Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b9e33d9cce | ||
|
|
e94465e304 | ||
|
|
8b9e2015f3 | ||
|
|
f64da6cabb | ||
|
|
6954eceb80 | ||
|
|
378774821a | ||
|
|
40562e37ee | ||
|
|
e7256edf67 | ||
|
|
7edff5d2bb | ||
|
|
5fd05a6d88 | ||
|
|
3009554a0b | ||
|
|
7545b00842 | ||
|
|
396772811a | ||
|
|
c0494994f0 | ||
|
|
1970f078cf | ||
|
|
376d5996a1 | ||
|
|
65a483106e | ||
|
|
5f308740df | ||
|
|
a8c1bfd673 | ||
|
|
18c7fa2f93 | ||
|
|
3f8c9d92af | ||
|
|
393135d693 | ||
|
|
82354deeb1 | ||
|
|
c22b540e4c | ||
|
|
d92d70ac5d | ||
|
|
00ff44c7c2 | ||
|
|
2f13e0ef98 | ||
|
|
a80dc538bd | ||
|
|
40a90fbf89 | ||
|
|
31b6ae485e | ||
|
|
19f6a63184 | ||
|
|
14e9925868 | ||
|
|
7bc5d7f5e8 | ||
|
|
1dc8208a89 | ||
|
|
6ead410268 | ||
|
|
a573b93b46 | ||
|
|
165df18f75 | ||
|
|
9bb32395b2 | ||
|
|
8993ecd06a | ||
|
|
2f4e0e5a81 | ||
|
|
78e1d7cdde | ||
|
|
ba613d22bf | ||
|
|
858228febe | ||
|
|
5b2b9340fe | ||
|
|
6035d557c4 | ||
|
|
900215654b | ||
|
|
445cabb392 | ||
|
|
a197094d76 | ||
|
|
f975d0acaa | ||
|
|
656eed7c9b | ||
|
|
7a0188774f | ||
|
|
bcce55197a | ||
|
|
3bfc28a0d0 | ||
|
|
6f5cc4206d | ||
|
|
e2f9dcfd86 | ||
|
|
31975d85de | ||
|
|
3d905e0533 | ||
|
|
3def40b01b | ||
|
|
04934b28ea | ||
|
|
8c1b8dd55d | ||
|
|
6bbbf12936 | ||
|
|
9eb5aa40aa | ||
|
|
f581ac4726 | ||
|
|
c0e3e1fe44 | ||
|
|
312c84c73a | ||
|
|
b231ddc65d | ||
|
|
0cba7ca6af | ||
|
|
f4b2356359 | ||
|
|
a1aa42b9cd | ||
|
|
c999531fa4 | ||
|
|
00827f59d2 | ||
|
|
e03e455cd5 | ||
|
|
a1a5145867 | ||
|
|
4034b098d8 | ||
|
|
27bf48327c | ||
|
|
c652213857 | ||
|
|
5b1e929b8b | ||
|
|
a41e41d6a4 | ||
|
|
0e29543a3d | ||
|
|
f13c1c09e9 | ||
|
|
e3d9aafff0 | ||
|
|
23b81977fe | ||
|
|
2a390b2537 | ||
|
|
e6801bf89e | ||
|
|
3300f6aeda | ||
|
|
b819a478b7 | ||
|
|
7e1df5182c | ||
|
|
72ddd51e74 | ||
|
|
c3d0ccdc8f | ||
|
|
f305a705c4 | ||
|
|
490c321e25 | ||
|
|
e7b53943fe | ||
|
|
8d23105547 | ||
|
|
95dce4e68c | ||
|
|
9bb007fd2d | ||
|
|
3b5718a8c9 | ||
|
|
40298d8bee | ||
|
|
92bbc9914c | ||
|
|
4359be18f4 | ||
|
|
0698ad8503 | ||
|
|
9b3fc207df | ||
|
|
db15f78ad7 | ||
|
|
ff30290b48 | ||
|
|
7bbb034952 | ||
|
|
a51352c4a4 | ||
|
|
37039792cb | ||
|
|
41b1a98545 | ||
|
|
dd61c4ad3e | ||
|
|
85bd975d3d | ||
|
|
ee42f734d5 | ||
|
|
6e02359034 | ||
|
|
0ed0c4b1a5 | ||
|
|
facf811847 | ||
|
|
4ae8f28711 | ||
|
|
2658ebbcba | ||
|
|
45d4d62a0c | ||
|
|
63d83632d7 | ||
|
|
40e1e659b6 | ||
|
|
f5e1b555c5 | ||
|
|
4e2ba60f3c |
@@ -1,3 +1,99 @@
|
||||
4830. [bug] Failure to configure ATF when requested did not cause
|
||||
an error in top-level configure script. [RT #46655]
|
||||
|
||||
4829. [bug] isc_heap_delete did not zero the index value when
|
||||
the heap was created with a callback to do that.
|
||||
[RT #46709]
|
||||
|
||||
4828. [bug] Do not use thread-local storage for storing LMDB reader
|
||||
locktable slots. [RT #46556]
|
||||
|
||||
4827. [misc] Add a precommit check script util/checklibs.sh
|
||||
[RT #46215]
|
||||
|
||||
4826. [cleanup] Prevent potential build failures in bin/confgen/ and
|
||||
bin/named/ when using parallel make. [RT #46648]
|
||||
|
||||
4825. [bug] Prevent a bogus "error during managed-keys processing
|
||||
(no more)" warning from being logged. [RT #46645]
|
||||
|
||||
4824. [port] Add iOS hooks to dig. [RT #42011]
|
||||
|
||||
4823. [test] Refactor reclimit system test to improve its
|
||||
reliability and speed. [RT #46632]
|
||||
|
||||
4822. [bug] Use resign_sooner in dns_db_setsigningtime. [RT #46473]
|
||||
|
||||
4821. [bug] When resigning ensure that the SOA's expire time is
|
||||
always later that the resigning time of other records.
|
||||
[RT #46473]
|
||||
|
||||
4820. [bug] dns_db_subtractrdataset should transfer the resigning
|
||||
information to the new header. [RT #46473]
|
||||
|
||||
4819. [bug] Fully backout the transaction when adding a RRset
|
||||
to the resigning / removal heaps fails. [RT #46473]
|
||||
|
||||
4818. [test] The logfileconfig system test could intermittently
|
||||
report false negatives on some platforms. [RT #46615]
|
||||
|
||||
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
|
||||
[RT #45433]
|
||||
|
||||
4816. [bug] Don't use a common array for storing EDNS options
|
||||
in DiG as it could fill up. [RT #45611]
|
||||
|
||||
4815. [bug] rbt_test.c:insert_and_delete needed to call
|
||||
dns_rbt_addnode instead of dns_rbt_addname. [RT #46553]
|
||||
|
||||
4814. [cleanup] Use AS_HELP_STRING for consistent help text. [RT #46521]
|
||||
|
||||
4813. [bug] Address potential read after free errors from
|
||||
query_synthnodata, query_synthwildcard and
|
||||
query_synthnxdomain. [RT #46547]
|
||||
|
||||
4812. [bug] Minor improvements to stability and consistency of code
|
||||
handling managed keys. [RT #46468]
|
||||
|
||||
4811. [bug] Revert api changes to use <isc/buffer.h> inline
|
||||
macros. Provide a alternative mechanism to turn
|
||||
on the use of inline macros when building BIND.
|
||||
[RT #46520]
|
||||
|
||||
4810. [test] The chain system test failed if the IPv6 interfaces
|
||||
were not configured. [RT #46508]
|
||||
|
||||
--- 9.12.0b2 released ---
|
||||
|
||||
4809. [port] Check at configure time whether -latomic is needed
|
||||
for stdatomic.h. [RT #46324]
|
||||
|
||||
4808. [bug] Properly test for zlib.h. [RT #46504]
|
||||
|
||||
4807. [cleanup] isc_rng_randombytes() returns a specified number of
|
||||
bytes from the PRNG; this is now used instead of
|
||||
calling isc_rng_random() multiple times. [RT #46230]
|
||||
|
||||
4806. [func] Log messages related to loading of zones are now
|
||||
directed to the "zoneload" logging category.
|
||||
[RT #41640]
|
||||
|
||||
4805. [bug] TCP4Active and TCP6Active weren't being updated
|
||||
correctly. [RT #46454]
|
||||
|
||||
4804. [port] win32: access() does not work on directories as
|
||||
required by POSIX. Supply a alternative in
|
||||
isc_file_isdirwritable. [RT #46394]
|
||||
|
||||
4803. [placeholder]
|
||||
|
||||
4802. [test] Refactor mkeys system test to make it quicker and more
|
||||
reliable. [RT #45293]
|
||||
|
||||
4801. [func] 'dnssec-lookaside auto;' and 'dnssec-lookaside .
|
||||
trust-anchor dlv.isc.org;' now elicit warnings rather
|
||||
than being fatal configuration errors. [RT #46410]
|
||||
|
||||
4800. [bug] When processing delzone, write one zone config per
|
||||
line to the NZF. [RT #46323]
|
||||
|
||||
@@ -200,7 +296,7 @@
|
||||
- Removed DLV key from bind.keys
|
||||
- No longer use ISC DLV by default in delv
|
||||
- "dnssec-lookaside auto" and configuration of
|
||||
"dnssec-lookaide" with dlv.isc.org as trust
|
||||
"dnssec-lookaide" with dlv.isc.org as the trust
|
||||
anchor are both now fatal errors.
|
||||
[RT #46155]
|
||||
|
||||
|
||||
@@ -25,4 +25,6 @@ Setting Description
|
||||
Disable the use of inline functions to implement
|
||||
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
||||
may be useful when debugging
|
||||
-DISC_HEAP_CHECK Test heap consistency after every heap
|
||||
operation; used when debugging
|
||||
|
||||
|
||||
@@ -22,3 +22,4 @@ Some of these settings are:
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
||||
|`-DISC_HEAP_CHECK`|Test heap consistency after every heap operation; used when debugging|
|
||||
|
||||
@@ -117,7 +117,11 @@ include:
|
||||
* 'named-checkconf -l' lists zones found in named.conf.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
data for zones added by rndc addzone is stored.
|
||||
* The default key algorithm in rndc-confgen is now hmac-sha256.
|
||||
* filter-aaaa-on-v4 and filter-aaaa-on-v6 options are now available by
|
||||
default without a configure option.
|
||||
* The obsolete isc-hmac-fixup command has been removed.
|
||||
|
||||
Building BIND
|
||||
|
||||
@@ -127,8 +131,8 @@ on many versions of Linux and UNIX, including RedHat, Fedora, Debian,
|
||||
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
||||
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||
win32utils/readme1st.txt for details on building for Windows systems.
|
||||
BIND is also available for Windows 2008 and higher. See win32utils/
|
||||
readme1st.txt for details on building for Windows systems.
|
||||
|
||||
To build on a UNIX or Linux system, use:
|
||||
|
||||
|
||||
@@ -129,7 +129,11 @@ include:
|
||||
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
data for zones added by rndc addzone is stored.
|
||||
* The default key algorithm in `rndc-confgen` is now hmac-sha256.
|
||||
* `filter-aaaa-on-v4` and `filter-aaaa-on-v6` options are now available
|
||||
by default without a configure option.
|
||||
* The obsolete `isc-hmac-fixup` command has been removed.
|
||||
|
||||
### <a name="build"/> Building BIND
|
||||
|
||||
@@ -139,8 +143,9 @@ many versions of Linux and UNIX, including RedHat, Fedora, Debian, Ubuntu,
|
||||
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
||||
SCO OpenServer, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||
`win32utils/readme1st.txt` for details on building for Windows systems.
|
||||
BIND is also available for Windows 2008 and higher. See
|
||||
`win32utils/readme1st.txt` for details on building for Windows
|
||||
systems.
|
||||
|
||||
To build on a UNIX or Linux system, use:
|
||||
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
@@ -64,11 +68,11 @@ rndc-confgen.@O@: rndc-confgen.c
|
||||
ddns-confgen.@O@: ddns-confgen.c
|
||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
||||
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
|
||||
@@ -469,6 +469,11 @@ Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to hav
|
||||
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]keepalive\fR
|
||||
.RS 4
|
||||
Send [or do not send] an EDNS Keepalive option\&.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]keepopen\fR
|
||||
.RS 4
|
||||
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
||||
|
||||
+74
-38
@@ -109,6 +109,11 @@ print_usage(FILE *fp) {
|
||||
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
||||
}
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
static void usage(void) {
|
||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||
}
|
||||
#else
|
||||
ISC_PLATFORM_NORETURN_PRE static void
|
||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
@@ -119,6 +124,7 @@ usage(void) {
|
||||
"for complete list of options\n", stderr);
|
||||
exit(1);
|
||||
}
|
||||
#endif
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
@@ -414,14 +420,8 @@ isdotlocal(dns_message_t *msg) {
|
||||
isc_result_t result;
|
||||
static unsigned char local_ndata[] = { "\005local\0" };
|
||||
static unsigned char local_offsets[] = { 0, 6 };
|
||||
static dns_name_t local = {
|
||||
DNS_NAME_MAGIC,
|
||||
local_ndata, 7, 2,
|
||||
DNS_NAMEATTR_READONLY | DNS_NAMEATTR_ABSOLUTE,
|
||||
local_offsets, NULL,
|
||||
{(void *)-1, (void *)-1},
|
||||
{NULL, NULL}
|
||||
};
|
||||
static dns_name_t local =
|
||||
DNS_NAME_INITABSOLUTE(local_ndata, local_offsets);
|
||||
|
||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||
result == ISC_R_SUCCESS;
|
||||
@@ -824,8 +824,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, COMMSIZE,
|
||||
"buffer size");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse buffer size");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse buffer size");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->udpsize = num;
|
||||
break;
|
||||
default:
|
||||
@@ -870,8 +872,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value != NULL) {
|
||||
n = strlcpy(hexcookie, value,
|
||||
sizeof(hexcookie));
|
||||
if (n >= sizeof(hexcookie))
|
||||
fatal("COOKIE data too large");
|
||||
if (n >= sizeof(hexcookie)) {
|
||||
warn("COOKIE data too large");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->cookie = hexcookie;
|
||||
} else
|
||||
lookup->cookie = NULL;
|
||||
@@ -922,8 +926,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 0x3f, "DSCP");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse DSCP value");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse DSCP value");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->dscp = num;
|
||||
break;
|
||||
default:
|
||||
@@ -952,9 +958,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
255,
|
||||
"edns");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"edns");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->edns = num;
|
||||
break;
|
||||
case 'f':
|
||||
@@ -971,9 +979,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
0xffff,
|
||||
"ednsflags");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"ednsflags");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->ednsflags = num;
|
||||
break;
|
||||
case 'n':
|
||||
@@ -986,10 +996,12 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ednsoptscnt = 0;
|
||||
break;
|
||||
}
|
||||
if (value == NULL)
|
||||
fatal("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
if (value == NULL) {
|
||||
warn("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
code = next_token(&value, ":");
|
||||
save_opt(lookup, code, value);
|
||||
break;
|
||||
@@ -1104,8 +1116,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (!state)
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse ndots");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse ndots");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
ndots = num;
|
||||
break;
|
||||
case 's':
|
||||
@@ -1167,8 +1181,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
break;
|
||||
}
|
||||
result = parse_uint(&num, value, 15, "opcode");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse opcode");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse opcode");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->opcode = (dns_opcode_t)num;
|
||||
break;
|
||||
default:
|
||||
@@ -1182,8 +1198,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 512, "padding");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse padding");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse padding");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->padding = (isc_uint16_t)num;
|
||||
break;
|
||||
case 'q':
|
||||
@@ -1222,8 +1240,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES - 1, "retries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse retries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse retries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->retries++;
|
||||
break;
|
||||
default:
|
||||
@@ -1306,8 +1326,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
*/
|
||||
if (splitwidth)
|
||||
splitwidth += 3;
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse split");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse split");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
case 't': /* stats */
|
||||
FULLCHECK("stats");
|
||||
@@ -1331,8 +1353,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ecs_addr = NULL;
|
||||
}
|
||||
result = parse_netprefix(&lookup->ecs_addr, value);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse client");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse client");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
@@ -1355,8 +1379,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
||||
"timeout");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse timeout");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse timeout");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (timeout == 0)
|
||||
timeout = 1;
|
||||
break;
|
||||
@@ -1392,8 +1418,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES, "tries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse tries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse tries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (lookup->retries == 0)
|
||||
lookup->retries = 1;
|
||||
break;
|
||||
@@ -1450,11 +1478,19 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
default:
|
||||
invalid_option:
|
||||
need_value:
|
||||
#if TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
#endif
|
||||
fprintf(stderr, "Invalid option: +%s\n",
|
||||
option);
|
||||
usage();
|
||||
}
|
||||
return;
|
||||
|
||||
#if ! TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
digexit();
|
||||
#endif
|
||||
}
|
||||
|
||||
/*%
|
||||
|
||||
@@ -784,6 +784,15 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><option>+[no]keepalive</option></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Send [or do not send] an EDNS Keepalive option.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><option>+[no]keepopen</option></term>
|
||||
<listitem>
|
||||
|
||||
@@ -628,6 +628,12 @@
|
||||
with TCP. By default, TCP retries are performed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepalive</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Send [or do not send] an EDNS Keepalive option.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
+112
-31
@@ -375,6 +375,46 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
||||
}
|
||||
}
|
||||
|
||||
void (*dighost_pre_exit_hook)(void) = NULL;
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, ";; Warning: ");
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#else
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, "%s: ", progname);
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#endif
|
||||
|
||||
void
|
||||
digexit(void) {
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
if (dighost_pre_exit_hook != NULL) {
|
||||
dighost_pre_exit_hook();
|
||||
}
|
||||
exit(exitcode);
|
||||
}
|
||||
|
||||
void
|
||||
fatal(const char *format, ...) {
|
||||
va_list args;
|
||||
@@ -385,11 +425,7 @@ fatal(const char *format, ...) {
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
exit(exitcode);
|
||||
digexit();
|
||||
}
|
||||
|
||||
void
|
||||
@@ -655,6 +691,41 @@ make_empty_lookup(void) {
|
||||
return (looknew);
|
||||
}
|
||||
|
||||
#define EDNSOPT_OPTIONS 100U
|
||||
|
||||
static void
|
||||
cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
||||
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
||||
size_t i;
|
||||
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
||||
if (looknew->ednsopts == NULL)
|
||||
