable>integer</replaceable>;
|
||||||
sig-validity-interval <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ];
|
sig-validity-interval <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ];
|
||||||
sortlist { <replaceable>address_match_element</replaceable>; ... };
|
sortlist { <replaceable>address_match_element</replaceable>; ... };
|
||||||
stale-answer-enable <replaceable>boolean</replaceable>;
|
stale-answer-enable <replaceable>boolean</replaceable>;
|
||||||
stale-answer-ttl <replaceable>ttlval</replaceable>;
|
stale-answer-ttl <replaceable>duration</replaceable>;
|
||||||
synth-from-dnssec <replaceable>boolean</replaceable>;
|
synth-from-dnssec <replaceable>boolean</replaceable>;
|
||||||
transfer-format ( many-answers | one-answer );
|
transfer-format ( many-answers | one-answer );
|
||||||
transfer-source ( <replaceable>ipv4_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ] [
|
transfer-source ( <replaceable>ipv4_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * ) ] [
|
||||||
@@ -842,6 +845,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
dnskey-sig-validity <replaceable>integer</replaceable>;
|
dnskey-sig-validity <replaceable>integer</replaceable>;
|
||||||
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
||||||
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
||||||
|
dnssec-policy <replaceable>string</replaceable>;
|
||||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||||
dnssec-update-mode ( maintain | no-resign );
|
dnssec-update-mode ( maintain | no-resign );
|
||||||
file <replaceable>quoted_string</replaceable>;
|
file <replaceable>quoted_string</replaceable>;
|
||||||
@@ -867,7 +871,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
max-transfer-idle-out <replaceable>integer</replaceable>;
|
max-transfer-idle-out <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-in <replaceable>integer</replaceable>;
|
max-transfer-time-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-out <replaceable>integer</replaceable>;
|
max-transfer-time-out <replaceable>integer</replaceable>;
|
||||||
max-zone-ttl ( unlimited | <replaceable>ttlval</replaceable> );
|
max-zone-ttl ( unlimited | <replaceable>duration</replaceable> );
|
||||||
min-refresh-time <replaceable>integer</replaceable>;
|
min-refresh-time <replaceable>integer</replaceable>;
|
||||||
min-retry-time <replaceable>integer</replaceable>;
|
min-retry-time <replaceable>integer</replaceable>;
|
||||||
multi-master <replaceable>boolean</replaceable>;
|
multi-master <replaceable>boolean</replaceable>;
|
||||||
@@ -943,6 +947,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
dnskey-sig-validity <replaceable>integer</replaceable>;
|
dnskey-sig-validity <replaceable>integer</replaceable>;
|
||||||
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
||||||
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
||||||
|
dnssec-policy <replaceable>string</replaceable>;
|
||||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||||
dnssec-update-mode ( maintain | no-resign );
|
dnssec-update-mode ( maintain | no-resign );
|
||||||
file <replaceable>quoted_string</replaceable>;
|
file <replaceable>quoted_string</replaceable>;
|
||||||
@@ -967,7 +972,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
max-transfer-idle-out <replaceable>integer</replaceable>;
|
max-transfer-idle-out <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-in <replaceable>integer</replaceable>;
|
max-transfer-time-in <replaceable>integer</replaceable>;
|
||||||
max-transfer-time-out <replaceable>integer</replaceable>;
|
max-transfer-time-out <replaceable>integer</replaceable>;
|
||||||
max-zone-ttl ( unlimited | <replaceable>ttlval</replaceable> );
|
max-zone-ttl ( unlimited | <replaceable>duration</replaceable> );
|
||||||
min-refresh-time <replaceable>integer</replaceable>;
|
min-refresh-time <replaceable>integer</replaceable>;
|
||||||
min-retry-time <replaceable>integer</replaceable>;
|
min-retry-time <replaceable>integer</replaceable>;
|
||||||
multi-master <replaceable>boolean</replaceable>;
|
multi-master <replaceable>boolean</replaceable>;
|
||||||
@@ -1008,6 +1013,26 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
|
<refsection><info><title>DNSSEC-POLICY</title></info>
|
||||||
|
|
||||||
|
<literallayout class="normal">
|
||||||
|
dnssec-policy <replaceable>string</replaceable> {
|
||||||
|
dnskey-ttl <replaceable>ttlval</replaceable>;
|
||||||
|
keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... };
|
||||||
|
parent-ds-ttl <replaceable>duration</replaceable>;
|
||||||
|
parent-propagation-delay <replaceable>duration</replaceable>;
|
||||||
|
parent-registration-delay <replaceable>duration</replaceable>;
|
||||||
|
publish-safety <replaceable>duration</replaceable>;
|
||||||
|
retire-safety <replaceable>duration</replaceable>;
|
||||||
|
signatures-refresh <replaceable>duration</replaceable>;
|
||||||
|
signatures-validity <replaceable>duration</replaceable>;
|
||||||
|
signatures-validity-dnskey <replaceable>duration</replaceable>;
|
||||||
|
zone-max-ttl <replaceable>duration</replaceable>;
|
||||||
|
zone-propagation-delay <replaceable>duration</replaceable>;
|
||||||
|
};
|
||||||
|
</literallayout>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>FILES</title></info>
|
<refsection><info><title>FILES</title></info>
|
||||||
|
|
||||||
<para><filename>/etc/named.conf</filename>
|
<para><filename>/etc/named.conf</filename>
|
||||||
|
|||||||
+70
-44
@@ -95,7 +95,8 @@ dlz
|
|||||||
<a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
|
<a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
initial-key | static-ds | initial-ds )<br>
|
||||||
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
@@ -144,9 +145,9 @@ logging
|
|||||||
<p>Deprecated - see DNSSEC-KEYS.</p>
|
<p>Deprecated - see DNSSEC-KEYS.</p>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
|
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
|
||||||
| initial-key ) <em class="replaceable"><code>integer</code></em><br>
|
| initial-key | static-ds |<br>
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
initial-ds ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -196,7 +197,7 @@ options
|
|||||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||||
check-dup-records ( fail | warn | ignore );<br>
|
check-dup-records ( fail | warn | ignore );<br>
|
||||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
check-mx ( fail | warn | ignore );<br>
|
check-mx ( fail | warn | ignore );<br>
|
||||||
@@ -278,18 +279,18 @@ options
|
|||||||
fstrm-set-output-notify-threshold <em class="replaceable"><code>integer</code></em>;<br>
|
fstrm-set-output-notify-threshold <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
fstrm-set-output-queue-model ( mpsc | spsc );<br>
|
fstrm-set-output-queue-model ( mpsc | spsc );<br>
|
||||||
fstrm-set-output-queue-size <em class="replaceable"><code>integer</code></em>;<br>
|
fstrm-set-output-queue-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
fstrm-set-reopen-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
fstrm-set-reopen-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
geoip-directory ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
geoip-directory ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
glue-cache <em class="replaceable"><code>boolean</code></em>;<br>
|
glue-cache <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
heartbeat-interval <em class="replaceable"><code>integer</code></em>;<br>
|
heartbeat-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
hostname ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
hostname ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
inline-signing <em class="replaceable"><code>boolean</code></em>;<br>
|
inline-signing <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
interface-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
interface-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
ixfr-from-differences ( primary | master | secondary | slave |<br>
|
ixfr-from-differences ( primary | master | secondary | slave |<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> );<br>
|
<em class="replaceable"><code>boolean</code></em> );<br>
|
||||||
keep-response-order { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
keep-response-order { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
listen-on [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
listen-on [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] {<br>
|
<em class="replaceable"><code>integer</code></em> ] {<br>
|
||||||
<em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
<em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
@@ -303,28 +304,28 @@ options
|
|||||||
masterfile-style ( full | relative );<br>
|
masterfile-style ( full | relative );<br>
|
||||||
match-mapped-addresses <em class="replaceable"><code>boolean</code></em>;<br>
|
match-mapped-addresses <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-rsa-exponent-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-rsa-exponent-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
memstatistics <em class="replaceable"><code>boolean</code></em>;<br>
|
memstatistics <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
memstatistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
memstatistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -341,8 +342,8 @@ options
|
|||||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||||
pid-file ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
pid-file ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
port <em class="replaceable"><code>integer</code></em>;<br>
|
port <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
@@ -389,13 +390,13 @@ options
|
|||||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||||
<em class="replaceable"><code>integer</code></em>;<br>
|
<em class="replaceable"><code>integer</code></em>;<br>
|
||||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
@@ -409,7 +410,7 @@ options
|
|||||||
serial-query-rate <em class="replaceable"><code>integer</code></em>;<br>
|
serial-query-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
serial-update-method ( date | increment | unixtime );<br>
|
serial-update-method ( date | increment | unixtime );<br>
|
||||||
server-id ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );<br>
|
server-id ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );<br>
|
||||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
session-keyalg <em class="replaceable"><code>string</code></em>;<br>
|
session-keyalg <em class="replaceable"><code>string</code></em>;<br>
|
||||||
session-keyfile ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
session-keyfile ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
session-keyname <em class="replaceable"><code>string</code></em>;<br>
|
session-keyname <em class="replaceable"><code>string</code></em>;<br>
|
||||||
@@ -420,7 +421,7 @@ options
|
|||||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
stacksize ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
stacksize ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
startup-notify-rate <em class="replaceable"><code>integer</code></em>;<br>
|
startup-notify-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
statistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
statistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -557,7 +558,7 @@ view
|
|||||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||||
check-dup-records ( fail | warn | ignore );<br>
|
check-dup-records ( fail | warn | ignore );<br>
|
||||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
check-mx ( fail | warn | ignore );<br>
|
check-mx ( fail | warn | ignore );<br>
|
||||||
@@ -600,8 +601,9 @@ view
|
|||||||
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
initial-key | static-ds | initial-ds<br>
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
|
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -635,10 +637,11 @@ view
|
|||||||
secret <em class="replaceable"><code>string</code></em>;<br>
|
secret <em class="replaceable"><code>string</code></em>;<br>
|
||||||
};<br>
|
};<br>
|
||||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
lmdb-mapsize <em class="replaceable"><code>sizeval</code></em>;<br>
|
lmdb-mapsize <em class="replaceable"><code>sizeval</code></em>;<br>
|
||||||
managed-keys { <em class="replaceable"><code>string</code></em> (<br>
|
managed-keys { <em class="replaceable"><code>string</code></em> (<br>
|
||||||
static-key | initial-key<br>
|
static-key | initial-key<br>
|
||||||
|
| static-ds | initial-ds<br>
|
||||||
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>integer</code></em><br>
|
<em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||||
@@ -648,25 +651,25 @@ view
|
|||||||
match-destinations { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
