Compare commits
343
Commits
patch-2
...
v9.5.0-P2-W1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3685c78c57 | ||
|
|
1980663de0 | ||
|
|
b2aa471a0c | ||
|
|
b7586d09a2 | ||
|
|
0aa6fd8cbc | ||
|
|
72bbd4f665 | ||
|
|
256664f0df | ||
|
|
964525fd31 | ||
|
|
fc4997b83f | ||
|
|
4343ea5c4c | ||
|
|
907eab9404 | ||
|
|
62903ea8cd | ||
|
|
ca5d82ecf0 | ||
|
|
cf5ea2dff6 | ||
|
|
8531ac4b3e | ||
|
|
6aed1128e9 | ||
|
|
e959afd003 | ||
|
|
e68c2114c9 | ||
|
|
065bb19e39 | ||
|
|
efc490471d | ||
|
|
455cc8abc0 | ||
|
|
0e09bd60b8 | ||
|
|
d139d9b0e3 | ||
|
|
c1c2820447 | ||
|
|
5aa27fe904 | ||
|
|
8bf55eceff | ||
|
|
3a9fd81f83 | ||
|
|
32eb7fb045 | ||
|
|
84f20a99a3 | ||
|
|
167fb12ef0 | ||
|
|
484de8aeb4 | ||
|
|
3102bcca7e | ||
|
|
bc7a739185 | ||
|
|
9bac6dad05 | ||
|
|
baf6346a75 | ||
|
|
20cb8193d4 | ||
|
|
11b162adbb | ||
|
|
c5b7f92366 | ||
|
|
4bcb059b17 | ||
|
|
3fddcefa6d | ||
|
|
867d55617b | ||
|
|
db3f58cef5 | ||
|
|
6ce96fdb2b | ||
|
|
0107d4b94e | ||
|
|
10bb5de410 | ||
|
|
b5af28291f | ||
|
|
98933c165f | ||
|
|
4bf9757496 | ||
|
|
54880cd0e0 | ||
|
|
13df807778 | ||
|
|
d1ce98b4dc | ||
|
|
800ec63dfc | ||
|
|
338dc11376 | ||
|
|
7597ccff8c | ||
|
|
9205748541 | ||
|
|
a9e440af0a | ||
|
|
16cdc2fc93 | ||
|
|
500fe450bc | ||
|
|
15280ddf7f | ||
|
|
11ac60f81a | ||
|
|
30162a73f4 | ||
|
|
d978441bfc | ||
|
|
22b8be6acb | ||
|
|
a8e5c0229e | ||
|
|
3e9ce03245 | ||
|
|
efcf8c8bf6 | ||
|
|
1bff2d56a0 | ||
|
|
677b69cee2 | ||
|
|
f9ecef19c7 | ||
|
|
fe75a4844e | ||
|
|
3917e0f147 | ||
|
|
0598502e9e | ||
|
|
4883ba14a2 | ||
|
|
1b009fdcb6 | ||
|
|
305ef3b37e | ||
|
|
4f47207ff3 | ||
|
|
9367357752 | ||
|
|
fcf5669651 | ||
|
|
3751d910d4 | ||
|
|
42a1be3481 | ||
|
|
09d567f784 | ||
|
|
4edcb0a7b4 | ||
|
|
e86a55fa74 | ||
|
|
e81a504bc9 | ||
|
|
674e9786c9 | ||
|
|
8f205b69b1 | ||
|
|
03007a2095 | ||
|
|
b0b37d3fcf | ||
|
|
47682a39a6 | ||
|
|
c6fe8292ad | ||
|
|
09216afdb1 | ||
|
|
ecc7721a06 | ||
|
|
37df6394c2 | ||
|
|
c38498dc94 | ||
|
|
cbcda9fcbf | ||
|
|
4d5d79c2bf | ||
|
|
8aaed07569 | ||
|
|
412555b357 | ||
|
|
5436d7d29d | ||
|
|
9b499d30ab | ||
|
|
c8535afd17 | ||
|
|
b03896b8f2 | ||
|
|
cc8f4eeb27 | ||
|
|
e602fc802e | ||
|
|
b08fa225e7 | ||
|
|
3c9321d7f6 | ||
|
|
982f479ef8 | ||
|
|
eeaf86677c | ||
|
|
90db307f35 | ||
|
|
cb66d7252e | ||
|
|
49a05a11d9 | ||
|
|
516f7013e6 | ||
|
|
4203f5255b | ||
|
|
96f73d33c2 | ||
|
|
710077836a | ||
|
|
e431b34601 | ||
|
|
739ca9f9ad | ||
|
|
dbbab64f9d | ||
|
|
e3b7bbf52b | ||
|
|
3c13437de0 | ||
|
|
a24b174ca4 | ||
|
|
5702efd795 | ||
|
|
2d70db1fa3 | ||
|
|
d8bd46d4cc | ||
|
|
5a28de8a7e | ||
|
|
014d9f7261 | ||
|
|
aad58d0adf | ||
|
|
e7b4b25911 | ||
|
|
b104b0c23e | ||
|
|
a19ec120c5 | ||
|
|
7cfe8c8f4d | ||
|
|
391c2ab68f | ||
|
|
14651ee41b | ||
|
|
c583c691fb | ||
|
|
83df26458f | ||
|
|
6fa7523201 | ||
|
|
7aef379fd1 | ||
|
|
961bf2a3e8 | ||
|
|
0192a58877 | ||
|
|
fea5003e29 | ||
|
|
92fbb8eac8 | ||
|
|
5b810282a9 | ||
|
|
4d4acb42d2 | ||
|
|
e537df0ea9 | ||
|
|
e5b1dde7c5 | ||
|
|
6a71e56a3f | ||
|
|
438720772d | ||
|
|
47885dbdde | ||
|
|
af1599b1da | ||
|
|
8ebab4b98f | ||
|
|
7100256640 | ||
|
|
e76eb48859 | ||
|
|
4a28636431 | ||
|
|
829c34e396 | ||
|
|
5c2712bfb8 | ||
|
|
fc29ccea3d | ||
|
|
c78c0e226d | ||
|
|
b15ca1e4a8 | ||
|
|
4a2a5e97c8 | ||
|
|
e3f89c5bf1 | ||
|
|
380c7b4299 | ||
|
|
569866242d | ||
|
|
0655b0e422 | ||
|
|
e1b8868347 | ||
|
|
3b3a602c84 | ||
|
|
97c6bb525f | ||
|
|
febd51128d | ||
|
|
d6a28f56c1 | ||
|
|
4926627bcf | ||
|
|
a3bc124972 | ||
|
|
3bfe5db91d | ||
|
|
7826436f62 | ||
|
|
8fed9314f6 | ||
|
|
a5c4ae5173 | ||
|
|
77f549e6b4 | ||
|
|
ca3ecfb9b5 | ||
|
|
c367f5e243 | ||
|
|
c93c2295a3 | ||
|
|
4e1aab5a12 | ||
|
|
5ff3649205 | ||
|
|
b1edc6d4c5 | ||
|
|
98ef27178a | ||
|
|
3bebac792f | ||
|
|
5c1119ddb2 | ||
|
|
6b2bbc7acd | ||
|
|
61e1949537 | ||
|
|
7ead775452 | ||
|
|
8c16eea7cb | ||
|
|
5815d6d626 | ||
|
|
c6efdf3877 | ||
|
|
acfc90e470 | ||
|
|
4b44e87afa | ||
|
|
d01a2c3074 | ||
|
|
fa14a55a9b | ||
|
|
7a66933966 | ||
|
|
08554db8e8 | ||
|
|
4daa027dae | ||
|
|
961bf334ad | ||
|
|
92a67c70fc | ||
|
|
54d79b7ee6 | ||
|
|
8499acff4b | ||
|
|
a575cc7345 | ||
|
|
7443e9a0ab | ||
|
|
de4f3419d3 | ||
|
|
3d20fde5d5 | ||
|
|
4a8284d2d9 | ||
|
|
dde0554201 | ||
|
|
085c04709b | ||
|
|
a637837c26 | ||
|
|
49d06d08af | ||
|
|
fbcc990683 | ||
|
|
8bf830cf9a | ||
|
|
25483f341c | ||
|
|
a3f132e1d5 | ||
|
|
4dced8b5ca | ||
|
|
a7e1401d6f | ||
|
|
bf893e98a1 | ||
|
|
785ba57b1d | ||
|
|
b3d76dc009 | ||
|
|
0fd9a6a418 | ||
|
|
cbb58f7806 | ||
|
|
e612fee97e | ||
|
|
9ad9a85600 | ||
|
|
50a826f981 | ||
|
|
657f12a6c2 | ||
|
|
b92d30fdf6 | ||
|
|
be3fa0f93c | ||
|
|
6ae5d3fe2e | ||
|
|
fff23805cd | ||
|
|
baf0deb78a | ||
|
|
1c761ab7cd | ||
|
|
19621ecd33 | ||
|
|
6d6b4d2b44 | ||
|
|
408d189490 | ||
|
|
2302483203 | ||
|
|
5205441b98 | ||
|
|
9269f5932a | ||
|
|
01167e9f54 | ||
|
|
c70668447c | ||
|
|
facbe6140d | ||
|
|
200538d835 | ||
|
|
5b5459fa39 | ||
|
|
970e4f9c17 | ||
|
|
988fcd8e91 | ||
|
|
15538c5cf9 | ||
|
|
b0bf8fb3d7 | ||
|
|
a927d3d2f5 | ||
|
|
d7fe687447 | ||
|
|
dd6673e550 | ||
|
|
0fd958bf27 | ||
|
|
b20fabbc3a | ||
|
|
3a1a42acf0 | ||
|
|
a7cd86b7e5 | ||
|
|
438763e4ca | ||
|
|
6f054fb0c0 | ||
|
|
fd7dee0a02 | ||
|
|
64af101571 | ||
|
|
61c08ad3b7 | ||
|
|
db746aa5ef | ||
|
|
4bb592c78c | ||
|
|
2f58f058c1 | ||
|
|
72ef4f17c9 | ||
|
|
22df9a9b9e | ||
|
|
dd45b00f68 | ||
|
|
3999907ad2 | ||
|
|
bd3598f239 | ||
|
|
764150b71d | ||
|
|
0154d8b824 | ||
|
|
d595af5b6a | ||
|
|
59b0f0ac6c | ||
|
|
5b9f34295f | ||
|
|
b177a884b4 | ||
|
|
09274b9cea | ||
|
|
2e5426b5aa | ||
|
|
e00da2eb68 | ||
|
|
468a0a9f0e | ||
|
|
09bd4960ef | ||
|
|
715d3e82cb | ||
|
|
233dd63115 | ||
|
|
d504c44c35 | ||
|
|
66240d2746 | ||
|
|
bc5f9d92c3 | ||
|
|
ce09884de7 | ||
|
|
2d3aafb354 | ||
|
|
a9b24b418c | ||
|
|
b336b9332d | ||
|
|
a981760738 | ||
|
|
d244a5b2a3 | ||
|
|
1cbd155085 | ||
|
|
84a2c39fa0 | ||
|
|
cfcbcf061f | ||
|
|
62bd59af24 | ||
|
|
8d121214ec | ||
|
|
3eb81a73aa | ||
|
|
ebfc85d52f | ||
|
|
b18d6066b2 | ||
|
|
4602a30928 | ||
|
|
ac80f65020 | ||
|
|
7a2ff97296 | ||
|
|
40a2001899 | ||
|
|
d4c9827b5a | ||
|
|
e09484c1b5 | ||
|
|
138c9af8ee | ||
|
|
98b01ed499 | ||
|
|
d760be189b | ||
|
|
531dca2420 | ||
|
|
d610a63637 | ||
|
|
0ca2c72ec4 | ||
|
|
c5f7d960af | ||
|
|
ddc792aa74 | ||
|
|
e886663bb8 | ||
|
|
e616752523 | ||
|
|
395f6d6ee7 | ||
|
|
2699cd0532 | ||
|
|
fbcb13ce0b | ||
|
|
0ab8208ade | ||
|
|
7feda2cbd7 | ||
|
|
439716d3b5 | ||
|
|
c3926cdf4c | ||
|
|
b57c180e78 | ||
|
|
08332cd77d | ||
|
|
e5009e717f | ||
|
|
b67bacecc9 | ||
|
|
2b5a1b5eb1 | ||
|
|
23a012ebfe | ||
|
|
f5471da9bb | ||
|
|
1a83d0a2dd | ||
|
|
d4662c174d | ||
|
|
1fbd092244 | ||
|
|
4417182aba | ||
|
|
01e203ad6b | ||
|
|
4f6b9050ee | ||
|
|
c9670b654c | ||
|
|
5b538e89ac | ||
|
|
168f7c2650 | ||
|
|
a70f5c100c | ||
|
|
3ac85ae815 | ||
|
|
07779b37f7 | ||
|
|
a5e8b7acd2 | ||
|
|
798d69d4c5 | ||
|
|
0e46658ea8 | ||
|
|
00a4159352 | ||
|
|
a1e1382c9a |
@@ -1,43 +1,96 @@
|
||||
2382. [doc] Add descriptions of DHCID, IPSECKEY, SPF and SSHFP
|
||||
to ARM.
|
||||
--- 9.5.0-P2-W1 released ---
|
||||
|
||||
2381. [port] dlz/mysql: support multiple install layouts for
|
||||
mysql. <prefix>/include/{,mysql/}mysql.h and
|
||||
<prefix>/lib/{,mysql/}. [RT #18152]
|
||||
2435. [bug] Fixed an ACL memory leak affecting win32.
|
||||
|
||||
2380. [bug] dns_view_find() was not returning NXDOMAIN/NXRRSET
|
||||
proofs which, in turn, caused validation failures
|
||||
for insecure zones immediately below a secure zone
|
||||
the server was authoritative for. [RT #18112]
|
||||
2434. [bug] Fixed a minor error-reporting bug in
|
||||
lib/isc/win32/socket.c.
|
||||
|
||||
2379. [contrib] queryperf/gen-data-queryperf.py: removed redundant
|
||||
TLDs and supported RRs with TTLs [RT #17972]
|
||||
2432. [bug] More Windows socket handling improvements. Stop
|
||||
using I/O events and use IO Completion Ports
|
||||
throughout. Rewrite the receive path logic to make
|
||||
it easier to support multiple simultaneous
|
||||
requestrs in the future. Add stricter consistency
|
||||
checking as a compile-time option (define
|
||||
ISC_SOCKET_CONSISTENCY_CHECKS; defaults to off).
|
||||
|
||||
2378. [bug] gssapi_functions{} had a redundant member in BIND 9.5.
|
||||
[RT #18169]
|
||||
2420. [bug] Windows socket handling cleanup. Let the io
|
||||
completion event send out cancelled read/write
|
||||
done events, which keeps us from writing to memeory
|
||||
we no longer have ownership of. Add debugging
|
||||
socket_log() function. Rework TCP socket handling
|
||||
to not leak sockets.
|
||||
|
||||
2377. [bug] Address race condition in dnssec-signzone. [RT #18142]
|
||||
--- 9.5.0-P2 released ---
|
||||
|
||||
2376. [bug] Change #2144 was not complete.
|
||||
2406. [bug] Some operating systems have FD_SETSIZE set to a
|
||||
low value by default, which can cause resource
|
||||
exhaustion when many simultaneous connections are
|
||||
open. Linux in particular makes it difficult to
|
||||
increase this value. To use more sockets with
|
||||
select(), set ISC_SOCKET_FDSETSIZE. Example:
|
||||
STD_CDEFINES="-DISC_SOCKET_FDSETSIZE=4096" ./configure
|
||||
(This should not be necessary in most cases, and
|
||||
never for an authoritative-only server.) [RT #18328]
|
||||
|
||||
2375. [placeholder]
|
||||
2405. [cleanup] The default value for dnssec-validation was changed to
|
||||
"yes" in 9.5.0-P1 and all subsequent releases; this
|
||||
was inadvertently omitted from CHANGES at the time.
|
||||
|
||||
2404. [port] hpux: files unlimited support.
|
||||
|
||||
2403. [bug] TSIG context leak. [RT #18341]
|
||||
|
||||
2402. [port] Support Solaris 2.11 and over. [RT #18362]
|
||||
|
||||
2401. [bug] Expect to get E[MN]FILE errno internal_accept()
|
||||
(from accept() or fcntl() system calls). [RT #18358]
|
||||
|
||||
2399. [bug] Abort timeout queries to reduce the number of open
|
||||
UDP sockets. [RT #18367]
|
||||
|
||||
2398. [bug] Improve file descriptor management. New,
|
||||
temporary, named.conf option reserved-sockets,
|
||||
default 512. [RT #18344]
|
||||
|
||||
2397. [bug] gssapi_functions had too many elements. [RT #18355]
|
||||
|
||||
2396. [bug] Don't set SO_REUSEADDR for randomized ports.
|
||||
[RT #18336]
|
||||
|
||||
2395. [port] Avoid warning and no effect from "files unlimited"
|
||||
on Linux when running as root. [RT #18335]
|
||||
|
||||
2394. [bug] Default configuration options set the limit for
|
||||
open files to 'unlimited' as described in the
|
||||
documentation. [RT #18331]
|
||||
|
||||
2393. [bug] nested acls containing keys could trigger an
|
||||
assertion in acl.c. [RT #18166]
|
||||
|
||||
2392. [bug] remove 'grep -q' from acl test script, some platforms
|
||||
don't support it. [RT #18253]
|
||||
|
||||
2387. [bug] Silence compiler warnings in lib/isc/radix.c.
|
||||
[RT #18147] [RT #18258]
|
||||
|
||||
--- 9.5.0-P1 released ---
|
||||
|
||||
2375. [security] Fully randomize UDP query ports to improve
|
||||
forgery resilience. [RT #17949]
|
||||
|
||||
--- 9.5.0 released ---
|
||||
|
||||
2374. [bug] "blackhole" ACLs could cause named to segfault due
|
||||
to some uninitialized memory. [RT #18095]
|
||||
|
||||
2373. [bug] Default values of zone ACLs were re-parsed each time a
|
||||
new zone was configured, causing an overconsumption
|
||||
of memory. [RT #18092]
|
||||
2372. [bug] fixed incorrect TAG_HMACSHA256_BITS value [RT #18047]
|
||||
|
||||
2372. [bug] Fixed incorrect TAG_HMACSHA256_BITS value [RT #18047]
|
||||
|
||||
2371. [doc] Add +nsid option to dig man page. [RT #18039]
|
||||
2371. [doc] add +nsid option to dig man page. [RT #18039]
|
||||
|
||||
2370. [bug] "rndc freeze" could trigger an assertion in named
|
||||
when called on a nonexistent zone. [RT #18050]
|
||||
|
||||
2369. [bug] libbind: Array bounds overrun on read in bitncmp().
|
||||
[RT #18054]
|
||||
--- 9.5.0rc1 released ---
|
||||
|
||||
2368. [port] Linux: use libcap for capability management if
|
||||
possible. [RT# 18026]
|
||||
@@ -56,13 +109,15 @@
|
||||
2363. [port] sunos: pre-set "lt_cv_sys_max_cmd_len=4096;".
|
||||
[RT #17513]
|
||||
|
||||
2362. [cleanup] Make "rrset-order fixed" a compile-time option.
|
||||
2362. [cleanup] Make "rrset-order fixed" a compile-time option.
|
||||
settable by "./configure --enable-fixed-rrset".
|
||||
Disabled by default. [RT #17977]
|
||||
|
||||
2361. [bug] "recursion" statistics counter could be counted
|
||||
multiple times for a single query. [RT #17990]
|
||||
|
||||
--- 9.5.0b3 released ---
|
||||
|
||||
2360. [bug] Fix a condition where we release a database version
|
||||
(which may acquire a lock) while holding the lock.
|
||||
|
||||
@@ -70,9 +125,6 @@
|
||||
|
||||
2358. [doc] Update host's default query description. [RT #17934]
|
||||
|
||||
2357. [port] Don't use OpenSSL's engine support in versions before
|
||||
OpenSSL 0.9.7f. [RT #17922]
|
||||
|
||||
2356. [bug] Built in mutex profiler was not scalable enough.
|
||||
[RT #17436]
|
||||
|
||||
@@ -95,13 +147,6 @@
|
||||
|
||||
2350. [port] win32: IPv6 support. [RT #17797]
|
||||
|
||||
2349. [func] Provide incremental re-signing support for secure
|
||||
dynamic zones. [RT #1091]
|
||||
|
||||
2348. [func] Use the EVP interface to OpenSSL. Add PKCS#11 support.
|
||||
Documentation is in the new README.pkcs11 file.
|
||||
[RT #16844]
|
||||
|
||||
2347. [bug] Delete now traverses the RB tree in the canonical
|
||||
order. [RT #17451]
|
||||
|
||||
@@ -118,8 +163,6 @@
|
||||
2343. [bug] (Seemingly) duplicate IPv6 entries could be
|
||||
created in ADB. [RT #17837]
|
||||
|
||||
2342. [func] Use getifaddrs() if available under Linux. [RT #17224]
|
||||
|
||||
2341. [bug] libbind: add missing -I../include for off source
|
||||
tree builds. [RT #17606]
|
||||
|
||||
@@ -132,10 +175,6 @@
|
||||
|
||||
2337. [bug] BUILD_LDFLAGS was not being correctly set. [RT #17614]
|
||||
|
||||
2336. [func] If "named -6" is specified then listen on all IPv6
|
||||
interfaces if there are not listen-on-v6 clauses in
|
||||
named.conf. [RT #17581]
|
||||
|
||||
2335. [port] sunos: libbind and *printf() support for long long.
|
||||
[RT #17513]
|
||||
|
||||
@@ -149,7 +188,7 @@
|
||||
|
||||
2331. [bug] Failure to regenerate any signatures was not being
|
||||
reported nor being past back to the UPDATE client.
|
||||
[RT #17570]
|
||||
[RT #17570]
|
||||
|
||||
2330. [bug] Remove potential race condition when handling
|
||||
over memory events. [RT #17572]
|
||||
@@ -174,6 +213,8 @@
|
||||
|
||||
2325. [port] Linux: use capset() function if available. [RT #17557]
|
||||
|
||||
--- 9.5.0b2 released ---
|
||||
|
||||
2324. [bug] Fix IPv6 matching against "any;". [RT #17533]
|
||||
|
||||
2323. [port] tru64: namespace clash. [RT #17547]
|
||||
@@ -181,8 +222,6 @@
|
||||
2322. [port] MacOS: work around the limitation of setrlimit()
|
||||
for RLIMIT_NOFILE. [RT #17526]
|
||||
|
||||
2321. [placeholder]
|
||||
|
||||
2320. [func] Make statistics counters thread-safe for platforms
|
||||
that support certain atomic operations. [RT #17466]
|
||||
|
||||
@@ -196,8 +235,8 @@
|
||||
2316. [port] Missing #include <isc/print.h> in lib/dns/gssapictx.c.
|
||||
[RT #17513]
|
||||
|
||||
2315. [bug] Used incorrect address family for mapped IPv4
|
||||
addresses in acl.c. [RT #17519]
|
||||
2315. [bug] Used incorrect address family for mapped IPv4
|
||||
addresses in acl.c. [RT #17519]
|
||||
|
||||
2314. [bug] Uninitialized memory use on error path in
|
||||
bin/named/lwdnoop.c. [RT #17476]
|
||||
@@ -208,14 +247,14 @@
|
||||
2312. [cleanup] Silence Coverity warning in lib/isc/unix/socket.c.
|
||||
[RT #17458]
|
||||
|
||||
2311. [bug] IPv6 addresses could match IPv4 ACL entries and
|
||||
vice versa. [RT #17462]
|
||||
2311. [bug] IPv6 addresses could match IPv4 ACL entries and
|
||||
vice versa. [RT #17462]
|
||||
|
||||
2310. [bug] dig, host, nslookup: flush stdout before emitting
|
||||
debug/fatal messages. [RT #17501]
|
||||
|
||||
2309. [cleanup] Fix Coverity warnings in lib/dns/acl.c and iptable.c.
|
||||
[RT #17455]
|
||||
2309. [cleanup] Fix Coverity warnings in lib/dns/acl.c and iptable.c.
|
||||
[RT #17455]
|
||||
|
||||
2308. [cleanup] Silence Coverity warning in bin/named/controlconf.c.
|
||||
[RT #17495]
|
||||
@@ -267,28 +306,17 @@
|
||||
2292. [bug] Log if the working directory is not writable.
|
||||
[RT #17312]
|
||||
|
||||
2291. [bug] PR_SET_DUMPABLE may be set too late. Also report
|
||||
2291. [bug] PR_SET_DUMPABLE may be set too late. Also report
|
||||
failure to set PR_SET_DUMPABLE. [RT #17312]
|
||||
|
||||
2290. [bug] Let AD in the query signal that the client wants AD
|
||||
set in the response. [RT #17301]
|
||||
|
||||
2289. [func] named-checkzone now reports the out-of-zone CNAME
|
||||
found. [RT #17309]
|
||||
|
||||
2288. [port] win32: mark service as running when we have finished
|
||||
loading. [RT #17441]
|
||||
|
||||
2287. [bug] Use 'volatile' if the compiler supports it. [RT #17413]
|
||||
|
||||
2286. [func] Allow a TCP connection to be used as a weak
|
||||
authentication method for reverse zones.
|
||||
New update-policy methods tcp-self and 6to4-self.
|
||||
[RT #17378]
|
||||
|
||||
2285. [func] Test framework for client memory context management.
|
||||
[RT #17377]
|
||||
|
||||
2284. [bug] Memory leak in UPDATE prerequisite processing.
|
||||
[RT #17377]
|
||||
|
||||
@@ -305,7 +333,7 @@
|
||||
2280. [func] Allow the experimental http server to be reached
|
||||
over IPv6 as well as IPv4. [RT #17332]
|
||||
|
||||
2279. [bug] Use setsockopt(SO_NOSIGPIPE), when available,
|
||||
2279. [bug] Use setsockopt(SO_NOSIGPIPE), when available,
|
||||
to protect applications from receiving spurious
|
||||
SIGPIPE signals when using the resolver.
|
||||
|
||||
@@ -340,9 +368,9 @@
|
||||
|
||||
--- 9.5.0b1 released ---
|
||||
|
||||
2267. [bug] Radix tree node_num value could be set incorrectly,
|
||||
causing positive ACL matches to look like negative
|
||||
ones. [RT #17311]
|
||||
2267. [bug] Radix tree node_num value could be set incorrectly,
|
||||
causing positive ACL matches to look like negative
|
||||
ones. [RT #17311]
|
||||
|
||||
2266. [bug] client.c:get_clientmctx() returned the same mctx
|
||||
once the pool of mctx's was filled. [RT #17218]
|
||||
@@ -358,10 +386,10 @@
|
||||
2262. [bug] Error status from all but the last view could be
|
||||
lost. [RT #17292]
|
||||
|
||||
2261. [bug] Fix memory leak with "any" and "none" ACLs [RT #17272]
|
||||
2261. [bug] Fix memory leak with "any" and "none" ACLs [RT #17272]
|
||||
|
||||
2260. [bug] Reported wrong clients-per-query when increasing the
|
||||
value. [RT #17236]
|
||||
value. [RT #17236]
|
||||
|
||||
2259. [placeholder]
|
||||
|
||||
@@ -386,7 +414,7 @@
|
||||
2253. [func] "max-cache-size" defaults to 32M.
|
||||
"max-acache-size" defaults to 16M.
|
||||
|
||||
2252. [bug] Fixed errors in sortlist code [RT #17216]
|
||||
2252. [bug] Fixed errors in sortlist code [RT #17216]
|
||||
|
||||
2251. [placeholder]
|
||||
|
||||
@@ -395,10 +423,10 @@
|
||||
Additionally named's -m option will cause the
|
||||
statistics file to be written. [RT #17113]
|
||||
|
||||
2249. [bug] Only set Authentic Data bit if client requested
|
||||
DNSSEC, per RFC 3655 [RT #17175]
|
||||
2249. [bug] Only set Authentic Data bit if client requested
|
||||
DNSSEC, per RFC 3655 [RT #17175]
|
||||
|
||||
2248. [cleanup] Fix several errors reported by Coverity. [RT #17160]
|
||||
2248. [cleanup] Fix several errors reported by Coverity. [RT #17160]
|
||||
|
||||
2247. [doc] Sort doc/misc/options. [RT #17067]
|
||||
|
||||
@@ -439,11 +467,11 @@
|
||||
|
||||
2235. [bug] <isc/atomic.h> was not being installed. [RT #17135]
|
||||
|
||||
2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134]
|
||||
|
||||
2233. [func] Add support for O(1) ACL processing, based on
|
||||
radix tree code originally written by Kevin
|
||||
Brintnall. [RT #16288]
|
||||
2234. [port] Correct some compiler warnings on SCO OSr5 [RT #17134]
|
||||
|
||||
2233. [func] Add support for O(1) ACL processing, based on
|
||||
radix tree code originally written by Kevin
|
||||
Brintnall. [RT #16288]
|
||||
|
||||
2232. [bug] dns_adb_findaddrinfo() could fail and return
|
||||
ISC_R_SUCCESS. [RT #17137]
|
||||
|
||||
@@ -13,7 +13,7 @@ LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
$Id: COPYRIGHT,v 1.14 2008/01/02 23:47:01 tbox Exp $
|
||||
$Id: COPYRIGHT,v 1.13.130.1 2008/01/02 23:46:28 tbox Exp $
|
||||
|
||||
Portions Copyright (C) 1996-2001 Nominum, Inc.
|
||||
|
||||
|
||||
@@ -396,8 +396,8 @@ A: Someone is trying to update your DNS data using the RFC2136 Dynamic
|
||||
Update protocol. Windows 2000 machines have a habit of sending dynamic
|
||||
update requests to DNS servers without being specifically configured to
|
||||
do so. If the update requests are coming from a Windows 2000 machine,
|
||||
see <http://support.microsoft.com/support/kb/articles/q246/8/04.asp>
|
||||
for information about how to turn them off.
|
||||
see http://support.microsoft.com/support/kb/articles/q246/8/04.asp for
|
||||
information about how to turn them off.
|
||||
|
||||
Q: When I do a "dig . ns", many of the A records for the root servers are
|
||||
missing. Why?
|
||||
@@ -468,7 +468,7 @@ A: If the IN-ADDR.ARPA name covered refers to a internal address space you
|
||||
are using then you have failed to follow RFC 1918 usage rules and are
|
||||
leaking queries to the Internet. You should establish your own zones
|
||||
for these addresses to prevent you querying the Internet's name servers
|
||||
for these addresses. Please see <http://as112.net/> for details of the
|
||||
for these addresses. Please see http://as112.net/ for details of the
|
||||
problems you are causing and the counter measures that have had to be
|
||||
deployed.
|
||||
|
||||
@@ -569,20 +569,7 @@ Q: Why do I get the following errors:
|
||||
|
||||
A: This is the result of a Linux kernel bug.
|
||||
|
||||
See: <http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=
|
||||
2>
|
||||
|
||||
Q: Why does named lock up when it attempts to connect over IPSEC tunnels?
|
||||
|
||||
A: This is due to a kernel bug where the fact that a socket is marked
|
||||
non-blocking is ignored. It is reported that setting xfrm_larval_drop
|
||||
to 1 helps but this may have negative side effects. See: <https://
|
||||
bugzilla.redhat.com/show_bug.cgi?id=427629> and <http://lkml.org/lkml/
|
||||
2007/12/4/260>.
|
||||
|
||||
xfrm_larval_drop can be set to 1 by the following procedure:
|
||||
|
||||
echo "1" > proc/sys/net/core/xfrm_larval_drop
|
||||
See: http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2
|
||||
|
||||
Q: Why do I see 5 (or more) copies of named on Linux?
|
||||
|
||||
@@ -626,7 +613,7 @@ Q: I'm running BIND on Red Hat Enterprise Linux or Fedora Core -
|
||||
A: Red Hat Security Enhanced Linux (SELinux) policy security protections :
|
||||
|
||||
Red Hat have adopted the National Security Agency's SELinux security
|
||||
policy (see <http://www.nsa.gov/selinux>) and recommendations for BIND
|
||||
policy ( see http://www.nsa.gov/selinux ) and recommendations for BIND
|
||||
security , which are more secure than running named in a chroot and
|
||||
make use of the bind-chroot environment unnecessary .
|
||||
|
||||
@@ -766,7 +753,7 @@ A: /dev/random is not configured. Use rndcontrol(8) to tell the kernel to
|
||||
/etc/rc.conf
|
||||
rand_irqs="3 14 15"
|
||||
|
||||
See also <http://people.freebsd.org/~dougb/randomness.html>.
|
||||
See also http://people.freebsd.org/~dougb/randomness.html
|
||||
|
||||
4.5. Solaris
|
||||
|
||||
@@ -774,7 +761,7 @@ Q: How do I integrate BIND 9 and Solaris SMF
|
||||
|
||||
A: Sun has a blog entry describing how to do this.
|
||||
|
||||
<http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris>
|
||||
http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris
|
||||
|
||||
4.6. Apple Mac OS X
|
||||
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: FAQ.xml,v 1.39 2008/05/31 01:44:13 marka Exp $ -->
|
||||
<!-- $Id: FAQ.xml,v 1.30.26.3 2008/02/25 05:08:10 marka Exp $ -->
|
||||
|
||||
<article class="faq">
|
||||
<title>Frequently Asked Questions about BIND 9</title>
|
||||
@@ -706,7 +706,8 @@ zone "list.dsbl.org" {
|
||||
requests are coming from a Windows 2000 machine, see
|
||||
<ulink
|
||||
url="http://support.microsoft.com/support/kb/articles/q246/8/04.asp">
|
||||
<http://support.microsoft.com/support/kb/articles/q246/8/04.asp></ulink>
|
||||
http://support.microsoft.com/support/kb/articles/q246/8/04.asp
|
||||
</ulink>
|
||||
for information about how to turn them off.
|
||||
</para>
|
||||
</answer>
|
||||
@@ -856,7 +857,7 @@ serial-query-rate 5; // default 20</programlisting>
|
||||
usage rules and are leaking queries to the Internet. You
|
||||
should establish your own zones for these addresses to prevent
|
||||
you querying the Internet's name servers for these addresses.
|
||||
Please see <ulink url="http://as112.net/"><http://as112.net/></ulink>
|
||||
Please see <ulink url="http://as112.net/">http://as112.net/</ulink>
|
||||
for details of the problems you are causing and the counter
|
||||
measures that have had to be deployed.
|
||||
</para>
|
||||
@@ -1009,31 +1010,7 @@ client: UDP client handler shutting down due to fatal receive error: unexpected
|
||||
</para>
|
||||
<para>
|
||||
See:
|
||||
<ulink url="http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2"><http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2></ulink>
|
||||
</para>
|
||||
</answer>
|
||||
</qandaentry>
|
||||
|
||||
<qandaentry>
|
||||
<question>
|
||||
<para>
|
||||
Why does named lock up when it attempts to connect over IPSEC tunnels?