fatal("out of memory");
|
||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||
looknew->ednsopts[i].code = 0;
|
||||
looknew->ednsopts[i].length = 0;
|
||||
looknew->ednsopts[i].value = NULL;
|
||||
}
|
||||
looknew->ednsoptscnt = 0;
|
||||
if (lookold == NULL || lookold->ednsopts == NULL)
|
||||
return;
|
||||
|
||||
for (i = 0; i < lookold->ednsoptscnt; i++) {
|
||||
len = lookold->ednsopts[i].length;
|
||||
if (len != 0) {
|
||||
INSIST(lookold->ednsopts[i].value != NULL);
|
||||
looknew->ednsopts[i].value =
|
||||
isc_mem_allocate(mctx, len);
|
||||
if (looknew->ednsopts[i].value == NULL)
|
||||
fatal("out of memory");
|
||||
memmove(looknew->ednsopts[i].value,
|
||||
lookold->ednsopts[i].value, len);
|
||||
}
|
||||
looknew->ednsopts[i].code = lookold->ednsopts[i].code;
|
||||
looknew->ednsopts[i].length = len;
|
||||
}
|
||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||
}
|
||||
|
||||
/*%
|
||||
* Clone a lookup, perhaps copying the server list. This does not clone
|
||||
* the query list, since it will be regenerated by the setup_lookup()
|
||||
@@ -700,8 +771,12 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||
looknew->badcookie = lookold->badcookie;
|
||||
looknew->cookie = lookold->cookie;
|
||||
looknew->ednsopts = lookold->ednsopts;
|
||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||
if (lookold->ednsopts != NULL) {
|
||||
cloneopts(looknew, lookold);
|
||||
} else {
|
||||
looknew->ednsopts = NULL;
|
||||
looknew->ednsoptscnt = 0;
|
||||
}
|
||||
looknew->ednsneg = lookold->ednsneg;
|
||||
looknew->padding = lookold->padding;
|
||||
looknew->mapped = lookold->mapped;
|
||||
@@ -1317,13 +1392,6 @@ setup_libs(void) {
|
||||
check_result(result, "isc_mutex_init");
|
||||
}
|
||||
|
||||
/*
|
||||
* Array of up to 100 options configured by +ednsopt
|
||||
*/
|
||||
#define EDNSOPT_OPTIONS 100U
|
||||
static dns_ednsopt_t ednsopts[EDNSOPT_OPTIONS];
|
||||
static unsigned char ednsoptscnt = 0;
|
||||
|
||||
typedef struct dig_ednsoptname {
|
||||
isc_uint32_t code;
|
||||
const char *name;
|
||||
@@ -1350,12 +1418,12 @@ dig_ednsoptname_t optnames[] = {
|
||||
void
|
||||
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
isc_result_t result;
|
||||
isc_uint32_t num;
|
||||
isc_uint32_t num = 0;
|
||||
isc_buffer_t b;
|
||||
isc_boolean_t found = ISC_FALSE;
|
||||
unsigned int i;
|
||||
|
||||
if (ednsoptscnt == EDNSOPT_OPTIONS)
|
||||
if (lookup->ednsoptscnt >= EDNSOPT_OPTIONS)
|
||||
fatal("too many ednsopts");
|
||||
|
||||
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
||||
@@ -1372,9 +1440,16 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
fatal("bad edns code point: %s", code);
|
||||
}
|
||||
|
||||
ednsopts[ednsoptscnt].code = num;
|
||||
ednsopts[ednsoptscnt].length = 0;
|
||||
ednsopts[ednsoptscnt].value = NULL;
|
||||
if (lookup->ednsopts == NULL) {
|
||||
cloneopts(lookup, NULL);
|
||||
}
|
||||
|
||||
if (lookup->ednsopts[lookup->ednsoptscnt].value != NULL)
|
||||
isc_mem_free(mctx, lookup->ednsopts[lookup->ednsoptscnt].value);
|
||||
|
||||
lookup->ednsopts[lookup->ednsoptscnt].code = num;
|
||||
lookup->ednsopts[lookup->ednsoptscnt].length = 0;
|
||||
lookup->ednsopts[lookup->ednsoptscnt].value = NULL;
|
||||
|
||||
if (value != NULL) {
|
||||
char *buf;
|
||||
@@ -1384,14 +1459,13 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
||||
result = isc_hex_decodestring(value, &b);
|
||||
check_result(result, "isc_hex_decodestring");
|
||||
ednsopts[ednsoptscnt].value = isc_buffer_base(&b);
|
||||
ednsopts[ednsoptscnt].length = isc_buffer_usedlength(&b);
|
||||
lookup->ednsopts[lookup->ednsoptscnt].value =
|
||||
isc_buffer_base(&b);
|
||||
lookup->ednsopts[lookup->ednsoptscnt].length =
|
||||
isc_buffer_usedlength(&b);
|
||||
}
|
||||
|
||||
if (lookup->ednsoptscnt == 0)
|
||||
lookup->ednsopts = &ednsopts[ednsoptscnt];
|
||||
lookup->ednsoptscnt++;
|
||||
ednsoptscnt++;
|
||||
}
|
||||
|
||||
/*%
|
||||
@@ -1570,6 +1644,15 @@ destroy_lookup(dig_lookup_t *lookup) {
|
||||
if (lookup->ecs_addr != NULL)
|
||||
isc_mem_free(mctx, lookup->ecs_addr);
|
||||
|
||||
if (lookup->ednsopts != NULL) {
|
||||
size_t i;
|
||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||
if (lookup->ednsopts[i].value != NULL)
|
||||
isc_mem_free(mctx, lookup->ednsopts[i].value);
|
||||
}
|
||||
isc_mem_free(mctx, lookup->ednsopts);
|
||||
}
|
||||
|
||||
isc_mem_free(mctx, lookup);
|
||||
}
|
||||
|
||||
@@ -2114,9 +2197,13 @@ setup_lookup(dig_lookup_t *lookup) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_message_puttempname(lookup->sendmsg,
|
||||
&lookup->name);
|
||||
fatal("'%s' is not a legal name "
|
||||
warn("'%s' is not a legal name "
|
||||
"(%s)", lookup->textname,
|
||||
isc_result_totext(result));
|
||||
#if TARGET_OS_IPHONE
|
||||
check_next_lookup(current_lookup);
|
||||
return (ISC_FALSE);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
dns_name_format(lookup->name, store, sizeof(store));
|
||||
@@ -4127,12 +4214,6 @@ destroy_libs(void) {
|
||||
debug("Removing log context");
|
||||
isc_log_destroy(&lctx);
|
||||
|
||||
while (ednsoptscnt > 0U) {
|
||||
ednsoptscnt--;
|
||||
if (ednsopts[ednsoptscnt].value != NULL)
|
||||
isc_mem_free(mctx, ednsopts[ednsoptscnt].value);
|
||||
}
|
||||
|
||||
debug("Destroy memory");
|
||||
if (memdebugging != 0)
|
||||
isc_mem_stats(mctx, stderr);
|
||||
|
||||
@@ -26,6 +26,10 @@
|
||||
#include <isc/sockaddr.h>
|
||||
#include <isc/socket.h>
|
||||
|
||||
#ifdef __APPLE__
|
||||
#include <TargetConditionals.h>
|
||||
#endif
|
||||
|
||||
#define MXSERV 20
|
||||
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
||||
#define MXRD 32
|
||||
@@ -282,6 +286,13 @@ ISC_PLATFORM_NORETURN_PRE void
|
||||
fatal(const char *format, ...)
|
||||
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_PLATFORM_NORETURN_PRE void
|
||||
digexit(void)
|
||||
ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
@@ -384,6 +395,9 @@ extern void
|
||||
extern void
|
||||
(*dighost_shutdown)(void);
|
||||
|
||||
extern void
|
||||
(*dighost_pre_exit_hook)(void);
|
||||
|
||||
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
||||
|
||||
void setup_file_key(void);
|
||||
|
||||
@@ -62,11 +62,11 @@ may be preferable to direct use of
|
||||
.RS 4
|
||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||
\fBalgorithm\fR
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY and SIG(0) keys, the value must be DH (Diffie Hellman); specifying this value will automatically set the
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
|
||||
\fB\-T KEY\fR
|
||||
option as well\&.
|
||||
.sp
|
||||
TSIG keys can also by generated by setting the value to one of HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512\&. As with DH, specifying these values will automatically set
|
||||
TSIG keys can also be generated by setting the value to one of HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512\&. As with DH, specifying these values will automatically set
|
||||
\fB\-T KEY\fR\&. Note, however, that
|
||||
\fBtsig\-keygen\fR
|
||||
produces TSIG keys in a more useful format\&. These algorithms have been deprecated in
|
||||
|
||||
@@ -122,12 +122,12 @@
|
||||
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<option>-T KEY</option> option as well.
|
||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||
his value will automatically set the <option>-T KEY</option>
|
||||
option as well.
|
||||
</para>
|
||||
<para>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
TSIG keys can also be generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <option>-T KEY</option>. Note,
|
||||
|
||||
@@ -103,12 +103,12 @@
|
||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<code class="option">-T KEY</code> option as well.
|
||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||
his value will automatically set the <code class="option">-T KEY</code>
|
||||
option as well.
|
||||
</p>
|
||||
<p>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
TSIG keys can also be generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_PRODUCT@
|
||||
@@ -130,7 +134,7 @@ server.@O@: server.c
|
||||
-DPRODUCT=\"${PRODUCT}\" \
|
||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||
|
||||
named@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||
export MAKE_SYMTABLE="yes"; \
|
||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
@@ -26,6 +26,8 @@
|
||||
int scmp_syscalls[] = {
|
||||
SCMP_SYS(access),
|
||||
SCMP_SYS(open),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(clock_gettime),
|
||||
SCMP_SYS(time),
|
||||
SCMP_SYS(read),
|
||||
@@ -54,6 +56,7 @@ int scmp_syscalls[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
SCMP_SYS(getrandom),
|
||||
#endif
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(unlink),
|
||||
SCMP_SYS(socket),
|
||||
SCMP_SYS(sendto),
|
||||
@@ -72,7 +75,6 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(getsockopt),
|
||||
SCMP_SYS(getsockname),
|
||||
SCMP_SYS(lstat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(getgid),
|
||||
SCMP_SYS(getegid),
|
||||
SCMP_SYS(getuid),
|
||||
@@ -83,9 +85,7 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(setuid),
|
||||
SCMP_SYS(prctl),
|
||||
SCMP_SYS(epoll_wait),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(getdents),
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(utimes),
|
||||
SCMP_SYS(dup),
|
||||
#endif
|
||||
@@ -93,6 +93,8 @@ int scmp_syscalls[] = {
|
||||
const char *scmp_syscall_names[] = {
|
||||
"access",
|
||||
"open",
|
||||
"openat",
|
||||
"lseek",
|
||||
"clock_gettime",
|
||||
"time",
|
||||
"read",
|
||||
@@ -121,6 +123,7 @@ const char *scmp_syscall_names[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
"getrandom",
|
||||
#endif
|
||||
"rename",
|
||||
"unlink",
|
||||
"socket",
|
||||
"sendto",
|
||||
@@ -139,7 +142,6 @@ const char *scmp_syscall_names[] = {
|
||||
"getsockopt",
|
||||
"getsockname",
|
||||
"lstat",
|
||||
"lseek",
|
||||
"getgid",
|
||||
"getegid",
|
||||
"getuid",
|
||||
@@ -150,9 +152,7 @@ const char *scmp_syscall_names[] = {
|
||||
"setuid",
|
||||
"prctl",
|
||||
"epoll_wait",
|
||||
"openat",
|
||||
"getdents",
|
||||
"rename",
|
||||
"utimes",
|
||||
"dup",
|
||||
#endif
|
||||
|
||||
+210
-162
@@ -154,12 +154,6 @@
|
||||
#define EXCLBUFFERS 4096
|
||||
#endif /* TUNE_LARGE */
|
||||
|
||||
#ifdef WIN32
|
||||
#define DIR_PERM_OK W_OK
|
||||
#else
|
||||
#define DIR_PERM_OK W_OK|X_OK
|
||||
#endif
|
||||
|
||||
#define MAX_TCP_TIMEOUT 65535
|
||||
|
||||
/*%
|
||||
@@ -1059,7 +1053,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
goto cleanup;
|
||||
|
||||
} else if (directory != NULL) {
|
||||
if (access(directory, DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(directory)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"managed-keys-directory '%s' "
|
||||
@@ -3344,7 +3338,7 @@ create_empty_zone(dns_zone_t *zone, dns_name_t *name, dns_view_t *view,
|
||||
viewname = "";
|
||||
}
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_ZONELOAD,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"automatic empty zone%s%s: %s",
|
||||
sep, viewname, namebuf);
|
||||
@@ -4975,11 +4969,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
if (!strcasecmp(dom, "no")) {
|
||||
result = ISC_R_NOTFOUND;
|
||||
} else if (!strcasecmp(dom, "auto")) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"WARNING: the DLV server at "
|
||||
"'dlv.isc.org' is no longer "
|
||||
"in service; dnssec-lookaside "
|
||||
"ignored");
|
||||
/*
|
||||
* Warning logged by libbind9.
|
||||
*/
|
||||
result = ISC_R_NOTFOUND;
|
||||
}
|
||||
}
|
||||
@@ -5005,11 +4997,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
CHECK(dns_name_fromstring(dlv, cfg_obj_asstring(obj),
|
||||
DNS_NAME_DOWNCASE, NULL));
|
||||
if (dns_name_equal(dlv, iscdlv)) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"WARNING: the DLV server at "
|
||||
"'dlv.isc.org' is no longer "
|
||||
"in service; dnssec-lookaside "
|
||||
"ignored");
|
||||
/*
|
||||
* Warning logged by libbind9.
|
||||
*/
|
||||
view->dlv = NULL;
|
||||
} else {
|
||||
view->dlv = dlv;
|
||||
@@ -6026,7 +6016,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
* Add the zone to its view in the new view list.
|
||||
*/
|
||||
if (!modify)
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
|
||||
if (zone_is_catz) {
|
||||
/*
|
||||
@@ -6184,7 +6174,7 @@ directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
|
||||
"option 'directory' contains relative path '%s'",
|
||||
directory);
|
||||
|
||||
if (access(directory, DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(directory)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"directory '%s' is not writable",
|
||||
@@ -7079,7 +7069,7 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
dir, isc_result_totext(result));
|
||||
return (result);
|
||||
}
|
||||
if (access(dir, DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(dir)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"new-zones-directory '%s' "
|
||||
@@ -7343,18 +7333,128 @@ data_to_cfg(dns_view_t *view, MDB_val *key, MDB_val *data,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Prototype for a callback which can be used with for_all_newzone_cfgs().
|
||||
*/
|
||||
typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx);
|
||||
|
||||
/*%
|
||||
* For each zone found in a NZD opened by the caller, create an object
|
||||
* representing its configuration and invoke "callback" with the created
|
||||
* object, "config", "vconfig", "mctx", "view" and "actx" as arguments (all
|
||||
* these are non-global variables required to invoke configure_zone()).
|
||||
* Immediately interrupt processing if an error is encountered while
|
||||
* transforming NZD data into a zone configuration object or if "callback"
|
||||
* returns an error.
|
||||
*/
|
||||
static isc_result_t
|
||||
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx, MDB_txn *txn, MDB_dbi dbi)
|
||||
{
|
||||
const cfg_obj_t *zconfig, *zlist = NULL;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
cfg_obj_t *zconfigobj = NULL;
|
||||
isc_buffer_t *text = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
MDB_val data, key;
|
||||
int status;
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != MDB_SUCCESS) {
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||
status == MDB_SUCCESS;
|
||||
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT))
|
||||
{
|
||||
/*
|
||||
* Create a configuration object from data fetched from NZD.
|
||||
*/
|
||||
result = data_to_cfg(view, &key, &data, &text, &zconfigobj);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Extract zone configuration from configuration object.
|
||||
*/
|
||||
result = cfg_map_get(zconfigobj, "zone", &zlist);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
} else if (!cfg_obj_islist(zlist)) {
|
||||
result = ISC_R_FAILURE;
|
||||
break;
|
||||
}
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
|
||||
/*
|
||||
* Invoke callback.
|
||||
*/
|
||||
result = callback(zconfig, config, vconfig, mctx, view, actx);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Destroy the configuration object created in this iteration.
|
||||
*/
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zconfigobj != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
mdb_cursor_close(cursor);
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Attempt to configure a zone found in NZD and return the result.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
return (configure_zone(config, zconfig, vconfig, mctx, view,
|
||||
&named_g_server->viewlist, actx, ISC_TRUE,
|
||||
ISC_FALSE, ISC_FALSE));
|
||||
}
|
||||
|
||||
/*%
|
||||
* Revert new view assignment for a zone found in NZD.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
UNUSED(config);
|
||||
UNUSED(vconfig);
|
||||
UNUSED(mctx);
|
||||
UNUSED(actx);
|
||||
|
||||
configure_zone_setviewcommit(ISC_R_FAILURE, zconfig, view);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx)
|
||||
{
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
int status;
|
||||
isc_buffer_t *text = NULL;
|
||||
cfg_obj_t *zoneconf = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
isc_result_t result;
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
MDB_val key, data;
|
||||
|
||||
if (view->new_zone_config == NULL) {
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -7371,82 +7471,22 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
"for view '%s'",
|
||||
view->new_zone_db, view->name);
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zoneobj = NULL;
|
||||
|
||||
result = data_to_cfg(view, &key, &data, &text, &zoneconf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
CHECK(cfg_map_get(zoneconf, "zone", &zlist));
|
||||
if (!cfg_obj_islist(zlist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
zoneobj = cfg_listelt_value(cfg_list_first(zlist));
|
||||
CHECK(configure_zone(config, zoneobj, vconfig, mctx,
|
||||
view, &named_g_server->viewlist, actx,
|
||||
ISC_TRUE, ISC_FALSE, ISC_FALSE));
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
cursor = NULL;
|
||||
}
|
||||
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, mctx,
|
||||
view, actx, txn, dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
goto cleanup2;
|
||||
}
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zconfig = NULL;
|
||||
isc_result_t result2;
|
||||
|
||||
result2 = data_to_cfg(view, &key, &data, &text,
|
||||
&zoneconf);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
result2 = cfg_map_get(zoneconf, "zone", &zlist);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
configure_zone_setviewcommit(result, zconfig, view);
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
/*
|
||||
* An error was encountered while attempting to configure zones
|
||||
* found in NZD. As this error may have been caused by a
|
||||
* configure_zone() failure, try restoring a sane configuration
|
||||
* by reattaching all zones found in NZD to the old view. If
|
||||
* this also fails, too bad, there is nothing more we can do in
|
||||
* terms of trying to make things right.