match-destinations { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
match-recursive-only <em class="replaceable"><code>boolean</code></em>;<br>
|
match-recursive-only <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -682,8 +685,8 @@ view
|
|||||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||||
plugin ( query ) <em class="replaceable"><code>string</code></em> [ {<br>
|
plugin ( query ) <em class="replaceable"><code>string</code></em> [ {<br>
|
||||||
<em class="replaceable"><code>unspecified-text</code></em> } ];<br>
|
<em class="replaceable"><code>unspecified-text</code></em> } ];<br>
|
||||||
@@ -725,13 +728,13 @@ view
|
|||||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||||
<em class="replaceable"><code>integer</code></em>;<br>
|
<em class="replaceable"><code>integer</code></em>;<br>
|
||||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
@@ -776,14 +779,14 @@ view
|
|||||||
<em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
<em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
transfers <em class="replaceable"><code>integer</code></em>;<br>
|
transfers <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
};<br>
|
};<br>
|
||||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-validity-interval <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ];<br>
|
sig-validity-interval <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
transfer-format ( many-answers | one-answer );<br>
|
transfer-format ( many-answers | one-answer );<br>
|
||||||
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [<br>
|
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [<br>
|
||||||
@@ -835,6 +838,7 @@ view
|
|||||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-update-mode ( maintain | no-resign );<br>
|
dnssec-update-mode ( maintain | no-resign );<br>
|
||||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
@@ -860,7 +864,7 @@ view
|
|||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -937,6 +941,7 @@ zone
|
|||||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-update-mode ( maintain | no-resign );<br>
|
dnssec-update-mode ( maintain | no-resign );<br>
|
||||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
@@ -961,7 +966,7 @@ zone
|
|||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -1003,14 +1008,35 @@ zone
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.24"></a><h2>FILES</h2>
|
<a name="id-1.24"></a><h2>DNSSEC-POLICY</h2>
|
||||||
|
|
||||||
|
<div class="literallayout"><p><br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
|
||||||
|
dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||||
|
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
|
||||||
|
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
parent-registration-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
publish-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
retire-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-refresh <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-validity <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-validity-dnskey <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
zone-max-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
zone-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
};<br>
|
||||||
|
</p></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="refsection">
|
||||||
|
<a name="id-1.25"></a><h2>FILES</h2>
|
||||||
|
|
||||||
<p><code class="filename">/etc/named.conf</code>
|
<p><code class="filename">/etc/named.conf</code>
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.25"></a><h2>SEE ALSO</h2>
|
<a name="id-1.26"></a><h2>SEE ALSO</h2>
|
||||||
|
|
||||||
<p><span class="citerefentry">
|
<p><span class="citerefentry">
|
||||||
<span class="refentrytitle">ddns-confgen</span>(8)
|
<span class="refentrytitle">ddns-confgen</span>(8)
|
||||||
|
|||||||
+434
-197
File diff suppressed because it is too large
Load Diff
@@ -241,6 +241,8 @@ init_desc(void) {
|
|||||||
SET_NSSTATDESC(invalidsig, "requests with invalid signature",
|
SET_NSSTATDESC(invalidsig, "requests with invalid signature",
|
||||||
"ReqBadSIG");
|
"ReqBadSIG");
|
||||||
SET_NSSTATDESC(requesttcp, "TCP requests received", "ReqTCP");
|
SET_NSSTATDESC(requesttcp, "TCP requests received", "ReqTCP");
|
||||||
|
SET_NSSTATDESC(tcphighwater, "TCP connection high-water",
|
||||||
|
"TCPConnHighWater");
|
||||||
SET_NSSTATDESC(authrej, "auth queries rejected", "AuthQryRej");
|
SET_NSSTATDESC(authrej, "auth queries rejected", "AuthQryRej");
|
||||||
SET_NSSTATDESC(recurserej, "recursive queries rejected", "RecQryRej");
|
SET_NSSTATDESC(recurserej, "recursive queries rejected", "RecQryRej");
|
||||||
SET_NSSTATDESC(xfrrej, "transfer requests rejected", "XfrRej");
|
SET_NSSTATDESC(xfrrej, "transfer requests rejected", "XfrRej");
|
||||||
@@ -322,6 +324,7 @@ init_desc(void) {
|
|||||||
"QryUsedStale");
|
"QryUsedStale");
|
||||||
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
|
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
|
||||||
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
|
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
|
||||||
|
|
||||||
INSIST(i == ns_statscounter_max);
|
INSIST(i == ns_statscounter_max);
|
||||||
|
|
||||||
/* Initialize resolver statistics */
|
/* Initialize resolver statistics */
|
||||||
|
|||||||
@@ -59,7 +59,6 @@ named_paths_init(void) {
|
|||||||
named_g_keyfile = isc_ntpaths_get(RNDC_KEY_PATH);
|
named_g_keyfile = isc_ntpaths_get(RNDC_KEY_PATH);
|
||||||
named_g_defaultsessionkeyfile = isc_ntpaths_get(SESSION_KEY_PATH);
|
named_g_defaultsessionkeyfile = isc_ntpaths_get(SESSION_KEY_PATH);
|
||||||
named_g_defaultbindkeys = isc_ntpaths_get(BIND_KEYS_PATH);
|
named_g_defaultbindkeys = isc_ntpaths_get(BIND_KEYS_PATH);
|
||||||
named_g_defaultdnstap = NULL;
|
|
||||||
|
|
||||||
Initialized = TRUE;
|
Initialized = TRUE;
|
||||||
}
|
}
|
||||||
|
|||||||
+83
-34
@@ -25,6 +25,7 @@
|
|||||||
#include <dns/ipkeylist.h>
|
#include <dns/ipkeylist.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
#include <dns/journal.h>
|
#include <dns/journal.h>
|
||||||
|
#include <dns/kasp.h>
|
||||||
#include <dns/log.h>
|
#include <dns/log.h>
|
||||||
#include <dns/name.h>
|
#include <dns/name.h>
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
@@ -840,8 +841,9 @@ process_notifytype(dns_notifytype_t ntype, dns_zonetype_t ztype,
|
|||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||||
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
const cfg_obj_t *zconfig, cfg_aclconfctx_t *ac,
|
||||||
dns_zone_t *zone, dns_zone_t *raw)
|
dns_kasplist_t *kasplist, dns_zone_t *zone,
|
||||||
|
dns_zone_t *raw)
|
||||||
{
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
const char *zname;
|
const char *zname;
|
||||||
@@ -853,6 +855,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
const cfg_obj_t *options = NULL;
|
const cfg_obj_t *options = NULL;
|
||||||
const cfg_obj_t *obj;
|
const cfg_obj_t *obj;
|
||||||
const char *filename = NULL;
|
const char *filename = NULL;
|
||||||
|
const char *kaspname = NULL;
|
||||||
const char *dupcheck;
|
const char *dupcheck;
|
||||||
dns_notifytype_t notifytype = dns_notifytype_yes;
|
dns_notifytype_t notifytype = dns_notifytype_yes;
|
||||||
uint32_t count;
|
uint32_t count;
|
||||||
@@ -868,7 +871,8 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
int32_t journal_size;
|
int32_t journal_size;
|
||||||
bool multi;
|
bool multi;
|
||||||
bool alt;
|
bool alt;
|
||||||
dns_view_t *view;
|
dns_view_t *view = NULL;
|
||||||
|
dns_kasp_t *kasp = NULL;
|
||||||
bool check = false, fail = false;
|
bool check = false, fail = false;
|
||||||
bool warn = false, ignore = false;
|
bool warn = false, ignore = false;
|
||||||
bool ixfrdiff;
|
bool ixfrdiff;
|
||||||
@@ -1045,8 +1049,8 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
} else if (result == ISC_R_SUCCESS) {
|
} else if (result == ISC_R_SUCCESS) {
|
||||||
dns_ttl_t maxttl = 0; /* unlimited */
|
dns_ttl_t maxttl = 0; /* unlimited */
|
||||||
|
|
||||||
if (cfg_obj_isuint32(obj))
|
if (cfg_obj_isduration(obj))
|
||||||
maxttl = cfg_obj_asuint32(obj);
|
maxttl = cfg_obj_asduration(obj);
|
||||||
dns_zone_setmaxttl(zone, maxttl);
|
dns_zone_setmaxttl(zone, maxttl);
|
||||||
if (raw != NULL)
|
if (raw != NULL)
|
||||||
dns_zone_setmaxttl(raw, maxttl);
|
dns_zone_setmaxttl(raw, maxttl);
|
||||||
@@ -1192,6 +1196,24 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
*/
|
*/
|
||||||
if (ztype != dns_zone_stub && ztype != dns_zone_staticstub &&
|
if (ztype != dns_zone_stub && ztype != dns_zone_staticstub &&
|
||||||
ztype != dns_zone_redirect) {
|
ztype != dns_zone_redirect) {
|
||||||
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "dnssec-policy", &obj);
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
|
kaspname = cfg_obj_asstring(obj);
|
||||||
|
if (strcmp(kaspname, "none") != 0) {
|
||||||
|
result = dns_kasplist_find(kasplist, kaspname,
|
||||||
|
&kasp);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
cfg_obj_log(obj, named_g_lctx,
|
||||||
|
ISC_LOG_ERROR,
|
||||||
|
"'dnssec-policy '%s' not "
|
||||||
|
"found ", kaspname);
|
||||||
|
RETERR(result);
|
||||||
|
}
|
||||||
|
dns_zone_setkasp(zone, kasp);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "notify", &obj);
|
result = named_config_get(maps, "notify", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
@@ -1481,38 +1503,52 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
bool allow = false, maint = false;
|
bool allow = false, maint = false;
|
||||||
bool sigvalinsecs;
|
bool sigvalinsecs;
|
||||||
|
|
||||||
obj = NULL;
|
if (kasp) {
|
||||||
result = named_config_get(maps, "dnskey-sig-validity", &obj);
|
seconds = (uint32_t) dns_kasp_sigvalidity_dnskey(kasp);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
} else {
|
||||||
seconds = cfg_obj_asuint32(obj) * 86400;
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "dnskey-sig-validity",
|
||||||
|
&obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
|
seconds = cfg_obj_asuint32(obj) * 86400;
|
||||||
|
}
|
||||||
dns_zone_setkeyvalidityinterval(zone, seconds);
|
dns_zone_setkeyvalidityinterval(zone, seconds);
|
||||||
|
|
||||||
obj = NULL;
|
if (kasp) {
|
||||||
result = named_config_get(maps, "sig-validity-interval", &obj);
|
seconds = (uint32_t) dns_kasp_sigvalidity(kasp);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
dns_zone_setsigvalidityinterval(zone, seconds);
|
||||||
|
seconds = (uint32_t) dns_kasp_sigrefresh(kasp);
|
||||||
sigvalinsecs = ns_server_getoption(named_g_server->sctx,
|
dns_zone_setsigresigninginterval(zone, seconds);
|
||||||
NS_SERVER_SIGVALINSECS);
|
|
||||||
validity = cfg_tuple_get(obj, "validity");
|
|
||||||
seconds = cfg_obj_asuint32(validity);
|
|
||||||
if (!sigvalinsecs) {
|
|
||||||
seconds *= 86400;
|
|
||||||
}
|
|
||||||
dns_zone_setsigvalidityinterval(zone, seconds);
|
|
||||||
|
|
||||||
resign = cfg_tuple_get(obj, "re-sign");
|
|
||||||
if (cfg_obj_isvoid(resign)) {
|
|
||||||
seconds /= 4;
|
|
||||||
} else if (!sigvalinsecs) {
|
|
||||||
if (seconds > 7 * 86400) {
|
|
||||||
seconds = cfg_obj_asuint32(resign) * 86400;
|
|
||||||
} else {
|
|
||||||
seconds = cfg_obj_asuint32(resign) * 3600;
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
seconds = cfg_obj_asuint32(resign);
|
obj = NULL;
|
||||||
|
result = named_config_get(maps, "sig-validity-interval",
|
||||||
|
&obj);
|
||||||
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
|
|
||||||
|
sigvalinsecs = ns_server_getoption(named_g_server->sctx,
|
||||||
|
NS_SERVER_SIGVALINSECS);
|
||||||
|
validity = cfg_tuple_get(obj, "validity");
|
||||||
|
seconds = cfg_obj_asuint32(validity);
|
||||||
|
if (!sigvalinsecs) {
|
||||||
|
seconds *= 86400;
|
||||||
|
}
|
||||||
|
dns_zone_setsigvalidityinterval(zone, seconds);
|
||||||
|
|
||||||
|
resign = cfg_tuple_get(obj, "re-sign");
|
||||||
|
if (cfg_obj_isvoid(resign)) {
|
||||||
|
seconds /= 4;
|
||||||
|
} else if (!sigvalinsecs) {
|
||||||
|
seconds = cfg_obj_asuint32(resign);
|
||||||
|
if (seconds > 7 * 86400) {
|
||||||
|
seconds *= 86400;
|
||||||
|
} else {
|
||||||
|
seconds *= 3600;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
seconds = cfg_obj_asuint32(resign);
|
||||||
|
}
|
||||||
|
dns_zone_setsigresigninginterval(zone, seconds);
|
||||||
}
|
}
|
||||||
dns_zone_setsigresigninginterval(zone, seconds);
|
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "key-directory", &obj);
|
result = named_config_get(maps, "key-directory", &obj);
|
||||||
@@ -1541,12 +1577,20 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setoption(zone, DNS_ZONEOPT_UPDATECHECKKSK,
|
dns_zone_setoption(zone, DNS_ZONEOPT_UPDATECHECKKSK,
|
||||||
cfg_obj_asboolean(obj));
|
cfg_obj_asboolean(obj));
|
||||||
|
/*
|
||||||
|
* This setting will be ignored if dnssec-policy is used.
|
||||||
|
* named-checkconf will error if both are configured.