|
||||
</para>
|
||||
</question>
|
||||
<answer>
|
||||
<para>
|
||||
This is due to a kernel bug where the fact that a socket is marked
|
||||
non-blocking is ignored. It is reported that setting
|
||||
xfrm_larval_drop to 1 helps but this may have negative side effects.
|
||||
See:
|
||||
<ulink url="https://bugzilla.redhat.com/show_bug.cgi?id=427629"><https://bugzilla.redhat.com/show_bug.cgi?id=427629></ulink>
|
||||
and
|
||||
<ulink url="http://lkml.org/lkml/2007/12/4/260"><http://lkml.org/lkml/2007/12/4/260></ulink>.
|
||||
</para>
|
||||
<para>
|
||||
xfrm_larval_drop can be set to 1 by the following procedure:
|
||||
<programlisting>
|
||||
echo "1" > proc/sys/net/core/xfrm_larval_drop</programlisting>
|
||||
<ulink url="http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2">http://marc.theaimsgroup.com/?l=linux-netdev&m=113081708031466&w=2</ulink>
|
||||
</para>
|
||||
</answer>
|
||||
</qandaentry>
|
||||
@@ -1124,9 +1101,8 @@ modprobe capability</programlisting>
|
||||
|
||||
<para>
|
||||
Red Hat have adopted the National Security Agency's
|
||||
SELinux security policy (see <ulink
|
||||
url="http://www.nsa.gov/selinux"><http://www.nsa.gov/selinux></ulink>)
|
||||
and recommendations for BIND security , which are more
|
||||
SELinux security policy ( see http://www.nsa.gov/selinux
|
||||
) and recommendations for BIND security , which are more
|
||||
secure than running named in a chroot and make use of
|
||||
the bind-chroot environment unnecessary .
|
||||
</para>
|
||||
@@ -1365,7 +1341,8 @@ rand_irqs="3 14 15"</programlisting>
|
||||
<para>
|
||||
See also
|
||||
<ulink url="http://people.freebsd.org/~dougb/randomness.html">
|
||||
<http://people.freebsd.org/~dougb/randomness.html></ulink>.
|
||||
http://people.freebsd.org/~dougb/randomness.html
|
||||
</ulink>
|
||||
</para>
|
||||
</answer>
|
||||
</qandaentry>
|
||||
@@ -1387,7 +1364,7 @@ rand_irqs="3 14 15"</programlisting>
|
||||
<para>
|
||||
<ulink
|
||||
url="http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris">
|
||||
<http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris>
|
||||
http://blogs.sun.com/roller/page/anay/Weblog?catname=%2FSolaris
|
||||
</ulink>
|
||||
</para>
|
||||
</answer>
|
||||
|
||||
+315
@@ -0,0 +1,315 @@
|
||||
Known defects in ISC BIND 9.5.0
|
||||
|
||||
Just before the 9.5.0 release of BIND it was determined that some of
|
||||
the changes in this release have caused an overuse of memory on systems
|
||||
serving very large numbers of zones.
|
||||
|
||||
Zone ACLs, including allow-transfer, allow-query, allow-notify,
|
||||
allow-update, and allow-update-forwarding, that are defined in the
|
||||
"view" or "options" block of named.conf, should be parsed and loaded
|
||||
once, and then referenced by the zones that use them; however, they
|
||||
are currently parsed and loaded into memory separately by each zone. On
|
||||
systems with hundreds or thousands of zones, this can consume a huge
|
||||
amount of memory--especially when the ACLs being copied are also large.
|
||||
|
||||
There is a fix for this problem, but it was developed too late in the
|
||||
the test/release cycle for inclusion in BIND 9.5.0 as part of the mainline
|
||||
source code. After it has been sufficiently tested, it will be included in
|
||||
BIND 9.5.1.
|
||||
|
||||
In the meantime, the patch is included below for those who wish to
|
||||
experiment with it. To apply, run: "patch -p0 < KNOWN-DEFECTS;
|
||||
make clean; configure; make".
|
||||
|
||||
Index: bin/named/server.c
|
||||
===================================================================
|
||||
RCS file: /proj/cvs/prod/bind9/bin/named/server.c,v
|
||||
retrieving revision 1.495.10.10
|
||||
diff -u -r1.495.10.10 server.c
|
||||
--- bin/named/server.c 3 Apr 2008 06:20:33 -0000 1.495.10.10
|
||||
+++ bin/named/server.c 21 May 2008 23:46:14 -0000
|
||||
@@ -1684,6 +1684,28 @@
|
||||
CHECK(configure_view_sortlist(vconfig, config, actx, ns_g_mctx,
|
||||
&view->sortlist));
|
||||
|
||||
+ /*
|
||||
+ * Configure default allow-transfer, allow-notify, allow-update
|
||||
+ * and allow-update-forwarding ACLs, if set, so they can be
|
||||
+ * inherited by zones.
|
||||
+ */
|
||||
+ if (view->notifyacl == NULL)
|
||||
+ CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
+ "allow-notify", actx,
|
||||
+ ns_g_mctx, &view->notifyacl));
|
||||
+ if (view->transferacl == NULL)
|
||||
+ CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
+ "allow-transfer", actx,
|
||||
+ ns_g_mctx, &view->transferacl));
|
||||
+ if (view->updateacl == NULL)
|
||||
+ CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
+ "allow-update", actx,
|
||||
+ ns_g_mctx, &view->updateacl));
|
||||
+ if (view->upfwdacl == NULL)
|
||||
+ CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
+ "allow-update-forwarding", actx,
|
||||
+ ns_g_mctx, &view->upfwdacl));
|
||||
+
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "request-ixfr", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
Index: bin/named/zoneconf.c
|
||||
===================================================================
|
||||
RCS file: /proj/cvs/prod/bind9/bin/named/zoneconf.c,v
|
||||
retrieving revision 1.139.56.3
|
||||
diff -u -r1.139.56.3 zoneconf.c
|
||||
--- bin/named/zoneconf.c 21 May 2008 23:26:11 -0000 1.139.56.3
|
||||
+++ bin/named/zoneconf.c 21 May 2008 23:46:15 -0000
|
||||
@@ -45,6 +45,15 @@
|
||||
#include <named/server.h>
|
||||
#include <named/zoneconf.h>
|
||||
|
||||
+/* ACLs associated with zone */
|
||||
+typedef enum {
|
||||
+ allow_notify,
|
||||
+ allow_query,
|
||||
+ allow_transfer,
|
||||
+ allow_update,
|
||||
+ allow_update_forwarding
|
||||
+} acl_type_t;
|
||||
+
|
||||
/*%
|
||||
* These are BIND9 server defaults, not necessarily identical to the
|
||||
* library defaults defined in zone.c.
|
||||
@@ -60,19 +69,69 @@
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
- const cfg_obj_t *config, const char *aclname,
|
||||
+ const cfg_obj_t *config, acl_type_t acltype,
|
||||
cfg_aclconfctx_t *actx, dns_zone_t *zone,
|
||||
void (*setzacl)(dns_zone_t *, dns_acl_t *),
|
||||
void (*clearzacl)(dns_zone_t *))
|
||||
{
|
||||
isc_result_t result;
|
||||
- const cfg_obj_t *maps[5];
|
||||
+ const cfg_obj_t *maps[5] = {NULL, NULL, NULL, NULL, NULL};
|
||||
const cfg_obj_t *aclobj = NULL;
|
||||
int i = 0;
|
||||
- dns_acl_t *dacl = NULL;
|
||||
+ dns_acl_t **aclp = NULL, *acl = NULL;
|
||||
+ const char *aclname;
|
||||
+ dns_view_t *view;
|
||||
+
|
||||
+ view = dns_zone_getview(zone);
|
||||
+
|
||||
+ switch (acltype) {
|
||||
+ case allow_notify:
|
||||
+ if (view != NULL)
|
||||
+ aclp = &view->notifyacl;
|
||||
+ aclname = "allow-notify";
|
||||
+ break;
|
||||
+ case allow_query:
|
||||
+ if (view != NULL)
|
||||
+ aclp = &view->queryacl;
|
||||
+ aclname = "allow-query";
|
||||
+ break;
|
||||
+ case allow_transfer:
|
||||
+ if (view != NULL)
|
||||
+ aclp = &view->transferacl;
|
||||
+ aclname = "allow-transfer";
|
||||
+ break;
|
||||
+ case allow_update:
|
||||
+ if (view != NULL)
|
||||
+ aclp = &view->updateacl;
|
||||
+ aclname = "allow-update";
|
||||
+ break;
|
||||
+ case allow_update_forwarding:
|
||||
+ if (view != NULL)
|
||||
+ aclp = &view->upfwdacl;
|
||||
+ aclname = "allow-update-forwarding";
|
||||
+ break;
|
||||
+ default:
|
||||
+ INSIST(0);
|
||||
+ return (ISC_R_FAILURE);
|
||||
+ }
|
||||
|
||||
- if (zconfig != NULL)
|
||||
- maps[i++] = cfg_tuple_get(zconfig, "options");
|
||||
+ /* First check to see if ACL is defined within the zone */
|
||||
+ if (zconfig != NULL) {
|
||||
+ maps[0] = cfg_tuple_get(zconfig, "options");
|
||||
+ ns_config_get(maps, aclname, &aclobj);
|
||||
+ if (aclobj != NULL) {
|
||||
+ aclp = NULL;
|
||||
+ goto parse_acl;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ /* Failing that, see if there's a default ACL already in the view */
|
||||
+ if (aclp != NULL && *aclp != NULL) {
|
||||
+ (*setzacl)(zone, *aclp);
|
||||
+ return (ISC_R_SUCCESS);
|
||||
+ }
|
||||
+
|
||||
+ /* Check for default ACLs that haven't been parsed yet */
|
||||
if (vconfig != NULL)
|
||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
||||
if (config != NULL) {
|
||||
@@ -90,12 +149,18 @@
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
+parse_acl:
|
||||
result = cfg_acl_fromconfig(aclobj, config, ns_g_lctx, actx,
|
||||
- dns_zone_getmctx(zone), 0, &dacl);
|
||||
+ dns_zone_getmctx(zone), 0, &acl);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
- (*setzacl)(zone, dacl);
|
||||
- dns_acl_detach(&dacl);
|
||||
+ (*setzacl)(zone, acl);
|
||||
+
|
||||
+ /* Set the view default now */
|
||||
+ if (aclp != NULL)
|
||||
+ dns_acl_attach(acl, aclp);
|
||||
+
|
||||
+ dns_acl_detach(&acl);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -454,14 +519,14 @@
|
||||
|
||||
if (ztype == dns_zone_slave)
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
- "allow-notify", ac, zone,
|
||||
+ allow_notify, ac, zone,
|
||||
dns_zone_setnotifyacl,
|
||||
dns_zone_clearnotifyacl));
|
||||
/*
|
||||
* XXXAG This probably does not make sense for stubs.
|
||||
*/
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
- "allow-query", ac, zone,
|
||||
+ allow_query, ac, zone,
|
||||
dns_zone_setqueryacl,
|
||||
dns_zone_clearqueryacl));
|
||||
|
||||
@@ -564,7 +629,7 @@
|
||||
dns_zone_setisself(zone, ns_client_isself, NULL);
|
||||
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
- "allow-transfer", ac, zone,
|
||||
+ allow_transfer, ac, zone,
|
||||
dns_zone_setxfracl,
|
||||
dns_zone_clearxfracl));
|
||||
|
||||
@@ -655,7 +720,7 @@
|
||||
if (ztype == dns_zone_master) {
|
||||
dns_acl_t *updateacl;
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
- "allow-update", ac, zone,
|
||||
+ allow_update, ac, zone,
|
||||
dns_zone_setupdateacl,
|
||||
dns_zone_clearupdateacl));
|
||||
|
||||
@@ -754,7 +819,7 @@
|
||||
cfg_obj_asboolean(obj));
|
||||
} else if (ztype == dns_zone_slave) {
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
- "allow-update-forwarding", ac, zone,
|
||||
+ allow_update_forwarding, ac, zone,
|
||||
dns_zone_setforwardacl,
|
||||
dns_zone_clearforwardacl));
|
||||
}
|
||||
Index: lib/dns/view.c
|
||||
===================================================================
|
||||
RCS file: /proj/cvs/prod/bind9/lib/dns/view.c,v
|
||||
retrieving revision 1.143.128.5
|
||||
diff -u -r1.143.128.5 view.c
|
||||
--- lib/dns/view.c 13 May 2008 23:46:31 -0000 1.143.128.5
|
||||
+++ lib/dns/view.c 21 May 2008 23:46:19 -0000
|
||||
@@ -172,6 +172,10 @@
|
||||
view->recursionacl = NULL;
|
||||
view->recursiononacl = NULL;
|
||||
view->sortlist = NULL;
|
||||
+ view->transferacl = NULL;
|
||||
+ view->notifyacl = NULL;
|
||||
+ view->updateacl = NULL;
|
||||
+ view->upfwdacl = NULL;
|
||||
view->requestixfr = ISC_TRUE;
|
||||
view->provideixfr = ISC_TRUE;
|
||||
view->maxcachettl = 7 * 24 * 3600;
|
||||
@@ -299,6 +303,14 @@
|
||||
dns_acl_detach(&view->recursiononacl);
|
||||
if (view->sortlist != NULL)
|
||||
dns_acl_detach(&view->sortlist);
|
||||
+ if (view->transferacl != NULL)
|
||||
+ dns_acl_detach(&view->transferacl);
|
||||
+ if (view->notifyacl != NULL)
|
||||
+ dns_acl_detach(&view->notifyacl);
|
||||
+ if (view->updateacl != NULL)
|
||||
+ dns_acl_detach(&view->updateacl);
|
||||
+ if (view->upfwdacl != NULL)
|
||||
+ dns_acl_detach(&view->upfwdacl);
|
||||
if (view->delonly != NULL) {
|
||||
dns_name_t *name;
|
||||
int i;
|
||||
Index: lib/dns/include/dns/view.h
|
||||
===================================================================
|
||||
RCS file: /proj/cvs/prod/bind9/lib/dns/include/dns/view.h,v
|
||||
retrieving revision 1.107.128.4
|
||||
diff -u -r1.107.128.4 view.h
|
||||
--- lib/dns/include/dns/view.h 3 Apr 2008 06:20:34 -0000 1.107.128.4
|
||||
+++ lib/dns/include/dns/view.h 21 May 2008 23:46:21 -0000
|
||||
@@ -123,6 +123,10 @@
|
||||
dns_acl_t * recursionacl;
|
||||
dns_acl_t * recursiononacl;
|
||||
dns_acl_t * sortlist;
|
||||
+ dns_acl_t * notifyacl;
|
||||
+ dns_acl_t * transferacl;
|
||||
+ dns_acl_t * updateacl;
|
||||
+ dns_acl_t * upfwdacl;
|
||||
isc_boolean_t requestixfr;
|
||||
isc_boolean_t provideixfr;
|
||||
isc_boolean_t requestnsid;
|
||||
Index: lib/isccfg/aclconf.c
|
||||
===================================================================
|
||||
RCS file: /proj/cvs/prod/bind9/lib/isccfg/aclconf.c,v
|
||||
retrieving revision 1.17
|
||||
diff -u -r1.17 aclconf.c
|
||||
--- lib/isccfg/aclconf.c 21 Dec 2007 06:46:47 -0000 1.17
|
||||
+++ lib/isccfg/aclconf.c 21 May 2008 23:46:21 -0000
|
||||
@@ -175,6 +175,7 @@
|
||||
const cfg_listelt_t *elt;
|
||||
dns_iptable_t *iptab;
|
||||
int new_nest_level = 0;
|
||||
+ int nelem;
|
||||
|
||||
if (nest_level != 0)
|
||||
new_nest_level = nest_level - 1;
|
||||
@@ -206,6 +207,8 @@
|
||||
return (result);
|
||||
}
|
||||
|
||||
+ nelem = cfg_list_length(caml, ISC_FALSE);
|
||||
+
|
||||
de = dacl->elements;
|
||||
for (elt = cfg_list_first(caml);
|
||||
elt != NULL;
|
||||
@@ -350,6 +353,16 @@
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
|
||||
+ /*
|
||||
+ * There was only one element and it was
|
||||
+ * a nested named ACL; attach it to the
|
||||
+ * target and let's go home.
|
||||
+ */
|
||||
+ if (nelem == 1) {
|
||||
+ dns_acl_attach(inneracl, target);
|
||||
+ goto cleanup;
|
||||
+ }
|
||||
+
|
||||
goto nested_acl;
|
||||
}
|
||||
} else {
|
||||
@@ -48,21 +48,18 @@ BIND 9.5.0
|
||||
BIND 9.5.0 has a number of new features over 9.4,
|
||||
including:
|
||||
|
||||
GSS-TSIG support (RFC 3645).
|
||||
- GSS-TSIG support (RFC 3645).
|
||||
- DHCID support.
|
||||
- Experimental http server and statistics support for named via xml.
|
||||
- More detailed statistics counters including those supported in
|
||||
BIND 8.
|
||||
- Faster ACL processing.
|
||||
- Internal documentation generated by Doxygen.
|
||||
- Efficient LRU cache-cleaning mechanism.
|
||||
- NSID support (RFC 5001).
|
||||
|
||||
DHCID support.
|
||||
|
||||
Experimental http server and statistics support for named via xml.
|
||||
|
||||
More detailed statistics counters including those supported in BIND 8.
|
||||
|
||||
Faster ACL processing.
|
||||
|
||||
Use Doxygen to generate internal documentation.
|
||||
|
||||
Efficient LRU cache-cleaning mechanism.
|
||||
|
||||
NSID support.
|
||||
Please see the file KNOWN-DEFECTS for information about known
|
||||
problems in the 9.5.0 release.
|
||||
|
||||
BIND 9.4.0
|
||||
|
||||
|
||||
@@ -1,61 +0,0 @@
|
||||
|
||||
BIND-9 PKCS#11 support
|
||||
|
||||
Prerequisite
|
||||
|
||||
The PKCS#11 support needs a PKCS#11 OpenSSL engine based on the Solaris one,
|
||||
released the 2007-11-21 for OpenSSL 0.9.8g, with a bug fix (call to free)
|
||||
and some improvements, including user friendly PIN management.
|
||||
|
||||
Compilation
|
||||
|
||||
"configure --with-pkcs11 ..."
|
||||
|
||||
PKCS#11 Libraries
|
||||
|
||||
Tested with Solaris one with a SCA board and with openCryptoki with the
|
||||
software token.
|
||||
|
||||
OpenSSL Engines
|
||||
|
||||
With PKCS#11 support the PKCS#11 engine is statically loaded but at its
|
||||
initialization it dynamically loads the PKCS#11 objects.
|
||||
Even the pre commands are therefore unused they are defined with:
|
||||
SO_PATH:
|
||||
define: PKCS11_SO_PATH
|
||||
default: /usr/local/lib/engines/engine_pkcs11.so
|
||||
MODULE_PATH:
|
||||
define: PKCS11_MODULE_PATH
|
||||
default: /usr/lib/libpkcs11.so
|
||||
Without PKCS#11 support, a specific OpenSSL engine can be still used
|
||||
by defining ENGINE_ID at compile time.
|
||||
|
||||
PKCS#11 tools
|
||||
|
||||
The contrib/pkcs11-keygen directory contains a set of experimental tools
|
||||
to handle keys stored in a Hardware Security Module at the benefit of BIND.
|
||||
|
||||
The patch for OpenSSL 0.9.8g is in this directory. Read its README.pkcs11
|
||||
for the way to use it (these are the original notes so with the original
|
||||
path, etc. Define OPENCRYPTOKI to use it with openCryptoki.)
|
||||
|
||||
PIN management
|
||||
|
||||
With the just fixed PKCS#11 OpenSSL engine, the PIN should be entered
|
||||
each time it is required. With the improved engine, the PIN should be
|
||||
entered the first time it is required or can be configured in the
|
||||
OpenSSL configuration file (aka. openssl.cnf) by adding in it:
|
||||
- at the beginning:
|
||||
openssl_conf = openssl_def
|
||||
- at any place these sections:
|
||||
[ openssl_def ]
|
||||
engines = engine_section
|
||||
[ engine_section ]
|
||||
pkcs11 = pkcs11_section
|
||||
[ pkcs11_section ]
|
||||
PIN = put__your__pin__value__here
|
||||
|
||||
Note
|
||||
|
||||
Some names here are registered trademarks, at least Solaris is a trademark
|
||||
of Sun Microsystems Inc...
|
||||
+13
-17
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: check-tool.c,v 1.34 2008/01/18 23:46:57 tbox Exp $ */
|
||||
/* $Id: check-tool.c,v 1.31 2007/09/13 04:45:18 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -60,7 +60,7 @@
|
||||
result = (r); \
|
||||
if (result != ISC_R_SUCCESS) \
|
||||
goto cleanup; \
|
||||
} while (0)
|
||||
} while (0)
|
||||
|
||||
#define ERR_IS_CNAME 1
|
||||
#define ERR_NO_ADDRESSES 2
|
||||
@@ -78,7 +78,7 @@ isc_boolean_t nomerge = ISC_TRUE;
|
||||
isc_boolean_t docheckmx = ISC_TRUE;
|
||||
isc_boolean_t dochecksrv = ISC_TRUE;
|
||||
isc_boolean_t docheckns = ISC_TRUE;
|
||||
unsigned int zone_options = DNS_ZONEOPT_CHECKNS |
|
||||
unsigned int zone_options = DNS_ZONEOPT_CHECKNS |
|
||||
DNS_ZONEOPT_CHECKMX |
|
||||
DNS_ZONEOPT_MANYERRORS |
|
||||
DNS_ZONEOPT_CHECKNAMES |
|
||||
@@ -109,7 +109,7 @@ freekey(char *key, unsigned int type, isc_symvalue_t value, void *userarg) {
|
||||
UNUSED(type);
|
||||
UNUSED(value);
|
||||
isc_mem_free(userarg, key);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
add(char *key, int value) {
|
||||
@@ -205,9 +205,8 @@ checkns(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner,
|
||||
!logged(namebuf, ERR_IS_CNAME)) {
|
||||
dns_zone_log(zone, ISC_LOG_ERROR,
|
||||
"%s/NS '%s' (out of zone) "
|
||||
"is a CNAME '%s' (illegal)",
|
||||
ownerbuf, namebuf,
|
||||
cur->ai_canonname);
|
||||
"is a CNAME (illegal)",
|
||||
ownerbuf, namebuf);
|
||||
/* XXX950 make fatal for 9.5.0 */
|
||||
/* answer = ISC_FALSE; */
|
||||
add(namebuf, ERR_IS_CNAME);
|
||||
@@ -377,7 +376,7 @@ checkmx(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||
if (dns_name_countlabels(name) > 1U)
|
||||
strcat(namebuf, ".");
|
||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||
|
||||
|
||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||
switch (result) {
|
||||
@@ -398,10 +397,8 @@ checkmx(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||
if (!logged(namebuf, ERR_IS_MXCNAME)) {
|
||||
dns_zone_log(zone, level,
|
||||
"%s/MX '%s' (out of zone)"
|
||||
" is a CNAME '%s' "
|
||||
"(illegal)",
|
||||
ownerbuf, namebuf,
|
||||
cur->ai_canonname);
|
||||
" is a CNAME (illegal)",
|
||||
ownerbuf, namebuf);
|
||||
add(namebuf, ERR_IS_MXCNAME);
|
||||
}
|
||||
if (level == ISC_LOG_ERROR)
|
||||
@@ -462,7 +459,7 @@ checksrv(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||
if (dns_name_countlabels(name) > 1U)
|
||||
strcat(namebuf, ".");
|
||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||
|
||||
|
||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||
dns_name_format(name, namebuf, sizeof(namebuf) - 1);
|
||||
switch (result) {
|
||||
@@ -483,9 +480,8 @@ checksrv(dns_zone_t *zone, dns_name_t *name, dns_name_t *owner) {
|
||||
if (!logged(namebuf, ERR_IS_SRVCNAME)) {
|
||||
dns_zone_log(zone, level, "%s/SRV '%s'"
|
||||
" (out of zone) is a "
|
||||
"CNAME '%s' (illegal)",
|
||||
ownerbuf, namebuf,
|
||||
cur->ai_canonname);
|
||||
"CNAME (illegal)",
|
||||
ownerbuf, namebuf);
|
||||
add(namebuf, ERR_IS_SRVCNAME);
|
||||
}
|
||||
if (level == ISC_LOG_ERROR)
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dig.1,v 1.48 2008/05/15 01:12:20 tbox Exp $
|
||||
.\" $Id: dig.1,v 1.45.150.3 2008/05/15 01:42:11 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.c,v 1.221 2008/04/03 02:01:08 marka Exp $ */
|
||||
/* $Id: dig.c,v 1.218.12.3 2008/04/03 02:12:21 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+1
-1
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dig.docbook,v 1.40 2008/05/14 23:47:03 tbox Exp $ -->
|
||||
<!-- $Id: dig.docbook,v 1.38.130.2 2008/05/14 23:46:33 tbox Exp $ -->
|
||||
<refentry id="man.dig">
|
||||
|
||||
<refentryinfo>
|
||||
|
||||
+1
-1
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dig.html,v 1.43 2008/05/15 01:12:20 tbox Exp $ -->
|
||||
<!-- $Id: dig.html,v 1.41.150.2 2008/05/15 01:42:11 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
|
||||
+7
-5
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dighost.c,v 1.309 2008/04/03 02:01:08 marka Exp $ */
|
||||
/* $Id: dighost.c,v 1.304.12.5.4.2 2008/07/23 22:51:52 marka Exp $ */
|
||||
|
||||
/*! \file
|
||||
* \note
|
||||
@@ -2236,14 +2236,15 @@ send_tcp_connect(dig_query_t *query) {
|
||||
sockcount++;
|
||||
debug("sockcount=%d", sockcount);
|
||||
if (specified_source)
|
||||
result = isc_socket_bind(query->sock, &bind_address);
|
||||
result = isc_socket_bind(query->sock, &bind_address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
else {
|
||||
if ((isc_sockaddr_pf(&query->sockaddr) == AF_INET) &&
|
||||
have_ipv4)
|
||||
isc_sockaddr_any(&bind_any);
|
||||
else
|
||||
isc_sockaddr_any6(&bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any, 0);
|
||||
}
|
||||
check_result(result, "isc_socket_bind");
|
||||
bringup_timer(query, TCP_TIMEOUT);
|
||||
@@ -2290,11 +2291,12 @@ send_udp(dig_query_t *query) {
|
||||
sockcount++;
|
||||
debug("sockcount=%d", sockcount);
|
||||
if (specified_source) {
|
||||
result = isc_socket_bind(query->sock, &bind_address);
|
||||
result = isc_socket_bind(query->sock, &bind_address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
} else {
|
||||
isc_sockaddr_anyofpf(&bind_any,
|
||||
isc_sockaddr_pf(&query->sockaddr));
|
||||
result = isc_socket_bind(query->sock, &bind_any);
|
||||
result = isc_socket_bind(query->sock, &bind_any, 0);
|
||||
}
|
||||
check_result(result, "isc_socket_bind");
|
||||
|
||||
|
||||
+1
-1
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: host.1,v 1.29 2008/04/05 01:09:34 tbox Exp $
|
||||
.\" $Id: host.1,v 1.28.164.2 2008/04/06 01:41:39 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: host.docbook,v 1.18 2008/04/04 23:47:01 tbox Exp $ -->
|
||||
<!-- $Id: host.docbook,v 1.16.130.2 2008/04/05 23:46:39 tbox Exp $ -->
|
||||
<refentry id="man.host">
|
||||
|
||||
<refentryinfo>
|
||||
|
||||
+1
-1
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: host.html,v 1.28 2008/04/05 01:09:34 tbox Exp $ -->
|
||||
<!-- $Id: host.html,v 1.27.164.2 2008/04/06 01:41:39 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.h,v 1.107 2008/04/03 06:09:04 tbox Exp $ */
|
||||
/* $Id: dig.h,v 1.105.130.2 2008/04/03 06:08:26 tbox Exp $ */
|
||||
|
||||
#ifndef DIG_H
|
||||
#define DIG_H
|
||||
|
||||
@@ -3,6 +3,5 @@ dnssec-keygen
|
||||
dnssec-makekeyset
|
||||
dnssec-signkey
|
||||
dnssec-signzone
|
||||
dnssec-keyfromlabel
|
||||
*.lo
|
||||
.libs
|
||||
|
||||
+6
-13
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000-2002 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.34 2008/04/01 23:47:10 tbox Exp $
|
||||
# $Id: Makefile.in,v 1.32 2007/06/19 23:46:59 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -39,27 +39,20 @@ DEPLIBS = ${DNSDEPLIBS} ${ISCDEPLIBS}
|
||||
LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
||||
|
||||
# Alphabetically
|
||||
TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
||||
dnssec-keyfromlabel@EXEEXT@
|
||||
TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@
|
||||
|
||||
OBJS = dnssectool.@O@
|
||||
|
||||
SRCS = dnssec-keyfromlabel.c dnssec-keygen.c dnssec-signzone.c \
|
||||
dnssectool.c
|
||||
SRCS = dnssec-keygen.c dnssec-signzone.c dnssectool.c
|
||||
|
||||
MANPAGES = dnssec-keyfromlabel.8 dnssec-keygen.8 dnssec-signzone.8
|
||||
MANPAGES = dnssec-keygen.8 dnssec-signzone.8
|
||||
|
||||
HTMLPAGES = dnssec-keyfromlabel.html dnssec-keygen.html \
|
||||
dnssec-signzone.html
|
||||
HTMLPAGES = dnssec-keygen.html dnssec-signzone.html
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
dnssec-keyfromlabel@EXEEXT@: dnssec-keyfromlabel.@O@ ${OBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
dnssec-keyfromlabel.@O@ ${OBJS} ${LIBS}
|
||||
|
||||
dnssec-keygen@EXEEXT@: dnssec-keygen.@O@ ${OBJS} ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
dnssec-keygen.@O@ ${OBJS} ${LIBS}
|
||||
|
||||
@@ -1,149 +0,0 @@
|
||||
.\" Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-keyfromlabel.8,v 1.3 2008/04/01 01:11:50 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
.\" Title: dnssec\-keyfromlabel
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>
|
||||
.\" Date: february 8, 2008
|
||||
.\" Manual: BIND9
|
||||
.\" Source: BIND9
|
||||
.\"
|
||||
.TH "DNSSEC\-KEYFROMLABEL" "8" "february 8, 2008" "BIND9" "BIND9"
|
||||
.\" disable hyphenation
|
||||
.nh
|
||||
.\" disable justification (adjust text to left margin only)
|
||||
.ad l
|
||||
.SH "NAME"
|
||||
dnssec\-keyfromlabel \- DNSSEC key generation tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP 20
|
||||
\fBdnssec\-keyfromlabel\fR {\-a\ \fIalgorithm\fR} {\-l\ \fIlabel\fR} [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-k\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-keyfromlabel\fR
|
||||
gets keys with the given label from a crypto hardware and builds key files for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-a \fIalgorithm\fR
|
||||
.RS 4
|
||||
Selects the cryptographic algorithm. The value of
|
||||
\fBalgorithm\fR
|
||||
must be one of RSAMD5 (RSA) or RSASHA1, DSA or DH (Diffie Hellman). These values are case insensitive.
|
||||
.sp
|
||||
Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement algorithm, and DSA is recommended.
|
||||
.sp
|
||||
Note 2: DH automatically sets the \-k flag.
|
||||
.RE
|
||||
.PP
|
||||
\-l \fIlabel\fR
|
||||
.RS 4
|
||||
Specifies the label of keys in the crypto hardware (PKCS#11 device).
|
||||
.RE
|
||||
.PP
|
||||
\-n \fInametype\fR
|
||||
.RS 4
|
||||
Specifies the owner type of the key. The value of
|
||||
\fBnametype\fR
|
||||
must either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with a host (KEY)), USER (for a key associated with a user(KEY)) or OTHER (DNSKEY). These values are case insensitive.
|
||||
.RE
|
||||
.PP
|
||||
\-c \fIclass\fR
|
||||
.RS 4
|
||||
Indicates that the DNS record containing the key should have the specified class. If not specified, class IN is used.
|
||||
.RE
|
||||
.PP
|
||||
\-f \fIflag\fR
|
||||
.RS 4
|
||||
Set the specified flag in the flag field of the KEY/DNSKEY record. The only recognized flag is KSK (Key Signing Key) DNSKEY.
|
||||
.RE
|
||||
.PP
|
||||
\-h
|
||||
.RS 4
|
||||
Prints a short summary of the options and arguments to
|
||||
\fBdnssec\-keygen\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-k
|
||||
.RS 4
|
||||
Generate KEY records rather than DNSKEY records.
|
||||
.RE
|
||||
.PP
|
||||
\-p \fIprotocol\fR
|
||||
.RS 4
|
||||
Sets the protocol value for the generated key. The protocol is a number between 0 and 255. The default is 3 (DNSSEC). Other possible values for this argument are listed in RFC 2535 and its successors.
|
||||
.RE
|
||||
.PP
|
||||
\-t \fItype\fR
|
||||
.RS 4
|
||||
Indicates the use of the key.
|
||||
\fBtype\fR
|
||||
must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH refers to the ability to authenticate data, and CONF the ability to encrypt data.
|
||||
.RE
|
||||
.PP
|
||||
\-v \fIlevel\fR
|
||||
.RS 4
|
||||
Sets the debugging level.
|
||||
.RE
|
||||
.SH "GENERATED KEY FILES"
|
||||
.PP
|
||||
When
|
||||
\fBdnssec\-keyfromlabel\fR
|
||||
completes successfully, it prints a string of the form
|
||||
\fIKnnnn.+aaa+iiiii\fR
|
||||
to the standard output. This is an identification string for the key files it has generated.
|
||||
.TP 4
|
||||
\(bu
|
||||
\fInnnn\fR
|
||||
is the key name.
|
||||
.TP 4
|
||||
\(bu
|
||||
\fIaaa\fR
|
||||
is the numeric representation of the algorithm.
|
||||
.TP 4
|
||||
\(bu
|
||||
\fIiiiii\fR
|
||||
is the key identifier (or footprint).
|
||||
.PP
|
||||
\fBdnssec\-keyfromlabel\fR
|
||||
creates two files, with names based on the printed string.
|
||||
\fIKnnnn.+aaa+iiiii.key\fR
|
||||
contains the public key, and
|
||||
\fIKnnnn.+aaa+iiiii.private\fR
|
||||
contains the private key.
|
||||
.PP
|
||||
The
|
||||
\fI.key\fR
|
||||
file contains a DNS KEY record that can be inserted into a zone file (directly or with a $INCLUDE statement).
|
||||
.PP
|
||||
The
|
||||
\fI.private\fR
|
||||
file contains algorithm specific fields. For obvious security reasons, this file does not have general read permission.