|
||||
*/
|
||||
(void) for_all_newzone_cfgs(configure_newzone_revert, config,
|
||||
vconfig, mctx, view, actx, txn,
|
||||
dbi);
|
||||
}
|
||||
|
||||
cleanup2:
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
}
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
return (result);
|
||||
}
|
||||
@@ -7490,8 +7530,9 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
||||
key.mv_size = strlen(zname);
|
||||
|
||||
status = mdb_get(txn, dbi, &key, &data);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(data_to_cfg(view, &key, &data, &text, &zoneconf));
|
||||
|
||||
@@ -8520,7 +8561,7 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
/*
|
||||
* Check that the working directory is writable.
|
||||
*/
|
||||
if (access(".", DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(".")) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"the working directory is not writable");
|
||||
@@ -11863,7 +11904,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
if (zconfig == NULL) {
|
||||
/* We're deleting the zone from the database */
|
||||
status = mdb_del(*txnp, dbi, &key, NULL);
|
||||
if (status != 0 && status != MDB_NOTFOUND) {
|
||||
if (status != MDB_SUCCESS && status != MDB_NOTFOUND) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11873,8 +11914,9 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
namebuf, mdb_strerror(status));
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
} else if (status != MDB_NOTFOUND)
|
||||
} else if (status != MDB_NOTFOUND) {
|
||||
commit = ISC_TRUE;
|
||||
}
|
||||
} else {
|
||||
/* We're creating or overwriting the zone */
|
||||
const cfg_obj_t *zoptions;
|
||||
@@ -11909,7 +11951,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(*txnp, dbi, &key, &data, 0);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11927,11 +11969,11 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (!commit || result != ISC_R_SUCCESS)
|
||||
if (!commit || result != ISC_R_SUCCESS) {
|
||||
(void) mdb_txn_abort(*txnp);
|
||||
else {
|
||||
} else {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11946,8 +11988,10 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -11961,7 +12005,7 @@ nzd_writable(dns_view_t *view) {
|
||||
REQUIRE(view != NULL);
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0, 0, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_txn_begin: %s",
|
||||
@@ -11970,7 +12014,7 @@ nzd_writable(dns_view_t *view) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_dbi_open: %s",
|
||||
@@ -11993,7 +12037,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0,
|
||||
flags, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_txn_begin: %s",
|
||||
@@ -12002,7 +12046,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_dbi_open: %s",
|
||||
@@ -12013,9 +12057,10 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*txnp = txn;
|
||||
|
||||
cleanup:
|
||||
if (status != 0) {
|
||||
if (txn != NULL)
|
||||
if (status != MDB_SUCCESS) {
|
||||
if (txn != NULL) {
|
||||
mdb_txn_abort(txn);
|
||||
}
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
@@ -12029,38 +12074,34 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*/
|
||||
static void
|
||||
nzd_env_close(dns_view_t *view) {
|
||||
if (view->new_zone_dbenv != NULL) {
|
||||
const char *dbpath = NULL;
|
||||
isc_boolean_t have_dbpath = ISC_FALSE;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int ret;
|
||||
const char *dbpath = NULL;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int status, ret;
|
||||
|
||||
if (mdb_env_get_path(view->new_zone_dbenv, &dbpath) == 0) {
|
||||
have_dbpath = ISC_TRUE;
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock",
|
||||
dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
}
|
||||
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
view->new_zone_dbenv = NULL;
|
||||
|
||||
if (have_dbpath) {
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not
|
||||
* by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we
|
||||
* reopen the environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
}
|
||||
if (view->new_zone_dbenv == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
status = mdb_env_get_path(view->new_zone_dbenv, &dbpath);
|
||||
INSIST(status == MDB_SUCCESS);
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock", dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we reopen the
|
||||
* environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
|
||||
view->new_zone_dbenv = NULL;
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
@@ -12076,7 +12117,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
nzd_env_close(view);
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_create failed: %s",
|
||||
@@ -12086,7 +12127,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
|
||||
if (view->new_zone_mapsize != 0ULL) {
|
||||
status = mdb_env_set_mapsize(env, view->new_zone_mapsize);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_set_mapsize failed: %s",
|
||||
@@ -12095,9 +12136,8 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
}
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, view->new_zone_db,
|
||||
MDB_NOSUBDIR|MDB_CREATE, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, view->new_zone_db, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_open of '%s' failed: %s",
|
||||
@@ -12126,10 +12166,12 @@ nzd_close(MDB_txn **txnp, isc_boolean_t commit) {
|
||||
if (*txnp != NULL) {
|
||||
if (commit) {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
result = ISC_R_FAILURE;
|
||||
} else
|
||||
}
|
||||
} else {
|
||||
mdb_txn_abort(*txnp);
|
||||
}
|
||||
*txnp = NULL;
|
||||
}
|
||||
|
||||
@@ -12147,11 +12189,12 @@ nzd_count(dns_view_t *view, int *countp) {
|
||||
REQUIRE(countp != NULL);
|
||||
|
||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
status = mdb_stat(txn, dbi, &statbuf);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_stat: %s",
|
||||
@@ -12224,8 +12267,9 @@ migrate_nzf(dns_view_t *view) {
|
||||
|
||||
zonelist = NULL;
|
||||
CHECK(cfg_map_get(nzf_config, "zone", &zonelist));
|
||||
if (!cfg_obj_islist(zonelist))
|
||||
if (!cfg_obj_islist(zonelist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(nzd_open(view, 0, &txn, &dbi));
|
||||
|
||||
@@ -12276,7 +12320,7 @@ migrate_nzf(dns_view_t *view) {
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(txn, dbi, &key, &data, MDB_NOOVERWRITE);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -12305,15 +12349,19 @@ migrate_nzf(dns_view_t *view) {
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
else
|
||||
} else {
|
||||
result = nzd_close(&txn, commit);
|
||||
}
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
if (nzf_config != NULL)
|
||||
}
|
||||
|
||||
if (nzf_config != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &nzf_config);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
@@ -14465,10 +14513,10 @@ mkey_dumpzone(dns_view_t *view, isc_buffer_t **text) {
|
||||
else if (revoked)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrust revoked");
|
||||
else if (kd.addhd < now)
|
||||
else if (kd.addhd <= now)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrusted since: %s", tbuf);
|
||||
else if (kd.addhd >= now)
|
||||
else if (kd.addhd > now)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrust pending: %s", tbuf);
|
||||
CHECK(putstr(text, buf));
|
||||
|
||||
+4
-1
@@ -516,7 +516,10 @@ Status will report whether serving of stale answers is currently enabled, disabl
|
||||
.PP
|
||||
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
|
||||
.RS 4
|
||||
Dump the server\*(Aqs security roots and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&.
|
||||
Dump the security roots (i\&.e\&., trust anchors configured via
|
||||
\fBtrusted\-keys\fR,
|
||||
\fBmanaged\-keys\fR, or
|
||||
\fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&.
|
||||
.sp
|
||||
If the first argument is "\-", then the output is returned via the
|
||||
\fBrndc\fR
|
||||
|
||||
+15
-9
@@ -774,9 +774,15 @@
|
||||
<term><userinput>secroots <optional>-</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Dump the server's security roots and negative trust anchors
|
||||
for the specified views. If no view is specified, all views
|
||||
are dumped.
|
||||
Dump the security roots (i.e., trust anchors
|
||||
configured via <command>trusted-keys</command>,
|
||||
<command>managed-keys</command>, or
|
||||
<command>dnssec-validation auto</command>) and negative trust
|
||||
anchors for the specified views. If no view is specified, all
|
||||
views are dumped. Security roots will indicate whether
|
||||
they are configured as trusted keys, managed keys, or
|
||||
initializing managed keys (managed keys that have not yet
|
||||
been updated by a successful key refresh query).
|
||||
</para>
|
||||
<para>
|
||||
If the first argument is "-", then the output is
|
||||
@@ -963,15 +969,15 @@
|
||||
<listitem>
|
||||
<para>
|
||||
When called without arguments, display the current
|
||||
values of the <command>tcp-initial-timeout</command>,
|
||||
values of the <command>tcp-initial-timeout</command>,
|
||||
<command>tcp-idle-timeout</command>,
|
||||
<command>tcp-keepalive-timeout</command> and
|
||||
<command>tcp-advertised-timeout</command> options.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+15
-9
@@ -657,9 +657,15 @@
|
||||
<dt><span class="term"><strong class="userinput"><code>secroots [<span class="optional">-</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Dump the server's security roots and negative trust anchors
|
||||
for the specified views. If no view is specified, all views
|
||||
are dumped.
|
||||
Dump the security roots (i.e., trust anchors
|
||||
configured via <span class="command"><strong>trusted-keys</strong></span>,
|
||||
<span class="command"><strong>managed-keys</strong></span>, or
|
||||
<span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust
|
||||
anchors for the specified views. If no view is specified, all
|
||||
views are dumped. Security roots will indicate whether
|
||||
they are configured as trusted keys, managed keys, or
|
||||
initializing managed keys (managed keys that have not yet
|
||||
been updated by a successful key refresh query).
|
||||
</p>
|
||||
<p>
|
||||
If the first argument is "-", then the output is
|
||||
@@ -822,15 +828,15 @@
|
||||
<dd>
|
||||
<p>
|
||||
When called without arguments, display the current
|
||||
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
||||
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
||||
<span class="command"><strong>tcp-idle-timeout</strong></span>,
|
||||
<span class="command"><strong>tcp-keepalive-timeout</strong></span> and
|
||||
<span class="command"><strong>tcp-advertised-timeout</strong></span> options.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><strong class="userinput"><code>thaw [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
|
||||
|
||||
@@ -10,4 +10,4 @@ my $target = shift;
|
||||
my $file = shift;
|
||||
my $mtime = time - (stat $file)[9];
|
||||
die "bad mtime $mtime"
|
||||
unless abs($mtime - $target) < 3;
|
||||
unless abs($mtime - $target) < 10;
|
||||
|
||||
@@ -254,7 +254,7 @@ def create_response(msg):
|
||||
def sigterm(signum, frame):
|
||||
print ("Shutting down now...")
|
||||
os.remove('ans.pid')
|
||||
running = 0
|
||||
running = False
|
||||
sys.exit(0)
|
||||
|
||||
############################################################################
|
||||
@@ -270,8 +270,17 @@ sock = 5300
|
||||
|
||||
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||
query4_socket.bind((ip4, sock))
|
||||
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||
query6_socket.bind((ip6, sock))
|
||||
|
||||
havev6 = True
|
||||
try:
|
||||
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||
try:
|
||||
query6_socket.bind((ip6, sock))
|
||||
except:
|
||||
query6_socket.close()
|
||||
havev6 = False
|
||||
except:
|
||||
havev6 = False
|
||||
|
||||
ctrl_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||
ctrl_socket.bind((ip4, sock + 1))
|
||||
@@ -284,14 +293,18 @@ pid = os.getpid()
|
||||
print (pid, file=f)
|
||||
f.close()
|
||||
|
||||
running = 1
|
||||
running = True
|
||||
|
||||
print ("Listening on %s port %d" % (ip4, sock))
|
||||
print ("Listening on %s port %d" % (ip6, sock))
|
||||
if havev6:
|
||||
print ("Listening on %s port %d" % (ip6, sock))
|
||||
print ("Control channel on %s port %d" % (ip4, sock + 1))
|
||||
print ("Ctrl-c to quit")
|
||||
|
||||
input = [query4_socket, query6_socket, ctrl_socket]
|
||||
if havev6:
|
||||
input = [query4_socket, query6_socket, ctrl_socket]
|
||||
else:
|
||||
input = [query4_socket, ctrl_socket]
|
||||
|
||||
while running:
|
||||
try:
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
dnssec-lookaside . trust-anchor dlv.example.com;
|
||||
};
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2005, 2007, 2010-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005, 2007, 2010-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -135,6 +135,7 @@ done
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking options allowed in inline-signing slaves ($n)"
|
||||
ret=0
|
||||
l=`$CHECKCONF bad-dnssec.conf 2>&1 | grep "dnssec-dnskey-kskonly.*requires inline" | wc -l`
|
||||
@@ -327,5 +328,29 @@ diff good.zonelist checkconf.out$n > diff.out$n || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside auto;' generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF warn-dlv-auto.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "dnssec-lookaside 'auto' is no longer supported" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.isc.org;' generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF warn-dlv-dlv.isc.org.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "dlv.isc.org has been shut down" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.example.com;' doesn't generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF good-dlv-dlv.example.com.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
[ -s checkconf.out$n ] && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -1,8 +1,2 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
prep.example. IN DS 65482 8 1 F3673708FBADDEC3EB55933E2E393ACE85EAC2BB
|
||||
prep.example. IN DS 65482 8 2 51A7C97AAC42803DA515D1CAFEE28031A5018F6345F12F4B6C1B6D20 02B59820
|
||||
|
||||
@@ -186,6 +186,19 @@ else
|
||||
}
|
||||
fi
|
||||
|
||||
#
|
||||
# Useful functions in test scripts
|
||||
#
|
||||
|
||||
# nextpart: read everything that's been appended to a file since the
|
||||
# last time 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "NR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
|
||||
@@ -58,6 +58,8 @@ MDIG=$TOP/Build/$VSCONF/mdig@EXEEXT@
|
||||
NZD2NZF=$TOP/Build/$VSCONF/named-nzd2nzf@EXEEXT@
|
||||
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||
FEATURETEST=$TOP/Build/$VSCONF/feature-test@EXEEXT@
|
||||
SAMPLEUPDATE=$TOP/Build/$VSCONF/update@EXEEXT@
|
||||
|
||||
# to port WIRETEST=$TOP/Build/$VSCONF/wire_test@EXEEXT@
|
||||
|
||||
# this is given as argument to native WIN32 executables
|
||||
@@ -176,6 +178,19 @@ echoinfo () {
|
||||
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
#
|
||||
# Useful functions in test scripts
|
||||
#
|
||||
|
||||
# nextpart: read everything that's been appended to a file since the
|
||||
# last time 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "NR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
@@ -211,6 +226,7 @@ export RANDFILE
|
||||
export RESOLVE
|
||||
export RNDC
|
||||
export RRCHECKER
|
||||
export SAMPLEUPDATE
|
||||
export SIGNER
|
||||
export SUBDIRS
|
||||
export TESTSOCK6
|
||||
|
||||
@@ -35,6 +35,19 @@ PIDFILE="${THISDIR}/${CONFDIR}/named.pid"
|
||||
myRNDC="$RNDC -c ${THISDIR}/${CONFDIR}/rndc.conf"
|
||||
myNAMED="$NAMED -c ${THISDIR}/${CONFDIR}/named.conf -m record,size,mctx -T clienttest -T nosyslog -d 99 -X named.lock -U 4"
|
||||
|
||||
# Test given condition. If true, test again after a second. Used for testing
|
||||
# filesystem-dependent conditions in order to prevent false negatives caused by
|
||||
# directory contents not being synchronized immediately after rename() returns.
|
||||
test_with_retry() {
|
||||
if test "$@"; then
|
||||
sleep 1
|
||||
if test "$@"; then
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
waitforpidfile() {
|
||||
for _w in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
@@ -48,9 +61,10 @@ n=0
|
||||
|
||||
cd $CONFDIR
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (named -g + only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (named -g + only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -58,9 +72,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -79,14 +93,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -103,14 +117,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -129,14 +143,14 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
# Stop the server and run through a series of tests with various config
|
||||
# files while controlling the stop/start of the server.
|
||||
@@ -155,9 +169,10 @@ fi
|
||||
|
||||
status=0
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -165,9 +180,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -186,14 +201,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -210,14 +225,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -237,18 +252,18 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing default logfile using named -L file ($n)"
|
||||
echo "I:testing default logfile using named -L file ($n)"
|
||||
# Now stop the server again and test the -L option
|
||||
rm -f $DLFILE
|
||||
$PERL ../../stop.pl .. ns1
|
||||
@@ -256,7 +271,7 @@ if ! test -f $PIDFILE; then
|
||||
cp $PLAINCONF named.conf
|
||||
$myNAMED -L $DLFILE > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "I:failed to start $myNAMED"
|
||||
echo "I: failed to start $myNAMED"
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
fi
|
||||
@@ -272,7 +287,7 @@ if ! test -f $PIDFILE; then
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:failed to cleanly stop $myNAMED"
|
||||
echo "I: failed to cleanly stop $myNAMED"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -284,9 +299,9 @@ echo "I: testing iso8601 timestamp ($n)"
|
||||
cp $ISOCONF named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\.... ' $ISOFILE > /dev/null; then
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -295,14 +310,14 @@ echo "I: testing iso8601-utc timestamp ($n)"
|
||||
cp $ISOCONFUTC named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\....Z' $ISOUTCFILE > /dev/null; then
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing explict versions ($n)"
|
||||
echo "I: testing explicit versions ($n)"
|
||||
cp $VERSCONF named.conf
|
||||
# a seconds since epoch version number
|
||||
touch $VERSFILE.1480039317
|
||||
@@ -313,27 +328,27 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing explict versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing explicit versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing explict versions failed DiG lookup failed"
|
||||
echo "I: testing explicit versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.1480039317
|
||||
if test_with_retry -f $VERSFILE.1480039317
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.1480039317 not removed"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.5
|
||||
if test_with_retry -f $VERSFILE.5
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.5 exists"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.5 exists"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $VERSFILE.4
|
||||
if test_with_retry ! -f $VERSFILE.4
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.4 does not exist"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -349,17 +364,17 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing timestamped versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing timestamped versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing timestamped versions failed DiG lookup failed"
|
||||
echo "I: testing timestamped versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $TSFILE.1480039317
|
||||
if test_with_retry -f $TSFILE.1480039317
|
||||
then
|
||||
echo "I: testing timestamped versions failed $TSFILE.1480039317 not removed"
|
||||
echo "I: testing timestamped versions failed: $TSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -375,22 +390,22 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing unlimited versions failed took too long ($t secs)"
|
||||
echo "I: testing unlimited versions failed: took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing unlimited versions failed DiG lookup failed"
|
||||
echo "I: testing unlimited versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.1480039317
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.1480039317
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.1480039317 removed"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.1480039317 removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.4
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.4
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.4 does not"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@ rm -f dsset-. ns1/dsset-.