|
||||||
|
*/
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "dnssec-dnskey-kskonly", &obj);
|
result = named_config_get(maps, "dnssec-dnskey-kskonly", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||||
dns_zone_setoption(zone, DNS_ZONEOPT_DNSKEYKSKONLY,
|
dns_zone_setoption(zone, DNS_ZONEOPT_DNSKEYKSKONLY,
|
||||||
cfg_obj_asboolean(obj));
|
cfg_obj_asboolean(obj));
|
||||||
|
/*
|
||||||
|
* This setting will be ignored if dnssec-policy is used.
|
||||||
|
* named-checkconf will error if both are configured.
|
||||||
|
*/
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "dnssec-loadkeys-interval",
|
result = named_config_get(maps, "dnssec-loadkeys-interval",
|
||||||
@@ -1557,7 +1601,11 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = cfg_map_get(zoptions, "auto-dnssec", &obj);
|
result = cfg_map_get(zoptions, "auto-dnssec", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (dns_zone_getkasp(zone) != NULL) {
|
||||||
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_ALLOW, true);
|
||||||
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_CREATE, true);
|
||||||
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_MAINTAIN, true);
|
||||||
|
} else if (result == ISC_R_SUCCESS) {
|
||||||
const char *arg = cfg_obj_asstring(obj);
|
const char *arg = cfg_obj_asstring(obj);
|
||||||
if (strcasecmp(arg, "allow") == 0) {
|
if (strcasecmp(arg, "allow") == 0) {
|
||||||
allow = true;
|
allow = true;
|
||||||
@@ -1570,6 +1618,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
|||||||
ISC_UNREACHABLE();
|
ISC_UNREACHABLE();
|
||||||
}
|
}
|
||||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_ALLOW, allow);
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_ALLOW, allow);
|
||||||
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_CREATE, false);
|
||||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_MAINTAIN, maint);
|
dns_zone_setkeyopt(zone, DNS_ZONEKEY_MAINTAIN, maint);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -906,7 +906,7 @@ setup_system(void) {
|
|||||||
result = isc_timermgr_create(gmctx, &timermgr);
|
result = isc_timermgr_create(gmctx, &timermgr);
|
||||||
check_result(result, "dns_timermgr_create");
|
check_result(result, "dns_timermgr_create");
|
||||||
|
|
||||||
result = isc_taskmgr_create(gmctx, 1, 0, &taskmgr);
|
result = isc_taskmgr_create(gmctx, 1, 0, NULL, &taskmgr);
|
||||||
check_result(result, "isc_taskmgr_create");
|
check_result(result, "isc_taskmgr_create");
|
||||||
|
|
||||||
result = isc_task_create(taskmgr, 0, &global_task);
|
result = isc_task_create(taskmgr, 0, &global_task);
|
||||||
|
|||||||
+5
-3
@@ -276,7 +276,8 @@ See also
|
|||||||
Fetch all DNSSEC keys for the given zone from the key directory\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. Unlike
|
Fetch all DNSSEC keys for the given zone from the key directory\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. Unlike
|
||||||
\fBrndc sign\fR, however, the zone is not immediately re\-signed by the new keys, but is allowed to incrementally re\-sign over time\&.
|
\fBrndc sign\fR, however, the zone is not immediately re\-signed by the new keys, but is allowed to incrementally re\-sign over time\&.
|
||||||
.sp
|
.sp
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
\fBdnssec\-policy\fR, or that the
|
||||||
\fBauto\-dnssec\fR
|
\fBauto\-dnssec\fR
|
||||||
zone option be set to
|
zone option be set to
|
||||||
maintain, and also requires the zone to be configured to allow dynamic DNS\&. (See "Dynamic Update Policies" in the Administrator Reference Manual for more details\&.)
|
maintain, and also requires the zone to be configured to allow dynamic DNS\&. (See "Dynamic Update Policies" in the Administrator Reference Manual for more details\&.)
|
||||||
@@ -566,7 +567,8 @@ Fetch all DNSSEC keys for the given zone from the key directory (see the
|
|||||||
\fBkey\-directory\fR
|
\fBkey\-directory\fR
|
||||||
option in the BIND 9 Administrator Reference Manual)\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. If the DNSKEY RRset is changed, then the zone is automatically re\-signed with the new key set\&.
|
option in the BIND 9 Administrator Reference Manual)\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. If the DNSKEY RRset is changed, then the zone is automatically re\-signed with the new key set\&.
|
||||||
.sp
|
.sp
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
\fBdnssec\-policy\fR, or that the
|
||||||
\fBauto\-dnssec\fR
|
\fBauto\-dnssec\fR
|
||||||
zone option be set to
|
zone option be set to
|
||||||
allow
|
allow
|
||||||
@@ -702,7 +704,7 @@ in each view\&. The list includes both statically configured keys and dynamic TK
|
|||||||
.PP
|
.PP
|
||||||
\fBvalidation ( on | off | status ) \fR\fB[\fIview \&.\&.\&.\fR]\fR\fB \fR
|
\fBvalidation ( on | off | status ) \fR\fB[\fIview \&.\&.\&.\fR]\fR\fB \fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Enable, disable, or check the current status of DNSSEC validation\&. By default, validation is enabled\&.
|
Enable, disable, or check the current status of DNSSEC validation\&. By default, validation is enabled\&. The cache is flushed when validation is turned on or off to avoid using data that might differ between states\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fBzonestatus \fR\fB\fIzone\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR
|
\fBzonestatus \fR\fB\fIzone\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR
|
||||||
|
|||||||
+6
-3
@@ -936,11 +936,14 @@ main(int argc, char **argv) {
|
|||||||
serial = isc_random32();
|
serial = isc_random32();
|
||||||
|
|
||||||
isc_mem_create(&rndc_mctx);
|
isc_mem_create(&rndc_mctx);
|
||||||
DO("create socket manager", isc_socketmgr_create(rndc_mctx, &socketmgr));
|
DO("create socket manager", isc_socketmgr_create(rndc_mctx,
|
||||||
DO("create task manager", isc_taskmgr_create(rndc_mctx, 1, 0, &taskmgr));
|
&socketmgr));
|
||||||
|
DO("create task manager", isc_taskmgr_create(rndc_mctx, 1, 0,
|
||||||
|
NULL, &taskmgr));
|
||||||
DO("create task", isc_task_create(taskmgr, 0, &task));
|
DO("create task", isc_task_create(taskmgr, 0, &task));
|
||||||
|
|
||||||
DO("create logging context", isc_log_create(rndc_mctx, &log, &logconfig));
|
DO("create logging context", isc_log_create(rndc_mctx, &log,
|
||||||
|
&logconfig));
|
||||||
isc_log_setcontext(log);
|
isc_log_setcontext(log);
|
||||||
DO("setting log tag", isc_log_settag(logconfig, progname));
|
DO("setting log tag", isc_log_settag(logconfig, progname));
|
||||||
logdest.file.stream = stderr;
|
logdest.file.stream = stderr;
|
||||||
|
|||||||
@@ -443,7 +443,8 @@
|
|||||||
allowed to incrementally re-sign over time.
|
allowed to incrementally re-sign over time.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
<command>dnssec-policy</command>, or that the
|
||||||
<command>auto-dnssec</command> zone option
|
<command>auto-dnssec</command> zone option
|
||||||
be set to <literal>maintain</literal>,
|
be set to <literal>maintain</literal>,
|
||||||
and also requires the zone to be configured to
|
and also requires the zone to be configured to
|
||||||
@@ -849,7 +850,8 @@
|
|||||||
re-signed with the new key set.
|
re-signed with the new key set.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
<command>dnssec-policy</command>, or that the
|
||||||
<command>auto-dnssec</command> zone option be set
|
<command>auto-dnssec</command> zone option be set
|
||||||
to <literal>allow</literal> or
|
to <literal>allow</literal> or
|
||||||
<literal>maintain</literal>,
|
<literal>maintain</literal>,
|
||||||
@@ -1078,6 +1080,8 @@
|
|||||||
<para>
|
<para>
|
||||||
Enable, disable, or check the current status of
|
Enable, disable, or check the current status of
|
||||||
DNSSEC validation. By default, validation is enabled.
|
DNSSEC validation. By default, validation is enabled.
|
||||||
|
The cache is flushed when validation is turned on or off
|
||||||
|
to avoid using data that might differ between states.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|||||||
+6
-2
@@ -366,7 +366,8 @@
|
|||||||
allowed to incrementally re-sign over time.
|
allowed to incrementally re-sign over time.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
<span class="command"><strong>dnssec-policy</strong></span>, or that the
|
||||||
<span class="command"><strong>auto-dnssec</strong></span> zone option
|
<span class="command"><strong>auto-dnssec</strong></span> zone option
|
||||||
be set to <code class="literal">maintain</code>,
|
be set to <code class="literal">maintain</code>,
|
||||||
and also requires the zone to be configured to
|
and also requires the zone to be configured to
|
||||||
@@ -721,7 +722,8 @@
|
|||||||
re-signed with the new key set.
|
re-signed with the new key set.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
This command requires that the
|
This command requires that the zone is configured with a
|
||||||
|
<span class="command"><strong>dnssec-policy</strong></span>, or that the
|
||||||
<span class="command"><strong>auto-dnssec</strong></span> zone option be set
|
<span class="command"><strong>auto-dnssec</strong></span> zone option be set
|
||||||
to <code class="literal">allow</code> or
|
to <code class="literal">allow</code> or
|
||||||
<code class="literal">maintain</code>,
|
<code class="literal">maintain</code>,
|
||||||
@@ -914,6 +916,8 @@
|
|||||||
<p>
|
<p>
|
||||||
Enable, disable, or check the current status of
|
Enable, disable, or check the current status of
|
||||||
DNSSEC validation. By default, validation is enabled.
|
DNSSEC validation. By default, validation is enabled.