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR(8),
|
||||
\fBdnssec\-signzone\fR(8),
|
||||
BIND 9 Administrator Reference Manual,
|
||||
RFC 2535,
|
||||
RFC 2845,
|
||||
RFC 2539.
|
||||
.SH "AUTHOR"
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
@@ -1,326 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-keyfromlabel.c,v 1.3 2008/03/31 23:47:11 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/commandline.h>
|
||||
#include <isc/entropy.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/fixedname.h>
|
||||
#include <dns/keyvalues.h>
|
||||
#include <dns/log.h>
|
||||
#include <dns/name.h>
|
||||
#include <dns/rdataclass.h>
|
||||
#include <dns/result.h>
|
||||
#include <dns/secalg.h>
|
||||
|
||||
#include <dst/dst.h>
|
||||
|
||||
#include "dnssectool.h"
|
||||
|
||||
#define MAX_RSA 4096 /* should be long enough... */
|
||||
|
||||
const char *program = "dnssec-keyfromlabel";
|
||||
int verbose;
|
||||
|
||||
static const char *algs = "RSA | RSAMD5 | DH | DSA | RSASHA1";
|
||||
|
||||
static void
|
||||
usage(void) {
|
||||
fprintf(stderr, "Usage:\n");
|
||||
fprintf(stderr, " %s -a alg -l label [options] name\n\n",
|
||||
program);
|
||||
fprintf(stderr, "Version: %s\n", VERSION);
|
||||
fprintf(stderr, "Required options:\n");
|
||||
fprintf(stderr, " -a algorithm: %s\n", algs);
|
||||
fprintf(stderr, " -l label: label of the key\n");
|
||||
fprintf(stderr, " name: owner of the key\n");
|
||||
fprintf(stderr, "Other options:\n");
|
||||
fprintf(stderr, " -n nametype: ZONE | HOST | ENTITY | USER | OTHER\n");
|
||||
fprintf(stderr, " (DNSKEY generation defaults to ZONE\n");
|
||||
fprintf(stderr, " -c <class> (default: IN)\n");
|
||||
fprintf(stderr, " -f keyflag: KSK\n");
|
||||
fprintf(stderr, " -t <type>: "
|
||||
"AUTHCONF | NOAUTHCONF | NOAUTH | NOCONF "
|
||||
"(default: AUTHCONF)\n");
|
||||
fprintf(stderr, " -p <protocol>: "
|
||||
"default: 3 [dnssec]\n");
|
||||
fprintf(stderr, " -v <verbose level>\n");
|
||||
fprintf(stderr, " -k : generate a TYPE=KEY key\n");
|
||||
fprintf(stderr, "Output:\n");
|
||||
fprintf(stderr, " K<name>+<alg>+<id>.key, "
|
||||
"K<name>+<alg>+<id>.private\n");
|
||||
|
||||
exit (-1);
|
||||
}
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
char *algname = NULL, *nametype = NULL, *type = NULL;
|
||||
char *classname = NULL;
|
||||
char *endp;
|
||||
dst_key_t *key = NULL, *oldkey;
|
||||
dns_fixedname_t fname;
|
||||
dns_name_t *name;
|
||||
isc_uint16_t flags = 0, ksk = 0;
|
||||
dns_secalg_t alg;
|
||||
isc_boolean_t null_key = ISC_FALSE;
|
||||
isc_mem_t *mctx = NULL;
|
||||
int ch;
|
||||
int protocol = -1, signatory = 0;
|
||||
isc_result_t ret;
|
||||
isc_textregion_t r;
|
||||
char filename[255];
|
||||
isc_buffer_t buf;
|
||||
isc_log_t *log = NULL;
|
||||
isc_entropy_t *ectx = NULL;
|
||||
dns_rdataclass_t rdclass;
|
||||
int options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC;
|
||||
char *label = NULL;
|
||||
|
||||
if (argc == 1)
|
||||
usage();
|
||||
|
||||
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||
|
||||
dns_result_register();
|
||||
|
||||
isc_commandline_errprint = ISC_FALSE;
|
||||
|
||||
while ((ch = isc_commandline_parse(argc, argv,
|
||||
"a:c:f:kl:n:p:t:v:h")) != -1)
|
||||
{
|
||||
switch (ch) {
|
||||
case 'a':
|
||||
algname = isc_commandline_argument;
|
||||
break;
|
||||
case 'c':
|
||||
classname = isc_commandline_argument;
|
||||
break;
|
||||
case 'f':
|
||||
if (strcasecmp(isc_commandline_argument, "KSK") == 0)
|
||||
ksk = DNS_KEYFLAG_KSK;
|
||||
else
|
||||
fatal("unknown flag '%s'",
|
||||
isc_commandline_argument);
|
||||
break;
|
||||
case 'k':
|
||||
options |= DST_TYPE_KEY;
|
||||
break;
|
||||
case 'l':
|
||||
label = isc_commandline_argument;
|
||||
break;
|
||||
case 'n':
|
||||
nametype = isc_commandline_argument;
|
||||
break;
|
||||
case 'p':
|
||||
protocol = strtol(isc_commandline_argument, &endp, 10);
|
||||
if (*endp != '\0' || protocol < 0 || protocol > 255)
|
||||
fatal("-p must be followed by a number "
|
||||
"[0..255]");
|
||||
break;
|
||||
case 't':
|
||||
type = isc_commandline_argument;
|
||||
break;
|
||||
case 'v':
|
||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||
if (*endp != '\0')
|
||||
fatal("-v must be followed by a number");
|
||||
break;
|
||||
|
||||
case '?':
|
||||
if (isc_commandline_option != '?')
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
case 'h':
|
||||
usage();
|
||||
|
||||
default:
|
||||
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||
program, isc_commandline_option);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
ret = dst_lib_init(mctx, ectx,
|
||||
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("could not initialize dst");
|
||||
|
||||
setup_logging(verbose, mctx, &log);
|
||||
|
||||
if (label == NULL)
|
||||
fatal("the key label was not specified");
|
||||
if (argc < isc_commandline_index + 1)
|
||||
fatal("the key name was not specified");
|
||||
if (argc > isc_commandline_index + 1)
|
||||
fatal("extraneous arguments");
|
||||
|
||||
if (algname == NULL)
|
||||
fatal("no algorithm was specified");
|
||||
if (strcasecmp(algname, "RSA") == 0) {
|
||||
fprintf(stderr, "The use of RSA (RSAMD5) is not recommended.\n"
|
||||
"If you still wish to use RSA (RSAMD5) please "
|
||||
"specify \"-a RSAMD5\"\n");
|
||||
return (1);
|
||||
} else {
|
||||
r.base = algname;
|
||||
r.length = strlen(algname);
|
||||
ret = dns_secalg_fromtext(&alg, &r);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("unknown algorithm %s", algname);
|
||||
if (alg == DST_ALG_DH)
|
||||
options |= DST_TYPE_KEY;
|
||||
}
|
||||
|
||||
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
|
||||
if (strcasecmp(type, "NOAUTH") == 0)
|
||||
flags |= DNS_KEYTYPE_NOAUTH;
|
||||
else if (strcasecmp(type, "NOCONF") == 0)
|
||||
flags |= DNS_KEYTYPE_NOCONF;
|
||||
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
|
||||
flags |= (DNS_KEYTYPE_NOAUTH | DNS_KEYTYPE_NOCONF);
|
||||
}
|
||||
else if (strcasecmp(type, "AUTHCONF") == 0)
|
||||
/* nothing */;
|
||||
else
|
||||
fatal("invalid type %s", type);
|
||||
}
|
||||
|
||||
if (nametype == NULL) {
|
||||
if ((options & DST_TYPE_KEY) != 0) /* KEY */
|
||||
fatal("no nametype specified");
|
||||
flags |= DNS_KEYOWNER_ZONE; /* DNSKEY */
|
||||
} else if (strcasecmp(nametype, "zone") == 0)
|
||||
flags |= DNS_KEYOWNER_ZONE;
|
||||
else if ((options & DST_TYPE_KEY) != 0) { /* KEY */
|
||||
if (strcasecmp(nametype, "host") == 0 ||
|
||||
strcasecmp(nametype, "entity") == 0)
|
||||
flags |= DNS_KEYOWNER_ENTITY;
|
||||
else if (strcasecmp(nametype, "user") == 0)
|
||||
flags |= DNS_KEYOWNER_USER;
|
||||
else
|
||||
fatal("invalid KEY nametype %s", nametype);
|
||||
} else if (strcasecmp(nametype, "other") != 0) /* DNSKEY */
|
||||
fatal("invalid DNSKEY nametype %s", nametype);
|
||||
|
||||
rdclass = strtoclass(classname);
|
||||
|
||||
if ((options & DST_TYPE_KEY) != 0) /* KEY */
|
||||
flags |= signatory;
|
||||
else if ((flags & DNS_KEYOWNER_ZONE) != 0) /* DNSKEY */
|
||||
flags |= ksk;
|
||||
|
||||
if (protocol == -1)
|
||||
protocol = DNS_KEYPROTO_DNSSEC;
|
||||
else if ((options & DST_TYPE_KEY) == 0 &&
|
||||
protocol != DNS_KEYPROTO_DNSSEC)
|
||||
fatal("invalid DNSKEY protocol: %d", protocol);
|
||||
|
||||
if ((flags & DNS_KEYFLAG_TYPEMASK) == DNS_KEYTYPE_NOKEY) {
|
||||
if ((flags & DNS_KEYFLAG_SIGNATORYMASK) != 0)
|
||||
fatal("specified null key with signing authority");
|
||||
}
|
||||
|
||||
if ((flags & DNS_KEYFLAG_OWNERMASK) == DNS_KEYOWNER_ZONE &&
|
||||
alg == DNS_KEYALG_DH)
|
||||
fatal("a key with algorithm '%s' cannot be a zone key",
|
||||
algname);
|
||||
|
||||
dns_fixedname_init(&fname);
|
||||
name = dns_fixedname_name(&fname);
|
||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||
strlen(argv[isc_commandline_index]));
|
||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||
ret = dns_name_fromtext(name, &buf, dns_rootname, ISC_FALSE, NULL);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("invalid key name %s: %s", argv[isc_commandline_index],
|
||||
isc_result_totext(ret));
|
||||
|
||||
if ((flags & DNS_KEYFLAG_TYPEMASK) == DNS_KEYTYPE_NOKEY)
|
||||
null_key = ISC_TRUE;
|
||||
|
||||
isc_buffer_init(&buf, filename, sizeof(filename) - 1);
|
||||
|
||||
/* associate the key */
|
||||
ret = dst_key_fromlabel(name, alg, flags, protocol,
|
||||
rdclass, "", label, NULL, mctx, &key);
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
if (ret != ISC_R_SUCCESS) {
|
||||
char namestr[DNS_NAME_FORMATSIZE];
|
||||
char algstr[ALG_FORMATSIZE];
|
||||
dns_name_format(name, namestr, sizeof(namestr));
|
||||
alg_format(alg, algstr, sizeof(algstr));
|
||||
fatal("failed to generate key %s/%s: %s\n",
|
||||
namestr, algstr, isc_result_totext(ret));
|
||||
exit(-1);
|
||||
}
|
||||
|
||||
/*
|
||||
* Try to read a key with the same name, alg and id from disk.
|
||||
* If there is one we must continue generating a new one
|
||||
* unless we were asked to generate a null key, in which
|
||||
* case we return failure.
|
||||
*/
|
||||
ret = dst_key_fromfile(name, dst_key_id(key), alg,
|
||||
DST_TYPE_PRIVATE, NULL, mctx, &oldkey);
|
||||
/* do not overwrite an existing key */
|
||||
if (ret == ISC_R_SUCCESS) {
|
||||
isc_buffer_clear(&buf);
|
||||
ret = dst_key_buildfilename(key, 0, NULL, &buf);
|
||||
fprintf(stderr, "%s: %s already exists\n",
|
||||
program, filename);
|
||||
dst_key_free(&key);
|
||||
exit (1);
|
||||
}
|
||||
|
||||
ret = dst_key_tofile(key, options, NULL);
|
||||
if (ret != ISC_R_SUCCESS) {
|
||||
char keystr[KEY_FORMATSIZE];
|
||||
key_format(key, keystr, sizeof(keystr));
|
||||
fatal("failed to write key %s: %s\n", keystr,
|
||||
isc_result_totext(ret));
|
||||
}
|
||||
|
||||
isc_buffer_clear(&buf);
|
||||
ret = dst_key_buildfilename(key, 0, NULL, &buf);
|
||||
printf("%s\n", filename);
|
||||
dst_key_free(&key);
|
||||
|
||||
cleanup_logging(&log);
|
||||
cleanup_entropy(&ectx);
|
||||
dst_lib_destroy();
|
||||
dns_name_destroy();
|
||||
if (verbose > 10)
|
||||
isc_mem_stats(mctx, stdout);
|
||||
isc_mem_destroy(&mctx);
|
||||
|
||||
return (0);
|
||||
}
|
||||
@@ -1,265 +0,0 @@
|
||||
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-keyfromlabel.docbook,v 1.3 2008/03/31 23:47:11 tbox Exp $ -->
|
||||
<refentry id="man.dnssec-keyfromlabel">
|
||||
<refentryinfo>
|
||||
<date>february 8, 2008</date>
|
||||
</refentryinfo>
|
||||
|
||||
<refmeta>
|
||||
<refentrytitle><application>dnssec-keyfromlabel</application></refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
<refmiscinfo>BIND9</refmiscinfo>
|
||||
</refmeta>
|
||||
|
||||
<refnamediv>
|
||||
<refname><application>dnssec-keyfromlabel</application></refname>
|
||||
<refpurpose>DNSSEC key generation tool</refpurpose>
|
||||
</refnamediv>
|
||||
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2008</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis>
|
||||
<command>dnssec-keyfromlabel</command>
|
||||
<arg choice="req">-a <replaceable class="parameter">algorithm</replaceable></arg>
|
||||
<arg choice="req">-l <replaceable class="parameter">label</replaceable></arg>
|
||||
<arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||
<arg><option>-f <replaceable class="parameter">flag</replaceable></option></arg>
|
||||
<arg><option>-k</option></arg>
|
||||
<arg><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
|
||||
<arg><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
|
||||
<arg><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
||||
<arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||
<arg choice="req">name</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsect1>
|
||||
<title>DESCRIPTION</title>
|
||||
<para><command>dnssec-keyfromlabel</command>
|
||||
gets keys with the given label from a crypto hardware and builds
|
||||
key files for DNSSEC (Secure DNS), as defined in RFC 2535
|
||||
and RFC 4034.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>OPTIONS</title>
|
||||
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
<term>-a <replaceable class="parameter">algorithm</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Selects the cryptographic algorithm. The value of
|
||||
<option>algorithm</option> must be one of RSAMD5 (RSA)
|
||||
or RSASHA1, DSA or DH (Diffie Hellman). These values
|
||||
are case insensitive.
|
||||
</para>
|
||||
<para>
|
||||
Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
|
||||
algorithm, and DSA is recommended.
|
||||
</para>
|
||||
<para>
|
||||
Note 2: DH automatically sets the -k flag.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-l <replaceable class="parameter">label</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies the label of keys in the crypto hardware
|
||||
(PKCS#11 device).
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-n <replaceable class="parameter">nametype</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies the owner type of the key. The value of
|
||||
<option>nametype</option> must either be ZONE (for a DNSSEC
|
||||
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
|
||||
a host (KEY)),
|
||||
USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
|
||||
These values are
|
||||
case insensitive.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-c <replaceable class="parameter">class</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Indicates that the DNS record containing the key should have
|
||||
the specified class. If not specified, class IN is used.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-f <replaceable class="parameter">flag</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Set the specified flag in the flag field of the KEY/DNSKEY record.
|
||||
The only recognized flag is KSK (Key Signing Key) DNSKEY.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-h</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Prints a short summary of the options and arguments to
|
||||
<command>dnssec-keygen</command>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-k</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Generate KEY records rather than DNSKEY records.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-p <replaceable class="parameter">protocol</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the protocol value for the generated key. The protocol
|
||||
is a number between 0 and 255. The default is 3 (DNSSEC).
|
||||
Other possible values for this argument are listed in
|
||||
RFC 2535 and its successors.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-t <replaceable class="parameter">type</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Indicates the use of the key. <option>type</option> must be
|
||||
one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
||||
is AUTHCONF. AUTH refers to the ability to authenticate
|
||||
data, and CONF the ability to encrypt data.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-v <replaceable class="parameter">level</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the debugging level.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>GENERATED KEY FILES</title>
|
||||
<para>
|
||||
When <command>dnssec-keyfromlabel</command> completes
|
||||
successfully,
|
||||
it prints a string of the form <filename>Knnnn.+aaa+iiiii</filename>
|
||||
to the standard output. This is an identification string for
|
||||
the key files it has generated.
|
||||
</para>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para><filename>nnnn</filename> is the key name.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para><filename>aaa</filename> is the numeric representation
|
||||
of the
|
||||
algorithm.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para><filename>iiiii</filename> is the key identifier (or
|
||||
footprint).
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
<para><command>dnssec-keyfromlabel</command>
|
||||
creates two files, with names based
|
||||
on the printed string. <filename>Knnnn.+aaa+iiiii.key</filename>
|
||||
contains the public key, and
|
||||
<filename>Knnnn.+aaa+iiiii.private</filename> contains the
|
||||
private
|
||||
key.
|
||||
</para>
|
||||
<para>
|
||||
The <filename>.key</filename> file contains a DNS KEY record
|
||||
that
|
||||
can be inserted into a zone file (directly or with a $INCLUDE
|
||||
statement).
|
||||
</para>
|
||||
<para>
|
||||
The <filename>.private</filename> file contains algorithm
|
||||
specific
|
||||
fields. For obvious security reasons, this file does not have
|
||||
general read permission.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>SEE ALSO</title>
|
||||
<para><citerefentry>
|
||||
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>,
|
||||
<citetitle>RFC 2535</citetitle>,
|
||||
<citetitle>RFC 2845</citetitle>,
|
||||
<citetitle>RFC 2539</citetitle>.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>AUTHOR</title>
|
||||
<para><corpauthor>Internet Systems Consortium</corpauthor>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
</refentry><!--
|
||||
- Local variables:
|
||||
- mode: sgml
|
||||
- End:
|
||||
-->
|
||||
@@ -1,171 +0,0 @@
|
||||
<!--
|
||||
- Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dnssec-keyfromlabel.html,v 1.3 2008/04/01 01:11:50 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>dnssec-keyfromlabel</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
|
||||
<a name="man.dnssec-keyfromlabel"></a><div class="titlepage"></div>
|
||||
<div class="refnamediv">
|
||||
<h2>Name</h2>
|
||||
<p><span class="application">dnssec-keyfromlabel</span> — DNSSEC key generation tool</p>
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-a <em class="replaceable"><code>algorithm</code></em>} {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-k</code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {name}</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543413"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
|
||||
gets keys with the given label from a crypto hardware and builds
|
||||
key files for DNSSEC (Secure DNS), as defined in RFC 2535
|
||||
and RFC 4034.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543425"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Selects the cryptographic algorithm. The value of
|
||||
<code class="option">algorithm</code> must be one of RSAMD5 (RSA)
|
||||
or RSASHA1, DSA or DH (Diffie Hellman). These values
|
||||
are case insensitive.
|
||||
</p>
|
||||
<p>
|
||||
Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
|
||||
algorithm, and DSA is recommended.
|
||||
</p>
|
||||
<p>
|
||||
Note 2: DH automatically sets the -k flag.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-l <em class="replaceable"><code>label</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies the label of keys in the crypto hardware
|
||||
(PKCS#11 device).
|
||||
</p></dd>
|
||||
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies the owner type of the key. The value of
|
||||
<code class="option">nametype</code> must either be ZONE (for a DNSSEC
|
||||
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
|
||||
a host (KEY)),
|
||||
USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
|
||||
These values are
|
||||
case insensitive.
|
||||
</p></dd>
|
||||
<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
|
||||
<dd><p>
|
||||
Indicates that the DNS record containing the key should have
|
||||
the specified class. If not specified, class IN is used.
|
||||
</p></dd>
|
||||
<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
|
||||
<dd><p>
|
||||
Set the specified flag in the flag field of the KEY/DNSKEY record.
|
||||
The only recognized flag is KSK (Key Signing Key) DNSKEY.
|
||||
</p></dd>
|
||||
<dt><span class="term">-h</span></dt>
|
||||
<dd><p>
|
||||
Prints a short summary of the options and arguments to
|
||||
<span><strong class="command">dnssec-keygen</strong></span>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-k</span></dt>
|
||||
<dd><p>
|
||||
Generate KEY records rather than DNSKEY records.
|
||||
</p></dd>
|
||||
<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
|
||||
<dd><p>
|
||||
Sets the protocol value for the generated key. The protocol
|
||||
is a number between 0 and 255. The default is 3 (DNSSEC).
|
||||
Other possible values for this argument are listed in
|
||||
RFC 2535 and its successors.
|
||||
</p></dd>
|
||||
<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
|
||||
<dd><p>
|
||||
Indicates the use of the key. <code class="option">type</code> must be
|
||||
one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
||||
is AUTHCONF. AUTH refers to the ability to authenticate
|
||||
data, and CONF the ability to encrypt data.
|
||||
</p></dd>
|
||||
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
|
||||
<dd><p>
|
||||
Sets the debugging level.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543619"></a><h2>GENERATED KEY FILES</h2>
|
||||
<p>
|
||||
When <span><strong class="command">dnssec-keyfromlabel</strong></span> completes
|
||||
successfully,
|
||||
it prints a string of the form <code class="filename">Knnnn.+aaa+iiiii</code>
|
||||
to the standard output. This is an identification string for
|
||||
the key files it has generated.
|
||||
</p>
|
||||
<div class="itemizedlist"><ul type="disc">
|
||||
<li><p><code class="filename">nnnn</code> is the key name.
|
||||
</p></li>
|
||||
<li><p><code class="filename">aaa</code> is the numeric representation
|
||||
of the
|
||||
algorithm.
|
||||
</p></li>
|
||||
<li><p><code class="filename">iiiii</code> is the key identifier (or
|
||||
footprint).
|
||||
</p></li>
|
||||
</ul></div>
|
||||
<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
|
||||
creates two files, with names based
|
||||
on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
|
||||
contains the public key, and
|
||||
<code class="filename">Knnnn.+aaa+iiiii.private</code> contains the
|
||||
private
|
||||
key.
|
||||
</p>
|
||||
<p>
|
||||
The <code class="filename">.key</code> file contains a DNS KEY record
|
||||
that
|
||||
can be inserted into a zone file (directly or with a $INCLUDE
|
||||
statement).
|
||||
</p>
|
||||
<p>
|
||||
The <code class="filename">.private</code> file contains algorithm
|
||||
specific
|
||||
fields. For obvious security reasons, this file does not have
|
||||
general read permission.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543691"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
<em class="citetitle">RFC 2535</em>,
|
||||
<em class="citetitle">RFC 2845</em>,
|
||||
<em class="citetitle">RFC 2539</em>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543731"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
</div></body>
|
||||
</html>
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Portions Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -29,7 +29,7 @@
|
||||
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-signzone.c,v 1.206 2008/06/02 23:47:04 tbox Exp $ */
|
||||
/* $Id: dnssec-signzone.c,v 1.204 2007/08/28 07:20:42 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -141,6 +141,7 @@ static dns_name_t *gorigin; /* The database origin */
|
||||
static isc_task_t *master = NULL;
|
||||
static unsigned int ntasks = 0;
|
||||
static isc_boolean_t shuttingdown = ISC_FALSE, finished = ISC_FALSE;
|
||||
static unsigned int assigned = 0, completed = 0;
|
||||
static isc_boolean_t nokeys = ISC_FALSE;
|
||||
static isc_boolean_t removefile = ISC_FALSE;
|
||||
static isc_boolean_t generateds = ISC_FALSE;
|
||||
@@ -981,7 +982,7 @@ active_node(dns_dbnode_t *node) {
|
||||
fatal("rdataset iteration failed: %s",
|
||||
isc_result_totext(result));
|
||||
} else {
|
||||
/*
|
||||
/*
|
||||
* Delete RRSIGs for types that no longer exist.
|
||||
*/
|
||||
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter2);
|
||||
@@ -1206,7 +1207,7 @@ signapex(void) {
|
||||
dns_fixedname_t fixed;
|
||||
dns_name_t *name;
|
||||
isc_result_t result;
|
||||
|
||||
|
||||
dns_fixedname_init(&fixed);
|
||||
name = dns_fixedname_name(&fixed);
|
||||
result = dns_dbiterator_current(gdbiter, &node, name);
|
||||
@@ -1236,19 +1237,16 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
||||
dns_rdataset_t nsec;
|
||||
isc_boolean_t found;
|
||||
isc_result_t result;
|
||||
static unsigned int ended = 0; /* Protected by namelock. */
|
||||
|
||||
if (shuttingdown)
|
||||
return;
|
||||
|
||||
LOCK(&namelock);
|
||||
if (finished) {
|
||||
ended++;
|
||||
if (ended == ntasks) {
|
||||
if (assigned == completed) {
|
||||
isc_task_detach(&task);
|
||||
isc_app_shutdown();
|
||||
}
|
||||
goto unlock;
|
||||
return;
|
||||
}
|
||||
|
||||
fname = isc_mem_get(mctx, sizeof(dns_fixedname_t));
|
||||
@@ -1258,6 +1256,7 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
||||
name = dns_fixedname_name(fname);
|
||||
node = NULL;
|
||||
found = ISC_FALSE;
|
||||
LOCK(&namelock);
|
||||
while (!found) {
|
||||
result = dns_dbiterator_current(gdbiter, &node, name);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
@@ -1284,14 +1283,14 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
||||
fatal("failure iterating database: %s",
|
||||
isc_result_totext(result));
|
||||
}
|
||||
UNLOCK(&namelock);
|
||||
if (!found) {
|
||||
ended++;
|
||||
if (ended == ntasks) {
|
||||
if (assigned == completed) {
|
||||
isc_task_detach(&task);
|
||||
isc_app_shutdown();
|
||||
}
|
||||
isc_mem_put(mctx, fname, sizeof(dns_fixedname_t));
|
||||
goto unlock;
|
||||
return;
|
||||
}
|
||||
sevent = (sevent_t *)
|
||||
isc_event_allocate(mctx, task, SIGNER_EVENT_WORK,
|
||||
@@ -1302,8 +1301,7 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
||||
sevent->node = node;
|
||||
sevent->fname = fname;
|
||||
isc_task_send(worker, ISC_EVENT_PTR(&sevent));
|
||||
unlock:
|
||||
UNLOCK(&namelock);
|
||||
assigned++;
|
||||
}
|
||||
|
||||
/*%
|
||||
@@ -1326,6 +1324,7 @@ writenode(isc_task_t *task, isc_event_t *event) {
|
||||
isc_task_t *worker;
|
||||
sevent_t *sevent = (sevent_t *)event;
|
||||
|
||||
completed++;
|
||||
worker = (isc_task_t *)event->ev_sender;
|
||||
dumpnode(dns_fixedname_name(sevent->fname), sevent->node);
|
||||
cleannode(gdb, gversion, sevent->node);
|
||||
@@ -1619,7 +1618,7 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
||||
unsigned char dsbuf[DNS_DS_BUFFERSIZE];
|
||||
unsigned char keybuf[DST_KEY_MAXSIZE];
|
||||
unsigned int filenamelen;
|
||||
const dns_master_style_t *style =
|
||||
const dns_master_style_t *style =
|
||||
(type == dns_rdatatype_dnskey) ? masterstyle : dsstyle;
|
||||
|
||||
isc_buffer_init(&namebuf, namestr, sizeof(namestr));
|
||||
@@ -1832,13 +1831,13 @@ print_stats(isc_time_t *timer_start, isc_time_t *timer_finish) {
|
||||
printf("Signatures successfully verified: %10d\n", nverified);
|
||||
printf("Signatures unsuccessfully verified: %10d\n", nverifyfailed);
|
||||
runtime_ms = runtime_us / 1000;
|
||||
printf("Runtime in seconds: %7u.%03u\n",
|
||||
(unsigned int) (runtime_ms / 1000),
|
||||
printf("Runtime in seconds: %7u.%03u\n",
|
||||
(unsigned int) (runtime_ms / 1000),
|
||||
(unsigned int) (runtime_ms % 1000));
|
||||
if (runtime_us > 0) {
|
||||
sig_ms = ((isc_uint64_t)nsigned * 1000000000) / runtime_us;
|
||||
printf("Signatures per second: %7u.%03u\n",
|
||||
(unsigned int) sig_ms / 1000,
|
||||
(unsigned int) sig_ms / 1000,
|
||||
(unsigned int) sig_ms % 1000);
|
||||
}
|
||||
}
|
||||
@@ -1938,7 +1937,7 @@ main(int argc, char *argv[]) {
|
||||
fatal("jitter must be numeric and positive");
|
||||
break;
|
||||
|
||||
case 'l':
|
||||
case 'l':
|
||||
dns_fixedname_init(&dlv_fixed);
|
||||
len = strlen(isc_commandline_argument);
|
||||
isc_buffer_init(&b, isc_commandline_argument, len);
|
||||
@@ -2104,7 +2103,7 @@ main(int argc, char *argv[]) {
|
||||
result = dns_master_stylecreate(&dsstyle, DNS_STYLEFLAG_NO_TTL,
|
||||
0, 24, 0, 0, 0, 8, mctx);
|
||||
check_result(result, "dns_master_stylecreate");
|
||||
|
||||
|
||||
|
||||
gdb = NULL;
|
||||
TIME_NOW(&timer_start);
|
||||
@@ -2126,8 +2125,8 @@ main(int argc, char *argv[]) {
|
||||
DST_TYPE_PRIVATE,
|
||||
mctx, &newkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot load dnskey %s: %s", argv[i],
|
||||
isc_result_totext(result));
|
||||
fatal("cannot load dnskey %s: %s", argv[i],
|
||||
isc_result_totext(result));
|
||||
|
||||
key = ISC_LIST_HEAD(keylist);
|
||||
while (key != NULL) {
|
||||
@@ -2135,7 +2134,7 @@ main(int argc, char *argv[]) {
|
||||
if (dst_key_id(dkey) == dst_key_id(newkey) &&
|
||||
dst_key_alg(dkey) == dst_key_alg(newkey) &&
|
||||
dns_name_equal(dst_key_name(dkey),
|
||||
dst_key_name(newkey)))
|
||||
dst_key_name(newkey)))
|
||||
{
|
||||
if (!dst_key_isprivate(dkey))
|
||||
fatal("cannot sign zone with "
|
||||
@@ -2164,7 +2163,7 @@ main(int argc, char *argv[]) {
|
||||
mctx, &newkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot load dnskey %s: %s", dskeyfile[i],
|
||||
isc_result_totext(result));
|
||||
isc_result_totext(result));
|
||||
|
||||
key = ISC_LIST_HEAD(keylist);
|
||||
while (key != NULL) {
|
||||
@@ -2172,7 +2171,7 @@ main(int argc, char *argv[]) {
|
||||
if (dst_key_id(dkey) == dst_key_id(newkey) &&
|
||||
dst_key_alg(dkey) == dst_key_alg(newkey) &&
|
||||
dns_name_equal(dst_key_name(dkey),
|
||||
dst_key_name(newkey)))
|
||||
dst_key_name(newkey)))
|
||||
{
|
||||
/* Override key flags. */
|
||||
key->issigningkey = ISC_TRUE;
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.100 2008/03/31 05:00:29 marka Exp $
|
||||
# $Id: Makefile.in,v 1.96.130.4 2008/03/31 05:06:47 marka Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: bind9.xsl,v 1.17 2008/04/09 22:48:17 jinmei Exp $ -->
|
||||
<!-- $Id: bind9.xsl,v 1.13.130.4 2008/04/09 22:49:37 jinmei Exp $ -->
|
||||
|
||||
<xsl:stylesheet version="1.0"
|
||||
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* Generated by convertxsl.pl 1.13 2008/04/03 10:52:46 marka Exp
|
||||
* From bind9.xsl 1.17 2008/04/09 22:48:17 jinmei Exp
|
||||
* Generated by convertxsl.pl 1.9.60.4 2008/04/03 10:51:01 marka Exp
|
||||
* From bind9.xsl 1.13.130.4 2008/04/09 22:49:37 jinmei Exp
|
||||
*/
|
||||
static char xslmsg[] =
|
||||
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n"
|
||||
@@ -20,7 +20,7 @@ static char xslmsg[] =
|
||||
" - PERFORMANCE OF THIS SOFTWARE.\n"
|
||||
"-->\n"
|
||||
"\n"
|
||||
"<!-- \045Id: bind9.xsl,v 1.17 2008/04/09 22:48:17 jinmei Exp \045 -->\n"
|
||||
"<!-- \045Id: bind9.xsl,v 1.13.130.4 2008/04/09 22:49:37 jinmei Exp \045 -->\n"
|
||||
"\n"
|
||||
"<xsl:stylesheet version=\"1.0\"\n"
|
||||
" xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\"\n"
|
||||
|
||||
+5
-32
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: client.c,v 1.257 2008/04/03 06:09:04 tbox Exp $ */
|
||||
/* $Id: client.c,v 1.250.16.6 2008/05/27 22:36:09 each Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -465,8 +465,6 @@ exit_check(ns_client_t *client) {
|
||||
|
||||
if (client->state == client->newstate) {
|
||||
client->newstate = NS_CLIENTSTATE_MAX;
|
||||
if (client->needshutdown)
|
||||
isc_task_shutdown(client->task);
|
||||
goto unlock;
|
||||
}
|
||||
}
|
||||
@@ -523,14 +521,6 @@ exit_check(ns_client_t *client) {
|
||||
|
||||
CTRACE("free");
|
||||
client->magic = 0;
|
||||
/*
|
||||
* Check that there are no other external references to
|
||||
* the memory context.
|
||||
*/
|
||||
if (ns_g_clienttest && isc_mem_references(client->mctx) != 1) {
|
||||
isc_mem_stats(client->mctx, stderr);
|
||||
INSIST(0);
|
||||
}
|
||||
isc_mem_putanddetach(&client->mctx, client, sizeof(*client));
|
||||
|
||||
goto unlock;
|
||||
@@ -604,7 +594,6 @@ client_shutdown(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
|
||||
client->newstate = NS_CLIENTSTATE_FREED;
|
||||
client->needshutdown = ISC_FALSE;
|
||||
(void)exit_check(client);
|
||||
}
|
||||
|
||||
@@ -657,7 +646,7 @@ ns_client_checkactive(ns_client_t *client) {
|
||||
* keep it active to make up for the shortage.
|
||||
*/
|
||||
isc_boolean_t need_another_client = ISC_FALSE;
|
||||
if (TCP_CLIENT(client) && !ns_g_clienttest) {
|
||||
if (TCP_CLIENT(client)) {
|
||||
LOCK(&client->interface->lock);
|
||||
if (client->interface->ntcpcurrent <
|
||||
client->interface->ntcptarget)
|
||||
@@ -1524,14 +1513,6 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
dns_generalstats_increment(ns_g_server->nsstats,
|
||||
dns_nsstatscounter_tcp);
|
||||
|
||||
/*
|
||||
* Hash the incoming request here as it is after
|
||||
* dns_dispatch_importrecv().
|
||||
*/
|
||||
dns_dispatch_hash(&client->now, sizeof(client->now));
|
||||
dns_dispatch_hash(isc_buffer_base(buffer),
|
||||
isc_buffer_usedlength(buffer));
|
||||
|
||||
/*
|
||||
* It's a request. Parse it.