|
||||
rm -f ns*/named.lock
|
||||
rm -f */managed-keys.bind* */named.secroots
|
||||
rm -f */managed*.conf ns1/managed.key ns1/managed.key.id
|
||||
rm -f */named.memstats */named.run
|
||||
rm -f */named.memstats */named.run */named.run.prev
|
||||
rm -f dig.out* delv.out* rndc.out* signer.out*
|
||||
rm -f ns1/named.secroots ns1/root.db.signed* ns1/root.db.tmp
|
||||
rm -f ns1/named.conf
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
; Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
$TTL 2
|
||||
$TTL 20
|
||||
. IN SOA gson.nominum.com. a.root.servers.nil. (
|
||||
2000042100 ; serial
|
||||
600 ; refresh
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40 -T tat=1
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20 -T tat=1
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40 -T tat=1
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -23,6 +23,7 @@ options {
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
bindkeys-file "managed.conf";
|
||||
trust-anchor-telemetry no;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
+204
-110
@@ -9,6 +9,74 @@
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
wait_for_log() {
|
||||
msg=$1
|
||||
file=$2
|
||||
for i in 1 2 3 4 5 6 7 8 9 10; do
|
||||
nextpart "$file" | grep "$msg" > /dev/null && return
|
||||
sleep 1
|
||||
done
|
||||
echo "I: exceeded time limit waiting for '$msg' in $file"
|
||||
ret=1
|
||||
}
|
||||
|
||||
mkeys_reconfig_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reconfig . | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
mkeys_reload_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reload . | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "loaded serial" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_loadkeys_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 loadkeys . | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "next key event" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_refresh_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys refresh | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_sync_on() {
|
||||
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||
# returns immediately after the expected log message is written, the
|
||||
# managed-keys zone is already locked and the command below calls
|
||||
# dns_zone_flush(), which also attempts to take that zone's lock
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys sync | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "dump_done" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_status_on() {
|
||||
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||
# returns immediately after the expected log message is written, the
|
||||
# managed-keys zone is already locked and the command below calls
|
||||
# mkey_status(), which in turn calls dns_zone_getrefreshkeytime(),
|
||||
# which also attempts to take that zone's lock
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys status
|
||||
}
|
||||
|
||||
mkeys_flush_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 flush | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
mkeys_secroots_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 secroots | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
status=0
|
||||
n=1
|
||||
|
||||
@@ -58,11 +126,9 @@ n=`expr $n + 1`
|
||||
echo "I: check new trust anchor can be added ($n)"
|
||||
ret=0
|
||||
standby1=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 5
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# there should be two keys listed now
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -81,10 +147,8 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check new trust anchor can't be added with bad initial key ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys refresh | sed 's/^/I: ns3 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys sync | sed 's/^/I: ns3 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 3
|
||||
mkeys_status_on 3 > rndc.out.$n 2>&1
|
||||
# there should be one key listed now
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -100,14 +164,17 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: remove untrusted standby key, check timer restarts ($n)"
|
||||
ret=0
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
mkeys_sync_on 2
|
||||
t1=`grep "trust pending" ns2/managed-keys.bind`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
t2=`grep "trust pending" ns2/managed-keys.bind`
|
||||
# trust pending date must be different
|
||||
[ -n "$t2" ] || ret=1
|
||||
@@ -121,12 +188,15 @@ echo "I: restore untrusted standby key, revoke original key ($n)"
|
||||
t1=$t2
|
||||
$SETTIME -D none -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -153,10 +223,14 @@ n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I: refresh managed-keys, ensure same result ($n)"
|
||||
t1=$t2
|
||||
sleep 2
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -184,15 +258,17 @@ ret=0
|
||||
echo "I: restore revoked key, ensure same result ($n)"
|
||||
t1=$t2
|
||||
$SETTIME -R none -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
mkeys_loadkeys_on 1
|
||||
$SETTIME -D none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -229,14 +305,14 @@ managed-keys {
|
||||
};
|
||||
EOF
|
||||
' > ns2/managed.conf
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that no key from bind.keys is marked as an initializing key ($n)"
|
||||
ret=0
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
mkeys_secroots_on 2
|
||||
grep '; initializing' ns2/named.secroots > /dev/null 2>&1 && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -245,14 +321,14 @@ echo "I: reinitialize trust anchors, revert to one key in bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
mv ns2/managed1.conf ns2/managed.conf
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that standby key is now trusted ($n)"
|
||||
ret=0
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -270,12 +346,9 @@ echo "I: revoke original key, add new standby ($n)"
|
||||
ret=0
|
||||
standby2=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# three keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 3 ] || ret=1
|
||||
@@ -304,11 +377,9 @@ n=`expr $n + 1`
|
||||
echo "I: revoke standby before it is trusted ($n)"
|
||||
ret=0
|
||||
standby3=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.a.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.a.$n 2>&1
|
||||
# four keys listed
|
||||
count=`grep -c "keyid: " rndc.out.a.$n`
|
||||
[ "$count" -eq 4 ] || { echo "keyid: count ($count) != 4"; ret=1; }
|
||||
@@ -319,11 +390,9 @@ count=`grep -c "trust revoked" rndc.out.a.$n`
|
||||
count=`grep -c "trust pending" rndc.out.a.$n`
|
||||
[ "$count" -eq 2 ] || { echo "trust pending count ($count) != 2"; ret=1; }
|
||||
$SETTIME -R now -K ns1 $standby3 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.b.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.b.$n 2>&1
|
||||
# now three keys listed
|
||||
count=`grep -c "keyid: " rndc.out.b.$n`
|
||||
[ "$count" -eq 3 ] || { echo "keyid: count ($count) != 3"; ret=1; }
|
||||
@@ -334,18 +403,16 @@ count=`grep -c "trust revoked" rndc.out.b.$n`
|
||||
count=`grep -c "trust pending" rndc.out.b.$n`
|
||||
[ "$count" -eq 1 ] || { echo "trust pending count ($count) != 1"; ret=1; }
|
||||
$SETTIME -D now -K ns1 $standby3 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
mkeys_loadkeys_on 1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: wait 30 seconds for key add/remove holddowns to expire ($n)"
|
||||
echo "I: wait 20 seconds for key add/remove holddowns to expire ($n)"
|
||||
ret=0
|
||||
sleep 30
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
sleep 20
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -367,12 +434,9 @@ ret=0
|
||||
$SETTIME -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$SETTIME -R now -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -R now -K ns1 $standby2 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -394,8 +458,10 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check for insecure response ($n)"
|
||||
ret=0
|
||||
mkeys_refresh_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -407,16 +473,18 @@ $SETTIME -D now -K ns1 $standby2 > /dev/null
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig
|
||||
mkeys_reconfig_on 1
|
||||
|
||||
echo "I: reinitialize trust anchors"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check positive validation ($n)"
|
||||
ret=0
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -430,17 +498,25 @@ orig=`cat ns1/managed.key`
|
||||
keyid=`cat ns1/managed.key.id`
|
||||
revoked=`$REVOKE -K ns1 $orig`
|
||||
rkeyid=`expr $revoked : 'ns1/K\.+00.+0*\([1-9]*[0-9]*[0-9]\)'`
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
# We need to activate at least one valid DNSKEY to prevent dnssec-signzone from
|
||||
# failing. Alternatively, we could use -P to disable post-sign verification,
|
||||
# but we actually do want post-sign verification to happen to ensure the zone
|
||||
# is correct before we break it on purpose.
|
||||
$SETTIME -R none -D none -K ns1 $standby1 > /dev/null
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -O full -o . -f signer.out.$n ns1/root.db > /dev/null 2>&-
|
||||
cp -f ns1/root.db.signed ns1/root.db.tmp
|
||||
BADSIG="SVn2tLDzpNX2rxR4xRceiCsiTqcWNKh7NQ0EQfCrVzp9WEmLw60sQ5kP xGk4FS/xSKfh89hO2O/H20Bzp0lMdtr2tKy8IMdU/mBZxQf2PXhUWRkg V2buVBKugTiOPTJSnaqYCN3rSfV1o7NtC1VNHKKK/D5g6bpDehdn5Gaq kpBhN+MSCCh9OZP2IT20luS1ARXxLlvuSVXJ3JYuuhTsQXUbX/SQpNoB Lo6ahCE55szJnmAxZEbb2KOVnSlZRA6ZBHDhdtO0S4OkvcmTutvcVV+7 w53CbKdaXhirvHIh0mZXmYk2PbPLDY7PU9wSH40UiWPOB9f00wwn6hUe uEQ1Qg=="
|
||||
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
# Less than a second may have passed since ns1 was started. If we call
|
||||
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||
# subsequent "rndc reload ." call on platforms which do not set the
|
||||
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||
# equal to master file modification time.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
||||
mkeys_reload_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || { echo "'keyid:' count ($count) != 1"; ret=1; }
|
||||
@@ -461,6 +537,7 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check validation fails with bad DNSKEY rrset ($n)"
|
||||
ret=0
|
||||
mkeys_flush_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
@@ -470,17 +547,18 @@ n=`expr $n + 1`
|
||||
echo "I: restore DNSKEY rrset, check validation succeeds again ($n)"
|
||||
ret=0
|
||||
rm -f ${revoked}.key ${revoked}.private
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$SETTIME -D none -R none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby2 > /dev/null
|
||||
# Less than a second may have passed since ns1 was started. If we call
|
||||
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||
# subsequent "rndc reload ." call on platforms which do not set the
|
||||
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||
# equal to master file modification time.
|
||||
sleep 1
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 flush | sed 's/^/I: ns1 /'
|
||||
mkeys_reload_on 1
|
||||
mkeys_flush_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -489,15 +567,24 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: reset the root server with no keys, check for minimal update ($n)"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
ret=0
|
||||
# Refresh keys first to prevent previous checks from influencing this one.
|
||||
# Note that we might still get occasional false negatives on some really slow
|
||||
# machines, when $t1 equals $t2 due to the time elapsed between "rndc
|
||||
# managed-keys status" calls being equal to the normal active refresh period
|
||||
# (as calculated per rules listed in RFC 5011 section 2.3) minus an "hour" (as
|
||||
# set using -T mkeytimers).
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
t1=`grep 'next refresh:' rndc.out.$n`
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
cp ns1/root.db ns1/root.db.signed
|
||||
nextpart ns1/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
wait_for_log "loaded serial" ns1/named.run
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -519,14 +606,23 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: reset the root server with no signatures, check for minimal update ($n)"
|
||||
t2=$t1
|
||||
ret=0
|
||||
# Refresh keys first to prevent previous checks from influencing this one
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
t1=`grep 'next refresh:' rndc.out.$n`
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
cat ns1/K*.key >> ns1/root.db.signed
|
||||
nextpart ns1/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
wait_for_log "loaded serial" ns1/named.run
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent minimal update from resetting it to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -548,13 +644,12 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: restore root server, check validation succeeds again ($n)"
|
||||
ret=0
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_reload_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -579,12 +674,10 @@ n=`expr $n + 1`
|
||||
echo "I: check 'rndc-managed-keys destroy' ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys destroy | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
grep "no views with managed keys" rndc.out.$n > /dev/null || ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_reconfig_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
grep "name: \." rndc.out.$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -596,7 +689,7 @@ ret=0
|
||||
# compare against the known key.
|
||||
tathex=`grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run | awk '{print $6; exit 0}' | sed -e 's/(_ta-\([0-9a-f][0-9a-f]*\)):/\1/'`
|
||||
tatkey=`$PERL -e 'printf("%d\n", hex(@ARGV[0]));' $tathex`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | grep '; managed' | sed 's#.*SHA256/\([0-9][0-9]*\) ; managed.*#\1#'`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | sed -n 's#.*SHA256/\([0-9][0-9]*\) ; .*managed.*#\1#p'`
|
||||
[ "$tatkey" -eq "$realkey" ] || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -604,7 +697,7 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check initialization fails if managed-keys can't be created ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
mkeys_secroots_on 4
|
||||
grep '; initializing managed' ns4/named.secroots > /dev/null 2>&1 || ret=1
|
||||
grep '; managed' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
grep '; trusted' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
@@ -621,8 +714,9 @@ ret=0
|
||||
# key refresh failure instead of just a few seconds, in order to prevent races
|
||||
# between the next scheduled key refresh time and startup time of restarted ns5.
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
nextpart ns5/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
sleep 2
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
# ns5/named.run will contain logs from both the old instance and the new
|
||||
# instance. In order for the test to pass, both must attempt a fetch.
|
||||
count=`grep -c "Creating key fetch" ns5/named.run`
|
||||
@@ -635,14 +729,14 @@ echo "I: check key refreshes are resumed after root servers become available ($n
|
||||
ret=0
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
# Prevent previous check from affecting this one
|
||||
rm -f ns2/managed-keys.bind*
|
||||
rm -f ns5/managed-keys.bind*
|
||||
# named2.args adds "-T mkeytimers=2/20/40" to named1.args as we need to wait for
|
||||
# an "hour" until keys are refreshed again after initial failure
|
||||
cp ns5/named2.args ns5/named.args
|
||||
nextpart ns5/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
sleep 2
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.5 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
sleep 1
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
mkeys_secroots_on 5
|
||||
grep '; initializing managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should still REFUSE queries from ns5, so resolving should be impossible
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.a.test$n || ret=1
|
||||
@@ -652,10 +746,10 @@ grep "status: SERVFAIL" dig.out.ns5.a.test$n > /dev/null || ret=1
|
||||
# Allow queries from ns5 to ns1
|
||||
cp ns1/named3.conf ns1/named.conf
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.5 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
sleep 1
|
||||
mkeys_reconfig_on 1
|
||||
nextpart ns5/named.run > /dev/null
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
mkeys_secroots_on 5
|
||||
grep '; managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should not longer REFUSE queries from ns5, so managed keys should be
|
||||
# correctly refreshed and resolving should succeed
|
||||
|
||||
@@ -53,6 +53,7 @@ view "b" {
|
||||
type slave;
|
||||
masters { 10.53.0.5 key "a"; };
|
||||
file "x21.bk-b";
|
||||
notify no;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -62,5 +63,6 @@ view "c" {
|
||||
type slave;
|
||||
masters { 10.53.0.5 key "a"; };
|
||||
file "x21.bk-c";
|
||||
notify no;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -20,6 +20,7 @@ options {
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify yes;
|
||||
serial-query-rate 1; // workaround for KB AA-01213
|
||||
};
|
||||
|
||||
key altkey {
|
||||
|
||||
@@ -278,7 +278,7 @@ sleep 10
|
||||
if
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
then
|
||||
echo "I:restarted server ns1"
|
||||
echo "I:restarted server ns1"
|
||||
else
|
||||
echo "I:could not restart server ns1"
|
||||
exit 1
|
||||
@@ -709,8 +709,12 @@ size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->siz
|
||||
[ "$size" -gt 6000 ] || ret=1
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 sync maxjournal.test
|
||||
sleep 1
|
||||
|
||||
for i in 1 2 3 4 5 6
|
||||
do
|
||||
sleep 1
|
||||
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||
[ "$size" -lt 5000 ] && break
|
||||
done
|
||||
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||
[ "$size" -lt 5000 ] || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
@@ -885,75 +889,81 @@ grep "address family not supported" nsupdate.out-$n > /dev/null 2>&1 || ret=1
|
||||
#
|
||||
# Add client library tests here
|
||||
#
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
|
||||
if test unset != "${SAMPLEUPDATE:-unset}" -a -x "${SAMPLEUPDATE}"
|
||||
then
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
add "nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
add "check-nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
add "yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
add "check-yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
add "nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
add "check-nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
||||
-p "yxrrset no-txt.sample TXT" \
|
||||
add "yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
||||
add "check-yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
fi
|
||||
|
||||
#
|
||||
# End client library tests here
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -7,8 +7,9 @@ file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
system test for recursion limits
|
||||
|
||||
ns1 -- root server
|
||||
ans2 -- delegate to ns1.(n+1).example.com for all n, up to
|
||||
the value specified in ans.limit (or forever if limit is 0)
|
||||
ans2 -- for example.org: delegate to ns1.(n+1).example.org for all n, up to the
|
||||
value specified in ans.limit (or forever if limit is 0)
|
||||
for example.net: delegate every query to 15 more name servers, with
|
||||
"victim" address
|
||||
ns3 -- resolver under test
|
||||
ans4 -- delegates every query to 16 more name servers, with "victim" address
|
||||
ans7 -- "victim" server
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -10,9 +10,17 @@ use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
use Time::HiRes qw(usleep nanosleep);
|
||||
use IO::Socket;
|
||||
use Net::DNS;
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $limit = getlimit();
|
||||
my $no_more_waiting = 0;
|
||||
my @delayed_response;
|
||||
my $timeout;
|
||||
|
||||
my $udpsock = IO::Socket::INET->new(LocalAddr => "$localaddr",
|
||||
LocalPort => 5300, Proto => "udp", Reuse => 1) or die "$!";
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
@@ -39,21 +47,18 @@ sub getlimit {
|
||||
return 0;
|
||||
}
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
my $limit = getlimit();