|
||||||
|
The cache is flushed when validation is turned on or off
|
||||||
|
to avoid using data that might differ between states.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><strong class="userinput"><code>zonestatus <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
|
<dt><span class="term"><strong class="userinput"><code>zonestatus <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
|
||||||
|
|||||||
@@ -144,7 +144,7 @@ create_managers(void) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
taskmgr = NULL;
|
taskmgr = NULL;
|
||||||
result = isc_taskmgr_create(mctx, 5, 0, &taskmgr);
|
result = isc_taskmgr_create(mctx, 5, 0, NULL, &taskmgr);
|
||||||
check_result(result, "isc_taskmgr_create");
|
check_result(result, "isc_taskmgr_create");
|
||||||
|
|
||||||
timermgr = NULL;
|
timermgr = NULL;
|
||||||
|
|||||||
@@ -112,7 +112,7 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
taskmgr = NULL;
|
taskmgr = NULL;
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, &taskmgr)
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, NULL, &taskmgr)
|
||||||
== ISC_R_SUCCESS);
|
== ISC_R_SUCCESS);
|
||||||
task = NULL;
|
task = NULL;
|
||||||
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task)
|
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task)
|
||||||
|
|||||||
@@ -226,7 +226,7 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
taskmgr = NULL;
|
taskmgr = NULL;
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, &taskmgr) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, NULL, &taskmgr) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
task = NULL;
|
task = NULL;
|
||||||
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task) ==
|
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task) ==
|
||||||
|
|||||||
@@ -470,7 +470,7 @@ main(int argc, char *argv[]) {
|
|||||||
RUNCHECK(dst_lib_init(mctx, NULL));
|
RUNCHECK(dst_lib_init(mctx, NULL));
|
||||||
|
|
||||||
taskmgr = NULL;
|
taskmgr = NULL;
|
||||||
RUNCHECK(isc_taskmgr_create(mctx, 1, 0, &taskmgr));
|
RUNCHECK(isc_taskmgr_create(mctx, 1, 0, NULL, &taskmgr));
|
||||||
task = NULL;
|
task = NULL;
|
||||||
RUNCHECK(isc_task_create(taskmgr, 0, &task));
|
RUNCHECK(isc_task_create(taskmgr, 0, &task));
|
||||||
timermgr = NULL;
|
timermgr = NULL;
|
||||||
|
|||||||
@@ -102,7 +102,7 @@ main(int argc, char *argv[]) {
|
|||||||
isc_interval_set(&linterval, 1, 0);
|
isc_interval_set(&linterval, 1, 0);
|
||||||
|
|
||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, 3, 0, &taskmgr) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, 3, 0, NULL, &taskmgr) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
RUNTIME_CHECK(isc_timermgr_create(mctx, &timermgr) ==
|
RUNTIME_CHECK(isc_timermgr_create(mctx, &timermgr) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
|
|||||||
@@ -181,7 +181,7 @@ main(int argc, char *argv[]) {
|
|||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
mctx2 = NULL;
|
mctx2 = NULL;
|
||||||
isc_mem_create(&mctx2);
|
isc_mem_create(&mctx2);
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, &task_manager) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, NULL, &task_manager) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
RUNTIME_CHECK(isc_timermgr_create(mctx, &timer_manager) ==
|
RUNTIME_CHECK(isc_timermgr_create(mctx, &timer_manager) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
|
|||||||
@@ -226,7 +226,7 @@ main(int argc, char *argv[]) {
|
|||||||
dst_result_register();
|
dst_result_register();
|
||||||
|
|
||||||
taskmgr = NULL;
|
taskmgr = NULL;
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, 2, 0, &taskmgr) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, 2, 0, NULL, &taskmgr) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
task1 = NULL;
|
task1 = NULL;
|
||||||
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task1) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_task_create(taskmgr, 0, &task1) == ISC_R_SUCCESS);
|
||||||
|
|||||||
@@ -292,7 +292,7 @@ main(int argc, char *argv[]) {
|
|||||||
* The task manager is independent (other than memory context)
|
* The task manager is independent (other than memory context)
|
||||||
*/
|
*/
|
||||||
manager = NULL;
|
manager = NULL;
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, &manager) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, NULL, &manager) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
|
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, &manager) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, workers, 0, NULL, &manager) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
|
|
||||||
RUNTIME_CHECK(isc_task_create(manager, 0, &t1) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_task_create(manager, 0, &t1) == ISC_R_SUCCESS);
|
||||||
|
|||||||
@@ -108,7 +108,7 @@ main(int argc, char *argv[]) {
|
|||||||
printf("%u workers\n", workers);
|
printf("%u workers\n", workers);
|
||||||
|
|
||||||
isc_mem_create(&mctx1);
|
isc_mem_create(&mctx1);
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx1, workers, 0, &manager) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx1, workers, 0, NULL, &manager) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
RUNTIME_CHECK(isc_timermgr_create(mctx1, &timgr) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_timermgr_create(mctx1, &timgr) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
|||||||
@@ -146,12 +146,11 @@ query(void) {
|
|||||||
dns_fixedname_t name;
|
dns_fixedname_t name;
|
||||||
dns_fixedname_t found;
|
dns_fixedname_t found;
|
||||||
dns_db_t *db;
|
dns_db_t *db;
|
||||||
char *s;
|
|
||||||
isc_buffer_t buffer;
|
isc_buffer_t buffer;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_rdataset_t sigset;
|
dns_rdataset_t sigset;
|
||||||
fd_set rfdset;
|
fd_set rfdset = { { 0 } };
|
||||||
|
|
||||||
db = NULL;
|
db = NULL;
|
||||||
result = dns_zone_getdb(zone, &db);
|
result = dns_zone_getdb(zone, &db);
|
||||||
@@ -166,7 +165,7 @@ query(void) {
|
|||||||
dns_rdataset_init(&sigset);
|
dns_rdataset_init(&sigset);
|
||||||
|
|
||||||
do {
|
do {
|
||||||
|
char *s;
|
||||||
fprintf(stdout, "zone_test ");
|
fprintf(stdout, "zone_test ");
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
FD_ZERO(&rfdset);
|
FD_ZERO(&rfdset);
|
||||||
@@ -281,7 +280,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
RUNTIME_CHECK(isc_app_start() == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_app_start() == ISC_R_SUCCESS);
|
||||||
isc_mem_create(&mctx);
|
isc_mem_create(&mctx);
|
||||||
RUNTIME_CHECK(isc_taskmgr_create(mctx, 2, 0, &taskmgr) ==
|
RUNTIME_CHECK(isc_taskmgr_create(mctx, 2, 0, NULL, &taskmgr) ==
|
||||||
ISC_R_SUCCESS);
|
ISC_R_SUCCESS);
|
||||||
RUNTIME_CHECK(isc_timermgr_create(mctx, &timermgr) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_timermgr_create(mctx, &timermgr) == ISC_R_SUCCESS);
|
||||||
RUNTIME_CHECK(isc_socketmgr_create(mctx, &socketmgr) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_socketmgr_create(mctx, &socketmgr) == ISC_R_SUCCESS);
|
||||||
|
|||||||
@@ -584,10 +584,6 @@ By default, start.pl starts a "named" server with the following options:
|
|||||||
preventing multiple instances of this named running in this
|
preventing multiple instances of this named running in this
|
||||||
directory (which could possibly interfere with the test).
|
directory (which could possibly interfere with the test).
|
||||||
|
|
||||||
In addition, start.pl also sets the following undocumented flag:
|
|
||||||
|
|
||||||
-T clienttest Makes clients single-shot with their own memory context.
|
|
||||||
|
|
||||||
All output is sent to a file called "named.run" in the nameserver directory.
|
All output is sent to a file called "named.run" in the nameserver directory.
|
||||||
|
|
||||||
The options used to start named can be altered. There are three ways of doing
|
The options used to start named can be altered. There are three ways of doing
|
||||||
@@ -608,9 +604,9 @@ the named command-line arguments. The rest of the file is ignored.
|
|||||||
|
|
||||||
3. Tweaking the default command line arguments with "-T" options. This flag is
|
3. Tweaking the default command line arguments with "-T" options. This flag is
|
||||||
used to alter the behavior of BIND for testing and is not documented in the
|
used to alter the behavior of BIND for testing and is not documented in the
|
||||||
ARM. The "clienttest" option has already been mentioned, but the presence of
|
ARM. The presence of certain files in the "nsN" directory adds flags to
|
||||||
certain files in the "nsN" directory adds flags to the default command line
|
the default command line (the content of the files is irrelevant - it
|
||||||
(the content of the files is irrelevant - it is only the presence that counts):
|
is only the presence that counts):
|
||||||
|
|
||||||
named.noaa Appends "-T noaa" to the command line, which causes
|
named.noaa Appends "-T noaa" to the command line, which causes
|
||||||
"named" to never set the AA bit in an answer.
|
"named" to never set the AA bit in an answer.
|
||||||
@@ -635,7 +631,6 @@ certain files in the "nsN" directory adds flags to the default command line
|
|||||||
the additional section if the response is triggered by RPZ
|
the additional section if the response is triggered by RPZ
|
||||||
rewriting).
|
rewriting).
|
||||||
|
|
||||||
|
|
||||||
Starting Other Nameservers
|
Starting Other Nameservers
|
||||||
---
|
---
|
||||||
In contrast to "named", nameservers written in Perl or Python (whose script
|
In contrast to "named", nameservers written in Perl or Python (whose script
|
||||||
|
|||||||
@@ -1,2 +1,2 @@
|
|||||||
# this server runs named with only one worker thread
|
# this server runs named with only one worker thread
|
||||||
-m record,size,mctx -c named.conf -d 99 -D additional-ns1 -X named.lock -g -T clienttest -n 1
|
-m record,size,mctx -c named.conf -d 99 -D additional-ns1 -X named.lock -g -n 1
|
||||||
|
|||||||
@@ -696,11 +696,17 @@ $RNDCCMD 10.53.0.3 addzone "test4.baz" '{ type master; file "e.db"; };' > /dev/n
|
|||||||
$RNDCCMD 10.53.0.3 addzone "test5.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1
|
$RNDCCMD 10.53.0.3 addzone "test5.baz" '{ type master; file "e.db"; };' > /dev/null 2>&1 || ret=1
|
||||||
$PERL $SYSTEMTESTTOP/stop.pl addzone ns3
|
$PERL $SYSTEMTESTTOP/stop.pl addzone ns3
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} addzone ns3 || ret=1
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} addzone ns3 || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 version.bind txt ch > dig.out.test$n || ret=1
|
for try in 0 1 2 3 4 5 6 7 8 9; do
|
||||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
iret=0
|
||||||
n=`expr $n + 1`
|
$DIG $DIGOPTS @10.53.0.3 version.bind txt ch > dig.out.test$n || iret=1
|
||||||
|
grep "status: NOERROR" dig.out.test$n > /dev/null || iret=1
|
||||||
|
[ "$iret" -eq 0 ] && break
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
[ "$iret" -ne 0 ] && ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
n=`expr $n + 1`
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -1,2 +1,2 @@
|
|||||||
# this server only has 127.0.0.1 in its localhost/localnets ACLs
|
# this server only has 127.0.0.1 in its localhost/localnets ACLs
|
||||||
-m record,size,mctx -c named.conf -d 99 -D allow-query-ns3 -X named.lock -g -T clienttest -T fixedlocal
|
-m record,size,mctx -c named.conf -d 99 -D allow-query-ns3 -X named.lock -g -T fixedlocal
|
||||||
|
|||||||
@@ -39,6 +39,7 @@ rm -f ns3/inacksk2.example.db
|
|||||||
rm -f ns3/inacksk3.example.db
|
rm -f ns3/inacksk3.example.db
|
||||||
rm -f ns3/inaczsk2.example.db
|
rm -f ns3/inaczsk2.example.db
|
||||||
rm -f ns3/inaczsk3.example.db
|
rm -f ns3/inaczsk3.example.db
|
||||||
|
rm -f ns3/jitter.nsec3.example.db
|
||||||
rm -f ns3/kg.out ns3/s.out ns3/st.out
|
rm -f ns3/kg.out ns3/s.out ns3/st.out
|
||||||
rm -f ns3/kskonly.example.db
|
rm -f ns3/kskonly.example.db
|
||||||
rm -f ns3/nozsk.example.db ns3/inaczsk.example.db
|
rm -f ns3/nozsk.example.db ns3/inaczsk.example.db
|
||||||
|
|||||||
@@ -33,12 +33,12 @@ rm $zsknopriv.private
|
|||||||
ksksby=`$KEYGEN -3 -a RSASHA1 -q -P now -A now+15s -fk $zone`
|
ksksby=`$KEYGEN -3 -a RSASHA1 -q -P now -A now+15s -fk $zone`
|
||||||
kskrev=`$KEYGEN -3 -a RSASHA1 -q -R now+15s -fk $zone`
|
kskrev=`$KEYGEN -3 -a RSASHA1 -q -R now+15s -fk $zone`
|
||||||
|
|
||||||
keyfile_to_static_keys $ksksby > trusted.conf
|
keyfile_to_static_ds $ksksby > trusted.conf
|
||||||
cp trusted.conf ../ns2/trusted.conf
|
cp trusted.conf ../ns2/trusted.conf
|
||||||
cp trusted.conf ../ns3/trusted.conf
|
cp trusted.conf ../ns3/trusted.conf
|
||||||
cp trusted.conf ../ns4/trusted.conf
|
cp trusted.conf ../ns4/trusted.conf
|
||||||
|
|
||||||
keyfile_to_static_keys $kskrev > trusted.conf
|
keyfile_to_static_ds $kskrev > trusted.conf
|
||||||
cp trusted.conf ../ns5/trusted.conf
|
cp trusted.conf ../ns5/trusted.conf
|
||||||
|
|
||||||
echo $zskact > ../active.key
|
echo $zskact > ../active.key
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ zonefile="${zone}.db"
|
|||||||
infile="${zonefile}.in"
|
infile="${zonefile}.in"
|
||||||
ksk=`$KEYGEN -a RSASHA1 -3 -q -fk $zone`
|
ksk=`$KEYGEN -a RSASHA1 -3 -q -fk $zone`
|
||||||
$KEYGEN -a RSASHA1 -3 -q $zone > /dev/null
|
$KEYGEN -a RSASHA1 -3 -q $zone > /dev/null
|
||||||
keyfile_to_static_keys $ksk > private.conf
|
keyfile_to_static_ds $ksk > private.conf
|
||||||
cp private.conf ../ns4/private.conf
|
cp private.conf ../ns4/private.conf
|
||||||
$SIGNER -S -3 beef -A -o $zone -f $zonefile $infile > /dev/null
|
$SIGNER -S -3 beef -A -o $zone -f $zonefile $infile > /dev/null
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
;
|
||||||
|
; See the COPYRIGHT file distributed with this work for additional
|
||||||
|
; information regarding copyright ownership.