|
||||
*/
|
||||
@@ -1960,17 +1941,13 @@ client_timeout(isc_task_t *task, isc_event_t *event) {
|
||||
static isc_result_t
|
||||
get_clientmctx(ns_clientmgr_t *manager, isc_mem_t **mctxp) {
|
||||
isc_mem_t *clientmctx;
|
||||
#if NMCTXS > 0
|
||||
isc_result_t result;
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Caller must be holding the manager lock.
|
||||
*/
|
||||
if (ns_g_clienttest) {
|
||||
result = isc_mem_create(0, 0, mctxp);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
isc_mem_setname(*mctxp, "client", NULL);
|
||||
return (result);
|
||||
}
|
||||
#if NMCTXS > 0
|
||||
INSIST(manager->nextmctx < NMCTXS);
|
||||
clientmctx = manager->mctxpool[manager->nextmctx];
|
||||
@@ -2127,8 +2104,6 @@ client_create(ns_clientmgr_t *manager, ns_client_t **clientp) {
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup_query;
|
||||
|
||||
client->needshutdown = ns_g_clienttest;
|
||||
|
||||
CTRACE("create");
|
||||
|
||||
*clientp = client;
|
||||
@@ -2550,9 +2525,7 @@ ns_clientmgr_createclients(ns_clientmgr_t *manager, unsigned int n,
|
||||
* Allocate a client. First try to get a recycled one;
|
||||
* if that fails, make a new one.
|
||||
*/
|
||||
client = NULL;
|
||||
if (!ns_g_clienttest)
|
||||
client = ISC_LIST_HEAD(manager->inactive);
|
||||
client = ISC_LIST_HEAD(manager->inactive);
|
||||
if (client != NULL) {
|
||||
MTRACE("recycle");
|
||||
ISC_LIST_UNLINK(manager->inactive, client, link);
|
||||
|
||||
+3
-5
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.c,v 1.88 2008/05/28 21:02:45 each Exp $ */
|
||||
/* $Id: config.c,v 1.82.38.5.2.2 2008/07/23 11:46:01 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -52,7 +52,7 @@ options {\n\
|
||||
#ifndef WIN32
|
||||
" coresize default;\n\
|
||||
datasize default;\n\
|
||||
files default;\n\
|
||||
files unlimited;\n\
|
||||
stacksize default;\n"
|
||||
#endif
|
||||
" deallocate-on-exit true;\n\
|
||||
@@ -100,6 +100,7 @@ options {\n\
|
||||
edns-udp-size 4096;\n\
|
||||
max-udp-size 4096;\n\
|
||||
request-nsid false;\n\
|
||||
reserved-sockets 512;\n\
|
||||
\n\
|
||||
/* view */\n\
|
||||
allow-notify {none;};\n\
|
||||
@@ -173,9 +174,6 @@ options {\n\
|
||||
min-refresh-time 300;\n\
|
||||
multi-master no;\n\
|
||||
sig-validity-interval 30; /* days */\n\
|
||||
sig-signing-nodes 100;\n\
|
||||
sig-signing-signatures 10;\n\
|
||||
sig-signing-type 65535;\n\
|
||||
zone-statistics false;\n\
|
||||
max-journal-size unlimited;\n\
|
||||
ixfr-from-differences false;\n\
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: controlconf.c,v 1.58 2008/01/18 23:46:57 tbox Exp $ */
|
||||
/* $Id: controlconf.c,v 1.55.64.2.12.2 2008/07/23 22:51:52 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -1149,8 +1149,8 @@ add_listener(ns_controls_t *cp, controllistener_t **listenerp,
|
||||
isc_socket_setname(listener->sock, "control", NULL);
|
||||
|
||||
if (result == ISC_R_SUCCESS)
|
||||
result = isc_socket_bind(listener->sock,
|
||||
&listener->address);
|
||||
result = isc_socket_bind(listener->sock, &listener->address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
|
||||
if (result == ISC_R_SUCCESS && type == isc_sockettype_unix) {
|
||||
listener->perm = cfg_obj_asuint32(cfg_tuple_get(control,
|
||||
|
||||
@@ -14,12 +14,12 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: convertxsl.pl,v 1.13 2008/04/03 10:52:46 marka Exp $
|
||||
# $Id: convertxsl.pl,v 1.9.60.4 2008/04/03 10:51:01 marka Exp $
|
||||
|
||||
use strict;
|
||||
use warnings;
|
||||
|
||||
my $rev = '$Id: convertxsl.pl,v 1.13 2008/04/03 10:52:46 marka Exp $';
|
||||
my $rev = '$Id: convertxsl.pl,v 1.9.60.4 2008/04/03 10:51:01 marka Exp $';
|
||||
$rev =~ s/\$//g;
|
||||
$rev =~ s/,v//g;
|
||||
$rev =~ s/Id: //;
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: client.h,v 1.86 2008/04/03 02:01:08 marka Exp $ */
|
||||
/* $Id: client.h,v 1.82.128.2 2008/04/03 06:08:26 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_CLIENT_H
|
||||
#define NAMED_CLIENT_H 1
|
||||
@@ -97,13 +97,6 @@ struct ns_client {
|
||||
int nupdates;
|
||||
int nctls;
|
||||
int references;
|
||||
isc_boolean_t needshutdown; /*
|
||||
* Used by clienttest to get
|
||||
* the client to go from
|
||||
* inactive to free state
|
||||
* by shutting down the
|
||||
* client's task.
|
||||
*/
|
||||
unsigned int attributes;
|
||||
isc_task_t * task;
|
||||
dns_view_t * view;
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: globals.h,v 1.75 2008/01/02 23:47:01 tbox Exp $ */
|
||||
/* $Id: globals.h,v 1.73 2007/09/26 03:22:43 marka Exp $ */
|
||||
|
||||
#ifndef NAMED_GLOBALS_H
|
||||
#define NAMED_GLOBALS_H 1
|
||||
@@ -115,7 +115,6 @@ EXTERN const char * ns_g_username INIT(NULL);
|
||||
EXTERN int ns_g_listen INIT(3);
|
||||
EXTERN isc_time_t ns_g_boottime;
|
||||
EXTERN isc_boolean_t ns_g_memstatistics INIT(ISC_FALSE);
|
||||
EXTERN isc_boolean_t ns_g_clienttest INIT(ISC_FALSE);
|
||||
|
||||
#undef EXTERN
|
||||
#undef INIT
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: server.h,v 1.93 2008/04/03 05:55:51 marka Exp $ */
|
||||
/* $Id: server.h,v 1.88.10.4 2008/04/03 06:10:19 marka Exp $ */
|
||||
|
||||
#ifndef NAMED_SERVER_H
|
||||
#define NAMED_SERVER_H 1
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: statschannel.h,v 1.3 2008/04/03 05:55:51 marka Exp $ */
|
||||
/* $Id: statschannel.h,v 1.2.2.2 2008/04/03 06:10:19 marka Exp $ */
|
||||
|
||||
#ifndef NAMED_STATSCHANNEL_H
|
||||
#define NAMED_STATSCHANNEL_H 1
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: types.h,v 1.29 2008/01/17 23:46:59 tbox Exp $ */
|
||||
/* $Id: types.h,v 1.27.128.2 2008/01/17 23:46:36 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_TYPES_H
|
||||
#define NAMED_TYPES_H 1
|
||||
|
||||
+23
-22
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: interfacemgr.c,v 1.90 2007/09/12 01:09:07 each Exp $ */
|
||||
/* $Id: interfacemgr.c,v 1.90.168.3 2008/07/23 22:51:52 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -90,7 +90,7 @@ ns_interfacemgr_create(isc_mem_t *mctx, isc_taskmgr_t *taskmgr,
|
||||
mgr->generation = 1;
|
||||
mgr->listenon4 = NULL;
|
||||
mgr->listenon6 = NULL;
|
||||
|
||||
|
||||
ISC_LIST_INIT(mgr->interfaces);
|
||||
ISC_LIST_INIT(mgr->listenon);
|
||||
|
||||
@@ -308,7 +308,8 @@ ns_interface_accepttcp(ns_interface_t *ifp) {
|
||||
#ifndef ISC_ALLOW_MAPPED
|
||||
isc_socket_ipv6only(ifp->tcpsocket, ISC_TRUE);
|
||||
#endif
|
||||
result = isc_socket_bind(ifp->tcpsocket, &ifp->addr);
|
||||
result = isc_socket_bind(ifp->tcpsocket, &ifp->addr,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_log_write(IFMGR_COMMON_LOGARGS, ISC_LOG_ERROR,
|
||||
"binding TCP socket: %s",
|
||||
@@ -323,7 +324,7 @@ ns_interface_accepttcp(ns_interface_t *ifp) {
|
||||
goto tcp_listen_failure;
|
||||
}
|
||||
|
||||
/*
|
||||
/*
|
||||
* If/when there a multiple filters listen to the
|
||||
* result.
|
||||
*/
|
||||
@@ -494,26 +495,26 @@ clearacl(isc_mem_t *mctx, dns_acl_t **aclp) {
|
||||
|
||||
static isc_boolean_t
|
||||
listenon_is_ip6_any(ns_listenelt_t *elt) {
|
||||
REQUIRE(elt && elt->acl);
|
||||
return dns_acl_isany(elt->acl);
|
||||
REQUIRE(elt && elt->acl);
|
||||
return dns_acl_isany(elt->acl);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
setup_locals(ns_interfacemgr_t *mgr, isc_interface_t *interface) {
|
||||
isc_result_t result;
|
||||
unsigned int prefixlen;
|
||||
isc_netaddr_t *netaddr;
|
||||
isc_netaddr_t *netaddr;
|
||||
|
||||
netaddr = &interface->address;
|
||||
|
||||
/* First add localhost address */
|
||||
netaddr = &interface->address;
|
||||
|
||||
/* First add localhost address */
|
||||
prefixlen = (netaddr->family == AF_INET) ? 32 : 128;
|
||||
result = dns_iptable_addprefix(mgr->aclenv.localhost->iptable,
|
||||
netaddr, prefixlen, ISC_TRUE);
|
||||
result = dns_iptable_addprefix(mgr->aclenv.localhost->iptable,
|
||||
netaddr, prefixlen, ISC_TRUE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
/* Then add localnets prefix */
|
||||
/* Then add localnets prefix */
|
||||
result = isc_netaddr_masktoprefixlen(&interface->netmask,
|
||||
&prefixlen);
|
||||
|
||||
@@ -528,11 +529,11 @@ setup_locals(ns_interfacemgr_t *mgr, isc_interface_t *interface) {
|
||||
"localnets ACL: %s",
|
||||
interface->name,
|
||||
isc_result_totext(result));
|
||||
return (ISC_R_SUCCESS);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
result = dns_iptable_addprefix(mgr->aclenv.localnets->iptable,
|
||||
netaddr, prefixlen, ISC_TRUE);
|
||||
result = dns_iptable_addprefix(mgr->aclenv.localnets->iptable,
|
||||
netaddr, prefixlen, ISC_TRUE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
@@ -542,7 +543,7 @@ setup_locals(ns_interfacemgr_t *mgr, isc_interface_t *interface) {
|
||||
static void
|
||||
setup_listenon(ns_interfacemgr_t *mgr, isc_interface_t *interface,
|
||||
in_port_t port)
|
||||
{
|
||||
{
|
||||
isc_sockaddr_t *addr;
|
||||
isc_sockaddr_t *old;
|
||||
|
||||
@@ -556,7 +557,7 @@ setup_listenon(ns_interfacemgr_t *mgr, isc_interface_t *interface,
|
||||
old != NULL;
|
||||
old = ISC_LIST_NEXT(old, link))
|
||||
if (isc_sockaddr_equal(addr, old))
|
||||
break;
|
||||
break;
|
||||
|
||||
if (old != NULL)
|
||||
isc_mem_put(mgr->mctx, addr, sizeof(*addr));
|
||||
@@ -692,7 +693,7 @@ do_scan(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
{
|
||||
isc_interface_t interface;
|
||||
ns_listenlist_t *ll;
|
||||
unsigned int family;
|
||||
unsigned int family;
|
||||
|
||||
result = isc_interfaceiter_current(iter, &interface);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
@@ -876,7 +877,7 @@ do_scan(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
||||
"interface iteration failed: %s",
|
||||
isc_result_totext(result));
|
||||
else
|
||||
else
|
||||
result = ISC_R_SUCCESS;
|
||||
cleanup_iter:
|
||||
isc_interfaceiter_destroy(&iter);
|
||||
@@ -907,7 +908,7 @@ ns_interfacemgr_scan0(ns_interfacemgr_t *mgr, ns_listenlist_t *ext_listen,
|
||||
|
||||
/*
|
||||
* Warn if we are not listening on any interface, unless
|
||||
* we're in lwresd-only mode, in which case that is to
|
||||
* we're in lwresd-only mode, in which case that is to
|
||||
* be expected.
|
||||
*/
|
||||
if (ext_listen == NULL &&
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwaddr.c,v 1.10 2008/01/11 23:46:56 tbox Exp $ */
|
||||
/* $Id: lwaddr.c,v 1.8.130.2 2008/01/11 23:46:27 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdgnba.c,v 1.22 2008/01/14 23:46:56 tbox Exp $ */
|
||||
/* $Id: lwdgnba.c,v 1.20.130.2 2008/01/14 23:46:28 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwdnoop.c,v 1.13 2008/01/22 23:28:04 tbox Exp $ */
|
||||
/* $Id: lwdnoop.c,v 1.11.130.2 2008/01/22 23:27:35 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+6
-5
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,9 +15,9 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwresd.c,v 1.55 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: lwresd.c,v 1.55.234.3 2008/07/23 22:51:52 marka Exp $ */
|
||||
|
||||
/*! \file
|
||||
/*! \file
|
||||
* \brief
|
||||
* Main program for the Lightweight Resolver Daemon.
|
||||
*
|
||||
@@ -224,7 +224,7 @@ ns_lwresd_parseeresolvconf(isc_mem_t *mctx, cfg_parser_t *pctx,
|
||||
for (i = 0; i < lwc->searchnxt; i++) {
|
||||
CHECK(buffer_putstr(&b, "\t\t\""));
|
||||
CHECK(buffer_putstr(&b, lwc->search[i]));
|
||||
CHECK(buffer_putstr(&b, "\";\n"));
|
||||
CHECK(buffer_putstr(&b, "\";\n"));
|
||||
}
|
||||
CHECK(buffer_putstr(&b, "\t};\n"));
|
||||
}
|
||||
@@ -576,7 +576,8 @@ listener_bind(ns_lwreslistener_t *listener, isc_sockaddr_t *address) {
|
||||
return (result);
|
||||
}
|
||||
|
||||
result = isc_socket_bind(sock, &listener->address);
|
||||
result = isc_socket_bind(sock, &listener->address,
|
||||
ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_format(&listener->address, socktext,
|
||||
|
||||
+2
-13
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: main.c,v 1.162 2008/04/03 23:14:52 jinmei Exp $ */
|
||||
/* $Id: main.c,v 1.158.48.2 2008/04/03 23:46:30 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -356,7 +356,7 @@ parse_command_line(int argc, char *argv[]) {
|
||||
|
||||
isc_commandline_errprint = ISC_FALSE;
|
||||
while ((ch = isc_commandline_parse(argc, argv,
|
||||
"46c:C:d:fgi:lm:n:N:p:P:st:T:u:vx:")) != -1) {
|
||||
"46c:C:d:fgi:lm:n:N:p:P:st:u:vx:")) != -1) {
|
||||
switch (ch) {
|
||||
case '4':
|
||||
if (disable4)
|
||||
@@ -439,17 +439,6 @@ parse_command_line(int argc, char *argv[]) {
|
||||
/* XXXJAB should we make a copy? */
|
||||
ns_g_chrootdir = isc_commandline_argument;
|
||||
break;
|
||||
case 'T':
|
||||
/*
|
||||
* clienttest: make clients single shot with their
|
||||
* own memory context.
|
||||
*/
|
||||
if (strcmp(isc_commandline_argument, "clienttest") == 0)
|
||||
ns_g_clienttest = ISC_TRUE;
|
||||
else
|
||||
fprintf(stderr, "unknown -T flag '%s\n",
|
||||
isc_commandline_argument);
|
||||
break;
|
||||
case 'u':
|
||||
ns_g_username = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
+4
-10
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named.conf.5,v 1.34 2008/04/03 01:09:59 tbox Exp $
|
||||
.\" $Id: named.conf.5,v 1.31 2007/10/21 22:15:32 marka Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -283,10 +283,6 @@ options {
|
||||
min\-refresh\-time \fIinteger\fR;
|
||||
multi\-master \fIboolean\fR;
|
||||
sig\-validity\-interval \fIinteger\fR;
|
||||
sig\-re\-signing\-interval \fIinteger\fR;
|
||||
sig\-signing\-nodes \fIinteger\fR;
|
||||
sig\-signing\-signatures \fIinteger\fR;
|
||||
sig\-signing\-type \fIinteger\fR;
|
||||
transfer\-source ( \fIipv4_address\fR | * )
|
||||
[ port ( \fIinteger\fR | * ) ];
|
||||
transfer\-source\-v6 ( \fIipv6_address\fR | * )
|
||||
@@ -481,9 +477,7 @@ zone \fIstring\fR \fIoptional_class\fR {
|
||||
allow\-update\-forwarding { \fIaddress_match_element\fR; ... };
|
||||
update\-policy {
|
||||
( grant | deny ) \fIstring\fR
|
||||
( name | subdomain | wildcard | self | selfsub | selfwild |
|
||||
krb5\-self | ms\-self | krb5\-subdomain | ms\-subdomain |
|
||||
tcp\-self | 6to4\-self ) \fIstring\fR
|
||||
( name | subdomain | wildcard | self ) \fIstring\fR
|
||||
\fIrrtypelist\fR; ...
|
||||
};
|
||||
update\-check\-ksk \fIboolean\fR;
|
||||
@@ -541,5 +535,5 @@ zone \fIstring\fR \fIoptional_class\fR {
|
||||
\fBrndc\fR(8),
|
||||
BIND 9 Administrator Reference Manual.
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004\-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named.conf.docbook,v 1.37 2008/04/02 02:37:41 marka Exp $ -->
|
||||
<!-- $Id: named.conf.docbook,v 1.34.50.2 2008/07/23 23:48:45 tbox Exp $ -->
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
<date>Aug 13, 2004</date>
|
||||
@@ -202,6 +202,7 @@ options {
|
||||
port <replaceable>integer</replaceable>;
|
||||
querylog <replaceable>boolean</replaceable>;
|
||||
recursing-file <replaceable>quoted_string</replaceable>;
|
||||
reserved-sockets <replaceable>integer</replaceable>;
|
||||
random-device <replaceable>quoted_string</replaceable>;
|
||||
recursive-clients <replaceable>integer</replaceable>;
|
||||
serial-query-rate <replaceable>integer</replaceable>;
|
||||
@@ -316,12 +317,7 @@ options {
|
||||
max-refresh-time <replaceable>integer</replaceable>;
|
||||
min-refresh-time <replaceable>integer</replaceable>;
|
||||
multi-master <replaceable>boolean</replaceable>;
|
||||
|
||||
sig-validity-interval <replaceable>integer</replaceable>;
|
||||
sig-re-signing-interval <replaceable>integer</replaceable>;
|
||||
sig-signing-nodes <replaceable>integer</replaceable>;
|
||||
sig-signing-signatures <replaceable>integer</replaceable>;
|
||||
sig-signing-type <replaceable>integer</replaceable>;
|
||||
|
||||
transfer-source ( <replaceable>ipv4_address</replaceable> | * )
|
||||
<optional> port ( <replaceable>integer</replaceable> | * ) </optional>;
|
||||
@@ -538,9 +534,7 @@ zone <replaceable>string</replaceable> <replaceable>optional_class</replaceable>
|
||||
allow-update-forwarding { <replaceable>address_match_element</replaceable>; ... };
|
||||
update-policy {
|
||||
( grant | deny ) <replaceable>string</replaceable>
|
||||
( name | subdomain | wildcard | self | selfsub | selfwild |
|
||||
krb5-self | ms-self | krb5-subdomain | ms-subdomain |
|
||||
tcp-self | 6to4-self ) <replaceable>string</replaceable>
|
||||
( name | subdomain | wildcard | self ) <replaceable>string</replaceable>
|
||||
<replaceable>rrtypelist</replaceable>; ...
|
||||
};
|
||||
update-check-ksk <replaceable>boolean</replaceable>;
|
||||
|
||||
+17
-24
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named.conf.html,v 1.43 2008/04/03 01:09:59 tbox Exp $ -->
|
||||
<!-- $Id: named.conf.html,v 1.40 2007/10/21 22:15:32 marka Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -31,7 +31,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">named.conf</code> </p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543342"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2542042"></a><h2>DESCRIPTION</h2>
|
||||
<p><code class="filename">named.conf</code> is the configuration file
|
||||
for
|
||||
<span><strong class="command">named</strong></span>. Statements are enclosed
|
||||
@@ -50,14 +50,14 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543370"></a><h2>ACL</h2>
|
||||
<a name="id2543367"></a><h2>ACL</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
acl <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
<br>
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543386"></a><h2>KEY</h2>
|
||||
<a name="id2543383"></a><h2>KEY</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
key <em class="replaceable"><code>domain_name</code></em> {<br>
|
||||
algorithm <em class="replaceable"><code>string</code></em>;<br>
|
||||
@@ -66,7 +66,7 @@ key
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543405"></a><h2>MASTERS</h2>
|
||||
<a name="id2543402"></a><h2>MASTERS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
masters <em class="replaceable"><code>string</code></em> [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
|
||||
( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<span class="optional">port <em class="replaceable"><code>integer</code></em></span>] |<br>
|
||||
@@ -75,7 +75,7 @@ masters
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543451"></a><h2>SERVER</h2>
|
||||
<a name="id2543448"></a><h2>SERVER</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
server ( <em class="replaceable"><code>ipv4_address[<span class="optional">/prefixlen</span>]</code></em> | <em class="replaceable"><code>ipv6_address[<span class="optional">/prefixlen</span>]</code></em> ) {<br>
|
||||
bogus <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -97,7 +97,7 @@ server
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543520"></a><h2>TRUSTED-KEYS</h2>
|
||||
<a name="id2543516"></a><h2>TRUSTED-KEYS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
trusted-keys {<br>
|
||||
<em class="replaceable"><code>domain_name</code></em> <em class="replaceable"><code>flags</code></em> <em class="replaceable"><code>protocol</code></em> <em class="replaceable"><code>algorithm</code></em> <em class="replaceable"><code>key</code></em>; ... <br>
|
||||
@@ -105,7 +105,7 @@ trusted-keys
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543545"></a><h2>CONTROLS</h2>
|
||||
<a name="id2543542"></a><h2>CONTROLS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
controls {<br>
|
||||
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> | * )<br>
|
||||
@@ -117,7 +117,7 @@ controls
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543580"></a><h2>LOGGING</h2>
|
||||
<a name="id2543577"></a><h2>LOGGING</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
logging {<br>
|
||||
channel <em class="replaceable"><code>string</code></em> {<br>
|
||||
@@ -135,7 +135,7 @@ logging
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543619"></a><h2>LWRES</h2>
|
||||
<a name="id2543616"></a><h2>LWRES</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
lwres {<br>
|
||||
listen-on [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
|
||||
@@ -148,7 +148,7 @@ lwres
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543660"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543657"></a><h2>OPTIONS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
options {<br>
|
||||
avoid-v4-udp-ports { <em class="replaceable"><code>port</code></em>; ... };<br>
|
||||
@@ -286,12 +286,7 @@ options
|
||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
<br>
|
||||
sig-validity-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-re-signing-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
||||
<br>
|
||||
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * )<br>
|
||||
[<span class="optional"> port ( <em class="replaceable"><code>integer</code></em> | * ) </span>];<br>
|
||||
@@ -326,7 +321,7 @@ options
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544444"></a><h2>VIEW</h2>
|
||||
<a name="id2544428"></a><h2>VIEW</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
view <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
|
||||
match-clients { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
@@ -474,7 +469,7 @@ view
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545106"></a><h2>ZONE</h2>
|
||||
<a name="id2545090"></a><h2>ZONE</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
zone <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
|
||||
type ( master | slave | stub | hint |<br>
|
||||
@@ -506,9 +501,7 @@ zone
|
||||
allow-update-forwarding { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
update-policy {<br>
|
||||
( grant | deny ) <em class="replaceable"><code>string</code></em><br>
|
||||
( name | subdomain | wildcard | self | selfsub | selfwild |<br>
|
||||
krb5-self | ms-self | krb5-subdomain | ms-subdomain |<br>
|
||||
tcp-self | 6to4-self ) <em class="replaceable"><code>string</code></em><br>
|
||||
( name | subdomain | wildcard | self ) <em class="replaceable"><code>string</code></em><br>
|
||||
<em class="replaceable"><code>rrtypelist</code></em>; ...<br>
|
||||
};<br>
|
||||
update-check-ksk <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -564,12 +557,12 @@ zone
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545399"></a><h2>FILES</h2>
|
||||
<a name="id2545384"></a><h2>FILES</h2>
|
||||
<p><code class="filename">/etc/named.conf</code>
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545411"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2545396"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
|
||||
|
||||
+6
-25
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: query.c,v 1.307 2008/04/29 00:54:28 marka Exp $ */
|
||||
/* $Id: query.c,v 1.298.48.7 2008/04/29 00:56:50 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -1099,12 +1099,8 @@ query_addadditional(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
||||
result = dns_db_find(db, name, version, type, client->query.dboptions,
|
||||
client->now, &node, fname, rdataset,
|
||||
sigrdataset);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
if (sigrdataset != NULL && !dns_db_issecure(db) &&
|
||||
dns_rdataset_isassociated(sigrdataset))
|
||||
dns_rdataset_disassociate(sigrdataset);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
goto found;
|
||||
}
|
||||
|
||||
if (dns_rdataset_isassociated(rdataset))
|
||||
dns_rdataset_disassociate(rdataset);
|
||||
@@ -2041,7 +2037,7 @@ query_addsoa(ns_client_t *client, dns_db_t *db, dns_dbversion_t *version,
|
||||
eresult = DNS_R_SERVFAIL;
|
||||
goto cleanup;
|
||||
}
|
||||
if (WANTDNSSEC(client) && dns_db_issecure(db)) {
|
||||
if (WANTDNSSEC(client)) {
|
||||
sigrdataset = query_newrdataset(client);
|
||||
if (sigrdataset == NULL) {
|
||||
eresult = DNS_R_SERVFAIL;
|
||||
@@ -2159,7 +2155,7 @@ query_addns(ns_client_t *client, dns_db_t *db, dns_dbversion_t *version) {
|
||||
eresult = DNS_R_SERVFAIL;
|
||||
goto cleanup;
|
||||
}
|
||||
if (WANTDNSSEC(client) && dns_db_issecure(db)) {
|
||||
if (WANTDNSSEC(client)) {
|
||||
sigrdataset = query_newrdataset(client);
|
||||
if (sigrdataset == NULL) {
|
||||
CTRACE("query_addns: query_newrdataset failed");
|
||||
@@ -3566,7 +3562,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
QUERY_ERROR(DNS_R_SERVFAIL);
|
||||
goto cleanup;
|
||||
}
|
||||
if (WANTDNSSEC(client) && (!is_zone || dns_db_issecure(db))) {
|
||||
if (WANTDNSSEC(client)) {
|
||||
sigrdataset = query_newrdataset(client);
|
||||
if (sigrdataset == NULL) {
|
||||
QUERY_ERROR(DNS_R_SERVFAIL);
|
||||
@@ -4207,16 +4203,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
result = dns_rdatasetiter_first(rdsiter);
|
||||
while (result == ISC_R_SUCCESS) {
|
||||
dns_rdatasetiter_current(rdsiter, rdataset);
|
||||
if (is_zone && qtype == dns_rdatatype_any &&
|
||||
!dns_db_issecure(db) &&
|
||||
dns_rdatatype_isdnssec(rdataset->type)) {
|
||||
/*
|
||||
* The zone is transitioning from insecure
|
||||
* to secure. Hide the dnssec records from
|
||||
* ANY queries.
|
||||
*/
|
||||
dns_rdataset_disassociate(rdataset);
|
||||
} else if ((qtype == dns_rdatatype_any ||
|
||||
if ((qtype == dns_rdatatype_any ||
|
||||
rdataset->type == qtype) && rdataset->type != 0) {
|
||||
query_addrrset(client,
|
||||
fname != NULL ? &fname : &tname,
|
||||
@@ -4490,12 +4477,6 @@ ns_query_start(ns_client_t *client) {
|
||||
|
||||
CTRACE("ns_query_start");
|
||||
|
||||
/*
|
||||
* Test only.
|
||||
*/
|
||||
if (ns_g_clienttest && (client->attributes & NS_CLIENTATTR_TCP) == 0)
|
||||
RUNTIME_CHECK(ns_client_replace(client) == ISC_R_SUCCESS);
|
||||
|
||||
/*
|
||||
* Ensure that appropriate cleanups occur.
|
||||
*/
|
||||
|
||||
+74
-104
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: server.c,v 1.508 2008/05/21 23:47:00 tbox Exp $ */
|
||||
/* $Id: server.c,v 1.495.10.11.2.2 2008/07/23 23:48:45 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -596,6 +596,14 @@ get_view_querysource_dispatch(const cfg_obj_t **maps,
|
||||
attrs |= DNS_DISPATCHATTR_IPV6;
|
||||
break;
|
||||
}
|
||||
|
||||
if (isc_sockaddr_getport(&sa) != 0) {
|
||||
INSIST(obj != NULL);
|
||||
cfg_obj_log(obj, ns_g_lctx, ISC_LOG_INFO,
|
||||
"using specific query-source port suppresses port "
|
||||
"randomization and can be insecure.");
|
||||
}
|
||||
|
||||
attrmask = 0;
|
||||
attrmask |= DNS_DISPATCHATTR_UDP;
|
||||
attrmask |= DNS_DISPATCHATTR_TCP;
|
||||
@@ -605,7 +613,7 @@ get_view_querysource_dispatch(const cfg_obj_t **maps,
|
||||
disp = NULL;
|
||||
result = dns_dispatch_getudp(ns_g_dispatchmgr, ns_g_socketmgr,
|
||||
ns_g_taskmgr, &sa, 4096,
|
||||
1000, 32768, 16411, 16433,
|
||||
1024, 32768, 16411, 16433,
|
||||
attrs, attrmask, &disp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_sockaddr_t any;
|
||||
@@ -1015,7 +1023,6 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
isc_boolean_t rfc1918;
|
||||
isc_boolean_t empty_zones_enable;
|
||||
const cfg_obj_t *disablelist = NULL;
|
||||
isc_uint32_t nqports, qports_updateinterval;
|
||||
dns_stats_t *resstats = NULL;
|
||||
dns_stats_t *resquerystats = NULL;
|
||||
|
||||
@@ -1330,53 +1337,6 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
resopts, ns_g_dispatchmgr,
|
||||
dispatch4, dispatch6));
|
||||
|
||||
/*
|
||||
* Query-port pool parameters.
|
||||
*/
|
||||
obj = NULL;
|
||||
nqports = 8;
|
||||
result = ns_config_get(maps, "queryport-pool-ports", &obj);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
if ((resopts & (DNS_RESOLVER_USEDISPATCHPOOL4 |
|
||||
DNS_RESOLVER_USEDISPATCHPOOL6)) == 0) {
|
||||
cfg_obj_log(obj, ns_g_lctx, ISC_LOG_ERROR,
|
||||
"queryport-pool-ports is effective only "
|
||||
"with 'use-queryport-pool yes' (ignored)");
|
||||
} else
|
||||
nqports = cfg_obj_asuint32(obj);
|
||||
}
|
||||
|
||||
obj = NULL;
|
||||
qports_updateinterval = 15;
|
||||
result = ns_config_get(maps, "queryport-pool-updateinterval", &obj);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
if ((resopts & (DNS_RESOLVER_USEDISPATCHPOOL4 |
|
||||
DNS_RESOLVER_USEDISPATCHPOOL6)) == 0) {
|
||||
cfg_obj_log(obj, ns_g_lctx, ISC_LOG_ERROR,
|
||||
"queryport-pool-updateinterval is "
|
||||
"effective only with 'use-queryport-pool "
|
||||
"yes' (ignored)");
|
||||
} else
|
||||
qports_updateinterval = cfg_obj_asuint32(obj);
|
||||
}
|
||||
|
||||
if ((resopts & (DNS_RESOLVER_USEDISPATCHPOOL4 |
|
||||
DNS_RESOLVER_USEDISPATCHPOOL6)) != 0) {
|
||||
CHECK(dns_resolver_createdispatchpool(view->resolver,
|
||||
nqports,
|
||||
qports_updateinterval
|
||||
* 60));
|
||||
}
|
||||
|
||||
if (resstats == NULL) {
|
||||
CHECK(dns_generalstats_create(mctx, &resstats,
|
||||
dns_resstatscounter_max));
|
||||
}
|
||||
dns_view_setresstats(view, resstats);
|
||||
if (resquerystats == NULL)
|
||||
CHECK(dns_rdatatypestats_create(mctx, &resquerystats));
|
||||
dns_view_setresquerystats(view, resquerystats);
|
||||
|
||||
/*
|
||||
* Set the ADB cache size to 1/8th of the max-cache-size.
|
||||
*/
|
||||
@@ -1684,28 +1644,6 @@ configure_view(dns_view_t *view, const cfg_obj_t *config,
|
||||
CHECK(configure_view_sortlist(vconfig, config, actx, ns_g_mctx,
|
||||
&view->sortlist));
|
||||
|
||||
/*
|
||||
* Configure default allow-transfer, allow-notify, allow-update
|
||||
* and allow-update-forwarding ACLs, if set, so they can be
|
||||
* inherited by zones.
|
||||
*/
|
||||
if (view->notifyacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
"allow-notify", actx,
|
||||
ns_g_mctx, &view->notifyacl));
|
||||
if (view->transferacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
"allow-transfer", actx,
|
||||
ns_g_mctx, &view->transferacl));
|
||||
if (view->updateacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
"allow-update", actx,
|
||||
ns_g_mctx, &view->updateacl));
|
||||
if (view->upfwdacl == NULL)
|
||||
CHECK(configure_view_acl(NULL, ns_g_config,
|
||||
"allow-update-forwarding", actx,
|
||||
ns_g_mctx, &view->upfwdacl));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "request-ixfr", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -2674,8 +2612,6 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) {
|
||||
view != NULL;
|
||||
view = ISC_LIST_NEXT(view, link)) {
|
||||
dns_dispatch_t *dispatch6;
|
||||
isc_boolean_t use_portpool = ISC_FALSE;
|
||||
unsigned int resopts;
|
||||
|
||||
dispatch6 = dns_resolver_dispatchv6(view->resolver);
|
||||
if (dispatch6 == NULL)
|
||||
@@ -2683,19 +2619,16 @@ adjust_interfaces(ns_server_t *server, isc_mem_t *mctx) {
|
||||
result = dns_dispatch_getlocaladdress(dispatch6, &addr);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
resopts = dns_resolver_getoptions(view->resolver);
|
||||
if ((resopts & (DNS_RESOLVER_USEDISPATCHPOOL4 |
|
||||
DNS_RESOLVER_USEDISPATCHPOOL6)) != 0) {
|
||||
/*
|
||||
* If the resolver uses a dynamic pool of query ports
|
||||
* with a specific source address, some of the current
|
||||
* and future ports may override an existing wildcard
|
||||
* IPv6 port. So we need to allow wildcard match
|
||||
* in this case.