|
||||
|
||||
# If $wait == 0 is returned, returned reply will be sent immediately.
|
||||
# If $wait == 1 is returned, sending the returned reply might be delayed; see
|
||||
# comments inside handle_UDP() for details.
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
my ($qname, $qclass, $qtype) = @_;
|
||||
my ($rcode, @ans, @auth, @add, $wait);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$wait = 0;
|
||||
$count += 1;
|
||||
# Sleep 100ms to make sure that named sends both A and AAAA queries.
|
||||
usleep(100000);
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
@@ -95,6 +100,7 @@ sub reply_handler {
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname =~ /^ns1\.(\d+)\.example\.org$/) {
|
||||
my $next = $1 + 1;
|
||||
$wait = 1;
|
||||
if ($limit == 0 || (! $send_response && $next <= $limit)) {
|
||||
my $rr = new Net::DNS::RR("$1.example.org 86400 $qclass NS ns1.$next.example.org");
|
||||
push @auth, $rr;
|
||||
@@ -108,24 +114,114 @@ sub reply_handler {
|
||||
}
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
return ($rcode, \@ans, \@auth, \@add, $wait);
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
sub handleUDP {
|
||||
my ($buf, $peer) = @_;
|
||||
my ($request, $rcode, $ans, $auth, $add, $wait);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
$request = new Net::DNS::Packet(\$buf, 0);
|
||||
$@ and die $@;
|
||||
|
||||
$ns->main_loop;
|
||||
my ($question) = $request->question;
|
||||
my $qname = $question->qname;
|
||||
my $qclass = $question->qclass;
|
||||
my $qtype = $question->qtype;
|
||||
|
||||
($rcode, $ans, $auth, $add, $wait) = reply_handler($qname, $qclass, $qtype);
|
||||
|
||||
my $reply = $request->reply();
|
||||
|
||||
$reply->header->rcode($rcode);
|
||||
$reply->header->aa(@$ans ? 1 : 0);
|
||||
$reply->header->id($request->header->id);
|
||||
$reply->{answer} = $ans if $ans;
|
||||
$reply->{authority} = $auth if $auth;
|
||||
$reply->{additional} = $add if $add;
|
||||
|
||||
if ($wait) {
|
||||
# reply_handler() asked us to delay sending this reply until
|
||||
# another reply with $wait == 1 is generated or a timeout
|
||||
# occurs.
|
||||
if (@delayed_response) {
|
||||
# A delayed reply is already queued, so we can now send
|
||||
# both the delayed reply and the current reply.
|
||||
send_delayed_response();
|
||||
return $reply;
|
||||
} elsif ($no_more_waiting) {
|
||||
# It was determined before that there is no point in
|
||||
# waiting for "accompanying" queries. Thus, send the
|
||||
# current reply immediately.
|
||||
return $reply;
|
||||
} else {
|
||||
# No delayed reply is queued and the client is expected
|
||||
# to send an "accompanying" query shortly. Do not send
|
||||
# the current reply right now, just save it for later
|
||||
# and wait for an "accompanying" query to be received.
|
||||
@delayed_response = ($reply, $peer);
|
||||
$timeout = 0.5;
|
||||
return;
|
||||
}
|
||||
} else {
|
||||
# Send reply immediately.
|
||||
return $reply;
|
||||
}
|
||||
}
|
||||
|
||||
sub send_delayed_response {
|
||||
my ($reply, $peer) = @delayed_response;
|
||||
# Truncation to 512 bytes is required for triggering "NS explosion" on
|
||||
# builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer);
|
||||
undef @delayed_response;
|
||||
undef $timeout;
|
||||
}
|
||||
|
||||
# Main
|
||||
my $rin;
|
||||
my $rout;
|
||||
for (;;) {
|
||||
$rin = '';
|
||||
vec($rin, fileno($udpsock), 1) = 1;
|
||||
|
||||
select($rout = $rin, undef, undef, $timeout);
|
||||
|
||||
if (vec($rout, fileno($udpsock), 1)) {
|
||||
my ($buf, $peer, $reply);
|
||||
$udpsock->recv($buf, 512);
|
||||
$peer = $udpsock->peername();
|
||||
$reply = handleUDP($buf, $peer);
|
||||
# Truncation to 512 bytes is required for triggering "NS
|
||||
# explosion" on builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer) if $reply;
|
||||
} else {
|
||||
# An "accompanying" query was expected to come in, but did not.
|
||||
# Assume the client never sends "accompanying" queries to
|
||||
# prevent pointlessly waiting for them ever again.
|
||||
$no_more_waiting = 1;
|
||||
# Send the delayed reply to the query which caused us to wait.
|
||||
send_delayed_response();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,89 +0,0 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
$pidf->close or die "cannot close pid file: $!";
|
||||
sub rmpid { unlink "ans.pid"; exit 1; };
|
||||
|
||||
$SIG{INT} = \&rmpid;
|
||||
$SIG{TERM} = \&rmpid;
|
||||
|
||||
my $count = 0;
|
||||
my $send_response = 0;
|
||||
|
||||
my $localaddr = "10.53.0.4";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$count += 1;
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
my ($ttl, $rdata) = (0, "$count");
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
print ("\tcount: $count\n");
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "reset" ) {
|
||||
$count = 0;
|
||||
$send_response = 0;
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
|
||||
$ns->main_loop;
|
||||
@@ -1,4 +1,4 @@
|
||||
; Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -11,4 +11,4 @@ ns.tld1. 60 IN A 10.53.0.1
|
||||
example.org. 60 IN NS direct.example.org.
|
||||
direct.example.org. 60 IN A 10.53.0.2
|
||||
example.net. 60 IN NS direct.example.net.
|
||||
direct.example.net. 60 IN A 10.53.0.4
|
||||
direct.example.net. 60 IN A 10.53.0.2
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -9,6 +9,20 @@
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
if $PERL -e 'use Net::DNS;' 2>/dev/null
|
||||
then
|
||||
if $PERL -e 'use Net::DNS; die if ($Net::DNS::VERSION <= 0.78);' 2>/dev/null
|
||||
then
|
||||
:
|
||||
else
|
||||
echo "I:Net::DNS versions up to 0.78 have a bug that causes this test to fail: please update." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:This test requires the Net::DNS library." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
||||
then
|
||||
:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -14,101 +14,107 @@ DIGOPTS="-p 5300"
|
||||
status=0
|
||||
n=0
|
||||
|
||||
ns3_reset() {
|
||||
cp $1 ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns3 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush | sed 's/^/I: ns3 /'
|
||||
}
|
||||
|
||||
ns3_sends_aaaa_queries() {
|
||||
if grep "started AAAA fetch" ns3/named.run >/dev/null; then
|
||||
return 0
|
||||
else
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Check whether the number of queries ans2 received from ns3 (this value is
|
||||
# read from dig output stored in file $1) is as expected. The expected query
|
||||
# count is variable:
|
||||
# - if ns3 sends AAAA queries, the query count should equal $2,
|
||||
# - if ns3 does not send AAAA queries, the query count should equal $3.
|
||||
check_query_count() {
|
||||
count=`sed 's/[^0-9]//g;' $1`
|
||||
expected_count_with_aaaa=$2
|
||||
expected_count_without_aaaa=$3
|
||||
|
||||
if ns3_sends_aaaa_queries; then
|
||||
expected_count=$expected_count_with_aaaa
|
||||
else
|
||||
expected_count=$expected_count_without_aaaa
|
||||
fi
|
||||
|
||||
if [ $count -ne $expected_count ]; then
|
||||
echo "I: count ($count) != $expected_count"
|
||||
ret=1
|
||||
fi
|
||||
}
|
||||
|
||||
echo "I: set max-recursion-depth=12"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "1000" > ans2/ans.limit
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect1.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
else
|
||||
[ $count -eq 14 ] || { ret=1; echo "I: count ($count) != 14"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 26 14
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
sleep 2
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named1.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect2.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 49 ] || { ret=1; echo "I: count ($count) != 49"; }
|
||||
else
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 49 26
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named2.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=5"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect3.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
else
|
||||
[ $count -eq 7 ] || { ret=1; echo "I: count ($count) != 7"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 12 7
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "5" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect4.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 21 ] || { ret=1; echo "I: count ($count) != 21"; }
|
||||
else
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 21 12
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named3.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=50"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "13" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect5.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -118,10 +124,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect6.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -131,20 +137,16 @@ eval count=`cat dig.out.2.test$n`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-queries"
|
||||
cp ns3/named4.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=40"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "10" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect7.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -154,10 +156,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "9" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect8.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -170,10 +172,10 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempting NS explosion ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.3 ns1.1.example.net > dig.out.1.test$n || ret=1
|
||||
sleep 2
|
||||
$DIG $DIGOPTS +short @10.53.0.4 count txt > dig.out.2.test$n || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
[ $count -lt 50 ] || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.7 count txt > dig.out.3.test$n || ret=1
|
||||
|
||||
@@ -14,4 +14,10 @@ $SHELL clean.sh
|
||||
cp ns2/named1.conf ns2/named.conf
|
||||
|
||||
mkdir ns2/nope
|
||||
chmod 555 ns2/nope
|
||||
|
||||
if [ 1 = "${CYGWIN:-0}" ]
|
||||
then
|
||||
setfacl -s user::r-x,group::r-x,other::r-x ns2/nope
|
||||
else
|
||||
chmod 555 ns2/nope
|
||||
fi
|
||||
|
||||
@@ -16,15 +16,6 @@ rm -f dig.out.*
|
||||
|
||||
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd -p 5300"
|
||||
|
||||
# read everything that's been appended to a file since the last time
|
||||
# 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "FNR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
echo "I:checking DNSSEC SERVFAIL is cached ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +dnssec foo.example. a @10.53.0.5 > dig.out.ns5.test$n || ret=1
|
||||
|
||||
@@ -16,6 +16,8 @@
|
||||
#include <stdlib.h>
|
||||
#include <lmdb.h>
|
||||
|
||||
#include <dns/view.h>
|
||||
|
||||
#include <isc/print.h>
|
||||
|
||||
int
|
||||
@@ -36,42 +38,43 @@ main (int argc, char *argv[]) {
|
||||
path = argv[1];
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_env_create: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, path,
|
||||
MDB_RDONLY|MDB_NOTLS|MDB_NOSUBDIR, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, path, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_env_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_txn_begin(env, 0, MDB_RDONLY, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_txn_begin: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_dbi_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
fprintf(stderr, "named-nzd2nzf: mdb_cursor_open: %s",
|
||||
mdb_strerror(status));
|
||||
exit(1);
|
||||
}
|
||||
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||
status == MDB_SUCCESS;
|
||||
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT)) {
|
||||
if (key.mv_data == NULL || key.mv_size == 0 ||
|
||||
data.mv_data == NULL || data.mv_size == 0)
|
||||
{
|
||||
|
||||
@@ -535,6 +535,9 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Define to the sockaddr length type used by getnameinfo(3). */
|
||||
#undef IRS_GETNAMEINFO_SOCKLEN_T
|
||||
|
||||
/* Define if you want to use inline buffers */
|
||||
#undef ISC_BUFFER_USEINLINE
|
||||
|
||||
/* Define to allow building of objects for dlopen(). */
|
||||
#undef ISC_DLZ_DLOPEN
|
||||
|
||||
|
||||
@@ -980,6 +980,7 @@ with_gnu_ld
|
||||
with_sysroot
|
||||
enable_libtool_lock
|
||||
enable_libbind
|
||||
enable_buffer_useinline
|
||||
enable_warn_shadow
|
||||
enable_warn_error
|
||||
enable_developer
|
||||
@@ -1685,11 +1686,14 @@ Optional Features:
|
||||
--enable-fast-install[=PKGS]
|
||||
optimize for fast installation [default=yes]
|
||||
--disable-libtool-lock avoid locking (might break parallel builds)
|
||||
--enable-libbind deprecated
|
||||
--enable-warn-shadow turn on -Wshadow when compiling
|
||||
--enable-warn-error turn on -Werror when compiling
|
||||
--enable-libbind deprecated
|
||||
--enable-buffer-useinline
|
||||
define ISC_BUFFER_USEINLINE when compiling
|
||||
[default=yes]
|
||||
--enable-warn-shadow turn on -Wshadow when compiling
|
||||
--enable-warn-error turn on -Werror when compiling
|
||||
--enable-developer enable developer build settings
|
||||
--enable-afl enable American Fuzzy Lop test harness [default=no]
|
||||
--enable-afl enable American Fuzzy Lop test harness [default=no]
|
||||
--enable-seccomp enable support for libseccomp system call filtering
|
||||
[default=no]
|
||||
--enable-kqueue use BSD kqueue when available [default=yes]
|
||||
@@ -1701,26 +1705,27 @@ Optional Features:
|
||||
check OpenSSL version [default=yes]
|
||||
--enable-openssl-hash use OpenSSL for hash functions [default=yes]
|
||||
--enable-crypto-rand use the crypto provider for random [default=yes]
|
||||
--enable-largefile 64-bit file support
|
||||
--enable-largefile 64-bit file support
|
||||
--enable-backtrace log stack backtrace on abort [default=yes]
|
||||
--enable-symtable use internal symbol table for backtrace
|
||||
[all|minimal(default)|none]
|
||||
--enable-ipv6 use IPv6 default=autodetect
|
||||
[all|minimal(default)|none]
|
||||
--enable-ipv6 use IPv6 [default=autodetect]
|
||||
--disable-tcp-fastopen disable TCP Fast Open support [default=autodetect]
|
||||
--enable-getifaddrs enable the use of getifaddrs() [yes|no].
|
||||
--disable-isc-spnego use SPNEGO from GSSAPI library
|
||||
--disable-chroot disable chroot
|
||||
--disable-linux-caps disable linux capabilities
|
||||
--enable-atomic enable machine specific atomic operations
|
||||
[default=autodetect]
|
||||
--disable-linux-caps disable linux capabilities
|
||||
--enable-atomic enable machine specific atomic operations
|
||||
[default=autodetect]
|
||||
--enable-fixed-rrset enable fixed rrset ordering [default=no]
|
||||
--disable-rpz-nsip disable rpz nsip rules [default=enabled]
|
||||
--disable-rpz-nsdname disable rpz nsdname rules [default=enabled]
|
||||
--enable-dnsrps-dl DNS Response Policy Service delayed link [default=$librpz_dl]
|
||||
--disable-rpz-nsip disable rpz nsip rules [default=enabled]
|
||||
--disable-rpz-nsdname disable rpz nsdname rules [default=enabled]
|
||||
--enable-dnsrps-dl DNS Response Policy Service delayed link
|
||||
[default=$librpz_dl]
|
||||
--enable-dnsrps enable DNS Response Policy Service API
|
||||
--enable-dnstap enable dnstap support (requires fstrm, protobuf-c)
|
||||
--enable-querytrace enable very verbose query trace logging [default=no]
|
||||
--enable-full-report report values of all configure options
|
||||
--enable-full-report report values of all configure options
|
||||
|
||||
Optional Packages:
|
||||
--with-PACKAGE[=ARG] use PACKAGE [ARG=yes]
|
||||
@@ -1734,54 +1739,60 @@ Optional Packages:
|
||||
--with-python-install-dir=PATH
|
||||
installation directory for Python modules
|
||||
--with-geoip=PATH Build with GeoIP support (yes|no|path)
|
||||
--with-gssapi=[PATH|[/path/]krb5-config] Specify path for system-supplied GSSAPI [default=yes]
|
||||
--with-gssapi=PATH|/path/krb5-config
|
||||
Specify path for system-supplied GSSAPI
|
||||
[default=yes]
|
||||
--with-randomdev=PATH Specify path for random device
|
||||
--with-locktype=ARG Specify mutex lock type (adaptive or standard)
|
||||
--with-libtool use GNU libtool
|
||||
--with-openssl=PATH Build with OpenSSL yes|no|path.
|
||||
(Crypto is required for DNSSEC)
|
||||
--with-pkcs11=PATH Build with PKCS11 support yes|no|path
|
||||
(PATH is for the PKCS11 provider)
|
||||
--with-openssl=PATH Build with OpenSSL [yes|no|path]. (Crypto is
|
||||
required for DNSSEC)
|
||||
--with-pkcs11=PATH Build with PKCS11 support [yes|no|path] (PATH is for
|
||||
the PKCS11 provider)
|
||||
--with-ecdsa Crypto ECDSA
|
||||
--with-gost Crypto GOST yes|no|raw|asn1.
|
||||
--with-eddsa Crypto EDDSA yes|all|no.
|
||||
--with-gost Crypto GOST [yes|no|raw|asn1].
|
||||
--with-eddsa Crypto EDDSA [yes|all|no].
|
||||
--with-aes Crypto AES
|
||||
--with-cc-alg=ALG choose the algorithm for Client Cookie [aes|sha1|sha256]
|
||||
--with-lmdb=PATH build with LMDB library yes|no|path
|
||||
--with-libxml2=PATH build with libxml2 library yes|no|path
|
||||
--with-libjson=PATH build with libjson0 library yes|no|path
|
||||
--with-cc-alg=ALG choose the algorithm for Client Cookie
|
||||
[aes|sha1|sha256]
|
||||
--with-lmdb=PATH build with LMDB library [yes|no|path]
|
||||
--with-libxml2=PATH build with libxml2 library [yes|no|path]
|
||||
--with-libjson=PATH build with libjson0 library [yes|no|path]
|
||||
--with-zlib=PATH build with zlib for HTTP compression [default=yes]
|
||||
--with-purify=PATH use Rational purify
|
||||
--with-gperftools-profiler use gperftools CPU profiler
|
||||
--with-kame=PATH use Kame IPv6 default path /usr/local/v6
|
||||
--with-readline=LIBSPEC specify readline library default auto
|
||||
--with-gperftools-profiler
|
||||
use gperftools CPU profiler
|
||||
--with-kame=PATH use Kame IPv6 [default path /usr/local/v6]
|
||||
--with-readline=LIBSPEC specify readline library [default auto]
|
||||
|
||||
--with-dnsrps-libname DNSRPS provider library name (librpz.so)
|
||||
--with-dnsrps-dir path to DNSRPS provider library
|
||||
--with-dnsrps-libname DNSRPS provider library name (librpz.so)
|
||||
--with-dnsrps-dir path to DNSRPS provider library
|
||||
--with-protobuf-c=path Path where protobuf-c is installed, for dnstap
|
||||
--with-libfstrm=path Path where libfstrm is installed, for dnstap
|
||||
--with-docbook-xsl=PATH specify path for Docbook-XSL stylesheets
|
||||
--with-idn=MPREFIX enable IDN support using idnkit default PREFIX
|
||||
--with-libiconv=IPREFIX GNU libiconv are in IPREFIX default PREFIX
|
||||
--with-iconv=LIBSPEC specify iconv library default -liconv
|
||||
--with-idn=MPREFIX enable IDN support using idnkit [default PREFIX]
|
||||
--with-libiconv=IPREFIX GNU libiconv are in IPREFIX [default PREFIX]
|
||||
--with-iconv=LIBSPEC specify iconv library [default -liconv]
|
||||
--with-idnlib=ARG specify libidnkit
|
||||
--with-atf=ARG support Automated Test Framework
|
||||
--with-atf support Automated Test Framework
|
||||
--with-tuning=ARG Specify server tuning (large or default)
|
||||
--with-dlopen=ARG support dynamically loadable DLZ drivers
|
||||
--with-dlz-postgres=PATH Build with Postgres DLZ driver yes|no|path.