|
||||||
|
|
||||||
|
$TTL 300 ; 5 minutes
|
||||||
|
@ IN SOA mname1. . (
|
||||||
|
2000042407 ; serial
|
||||||
|
20 ; refresh (20 seconds)
|
||||||
|
20 ; retry (20 seconds)
|
||||||
|
1814400 ; expire (3 weeks)
|
||||||
|
3600 ; minimum (1 hour)
|
||||||
|
)
|
||||||
|
NS ns
|
||||||
|
ns A 10.53.0.3
|
||||||
|
|
||||||
@@ -52,6 +52,21 @@ ksk=`$KEYGEN -q -a RSASHA1 -3 -fk $zone 2> kg.out` || dumpit kg.out
|
|||||||
$KEYGEN -q -a RSASHA1 -3 $zone > kg.out 2>&1 || dumpit kg.out
|
$KEYGEN -q -a RSASHA1 -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||||
|
|
||||||
|
#
|
||||||
|
# Jitter/NSEC3 test zone
|
||||||
|
#
|
||||||
|
setup jitter.nsec3.example
|
||||||
|
cp $infile $zonefile
|
||||||
|
count=1
|
||||||
|
while [ $count -le 1000 ]
|
||||||
|
do
|
||||||
|
echo "label${count} IN TXT label${count}" >> $zonefile
|
||||||
|
count=`expr $count + 1`
|
||||||
|
done
|
||||||
|
# Don't create keys just yet, because the scenario we want to test
|
||||||
|
# is an unsigned zone that has a NSEC3PARAM record added with
|
||||||
|
# dynamic update before the keys are generated.
|
||||||
|
|
||||||
#
|
#
|
||||||
# OPTOUT/NSEC3 test zone
|
# OPTOUT/NSEC3 test zone
|
||||||
#
|
#
|
||||||
@@ -150,9 +165,16 @@ $DSFROMKEY $ksk.key > dsset-${zone}$TP
|
|||||||
#
|
#
|
||||||
setup oldsigs.example
|
setup oldsigs.example
|
||||||
cp $infile $zonefile
|
cp $infile $zonefile
|
||||||
|
count=1
|
||||||
|
while [ $count -le 1000 ]
|
||||||
|
do
|
||||||
|
echo "label${count} IN TXT label${count}" >> $zonefile
|
||||||
|
count=`expr $count + 1`
|
||||||
|
done
|
||||||
$KEYGEN -q -a RSASHA1 -fk $zone > kg.out 2>&1 || dumpit kg.out
|
$KEYGEN -q -a RSASHA1 -fk $zone > kg.out 2>&1 || dumpit kg.out
|
||||||
$KEYGEN -q -a RSASHA1 $zone > kg.out 2>&1 || dumpit kg.out
|
$KEYGEN -q -a RSASHA1 $zone > kg.out 2>&1 || dumpit kg.out
|
||||||
$SIGNER -PS -s now-1y -e now-6mo -o $zone -f $zonefile $infile > s.out || dumpit s.out
|
$SIGNER -PS -s now-1y -e now-6mo -o $zone -f $zonefile.signed $zonefile > s.out || dumpit s.out
|
||||||
|
mv $zonefile.signed $zonefile
|
||||||
|
|
||||||
#
|
#
|
||||||
# NSEC3->NSEC transition test zone.
|
# NSEC3->NSEC transition test zone.
|
||||||
|
|||||||
@@ -95,6 +95,16 @@ zone "nsec3.nsec3.example" {
|
|||||||
auto-dnssec maintain;
|
auto-dnssec maintain;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
zone "jitter.nsec3.example" {
|
||||||
|
type master;
|
||||||
|
file "jitter.nsec3.example.db";
|
||||||
|
allow-update { any; };
|
||||||
|
auto-dnssec maintain;
|
||||||
|
sig-validity-interval 10 2;
|
||||||
|
sig-signing-nodes 1000;
|
||||||
|
sig-signing-signatures 100;
|
||||||
|
};
|
||||||
|
|
||||||
zone "secure.nsec3.example" {
|
zone "secure.nsec3.example" {
|
||||||
type master;
|
type master;
|
||||||
file "secure.nsec3.example.db";
|
file "secure.nsec3.example.db";
|
||||||
@@ -178,6 +188,9 @@ zone "oldsigs.example" {
|
|||||||
file "oldsigs.example.db";
|
file "oldsigs.example.db";
|
||||||
allow-update { any; };
|
allow-update { any; };
|
||||||
auto-dnssec maintain;
|
auto-dnssec maintain;
|
||||||
|
sig-validity-interval 10 2;
|
||||||
|
sig-signing-nodes 1000;
|
||||||
|
sig-signing-signatures 100;
|
||||||
};
|
};
|
||||||
|
|
||||||
zone "prepub.example" {
|
zone "prepub.example" {
|
||||||
|
|||||||
@@ -50,6 +50,75 @@ checkprivate () {
|
|||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
freq() {
|
||||||
|
_file=$1
|
||||||
|
# remove first and last line that has incomplete set and skews the distribution
|
||||||
|
awk '$4 == "RRSIG" {print substr($9,1,8)}' < "$_file" | sort | uniq -c | sed '1d;$d'
|
||||||
|
}
|
||||||
|
# Check the signatures expiration times. First check how many signatures
|
||||||
|
# there are in total ($rrsigs). Then see what the distribution of signature
|
||||||
|
# expiration times is ($expiretimes). Ignore the time part for a better
|
||||||
|
# modelled distribution.
|
||||||
|
checkjitter () {
|
||||||
|
_file=$1
|
||||||
|
_ret=0
|
||||||
|
|
||||||
|
if ! command -v bc >/dev/null 2>&1; then
|
||||||
|
echo_i "skip: bc not available"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
freq "$_file" | cat_i
|
||||||
|
_expiretimes=$(freq "$_file" | awk '{print $1}')
|
||||||
|
|
||||||
|
_count=0
|
||||||
|
# Check if we have at least 5 days
|
||||||
|
# This number has been tuned for `sig-validity-interval 10 2`, as
|
||||||
|
# 1. 1. signature expiration dates should be spread out across at most 8 (10-2) days
|
||||||
|
# 2. we remove first and last day to remove frequency outlier, we are left with 6 (8-2) days
|
||||||
|
# 3. we substract one more day to allow test pass on day boundaries, etc. leaving us with 5 (6-1) days
|
||||||
|
for _num in $_expiretimes
|
||||||
|
do
|
||||||
|
_count=$((_count+1))
|
||||||
|
done
|
||||||
|
if [ "$_count" -lt 5 ]; then
|
||||||
|
echo_i "error: not enough categories"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Calculate mean
|
||||||
|
_total=0
|
||||||
|
for _num in $_expiretimes
|
||||||
|
do
|
||||||
|
_total=$((_total+_num))
|
||||||
|
done
|
||||||
|
_mean=$(($_total / $_count))
|
||||||
|
|
||||||
|
# Calculate stddev
|
||||||
|
_stddev=0
|
||||||
|
for _num in $_expiretimes
|
||||||
|
do
|
||||||
|
_stddev=$(echo "$_stddev + (($_num - $_mean) * ($_num - $_mean))" | bc)
|
||||||
|
done
|
||||||
|
_stddev=$(echo "sqrt($_stddev/$_count)" | bc)
|
||||||
|
|
||||||
|
# We expect the number of signatures not to exceed the mean +- 3 * stddev.
|
||||||
|
_limit=$((_stddev*3))
|
||||||
|
_low=$((_mean-_limit))
|
||||||
|
_high=$((_mean+_limit))
|
||||||
|
# Find outliers.
|
||||||
|
echo_i "checking whether all frequencies fall into <$_low;$_high> range"
|
||||||
|
for _num in $_expiretimes
|
||||||
|
do
|
||||||
|
if [ $_num -gt $_high ] || [ $_num -lt $_low ]; then
|
||||||
|
echo_i "error: too many RRSIG records ($_num) with the same expiration time"
|
||||||
|
_ret=1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
return $_ret
|
||||||
|
}
|
||||||
|
|
||||||
#
|
#
|
||||||
# The NSEC record at the apex of the zone and its RRSIG records are
|
# The NSEC record at the apex of the zone and its RRSIG records are
|
||||||
# added as part of the last step in signing a zone. We wait for the
|
# added as part of the last step in signing a zone. We wait for the
|
||||||
@@ -322,18 +391,33 @@ $RNDCCMD 10.53.0.1 sync 2>&1 | sed 's/^/ns1 /' | cat_i
|
|||||||
$RNDCCMD 10.53.0.2 sync 2>&1 | sed 's/^/ns2 /' | cat_i
|
$RNDCCMD 10.53.0.2 sync 2>&1 | sed 's/^/ns2 /' | cat_i
|
||||||
$RNDCCMD 10.53.0.3 sync 2>&1 | sed 's/^/ns3 /' | cat_i
|
$RNDCCMD 10.53.0.3 sync 2>&1 | sed 's/^/ns3 /' | cat_i
|
||||||
|
|
||||||
|
now="$(TZ=UTC date +%Y%m%d%H%M%S)"
|
||||||
|
check_expiry() (
|
||||||
|
$DIG $DIGOPTS AXFR oldsigs.example @10.53.0.3 > dig.out.test$n
|
||||||
|
nearest_expiration="$(awk '$4 == "RRSIG" { print $9 }' < dig.out.test$n | sort -n | head -1)"
|
||||||
|
if [ "$nearest_expiration" -le "$now" ]; then
|
||||||
|
echo_i "failed: $nearest_expiration <= $now"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
)
|
||||||
|
|
||||||
echo_i "checking expired signatures were updated ($n)"
|
echo_i "checking expired signatures were updated ($n)"
|
||||||
for i in 1 2 3 4 5 6 7 8 9
|
retry 10 check_expiry || ret=1
|
||||||
do
|
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1
|
||||||
ret=0
|
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1
|
||||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1
|
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1
|
||||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1
|
||||||
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1
|
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1
|
|
||||||
[ $ret = 0 ] && break
|
|
||||||
sleep 1
|
|
||||||
done
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
# Check jitter distribution.
|
||||||
|
echo_i "checking expired signatures were jittered correctly ($n)"
|
||||||
|
ret=0
|
||||||
|
$DIG $DIGOPTS axfr oldsigs.example @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||||
|
checkjitter dig.out.ns3.test$n || ret=1
|
||||||
|
n=`expr $n + 1`
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo_i "checking NSEC->NSEC3 conversion succeeded ($n)"
|
echo_i "checking NSEC->NSEC3 conversion succeeded ($n)"
|
||||||
@@ -938,6 +1022,33 @@ n=`expr $n + 1`
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
echo_i "checking jitter in a newly signed NSEC3 zone ($n)"
|
||||||
|
ret=0
|
||||||
|
# Use DNS UPDATE to add an NSEC3PARAM record into the zone.
|
||||||
|
$NSUPDATE > nsupdate.out.test$n 2>&1 <<END || ret=1
|
||||||
|
server 10.53.0.3 ${PORT}
|
||||||
|
zone jitter.nsec3.example.