|
||||
*/
|
||||
use_portpool = ISC_TRUE;
|
||||
}
|
||||
result = add_listenelt(mctx, list, &addr, use_portpool);
|
||||
|
||||
/*
|
||||
* We always add non-wildcard address regardless of whether
|
||||
* the port is 'any' (the fourth arg is TRUE): if the port is
|
||||
* specific, we need to add it since it may conflict with a
|
||||
* listening interface; if it's zero, we'll dynamically open
|
||||
* query ports, and some of them may override an existing
|
||||
* wildcard IPv6 port.
|
||||
*/
|
||||
result = add_listenelt(mctx, list, &addr, ISC_TRUE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto fail;
|
||||
}
|
||||
@@ -2933,27 +2866,29 @@ static isc_result_t
|
||||
load_configuration(const char *filename, ns_server_t *server,
|
||||
isc_boolean_t first_time)
|
||||
{
|
||||
isc_result_t result;
|
||||
isc_interval_t interval;
|
||||
cfg_parser_t *parser = NULL;
|
||||
cfg_aclconfctx_t aclconfctx;
|
||||
cfg_obj_t *config;
|
||||
const cfg_obj_t *options;
|
||||
const cfg_obj_t *views;
|
||||
const cfg_obj_t *obj;
|
||||
const cfg_obj_t *v4ports, *v6ports;
|
||||
const cfg_obj_t *maps[3];
|
||||
const cfg_obj_t *builtin_views;
|
||||
cfg_parser_t *parser = NULL;
|
||||
const cfg_listelt_t *element;
|
||||
const cfg_obj_t *builtin_views;
|
||||
const cfg_obj_t *maps[3];
|
||||
const cfg_obj_t *obj;
|
||||
const cfg_obj_t *options;
|
||||
const cfg_obj_t *v4ports, *v6ports;
|
||||
const cfg_obj_t *views;
|
||||
dns_view_t *view = NULL;
|
||||
dns_view_t *view_next;
|
||||
dns_viewlist_t viewlist;
|
||||
dns_viewlist_t tmpviewlist;
|
||||
cfg_aclconfctx_t aclconfctx;
|
||||
isc_uint32_t interface_interval;
|
||||
isc_uint32_t heartbeat_interval;
|
||||
isc_uint32_t udpsize;
|
||||
dns_viewlist_t viewlist;
|
||||
in_port_t listen_port;
|
||||
int i;
|
||||
isc_interval_t interval;
|
||||
isc_resourcevalue_t files;
|
||||
isc_result_t result;
|
||||
isc_uint32_t heartbeat_interval;
|
||||
isc_uint32_t interface_interval;
|
||||
isc_uint32_t reserved;
|
||||
isc_uint32_t udpsize;
|
||||
|
||||
cfg_aclconfctx_init(&aclconfctx);
|
||||
ISC_LIST_INIT(viewlist);
|
||||
@@ -3042,6 +2977,43 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||
*/
|
||||
set_limits(maps);
|
||||
|
||||
/*
|
||||
* Sanity check on "files" limit.
|
||||
*/
|
||||
result = isc_resource_curlimit(isc_resource_openfiles, &files);
|
||||
if (result == ISC_R_SUCCESS && files < FD_SETSIZE) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"the 'files' limit (%" ISC_PRINT_QUADFORMAT "u) "
|
||||
"is less than FD_SETSIZE (%d), increase "
|
||||
"'files' in named.conf or recompile with a "
|
||||
"smaller FD_SETSIZE.", files, FD_SETSIZE);
|
||||
if (files > FD_SETSIZE)
|
||||
files = FD_SETSIZE;
|
||||
} else
|
||||
files = FD_SETSIZE;
|
||||
|
||||
/*
|
||||
* Set the number of socket reserved for TCP, stdio etc.
|
||||
*/
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "reserved-sockets", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
reserved = cfg_obj_asuint32(obj);
|
||||
if (files < 128U) /* Prevent underflow. */
|
||||
reserved = 0;
|
||||
else if (reserved > files - 128U) /* Mimimum UDP space. */
|
||||
reserved = files - 128;
|
||||
if (reserved < 128U) /* Mimimum TCP/stdio space. */
|
||||
reserved = 128;
|
||||
if (reserved + 128U > files) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"less than 128 UDP sockets available after "
|
||||
"applying 'reserved-sockets' and 'files'");
|
||||
}
|
||||
isc__socketmgr_setreserved(ns_g_socketmgr, reserved);
|
||||
|
||||
/*
|
||||
* Configure various server options.
|
||||
*/
|
||||
@@ -3188,13 +3160,11 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||
ns_g_mctx,
|
||||
&listenon);
|
||||
} else if (!ns_g_lwresdonly) {
|
||||
isc_boolean_t enable;
|
||||
/*
|
||||
* Not specified, use default.
|
||||
*/
|
||||
enable = ISC_TF(isc_net_probeipv4() != ISC_R_SUCCESS);
|
||||
CHECK(ns_listenlist_default(ns_g_mctx, listen_port,
|
||||
enable, &listenon));
|
||||
ISC_FALSE, &listenon));
|
||||
}
|
||||
if (listenon != NULL) {
|
||||
ns_interfacemgr_setlistenon6(server->interfacemgr,
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: statschannel.c,v 1.10 2008/04/09 22:53:36 tbox Exp $ */
|
||||
/* $Id: statschannel.c,v 1.2.2.9.4.2 2008/07/23 22:51:52 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -607,7 +607,7 @@ add_listener(ns_server_t *server, ns_statschannel_t **listenerp,
|
||||
isc_socket_ipv6only(sock, ISC_TRUE);
|
||||
#endif
|
||||
|
||||
result = isc_socket_bind(sock, addr);
|
||||
result = isc_socket_bind(sock, addr, ISC_SOCKET_REUSEADDRESS);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.84 2008/05/06 01:30:26 each Exp $ */
|
||||
/* $Id: os.c,v 1.79.128.5 2008/05/06 01:32:51 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+25
-345
@@ -15,13 +15,11 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: update.c,v 1.146 2008/04/03 05:55:51 marka Exp $ */
|
||||
/* $Id: update.c,v 1.138.2.4 2008/04/03 06:10:19 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/netaddr.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/serial.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/taskpool.h>
|
||||
#include <isc/util.h>
|
||||
@@ -196,11 +194,6 @@
|
||||
if (result != ISC_R_SUCCESS) goto failure; \
|
||||
} while (0)
|
||||
|
||||
/*
|
||||
* Return TRUE if NS_CLIENTATTR_TCP is set in the attibutes other FALSE.
|
||||
*/
|
||||
#define TCPCLIENT(client) (((client)->attributes & NS_CLIENTATTR_TCP) != 0)
|
||||
|
||||
/**************************************************************************/
|
||||
|
||||
typedef struct rr rr_t;
|
||||
@@ -354,7 +347,6 @@ do_one_tuple(dns_difftuple_t **tuple, dns_db_t *db, dns_dbversion_t *ver,
|
||||
* Create a singleton diff.
|
||||
*/
|
||||
dns_diff_init(diff->mctx, &temp_diff);
|
||||
temp_diff.resign = diff->resign;
|
||||
ISC_LIST_APPEND(temp_diff.tuples, *tuple, link);
|
||||
|
||||
/*
|
||||
@@ -748,22 +740,9 @@ name_exists(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||
RETURN_EXISTENCE_FLAG;
|
||||
}
|
||||
|
||||
/*
|
||||
* 'ssu_check_t' is used to pass the arguements to
|
||||
* dns_ssutable_checkrules() to the callback function
|
||||
* ssu_checkrule().
|
||||
*/
|
||||
typedef struct {
|
||||
/* The ownername of the record to be updated. */
|
||||
dns_name_t *name;
|
||||
|
||||
/* The signature's name if the request was signed. */
|
||||
dns_name_t *signer;
|
||||
|
||||
/* The address of the client if the request was received via TCP. */
|
||||
isc_netaddr_t *tcpaddr;
|
||||
|
||||
/* The ssu table to check against. */
|
||||
dns_ssutable_t *table;
|
||||
} ssu_check_t;
|
||||
|
||||
@@ -780,15 +759,13 @@ ssu_checkrule(void *data, dns_rdataset_t *rrset) {
|
||||
rrset->type == dns_rdatatype_nsec)
|
||||
return (ISC_R_SUCCESS);
|
||||
result = dns_ssutable_checkrules(ssuinfo->table, ssuinfo->signer,
|
||||
ssuinfo->name, ssuinfo->tcpaddr,
|
||||
rrset->type);
|
||||
ssuinfo->name, rrset->type);
|
||||
return (result == ISC_TRUE ? ISC_R_SUCCESS : ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
static isc_boolean_t
|
||||
ssu_checkall(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||
dns_ssutable_t *ssutable, dns_name_t *signer,
|
||||
isc_netaddr_t *tcpaddr)
|
||||
dns_ssutable_t *ssutable, dns_name_t *signer)
|
||||
{
|
||||
isc_result_t result;
|
||||
ssu_check_t ssuinfo;
|
||||
@@ -796,7 +773,6 @@ ssu_checkall(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||
ssuinfo.name = name;
|
||||
ssuinfo.table = ssutable;
|
||||
ssuinfo.signer = signer;
|
||||
ssuinfo.tcpaddr = tcpaddr;
|
||||
result = foreach_rrset(db, ver, name, ssu_checkrule, &ssuinfo);
|
||||
return (ISC_TF(result == ISC_R_SUCCESS));
|
||||
}
|
||||
@@ -1097,17 +1073,9 @@ rr_equal_p(dns_rdata_t *update_rr, dns_rdata_t *db_rr) {
|
||||
*
|
||||
* RFC2136 does not mention NSEC or DNAME, but multiple NSECs or DNAMEs
|
||||
* make little sense, so we replace those, too.
|
||||
*
|
||||
* Additionally replace RRSIG that have been generated by the same key
|
||||
* for the same type. This simplifies refreshing a offline KSK by not
|
||||
* requiring that the old RRSIG be deleted. It also simpifies key
|
||||
* rollover by only requiring that the new RRSIG be added.
|
||||
*/
|
||||
static isc_boolean_t
|
||||
replaces_p(dns_rdata_t *update_rr, dns_rdata_t *db_rr) {
|
||||
dns_rdata_rrsig_t updatesig, dbsig;
|
||||
isc_result_t result;
|
||||
|
||||
if (db_rr->type != update_rr->type)
|
||||
return (ISC_FALSE);
|
||||
if (db_rr->type == dns_rdatatype_cname)
|
||||
@@ -1118,20 +1086,6 @@ replaces_p(dns_rdata_t *update_rr, dns_rdata_t *db_rr) {
|
||||
return (ISC_TRUE);
|
||||
if (db_rr->type == dns_rdatatype_nsec)
|
||||
return (ISC_TRUE);
|
||||
if (db_rr->type == dns_rdatatype_rrsig) {
|
||||
/*
|
||||
* Replace existing RRSIG with the same keyid,
|
||||
* covered and algorithm.
|
||||
*/
|
||||
result = dns_rdata_tostruct(db_rr, &dbsig, NULL);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
result = dns_rdata_tostruct(update_rr, &updatesig, NULL);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
if (dbsig.keyid == updatesig.keyid &&
|
||||
dbsig.covered == updatesig.covered &&
|
||||
dbsig.algorithm == updatesig.algorithm)
|
||||
return (ISC_TRUE);
|
||||
}
|
||||
if (db_rr->type == dns_rdatatype_wks) {
|
||||
/*
|
||||
* Compare the address and protocol fields only. These
|
||||
@@ -1549,7 +1503,6 @@ next_active(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
dns_dbiterator_t *dbit = NULL;
|
||||
isc_boolean_t has_nsec;
|
||||
unsigned int wraps = 0;
|
||||
isc_boolean_t secure = dns_db_issecure(db);
|
||||
|
||||
CHECK(dns_db_createiterator(db, ISC_FALSE, &dbit));
|
||||
|
||||
@@ -1587,29 +1540,9 @@ next_active(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
* we must pause the iterator first.
|
||||
*/
|
||||
CHECK(dns_dbiterator_pause(dbit));
|
||||
if (secure) {
|
||||
CHECK(rrset_exists(db, ver, newname,
|
||||
dns_rdatatype_nsec, 0, &has_nsec));
|
||||
} else {
|
||||
dns_fixedname_t ffound;
|
||||
dns_name_t *found;
|
||||
dns_fixedname_init(&ffound);
|
||||
found = dns_fixedname_name(&ffound);
|
||||
result = dns_db_find(db, newname, ver,
|
||||
dns_rdatatype_soa,
|
||||
DNS_DBFIND_NOWILD, 0, NULL, found,
|
||||
NULL, NULL);
|
||||
if (result == ISC_R_SUCCESS ||
|
||||
result == DNS_R_EMPTYNAME ||
|
||||
result == DNS_R_NXRRSET ||
|
||||
result == DNS_R_CNAME ||
|
||||
(result == DNS_R_DELEGATION &&
|
||||
dns_name_equal(newname, found))) {
|
||||
has_nsec = ISC_TRUE;
|
||||
result = ISC_R_SUCCESS;
|
||||
} else if (result != DNS_R_NXDOMAIN)
|
||||
break;
|
||||
}
|
||||
CHECK(rrset_exists(db, ver, newname,
|
||||
dns_rdatatype_nsec, 0, &has_nsec));
|
||||
|
||||
} while (! has_nsec);
|
||||
failure:
|
||||
if (dbit != NULL)
|
||||
@@ -1618,35 +1551,6 @@ next_active(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
return (result);
|
||||
}
|
||||
|
||||
static isc_boolean_t
|
||||
has_opt_bit(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node) {
|
||||
isc_result_t result;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
dns_rdataset_t rdataset;
|
||||
isc_boolean_t has_bit = ISC_FALSE;
|
||||
|
||||
dns_rdataset_init(&rdataset);
|
||||
CHECK(dns_db_findrdataset(db, node, version, dns_rdatatype_nsec,
|
||||
dns_rdatatype_none, 0, &rdataset, NULL));
|
||||
CHECK(dns_rdataset_first(&rdataset));
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
has_bit = dns_nsec_typepresent(&rdata, dns_rdatatype_opt);
|
||||
failure:
|
||||
if (dns_rdataset_isassociated(&rdataset))
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
return (has_bit);
|
||||
}
|
||||
|
||||
static void
|
||||
set_bit(unsigned char *array, unsigned int index) {
|
||||
unsigned int shift, mask;
|
||||
|
||||
shift = 7 - (index % 8);
|
||||
mask = 1 << shift;
|
||||
|
||||
array[index / 8] |= mask;
|
||||
}
|
||||
|
||||
/*%
|
||||
* Add a NSEC record for "name", recording the change in "diff".
|
||||
* The existing NSEC is removed.
|
||||
@@ -1678,24 +1582,6 @@ add_nsec(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
CHECK(dns_db_findnode(db, name, ISC_FALSE, &node));
|
||||
dns_rdata_init(&rdata);
|
||||
CHECK(dns_nsec_buildrdata(db, ver, node, target, buffer, &rdata));
|
||||
/*
|
||||
* Preserve the status of the OPT bit in the origin's NSEC record.
|
||||
*/
|
||||
if (dns_name_equal(dns_db_origin(db), name) &&
|
||||
has_opt_bit(db, ver, node))
|
||||
{
|
||||
isc_region_t region;
|
||||
dns_name_t next;
|
||||
|
||||
dns_name_init(&next, NULL);
|
||||
dns_rdata_toregion(&rdata, ®ion);
|
||||
dns_name_fromregion(&next, ®ion);
|
||||
isc_region_consume(®ion, next.length);
|
||||
INSIST(region.length > (2 + dns_rdatatype_opt / 8) &&
|
||||
region.base[0] == 0 &&
|
||||
region.base[1] > dns_rdatatype_opt / 8);
|
||||
set_bit(region.base + 2, dns_rdatatype_opt);
|
||||
}
|
||||
dns_db_detachnode(db, &node);
|
||||
|
||||
/*
|
||||
@@ -1839,7 +1725,7 @@ add_sigs(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
|
||||
/* Update the database and journal with the RRSIG. */
|
||||
/* XXX inefficient - will cause dataset merging */
|
||||
CHECK(update_one_rr(db, ver, diff, DNS_DIFFOP_ADDRESIGN, name,
|
||||
CHECK(update_one_rr(db, ver, diff, DNS_DIFFOP_ADD, name,
|
||||
rdataset.ttl, &sig_rdata));
|
||||
dns_rdata_reset(&sig_rdata);
|
||||
added_sig = ISC_TRUE;
|
||||
@@ -1859,82 +1745,6 @@ add_sigs(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Delete expired RRsigs and any RRsigs we are about to re-sign.
|
||||
* See also zone.c:del_sigs().
|
||||
*/
|
||||
static isc_result_t
|
||||
del_keysigs(dns_db_t *db, dns_dbversion_t *ver, dns_name_t *name,
|
||||
dns_diff_t *diff, dst_key_t **keys, unsigned int nkeys)
|
||||
{
|
||||
isc_result_t result;
|
||||
dns_dbnode_t *node = NULL;
|
||||
dns_rdataset_t rdataset;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
unsigned int i;
|
||||
dns_rdata_rrsig_t rrsig;
|
||||
isc_boolean_t found;
|
||||
|
||||
dns_rdataset_init(&rdataset);
|
||||
|
||||
result = dns_db_findnode(db, name, ISC_FALSE, &node);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
return (ISC_R_SUCCESS);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto failure;
|
||||
result = dns_db_findrdataset(db, node, ver, dns_rdatatype_rrsig,
|
||||
dns_rdatatype_dnskey, (isc_stdtime_t) 0,
|
||||
&rdataset, NULL);
|
||||
dns_db_detachnode(db, &node);
|
||||
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
return (ISC_R_SUCCESS);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto failure;
|
||||
|
||||
for (result = dns_rdataset_first(&rdataset);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdataset_next(&rdataset)) {
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
result = dns_rdata_tostruct(&rdata, &rrsig, NULL);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
found = ISC_FALSE;
|
||||
for (i = 0; i < nkeys; i++) {
|
||||
if (rrsig.keyid == dst_key_id(keys[i])) {
|
||||
found = ISC_TRUE;
|
||||
if (!dst_key_isprivate(keys[i])) {
|
||||
/*
|
||||
* The re-signing code in zone.c
|
||||
* will mark this as offline.
|
||||
* Just skip the record for now.
|
||||
*/
|
||||
break;
|
||||
}
|
||||
result = update_one_rr(db, ver, diff,
|
||||
DNS_DIFFOP_DEL, name,
|
||||
rdataset.ttl, &rdata);
|
||||
break;
|
||||
}
|
||||
}
|
||||
/*
|
||||
* If there is not a matching DNSKEY then delete the RRSIG.
|
||||
*/
|
||||
if (!found)
|
||||
result = update_one_rr(db, ver, diff, DNS_DIFFOP_DEL,
|
||||
name, rdataset.ttl, &rdata);
|
||||
dns_rdata_reset(&rdata);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
break;
|
||||
}
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
if (result == ISC_R_NOMORE)
|
||||
result = ISC_R_SUCCESS;
|
||||
failure:
|
||||
if (node != NULL)
|
||||
dns_db_detachnode(db, &node);
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Update RRSIG and NSEC records affected by an update. The original
|
||||
* update, including the SOA serial update but exluding the RRSIG & NSEC
|
||||
@@ -1949,8 +1759,7 @@ failure:
|
||||
static isc_result_t
|
||||
update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
dns_dbversion_t *oldver, dns_dbversion_t *newver,
|
||||
dns_diff_t *diff, isc_uint32_t sigvalidityinterval,
|
||||
isc_boolean_t *deleted_zsk)
|
||||
dns_diff_t *diff, isc_uint32_t sigvalidityinterval)
|
||||
{
|
||||
isc_result_t result;
|
||||
dns_difftuple_t *t;
|
||||
@@ -1975,7 +1784,6 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
dns_diff_init(client->mctx, &affected);
|
||||
|
||||
dns_diff_init(client->mctx, &sig_diff);
|
||||
sig_diff.resign = dns_zone_getsigresigninginterval(zone);
|
||||
dns_diff_init(client->mctx, &nsec_diff);
|
||||
dns_diff_init(client->mctx, &nsec_mindiff);
|
||||
|
||||
@@ -1999,27 +1807,8 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
*/
|
||||
check_ksk = ISC_TF((dns_zone_getoptions(zone) &
|
||||
DNS_ZONEOPT_UPDATECHECKKSK) != 0);
|
||||
/*
|
||||
* If we are not checking the ZSK flag then all DNSKEY's are
|
||||
* already signing all RRsets so we don't need to trigger special
|
||||
* changes.
|
||||
*/
|
||||
if (*deleted_zsk && (!check_ksk || !ksk_sanity(db, oldver)))
|
||||
*deleted_zsk = ISC_FALSE;
|
||||
|
||||
if (check_ksk) {
|
||||
if (check_ksk)
|
||||
check_ksk = ksk_sanity(db, newver);
|
||||
if (!check_ksk && ksk_sanity(db, oldver))
|
||||
update_log(client, zone, ISC_LOG_WARNING,
|
||||
"disabling update-check-ksk");
|
||||
}
|
||||
|
||||
/*
|
||||
* If we have deleted a ZSK and we we still have some ZSK's
|
||||
* we don't need to convert the KSK's to a ZSK's.
|
||||
*/
|
||||
if (*deleted_zsk && check_ksk)
|
||||
*deleted_zsk = ISC_FALSE;
|
||||
|
||||
/*
|
||||
* Get the NSEC's TTL from the SOA MINIMUM field.
|
||||
@@ -2066,16 +1855,10 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
* Delete all old RRSIGs covering this type, since they
|
||||
* are all invalid when the signed RRset has changed.
|
||||
* We may not be able to recreate all of them - tough.
|
||||
* Special case changes to the zone's DNSKEY records
|
||||
* to support offline KSKs.
|
||||
*/
|
||||
if (type == dns_rdatatype_dnskey)
|
||||
del_keysigs(db, newver, name, &sig_diff,
|
||||
zone_keys, nkeys);
|
||||
else
|
||||
CHECK(delete_if(true_p, db, newver, name,
|
||||
dns_rdatatype_rrsig, type,
|
||||
NULL, &sig_diff));
|
||||
CHECK(delete_if(true_p, db, newver, name,
|
||||
dns_rdatatype_rrsig, type,
|
||||
NULL, &sig_diff));
|
||||
|
||||
/*
|
||||
* If this RRset still exists after the update,
|
||||
@@ -2580,52 +2363,6 @@ check_mx(ns_client_t *client, dns_zone_t *zone,
|
||||
return (ok ? ISC_R_SUCCESS : DNS_R_REFUSED);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
add_signing_records(dns_db_t *db, dns_name_t *name, dns_dbversion_t *ver,
|
||||
dns_rdatatype_t privatetype, dns_diff_t *diff)
|
||||
{
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
dns_difftuple_t *tuple, *newtuple = NULL;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
unsigned char buf[4];
|
||||
isc_region_t r;
|
||||
isc_uint16_t keyid;
|
||||
|
||||
for (tuple = ISC_LIST_HEAD(diff->tuples);
|
||||
tuple != NULL;
|
||||
tuple = ISC_LIST_NEXT(tuple, link)) {
|
||||
if (tuple->rdata.type != dns_rdatatype_dnskey ||
|
||||
tuple->op != DNS_DIFFOP_ADD)
|
||||
continue;
|
||||
|
||||
dns_rdata_tostruct(&tuple->rdata, &dnskey, NULL);
|
||||
if ((dnskey.flags &
|
||||
(DNS_KEYFLAG_OWNERMASK|DNS_KEYTYPE_NOAUTH))
|
||||
!= DNS_KEYOWNER_ZONE)
|
||||
continue;
|
||||
|
||||
dns_rdata_toregion(&tuple->rdata, &r);
|
||||
keyid = dst_region_computeid(&r, dnskey.algorithm);
|
||||
|
||||
buf[0] = dnskey.algorithm;
|
||||
buf[1] = (keyid & 0xff00) >> 8;
|
||||
buf[2] = (keyid & 0xff);
|
||||
buf[3] = 0;
|
||||
rdata.data = buf;
|
||||
rdata.length = sizeof(buf);
|
||||
rdata.type = privatetype;
|
||||
rdata.rdclass = tuple->rdata.rdclass;
|
||||
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_ADD, name,
|
||||
0, &rdata, &newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
INSIST(newtuple == NULL);
|
||||
}
|
||||
failure:
|
||||
return (result);
|
||||
}
|
||||
|
||||
static void
|
||||
update_action(isc_task_t *task, isc_event_t *event) {
|
||||
update_event_t *uev = (update_event_t *) event;
|
||||
@@ -2648,9 +2385,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
dns_fixedname_t tmpnamefixed;
|
||||
dns_name_t *tmpname = NULL;
|
||||
unsigned int options;
|
||||
isc_boolean_t deleted_zsk;
|
||||
dns_difftuple_t *tuple;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
|
||||
INSIST(event->ev_type == DNS_EVENT_UPDATE);
|
||||
|
||||
@@ -2790,7 +2524,7 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
if (ssutable == NULL)
|
||||
CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
||||
"update", zonename, ISC_FALSE, ISC_FALSE));
|
||||
else if (client->signer == NULL && !TCPCLIENT(client))
|
||||
else if (client->signer == NULL)
|
||||
CHECK(checkupdateacl(client, NULL, "update", zonename,
|
||||
ISC_FALSE, ISC_TRUE));
|
||||
|
||||
@@ -2857,39 +2591,25 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
FAILC(DNS_R_REFUSED,
|
||||
"explicit NSEC updates are not allowed "
|
||||
"in secure zones");
|
||||
} else if (rdata.type == dns_rdatatype_rrsig &&
|
||||
!dns_name_equal(name, zonename)) {
|
||||
}
|
||||
else if (rdata.type == dns_rdatatype_rrsig) {
|
||||
FAILC(DNS_R_REFUSED,
|
||||
"explicit RRSIG updates are currently "
|
||||
"not supported in secure zones except "
|
||||
"at the apex");
|
||||
"explicit RRSIG updates are currently not "
|
||||
"supported in secure zones");
|
||||
}
|
||||
}
|
||||
|
||||
if (ssutable != NULL) {
|
||||
isc_netaddr_t *tcpaddr, netaddr;
|
||||
/*
|
||||
* If this is a TCP connection then pass the
|
||||
* address of the client through for tcp-self
|
||||
* and 6to4-self otherwise pass NULL. This
|
||||
* provides weak address based authentication.
|
||||
*/
|
||||
if (TCPCLIENT(client)) {
|
||||
isc_netaddr_fromsockaddr(&netaddr,
|
||||
&client->peeraddr);
|
||||
tcpaddr = &netaddr;
|
||||
} else
|
||||
tcpaddr = NULL;
|
||||
if (ssutable != NULL && client->signer != NULL) {
|
||||
if (rdata.type != dns_rdatatype_any) {
|
||||
if (!dns_ssutable_checkrules(ssutable,
|
||||
client->signer,
|
||||
name, tcpaddr,
|
||||
rdata.type))
|
||||
name, rdata.type))
|
||||
FAILC(DNS_R_REFUSED,
|
||||
"rejected by secure update");
|
||||
} else {
|
||||
}
|
||||
else {
|
||||
if (!ssu_checkall(db, ver, name, ssutable,
|
||||
client->signer, tcpaddr))
|
||||
client->signer))
|
||||
FAILC(DNS_R_REFUSED,
|
||||
"rejected by secure update");
|
||||
}
|
||||
@@ -3138,7 +2858,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
if (! ISC_LIST_EMPTY(diff.tuples)) {
|
||||
char *journalfile;
|
||||
dns_journal_t *journal;
|
||||
isc_boolean_t has_dnskey;
|
||||
|
||||
/*
|
||||
* Increment the SOA serial, but only if it was not
|
||||
@@ -3152,19 +2871,10 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
CHECK(remove_orphaned_ds(db, ver, &diff));
|
||||
|
||||
CHECK(add_signing_records(db, zonename, ver,
|
||||
dns_zone_getprivatetype(zone),
|
||||
&diff));
|
||||
|
||||
CHECK(rrset_exists(db, ver, zonename, dns_rdatatype_dnskey,
|
||||
0, &has_dnskey));
|
||||
|
||||
if (has_dnskey && dns_db_isdnssec(db)) {
|
||||
isc_uint32_t interval;
|
||||
interval = dns_zone_getsigvalidityinterval(zone);
|
||||
if (dns_db_issecure(db)) {
|
||||
result = update_signatures(client, zone, db, oldver,
|
||||
ver, &diff, interval,
|
||||
&deleted_zsk);
|
||||
ver, &diff,
|
||||
dns_zone_getsigvalidityinterval(zone));
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
update_log(client, zone,
|
||||
ISC_LOG_ERROR,
|
||||
@@ -3201,7 +2911,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
*/
|
||||
update_log(client, zone, LOGLEVEL_DEBUG,
|
||||
"committing update transaction");
|
||||
|
||||
dns_db_closeversion(db, &ver, ISC_TRUE);
|
||||
|
||||
/*
|
||||
@@ -3213,35 +2922,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
* Notify slaves of the change we just made.
|
||||
*/
|
||||
dns_zone_notify(zone);
|
||||
|
||||
for (tuple = ISC_LIST_HEAD(diff.tuples);
|
||||
tuple != NULL;
|
||||
tuple = ISC_LIST_NEXT(tuple, link)) {
|
||||
isc_region_t r;
|
||||
dns_secalg_t algorithm;
|
||||
isc_uint16_t keyid;
|
||||
|
||||
if (tuple->rdata.type != dns_rdatatype_dnskey ||
|
||||
tuple->op != DNS_DIFFOP_ADD)
|
||||
continue;
|
||||
|
||||
dns_rdata_tostruct(&tuple->rdata, &dnskey, NULL);
|
||||
if ((dnskey.flags &
|
||||
(DNS_KEYFLAG_OWNERMASK|DNS_KEYTYPE_NOAUTH))
|
||||
!= DNS_KEYOWNER_ZONE)
|
||||
continue;
|
||||
|
||||
dns_rdata_toregion(&tuple->rdata, &r);
|
||||
algorithm = dnskey.algorithm;
|
||||
keyid = dst_region_computeid(&r, algorithm);
|
||||
|
||||
result = dns_zone_signwithkey(zone, algorithm, keyid);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
update_log(client, zone, ISC_LOG_ERROR,
|
||||
"dns_zone_signwithkey failed: %s",
|
||||
dns_result_totext(result));
|
||||
}
|
||||
}
|
||||
} else {
|
||||
update_log(client, zone, LOGLEVEL_DEBUG, "redundant request");
|
||||
dns_db_closeversion(db, &ver, ISC_TRUE);
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.28 2008/01/18 23:46:57 tbox Exp $ */
|
||||
/* $Id: os.c,v 1.25.128.3 2008/01/17 23:46:36 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdarg.h>
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: xfrout.c,v 1.128 2008/04/03 06:09:04 tbox Exp $ */
|
||||
/* $Id: xfrout.c,v 1.126.128.2 2008/04/03 06:20:33 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+26
-136
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: zoneconf.c,v 1.146 2008/05/21 23:47:00 tbox Exp $ */
|
||||
/* $Id: zoneconf.c,v 1.139.56.3 2008/05/21 23:26:11 each Exp $ */
|
||||
|
||||
/*% */
|
||||
|
||||
@@ -45,15 +45,6 @@
|
||||
#include <named/server.h>
|
||||
#include <named/zoneconf.h>
|
||||
|
||||
/* ACLs associated with zone */
|
||||
typedef enum {
|
||||
allow_notify,
|
||||
allow_query,
|
||||
allow_transfer,
|
||||
allow_update,
|
||||
allow_update_forwarding
|
||||
} acl_type_t;
|
||||
|
||||
/*%
|
||||
* These are BIND9 server defaults, not necessarily identical to the
|
||||
* library defaults defined in zone.c.
|
||||
@@ -69,69 +60,19 @@ typedef enum {
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
const cfg_obj_t *config, acl_type_t acltype,
|
||||
const cfg_obj_t *config, const char *aclname,
|
||||
cfg_aclconfctx_t *actx, dns_zone_t *zone,
|
||||
void (*setzacl)(dns_zone_t *, dns_acl_t *),
|
||||
void (*clearzacl)(dns_zone_t *))
|
||||
{
|
||||
isc_result_t result;
|
||||
const cfg_obj_t *maps[5] = {NULL, NULL, NULL, NULL, NULL};
|
||||
const cfg_obj_t *maps[5];
|
||||
const cfg_obj_t *aclobj = NULL;
|
||||
int i = 0;
|
||||
dns_acl_t **aclp = NULL, *acl = NULL;
|
||||
const char *aclname;
|
||||
dns_view_t *view;
|
||||
dns_acl_t *dacl = NULL;
|
||||
|
||||
view = dns_zone_getview(zone);
|
||||
|
||||
switch (acltype) {
|
||||
case allow_notify:
|
||||
if (view != NULL)
|
||||
aclp = &view->notifyacl;
|
||||
aclname = "allow-notify";
|
||||
break;
|
||||
case allow_query:
|
||||
if (view != NULL)
|
||||
aclp = &view->queryacl;
|
||||
aclname = "allow-query";
|
||||
break;
|
||||
case allow_transfer:
|
||||
if (view != NULL)
|
||||
aclp = &view->transferacl;
|
||||
aclname = "allow-transfer";
|
||||
break;
|
||||
case allow_update:
|
||||
if (view != NULL)
|
||||
aclp = &view->updateacl;
|
||||
aclname = "allow-update";
|
||||
break;
|
||||
case allow_update_forwarding:
|
||||
if (view != NULL)
|
||||
aclp = &view->upfwdacl;
|
||||
aclname = "allow-update-forwarding";
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
/* First check to see if ACL is defined within the zone */
|
||||
if (zconfig != NULL) {
|
||||
maps[0] = cfg_tuple_get(zconfig, "options");
|
||||
ns_config_get(maps, aclname, &aclobj);
|
||||
if (aclobj != NULL) {
|
||||
aclp = NULL;
|
||||
goto parse_acl;
|
||||
}
|
||||
}
|
||||
|
||||
/* Failing that, see if there's a default ACL already in the view */
|
||||
if (aclp != NULL && *aclp != NULL) {
|
||||
(*setzacl)(zone, *aclp);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
/* Check for default ACLs that haven't been parsed yet */
|
||||
if (zconfig != NULL)
|
||||
maps[i++] = cfg_tuple_get(zconfig, "options");
|
||||
if (vconfig != NULL)
|
||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
||||
if (config != NULL) {
|
||||
@@ -149,18 +90,12 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
parse_acl:
|
||||
result = cfg_acl_fromconfig(aclobj, config, ns_g_lctx, actx,
|
||||
dns_zone_getmctx(zone), 0, &acl);
|
||||
dns_zone_getmctx(zone), 0, &dacl);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
(*setzacl)(zone, acl);
|
||||
|
||||
/* Set the view default now */
|
||||
if (aclp != NULL)
|
||||
dns_acl_attach(acl, aclp);
|
||||
|
||||
dns_acl_detach(&acl);
|
||||
(*setzacl)(zone, dacl);
|
||||
dns_acl_detach(&dacl);
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -232,10 +167,6 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone) {
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAINMS;
|
||||
else if (strcasecmp(str, "krb5-subdomain") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAINKRB5;
|
||||
else if (strcasecmp(str, "tcp-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_TCPSELF;
|
||||
else if (strcasecmp(str, "6to4-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_6TO4SELF;
|
||||
else
|
||||
INSIST(0);
|
||||
|
||||
@@ -433,7 +364,6 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
dns_masterformat_t masterformat;
|
||||
dns_stats_t *zoneqrystats;
|
||||
isc_boolean_t zonestats_on;
|
||||
int seconds;
|
||||
|
||||
i = 0;
|
||||
if (zconfig != NULL) {
|
||||
@@ -524,14 +454,14 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
if (ztype == dns_zone_slave)
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
allow_notify, ac, zone,
|
||||
"allow-notify", ac, zone,
|
||||
dns_zone_setnotifyacl,
|
||||
dns_zone_clearnotifyacl));
|
||||
/*
|
||||
* XXXAG This probably does not make sense for stubs.