|
||||
(Required to use Postgres with DLZ)
|
||||
--with-dlz-mysql=PATH Build with MySQL DLZ driver yes|no|path.
|
||||
(Required to use MySQL with DLZ)
|
||||
--with-dlz-bdb=PATH Build with Berkeley DB DLZ driver yes|no|path.
|
||||
(Required to use Berkeley DB with DLZ)
|
||||
--with-dlz-filesystem=ARG Build with filesystem DLZ driver yes|no.
|
||||
(Required to use file system driver with DLZ)
|
||||
--with-dlz-ldap=PATH Build with LDAP DLZ driver yes|no|path.
|
||||
(Required to use LDAP with DLZ)
|
||||
--with-dlz-odbc=PATH Build with ODBC DLZ driver yes|no|path.
|
||||
(Required to use ODBC with DLZ)
|
||||
--with-dlz-stub=ARG Build with stub DLZ driver yes|no.
|
||||
(Required to use stub driver with DLZ)
|
||||
--with-dlz-postgres=PATH
|
||||
Build with Postgres DLZ driver [yes|no|path].
|
||||
(Required to use Postgres with DLZ)
|
||||
--with-dlz-mysql=PATH Build with MySQL DLZ driver [yes|no|path]. (Required
|
||||
to use MySQL with DLZ)
|
||||
--with-dlz-bdb=PATH Build with Berkeley DB DLZ driver [yes|no|path].
|
||||
(Required to use Berkeley DB with DLZ)
|
||||
--with-dlz-filesystem=ARG
|
||||
Build with filesystem DLZ driver [yes|no]. (Required
|
||||
to use file system driver with DLZ)
|
||||
--with-dlz-ldap=PATH Build with LDAP DLZ driver [yes|no|path]. (Required
|
||||
to use LDAP with DLZ)
|
||||
--with-dlz-odbc=PATH Build with ODBC DLZ driver [yes|no|path]. (Required
|
||||
to use ODBC with DLZ)
|
||||
--with-dlz-stub=ARG Build with stub DLZ driver [yes|no]. (Required to
|
||||
use stub driver with DLZ)
|
||||
--with-make-clean run "make clean" at end of configure [yes|no]
|
||||
|
||||
Some influential environment variables:
|
||||
@@ -11444,6 +11455,20 @@ It is available from http://www.isc.org as a separate download." "$LINENO" 5
|
||||
;;
|
||||
esac
|
||||
|
||||
# Check whether --enable-buffer_useinline was given.
|
||||
if test "${enable_buffer_useinline+set}" = set; then :
|
||||
enableval=$enable_buffer_useinline; if test yes = "${enable}"
|
||||
then
|
||||
|
||||
$as_echo "#define ISC_BUFFER_USEINLINE 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
else
|
||||
$as_echo "#define ISC_BUFFER_USEINLINE 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
|
||||
# Check whether --enable-warn_shadow was given.
|
||||
if test "${enable_warn_shadow+set}" = set; then :
|
||||
enableval=$enable_warn_shadow;
|
||||
@@ -11925,24 +11950,24 @@ $as_echo_n "checking python2 version >= 2.7 or python3 version >= 3.2... " >&6;
|
||||
if ${PYTHON:-false} -c "$testminvers"; then
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: found" >&5
|
||||
$as_echo "found" >&6; }
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
$as_echo "not found" >&6; }
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
continue
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
continue
|
||||
fi
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking python module 'argparse'" >&5
|
||||
$as_echo_n "checking python module 'argparse'... " >&6; }
|
||||
if ${PYTHON:-false} -c "$testargparse"; then
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: found" >&5
|
||||
$as_echo "found" >&6; }
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
$as_echo "not found" >&6; }
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
continue
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
continue
|
||||
fi
|
||||
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking python module 'ply'" >&5
|
||||
@@ -11951,11 +11976,11 @@ $as_echo_n "checking python module 'ply'... " >&6; }
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: found" >&5
|
||||
$as_echo "found" >&6; }
|
||||
break
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
|
||||
$as_echo "not found" >&6; }
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
unset ac_cv_path_PYTHON
|
||||
unset PYTHON
|
||||
fi
|
||||
done
|
||||
if test "X$PYTHON" != "X"
|
||||
@@ -13382,12 +13407,12 @@ _ACEOF
|
||||
if ac_fn_c_try_compile "$LINENO"; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
$as_echo "#define HAVE_UNAME 1" >>confdefs.h
|
||||
$as_echo "#define HAVE_UNAME 1" >>confdefs.h
|
||||
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: uname is not correctly supported" >&5
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: uname is not correctly supported" >&5
|
||||
$as_echo "$as_me: WARNING: uname is not correctly supported" >&2;}
|
||||
fi
|
||||
rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
@@ -15447,12 +15472,12 @@ else
|
||||
fi
|
||||
|
||||
|
||||
case "$locktype" in
|
||||
adaptive)
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for PTHREAD_MUTEX_ADAPTIVE_NP" >&5
|
||||
case "$locktype" in
|
||||
adaptive)
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for PTHREAD_MUTEX_ADAPTIVE_NP" >&5
|
||||
$as_echo_n "checking for PTHREAD_MUTEX_ADAPTIVE_NP... " >&6; }
|
||||
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
/* end confdefs.h. */
|
||||
|
||||
#ifndef _GNU_SOURCE
|
||||
@@ -15481,15 +15506,15 @@ else
|
||||
$as_echo "using standard lock type" >&6; }
|
||||
fi
|
||||
rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
;;
|
||||
standard)
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: using standard lock type" >&5
|
||||
;;
|
||||
standard)
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: using standard lock type" >&5
|
||||
$as_echo "using standard lock type" >&6; }
|
||||
;;
|
||||
*)
|
||||
as_fn_error $? "You must specify \"adaptive\" or \"standard\" for --with-locktype." "$LINENO" 5
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
as_fn_error $? "You must specify \"adaptive\" or \"standard\" for --with-locktype." "$LINENO" 5
|
||||
;;
|
||||
esac
|
||||
|
||||
for ac_header in sched.h
|
||||
do :
|
||||
@@ -15968,7 +15993,7 @@ If you do not want OpenSSL, use --without-openssl" "$LINENO" 5
|
||||
*)
|
||||
if test "yes" = "$want_native_pkcs11"
|
||||
then
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: " >&5
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: " >&5
|
||||
$as_echo "" >&6; }
|
||||
as_fn_error $? "OpenSSL and native PKCS11 cannot be used together." "$LINENO" 5
|
||||
fi
|
||||
@@ -16492,7 +16517,7 @@ $as_echo_n "checking for OpenSSL AES support... " >&6; }
|
||||
if test "$cross_compiling" = yes; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: using --with-aes" >&5
|
||||
$as_echo "using --with-aes" >&6; }
|
||||
# Expect cross-compiling with a modern OpenSSL
|
||||
# Expect cross-compiling with a modern OpenSSL
|
||||
have_aes="evp"
|
||||
else
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
@@ -17239,8 +17264,8 @@ then
|
||||
$as_echo "#define HAVE_LMDB 1" >>confdefs.h
|
||||
|
||||
NZD_TOOLS="nzd"
|
||||
NZDSRCS='${NZDSRCS}'
|
||||
NZDTARGETS='${NZDTARGETS}'
|
||||
NZDSRCS='${NZDSRCS}'
|
||||
NZDTARGETS='${NZDTARGETS}'
|
||||
fi
|
||||
|
||||
|
||||
@@ -17508,7 +17533,7 @@ case "$with_zlib" in
|
||||
done
|
||||
;;
|
||||
*)
|
||||
if test -f "${with_zlib}/zlib.h"
|
||||
if test -f "${with_zlib}/include/zlib.h"
|
||||
then
|
||||
zlib_cflags="-I${with_zlib}/include"
|
||||
LIBS="$LIBS -L${with_zlib}/lib"
|
||||
@@ -19371,11 +19396,11 @@ else
|
||||
|
||||
#include <stdio.h>
|
||||
main() {
|
||||
size_t j = 0;
|
||||
char buf[100];
|
||||
buf[0] = 0;
|
||||
sprintf(buf, "%zu", j);
|
||||
exit(strcmp(buf, "0") != 0);
|
||||
size_t j = 0;
|
||||
char buf[100];
|
||||
buf[0] = 0;
|
||||
sprintf(buf, "%zu", j);
|
||||
exit(strcmp(buf, "0") != 0);
|
||||
}
|
||||
|
||||
_ACEOF
|
||||
@@ -19387,9 +19412,9 @@ else
|
||||
$as_echo "no" >&6; }
|
||||
ISC_PRINT_OBJS="print.$O"
|
||||
ISC_PRINT_SRCS="print.c"
|
||||
ISC_PLATFORM_NEEDPRINTF='#define ISC_PLATFORM_NEEDPRINTF 1'
|
||||
ISC_PLATFORM_NEEDFPRINTF='#define ISC_PLATFORM_NEEDFPRINTF 1'
|
||||
ISC_PLATFORM_NEEDFSRINTF='#define ISC_PLATFORM_NEEDSPRINTF 1'
|
||||
ISC_PLATFORM_NEEDPRINTF='#define ISC_PLATFORM_NEEDPRINTF 1'
|
||||
ISC_PLATFORM_NEEDFPRINTF='#define ISC_PLATFORM_NEEDFPRINTF 1'
|
||||
ISC_PLATFORM_NEEDFSRINTF='#define ISC_PLATFORM_NEEDSPRINTF 1'
|
||||
ISC_PLATFORM_NEEDVSNPRINTF="#define ISC_PLATFORM_NEEDVSNPRINTF 1"
|
||||
fi
|
||||
rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \
|
||||
@@ -19718,11 +19743,11 @@ _ACEOF
|
||||
if ac_fn_c_try_compile "$LINENO"; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
ISC_PLATFORM_HAVESTATNSEC="#define ISC_PLATFORM_HAVESTATNSEC 1"
|
||||
ISC_PLATFORM_HAVESTATNSEC="#define ISC_PLATFORM_HAVESTATNSEC 1"
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
ISC_PLATFORM_HAVESTATNSEC="#undef ISC_PLATFORM_HAVESTATNSEC"
|
||||
ISC_PLATFORM_HAVESTATNSEC="#undef ISC_PLATFORM_HAVESTATNSEC"
|
||||
fi
|
||||
rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
|
||||
@@ -20129,6 +20154,7 @@ done
|
||||
#
|
||||
# Machine architecture dependent features
|
||||
#
|
||||
have_stdatomic=no
|
||||
for ac_header in stdatomic.h
|
||||
do :
|
||||
ac_fn_c_check_header_mongrel "$LINENO" "stdatomic.h" "ac_cv_header_stdatomic_h" "$ac_includes_default"
|
||||
@@ -20136,9 +20162,11 @@ if test "x$ac_cv_header_stdatomic_h" = xyes; then :
|
||||
cat >>confdefs.h <<_ACEOF
|
||||
#define HAVE_STDATOMIC_H 1
|
||||
_ACEOF
|
||||
ISC_PLATFORM_HAVESTDATOMIC="#define ISC_PLATFORM_HAVESTDATOMIC 1"
|
||||
have_stdatomic=yes
|
||||
ISC_PLATFORM_HAVESTDATOMIC="#define ISC_PLATFORM_HAVESTDATOMIC 1"
|
||||
else
|
||||
ISC_PLATFORM_HAVESTDATOMIC="#undef ISC_PLATFORM_HAVESTDATOMIC"
|
||||
have_stdatomic=no
|
||||
ISC_PLATFORM_HAVESTDATOMIC="#undef ISC_PLATFORM_HAVESTDATOMIC"
|
||||
fi
|
||||
|
||||
done
|
||||
@@ -20219,12 +20247,42 @@ rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
esac
|
||||
;;
|
||||
no)
|
||||
have_stdatomic=no
|
||||
ISC_PLATFORM_HAVESTDATOMIC="#undef ISC_PLATFORM_HAVESTDATOMIC"
|
||||
use_atomic=no
|
||||
arch=noatomic
|
||||
;;
|
||||
esac
|
||||
|
||||
if test "X$have_stdatomic" = "Xyes"; then
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if -latomic is needed to use 64-bit stdatomic.h primitives" >&5
|
||||
$as_echo_n "checking if -latomic is needed to use 64-bit stdatomic.h primitives... " >&6; }
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
/* end confdefs.h. */
|
||||
#include <stdatomic.h>
|
||||
int
|
||||
main ()
|
||||
{
|
||||
atomic_int_fast64_t val = 0; atomic_fetch_add_explicit(&val, 1, memory_order_relaxed);
|
||||
;
|
||||
return 0;
|
||||
}
|
||||
_ACEOF
|
||||
if ac_fn_c_try_link "$LINENO"; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
ISC_ATOMIC_LIBS=""
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
ISC_ATOMIC_LIBS="-latomic"
|
||||
|
||||
fi
|
||||
rm -f core conftest.err conftest.$ac_objext \
|
||||
conftest$ac_exeext conftest.$ac_ext
|
||||
LIBS="$LIBS $ISC_ATOMIC_LIBS"
|
||||
fi
|
||||
|
||||
|
||||
|
||||
ISC_PLATFORM_USEOSFASM="#undef ISC_PLATFORM_USEOSFASM"
|
||||
@@ -20474,7 +20532,7 @@ int
|
||||
main ()
|
||||
{
|
||||
|
||||
return (__builtin_expect(1, 1) ? 1 : 0);
|
||||
return (__builtin_expect(1, 1) ? 1 : 0);
|
||||
|
||||
;
|
||||
return 0;
|
||||
@@ -20482,14 +20540,14 @@ main ()
|
||||
_ACEOF
|
||||
if ac_fn_c_try_link "$LINENO"; then :
|
||||
|
||||
have_builtin_expect=yes
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
have_builtin_expect=yes
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
|
||||
else
|
||||
|
||||
have_builtin_expect=no
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
have_builtin_expect=no
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
|
||||
fi
|
||||
@@ -20513,7 +20571,7 @@ int
|
||||
main ()
|
||||
{
|
||||
|
||||
return (__builtin_clz(0xff) == 24 ? 1 : 0);
|
||||
return (__builtin_clz(0xff) == 24 ? 1 : 0);
|
||||
|
||||
;
|
||||
return 0;
|
||||
@@ -20521,14 +20579,14 @@ main ()
|
||||
_ACEOF
|
||||
if ac_fn_c_try_link "$LINENO"; then :
|
||||
|
||||
have_builtin_clz=yes
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
have_builtin_clz=yes
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
|
||||
else
|
||||
|
||||
have_builtin_clz=no
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
have_builtin_clz=no
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
|
||||
fi
|
||||
@@ -20930,9 +20988,9 @@ else
|
||||
fi
|
||||
|
||||
if test "x$enable_dnsrps" != "xno"; then
|
||||
if test "x$dnsrps_avail" != "xyes"; then
|
||||
as_fn_error $? "dlopen and librpz.so needed for DNSRPS" "$LINENO" 5
|
||||
fi
|
||||
if test "x$dnsrps_avail" != "xyes"; then
|
||||
as_fn_error $? "dlopen and librpz.so needed for DNSRPS" "$LINENO" 5
|
||||
fi
|
||||
if test "x$dnsrps_lib_open" = "x0"; then
|
||||
as_fn_error $? "dlopen and librpz.so needed for DNSRPS" "$LINENO" 5
|
||||
fi
|
||||
@@ -22200,7 +22258,7 @@ if test "no" != "$atf"; then
|
||||
$as_echo "#define ATF_TEST 1" >>confdefs.h
|
||||
|
||||
STD_CINCLUDES="$STD_CINCLUDES -I$atf/include"
|
||||
STD_CDEFINES="$STD_CDEFINES -DNS_HOOKS_ENABLE=1"
|
||||
STD_CDEFINES="$STD_CDEFINES -DNS_HOOKS_ENABLE=1"
|
||||
ATFBIN="$atf/bin"
|
||||
ATFLIBS="-L$atf/lib -latf-c"