|
||||||
|
update add jitter.nsec3.example. 3600 NSEC3PARAM 1 0 10 BEEF
|
||||||
|
send
|
||||||
|
END
|
||||||
|
[ $ret != 0 ] && echo_i "error: dynamic update add NSEC3PARAM failed"
|
||||||
|
# Create DNSSEC keys in the zone directory.
|
||||||
|
$KEYGEN -a rsasha1 -3 -q -K ns3 jitter.nsec3.example > /dev/null
|
||||||
|
# Trigger zone signing.
|
||||||
|
$RNDCCMD 10.53.0.3 sign jitter.nsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i
|
||||||
|
# Wait until zone has been signed.
|
||||||
|
check_if_nsec3param_exists() {
|
||||||
|
$DIG $DIGOPTS NSEC3PARAM jitter.nsec3.example @10.53.0.3 > dig.out.ns3.1.test$n || return 1
|
||||||
|
grep -q "^jitter\.nsec3\.example\..*NSEC3PARAM" dig.out.ns3.1.test$n || return 1
|
||||||
|
}
|
||||||
|
retry_quiet 20 check_if_nsec3param_exists || ret=1
|
||||||
|
$DIG $DIGOPTS AXFR jitter.nsec3.example @10.53.0.3 > dig.out.ns3.2.test$n || ret=1
|
||||||
|
# Check jitter distribution.
|
||||||
|
checkjitter dig.out.ns3.2.test$n || ret=1
|
||||||
|
n=`expr $n + 1`
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo_i "checking that serial number and RRSIGs are both updated (rt21045) ($n)"
|
echo_i "checking that serial number and RRSIGs are both updated (rt21045) ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
oldserial=`$DIG $DIGOPTS +short soa prepub.example @10.53.0.3 | awk '$0 !~ /SOA/ {print $3}'`
|
oldserial=`$DIG $DIGOPTS +short soa prepub.example @10.53.0.3 | awk '$0 !~ /SOA/ {print $3}'`
|
||||||
@@ -1248,7 +1359,6 @@ $DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
|
|||||||
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null || ret=1
|
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null || ret=1
|
||||||
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null || ret=1
|
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null || ret=1
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
@@ -1283,19 +1393,19 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
|||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo_i "setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'"
|
echo_i "setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'"
|
||||||
$SETTIME -D sync now+2 `cat sync.key` > /dev/null
|
$SETTIME -D sync now `cat sync.key` > /dev/null
|
||||||
$RNDCCMD 10.53.0.3 loadkeys sync.example | sed 's/^/ns3 /' | cat_i
|
$RNDCCMD 10.53.0.3 loadkeys sync.example | sed 's/^/ns3 /' | cat_i
|
||||||
echo_i "waiting for deletion to occur"
|
|
||||||
sleep 3
|
|
||||||
|
|
||||||
echo_i "checking that the CDS and CDNSKEY are deleted ($n)"
|
echo_i "checking that the CDS and CDNSKEY are deleted ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$DIG $DIGOPTS @10.53.0.3 sync.example cds > dig.out.ns3.cdstest$n
|
ensure_cds_and_cdnskey_are_deleted() {
|
||||||
$DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
|
$DIG $DIGOPTS @10.53.0.3 sync.example. CDS > dig.out.ns3.cdstest$n || return 1
|
||||||
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null && ret=1
|
awk '$1 == "sync.example." && $4 == "CDS" { exit 1; }' dig.out.ns3.cdstest$n || return 1
|
||||||
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null && ret=1
|
$DIG $DIGOPTS @10.53.0.3 sync.example. CDNSKEY > dig.out.ns3.cdnskeytest$n || return 1
|
||||||
|
awk '$1 == "sync.example." && $4 == "CDNSKEY" { exit 1; }' dig.out.ns3.cdnskeytest$n || return 1
|
||||||
|
}
|
||||||
|
retry 10 ensure_cds_and_cdnskey_are_deleted || ret=1
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
@@ -1304,7 +1414,6 @@ ret=0
|
|||||||
$SETTIME -p Dsync `cat sync.key` > settime.out.$n|| ret=0
|
$SETTIME -p Dsync `cat sync.key` > settime.out.$n|| ret=0
|
||||||
grep "SYNC Delete:" settime.out.$n >/dev/null || ret=0
|
grep "SYNC Delete:" settime.out.$n >/dev/null || ret=0
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
@@ -1313,7 +1422,6 @@ ret=0
|
|||||||
$SETTIME -p Psync `cat sync.key` > settime.out.$n|| ret=0
|
$SETTIME -p Psync `cat sync.key` > settime.out.$n|| ret=0
|
||||||
grep "SYNC Publish:" settime.out.$n >/dev/null || ret=0
|
grep "SYNC Publish:" settime.out.$n >/dev/null || ret=0
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||||
|
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||||
|
};
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||||
|
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||||
|
};
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// Using the keyword 'default' is not allowed.
|
||||||
|
dnssec-policy "default" {
|
||||||
|
signatures-refresh P5D;
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "example.net" {
|
||||||
|
type master;
|
||||||
|
file "example.db";
|
||||||
|
dnssec-policy "default";
|
||||||
|
};
|
||||||
|
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
include "good-kasp.conf";
|
||||||
|
|
||||||
|
// Bad zone configuration because this has dnssec-policy and other DNSSEC sign
|
||||||
|
// configuration options (auto-dnssec).
|
||||||
|
zone "example.net" {
|
||||||
|
type master;
|
||||||
|
file "example.db";
|
||||||
|
dnssec-policy "test";
|
||||||
|
auto-dnssec maintain;
|
||||||
|
allow-update { any; };
|
||||||
|
};
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
include "good-kasp.conf";
|
||||||
|
|
||||||
|
// Bad zone configuration because this has dnssec-policy with no matching
|
||||||
|
// dnssec-policy configuration (good-kasp.conf has "test", zone refers to
|
||||||
|
// "nosuchpolicy".
|
||||||
|
zone "example.net" {
|
||||||
|
type master;
|
||||||
|
file "example.db";
|
||||||
|
dnssec-policy "nosuchpolicy";
|
||||||
|
};
|
||||||
|
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// Bad kasp configuration because this has an invalid duration for
|
||||||
|
// signatures-refresh.
|
||||||
|
dnssec-policy "badduration" {
|
||||||
|
signatures-refresh PT20Sabcd;
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "example.net" {
|
||||||
|
type master;
|
||||||
|
file "example.db";
|
||||||
|
dnssec-policy "badduration";
|
||||||
|
};
|
||||||
|
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// Using the keyword 'none' is not allowed.
|
||||||
|
dnssec-policy "none" {
|
||||||
|
signatures-refresh P5D;
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "example.net" {
|
||||||
|
type master;
|
||||||
|
file "example.db";
|
||||||
|
dnssec-policy "none";
|
||||||
|
};
|
||||||
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||||
|
example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||||
|
};
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||||
|
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||||
|
};
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||||
|
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||||
|
};
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. initial-key 257 3 5 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafGtURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJYkYrFYGLzYAgl/JtMyVVYlBl9pqxQuAPKYPOuO1axaad/wLN3+wTy/hcJfpvJpqzXlDF9bI5RmpoX/7geZ06vpcYJEoT0xkkmPlEl0ZjEDrm/WIaSWG0/CEDpHcOXFz4OEczMVpY+lnuFfKybwF1WHFn2BwVEOS6cMM6ukIjINQyrszHhWUU=";
|
||||||
|
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||||
|
};
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
. static-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
|
||||||
|
};
|
||||||
@@ -10,6 +10,7 @@
|
|||||||
# information regarding copyright ownership.
|
# information regarding copyright ownership.
|
||||||
|
|
||||||
rm -f good.conf.in good.conf.out badzero.conf *.out
|
rm -f good.conf.in good.conf.out badzero.conf *.out
|
||||||
|
rm -f good-kasp.conf.in
|
||||||
rm -rf test.keydir
|
rm -rf test.keydir
|
||||||
rm -f checkconf.out*
|
rm -f checkconf.out*
|
||||||
rm -f diff.out*
|
rm -f diff.out*
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
options {
|
||||||
|
dnskey-sig-validity 3660; /* maximum value 10 years */
|
||||||
|
};
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
options {
|
||||||
|
dnskey-sig-validity 0; /* 0 is disabled */
|
||||||
|
};
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. initial-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||||
|
};
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This is just a random selection of DNSSEC configuration options.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/* cut here */
|
||||||
|
dnssec-policy "test" {
|
||||||
|
dnskey-ttl 3600;
|
||||||
|
keys {
|
||||||
|
ksk key-directory lifetime P1Y algorithm 13 256;
|
||||||
|
zsk key-directory lifetime P30D algorithm 13;
|
||||||
|
csk key-directory lifetime P30D algorithm 8 2048;
|
||||||
|
};
|
||||||
|
publish-safety PT3600S;
|
||||||
|
retire-safety PT3600S;
|
||||||
|
signatures-refresh P3D;
|
||||||
|
signatures-validity P2W;
|
||||||
|
signatures-validity-dnskey P14D;
|
||||||
|
zone-max-ttl 86400;
|
||||||
|
zone-propagation-delay PT5M;
|
||||||
|
parent-ds-ttl 7200;
|
||||||
|
parent-propagation-delay PT1H;
|
||||||
|
parent-registration-delay P1D;
|
||||||
|
};
|
||||||
|
options {
|
||||||
|
dnssec-policy "default";
|
||||||
|
};
|
||||||
|
zone "example1" {
|
||||||
|
type master;
|
||||||
|
file "example1.db";
|
||||||
|
};
|
||||||
|
zone "example2" {
|
||||||
|
type master;
|
||||||
|
file "example2.db";
|
||||||
|
dnssec-policy "test";
|
||||||
|
};
|
||||||
|
zone "example3" {
|
||||||
|
type master;
|
||||||
|
file "example3.db";
|
||||||
|
dnssec-policy "default";
|
||||||
|
};
|
||||||
|
zone "example4" {
|
||||||
|
type master;
|
||||||
|
file "example4.db";
|
||||||
|
dnssec-policy "none";
|
||||||
|
};
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
dnssec-keys {
|
||||||
|
example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||||
|
};
|
||||||
@@ -14,6 +14,24 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
/* cut here */
|
/* cut here */
|
||||||
|
dnssec-policy "test" {
|
||||||
|
dnskey-ttl 3600;
|
||||||
|
keys {
|
||||||
|
ksk key-directory lifetime P1Y algorithm 13 256;
|
||||||
|
zsk key-directory lifetime P30D algorithm 13;
|
||||||
|
csk key-directory lifetime P30D algorithm 8 2048;
|
||||||
|
};
|
||||||
|
publish-safety PT3600S;
|
||||||
|
retire-safety PT3600S;
|
||||||
|
signatures-refresh P3D;
|
||||||
|
signatures-validity P2W;
|
||||||
|
signatures-validity-dnskey P14D;
|
||||||
|
zone-max-ttl 86400;
|
||||||
|
zone-propagation-delay PT5M;
|
||||||
|
parent-ds-ttl 7200;
|
||||||
|
parent-propagation-delay PT1H;
|
||||||
|
parent-registration-delay P1D;
|
||||||
|
};
|
||||||
options {
|
options {
|
||||||
avoid-v4-udp-ports {
|
avoid-v4-udp-ports {
|
||||||
100;
|
100;
|
||||||
@@ -60,6 +78,7 @@ options {
|
|||||||
validate-except {
|
validate-except {
|
||||||
"corp";
|
"corp";
|
||||||
};
|
};
|
||||||
|
dnssec-policy "test";
|
||||||
transfer-source 0.0.0.0 dscp 63;
|
transfer-source 0.0.0.0 dscp 63;
|
||||||
zone-statistics none;
|
zone-statistics none;
|
||||||
};
|
};
|
||||||
@@ -140,6 +159,28 @@ view "third" {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
view "fourth" {
|
||||||
|
zone "dnssec-test" {
|
||||||
|
type master;
|
||||||
|
file "dnssec-test.db";
|
||||||
|
dnssec-policy "test";
|
||||||
|
};
|
||||||
|
zone "dnssec-default" {
|
||||||
|
type master;
|
||||||
|
file "dnssec-default.db";
|
||||||
|
dnssec-policy "default";
|
||||||
|
};
|
||||||
|
zone "dnssec-inherit" {
|
||||||
|
type master;
|
||||||
|
file "dnssec-inherit.db";
|
||||||
|
};
|
||||||
|
zone "dnssec-none" {
|
||||||
|
type master;
|
||||||
|
file "dnssec-none.db";
|
||||||
|
dnssec-policy "none";
|
||||||
|
};
|
||||||
|
dnssec-policy "default";
|
||||||
|
};
|
||||||
view "chaos" chaos {
|
view "chaos" chaos {
|
||||||
zone "hostname.bind" chaos {
|
zone "hostname.bind" chaos {
|
||||||
type master;
|
type master;
|
||||||
|
|||||||
@@ -8,4 +8,8 @@ clone IN third in-view first
|
|||||||
dnssec IN third master
|
dnssec IN third master
|
||||||
p IN third primary
|
p IN third primary
|
||||||
s IN third secondary
|
s IN third secondary
|
||||||
|
dnssec-test IN fourth master
|
||||||
|
dnssec-default IN fourth master
|
||||||
|
dnssec-inherit IN fourth master
|
||||||
|
dnssec-none IN fourth master
|
||||||
hostname.bind chaos chaos master
|
hostname.bind chaos chaos master
|
||||||
|
|||||||
@@ -0,0 +1,28 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*
|
||||||
|
* See the COPYRIGHT file distributed with this work for additional
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
include "good-kasp.conf";
|
||||||
|
|
||||||
|
zone "nsec3.net" {
|
||||||
|
type master;
|
||||||
|
file "nsec3.db";
|
||||||
|
dnssec-policy "test";
|
||||||
|
auto-dnssec maintain;
|
||||||
|
dnskey-sig-validity 3600;
|
||||||
|
dnssec-dnskey-kskonly yes;
|
||||||
|
dnssec-secure-to-insecure yes;
|
||||||
|
dnssec-update-mode maintain;
|
||||||
|
inline-signing yes;
|
||||||
|
sig-validity-interval 3600;
|
||||||
|
update-check-ksk yes;
|
||||||
|
allow-update { any; };
|
||||||
|
};
|
||||||
|
|
||||||
@@ -437,7 +437,15 @@ n=`expr $n + 1`
|
|||||||
echo_i "check that a static root key generates a warning ($n)"
|
echo_i "check that a static root key generates a warning ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$CHECKCONF check-root-static-key.conf > checkconf.out$n 2>/dev/null || ret=1
|
$CHECKCONF check-root-static-key.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
grep "static-key entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
grep "static entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo_i "check that a static root DS trust anchor generates a warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF check-root-static-ds.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
|
grep "static entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
@@ -466,5 +474,38 @@ grep "'geoip-use-ecs' is obsolete" < checkconf.out$n > /dev/null || ret=1
|
|||||||
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo_i "checking named-checkconf kasp warnings ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF kasp-and-other-dnssec-options.conf > checkconf.out$n 2>&1
|
||||||
|
grep "'auto-dnssec maintain;' cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "dnskey-sig-validity: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "dnssec-dnskey-kskonly: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "dnssec-secure-to-insecure: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "dnssec-update-mode: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "inline-signing: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "sig-validity-interval: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
grep "update-check-ksk: cannot be configured if dnssec-policy is also set" < checkconf.out$n > /dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo_i "check that a good 'kasp' configuration is accepted ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF good-kasp.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo_i "checking that named-checkconf prints a known good kasp config ($n)"
|
||||||
|
ret=0
|
||||||
|
awk 'BEGIN { ok = 0; } /cut here/ { ok = 1; getline } ok == 1 { print }' good-kasp.conf > good-kasp.conf.in
|
||||||
|
[ -s good-kasp.conf.in ] || ret=1
|
||||||
|
$CHECKCONF -p good-kasp.conf.in | grep -v '^good-kasp.conf.in:' > good-kasp.conf.out 2>&1 || ret=1
|
||||||
|
cmp good-kasp.conf.in good-kasp.conf.out || ret=1
|
||||||
|
|
||||||
|
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo_i "exit status: $status"