|
||||
*/
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
allow_query, ac, zone,
|
||||
"allow-query", ac, zone,
|
||||
dns_zone_setqueryacl,
|
||||
dns_zone_clearqueryacl));
|
||||
|
||||
@@ -634,7 +564,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
dns_zone_setisself(zone, ns_client_isself, NULL);
|
||||
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
allow_transfer, ac, zone,
|
||||
"allow-transfer", ac, zone,
|
||||
dns_zone_setxfracl,
|
||||
dns_zone_clearxfracl));
|
||||
|
||||
@@ -725,7 +655,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
if (ztype == dns_zone_master) {
|
||||
dns_acl_t *updateacl;
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
allow_update, ac, zone,
|
||||
"allow-update", ac, zone,
|
||||
dns_zone_setupdateacl,
|
||||
dns_zone_clearupdateacl));
|
||||
|
||||
@@ -742,26 +672,8 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-validity-interval", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
{
|
||||
const cfg_obj_t *validity, *resign;
|
||||
|
||||
validity = cfg_tuple_get(obj, "validity");
|
||||
seconds = cfg_obj_asuint32(validity) * 86400;
|
||||
dns_zone_setsigvalidityinterval(zone, seconds);
|
||||
|
||||
resign = cfg_tuple_get(obj, "re-sign");
|
||||
if (cfg_obj_isvoid(resign)) {
|
||||
seconds /= 4;
|
||||
} else {
|
||||
if (seconds > 7 * 86400)
|
||||
seconds = cfg_obj_asuint32(resign) *
|
||||
86400;
|
||||
else
|
||||
seconds = cfg_obj_asuint32(resign) *
|
||||
3600;
|
||||
}
|
||||
dns_zone_setsigresigninginterval(zone, seconds);
|
||||
}
|
||||
dns_zone_setsigvalidityinterval(zone,
|
||||
cfg_obj_asuint32(obj) * 86400);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "key-directory", &obj);
|
||||
@@ -776,39 +688,6 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
RETERR(dns_zone_setkeydirectory(zone, filename));
|
||||
}
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-signatures", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
dns_zone_setsignatures(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-nodes", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
dns_zone_setnodes(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-type", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
dns_zone_setprivatetype(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "update-check-ksk", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_UPDATECHECKKSK,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
} else if (ztype == dns_zone_slave) {
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
allow_update_forwarding, ac, zone,
|
||||
dns_zone_setforwardacl,
|
||||
dns_zone_clearforwardacl));
|
||||
}
|
||||
|
||||
|
||||
/*%
|
||||
* Primary master functionality.
|
||||
*/
|
||||
if (ztype == dns_zone_master) {
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-wildcard", &obj);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
@@ -867,6 +746,17 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
INSIST(0);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_WARNSRVCNAME, warn);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_IGNORESRVCNAME, ignore);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "update-check-ksk", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_UPDATECHECKKSK,
|
||||
cfg_obj_asboolean(obj));
|
||||
} else if (ztype == dns_zone_slave) {
|
||||
RETERR(configure_zone_acl(zconfig, vconfig, config,
|
||||
"allow-update-forwarding", ac, zone,
|
||||
dns_zone_setforwardacl,
|
||||
dns_zone_clearforwardacl));
|
||||
}
|
||||
|
||||
/*
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: nsupdate.c,v 1.159 2008/04/02 02:37:41 marka Exp $ */
|
||||
/* $Id: nsupdate.c,v 1.154.56.3 2008/01/17 23:46:36 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -1032,7 +1032,7 @@ parse_rdata(char **cmdlinep, dns_rdataclass_t rdataclass,
|
||||
check_result(result, "isc_lex_openbuffer");
|
||||
result = isc_buffer_allocate(mctx, &buf, MAXWIRE);
|
||||
check_result(result, "isc_buffer_allocate");
|
||||
result = dns_rdata_fromtext(NULL, rdataclass, rdatatype, lex,
|
||||
result = dns_rdata_fromtext(rdata, rdataclass, rdatatype, lex,
|
||||
dns_rootname, 0, mctx, buf,
|
||||
&callbacks);
|
||||
isc_lex_destroy(&lex);
|
||||
@@ -1126,7 +1126,8 @@ make_prereq(char *cmdline, isc_boolean_t ispositive, isc_boolean_t isrrset) {
|
||||
result = dns_message_gettemprdata(updatemsg, &rdata);
|
||||
check_result(result, "dns_message_gettemprdata");
|
||||
|
||||
dns_rdata_init(rdata);
|
||||
rdata->data = NULL;
|
||||
rdata->length = 0;
|
||||
|
||||
if (isrrset && ispositive) {
|
||||
retval = parse_rdata(&cmdline, rdataclass, rdatatype,
|
||||
@@ -1445,7 +1446,10 @@ update_addordelete(char *cmdline, isc_boolean_t isdelete) {
|
||||
result = dns_message_gettemprdata(updatemsg, &rdata);
|
||||
check_result(result, "dns_message_gettemprdata");
|
||||
|
||||
dns_rdata_init(rdata);
|
||||
rdata->rdclass = 0;
|
||||
rdata->type = 0;
|
||||
rdata->data = NULL;
|
||||
rdata->length = 0;
|
||||
|
||||
/*
|
||||
* If this is an add, read the TTL and verify that it's in range.
|
||||
|
||||
+14
-14
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: rndc.c,v 1.118 2007/06/18 23:47:25 tbox Exp $ */
|
||||
/* $Id: rndc.c,v 1.118.232.3 2008/07/23 22:51:53 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -93,7 +93,7 @@ static void
|
||||
usage(int status) {
|
||||
fprintf(stderr, "\
|
||||
Usage: %s [-c config] [-s server] [-p port]\n\
|
||||
[-k key-file ] [-y key] [-V] command\n\
|
||||
[-k key-file ] [-y key] [-V] command\n\
|
||||
\n\
|
||||
command is one of the following:\n\
|
||||
\n\
|
||||
@@ -106,10 +106,10 @@ command is one of the following:\n\
|
||||
Retransfer a single zone without checking serial number.\n\
|
||||
freeze Suspend updates to all dynamic zones.\n\
|
||||
freeze zone [class [view]]\n\
|
||||
Suspend updates to a dynamic zone.\n\
|
||||
Suspend updates to a dynamic zone.\n\
|
||||
thaw Enable updates to all dynamic zones and reload them.\n\
|
||||
thaw zone [class [view]]\n\
|
||||
Enable updates to a frozen dynamic zone and reload it.\n\
|
||||
Enable updates to a frozen dynamic zone and reload it.\n\
|
||||
notify zone [class [view]]\n\
|
||||
Resend NOTIFY messages for the zone.\n\
|
||||
reconfig Reload configuration file and new zones only.\n\
|
||||
@@ -152,7 +152,7 @@ get_addresses(const char *host, in_port_t port) {
|
||||
result = isc_sockaddr_frompath(&serveraddrs[nserveraddrs],
|
||||
host);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
nserveraddrs++;
|
||||
nserveraddrs++;
|
||||
} else {
|
||||
count = SERVERADDRS - nserveraddrs;
|
||||
result = bind9_getaddresses(host, port,
|
||||
@@ -400,10 +400,10 @@ rndc_startconnect(isc_sockaddr_t *addr, isc_task_t *task) {
|
||||
DO("create socket", isc_socket_create(socketmgr, pf, type, &sock));
|
||||
switch (isc_sockaddr_pf(addr)) {
|
||||
case AF_INET:
|
||||
DO("bind socket", isc_socket_bind(sock, &local4));
|
||||
DO("bind socket", isc_socket_bind(sock, &local4, 0));
|
||||
break;
|
||||
case AF_INET6:
|
||||
DO("bind socket", isc_socket_bind(sock, &local6));
|
||||
DO("bind socket", isc_socket_bind(sock, &local6, 0));
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
@@ -485,7 +485,7 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
||||
(void)cfg_map_get(config, "server", &servers);
|
||||
if (servers != NULL) {
|
||||
for (elt = cfg_list_first(servers);
|
||||
elt != NULL;
|
||||
elt != NULL;
|
||||
elt = cfg_list_next(elt))
|
||||
{
|
||||
const char *name;
|
||||
@@ -521,7 +521,7 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
||||
else {
|
||||
DO("get config key list", cfg_map_get(config, "key", &keys));
|
||||
for (elt = cfg_list_first(keys);
|
||||
elt != NULL;
|
||||
elt != NULL;
|
||||
elt = cfg_list_next(elt))
|
||||
{
|
||||
key = cfg_listelt_value(elt);
|
||||
@@ -599,7 +599,7 @@ parse_config(isc_mem_t *mctx, isc_log_t *log, const char *keyname,
|
||||
get_addresses(name, (in_port_t) myport);
|
||||
else
|
||||
fprintf(stderr, "too many address: "
|
||||
"%s: dropped\n", name);
|
||||
"%s: dropped\n", name);
|
||||
continue;
|
||||
}
|
||||
sa = *cfg_obj_assockaddr(address);
|
||||
@@ -741,7 +741,7 @@ main(int argc, char **argv) {
|
||||
case 'y':
|
||||
keyname = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
|
||||
case '?':
|
||||
if (isc_commandline_option != '?') {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
@@ -754,7 +754,7 @@ main(int argc, char **argv) {
|
||||
default:
|
||||
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||
program, isc_commandline_option);
|
||||
exit(1);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -780,7 +780,7 @@ main(int argc, char **argv) {
|
||||
logdest.file.maximum_size = 0;
|
||||
DO("creating log channel",
|
||||
isc_log_createchannel(logconfig, "stderr",
|
||||
ISC_LOG_TOFILEDESC, ISC_LOG_INFO, &logdest,
|
||||
ISC_LOG_TOFILEDESC, ISC_LOG_INFO, &logdest,
|
||||
ISC_LOG_PRINTTAG|ISC_LOG_PRINTLEVEL));
|
||||
DO("enabling log channel", isc_log_usechannel(logconfig, "stderr",
|
||||
NULL, NULL));
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.46 2008/05/19 23:47:03 tbox Exp $
|
||||
# $Id: Makefile.in,v 1.44 2007/06/19 23:47:00 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -54,7 +54,7 @@ t_dst@EXEEXT@: t_dst.@O@ ${DEPLIBS} ${TLIB}
|
||||
t_dst.@O@ ${TLIB} ${LIBS}
|
||||
|
||||
gsstest@EXEEXT@: gsstest.@O@ ${DEPLIBS}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} -o $@ \
|
||||
gsstest.@O@ ${LIBS}
|
||||
|
||||
test: t_dst@EXEEXT@
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_dst.c,v 1.55 2008/01/12 23:47:13 tbox Exp $ */
|
||||
/* $Id: t_dst.c,v 1.53.128.2 2008/01/12 23:46:43 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+2
-49
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: inter_test.c,v 1.16 2008/03/20 23:47:00 tbox Exp $ */
|
||||
/* $Id: inter_test.c,v 1.14 2007/06/19 23:46:59 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
#include <config.h>
|
||||
@@ -83,53 +83,6 @@ main(int argc, char **argv) {
|
||||
}
|
||||
}
|
||||
isc_interfaceiter_destroy(&iter);
|
||||
|
||||
fprintf(stdout, "\nPass 2\n\n");
|
||||
|
||||
result = isc_interfaceiter_create(mctx, &iter);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto cleanup;
|
||||
result = isc_interfaceiter_first(iter);
|
||||
while (result == ISC_R_SUCCESS) {
|
||||
result = isc_interfaceiter_current(iter, &ifdata);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stdout, "isc_interfaceiter_current: %s",
|
||||
isc_result_totext(result));
|
||||
continue;
|
||||
}
|
||||
fprintf(stdout, "%s %d %x\n", ifdata.name, ifdata.af,
|
||||
ifdata.flags);
|
||||
INSIST(ifdata.af == AF_INET || ifdata.af == AF_INET6);
|
||||
res = inet_ntop(ifdata.af, &ifdata.address.type, buf,
|
||||
sizeof(buf));
|
||||
if (ifdata.address.zone != 0)
|
||||
fprintf(stdout, "address = %s (zone %u)\n",
|
||||
res == NULL ? "BAD" : res,
|
||||
ifdata.address.zone);
|
||||
else
|
||||
fprintf(stdout, "address = %s\n",
|
||||
res == NULL ? "BAD" : res);
|
||||
INSIST(ifdata.address.family == ifdata.af);
|
||||
res = inet_ntop(ifdata.af, &ifdata.netmask.type, buf,
|
||||
sizeof(buf));
|
||||
fprintf(stdout, "netmask = %s\n", res == NULL ? "BAD" : res);
|
||||
INSIST(ifdata.netmask.family == ifdata.af);
|
||||
if ((ifdata.flags & INTERFACE_F_POINTTOPOINT) != 0) {
|
||||
res = inet_ntop(ifdata.af, &ifdata.dstaddress.type,
|
||||
buf, sizeof(buf));
|
||||
fprintf(stdout, "dstaddress = %s\n",
|
||||
res == NULL ? "BAD" : res);
|
||||
|
||||
INSIST(ifdata.dstaddress.family == ifdata.af);
|
||||
}
|
||||
result = isc_interfaceiter_next(iter);
|
||||
if (result != ISC_R_SUCCESS && result != ISC_R_NOMORE) {
|
||||
fprintf(stdout, "isc_interfaceiter_next: %s",
|
||||
isc_result_totext(result));
|
||||
continue;
|
||||
}
|
||||
}
|
||||
isc_interfaceiter_destroy(&iter);
|
||||
cleanup:
|
||||
isc_mem_destroy(&mctx);
|
||||
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_names.c,v 1.46 2008/01/18 23:46:57 tbox Exp $ */
|
||||
/* $Id: t_names.c,v 1.43.128.3 2008/01/17 23:46:36 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: sig0_test.c,v 1.15 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: sig0_test.c,v 1.15.232.2 2008/07/23 07:32:56 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -189,7 +189,7 @@ buildquery(void) {
|
||||
|
||||
isc_buffer_usedregion(&qbuffer, &r);
|
||||
isc_sockaddr_any(&sa);
|
||||
result = isc_socket_bind(s, &sa);
|
||||
result = isc_socket_bind(s, &sa, 0);
|
||||
CHECK("isc_socket_bind", result);
|
||||
result = isc_socket_sendto(s, &r, task1, senddone, NULL, &address,
|
||||
NULL);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: sock_test.c,v 1.52 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: sock_test.c,v 1.52.232.3 2008/07/23 22:51:53 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -321,7 +321,7 @@ main(int argc, char *argv[]) {
|
||||
}
|
||||
RUNTIME_CHECK(isc_socket_create(socketmgr, pf, isc_sockettype_tcp,
|
||||
&so1) == ISC_R_SUCCESS);
|
||||
result = isc_socket_bind(so1, &sockaddr);
|
||||
result = isc_socket_bind(so1, &sockaddr, ISC_SOCKET_REUSEADDRESS);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
RUNTIME_CHECK(isc_socket_listen(so1, 0) == ISC_R_SUCCESS);
|
||||
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: clean.sh,v 1.3 2008/01/10 23:47:01 tbox Exp $
|
||||
# $Id: clean.sh,v 1.2.2.2 2008/01/10 23:46:34 tbox Exp $
|
||||
|
||||
#
|
||||
# Clean up after zone transfer tests.
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named2.conf,v 1.3 2008/01/21 20:38:54 each Exp $ */
|
||||
/* $Id: named2.conf,v 1.2.2.2 2008/01/21 21:02:23 each Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: setup.sh,v 1.3 2008/01/10 23:47:01 tbox Exp $
|
||||
# $Id: setup.sh,v 1.2.2.2 2008/01/10 23:46:34 tbox Exp $
|
||||
|
||||
sh ../genzone.sh 2 3 >ns2/example.db
|
||||
sh ../genzone.sh 2 3 >ns2/tsigzone.db
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: tests.sh,v 1.3 2008/01/10 23:47:01 tbox Exp $
|
||||
# $Id: tests.sh,v 1.2.2.2.12.1 2008/07/29 18:39:58 jinmei Exp $
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
@@ -29,13 +29,13 @@ echo "I:testing basic ACL processing"
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# any other key should be fine
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
cp -f ns2/named2.conf ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reload 2>&1 | sed 's/^/I:ns2 /'
|
||||
@@ -45,18 +45,18 @@ sleep 5
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# any other address should work, as long as it sends key "one"
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 127.0.0.1 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 127.0.0.1 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
echo "I:testing nested ACL processing"
|
||||
# all combinations of 10.53.0.{1|2} with key {one|two}, should succeed
|
||||
@@ -68,42 +68,42 @@ sleep 5
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.2 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should succeed
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.2 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should succeed
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should succeed
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# but only one or the other should fail
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 127.0.0.1 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.2 axfr -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $tt failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $tt failed" ; status=1; }
|
||||
|
||||
# and other values? right out
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 127.0.0.1 axfr -y three:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# now we only allow 10.53.0.1 *and* key one, or 10.53.0.2 *and* key two
|
||||
cp -f ns2/named4.conf ns2/named.conf
|
||||
@@ -114,31 +114,31 @@ sleep 5
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.2 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should succeed
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out && { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 && { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should fail
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.2 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should fail
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.1 axfr -y two:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
# should fail
|
||||
t=`expr $t + 1`
|
||||
$DIG $DIGOPTS tsigzone. \
|
||||
@10.53.0.2 -b 10.53.0.3 axfr -y one:1234abcd8765 -p 5300 > dig.out
|
||||
grep -q "^;" dig.out || { echo "I:test $t failed" ; status=1; }
|
||||
grep "^;" dig.out > /dev/null 2>&1 || { echo "I:test $t failed" ; status=1; }
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: conf.sh.in,v 1.39 2008/01/10 23:47:01 tbox Exp $
|
||||
# $Id: conf.sh.in,v 1.37.128.2 2008/01/10 23:46:34 tbox Exp $
|
||||
|
||||
#
|
||||
# Common configuration data for system tests, to be sourced into
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: ifconfig.sh,v 1.53 2008/03/03 23:47:02 tbox Exp $
|
||||
# $Id: ifconfig.sh,v 1.51.128.2.10.1 2008/07/25 20:52:09 fdupont Exp $
|
||||
|
||||
#
|
||||
# Set up interface aliases for bind9 system tests.
|
||||
@@ -72,7 +72,7 @@ case "$1" in
|
||||
*-sun-solaris2.[6-7])
|
||||
ifconfig lo0:$int 10.53.0.$ns netmask 0xffffffff up
|
||||
;;
|
||||
*-*-solaris2.[8-9]|*-*-solaris2.10)
|
||||
*-*-solaris2.[8-9]|*-*-solaris2.1[0-9])
|
||||
/sbin/ifconfig lo0:$int plumb
|
||||
/sbin/ifconfig lo0:$int 10.53.0.$ns up
|
||||
;;
|
||||
@@ -135,7 +135,7 @@ case "$1" in
|
||||
*-sun-solaris2.[6-7])
|
||||
ifconfig lo0:$int 10.53.0.$ns down
|
||||
;;
|
||||
*-*-solaris2.[8-9]|*-*-solaris2.10)
|
||||
*-*-solaris2.[8-9]|*-*-solaris2.1[0-9])
|
||||
ifconfig lo0:$int 10.53.0.$ns down
|
||||
ifconfig lo0:$int 10.53.0.$ns unplumb
|
||||
;;
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: lwtest.c,v 1.32 2008/04/02 02:37:42 marka Exp $ */
|
||||
/* $Id: lwtest.c,v 1.29.60.2 2008/01/14 23:46:28 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -764,7 +764,7 @@ main(void) {
|
||||
test_getrrsetbyname("a.example1.", 1, 1, 1, 0, 1);
|
||||
test_getrrsetbyname("e.example1.", 1, 1, 1, 1, 1);
|
||||
test_getrrsetbyname("e.example1.", 1, 255, 1, 1, 0);
|
||||
test_getrrsetbyname("e.example1.", 1, 46, 2, 0, 1);
|
||||
test_getrrsetbyname("e.example1.", 1, 46, 1, 0, 1);
|
||||
test_getrrsetbyname("", 1, 1, 0, 0, 0);
|
||||
|
||||
if (fails == 0)
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
; File written on Wed Mar 5 10:20:40 2008
|
||||
; dnssec_signzone version 9.3.4-P1
|
||||
e.example1. 300 IN SOA mname1. . (
|
||||
2002082210 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
300 RRSIG SOA 5 2 300 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
KtYwrnKM7Tu53BNf8XuTix53r9kDdCneJ1X7
|
||||
xklFbp4YjRKC3NhwVK9PFe0jdHOkIDMtrwxn
|
||||
n7/Rp07xIyURqw== )
|
||||
300 NS ns.e.example1.
|
||||
300 RRSIG NS 5 2 300 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
KBPx3XmNl4swVPdwuUEFuzZedMSfsyK2a0Fu
|
||||
o2wBnbCuS7G7DtfW9690lP/eTyixLOIwlFLQ
|
||||
MrjN3+XgpkdgIw== )
|
||||
300 A 10.0.1.1
|
||||
300 RRSIG A 5 2 300 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
KYlxMQUvv8DQtVgS23lNL5tFYmRppJ7vTgH3
|
||||
btvgKbyHxW/04ewRsgCa82iu3iJipdEhKM11
|
||||
ALkRNhqL7frnig== )
|
||||
3600 NSEC ns.e.example1. A NS SOA RRSIG NSEC DNSKEY
|
||||
3600 RRSIG NSEC 5 2 3600 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
azSgagb7bldM06qSZg8nDZWOY2FbqeZY0/T8
|
||||
nC+6VhCs7YTfNvXynLWmvmpqL7gVT6/O+Yi2
|
||||
2lmdntld7GORrQ== )
|
||||
300 DNSKEY 256 3 5 (
|
||||
AwEAAcvAUMfH7wA0z077fJaF7RMrxAFyvo0/
|
||||
7aAL4d2/yA5TqTaUCVnJtE+XgGO34kH9mwae
|
||||
we+Nyv2kRWDeLl6nhGk=
|
||||
) ; key id = 14043
|
||||
300 RRSIG DNSKEY 5 2 300 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
BQFWOHopXuBNdzcopkdl1YVKGF0QvIaYpywM
|
||||
fcpG5gi+sy9EoTofQ1UGsLOjU3nFXCvJFG4K
|
||||
1gUhzEEti440/g== )
|
||||
ns.e.example1. 300 IN A 10.53.0.1
|
||||
300 RRSIG A 5 3 300 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
cYPzsWNQ/eL4h2lihKRjKT2jhGpOqV9woGJA
|
||||
/Jstx2iethOAvYtgY22CsAbCUr/6E4bSgBZR
|
||||
TMoC604cNdFzIw== )
|
||||
3600 NSEC e.example1. A RRSIG NSEC
|
||||
3600 RRSIG NSEC 5 3 3600 20010101000000 (
|
||||
20000101000000 14043 e.example1.
|
||||
J8Md544zDLP4GjyAtkjH/rSFvpzXY/7bgJRS
|
||||
YDoARwFQRmlrJvavXEjqElb2fTQqlNNz1cal
|
||||
QROz/WJ3GLwOWw== )
|
||||
@@ -1,4 +1,4 @@
|
||||
; Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: example1.db,v 1.19 2008/04/02 23:46:57 tbox Exp $
|
||||
; $Id: example1.db,v 1.17 2007/06/19 23:47:04 tbox Exp $
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
@@ -32,4 +32,7 @@ a3 CNAME nowhere
|
||||
b AAAA eeee:eeee:eeee:eeee:ffff:ffff:ffff:ffff
|
||||
8.8.7.7 DNAME net
|
||||
0.0.f.f.e.e.d.d.c.c.b.b.a.a.9.9.net PTR dname
|
||||
e NS ns.e
|
||||
e A 10.0.1.1
|
||||
RRSIG A 1 1 300 20001202003412 (
|
||||
20001102003412 1 example. abcd )
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named.conf,v 1.21 2008/04/02 23:46:57 tbox Exp $ */
|
||||
/* $Id: named.conf,v 1.19 2007/06/19 23:47:04 tbox Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
@@ -43,11 +43,6 @@ zone "example1." {
|
||||
file "example1.db";
|
||||
};
|
||||
|
||||
zone "e.example1." {
|
||||
type master;
|
||||
file "e.example1.db";
|
||||
};
|
||||
|
||||
zone "example2." {
|
||||
type master;
|
||||
file "example2.db";
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: clean.sh,v 1.8 2008/04/24 23:46:59 tbox Exp $
|
||||
# $Id: clean.sh,v 1.6.46.2 2008/04/24 23:46:29 tbox Exp $
|
||||
|
||||
rm -f dig.out.cyclic dig.out.fixed dig.out.random
|
||||
rm -f dig.out.0 dig.out.1 dig.out.2 dig.out.3
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: tests.sh,v 1.7 2008/04/24 23:46:59 tbox Exp $
|
||||
# $Id: tests.sh,v 1.5.128.2 2008/04/24 23:46:29 tbox Exp $
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl -w
|
||||
#
|
||||
# Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: start.pl,v 1.13 2008/01/02 23:47:01 tbox Exp $
|
||||
# $Id: start.pl,v 1.11 2007/06/19 23:47:00 tbox Exp $
|
||||
|
||||
# Framework for starting test servers.
|
||||
# Based on the type of server specified, check for port availability, remove
|
||||
@@ -129,9 +129,7 @@ sub start_server {
|
||||
if ($options) {
|
||||
$command .= "$options";
|
||||
} else {
|
||||
$command .= "-m record,size,mctx ";
|
||||
$command .= "-T clienttest ";
|
||||
$command .= "-c named.conf -d 99 -g";
|
||||
$command .= "-m record,size,mctx -c named.conf -d 99 -g";
|
||||
}
|
||||
$command .= " >named.run 2>&1 &";
|
||||
$pid_file = "named.pid";
|
||||
@@ -141,10 +139,7 @@ sub start_server {
|
||||
if ($options) {
|
||||
$command .= "$options";
|
||||
} else {
|
||||
$command .= "-m record,size,mctx ";
|
||||
$command .= "-T clienttest ";
|
||||
$command .= "-C resolv.conf -d 99 -g ";
|
||||
$command .= "-i lwresd.pid -P 9210 -p 5300";
|
||||
$command .= "-m record,size,mctx -C resolv.conf -d 99 -g -i lwresd.pid -P 9210 -p 5300";
|
||||
}
|
||||
$command .= " >lwresd.run 2>&1 &";
|
||||
$pid_file = "lwresd.pid";
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_timers.c,v 1.28 2008/01/12 23:47:13 tbox Exp $ */
|
||||
/* $Id: t_timers.c,v 1.26.128.2 2008/01/12 23:46:43 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.h.in,v 1.99 2008/05/06 01:30:26 each Exp $ */
|
||||
/* $Id: config.h.in,v 1.90.60.8 2008/05/06 01:32:51 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
|
||||
+1
-1
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.h.win32,v 1.18 2008/04/02 23:46:57 tbox Exp $ */
|
||||
/* $Id: config.h.win32,v 1.16.130.2 2008/04/02 23:46:28 tbox Exp $ */
|
||||
|
||||
/*
|
||||
* win32 configuration file
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
#
|
||||
# $Id: configure,v 1.429 2008/06/17 03:58:27 marka Exp $
|
||||
# $Id: configure,v 1.418.60.8.4.1 2008/07/25 20:52:06 fdupont Exp $
|
||||
#
|
||||
# Portions Copyright (C) 1996-2001 Nominum, Inc.
|
||||
#
|
||||
@@ -29,7 +29,7 @@
|
||||
# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
|
||||
# OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
# From configure.in Revision: 1.443 .
|
||||
# From configure.in Revision: 1.432.60.9 .
|
||||
# Guess values for system-dependent variables and create Makefiles.
|
||||
# Generated by GNU Autoconf 2.61.
|
||||
#
|
||||
@@ -876,7 +876,6 @@ ISC_PLATFORM_NEEDSYSSELECTH
|
||||
LWRES_PLATFORM_NEEDSYSSELECTH
|
||||
USE_OPENSSL
|
||||
DST_OPENSSL_INC
|
||||
USE_PKCS11
|
||||
ISC_PLATFORM_HAVEGSSAPI
|
||||
ISC_PLATFORM_GSSAPIHEADER
|
||||
USE_GSSAPI
|
||||
@@ -1633,7 +1632,8 @@ Optional Features:
|
||||
--disable-libtool-lock avoid locking (might break parallel builds)
|
||||
--enable-libbind build libbind default=no
|
||||
--enable-ipv6 use IPv6 default=autodetect
|
||||
--enable-getifaddrs Enable the use of getifaddrs() [yes|no].
|
||||
--enable-getifaddrs Enable the use of getifaddrs() [yes|no|glibc].
|
||||
glibc: Use getifaddrs() in glibc if you know it supports IPv6.
|
||||
--disable-isc-spnego use SPNEGO from GSSAPI library
|
||||
--disable-linux-caps disable linux capabilities
|
||||
--enable-atomic enable machine specific atomic operations
|
||||
@@ -1646,7 +1646,6 @@ Optional Packages:
|
||||
--without-PACKAGE do not use PACKAGE (same as --with-PACKAGE=no)
|
||||
--with-openssl=PATH Build with OpenSSL yes|no|path.
|
||||
(Required for DNSSEC)
|
||||
--with-pkcs11 Build with PKCS11 support
|
||||
--with-gssapi=PATH Specify path for system-supplied GSSAPI
|
||||
--with-randomdev=PATH Specify path for random device
|
||||
--with-ptl2 on NetBSD, use the ptl2 thread library (experimental)
|
||||
@@ -5985,38 +5984,6 @@ esac
|
||||
|
||||
DNS_CRYPTO_LIBS="$DNS_CRYPTO_LIBS $DNS_OPENSSL_LIBS"
|
||||
|
||||
#
|
||||
# PKCS11 (aka crypto hardware) support
|
||||
#
|
||||
# This works only with the right OpenSSL with PKCS11 engine!
|
||||
#
|
||||
|
||||
{ echo "$as_me:$LINENO: checking for PKCS11 support" >&5
|
||||
echo $ECHO_N "checking for PKCS11 support... $ECHO_C" >&6; }
|
||||
|
||||
# Check whether --with-pkcs11 was given.
|
||||
if test "${with_pkcs11+set}" = set; then
|
||||
withval=$with_pkcs11; use_pkcs11="yes"
|
||||
else
|
||||
use_pkcs11="no"
|
||||
fi
|
||||
|
||||
|
||||
case "$use_pkcs11" in
|
||||
no)
|
||||
{ echo "$as_me:$LINENO: result: disabled" >&5
|
||||
echo "${ECHO_T}disabled" >&6; }
|
||||
USE_PKCS11=""
|
||||
;;
|
||||
yes)
|
||||
{ echo "$as_me:$LINENO: result: using OpenSSL with PKCS11 support" >&5
|
||||
echo "${ECHO_T}using OpenSSL with PKCS11 support" >&6; }
|
||||
USE_PKCS11='-DUSE_PKCS11'
|
||||
;;
|
||||
esac
|
||||
|
||||
|
||||
|
||||
{ echo "$as_me:$LINENO: checking for GSSAPI library" >&5
|
||||
echo $ECHO_N "checking for GSSAPI library... $ECHO_C" >&6; }
|
||||
|
||||
@@ -9624,7 +9591,7 @@ ia64-*-hpux*)
|
||||
;;
|
||||
*-*-irix6*)
|
||||
# Find out which ABI we are using.
|
||||
echo '#line 9627 "configure"' > conftest.$ac_ext
|
||||
echo '#line 9594 "configure"' > conftest.$ac_ext
|
||||
if { (eval echo "$as_me:$LINENO: \"$ac_compile\"") >&5
|
||||
(eval $ac_compile) 2>&5
|
||||
ac_status=$?
|
||||
@@ -11746,11 +11713,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:11749: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:11716: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:11753: \$? = $ac_status" >&5
|
||||
echo "$as_me:11720: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -11989,11 +11956,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:11992: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:11959: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:11996: \$? = $ac_status" >&5
|
||||
echo "$as_me:11963: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -12049,11 +12016,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:12052: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:12019: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>out/conftest.err)
|
||||
ac_status=$?
|
||||
cat out/conftest.err >&5
|
||||
echo "$as_me:12056: \$? = $ac_status" >&5
|
||||
echo "$as_me:12023: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s out/conftest2.$ac_objext
|
||||
then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
@@ -14197,7 +14164,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 14200 "configure"
|
||||
#line 14167 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -14295,7 +14262,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 14298 "configure"
|
||||
#line 14265 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -16488,11 +16455,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:16491: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:16458: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:16495: \$? = $ac_status" >&5
|
||||
echo "$as_me:16462: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -16548,11 +16515,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:16551: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:16518: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>out/conftest.err)
|
||||
ac_status=$?
|
||||
cat out/conftest.err >&5
|
||||
echo "$as_me:16555: \$? = $ac_status" >&5
|
||||
echo "$as_me:16522: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s out/conftest2.$ac_objext
|
||||
then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
@@ -17876,7 +17843,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 17879 "configure"
|
||||
#line 17846 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -17974,7 +17941,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 17977 "configure"
|
||||
#line 17944 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -18811,11 +18778,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:18814: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:18781: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:18818: \$? = $ac_status" >&5
|
||||
echo "$as_me:18785: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -18871,11 +18838,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:18874: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:18841: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>out/conftest.err)
|
||||
ac_status=$?
|
||||
cat out/conftest.err >&5
|
||||
echo "$as_me:18878: \$? = $ac_status" >&5
|
||||
echo "$as_me:18845: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s out/conftest2.$ac_objext
|
||||
then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
@@ -20905,11 +20872,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:20908: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:20875: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:20912: \$? = $ac_status" >&5
|
||||
echo "$as_me:20879: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -21148,11 +21115,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:21151: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:21118: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>conftest.err)
|
||||
ac_status=$?