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for exp in -lm" >&5
|
||||
@@ -22862,7 +22920,11 @@ else
|
||||
fi
|
||||
|
||||
|
||||
for ac_prog in mysql_config
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
for ac_prog in mysql_config
|
||||
do
|
||||
# Extract the first word of "$ac_prog", so it can be a program name with args.
|
||||
set dummy $ac_prog; ac_word=$2
|
||||
@@ -22904,11 +22966,6 @@ fi
|
||||
test -n "$MYSQL_CONFIG" && break
|
||||
done
|
||||
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
if test -n "$MYSQL_CONFIG"
|
||||
then
|
||||
mysql_include=`${MYSQL_CONFIG} --include`
|
||||
@@ -26145,9 +26202,9 @@ yes)
|
||||
then
|
||||
if test "yes" = "$silent"
|
||||
then
|
||||
make clean > /dev/null
|
||||
else
|
||||
make clean
|
||||
make clean > /dev/null
|
||||
else
|
||||
make clean
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
@@ -26165,84 +26222,84 @@ report() {
|
||||
echo "-------------------------------------------------------------------------------"
|
||||
echo "Optional features enabled:"
|
||||
if $use_threads; then
|
||||
echo " Multiprocessing support (--enable-threads)"
|
||||
if test "yes" = "$enable_full_report" -o "standard" = "$locktype"; then
|
||||
echo " Mutex lock type: $locktype"
|
||||
fi
|
||||
echo " Multiprocessing support (--enable-threads)"
|
||||
if test "yes" = "$enable_full_report" -o "standard" = "$locktype"; then
|
||||
echo " Mutex lock type: $locktype"
|
||||
fi
|
||||
fi
|
||||
test "large" = "$use_tuning" && echo " Large-system tuning (--with-tuning)"
|
||||
test "no" = "$use_dnstap" || \
|
||||
echo " Allow 'dnstap' packet logging (--enable-dnstap)"
|
||||
echo " Allow 'dnstap' packet logging (--enable-dnstap)"
|
||||
test "no" = "$use_geoip" || echo " GeoIP access control (--with-geoip)"
|
||||
test "no" = "$use_gssapi" || echo " GSS-API (--with-gssapi)"
|
||||
if test "yes" = "$enable_full_report" -o "aes" != "$with_cc_alg"; then
|
||||
echo " Algorithm: $with_cc_alg"
|
||||
echo " Algorithm: $with_cc_alg"
|
||||
fi
|
||||
|
||||
# these lines are only printed if run with --enable-full-report
|
||||
if test "yes" = "$enable_full_report"; then
|
||||
test "no" = "$enable_ipv6" -o "no" = "$found_ipv6" || \
|
||||
echo " IPv6 support (--enable-ipv6)"
|
||||
test "X$CRYPTO" = "X" -o "yes" = "$want_native_pkcs11" || \
|
||||
echo " OpenSSL cryptography/DNSSEC (--with-openssl)"
|
||||
test "no" = "$want_crypto_rand" || \
|
||||
echo " Crypto provider entropy source (--enable-crypto-rand)"
|
||||
test "X$PYTHON" = "X" || echo " Python tools (--with-python)"
|
||||
test "X$XMLSTATS" = "X" || echo " XML statistics (--with-libxml2)"
|
||||
test "X$JSONSTATS" = "X" || echo " JSON statistics (--with-libjson)"
|
||||
test "X$ZLIB" = "X" || echo " HTTP zlib compression (--with-zlib)"
|
||||
test "X$NZD_TOOLS" = "X" || echo " LMDB database to store configuration for 'addzone' zones (--with-lmdb)"
|
||||
test "no" = "$enable_ipv6" -o "no" = "$found_ipv6" || \
|
||||
echo " IPv6 support (--enable-ipv6)"
|
||||
test "X$CRYPTO" = "X" -o "yes" = "$want_native_pkcs11" || \
|
||||
echo " OpenSSL cryptography/DNSSEC (--with-openssl)"
|
||||
test "no" = "$want_crypto_rand" || \
|
||||
echo " Crypto provider entropy source (--enable-crypto-rand)"
|
||||
test "X$PYTHON" = "X" || echo " Python tools (--with-python)"
|
||||
test "X$XMLSTATS" = "X" || echo " XML statistics (--with-libxml2)"
|
||||
test "X$JSONSTATS" = "X" || echo " JSON statistics (--with-libjson)"
|
||||
test "X$ZLIB" = "X" || echo " HTTP zlib compression (--with-zlib)"
|
||||
test "X$NZD_TOOLS" = "X" || echo " LMDB database to store configuration for 'addzone' zones (--with-lmdb)"
|
||||
fi
|
||||
|
||||
if test "no" != "$use_pkcs11"; then
|
||||
if test "yes" = "$want_native_pkcs11"; then
|
||||
echo " Native PKCS#11/Cryptoki support (--enable-native-pkcs11)"
|
||||
else
|
||||
echo " PKCS#11/Cryptoki support using OpenSSL (--with-pkcs11)"
|
||||
fi
|
||||
echo " Provider library: $PKCS11_PROVIDER"
|
||||
if test "yes" = "$want_native_pkcs11"; then
|
||||
echo " Native PKCS#11/Cryptoki support (--enable-native-pkcs11)"
|
||||
else
|
||||
echo " PKCS#11/Cryptoki support using OpenSSL (--with-pkcs11)"
|
||||
fi
|
||||
echo " Provider library: $PKCS11_PROVIDER"
|
||||
fi
|
||||
if test "yes" = "$OPENSSL_GOST" -o "yes" = "$PKCS11_GOST"; then
|
||||
echo " GOST algorithm support (encoding: $gosttype) (--with-gost)"
|
||||
echo " GOST algorithm support (encoding: $gosttype) (--with-gost)"
|
||||
fi
|
||||
test "yes" = "$OPENSSL_ECDSA" -o "$PKCS11_ECDSA" && \
|
||||
echo " ECDSA algorithm support (--with-ecdsa)"
|
||||
echo " ECDSA algorithm support (--with-ecdsa)"
|
||||
test "yes" = "$OPENSSL_ED25519" -o "$PKCS11_ED25519" && \
|
||||
echo " EDDSA algorithm support (--with-eddsa)"
|
||||
echo " EDDSA algorithm support (--with-eddsa)"
|
||||
test "yes" = "$enable_dnsrps" && \
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
test "yes" = "$enable_fixed" && \
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
test "yes" = "$enable_seccomp" && \
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
test "yes" = "$want_backtrace" && \
|
||||
echo " Print backtrace on crash (--enable-backtrace)"
|
||||
echo " Print backtrace on crash (--enable-backtrace)"
|
||||
test "minimal" = "$want_symtable" && \
|
||||
echo " Use symbol table for backtrace, named only (--enable-symtable)"
|
||||
echo " Use symbol table for backtrace, named only (--enable-symtable)"
|
||||
test "yes" = "$want_symtable" -o "all" = "$want_symtable" && \
|
||||
echo " Use symbol table for backtrace, all binaries (--enable-symtable=all)"
|
||||
echo " Use symbol table for backtrace, all binaries (--enable-symtable=all)"
|
||||
test "no" = "$use_libtool" || echo " Use GNU libtool (--with-libtool)"
|
||||
test "yes" = "$want_querytrace" && \
|
||||
echo " Very verbose query trace logging (--enable-querytrace)"
|
||||
echo " Very verbose query trace logging (--enable-querytrace)"
|
||||
test "no" = "$atf" || echo " Automated Testing Framework (--with-atf)"
|
||||
|
||||
echo " Cryptographic library for DNSSEC: $CRYPTOLIB"
|
||||
|
||||
echo " Dynamically loadable zone (DLZ) drivers:"
|
||||
test "no" = "$use_dlz_bdb" || \
|
||||
echo " Berkeley DB (--with-dlz-bdb)"
|
||||
echo " Berkeley DB (--with-dlz-bdb)"
|
||||
test "no" = "$use_dlz_ldap" || \
|
||||
echo " LDAP (--with-dlz-ldap)"
|
||||
echo " LDAP (--with-dlz-ldap)"
|
||||
test "no" = "$use_dlz_mysql" || \
|
||||
echo " MySQL (--with-dlz-mysql)"
|
||||
echo " MySQL (--with-dlz-mysql)"
|
||||
test "no" = "$use_dlz_odbc" || \
|
||||
echo " ODBC (--with-dlz-odbc)"
|
||||
echo " ODBC (--with-dlz-odbc)"
|
||||
test "no" = "$use_dlz_postgres" || \
|
||||
echo " Postgres (--with-dlz-postgres)"
|
||||
echo " Postgres (--with-dlz-postgres)"
|
||||
test "no" = "$use_dlz_filesystem" || \
|
||||
echo " Filesystem (--with-dlz-filesystem)"
|
||||
echo " Filesystem (--with-dlz-filesystem)"
|
||||
test "no" = "$use_dlz_stub" || \
|
||||
echo " Stub (--with-dlz-stub)"
|
||||
echo " Stub (--with-dlz-stub)"
|
||||
test "$use_dlz_bdb $use_dlz_ldap $use_dlz_mysql $use_dlz_odbc $use_dlz_postgres $use_dlz_filesystem $use_dlz_stub" = "no no no no no no no" && echo " None"
|
||||
|
||||
echo "-------------------------------------------------------------------------------"
|
||||
@@ -26250,43 +26307,43 @@ report() {
|
||||
echo "Features disabled or unavailable on this platform:"
|
||||
$use_threads || echo " Multiprocessing support (--enable-threads)"
|
||||
test "no" = "$enable_ipv6" -o "no" = "$found_ipv6" && \
|
||||
echo " IPv6 support (--enable-ipv6)"
|
||||
echo " IPv6 support (--enable-ipv6)"
|
||||
test "large" = "$use_tuning" || echo " Large-system tuning (--with-tuning)"
|
||||
|
||||
test "no" = "$use_dnstap" && \
|
||||
echo " Allow 'dnstap' packet logging (--enable-dnstap)"
|
||||
echo " Allow 'dnstap' packet logging (--enable-dnstap)"
|
||||
test "no" = "$use_geoip" && echo " GeoIP access control (--with-geoip)"
|
||||
test "no" = "$use_gssapi" && echo " GSS-API (--with-gssapi)"
|
||||
|
||||
test "no" = "$enable_dnsrps" && \
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
|
||||
test "yes" = "$enable_fixed" || \
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
|
||||
if test "X$CRYPTO" = "X" -o "yes" = "$want_native_pkcs11"
|
||||
then
|
||||
echo " OpenSSL cryptography/DNSSEC (--with-openssl)"
|
||||
echo " OpenSSL cryptography/DNSSEC (--with-openssl)"
|
||||
elif test "no" = "$use_pkcs11"; then
|
||||
echo " PKCS#11/Cryptoki support (--with-pkcs11)"
|
||||
echo " PKCS#11/Cryptoki support (--with-pkcs11)"
|
||||
fi
|
||||
test "yes" = "$want_native_pkcs11" ||
|
||||
echo " Native PKCS#11/Cryptoki support (--enable-native-pkcs11)"
|
||||
echo " Native PKCS#11/Cryptoki support (--enable-native-pkcs11)"
|
||||
test "X$CRYPTO" = "X" -o "yes" = "$OPENSSL_GOST" -o "yes" = "$PKCS11_GOST" || \
|
||||
echo " GOST algorithm support (--with-gost)"
|
||||
echo " GOST algorithm support (--with-gost)"
|
||||
test "X$CRYPTO" = "X" -o "yes" = "$OPENSSL_ECDSA" -o "yes" = "$PKCS11_ECDSA" || \
|
||||
echo " ECDSA algorithm support (--with-ecdsa)"
|
||||
echo " ECDSA algorithm support (--with-ecdsa)"
|
||||
test "X$CRYPTO" = "X" -o "yes" = "$OPENSSL_ED25519" -o "yes" = "$PKCS11_ED25519" || \
|
||||
echo " EDDSA algorithm support (--with-eddsa)"
|
||||
echo " EDDSA algorithm support (--with-eddsa)"
|
||||
test "yes" = "$want_crypto_rand" || \
|
||||
echo " Crypto provider entropy source (--enable-crypto-rand)"
|
||||
echo " Crypto provider entropy source (--enable-crypto-rand)"
|
||||
|
||||
test "yes" = "$enable_seccomp" || \
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
test "yes" = "$want_backtrace" || \
|
||||
echo " Print backtrace on crash (--enable-backtrace)"
|
||||
echo " Print backtrace on crash (--enable-backtrace)"
|
||||
test "yes" = "$want_querytrace" || \
|
||||
echo " Very verbose query trace logging (--enable-querytrace)"
|
||||
echo " Very verbose query trace logging (--enable-querytrace)"
|
||||
|
||||
test "yes" = "$use_libtool" || echo " Use GNU libtool (--with-libtool)"
|
||||
test "no" = "$atf" && echo " Automated Testing Framework (--with-atf)"
|
||||
@@ -26305,20 +26362,20 @@ report() {
|
||||
|
||||
|
||||
if test "X$ac_unrecognized_opts" != "X"; then
|
||||
echo
|
||||
echo "Unrecognized options:"
|
||||
echo " $ac_unrecognized_opts"
|
||||
echo
|
||||
echo "Unrecognized options:"
|
||||
echo " $ac_unrecognized_opts"
|
||||
fi
|
||||
|
||||
if test "yes" != "$enable_full_report"; then
|
||||
echo "-------------------------------------------------------------------------------"
|
||||
echo "For more detail, use --enable-full-report."
|
||||
echo "-------------------------------------------------------------------------------"
|
||||
echo "For more detail, use --enable-full-report."
|
||||
fi
|
||||
echo "==============================================================================="
|
||||
}
|
||||
|
||||
if test "yes" != "$silent"; then
|
||||
report
|
||||
report
|
||||
fi
|
||||
|
||||
if test "X$CRYPTO" = "X"; then
|
||||
|
||||
+331
-247
File diff suppressed because it is too large
Load Diff
+22
-16
@@ -57,8 +57,9 @@ AC_DEFUN(DLZ_ADD_DRIVER, [
|
||||
|
||||
AC_MSG_CHECKING(for Postgres DLZ driver)
|
||||
AC_ARG_WITH(dlz_postgres,
|
||||
[ --with-dlz-postgres[=PATH] Build with Postgres DLZ driver [yes|no|path].
|
||||
(Required to use Postgres with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-postgres[=PATH]],
|
||||
[Build with Postgres DLZ driver [yes|no|path].
|
||||
(Required to use Postgres with DLZ)]),
|
||||
use_dlz_postgres="$withval", use_dlz_postgres="no")
|
||||
|
||||
if test "$use_dlz_postgres" != "no"
|
||||
@@ -126,16 +127,16 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for MySQL DLZ driver)
|
||||
AC_ARG_WITH(dlz_mysql,
|
||||
[ --with-dlz-mysql[=PATH] Build with MySQL DLZ driver [yes|no|path].
|
||||
(Required to use MySQL with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-mysql[=PATH]],
|
||||
[Build with MySQL DLZ driver [yes|no|path].
|
||||
(Required to use MySQL with DLZ)]),
|
||||
use_dlz_mysql="$withval", use_dlz_mysql="no")
|
||||
|
||||
AC_CHECK_PROGS(MYSQL_CONFIG, mysql_config)
|
||||
|
||||
mysql_include=""
|
||||
mysql_lib=""
|
||||
if test "$use_dlz_mysql" = "yes"
|
||||
then
|
||||
AC_CHECK_PROGS(MYSQL_CONFIG, mysql_config)
|
||||
if test -n "$MYSQL_CONFIG"
|
||||
then
|
||||
mysql_include=`${MYSQL_CONFIG} --include`
|
||||
@@ -232,8 +233,9 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for Berkeley DB DLZ driver...)
|
||||
AC_ARG_WITH(dlz_bdb,
|
||||
[ --with-dlz-bdb[=PATH] Build with Berkeley DB DLZ driver [yes|no|path].
|
||||
(Required to use Berkeley DB with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-bdb[=PATH]],
|
||||
[Build with Berkeley DB DLZ driver [yes|no|path].
|
||||
(Required to use Berkeley DB with DLZ)]),
|
||||
use_dlz_bdb="$withval", use_dlz_bdb="no")
|
||||
|
||||
case "$use_dlz_bdb" in
|
||||
@@ -356,8 +358,9 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for file system DLZ driver)
|
||||
AC_ARG_WITH(dlz_filesystem,
|
||||
[ --with-dlz-filesystem[=ARG] Build with filesystem DLZ driver [yes|no].
|
||||
(Required to use file system driver with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-filesystem[=ARG]],
|
||||
[Build with filesystem DLZ driver [yes|no].
|
||||
(Required to use file system driver with DLZ)]),
|
||||
use_dlz_filesystem="$withval", use_dlz_filesystem="no")
|
||||
|
||||
case "$use_dlz_filesystem" in
|
||||
@@ -378,8 +381,9 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for LDAP DLZ driver)
|
||||
AC_ARG_WITH(dlz_ldap,
|
||||
[ --with-dlz-ldap[=PATH] Build with LDAP DLZ driver [yes|no|path].
|
||||
(Required to use LDAP with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-ldap[=PATH]],
|
||||
[Build with LDAP DLZ driver [yes|no|path].
|
||||
(Required to use LDAP with DLZ)]),
|
||||
use_dlz_ldap="$withval", use_dlz_ldap="no")
|
||||
|
||||
if test "$use_dlz_ldap" = "yes"
|
||||
@@ -424,8 +428,9 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for ODBC DLZ driver)
|
||||
AC_ARG_WITH(dlz_odbc,
|
||||
[ --with-dlz-odbc[=PATH] Build with ODBC DLZ driver [yes|no|path].
|
||||
(Required to use ODBC with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-odbc[=PATH]],
|
||||
[Build with ODBC DLZ driver [yes|no|path].
|
||||
(Required to use ODBC with DLZ)]),
|
||||
use_dlz_odbc="$withval", use_dlz_odbc="no")
|
||||
|
||||
if test "$use_dlz_odbc" = "yes"
|
||||
@@ -481,8 +486,9 @@ esac
|
||||
|
||||
AC_MSG_CHECKING(for stub DLZ driver)
|
||||
AC_ARG_WITH(dlz_stub,
|
||||
[ --with-dlz-stub[=ARG] Build with stub DLZ driver [yes|no].
|
||||
(Required to use stub driver with DLZ)],
|
||||
AS_HELP_STRING([--with-dlz-stub[=ARG]],
|
||||
[Build with stub DLZ driver [yes|no].
|
||||
(Required to use stub driver with DLZ)]),
|
||||
use_dlz_stub="$withval", use_dlz_stub="no")
|
||||
|
||||
case "$use_dlz_stub" in
|
||||
|
||||
@@ -43,7 +43,7 @@ sub printstatus ($) {
|
||||
my $a = shift;
|
||||
if ($a->{removehd} ne "19700101000000") {
|
||||
printf " untrusted and to be removed at %s\n", ext8601 $a->{removehd};
|
||||
} elsif ($a->{addhd} lt $now) {
|
||||
} elsif ($a->{addhd} le $now) {
|
||||
printf " trusted\n";
|
||||
} else {
|
||||
printf " waiting for %s\n", ext8601 $a->{addhd};
|
||||
|
||||
+35
-23
@@ -397,14 +397,31 @@
|
||||
<para>
|
||||
The other authoritative servers, the <emphasis>slave</emphasis>
|
||||
servers (also known as <emphasis>secondary</emphasis> servers)
|
||||
load
|
||||
the zone contents from another server using a replication process
|
||||
known as a <emphasis>zone transfer</emphasis>. Typically the data
|
||||
are
|
||||
transferred directly from the primary master, but it is also
|
||||
possible
|
||||
to transfer it from another slave. In other words, a slave server
|
||||
may itself act as a master to a subordinate slave server.
|
||||
load the zone contents from another server using a replication
|
||||
process known as a <emphasis>zone transfer</emphasis>.
|
||||
Typically the data are transferred directly from the primary
|
||||
master, but it is also possible to transfer it from another
|
||||
slave. In other words, a slave server may itself act as a
|
||||
master to a subordinate slave server.