|
echo_i "exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
+102
-17
@@ -9,17 +9,14 @@
|
|||||||
# See the COPYRIGHT file distributed with this work for additional
|
# See the COPYRIGHT file distributed with this work for additional
|
||||||
# information regarding copyright ownership.
|
# information regarding copyright ownership.
|
||||||
|
|
||||||
if test -n "$PERL"
|
testsock6() {
|
||||||
then
|
if test -n "$PERL" && $PERL -e "use IO::Socket::INET6;" 2> /dev/null
|
||||||
if $PERL -e "use IO::Socket::INET6;" 2> /dev/null
|
|
||||||
then
|
then
|
||||||
TESTSOCK6="$PERL $TOP/bin/tests/system/testsock6.pl"
|
$PERL "$TOP/bin/tests/system/testsock6.pl" "$@"
|
||||||
else
|
else
|
||||||
TESTSOCK6=false
|
false
|
||||||
fi
|
fi
|
||||||
else
|
}
|
||||||
TESTSOCK6=false
|
|
||||||
fi
|
|
||||||
|
|
||||||
export LANG=C
|
export LANG=C
|
||||||
|
|
||||||
@@ -64,7 +61,7 @@ PARALLEL_COMMON="dnssec rpzrecurse serve-stale \
|
|||||||
ednscompliance emptyzones \
|
ednscompliance emptyzones \
|
||||||
fetchlimit filter-aaaa formerr forward \
|
fetchlimit filter-aaaa formerr forward \
|
||||||
geoip2 glue idna inline integrity ixfr \
|
geoip2 glue idna inline integrity ixfr \
|
||||||
keepalive legacy limits \
|
kasp keepalive legacy limits \
|
||||||
masterfile masterformat metadata mirror mkeys \
|
masterfile masterformat metadata mirror mkeys \
|
||||||
names notify nslookup nsupdate nzd2nzf \
|
names notify nslookup nsupdate nzd2nzf \
|
||||||
padding pending pipelined qmin \
|
padding pending pipelined qmin \
|
||||||
@@ -205,10 +202,28 @@ DISABLED_BITS=384
|
|||||||
# Useful functions in test scripts
|
# Useful functions in test scripts
|
||||||
#
|
#
|
||||||
|
|
||||||
|
# assert_int_equal: compare two integer variables, $1 and $2
|
||||||
|
#
|
||||||
|
# If $1 and $2 are equal, return 0; if $1 and $2 are not equal, report
|
||||||
|
# the error using the description of the tested variable provided in $3
|
||||||
|
# and return 1.
|
||||||
|
assert_int_equal() {
|
||||||
|
found="$1"
|
||||||
|
expected="$2"
|
||||||
|
description="$3"
|
||||||
|
|
||||||
|
if [ "${expected}" -ne "${found}" ]; then
|
||||||
|
echo_i "incorrect ${description}: got ${found}, expected ${expected}"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
# keyfile_to_keys_section: helper function for keyfile_to_*_keys() which
|
# keyfile_to_keys_section: helper function for keyfile_to_*_keys() which
|
||||||
# converts keyfile data into a configuration section using the supplied
|
# converts keyfile data into a key-style trust anchor configuration
|
||||||
# parameters
|
# section using the supplied parameters
|
||||||
keyfile_to_keys_section() {
|
keyfile_to_keys() {
|
||||||
section_name=$1
|
section_name=$1
|
||||||
key_prefix=$2
|
key_prefix=$2
|
||||||
shift
|
shift
|
||||||
@@ -226,18 +241,54 @@ keyfile_to_keys_section() {
|
|||||||
echo "};"
|
echo "};"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# keyfile_to_dskeys_section: helper function for keyfile_to_*_dskeys()
|
||||||
|
# converts keyfile data into a DS-style trust anchor configuration
|
||||||
|
# section using the supplied parameters
|
||||||
|
keyfile_to_dskeys() {
|
||||||
|
section_name=$1
|
||||||
|
key_prefix=$2
|
||||||
|
shift
|
||||||
|
shift
|
||||||
|
echo "$section_name {"
|
||||||
|
for keyname in $*; do
|
||||||
|
$DSFROMKEY $keyname.key | \
|
||||||
|
awk '!/^; /{
|
||||||
|
printf "\t\""$1"\" "
|
||||||
|
printf "'"$key_prefix "'"
|
||||||
|
printf $4 " " $5 " " $6 " \""
|
||||||
|
for (i=7; i<=NF; i++) printf $i
|
||||||
|
printf "\";\n"
|
||||||
|
}'
|
||||||
|
done
|
||||||
|
echo "};"
|
||||||
|
}
|
||||||
|
|
||||||
# keyfile_to_static_keys: convert key data contained in the keyfile(s)
|
# keyfile_to_static_keys: convert key data contained in the keyfile(s)
|
||||||
# provided to a *static* "dnssec-keys" section suitable for including in a
|
# provided to a *static-key* "dnssec-keys" section suitable for including in a
|
||||||
# resolver's configuration file
|
# resolver's configuration file
|
||||||
keyfile_to_static_keys() {
|
keyfile_to_static_keys() {
|
||||||
keyfile_to_keys_section "dnssec-keys" "static-key" $*
|
keyfile_to_keys "dnssec-keys" "static-key" $*
|
||||||
}
|
}
|
||||||
|
|
||||||
# keyfile_to_initial_keys: convert key data contained in the keyfile(s)
|
# keyfile_to_initial_keys: convert key data contained in the keyfile(s)
|
||||||
# provided to an *initialzing* "dnssec-keys" section suitable for including
|
# provided to an *initial-key* "dnssec-keys" section suitable for including
|
||||||
# in a resolver's configuration file
|
# in a resolver's configuration file
|
||||||
keyfile_to_initial_keys() {
|
keyfile_to_initial_keys() {
|
||||||
keyfile_to_keys_section "dnssec-keys" "initial-key" $*
|
keyfile_to_keys "dnssec-keys" "initial-key" $*
|
||||||
|
}
|
||||||
|
|
||||||
|
# keyfile_to_static_ds_keys: convert key data contained in the keyfile(s)
|
||||||
|
# provided to a *static-ds* "dnssec-keys" section suitable for including in a
|
||||||
|
# resolver's configuration file
|
||||||
|
keyfile_to_static_ds() {
|
||||||
|
keyfile_to_dskeys "dnssec-keys" "static-ds" $*
|
||||||
|
}
|
||||||
|
|
||||||
|
# keyfile_to_initial_ds_keys: convert key data contained in the keyfile(s)
|
||||||
|
# provided to an *initial-ds* "dnssec-keys" section suitable for including
|
||||||
|
# in a resolver's configuration file
|
||||||
|
keyfile_to_initial_ds() {
|
||||||
|
keyfile_to_dskeys "dnssec-keys" "initial-ds" $*
|
||||||
}
|
}
|
||||||
|
|
||||||
# keyfile_to_key_id: convert a key file name to a key ID
|
# keyfile_to_key_id: convert a key file name to a key ID
|
||||||
@@ -323,6 +374,40 @@ nextpartpeek() {
|
|||||||
nextpartread $1 2> /dev/null
|
nextpartread $1 2> /dev/null
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# _retry: keep running a command until it succeeds, up to $1 times, with
|
||||||
|
# one-second intervals, optionally printing a message upon every attempt
|
||||||
|
_retry() {
|
||||||
|
__retries="${1}"
|
||||||
|
shift
|
||||||
|
|
||||||
|
while :; do
|
||||||
|
if "$@"; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
__retries=$((__retries-1))
|
||||||
|
if [ "${__retries}" -gt 0 ]; then
|
||||||
|
if [ "${__retry_quiet}" -ne 1 ]; then
|
||||||
|
echo_i "retrying"
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
else
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
# retry: call _retry() in verbose mode
|
||||||
|
retry() {
|
||||||
|
__retry_quiet=0
|
||||||
|
_retry "$@"
|
||||||
|
}
|
||||||
|
|
||||||
|
# retry_quiet: call _retry() in silent mode
|
||||||
|
retry_quiet() {
|
||||||
|
__retry_quiet=1
|
||||||
|
_retry "$@"
|
||||||
|
}
|
||||||
|
|
||||||
rndc_reload() {
|
rndc_reload() {
|
||||||
echo_i "`$RNDC -c ../common/rndc.conf -s $2 -p ${CONTROLPORT} reload $3 2>&1 | sed 's/^/'$1' /'`"
|
echo_i "`$RNDC -c ../common/rndc.conf -s $2 -p ${CONTROLPORT} reload $3 2>&1 | sed 's/^/'$1' /'`"