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:21155: \$? = $ac_status" >&5
|
||||
echo "$as_me:21122: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s "$ac_outfile"; then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
# So say no if there are warnings
|
||||
@@ -21208,11 +21175,11 @@ else
|
||||
-e 's:.*FLAGS}? :&$lt_compiler_flag :; t' \
|
||||
-e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
|
||||
-e 's:$: $lt_compiler_flag:'`
|
||||
(eval echo "\"\$as_me:21211: $lt_compile\"" >&5)
|
||||
(eval echo "\"\$as_me:21178: $lt_compile\"" >&5)
|
||||
(eval "$lt_compile" 2>out/conftest.err)
|
||||
ac_status=$?
|
||||
cat out/conftest.err >&5
|
||||
echo "$as_me:21215: \$? = $ac_status" >&5
|
||||
echo "$as_me:21182: \$? = $ac_status" >&5
|
||||
if (exit $ac_status) && test -s out/conftest2.$ac_objext
|
||||
then
|
||||
# The compiler can only warn and ignore the option if not recognized
|
||||
@@ -23356,7 +23323,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 23359 "configure"
|
||||
#line 23326 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -23454,7 +23421,7 @@ else
|
||||
lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
|
||||
lt_status=$lt_dlunknown
|
||||
cat > conftest.$ac_ext <<EOF
|
||||
#line 23457 "configure"
|
||||
#line 23424 "configure"
|
||||
#include "confdefs.h"
|
||||
|
||||
#if HAVE_DLFCN_H
|
||||
@@ -26343,16 +26310,21 @@ else
|
||||
fi
|
||||
|
||||
|
||||
#
|
||||
# This interface iteration code for getifaddrs() will fall back to using
|
||||
# /proc/net/if_inet6 if getifaddrs() in glibc doesn't return any IPv6
|
||||
# addresses.
|
||||
#
|
||||
case $want_getifaddrs in
|
||||
glibc)
|
||||
{ echo "$as_me:$LINENO: WARNING: \"--enable-getifaddrs=glibc is no longer required\"" >&5
|
||||
echo "$as_me: WARNING: \"--enable-getifaddrs=glibc is no longer required\"" >&2;}
|
||||
{ echo "$as_me:$LINENO: checking for getifaddrs" >&5
|
||||
yes|glibc)
|
||||
#
|
||||
# Do we have getifaddrs() ?
|
||||
#
|
||||
case $host in
|
||||
*-linux*)
|
||||
# Some recent versions of glibc support getifaddrs() which does not
|
||||
# provide AF_INET6 addresses while the function provided by the USAGI
|
||||
# project handles the AF_INET6 case correctly. We need to avoid
|
||||
# using the former but prefer the latter unless overridden by
|
||||
# --enable-getifaddrs=glibc.
|
||||
if test $want_getifaddrs = glibc
|
||||
then
|
||||
{ echo "$as_me:$LINENO: checking for getifaddrs" >&5
|
||||
echo $ECHO_N "checking for getifaddrs... $ECHO_C" >&6; }
|
||||
if test "${ac_cv_func_getifaddrs+set}" = set; then
|
||||
echo $ECHO_N "(cached) $ECHO_C" >&6
|
||||
@@ -26440,9 +26412,84 @@ _ACEOF
|
||||
|
||||
fi
|
||||
|
||||
;;
|
||||
yes)
|
||||
{ echo "$as_me:$LINENO: checking for getifaddrs" >&5
|
||||
else
|
||||
save_LIBS="$LIBS"
|
||||
LIBS="-L/usr/local/v6/lib $LIBS"
|
||||
{ echo "$as_me:$LINENO: checking for getifaddrs in -linet6" >&5
|
||||
echo $ECHO_N "checking for getifaddrs in -linet6... $ECHO_C" >&6; }
|
||||
if test "${ac_cv_lib_inet6_getifaddrs+set}" = set; then
|
||||
echo $ECHO_N "(cached) $ECHO_C" >&6
|
||||
else
|
||||
ac_check_lib_save_LIBS=$LIBS
|
||||
LIBS="-linet6 $LIBS"
|
||||
cat >conftest.$ac_ext <<_ACEOF
|
||||
/* confdefs.h. */
|
||||
_ACEOF
|
||||
cat confdefs.h >>conftest.$ac_ext
|
||||
cat >>conftest.$ac_ext <<_ACEOF
|
||||
/* end confdefs.h. */
|
||||
|
||||
/* Override any GCC internal prototype to avoid an error.
|
||||
Use char because int might match the return type of a GCC
|
||||
builtin and then its argument prototype would still apply. */
|
||||
#ifdef __cplusplus
|
||||
extern "C"
|
||||
#endif
|
||||
char getifaddrs ();
|
||||
int
|
||||
main ()
|
||||
{
|
||||
return getifaddrs ();
|
||||
;
|
||||
return 0;
|
||||
}
|
||||
_ACEOF
|
||||
rm -f conftest.$ac_objext conftest$ac_exeext
|
||||
if { (ac_try="$ac_link"
|
||||
case "(($ac_try" in
|
||||
*\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
|
||||
*) ac_try_echo=$ac_try;;
|
||||
esac
|
||||
eval "echo \"\$as_me:$LINENO: $ac_try_echo\"") >&5
|
||||
(eval "$ac_link") 2>conftest.er1
|
||||
ac_status=$?
|
||||
grep -v '^ *+' conftest.er1 >conftest.err
|
||||
rm -f conftest.er1
|
||||
cat conftest.err >&5
|
||||
echo "$as_me:$LINENO: \$? = $ac_status" >&5
|
||||
(exit $ac_status); } && {
|
||||
test -z "$ac_c_werror_flag" ||
|
||||
test ! -s conftest.err
|
||||
} && test -s conftest$ac_exeext &&
|
||||
$as_test_x conftest$ac_exeext; then
|
||||
ac_cv_lib_inet6_getifaddrs=yes
|
||||
else
|
||||
echo "$as_me: failed program was:" >&5
|
||||
sed 's/^/| /' conftest.$ac_ext >&5
|
||||
|
||||
ac_cv_lib_inet6_getifaddrs=no
|
||||
fi
|
||||
|
||||
rm -f core conftest.err conftest.$ac_objext conftest_ipa8_conftest.oo \
|
||||
conftest$ac_exeext conftest.$ac_ext
|
||||
LIBS=$ac_check_lib_save_LIBS
|
||||
fi
|
||||
{ echo "$as_me:$LINENO: result: $ac_cv_lib_inet6_getifaddrs" >&5
|
||||
echo "${ECHO_T}$ac_cv_lib_inet6_getifaddrs" >&6; }
|
||||
if test $ac_cv_lib_inet6_getifaddrs = yes; then
|
||||
LIBS="$LIBS -linet6"
|
||||
cat >>confdefs.h <<\_ACEOF
|
||||
#define HAVE_GETIFADDRS 1
|
||||
_ACEOF
|
||||
|
||||
else
|
||||
LIBS=${save_LIBS}
|
||||
fi
|
||||
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
{ echo "$as_me:$LINENO: checking for getifaddrs" >&5
|
||||
echo $ECHO_N "checking for getifaddrs... $ECHO_C" >&6; }
|
||||
if test "${ac_cv_func_getifaddrs+set}" = set; then
|
||||
echo $ECHO_N "(cached) $ECHO_C" >&6
|
||||
@@ -26530,6 +26577,8 @@ _ACEOF
|
||||
|
||||
fi
|
||||
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
no)
|
||||
;;
|
||||
@@ -28547,7 +28596,7 @@ case "$host" in
|
||||
*-solaris2.[89])
|
||||
hack_shutup_pthreadonceinit=yes
|
||||
;;
|
||||
*-solaris2.10)
|
||||
*-solaris2.1[0-9])
|
||||
hack_shutup_pthreadonceinit=yes
|
||||
;;
|
||||
esac
|
||||
@@ -30516,8 +30565,6 @@ else
|
||||
fi
|
||||
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
# User did not specify a path - guess it
|
||||
@@ -30527,49 +30574,9 @@ then
|
||||
if test -f $d/include/mysql/mysql.h
|
||||
then
|
||||
use_dlz_mysql=$d
|
||||
mysql_include=$d/include/mysql
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
break
|
||||
elif test -f $d/include/mysql.h
|
||||
then
|
||||
use_dlz_mysql=$d
|
||||
mysql_include=$d/include
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
break
|
||||
fi
|
||||
done
|
||||
elif test "$use_dlz_mysql" != "no"
|
||||
then
|
||||
d = $use_dlz_mysql
|
||||
if test -f $d/include/mysql/mysql.h
|
||||
then
|
||||
mysql_include=$d/include/mysql
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
elif test -f $d/include/mysql.h
|
||||
then
|
||||
mysql_include=$d/include
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
@@ -30594,18 +30601,18 @@ echo "${ECHO_T}no" >&6; }
|
||||
DLZ_DRIVER_SRCS="$DLZ_DRIVER_SRCS $dlzdir/$i.c"
|
||||
DLZ_DRIVER_OBJS="$DLZ_DRIVER_OBJS $i.$O"
|
||||
done
|
||||
if test -n "-I${mysql_include}"
|
||||
if test -n "-I$use_dlz_mysql/include/mysql"
|
||||
then
|
||||
DLZ_DRIVER_INCLUDES="$DLZ_DRIVER_INCLUDES -I${mysql_include}"
|
||||
DLZ_DRIVER_INCLUDES="$DLZ_DRIVER_INCLUDES -I$use_dlz_mysql/include/mysql"
|
||||
fi
|
||||
if test -n "-L${mysql_lib} -lmysqlclient -lz -lcrypt -lm"
|
||||
if test -n "-L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm"
|
||||
then
|
||||
DLZ_DRIVER_LIBS="$DLZ_DRIVER_LIBS -L${mysql_lib} -lmysqlclient -lz -lcrypt -lm"
|
||||
DLZ_DRIVER_LIBS="$DLZ_DRIVER_LIBS -L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm"
|
||||
fi
|
||||
|
||||
|
||||
{ echo "$as_me:$LINENO: result: using mysql from ${mysql_lib} and ${mysql_include}" >&5
|
||||
echo "${ECHO_T}using mysql from ${mysql_lib} and ${mysql_include}" >&6; }
|
||||
{ echo "$as_me:$LINENO: result: using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql" >&5
|
||||
echo "${ECHO_T}using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql" >&6; }
|
||||
;;
|
||||
esac
|
||||
|
||||
@@ -32015,7 +32022,6 @@ ISC_PLATFORM_NEEDSYSSELECTH!$ISC_PLATFORM_NEEDSYSSELECTH$ac_delim
|
||||
LWRES_PLATFORM_NEEDSYSSELECTH!$LWRES_PLATFORM_NEEDSYSSELECTH$ac_delim
|
||||
USE_OPENSSL!$USE_OPENSSL$ac_delim
|
||||
DST_OPENSSL_INC!$DST_OPENSSL_INC$ac_delim
|
||||
USE_PKCS11!$USE_PKCS11$ac_delim
|
||||
ISC_PLATFORM_HAVEGSSAPI!$ISC_PLATFORM_HAVEGSSAPI$ac_delim
|
||||
ISC_PLATFORM_GSSAPIHEADER!$ISC_PLATFORM_GSSAPIHEADER$ac_delim
|
||||
USE_GSSAPI!$USE_GSSAPI$ac_delim
|
||||
@@ -32104,6 +32110,7 @@ LWRES_PLATFORM_NEEDSPRINTF!$LWRES_PLATFORM_NEEDSPRINTF$ac_delim
|
||||
ISC_PLATFORM_NEEDVSNPRINTF!$ISC_PLATFORM_NEEDVSNPRINTF$ac_delim
|
||||
LWRES_PLATFORM_NEEDVSNPRINTF!$LWRES_PLATFORM_NEEDVSNPRINTF$ac_delim
|
||||
ISC_EXTRA_OBJS!$ISC_EXTRA_OBJS$ac_delim
|
||||
ISC_EXTRA_SRCS!$ISC_EXTRA_SRCS$ac_delim
|
||||
_ACEOF
|
||||
|
||||
if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 97; then
|
||||
@@ -32145,7 +32152,6 @@ _ACEOF
|
||||
ac_delim='%!_!# '
|
||||
for ac_last_try in false false false false false :; do
|
||||
cat >conf$$subs.sed <<_ACEOF
|
||||
ISC_EXTRA_SRCS!$ISC_EXTRA_SRCS$ac_delim
|
||||
USE_ISC_SPNEGO!$USE_ISC_SPNEGO$ac_delim
|
||||
DST_EXTRA_OBJS!$DST_EXTRA_OBJS$ac_delim
|
||||
DST_EXTRA_SRCS!$DST_EXTRA_SRCS$ac_delim
|
||||
@@ -32208,7 +32214,7 @@ LIBOBJS!$LIBOBJS$ac_delim
|
||||
LTLIBOBJS!$LTLIBOBJS$ac_delim
|
||||
_ACEOF
|
||||
|
||||
if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 61; then
|
||||
if test `sed -n "s/.*$ac_delim\$/X/p" conf$$subs.sed | grep -c X` = 60; then
|
||||
break
|
||||
elif $ac_last_try; then
|
||||
{ { echo "$as_me:$LINENO: error: could not make $CONFIG_STATUS" >&5
|
||||
|
||||
+31
-38
@@ -18,7 +18,7 @@ AC_DIVERT_PUSH(1)dnl
|
||||
esyscmd([sed "s/^/# /" COPYRIGHT])dnl
|
||||
AC_DIVERT_POP()dnl
|
||||
|
||||
AC_REVISION($Revision: 1.443 $)
|
||||
AC_REVISION($Revision: 1.432.60.9.4.1 $)
|
||||
|
||||
AC_INIT(lib/dns/name.c)
|
||||
AC_PREREQ(2.59)
|
||||
@@ -545,30 +545,6 @@ AC_SUBST(USE_OPENSSL)
|
||||
AC_SUBST(DST_OPENSSL_INC)
|
||||
DNS_CRYPTO_LIBS="$DNS_CRYPTO_LIBS $DNS_OPENSSL_LIBS"
|
||||
|
||||
#
|
||||
# PKCS11 (aka crypto hardware) support
|
||||
#
|
||||
# This works only with the right OpenSSL with PKCS11 engine!
|
||||
#
|
||||
|
||||
AC_MSG_CHECKING(for PKCS11 support)
|
||||
AC_ARG_WITH(pkcs11,
|
||||
[ --with-pkcs11 Build with PKCS11 support],
|
||||
use_pkcs11="yes", use_pkcs11="no")
|
||||
|
||||
case "$use_pkcs11" in
|
||||
no)
|
||||
AC_MSG_RESULT(disabled)
|
||||
USE_PKCS11=""
|
||||
;;
|
||||
yes)
|
||||
AC_MSG_RESULT(using OpenSSL with PKCS11 support)
|
||||
USE_PKCS11='-DUSE_PKCS11'
|
||||
;;
|
||||
esac
|
||||
|
||||
AC_SUBST(USE_PKCS11)
|
||||
|
||||
AC_MSG_CHECKING(for GSSAPI library)
|
||||
AC_ARG_WITH(gssapi,
|
||||
[ --with-gssapi=PATH Specify path for system-supplied GSSAPI],
|
||||
@@ -1701,21 +1677,38 @@ AC_SUBST(ISC_LWRES_GETADDRINFOPROTO)
|
||||
AC_SUBST(ISC_LWRES_GETNAMEINFOPROTO)
|
||||
|
||||
AC_ARG_ENABLE(getifaddrs,
|
||||
[ --enable-getifaddrs Enable the use of getifaddrs() [[yes|no]].],
|
||||
[ --enable-getifaddrs Enable the use of getifaddrs() [[yes|no|glibc]].
|
||||
glibc: Use getifaddrs() in glibc if you know it supports IPv6.],
|
||||
want_getifaddrs="$enableval", want_getifaddrs="yes")
|
||||
|
||||
#
|
||||
# This interface iteration code for getifaddrs() will fall back to using
|
||||
# /proc/net/if_inet6 if getifaddrs() in glibc doesn't return any IPv6
|
||||
# addresses.
|
||||
#
|
||||
case $want_getifaddrs in
|
||||
glibc)
|
||||
AC_MSG_WARN("--enable-getifaddrs=glibc is no longer required")
|
||||
AC_CHECK_FUNC(getifaddrs, AC_DEFINE(HAVE_GETIFADDRS))
|
||||
;;
|
||||
yes)
|
||||
AC_CHECK_FUNC(getifaddrs, AC_DEFINE(HAVE_GETIFADDRS))
|
||||
yes|glibc)
|
||||
#
|
||||
# Do we have getifaddrs() ?
|
||||
#
|
||||
case $host in
|
||||
*-linux*)
|
||||
# Some recent versions of glibc support getifaddrs() which does not
|
||||
# provide AF_INET6 addresses while the function provided by the USAGI
|
||||
# project handles the AF_INET6 case correctly. We need to avoid
|
||||
# using the former but prefer the latter unless overridden by
|
||||
# --enable-getifaddrs=glibc.
|
||||
if test $want_getifaddrs = glibc
|
||||
then
|
||||
AC_CHECK_FUNC(getifaddrs, AC_DEFINE(HAVE_GETIFADDRS))
|
||||
else
|
||||
save_LIBS="$LIBS"
|
||||
LIBS="-L/usr/local/v6/lib $LIBS"
|
||||
AC_CHECK_LIB(inet6, getifaddrs,
|
||||
LIBS="$LIBS -linet6"
|
||||
AC_DEFINE(HAVE_GETIFADDRS),
|
||||
LIBS=${save_LIBS})
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
AC_CHECK_FUNC(getifaddrs, AC_DEFINE(HAVE_GETIFADDRS))
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
no)
|
||||
;;
|
||||
@@ -2035,7 +2028,7 @@ case "$host" in
|
||||
[*-solaris2.[89]])
|
||||
hack_shutup_pthreadonceinit=yes
|
||||
;;
|
||||
*-solaris2.10)
|
||||
*-solaris2.1[0-9])
|
||||
hack_shutup_pthreadonceinit=yes
|
||||
;;
|
||||
esac
|
||||
|
||||
@@ -123,8 +123,6 @@ AC_ARG_WITH(dlz_mysql,
|
||||
(Required to use MySQL with DLZ)],
|
||||
use_dlz_mysql="$withval", use_dlz_mysql="no")
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
# User did not specify a path - guess it
|
||||
@@ -134,49 +132,9 @@ then
|
||||
if test -f $d/include/mysql/mysql.h
|
||||
then
|
||||
use_dlz_mysql=$d
|
||||
mysql_include=$d/include/mysql
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
break
|
||||
elif test -f $d/include/mysql.h
|
||||
then
|
||||
use_dlz_mysql=$d
|
||||
mysql_include=$d/include
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
break
|
||||
fi
|
||||
done
|
||||
elif test "$use_dlz_mysql" != "no"
|
||||
then
|
||||
d=$use_dlz_mysql
|
||||
if test -f $d/include/mysql/mysql.h
|
||||
then
|
||||
mysql_include=$d/include/mysql
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
elif test -f $d/include/mysql.h
|
||||
then
|
||||
mysql_include=$d/include
|
||||
if test -d $d/lib/mysql
|
||||
then
|
||||
mysql_lib=$d/lib/mysql
|
||||
else
|
||||
mysql_lib=$d/lib
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
@@ -192,11 +150,11 @@ case "$use_dlz_mysql" in
|
||||
;;
|
||||
*)
|
||||
DLZ_ADD_DRIVER(MYSQL, dlz_mysql_driver,
|
||||
[-I${mysql_include}],
|
||||
[-L${mysql_lib} -lmysqlclient -lz -lcrypt -lm])
|
||||
[-I$use_dlz_mysql/include/mysql],
|
||||
[-L$use_dlz_mysql/lib/mysql -lmysqlclient -lz -lcrypt -lm])
|
||||
|
||||
AC_MSG_RESULT(
|
||||
[using mysql from ${mysql_lib} and ${mysql_include}])
|
||||
[using mysql from $use_dlz_mysql/lib/mysql and $use_dlz_mysql/include/mysql])
|
||||
;;
|
||||
esac
|
||||
|
||||
|
||||
@@ -1,124 +0,0 @@
|
||||
/* OpenSSL tool
|
||||
*
|
||||
* usage: PEM_write_pubkey -e engine -p pin -k keyname -f filename
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <openssl/engine.h>
|
||||
#include <openssl/conf.h>
|
||||
#include <unistd.h>
|
||||
#include <errno.h>
|
||||
|
||||
extern int PEM_write_PUBKEY(FILE *fp, EVP_PKEY *x);
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
ENGINE *e;
|
||||
EVP_PKEY *pub_key;
|
||||
FILE *fp;
|
||||
char *engine = NULL;
|
||||
char *pin = NULL;
|
||||
char *keyname = NULL;
|
||||
char *filename = NULL;
|
||||
int c, errflg = 0;
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":e:p:k:f:")) != -1) {
|
||||
switch (c) {
|
||||
case 'e':
|
||||
engine = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = optarg;
|
||||
break;
|
||||
case 'k':
|
||||
keyname = optarg;
|
||||
break;
|
||||
case 'f':
|
||||
filename = optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if ((errflg) || (!engine) || (!filename) || (!keyname)) {
|
||||
fprintf(stderr,
|
||||
"usage: PEM_write_pubkey -e engine [-p pin] "
|
||||
"-k keyname -f filename\n");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Load the config file */
|
||||
OPENSSL_config(NULL);
|
||||
|
||||
/* Register engine */
|
||||
e = ENGINE_by_id(engine);
|
||||
if (!e) {
|
||||
/* the engine isn't available */
|
||||
printf("The engine isn't available\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Send PIN to engine */
|
||||
if (pin && !ENGINE_ctrl_cmd_string(e, "PIN", pin, 0)){
|
||||
printf("Error sending PIN to engine\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (!ENGINE_init(e)) {
|
||||
/* the engine couldn't initialise, release 'e' */
|
||||
printf("The engine couldn't initialise\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (!ENGINE_register_RSA(e)){
|
||||
/* This should only happen when 'e' can't initialise, but the previous
|
||||
* statement suggests it did. */
|
||||
printf("This should not happen\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Load public key */
|
||||
pub_key = ENGINE_load_public_key(e, keyname, NULL, NULL);
|
||||
if (pub_key == NULL) {
|
||||
/* No public key */
|
||||
printf("Error loading public key\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* write public key to file in PEM format */
|
||||
fp = fopen(filename, "w");
|
||||
if (fp == NULL) {
|
||||
printf("Error opening output file.\n");
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (!PEM_write_PUBKEY(fp, pub_key)) {
|
||||
/* Error writing public key */
|
||||
printf("Error writing public key");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
fclose(fp);
|
||||
exit(0);
|
||||
}
|
||||
@@ -1,18 +0,0 @@
|
||||
This is a set of utilities that when used together create rsa keys in
|
||||
a PKCS11 keystore. The keys will have a label of "zone,zsk|ksk,xxx" and
|
||||
an id of the keytag in hex.
|
||||
|
||||
Run genkey.sh to generate a new key and call the other programs in turn.
|
||||
Run writekey.sh to load key to the key store from Kxxx.{key,private}.
|
||||
|
||||
genkey[.c] uses PKCS11 calls to generate keys.
|
||||
PEM_write_pubkey[.c] uses OpenSSL to write a public key from the key store
|
||||
into a file in PEM format.
|
||||
keyconv.pl uses Net::DNS::SEC to calculate the key tag and to write out
|
||||
a DNSKEY RR into a file.
|
||||
set_key_id[.c] uses PKCS11 to set to the key id == keytag in the key store.
|
||||
readkey[.c] and writekey[.c] extracts and loads a key from/to the key store.
|
||||
keydump.pl uses Net::DNS::SEC to get the key from a Kxxx.private file and
|
||||
write it into a file in PEM format.
|
||||
|
||||
listobjs and destroyobjs browse the key store, prints or destroys objects.
|
||||
@@ -1,183 +0,0 @@
|
||||
/* destroyobj [-s $slot] [-i $id | -l $label] [-p $pin] */
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
CK_BYTE attr_id[2];
|
||||
CK_OBJECT_HANDLE akey[50];
|
||||
char *label = NULL;
|
||||
int error = 0;
|
||||
int id = 0, i = 0;
|
||||
int c, errflg = 0;
|
||||
CK_ULONG ulObjectCount;
|
||||
CK_ATTRIBUTE search_template[] = {
|
||||
{CKA_ID, &attr_id, sizeof(attr_id)}
|
||||
};
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":s:i:l:p:")) != -1) {
|
||||
switch (c) {
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'i':
|
||||
id = atoi(optarg);
|
||||
id &= 0xffff;
|
||||
break;
|
||||
case 'l':
|
||||
label = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if (errflg || ((!id) && (!label))) {
|
||||
fprintf(stderr,
|
||||
"usage: destroykey [-s slot] [-i id | -l label] [-p pin]\n");
|
||||
exit(1);
|
||||
}
|
||||
if (id) {
|
||||
printf("id %i\n", id);
|
||||
attr_id[0] = (id >> 8) & 0xff;
|
||||
attr_id[1] = id & 0xff;
|
||||
} else if (label) {
|
||||
printf("label %s\n", label);
|
||||
search_template[0].type = CKA_LABEL;
|
||||
search_template[0].pValue = label;
|
||||
search_template[0].ulValueLen = strlen(label);
|
||||
}
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_RW_SESSION+CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
rv = C_FindObjectsInit(hSession, search_template,
|
||||
((id != 0) || (label != NULL)) ? 1 : 0);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
rv = C_FindObjects(hSession, akey, 50, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
for (i = 0; i < ulObjectCount; i++) {
|
||||
CK_OBJECT_CLASS oclass = 0;
|
||||
CK_BYTE labelbuf[64 + 1];
|
||||
CK_BYTE idbuf[64];
|
||||
CK_ATTRIBUTE attr_template[] = {
|
||||
{CKA_CLASS, &oclass, sizeof(oclass)},
|
||||
{CKA_LABEL, labelbuf, sizeof(labelbuf) - 1},
|
||||
{CKA_ID, idbuf, sizeof(idbuf)}
|
||||
};
|
||||
int j, len;
|
||||
|
||||
memset(labelbuf, 0, sizeof(labelbuf));
|
||||
memset(idbuf, 0, sizeof(idbuf));
|
||||
|
||||
rv = C_GetAttributeValue(hSession, akey[i], attr_template, 3);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_GetAttributeValue[%d]: rv = 0x%.8X\n", i, rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
len = attr_template[2].ulValueLen;
|
||||
printf("object[%d]: class %d label '%s' id[%u] ",
|
||||
i, oclass, labelbuf, attr_template[2].ulValueLen);
|
||||
if (len > 4)
|
||||
len = 4;
|
||||
for (j = 0; j < len; j++)
|
||||
printf("%02x", idbuf[j]);
|
||||
if (attr_template[2].ulValueLen > len)
|
||||
printf("...\n");
|
||||
else
|
||||
printf("\n");
|
||||
}
|
||||
|
||||
/* give a chance to kill this */
|
||||
printf("sleeping 5 seconds...\n");
|
||||
sleep(5);
|
||||
|
||||
for (i = 0; i < ulObjectCount; i++) {
|
||||
rv = C_DestroyObject(hSession, akey[i]);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_DestroyObject[%d]: rv = 0x%.8X\n", i, rv);
|
||||
error = 1;
|
||||
}
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
|
||||
exit(error);
|
||||
}
|
||||
@@ -1,206 +0,0 @@
|
||||
/* genkey - pkcs11 rsa key generator
|
||||
*
|
||||
* create RSASHA1 key in the keystore of an SCA6000
|
||||
* The calculation of key tag is left to the script
|
||||
* that converts the key into a DNSKEY RR and inserts
|
||||
* it into a zone file.
|
||||
*
|
||||
* usage:
|
||||
* genkey [-P] [-s slot] -b keysize -l label [-p pin]
|
||||
*
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
|
||||
/* Define static key template values */
|
||||
static CK_BBOOL truevalue = TRUE;
|
||||
static CK_BBOOL falsevalue = FALSE;
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_MECHANISM genmech;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
CK_ULONG modulusbits = 0;
|
||||
CK_CHAR *label = NULL;
|
||||
CK_OBJECT_HANDLE privatekey, publickey;
|
||||
CK_BYTE public_exponent[3];
|
||||
int error = 0;
|
||||
int i = 0;
|
||||
int c, errflg = 0;
|
||||
int hide = 1;
|
||||
CK_ULONG ulObjectCount;
|
||||
/* Set search template */
|
||||
CK_ATTRIBUTE search_template[] = {
|
||||
{CKA_LABEL, NULL_PTR, 0}
|
||||
};
|
||||
CK_ATTRIBUTE publickey_template[] = {
|
||||
{CKA_LABEL, NULL_PTR, 0},
|
||||
{CKA_VERIFY, &truevalue, sizeof (truevalue)},
|
||||
{CKA_TOKEN, &truevalue, sizeof (truevalue)},
|
||||
{CKA_MODULUS_BITS, &modulusbits, sizeof (modulusbits)},
|
||||
{CKA_PUBLIC_EXPONENT, &public_exponent, sizeof (public_exponent)}
|
||||
};
|
||||
CK_ATTRIBUTE privatekey_template[] = {
|
||||
{CKA_LABEL, NULL_PTR, 0},
|
||||
{CKA_SIGN, &truevalue, sizeof (truevalue)},
|
||||
{CKA_TOKEN, &truevalue, sizeof (truevalue)},
|
||||
{CKA_PRIVATE, &truevalue, sizeof (truevalue)},
|
||||
{CKA_SENSITIVE, &truevalue, sizeof (truevalue)},
|
||||
{CKA_EXTRACTABLE, &falsevalue, sizeof (falsevalue)}
|
||||
};
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":Ps:b:i:l:p:")) != -1) {
|
||||
switch (c) {
|
||||
case 'P':
|
||||
hide = 0;
|
||||
break;
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'b':
|
||||
modulusbits = atoi(optarg);
|
||||
break;
|
||||
case 'l':
|
||||
label = (CK_CHAR *)optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if ((errflg) || (!modulusbits) || (!label)) {
|
||||
fprintf(stderr,
|
||||
"usage: genkey [-P] [-s slot] -b keysize -l label [-p pin]\n");
|
||||
exit(2);
|
||||
}
|
||||
|
||||
search_template[0].pValue = label;
|
||||
search_template[0].ulValueLen = strlen((char *)label);
|
||||
publickey_template[0].pValue = label;
|
||||
publickey_template[0].ulValueLen = strlen((char *)label);
|
||||
privatekey_template[0].pValue = label;
|
||||
privatekey_template[0].ulValueLen = strlen((char *)label);
|
||||
|
||||
/* Set public exponent to 65537 */
|
||||
public_exponent[0] = 0x01;
|
||||
public_exponent[1] = 0x00;
|
||||
public_exponent[2] = 0x01;
|
||||
|
||||
/* Set up mechanism for generating key pair */
|
||||
genmech.mechanism = CKM_RSA_PKCS_KEY_PAIR_GEN;
|
||||
genmech.pParameter = NULL_PTR;
|
||||
genmech.ulParameterLen = 0;
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_RW_SESSION+CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
/* check if a key with the same id already exists */
|
||||
rv = C_FindObjectsInit(hSession, search_template, 1);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
rv = C_FindObjects(hSession, &privatekey, 1, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
if (ulObjectCount != 0) {
|
||||
fprintf(stderr, "Key already exists.\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
/* Set attributes if the key is not to be hidden */
|
||||
if (!hide) {
|
||||
privatekey_template[4].pValue = &falsevalue;
|
||||
privatekey_template[5].pValue = &truevalue;
|
||||
}
|
||||
|
||||
/* Generate Key pair for signing/verifying */
|
||||
rv = C_GenerateKeyPair(hSession, &genmech, publickey_template,
|
||||
(sizeof (publickey_template) /
|
||||
sizeof (CK_ATTRIBUTE)),
|
||||
privatekey_template,
|
||||
(sizeof (privatekey_template) /
|
||||
sizeof (CK_ATTRIBUTE)),
|
||||
&publickey, &privatekey);
|
||||
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_GenerateKeyPair: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
|
||||
exit(error);
|
||||
}
|
||||
@@ -1,55 +0,0 @@
|
||||
#!/usr/bin/bash
|
||||
|
||||
usage="Usage: $0 -z zone -x ext -p pin -b bits -e engine [-f] -k key_path"
|
||||
tmp_file=/tmp/cur_key.$$
|
||||
while getopts ":z:x:p:t:k:b:e:f" opt; do
|
||||
case $opt in
|
||||
z ) zone=$OPTARG ;;
|
||||
x ) ext=$OPTARG ;;
|
||||
p ) pin=$OPTARG ;;
|
||||
t ) id=$OPTARG ;;
|
||||
f ) flag="ksk" ;;
|
||||
e ) engine=$OPTARG ;;
|
||||
b ) bits=$OPTARG ;;
|
||||
k ) key_path=$OPTARG ;;
|
||||
\? ) echo $usage
|
||||
exit 1 ;;
|
||||
esac
|
||||
done
|
||||
shift $(($OPTIND -1))
|
||||
|
||||
if [ ! "$zone" -o ! "$ext" -o ! "$pin" -o ! "$engine" -o ! "$bits" -o ! "$key_path" ] ; then
|
||||
echo $usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ "$flag" ] ; then
|
||||
label="$zone,$flag,$ext"
|
||||
else
|
||||
label="$zone,zsk,$ext"
|
||||
fi
|
||||
|
||||
# for testing
|
||||
mypath=.