|
||||
</para>
|
||||
<para>
|
||||
Periodically, the slave server must send a refresh query to
|
||||
determine whether the zone contents have been updated. This
|
||||
is done by sending a query for the zone's SOA record and
|
||||
checking whether the SERIAL field has been updated; if so,
|
||||
a new transfer request is initiated. The timing of these
|
||||
refresh queries is controlled by the SOA REFRESH and RETRY
|
||||
fields, but can be overrridden with the
|
||||
<command>max-refresh-time</command>,
|
||||
<command>min-refresh-time</command>,
|
||||
<command>max-retry-time</command>, and
|
||||
<command>min-retry-time</command> options.
|
||||
</para>
|
||||
<para>
|
||||
If the zone data cannot be updated within the time specified
|
||||
by the SOA EXPIRE option (up to a hard-coded maximum of
|
||||
24 weeks) then the slave zone expires and will no longer
|
||||
respond to queries.
|
||||
</para>
|
||||
</section>
|
||||
|
||||
@@ -2340,8 +2357,6 @@ options {
|
||||
<para>
|
||||
The logged error reads "insecurity proof failed" and
|
||||
"got insecure response; parent indicates it should be secure".
|
||||
(Prior to BIND 9.7, the logged error was "not insecure".
|
||||
This referred to the zone, not the response.)
|
||||
</para>
|
||||
</note>
|
||||
</section>
|
||||
@@ -9385,21 +9400,18 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
<listitem>
|
||||
<para>
|
||||
These options control the server's behavior on refreshing a
|
||||
zone
|
||||
(querying for SOA changes) or retrying failed transfers.
|
||||
Usually the SOA values for the zone are used, but these
|
||||
values
|
||||
are set by the master, giving slave server administrators
|
||||
little
|
||||
control over their contents.
|
||||
zone (querying for SOA changes) or retrying failed
|
||||
transfers. Usually the SOA values for the zone are used,
|
||||
up to a hard-coded maximum expiry of 24 weeks. However,
|
||||
these values are set by the master, giving slave server
|
||||
administrators little control over their contents.
|
||||
</para>
|
||||
<para>
|
||||
These options allow the administrator to set a minimum and
|
||||
maximum refresh and retry time in seconds per-zone,
|
||||
per-view, or globally.
|
||||
These options are valid for slave and stub zones,
|
||||
and clamp the SOA refresh and retry times to the specified
|
||||
values.
|
||||
per-view, or globally. These options are valid for
|
||||
slave and stub zones, and clamp the SOA refresh and
|
||||
retry times to the specified values.
|
||||
</para>
|
||||
<para>
|
||||
The following defaults apply.
|
||||
@@ -11428,8 +11440,8 @@ example.com CNAME rpz-tcp-only.
|
||||
A <command>managed-keys</command> statement contains a list of
|
||||
the keys to be managed, along with information about how the
|
||||
keys are to be initialized for the first time. The only
|
||||
initialization method currently supported (as of
|
||||
<acronym>BIND</acronym> 9.7.0) is <literal>initial-key</literal>.
|
||||
initialization method currently supported is
|
||||
<literal>initial-key</literal>.
|
||||
This means the <command>managed-keys</command> statement must
|
||||
contain a copy of the initializing key. (Future releases may
|
||||
allow keys to be initialized by other methods, eliminating this
|
||||
|
||||
@@ -436,14 +436,31 @@
|
||||
<p>
|
||||
The other authoritative servers, the <span class="emphasis"><em>slave</em></span>
|
||||
servers (also known as <span class="emphasis"><em>secondary</em></span> servers)
|
||||
load
|
||||
the zone contents from another server using a replication process
|
||||
known as a <span class="emphasis"><em>zone transfer</em></span>. Typically the data
|
||||
are
|
||||
transferred directly from the primary master, but it is also
|
||||
possible
|
||||
to transfer it from another slave. In other words, a slave server
|
||||
may itself act as a master to a subordinate slave server.
|
||||
load the zone contents from another server using a replication
|
||||
process known as a <span class="emphasis"><em>zone transfer</em></span>.
|
||||
Typically the data are transferred directly from the primary
|
||||
master, but it is also possible to transfer it from another
|
||||
slave. In other words, a slave server may itself act as a
|
||||
master to a subordinate slave server.
|
||||
</p>
|
||||
<p>
|
||||
Periodically, the slave server must send a refresh query to
|
||||
determine whether the zone contents have been updated. This
|
||||
is done by sending a query for the zone's SOA record and
|
||||
checking whether the SERIAL field has been updated; if so,
|
||||
a new transfer request is initiated. The timing of these
|
||||
refresh queries is controlled by the SOA REFRESH and RETRY
|
||||
fields, but can be overrridden with the
|
||||
<span class="command"><strong>max-refresh-time</strong></span>,
|
||||
<span class="command"><strong>min-refresh-time</strong></span>,
|
||||
<span class="command"><strong>max-retry-time</strong></span>, and
|
||||
<span class="command"><strong>min-retry-time</strong></span> options.
|
||||
</p>
|
||||
<p>
|
||||
If the zone data cannot be updated within the time specified
|
||||
by the SOA EXPIRE option (up to a hard-coded maximum of
|
||||
24 weeks) then the slave zone expires and will no longer
|
||||
respond to queries.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
@@ -599,6 +616,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -146,6 +146,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -759,6 +759,6 @@ controls {
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+34
-37
@@ -60,19 +60,19 @@
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.3">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.8">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.16">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.25">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.32">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.34">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.39">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.41">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.43">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.45">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.47">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.51">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.53">NSEC3 and OPTOUT</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.2">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.7">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.15">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.24">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.31">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.33">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.38">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.40">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.42">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.44">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.46">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.52">NSEC3 and OPTOUT</a></span></dt>
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
|
||||
<dd><dl>
|
||||
@@ -1190,8 +1190,6 @@ options {
|
||||
<p>
|
||||
The logged error reads "insecurity proof failed" and
|
||||
"got insecure response; parent indicates it should be secure".
|
||||
(Prior to BIND 9.7, the logged error was "not insecure".
|
||||
This referred to the zone, not the response.)
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
@@ -1201,12 +1199,9 @@ options {
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="dnssec.dynamic.zones"></a>DNSSEC, Dynamic Zones, and Automatic Signing</h2></div></div></div>
|
||||
|
||||
<p>As of BIND 9.7.0 it is possible to change a dynamic zone
|
||||
from insecure to signed and back again. A secure zone can use
|
||||
either NSEC or NSEC3 chains.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.3"></a>Converting from insecure to secure</h3></div></div></div>
|
||||
<a name="id-1.5.10.2"></a>Converting from insecure to secure</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>Changing a zone from insecure to secure can be done in two
|
||||
@@ -1235,7 +1230,7 @@ options {
|
||||
signing process.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.8"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
<a name="id-1.5.10.7"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To insert the keys via dynamic update:</p>
|
||||
@@ -1274,7 +1269,7 @@ options {
|
||||
is happening, other updates are possible as well.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.16"></a>Fully automatic zone signing</h3></div></div></div>
|
||||
<a name="id-1.5.10.15"></a>Fully automatic zone signing</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To enable automatic signing, add the
|
||||
@@ -1340,7 +1335,7 @@ options {
|
||||
fail.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.25"></a>Private-type records</h3></div></div></div>
|
||||
<a name="id-1.5.10.24"></a>Private-type records</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>The state of the signing process is signaled by
|
||||
@@ -1384,7 +1379,7 @@ options {
|
||||
</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.32"></a>DNSKEY rollovers</h3></div></div></div>
|
||||
<a name="id-1.5.10.31"></a>DNSKEY rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>As with insecure-to-secure conversions, rolling DNSSEC
|
||||
@@ -1392,7 +1387,7 @@ options {
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.34"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
<a name="id-1.5.10.33"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p> To perform key rollovers via dynamic update, you need to add
|
||||
@@ -1417,7 +1412,7 @@ options {
|
||||
by the old key after the update completes.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.39"></a>Automatic key rollovers</h3></div></div></div>
|
||||
<a name="id-1.5.10.38"></a>Automatic key rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>When a new key reaches its activation date (as set by
|
||||
@@ -1435,7 +1430,7 @@ options {
|
||||
old key from the DNSKEY RRset.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.41"></a>NSEC3PARAM rollovers via UPDATE</h3></div></div></div>
|
||||
<a name="id-1.5.10.40"></a>NSEC3PARAM rollovers via UPDATE</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>Add the new NSEC3PARAM record via dynamic update. When the
|
||||
@@ -1445,7 +1440,7 @@ options {
|
||||
completes.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.43"></a>Converting from NSEC to NSEC3</h3></div></div></div>
|
||||
<a name="id-1.5.10.42"></a>Converting from NSEC to NSEC3</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To do this, you just need to add an NSEC3PARAM record. When
|
||||
@@ -1455,7 +1450,7 @@ options {
|
||||
destroyed.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.45"></a>Converting from NSEC3 to NSEC</h3></div></div></div>
|
||||
<a name="id-1.5.10.44"></a>Converting from NSEC3 to NSEC</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To do this, use <span class="command"><strong>nsupdate</strong></span> to
|
||||
@@ -1464,7 +1459,7 @@ options {
|
||||
removed.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.47"></a>Converting from secure to insecure</h3></div></div></div>
|
||||
<a name="id-1.5.10.46"></a>Converting from secure to insecure</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To convert a signed zone to unsigned using dynamic DNS,
|
||||
@@ -1482,7 +1477,7 @@ options {
|
||||
</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.51"></a>Periodic re-signing</h3></div></div></div>
|
||||
<a name="id-1.5.10.50"></a>Periodic re-signing</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>In any secure zone which supports dynamic updates, <span class="command"><strong>named</strong></span>
|
||||
@@ -1492,7 +1487,7 @@ options {
|
||||
all at once.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.53"></a>NSEC3 and OPTOUT</h3></div></div></div>
|
||||
<a name="id-1.5.10.52"></a>NSEC3 and OPTOUT</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
@@ -1511,11 +1506,13 @@ options {
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="rfc5011.support"></a>Dynamic Trust Anchor Management</h2></div></div></div>
|
||||
|
||||
<p>BIND 9.7.0 introduces support for RFC 5011, dynamic trust
|
||||
anchor management. Using this feature allows
|
||||
<span class="command"><strong>named</strong></span> to keep track of changes to critical
|
||||
DNSSEC keys without any need for the operator to make changes to
|
||||
configuration files.</p>
|
||||
<p>
|
||||
BIND is able to maintain DNSSEC trust anchors using RFC 5011 key
|
||||
management. This feature allows <span class="command"><strong>named</strong></span> to keep track
|
||||
of changes to critical DNSSEC keys without any need for the operator to
|
||||
make changes to configuration files.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.11.3"></a>Validating Resolver</h3></div></div></div>
|
||||
@@ -2870,6 +2867,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -81,6 +81,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+21
-14
@@ -2056,6 +2056,16 @@ category notify { null; };
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
<p><span class="command"><strong>zoneload</strong></span></p>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
Loading of zones and creation of automatic empty zones.
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
@@ -6964,21 +6974,18 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
<dd>
|
||||
<p>
|
||||
These options control the server's behavior on refreshing a
|
||||
zone
|
||||
(querying for SOA changes) or retrying failed transfers.
|
||||
Usually the SOA values for the zone are used, but these
|
||||
values
|
||||
are set by the master, giving slave server administrators
|
||||
little
|
||||
control over their contents.
|
||||
zone (querying for SOA changes) or retrying failed
|
||||
transfers. Usually the SOA values for the zone are used,
|
||||
up to a hard-coded maximum expiry of 24 weeks. However,
|
||||
these values are set by the master, giving slave server
|
||||
administrators little control over their contents.
|
||||
</p>
|
||||
<p>
|
||||
These options allow the administrator to set a minimum and
|
||||
maximum refresh and retry time in seconds per-zone,
|
||||
per-view, or globally.
|
||||
These options are valid for slave and stub zones,
|
||||
and clamp the SOA refresh and retry times to the specified
|
||||
values.
|
||||
per-view, or globally. These options are valid for
|
||||
slave and stub zones, and clamp the SOA refresh and
|
||||
retry times to the specified values.
|
||||
</p>
|
||||
<p>
|
||||
The following defaults apply.
|
||||
@@ -8960,8 +8967,8 @@ example.com CNAME rpz-tcp-only.
|
||||
A <span class="command"><strong>managed-keys</strong></span> statement contains a list of
|
||||
the keys to be managed, along with information about how the
|
||||
keys are to be initialized for the first time. The only
|
||||
initialization method currently supported (as of
|
||||
<acronym class="acronym">BIND</acronym> 9.7.0) is <code class="literal">initial-key</code>.
|
||||
initialization method currently supported is
|
||||
<code class="literal">initial-key</code>.
|
||||
This means the <span class="command"><strong>managed-keys</strong></span> statement must
|
||||
contain a copy of the initializing key. (Future releases may
|
||||
allow keys to be initialized by other methods, eliminating this
|
||||
@@ -14640,6 +14647,6 @@ HOST-127.EXAMPLE. MX 0 .
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -399,6 +399,6 @@ allow-query { !{ !10/8; any; }; key example; };
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -136,6 +136,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+13
-14
@@ -36,7 +36,7 @@
|
||||
<div class="toc">
|
||||
<p><b>Table of Contents</b></p>
|
||||
<dl class="toc">
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.12.0b1</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.12.0b2</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
@@ -55,7 +55,7 @@
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="id-1.10.2"></a>Release Notes for BIND Version 9.12.0b1</h2></div></div></div>
|
||||
<a name="id-1.10.2"></a>Release Notes for BIND Version 9.12.0b2</h2></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
@@ -515,15 +515,15 @@
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service has been shut
|
||||
down; all DLV records in the dlv.isc.org zone have been removed.
|
||||
References to the service have been removed from BIND documentation.
|
||||
Lookaside validation is no longer used by default by
|
||||
<span class="command"><strong>delv</strong></span>. The DLV key has been removed from
|
||||
<code class="filename">bind.keys</code>. Setting
|
||||
<span class="command"><strong>dnssec-lookaside</strong></span> to
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service has
|
||||
been shut down; all DLV records in the dlv.isc.org zone
|
||||
have been removed. References to the service have been
|
||||
removed from BIND documentation. Lookaside validation
|
||||
is no longer used by default by <span class="command"><strong>delv</strong></span>.
|
||||
The DLV key has been removed from <code class="filename">bind.keys</code>.
|
||||
Setting <span class="command"><strong>dnssec-lookaside</strong></span> to
|
||||
<span class="command"><strong>auto</strong></span> or to use dlv.isc.org as a trust
|
||||
anchor is now a fatal configuration error. [RT #46155]
|
||||
anchor results in a warning being issued.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
@@ -551,9 +551,8 @@
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The use of HMAC-MD5 for RNDC keys is no longer recommended.
|
||||
The default algorithm generated by <span class="command"><strong>rndc-confgen</strong></span>,
|
||||
is now HMAC-256, and a warning message will be printed if
|
||||
HMAC-MD5 is used. [RT #42272]
|
||||
The default algorithm generated by <span class="command"><strong>rndc-confgen</strong></span>
|
||||
is now HMAC-SHA256. [RT #42272]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
@@ -851,6 +850,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -148,6 +148,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -914,6 +914,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -210,6 +210,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+16
-16
@@ -32,7 +32,7 @@
|
||||
<div>
|
||||
<div><h1 class="title">
|
||||
<a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.12.0b1</p></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.12.0b2</p></div>
|
||||
<div><p class="copyright">Copyright © 2000-2017 Internet Systems Consortium, Inc. ("ISC")</p></div>
|
||||
</div>
|
||||
<hr>
|
||||
@@ -103,19 +103,19 @@
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.3">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.8">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.16">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.25">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.32">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.34">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.39">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.41">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.43">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.45">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.47">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.51">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.53">NSEC3 and OPTOUT</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.2">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.7">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.15">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.24">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.31">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.33">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.38">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.40">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.42">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.44">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.46">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.52">NSEC3 and OPTOUT</a></span></dt>
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
|
||||
<dd><dl>
|
||||
@@ -236,7 +236,7 @@
|
||||
</dl></dd>
|
||||
<dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.12.0b1</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.12.0b2</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
@@ -436,6 +436,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Binary file not shown.
+1
-4
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2010, 2011, 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2010, 2011, 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -9,9 +9,6 @@
|
||||
<!-- Converted by db4-upgrade version 1.0 -->
|
||||
<section xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="dnssec.dynamic.zones"><info><title>DNSSEC, Dynamic Zones, and Automatic Signing</title></info>
|
||||
|
||||
<para>As of BIND 9.7.0 it is possible to change a dynamic zone
|
||||
from insecure to signed and back again. A secure zone can use
|
||||
either NSEC or NSEC3 chains.</para>
|
||||
<section><info><title>Converting from insecure to secure</title></info>
|
||||
|
||||
</section>
|
||||
|
||||
@@ -389,6 +389,16 @@
|
||||
</para>
|
||||
</entry>
|
||||
</row>
|
||||
<row rowsep="0">
|
||||
<entry colname="1">
|
||||
<para><command>zoneload</command></para>
|
||||
</entry>
|
||||
<entry colname="2">
|
||||
<para>
|
||||
Loading of zones and creation of automatic empty zones.
|
||||
</para>
|
||||
</entry>
|
||||
</row>
|
||||
</tbody>
|
||||
</tgroup>
|
||||
</informaltable>
|
||||
|
||||
@@ -90,6 +90,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -235,6 +235,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -625,6 +625,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -646,6 +646,12 @@
|
||||
with TCP. By default, TCP retries are performed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepalive</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Send [or do not send] an EDNS Keepalive option.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
@@ -1095,6 +1101,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -365,6 +365,6 @@ nsupdate -l
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -150,6 +150,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -270,6 +270,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -289,6 +289,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -250,6 +250,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -498,6 +498,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -121,12 +121,12 @@
|
||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<code class="option">-T KEY</code> option as well.
|
||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||
his value will automatically set the <code class="option">-T KEY</code>
|
||||
option as well.
|
||||
</p>
|
||||
<p>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
TSIG keys can also be generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||
@@ -596,6 +596,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -398,6 +398,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -171,6 +171,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -349,6 +349,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -725,6 +725,6 @@ db.example.com.signed
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -202,6 +202,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -143,6 +143,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -126,6 +126,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -375,6 +375,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -610,6 +610,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -200,6 +200,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -463,6 +463,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -117,6 +117,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -119,6 +119,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -121,6 +121,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -1039,6 +1039,6 @@ zone
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -492,6 +492,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -155,6 +155,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b1</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.12.0b2</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user