|
||||||
# reloading single zone is synchronous, if we're reloading whole server
|
# reloading single zone is synchronous, if we're reloading whole server
|
||||||
@@ -491,6 +576,6 @@ export RRCHECKER
|
|||||||
export SAMPLEUPDATE
|
export SAMPLEUPDATE
|
||||||
export SIGNER
|
export SIGNER
|
||||||
export SUBDIRS
|
export SUBDIRS
|
||||||
export TESTSOCK6
|
export TMPDIR
|
||||||
export TSIGKEYGEN
|
export TSIGKEYGEN
|
||||||
export WIRETEST
|
export WIRETEST
|
||||||
|
|||||||
@@ -17,6 +17,9 @@
|
|||||||
# Find the top of the BIND9 tree.
|
# Find the top of the BIND9 tree.
|
||||||
TOP=@abs_top_builddir@
|
TOP=@abs_top_builddir@
|
||||||
|
|
||||||
|
# Provide TMPDIR variable for tests that need it.
|
||||||
|
TMPDIR=${TMPDIR:-/tmp}
|
||||||
|
|
||||||
# This is not the windows build.
|
# This is not the windows build.
|
||||||
CYGWIN=""
|
CYGWIN=""
|
||||||
|
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
-D delzone-ns2 -X named.lock -m record,size,mctx -T clienttest -c named.conf -g -U 4
|
-D delzone-ns2 -X named.lock -m record,size,mctx -c named.conf -g -U 4
|
||||||
|
|||||||
@@ -310,7 +310,7 @@ if [ -x "$DIG" ] ; then
|
|||||||
|
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
echo_i "checking dig @IPv6addr -4 A a.example ($n)"
|
echo_i "checking dig @IPv6addr -4 A a.example ($n)"
|
||||||
if $TESTSOCK6 fd92:7065:b8e:ffff::2 2>/dev/null
|
if testsock6 fd92:7065:b8e:ffff::2 2>/dev/null
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts +tcp @fd92:7065:b8e:ffff::2 -4 A a.example > dig.out.test$n 2>&1 && ret=1
|
dig_with_opts +tcp @fd92:7065:b8e:ffff::2 -4 A a.example > dig.out.test$n 2>&1 && ret=1
|
||||||
@@ -323,7 +323,7 @@ if [ -x "$DIG" ] ; then
|
|||||||
|
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
echo_i "checking dig @IPv4addr -6 +mapped A a.example ($n)"
|
echo_i "checking dig @IPv4addr -6 +mapped A a.example ($n)"
|
||||||
if "$TESTSOCK6" fd92:7065:b8e:ffff::2 2>/dev/null && [ "$(uname -s)" != "OpenBSD" ]
|
if testsock6 fd92:7065:b8e:ffff::2 2>/dev/null && [ "$(uname -s)" != "OpenBSD" ]
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts +tcp @10.53.0.2 -6 +mapped A a.example > dig.out.test$n 2>&1 || ret=1
|
dig_with_opts +tcp @10.53.0.2 -6 +mapped A a.example > dig.out.test$n 2>&1 || ret=1
|
||||||
@@ -336,7 +336,7 @@ if [ -x "$DIG" ] ; then
|
|||||||
|
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
echo_i "checking dig +tcp @IPv4addr -6 +nomapped A a.example ($n)"
|
echo_i "checking dig +tcp @IPv4addr -6 +nomapped A a.example ($n)"
|
||||||
if $TESTSOCK6 fd92:7065:b8e:ffff::2 2>/dev/null
|
if testsock6 fd92:7065:b8e:ffff::2 2>/dev/null
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts +tcp @10.53.0.2 -6 +nomapped A a.example > dig.out.test$n 2>&1 || ret=1
|
dig_with_opts +tcp @10.53.0.2 -6 +nomapped A a.example > dig.out.test$n 2>&1 || ret=1
|
||||||
@@ -349,7 +349,7 @@ if [ -x "$DIG" ] ; then
|
|||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
|
|
||||||
echo_i "checking dig +notcp @IPv4addr -6 +nomapped A a.example ($n)"
|
echo_i "checking dig +notcp @IPv4addr -6 +nomapped A a.example ($n)"
|
||||||
if $TESTSOCK6 fd92:7065:b8e:ffff::2 2>/dev/null
|
if testsock6 fd92:7065:b8e:ffff::2 2>/dev/null
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts +notcp @10.53.0.2 -6 +nomapped A a.example > dig.out.test$n 2>&1 || ret=1
|
dig_with_opts +notcp @10.53.0.2 -6 +nomapped A a.example > dig.out.test$n 2>&1 || ret=1
|
||||||
@@ -752,6 +752,7 @@ if [ -x "$DIG" ] ; then
|
|||||||
status=$((status+ret))
|
status=$((status+ret))
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
n=$((n+1))
|
||||||
echo_i "check that dig +unexpected works ($n)"
|
echo_i "check that dig +unexpected works ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
dig_with_opts @10.53.0.6 +unexpected a a.example > dig.out.test$n || ret=1
|
dig_with_opts @10.53.0.6 +unexpected a a.example > dig.out.test$n || ret=1
|
||||||
@@ -860,7 +861,7 @@ if [ -x "$DELV" ] ; then
|
|||||||
|
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
echo_i "checking delv with IPv6 on IPv4 does not work ($n)"
|
echo_i "checking delv with IPv6 on IPv4 does not work ($n)"
|
||||||
if $TESTSOCK6 fd92:7065:b8e:ffff::3 2>/dev/null
|
if testsock6 fd92:7065:b8e:ffff::3 2>/dev/null
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
# following should fail because @IPv4 overrides earlier @IPv6 above
|
# following should fail because @IPv4 overrides earlier @IPv6 above
|
||||||
@@ -878,7 +879,7 @@ if [ -x "$DELV" ] ; then
|
|||||||
|
|
||||||
n=$((n+1))
|
n=$((n+1))
|
||||||
echo_i "checking delv with IPv4 on IPv6 does not work ($n)"
|
echo_i "checking delv with IPv4 on IPv6 does not work ($n)"
|
||||||
if $TESTSOCK6 fd92:7065:b8e:ffff::3 2>/dev/null
|
if testsock6 fd92:7065:b8e:ffff::3 2>/dev/null
|
||||||
then
|
then
|
||||||
ret=0
|
ret=0
|
||||||
# following should fail because @IPv6 overrides earlier @IPv4 above
|
# following should fail because @IPv6 overrides earlier @IPv4 above
|
||||||
|
|||||||
@@ -99,6 +99,7 @@ add_name(struct dlz_example_data *state, struct record *list,
|
|||||||
int first_empty = -1;
|
int first_empty = -1;
|
||||||
|
|
||||||
for (i = 0; i < MAX_RECORDS; i++) {
|
for (i = 0; i < MAX_RECORDS; i++) {
|
||||||
|
INSIST(list[i].name != NULL);
|
||||||
if (first_empty == -1 && strlen(list[i].name) == 0U) {
|
if (first_empty == -1 && strlen(list[i].name) == 0U) {
|
||||||
first_empty = i;
|
first_empty = i;
|
||||||
}
|
}
|
||||||
@@ -123,13 +124,13 @@ add_name(struct dlz_example_data *state, struct record *list,
|
|||||||
strlen(data) >= sizeof(list[i].data))
|
strlen(data) >= sizeof(list[i].data))
|
||||||
return (ISC_R_NOSPACE);
|
return (ISC_R_NOSPACE);
|
||||||
|
|
||||||
strncpy(list[i].name, name, sizeof(list[i].name));
|
strncpy(list[i].name, name, sizeof(list[i].name) - 1);
|
||||||
list[i].name[sizeof(list[i].name) - 1] = '\0';
|
list[i].name[sizeof(list[i].name) - 1] = '\0';
|
||||||
|
|
||||||
strncpy(list[i].type, type, sizeof(list[i].type));
|
strncpy(list[i].type, type, sizeof(list[i].type) - 1);
|
||||||
list[i].type[sizeof(list[i].type) - 1] = '\0';
|
list[i].type[sizeof(list[i].type) - 1] = '\0';
|
||||||
|
|
||||||
strncpy(list[i].data, data, sizeof(list[i].data));
|
strncpy(list[i].data, data, sizeof(list[i].data) - 1);
|
||||||
list[i].data[sizeof(list[i].data) - 1] = '\0';
|
list[i].data[sizeof(list[i].data) - 1] = '\0';
|
||||||
|
|
||||||
list[i].ttl = ttl;
|
list[i].ttl = ttl;
|
||||||
|
|||||||
@@ -30,14 +30,15 @@ cp "../ns2/dsset-in-addr.arpa$TP" .
|
|||||||
grep "$DEFAULT_ALGORITHM_NUMBER [12] " "../ns2/dsset-algroll$TP" > "dsset-algroll$TP"
|
grep "$DEFAULT_ALGORITHM_NUMBER [12] " "../ns2/dsset-algroll$TP" > "dsset-algroll$TP"
|
||||||
cp "../ns6/dsset-optout-tld$TP" .
|
cp "../ns6/dsset-optout-tld$TP" .
|
||||||
|
|
||||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
ksk=$("$KEYGEN" -q -fk -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||||
|
zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||||
|
|
||||||
cat "$infile" "$keyname.key" > "$zonefile"
|
cat "$infile" "$ksk.key" "$zsk.key" > "$zonefile"
|
||||||
|
|
||||||
"$SIGNER" -P -g -o "$zone" "$zonefile" > /dev/null 2>&1
|
"$SIGNER" -P -g -o "$zone" "$zonefile" > /dev/null 2>&1
|
||||||
|
|
||||||
# Configure the resolving server with a staitc key.
|
# Configure the resolving server with a staitc key.
|
||||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
keyfile_to_static_ds "$ksk" > trusted.conf
|
||||||
cp trusted.conf ../ns2/trusted.conf
|
cp trusted.conf ../ns2/trusted.conf
|
||||||
cp trusted.conf ../ns3/trusted.conf
|
cp trusted.conf ../ns3/trusted.conf
|
||||||
cp trusted.conf ../ns4/trusted.conf
|
cp trusted.conf ../ns4/trusted.conf
|
||||||
@@ -46,11 +47,11 @@ cp trusted.conf ../ns7/trusted.conf
|
|||||||
cp trusted.conf ../ns9/trusted.conf
|
cp trusted.conf ../ns9/trusted.conf
|
||||||
|
|
||||||
# ...or with an initializing key.
|
# ...or with an initializing key.
|
||||||
keyfile_to_initial_keys "$keyname" > managed.conf
|
keyfile_to_initial_ds "$ksk" > managed.conf
|
||||||
cp managed.conf ../ns4/managed.conf
|
cp managed.conf ../ns4/managed.conf
|
||||||
|
|
||||||
#
|
#
|
||||||
# Save keyid for managed key id test.
|
# Save keyid for managed key id test.
|
||||||
#
|
#
|
||||||
|
|
||||||
keyfile_to_key_id "$keyname" > managed.key.id
|
keyfile_to_key_id "$ksk" > managed.key.id
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ zonefile=root.db.signed
|
|||||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
||||||
|
|
||||||
# copy the KSK out first, then revoke it
|
# copy the KSK out first, then revoke it
|
||||||
keyfile_to_initial_keys "$keyname" > revoked.conf
|
keyfile_to_initial_ds "$keyname" > revoked.conf
|
||||||
|
|
||||||
"$SETTIME" -R now "${keyname}.key" > /dev/null
|
"$SETTIME" -R now "${keyname}.key" > /dev/null
|
||||||
|
|
||||||
@@ -34,4 +34,4 @@ keyfile_to_initial_keys "$keyname" > revoked.conf
|
|||||||
|
|
||||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone ".")
|
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone ".")
|
||||||
|
|
||||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
keyfile_to_static_ds "$keyname" > trusted.conf
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
-m record,size,mctx -c named.conf -d 99 -D dnssec-ns6 -X named.lock -g -T nonearest -T clienttest -T tat=1
|
-m record,size,mctx -c named.conf -d 99 -D dnssec-ns6 -X named.lock -g -T nonearest -T tat=1
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ options {
|
|||||||
listen-on { 10.53.0.8; };
|
listen-on { 10.53.0.8; };
|
||||||
listen-on-v6 { none; };
|
listen-on-v6 { none; };
|
||||||
recursion yes;
|
recursion yes;
|
||||||
dnssec-enable yes;
|
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
minimal-responses no;
|
minimal-responses no;
|
||||||
disable-algorithms "disabled.managed." { @DISABLED_ALGORITHM@; };
|
disable-algorithms "disabled.managed." { @DISABLED_ALGORITHM@; };
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ options {
|
|||||||
listen-on { 10.53.0.9; };
|
listen-on { 10.53.0.9; };
|
||||||
listen-on-v6 { none; };
|
listen-on-v6 { none; };
|
||||||
recursion yes;
|
recursion yes;
|
||||||
dnssec-enable yes;
|
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
forward only;
|
forward only;
|
||||||
forwarders { 10.53.0.4; };
|
forwarders { 10.53.0.4; };
|
||||||
|
|||||||
@@ -1485,7 +1485,7 @@ n=$((n+1))
|
|||||||
test "$ret" -eq 0 || echo_i "failed"
|
test "$ret" -eq 0 || echo_i "failed"
|
||||||
status=$((status+ret))
|
status=$((status+ret))
|
||||||
|
|
||||||
echo_i "checking that dnsssec-signzone updates originalttl on ttl changes ($n)"
|
echo_i "checking that dnssec-signzone updates originalttl on ttl changes ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
zone=example
|
zone=example
|
||||||
key1=$($KEYGEN -K signer -q -a RSASHA1 -b 1024 -n zone $zone)
|
key1=$($KEYGEN -K signer -q -a RSASHA1 -b 1024 -n zone $zone)
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user