|
||||
|
||||
echo "Generating key"
|
||||
$mypath/genkey -b $bits -l $label -p $pin
|
||||
if [ $? -ne 0 ] ; then exit 1 ; fi
|
||||
|
||||
echo "Exporting public key"
|
||||
$mypath/PEM_write_pubkey -e $engine -p $pin -k pkcs11:$label -f $tmp_file
|
||||
if [ $? -ne 0 ] ; then exit 1 ; fi
|
||||
|
||||
echo "Generating DNSKEY RR"
|
||||
if [ "$flag" ] ; then
|
||||
keytag=`$mypath/keyconv.pl -a 5 -k -e $engine -l $label -p $key_path -i $tmp_file $zone`
|
||||
else
|
||||
keytag=`$mypath/keyconv.pl -a 5 -e $engine -l $label -p $key_path -i $tmp_file $zone`
|
||||
fi
|
||||
|
||||
if [ ! $keytag ] ; then rm $tmp_file; exit 1 ; fi
|
||||
|
||||
echo "Set key id"
|
||||
$mypath/set_key_id -l $label -n $keytag -p $pin
|
||||
|
||||
rm $tmp_file
|
||||
@@ -1,61 +0,0 @@
|
||||
#!/usr/bin/perl -w
|
||||
|
||||
use strict;
|
||||
use Crypt::OpenSSL::RSA;
|
||||
use Getopt::Std;
|
||||
use MIME::Base64;
|
||||
use Net::DNS;
|
||||
use Net::DNS::SEC;
|
||||
|
||||
my %option;
|
||||
getopts('a:e:i:l:p:hk',\%option);
|
||||
|
||||
die "usage: keyconv.pl [-a alg] [-k (to indicate KSK)] -e engine -l label [-p (path to store key)] -i filename domainname\n" if $option{h} || (not defined $option{i}) || (not defined $option{e}) || (not defined $option{l});
|
||||
|
||||
# The default path is local.
|
||||
$option{p} || ($option{p}="./");
|
||||
|
||||
# The default algorithm is 5.
|
||||
$option{a} || ($option{a}=5);
|
||||
|
||||
$option{k} || ($option{k}=0);
|
||||
|
||||
# The algorithm is either 5 or 133.
|
||||
$option{a}==5 || $option{a}==133 || die "algorithm must be 5 or 133\n";
|
||||
|
||||
# standard flags (value is 256) plus optionally the KSK flag.
|
||||
my $flags=(256 + $option{k});
|
||||
|
||||
open(PFILE, $option{i});
|
||||
my @fc = <PFILE>;
|
||||
close(PFILE);
|
||||
|
||||
my $rsa = Crypt::OpenSSL::RSA->new_public_key(join "", @fc);
|
||||
|
||||
my ($m,$e)= $rsa->get_key_parameters;
|
||||
|
||||
(my $l=pack("Cn",0,length($e->to_bin))) =~ s/^\000{2}//;
|
||||
|
||||
my $rrkey=$l.$e->to_bin.$m->to_bin;
|
||||
my $keystr = $ARGV[0]. ". IN DNSKEY $flags 3 $option{a} ".encode_base64($rrkey,"");
|
||||
my $keyrr = Net::DNS::RR->new($keystr);
|
||||
|
||||
open(PFILE, "> $option{p}/K".$ARGV[0].".+".sprintf("%03d",$option{a})."+".$keyrr->keytag.".key");
|
||||
print PFILE $ARGV[0], ". IN DNSKEY $flags 3 $option{a} ",encode_base64($rrkey,"")."\n";
|
||||
close(PFILE);
|
||||
|
||||
open(PFILE, "> $option{p}/K".$ARGV[0].".+".sprintf("%03d",$option{a})."+".$keyrr->keytag.".private");
|
||||
print PFILE "Private-key-format: v1.2\n";
|
||||
print PFILE "Algorithm: ", $option{a}, " (RSASHA1)\n";
|
||||
print PFILE "Modulus: ".encode_base64($m->to_bin,"")."\n";
|
||||
print PFILE "PublicExponent: ".encode_base64($e->to_bin,"")."\n";
|
||||
my $engine="";
|
||||
$engine=encode_base64($option{e}."\0","");
|
||||
print PFILE "Engine: ", $engine, "\n";
|
||||
my $label="";
|
||||
$option{k}==0 && ($label=encode_base64($option{e}.":".$option{l}."\0",""));
|
||||
$option{k}!=0 && ($label=encode_base64($option{e}.":".$option{l}."\0",""));
|
||||
print PFILE "Label: ", $label, "\n";
|
||||
close(PFILE);
|
||||
|
||||
print $keyrr->keytag;
|
||||
@@ -1,26 +0,0 @@
|
||||
#!/usr/bin/perl -w
|
||||
|
||||
use strict;
|
||||
use Getopt::Std;
|
||||
use Crypt::OpenSSL::RSA;
|
||||
use Net::DNS::SEC;
|
||||
|
||||
my %option;
|
||||
getopts('k:p:o:h',\%option);
|
||||
|
||||
$option{h} || (not defined $option{k}) || (not defined $option{p}) || (not defined $option{o}) && die "usage: keydump.pl -k Kxxx.key -p Kxxx.priv -o pem\n";
|
||||
|
||||
my $rsa = Net::DNS::SEC::Private->new($option{p});
|
||||
|
||||
open(PFILE, "> $option{o}");
|
||||
print PFILE $rsa->dump_rsa_private_der;
|
||||
close(PFILE);
|
||||
|
||||
open(KFILE, "< $option{k}");
|
||||
my @fc = <KFILE>;
|
||||
close(KFILE);
|
||||
|
||||
my $keyrr = Net::DNS::RR->new(join "", @fc);
|
||||
|
||||
print $keyrr->flags;
|
||||
|
||||
@@ -1,197 +0,0 @@
|
||||
/* listobjs [-P] [-s slot] [-i $id | -l $label] [-p $pin] */
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
CK_BYTE attr_id[2];
|
||||
CK_OBJECT_HANDLE akey[50];
|
||||
char *label = NULL;
|
||||
int error = 0, public = 0, all = 0;
|
||||
int i = 0, id = 0;
|
||||
int c, errflg = 0;
|
||||
CK_ULONG ulObjectCount;
|
||||
CK_ATTRIBUTE search_template[] = {
|
||||
{CKA_ID, &attr_id, sizeof(attr_id)}
|
||||
};
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":s:i:l:p:P")) != -1) {
|
||||
switch (c) {
|
||||
case 'P':
|
||||
public = 1;
|
||||
break;
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'i':
|
||||
id = atoi(optarg);
|
||||
id &= 0xffff;
|
||||
break;
|
||||
case 'l':
|
||||
label = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if (errflg) {
|
||||
fprintf(stderr,
|
||||
"usage: listobjs [-P] [-s slot] [-p pin] -i id | $label\n");
|
||||
exit(1);
|
||||
}
|
||||
if ((!id) && (!label))
|
||||
all = 1;
|
||||
if (slot)
|
||||
printf("slot %d\n", slot);
|
||||
if (id) {
|
||||
printf("id %i\n", id);
|
||||
attr_id[0] = (id >> 8) & 0xff;
|
||||
attr_id[1] = id & 0xff;
|
||||
} else if (label) {
|
||||
printf("label %s\n", label);
|
||||
search_template[0].type = CKA_LABEL;
|
||||
search_template[0].pValue = label;
|
||||
search_template[0].ulValueLen = strlen(label);
|
||||
}
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!public) {
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
}
|
||||
|
||||
rv = C_FindObjectsInit(hSession, search_template, all ? 0 : 1);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
ulObjectCount = 1;
|
||||
while (ulObjectCount) {
|
||||
rv = C_FindObjects(hSession, akey, 50, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
for (i = 0; i < ulObjectCount; i++) {
|
||||
CK_OBJECT_CLASS oclass = 0;
|
||||
CK_BYTE labelbuf[64 + 1];
|
||||
CK_BYTE idbuf[64];
|
||||
CK_ATTRIBUTE attr_template[] = {
|
||||
{CKA_CLASS, &oclass, sizeof(oclass)},
|
||||
{CKA_LABEL, labelbuf, sizeof(labelbuf) - 1},
|
||||
{CKA_ID, idbuf, sizeof(idbuf)}
|
||||
};
|
||||
int j, len;
|
||||
|
||||
memset(labelbuf, 0, sizeof(labelbuf));
|
||||
memset(idbuf, 0, sizeof(idbuf));
|
||||
|
||||
rv = C_GetAttributeValue(hSession, akey[i], attr_template, 3);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr,
|
||||
"C_GetAttributeValue[%d]: rv = 0x%.8X\n", i, rv);
|
||||
if (rv = CKR_BUFFER_TOO_SMALL)
|
||||
fprintf(stderr, "%d too small: %u %u %u\n", i,
|
||||
attr_template[0].ulValueLen,
|
||||
attr_template[1].ulValueLen,
|
||||
attr_template[2].ulValueLen);
|
||||
error = 1;
|
||||
continue;
|
||||
}
|
||||
|
||||
len = attr_template[2].ulValueLen;
|
||||
printf("object[%d]: handle %u class %d label[%u] '%s' id[%u] ",
|
||||
i, akey[i], oclass,
|
||||
attr_template[1].ulValueLen, labelbuf,
|
||||
attr_template[2].ulValueLen);
|
||||
if (len == 2) {
|
||||
id = (idbuf[0] << 8) & 0xff00;
|
||||
id |= idbuf[1] & 0xff;
|
||||
printf("%i\n", id);
|
||||
} else {
|
||||
if (len > 8)
|
||||
len = 8;
|
||||
for (j = 0; j < len; j++)
|
||||
printf("%02x", idbuf[j]);
|
||||
if (attr_template[2].ulValueLen > len)
|
||||
printf("...\n");
|
||||
else
|
||||
printf("\n");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
|
||||
exit(error);
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,230 +0,0 @@
|
||||
/* readkey [-s $slot] -l $label [-p $pin] -f $filename */
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
#include <openssl/conf.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rsa.h>
|
||||
#include <openssl/pem.h>
|
||||
|
||||
static CK_BBOOL truevalue = TRUE;
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
RSA *rsa = NULL;
|
||||
FILE *fp;
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
char *label;
|
||||
CK_OBJECT_HANDLE key = CK_INVALID_HANDLE;
|
||||
CK_OBJECT_CLASS kclass = CKO_PRIVATE_KEY;
|
||||
char *filename;
|
||||
int error = 0;
|
||||
int i = 0;
|
||||
int c, errflg = 0;
|
||||
CK_ULONG ulObjectCount;
|
||||
CK_ATTRIBUTE search_template[] = {
|
||||
{CKA_LABEL, NULL, 0},
|
||||
{CKA_TOKEN, &truevalue, sizeof (truevalue)},
|
||||
{CKA_CLASS, &kclass, sizeof (kclass)}
|
||||
};
|
||||
CK_BYTE id[32];
|
||||
CK_BYTE data[8][1024];
|
||||
CK_ATTRIBUTE attr_template[] = {
|
||||
{CKA_ID, &id, sizeof (id)},
|
||||
{CKA_MODULUS, (void *)data[0], 1024}, /* n */
|
||||
{CKA_PUBLIC_EXPONENT, (void *)data[1], 1024}, /* e */
|
||||
{CKA_PRIVATE_EXPONENT, (void *)data[2], 1024}, /* d */
|
||||
{CKA_PRIME_1, (void *)data[3], 1024}, /* p */
|
||||
{CKA_PRIME_2, (void *)data[4], 1024}, /* q */
|
||||
{CKA_EXPONENT_1, (void *)data[5], 1024}, /* dmp1 */
|
||||
{CKA_EXPONENT_2, (void *)data[6], 1024}, /* dmq1 */
|
||||
{CKA_COEFFICIENT, (void *)data[7], 1024} /* iqmp */
|
||||
};
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":s:l:p:f:")) != -1) {
|
||||
switch (c) {
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'l':
|
||||
label = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case 'f':
|
||||
filename = optarg;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if ((errflg) || (!label) || (!filename)) {
|
||||
fprintf(stderr,
|
||||
"usage: readkey [-s slot] -l label [-p pin] -f filename\n");
|
||||
exit(1);
|
||||
}
|
||||
if (slot)
|
||||
printf("slot %d\n", slot);
|
||||
|
||||
/* Initialize OpenSSL library */
|
||||
OPENSSL_config(NULL);
|
||||
rsa = RSA_new();
|
||||
if (!rsa) {
|
||||
fprintf(stderr, "RSA_new failed\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
if ((rv != CKR_OK) && (rv != CKR_CRYPTOKI_ALREADY_INITIALIZED)) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
/* Set search template. */
|
||||
if (strstr(label, "pkcs11:") == label)
|
||||
label = strstr(label, ":") + 1;
|
||||
search_template[0].pValue = label;
|
||||
search_template[0].ulValueLen = strlen(label);
|
||||
|
||||
rv = C_FindObjectsInit(hSession, search_template, 3);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
rv = C_FindObjects(hSession, &key, 1, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
if (ulObjectCount == 0) {
|
||||
fprintf(stderr, "C_FindObjects: can't find the key\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
rv = C_GetAttributeValue(hSession, key, attr_template, 9);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_GetAttributeValue: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
printf("ID[%u]=", attr_template[0].ulValueLen);
|
||||
for (i = 0; i < attr_template[0].ulValueLen; i++)
|
||||
printf("%02x", id[i]);
|
||||
printf("\n");
|
||||
|
||||
if (attr_template[1].ulValueLen > 0)
|
||||
rsa->n = BN_bin2bn(data[0], attr_template[1].ulValueLen, NULL);
|
||||
if (attr_template[2].ulValueLen > 0)
|
||||
rsa->e = BN_bin2bn(data[1], attr_template[2].ulValueLen, NULL);
|
||||
if (attr_template[3].ulValueLen > 0)
|
||||
rsa->d = BN_bin2bn(data[2], attr_template[3].ulValueLen, NULL);
|
||||
if (attr_template[4].ulValueLen > 0)
|
||||
rsa->p = BN_bin2bn(data[3], attr_template[4].ulValueLen, NULL);
|
||||
if (attr_template[5].ulValueLen > 0)
|
||||
rsa->q = BN_bin2bn(data[4], attr_template[5].ulValueLen, NULL);
|
||||
if (attr_template[6].ulValueLen > 0)
|
||||
rsa->dmp1 = BN_bin2bn(data[5], attr_template[6].ulValueLen, NULL);
|
||||
if (attr_template[7].ulValueLen > 0)
|
||||
rsa->dmq1 = BN_bin2bn(data[6], attr_template[7].ulValueLen, NULL);
|
||||
if (attr_template[8].ulValueLen > 0)
|
||||
rsa->iqmp = BN_bin2bn(data[7], attr_template[8].ulValueLen, NULL);
|
||||
|
||||
rv = C_FindObjects(hSession, &key, 1, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
if (ulObjectCount != 0) {
|
||||
fprintf(stderr, "C_FindObjects: found extra keys?\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
printf("RSA=");
|
||||
RSA_print_fp(stdout, rsa, 4);
|
||||
|
||||
fp = fopen(filename, "w");
|
||||
if (fp == NULL) {
|
||||
printf("Error opening output file.\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
if (!PEM_write_RSAPrivateKey(fp, rsa, NULL, NULL, 0, NULL, NULL)) {
|
||||
printf("Error writing output file.\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
|
||||
exit(error);
|
||||
}
|
||||
@@ -1,159 +0,0 @@
|
||||
/* set_key_id [-s slot] [-p $pin] -n $keytag {-i $id | -l $label} */
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
CK_BYTE old_id[2], new_id[2];
|
||||
CK_OBJECT_HANDLE akey;
|
||||
int error = 0;
|
||||
int i = 0;
|
||||
int c, errflg = 0;
|
||||
char *label = NULL;
|
||||
CK_ULONG ulObjectCount;
|
||||
int oid = 0, nid = 0;
|
||||
CK_ATTRIBUTE search_template[] = {
|
||||
{CKA_ID, &old_id, sizeof(old_id)}
|
||||
};
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":s:i:n:l:p:")) != -1) {
|
||||
switch (c) {
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'i':
|
||||
oid = atoi(optarg);
|
||||
oid &= 0xffff;
|
||||
old_id[0] = (oid >> 8) & 0xff;
|
||||
old_id[1] = oid & 0xff;
|
||||
break;
|
||||
case 'n':
|
||||
nid = atoi(optarg);
|
||||
nid &= 0xffff;
|
||||
new_id[0] = (nid >> 8) & 0xff;
|
||||
new_id[1] = nid & 0xff;
|
||||
break;
|
||||
case 'l':
|
||||
label = optarg;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if ((errflg) || (!nid) || ((!oid) && (!label))) {
|
||||
fprintf(stderr,
|
||||
"usage: set_key_id [-s slot] [-p pin] -n new_id "
|
||||
"{ -i old_id | -l label }\n");
|
||||
exit(1);
|
||||
}
|
||||
if (!label)
|
||||
printf("old %i new %i\n", oid, nid);
|
||||
else {
|
||||
printf("label %s new %i\n", label, nid);
|
||||
search_template[0].type = CKA_LABEL;
|
||||
search_template[0].pValue = label;
|
||||
search_template[0].ulValueLen = strlen(label);
|
||||
}
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_RW_SESSION+CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
rv = C_FindObjectsInit(hSession, search_template, 1);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
ulObjectCount = 1;
|
||||
while(ulObjectCount) {
|
||||
rv = C_FindObjects(hSession, &akey, 1, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
} else if (ulObjectCount) {
|
||||
/* Set update template. */
|
||||
CK_ATTRIBUTE new_template[] = {
|
||||
{CKA_ID, &new_id, sizeof(new_id)}
|
||||
};
|
||||
|
||||
rv = C_SetAttributeValue(hSession, akey, new_template, 1);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_SetAttributeValue: rv = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
|
||||
exit(error);
|
||||
}
|
||||
@@ -1,360 +0,0 @@
|
||||
/* writekey [-s $slot] [-p $pin] -l $label -i $id -f $filename */
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <unistd.h>
|
||||
#include <fcntl.h>
|
||||
#include <errno.h>
|
||||
#include <string.h>
|
||||
#include <sys/types.h>
|
||||
#ifndef OPENCRYPTOKI
|
||||
#include <security/cryptoki.h>
|
||||
#include <security/pkcs11.h>
|
||||
#else
|
||||
#include <opencryptoki/pkcs11.h>
|
||||
#endif
|
||||
#include <openssl/conf.h>
|
||||
#include <openssl/engine.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rsa.h>
|
||||
#include <openssl/pem.h>
|
||||
|
||||
/* Define static key template values */
|
||||
static CK_BBOOL truevalue = TRUE;
|
||||
static CK_BBOOL falsevalue = FALSE;
|
||||
|
||||
int
|
||||
main(int argc, char *argv[])
|
||||
{
|
||||
ENGINE *e;
|
||||
RSA *rsa = NULL;
|
||||
FILE *fp;
|
||||
CK_RV rv;
|
||||
CK_SLOT_ID slot = 0;
|
||||
CK_SESSION_HANDLE hSession;
|
||||
CK_UTF8CHAR *pin = NULL;
|
||||
CK_BYTE new_id[2];
|
||||
CK_OBJECT_HANDLE key = CK_INVALID_HANDLE;
|
||||
CK_OBJECT_CLASS kclass;
|
||||
CK_KEY_TYPE ktype = CKK_RSA;
|
||||
CK_ATTRIBUTE template[50];
|
||||
CK_ULONG template_size;
|
||||
CK_BYTE data[8][1024];
|
||||
CK_ULONG ulObjectCount;
|
||||
char *label = NULL, *filename = NULL;
|
||||
int id = 0;
|
||||
int error = 0;
|
||||
int c, errflg = 0;
|
||||
extern char *optarg;
|
||||
extern int optopt;
|
||||
|
||||
while ((c = getopt(argc, argv, ":s:l:i:p:f:")) != -1) {
|
||||
switch (c) {
|
||||
case 's':
|
||||
slot = atoi(optarg);
|
||||
break;
|
||||
case 'l':
|
||||
label = optarg;
|
||||
break;
|
||||
case 'i':
|
||||
id = atoi(optarg);
|
||||
id &= 0xffff;
|
||||
break;
|
||||
case 'p':
|
||||
pin = (CK_UTF8CHAR *)optarg;
|
||||
break;
|
||||
case 'f':
|
||||
filename = optarg;
|
||||
break;
|
||||
case ':':
|
||||
fprintf(stderr, "Option -%c requires an operand\n", optopt);
|
||||
errflg++;
|
||||
break;
|
||||
case '?':
|
||||
default:
|
||||
fprintf(stderr, "Unrecognised option: -%c\n", optopt);
|
||||
errflg++;
|
||||
}
|
||||
}
|
||||
if ((errflg) || (!label) || (!id) || (!filename)) {
|
||||
fprintf(stderr,
|
||||
"usage: writekey [-s slot] [-p pin] -l label -i id "
|
||||
"-f filename\n");
|
||||
exit(2);
|
||||
}
|
||||
|
||||
/* Load the config file */
|
||||
OPENSSL_config(NULL);
|
||||
|
||||
/* Register engine */
|
||||
e = ENGINE_by_id("pkcs11");
|
||||
if (!e) {
|
||||
/* the engine isn't available */
|
||||
printf("The engine isn't available\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (!ENGINE_init(e)) {
|
||||
/* the engine couldn't initialise, release 'e' */
|
||||
printf("The engine couldn't initialise\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Read the key */
|
||||
fp = fopen(filename, "r");
|
||||
if (fp == NULL) {
|
||||
printf("Error opening input file.\n");
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
rsa = PEM_read_RSAPrivateKey(fp, NULL, NULL, NULL);
|
||||
(void) fclose(fp);
|
||||
if (rsa == NULL) {
|
||||
printf("Error reading input file.\n");
|
||||
ERR_print_errors_fp(stderr);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Initialize the CRYPTOKI library */
|
||||
rv = C_Initialize(NULL_PTR);
|
||||
if ((rv != CKR_OK) && (rv != CKR_CRYPTOKI_ALREADY_INITIALIZED)) {
|
||||
fprintf(stderr, "C_Initialize: Error = 0x%.8X\n", rv);
|
||||
ENGINE_free(e);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/* Open a session on the slot found */
|
||||
rv = C_OpenSession(slot, CKF_RW_SESSION+CKF_SERIAL_SESSION,
|
||||
NULL_PTR, NULL_PTR, &hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_OpenSession: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_program;
|
||||
}
|
||||
|
||||
/* Login to the Token (Keystore) */
|
||||
if (!pin)
|
||||
#ifndef OPENCRYPTOKI
|
||||
pin = (CK_UTF8CHAR *)getpassphrase("Enter Pin: ");
|
||||
#else
|
||||
pin = (CK_UTF8CHAR *)getpass("Enter Pin: ");
|
||||
#endif
|
||||
rv = C_Login(hSession, CKU_USER, pin, strlen((char *)pin));
|
||||
memset(pin, 0, strlen((char *)pin));
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_Login: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
|
||||
/* fill the search template */
|
||||
if (strstr(label, "pkcs11:") == label)
|
||||
label = strstr(label, ":") + 1;
|
||||
kclass = CKO_PRIVATE_KEY;
|
||||
template[0].type = CKA_TOKEN;
|
||||
template[0].pValue = &truevalue;
|
||||
template[0].ulValueLen = sizeof (truevalue);
|
||||
template[1].type = CKA_CLASS;
|
||||
template[1].pValue = &kclass;
|
||||
template[1].ulValueLen = sizeof (kclass);
|
||||
template[2].type = CKA_LABEL;
|
||||
template[2].pValue = label;
|
||||
template[2].ulValueLen = strlen(label);
|
||||
|
||||
/* check if a key with the same label already exists */
|
||||
rv = C_FindObjectsInit(hSession, template, 3);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsInit: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_session;
|
||||
}
|
||||
rv = C_FindObjects(hSession, &key, 1, &ulObjectCount);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjects: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
if (ulObjectCount != 0) {
|
||||
fprintf(stderr, "Key already exists.\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
/* fill attributes for the public key */
|
||||
new_id[0] = (id >> 8) & 0xff;
|
||||
new_id[1] = id & 0xff;
|
||||
kclass = CKO_PUBLIC_KEY;
|
||||
if (BN_num_bytes(rsa->n) > 1024) {
|
||||
fprintf(stderr, "RSA modulus too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->n, data[0]);
|
||||
if (BN_num_bytes(rsa->e) > 1024) {
|
||||
fprintf(stderr, "RSA public exponent too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->e, data[1]);
|
||||
if (BN_num_bytes(rsa->d) > 1024) {
|
||||
fprintf(stderr, "RSA private exponent too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->d, data[2]);
|
||||
if (BN_num_bytes(rsa->p) > 1024) {
|
||||
fprintf(stderr, "RSA prime 1 too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->p, data[3]);
|
||||
if (BN_num_bytes(rsa->q) > 1024) {
|
||||
fprintf(stderr, "RSA prime 2 too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->q, data[4]);
|
||||
if (BN_num_bytes(rsa->dmp1) > 1024) {
|
||||
fprintf(stderr, "RSA exponent 1 too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->dmp1, data[5]);
|
||||
if (BN_num_bytes(rsa->dmq1) > 1024) {
|
||||
fprintf(stderr, "RSA exponent 2 too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->dmq1, data[6]);
|
||||
if (BN_num_bytes(rsa->iqmp) > 1024) {
|
||||
fprintf(stderr, "RSA coefficient too large\n");
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
BN_bn2bin(rsa->iqmp, data[7]);
|
||||
|
||||
template[0].type = CKA_TOKEN;
|
||||
template[0].pValue = &truevalue;
|
||||
template[0].ulValueLen = sizeof (truevalue);
|
||||
template[1].type = CKA_CLASS;
|
||||
template[1].pValue = &kclass;
|
||||
template[1].ulValueLen = sizeof (kclass);
|
||||
template[2].type = CKA_LABEL;
|
||||
template[2].pValue = label;
|
||||
template[2].ulValueLen = strlen(label);
|
||||
template[3].type = CKA_ID;
|
||||
template[3].pValue = new_id;
|
||||
template[3].ulValueLen = sizeof (new_id);
|
||||
template[4].type = CKA_KEY_TYPE;
|
||||
template[4].pValue = &ktype;
|
||||
template[4].ulValueLen = sizeof (ktype);
|
||||
template[5].type = CKA_ENCRYPT;
|
||||
template[5].pValue = &truevalue;
|
||||
template[5].ulValueLen = sizeof (truevalue);
|
||||
template[6].type = CKA_VERIFY;
|
||||
template[6].pValue = &truevalue;
|
||||
template[6].ulValueLen = sizeof (truevalue);
|
||||
template[7].type = CKA_VERIFY_RECOVER;
|
||||
template[7].pValue = &truevalue;
|
||||
template[7].ulValueLen = sizeof (truevalue);
|
||||
template[8].type = CKA_MODULUS;
|
||||
template[8].pValue = data[0];
|
||||
template[8].ulValueLen = BN_num_bytes(rsa->n);
|
||||
template[9].type = CKA_PUBLIC_EXPONENT;
|
||||
template[9].pValue = data[1];
|
||||
template[9].ulValueLen = BN_num_bytes(rsa->e);
|
||||
|
||||
rv = C_CreateObject(hSession, template, 10, &key);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_CreateObject (pub): Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
/* fill attributes for the private key */
|
||||
kclass = CKO_PRIVATE_KEY;
|
||||
template[0].type = CKA_TOKEN;
|
||||
template[0].pValue = &truevalue;
|
||||
template[0].ulValueLen = sizeof (truevalue);
|
||||
template[1].type = CKA_CLASS;
|
||||
template[1].pValue = &kclass;
|
||||
template[1].ulValueLen = sizeof (kclass);
|
||||
template[2].type = CKA_LABEL;
|
||||
template[2].pValue = label;
|
||||
template[2].ulValueLen = strlen(label);
|
||||
template[3].type = CKA_ID;
|
||||
template[3].pValue = new_id;
|
||||
template[3].ulValueLen = sizeof (new_id);
|
||||
template[4].type = CKA_KEY_TYPE;
|
||||
template[4].pValue = &ktype;
|
||||
template[4].ulValueLen = sizeof (ktype);
|
||||
template[5].type = CKA_SENSITIVE;
|
||||
template[5].pValue = &falsevalue;
|
||||
template[5].ulValueLen = sizeof (falsevalue);
|
||||
template[6].type = CKA_EXTRACTABLE;
|
||||
template[6].pValue = &truevalue;
|
||||
template[6].ulValueLen = sizeof (truevalue);
|
||||
template[7].type = CKA_DECRYPT;
|
||||
template[7].pValue = &truevalue;
|
||||
template[7].ulValueLen = sizeof (truevalue);
|
||||
template[8].type = CKA_SIGN;
|
||||
template[8].pValue = &truevalue;
|
||||
template[8].ulValueLen = sizeof (truevalue);
|
||||
template[9].type = CKA_SIGN_RECOVER;
|
||||
template[9].pValue = &truevalue;
|
||||
template[9].ulValueLen = sizeof (truevalue);
|
||||
template[10].type = CKA_MODULUS;
|
||||
template[10].pValue = data[0];
|
||||
template[10].ulValueLen = BN_num_bytes(rsa->n);
|
||||
template[11].type = CKA_PUBLIC_EXPONENT;
|
||||
template[11].pValue = data[1];
|
||||
template[11].ulValueLen = BN_num_bytes(rsa->e);
|
||||
template[12].type = CKA_PRIVATE_EXPONENT;
|
||||
template[12].pValue = data[2];
|
||||
template[12].ulValueLen = BN_num_bytes(rsa->d);
|
||||
template[13].type = CKA_PRIME_1;
|
||||
template[13].pValue = data[3];
|
||||
template[13].ulValueLen = BN_num_bytes(rsa->p);
|
||||
template[14].type = CKA_PRIME_2;
|
||||
template[14].pValue = data[4];
|
||||
template[14].ulValueLen = BN_num_bytes(rsa->q);
|
||||
template[15].type = CKA_EXPONENT_1;
|
||||
template[15].pValue = data[5];
|
||||
template[15].ulValueLen = BN_num_bytes(rsa->dmp1);
|
||||
template[16].type = CKA_EXPONENT_2;
|
||||
template[16].pValue = data[6];
|
||||
template[16].ulValueLen = BN_num_bytes(rsa->dmq1);
|
||||
template[17].type = CKA_COEFFICIENT;
|
||||
template[17].pValue = data[7];
|
||||
template[17].ulValueLen = BN_num_bytes(rsa->iqmp);
|
||||
|
||||
rv = C_CreateObject(hSession, template, 18, &key);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_CreateObject (priv): Error = 0x%.8X\n", rv);
|
||||
(void) C_DestroyObject(hSession, key);
|
||||
error = 1;
|
||||
goto exit_search;
|
||||
}
|
||||
|
||||
exit_search:
|
||||
rv = C_FindObjectsFinal(hSession);
|
||||
if (rv != CKR_OK) {
|
||||
fprintf(stderr, "C_FindObjectsFinal: Error = 0x%.8X\n", rv);
|
||||
error = 1;
|
||||
}
|
||||
|
||||
exit_session:
|
||||
(void) C_CloseSession(hSession);
|
||||
|
||||
exit_program:
|
||||
(void) C_Finalize(NULL_PTR);
|
||||
ENGINE_free(e);
|
||||
ENGINE_cleanup();
|
||||
|
||||
exit(error);
|
||||
}
|
||||
@@ -1,73 +0,0 @@
|
||||
#!/bin/bash --debug
|
||||
|
||||
usage="Usage: $0 -x ext -p pin -f keyrootname"
|
||||
tmp_file=/tmp/cur_pem.$$
|
||||
while getopts ":x:p:f:" opt; do
|
||||
case $opt in
|
||||
x ) ext=$OPTARG ;;
|
||||
p ) pin=$OPTARG ;;
|
||||
f ) root=$OPTARG ;;
|
||||
\? ) echo $usage
|
||||
exit 1 ;;
|
||||
esac
|
||||
done
|
||||
shift $(($OPTIND -1))
|
||||
|
||||
if [ ! "$ext" -o ! "$pin" -o ! "$root" ] ; then
|
||||
echo $usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
keyfile=${root}.key
|
||||
privfile=${root}.private
|
||||
file=`basename $root | sed 's/^K//'`
|
||||
zone=`echo $file | awk -F+ '{ print $1 }' | sed 's/\.$//'`
|
||||
algo=`echo $file | awk -F+ '{ print $2 }'`
|
||||
tag=`echo $file | awk -F+ '{ print $3 }'`
|
||||
|
||||
# debug
|
||||
echo 'zone: ' $zone
|
||||
echo 'algo: ' $algo
|
||||
echo 'tag: ' $tag
|
||||
|
||||
if [ ! -r "$keyfile" ] ; then
|
||||
echo "can't read " $keyfile
|
||||
exit 1
|
||||
fi
|
||||
if [ ! -r "$privfile" ] ; then
|
||||
echo "can't read " $privfile
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ "$algo" != "005" ] ; then
|
||||
echo 'algorithm must be 005'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# for testing
|
||||
mypath=.
|
||||
|
||||
echo 'Reading key files'
|
||||
flag=`$mypath/keydump.pl -k $keyfile -p $privfile -o $tmp_file`
|
||||
|
||||
if [ "$flag" = "256" ] ; then
|
||||
label=$zone,zsk,$ext
|
||||
elif [ "$flag" = "257" ] ; then
|
||||
label=$zone,ksk,$ext
|
||||
else
|
||||
echo 'flag must be 256 or 257'
|
||||
rm $tmp_file
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Label will be '"$label"'"
|
||||
$mypath/writekey -p $pin -l $label -i $tag -f $tmp_file
|
||||
|
||||
rm $tmp_file
|
||||
|
||||
echo 'Now you can add at the end of ' $privfile
|
||||
/usr/bin/perl <<EOF
|
||||
use MIME::Base64;
|
||||
print "Engine: ", encode_base64("pkcs11\0",""), "\n";
|
||||
print "Label: ", encode_base64("pkcs11:"."$label"."\0",""), "\n";
|
||||
EOF
|
||||
@@ -13,4 +13,4 @@ nikhef.nl
|
||||
yahoo.com
|
||||
nic.af
|
||||
|
||||
$Id: ADDRESSES,v 1.1 2008/02/15 01:47:15 marka Exp $
|
||||
$Id: ADDRESSES,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $
|
||||
|
||||
@@ -6,4 +6,4 @@ which I provide, if not found.
|
||||
|
||||
Tested on Linux (i386 and Alpha), Solaris (Sparc) and Digital Unix (Alpha).
|
||||
|
||||
$Id: INSTALL,v 1.1 2008/02/15 01:47:15 marka Exp $
|
||||
$Id: INSTALL,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# $Id: Makefile.in,v 1.1 2008/02/15 01:47:15 marka Exp $
|
||||
# $Id: Makefile.in,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $
|
||||
CC=@CC@
|
||||
CFLAGS=@CFLAGS@
|
||||
LIBS=@LIBS@
|
||||
|
||||
@@ -16,6 +16,6 @@
|
||||
<http://www.dtek.chalmers.se/~d3august/xt/>. Thanks to Roland
|
||||
Dirlewanger for extensive patching.
|
||||
|
||||
$Id: README,v 1.1 2008/02/15 01:47:15 marka Exp $
|
||||
$Id: README,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $
|
||||
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/* config.h.in. Generated from configure.in by autoheader. */
|
||||
/* $Id: config.h.in,v 1.1 2008/02/15 01:47:15 marka Exp $ */
|
||||
/* $Id: config.h.in,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $ */
|
||||
|
||||
|
||||
/* Define to 1 if you have the <inttypes.h> header file. */
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
dnl Process this file with autoconf to produce a configure script.
|
||||
AC_RELEASE("$Id: configure.in,v 1.1 2008/02/15 01:47:15 marka Exp $")
|
||||
AC_RELEASE("$Id: configure.in,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $")
|
||||
AC_INIT(query-loc.c)
|
||||
|
||||
dnl Checks for programs.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#include "loc.h"
|
||||
|
||||
/* $Id: loc.c,v 1.1 2008/02/15 01:47:15 marka Exp $ */
|
||||
/* $Id: loc.c,v 1.1.2.1 2008/02/15 02:11:57 marka Exp $ */
|
||||
|
||||
/* Global variables */
|
||||
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user