Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e82a6b5c00 | ||
|
|
625f656aa8 | ||
|
|
278b68ced5 | ||
|
|
c6c1193e39 | ||
|
|
8f532a13cb | ||
|
|
497f3f913e | ||
|
|
01139573bc | ||
|
|
4cbaa08602 | ||
|
|
c9f8165a06 | ||
|
|
1d57d460d4 | ||
|
|
959d294067 | ||
|
|
864bc6b56e | ||
|
|
06049b1c6c | ||
|
|
3b4f23cdbf | ||
|
|
08f18efba2 | ||
|
|
f808b5e0d2 | ||
|
|
a4bf990ed7 | ||
|
|
c341e524dc | ||
|
|
63270d33f1 | ||
|
|
09baa0cbb1 | ||
|
|
87387d8a41 | ||
|
|
5c76f3664c | ||
|
|
5b69d3da83 | ||
|
|
89d1777560 | ||
|
|
d3e8e9bdbb | ||
|
|
3056d6f532 | ||
|
|
96ebb55501 | ||
|
|
8e2a8a3855 | ||
|
|
81570e84a2 | ||
|
|
6a59e53a69 | ||
|
|
2bbca9594f | ||
|
|
eb2ef7b53e | ||
|
|
aebdc6cd7d | ||
|
|
910a01550a | ||
|
|
65314b0fd8 | ||
|
|
80739779fc | ||
|
|
a53e03205a | ||
|
|
ea055a82cd | ||
|
|
89c95e7141 | ||
|
|
79e78994d0 | ||
|
|
21761bfe79 | ||
|
|
969d923536 | ||
|
|
6b8e4d6e69 | ||
|
|
a94d68ce43 | ||
|
|
7810817b71 | ||
|
|
b49042a6a5 | ||
|
|
b1042e011c | ||
|
|
0207f6ff9e | ||
|
|
65f8b51893 | ||
|
|
5bead588b7 | ||
|
|
3f2e5f840a | ||
|
|
c9438ee2e0 | ||
|
|
a59d687db4 | ||
|
|
89636d8f30 | ||
|
|
34ee1cdb56 | ||
|
|
6853af8fc5 | ||
|
|
2e662cf514 | ||
|
|
321b8429f5 | ||
|
|
172aa40e8f | ||
|
|
0fc861dea9 | ||
|
|
b284857f96 | ||
|
|
807ad469fe | ||
|
|
5ff48dca18 | ||
|
|
66258ca349 | ||
|
|
2115e319ba | ||
|
|
429a43b720 | ||
|
|
bf9b90f977 | ||
|
|
d8442c1a15 | ||
|
|
9e5439a6d8 | ||
|
|
0fab171196 | ||
|
|
583e355951 | ||
|
|
fe79e2efbf | ||
|
|
b7b8e298f6 | ||
|
|
d99d5249b7 | ||
|
|
208abf3fc7 | ||
|
|
6e87e723a4 | ||
|
|
4f554c2445 | ||
|
|
30419509dd | ||
|
|
2361003a88 | ||
|
|
94d96121b9 | ||
|
|
31275c3f39 | ||
|
|
d63943f063 | ||
|
|
ebf5459c44 | ||
|
|
9d47a267c4 |
@@ -1,3 +1,99 @@
|
||||
4800. [bug] When processing delzone, write one zone config per
|
||||
line to the NZF. [RT #46323]
|
||||
|
||||
4799. [cleanup] Improve clarity of keytable unit tests. [RT #46407]
|
||||
|
||||
4798. [func] Keys specified in "managed-keys" statements
|
||||
are tagged as "initializing" until they have been
|
||||
updated by a key refresh query. If initialization
|
||||
fails it will be visible from "rndc secroots".
|
||||
[RT #46267]
|
||||
|
||||
4797. [func] Removed "isc-hmac-fixup", as the versions of BIND that
|
||||
had the bug it worked around are long past end of
|
||||
life. [RT #46411]
|
||||
|
||||
4796. [bug] Increase the maximum configurable TCP keepalive
|
||||
timeout to 65535. [RT #44710]
|
||||
|
||||
4795. [func] A new statistics counter has been added to track
|
||||
priming queries. [RT #46313]
|
||||
|
||||
4794. [func] "dnssec-checkds -s" specifies a file from which
|
||||
to read a DS set rather than querying the parent.
|
||||
[RT #44667]
|
||||
|
||||
4793. [bug] nsupdate -[46] could overflow the array of server
|
||||
addresses. [RT #46402]
|
||||
|
||||
4792. [bug] Fix map file header correctness check. [RT #38418]
|
||||
|
||||
4791. [doc] Fixed outdated documentation about export libraries.
|
||||
[RT #46341]
|
||||
|
||||
4790. [bug] nsupdate could trigger a require when sending a
|
||||
update to the second address of the server.
|
||||
[RT #45731]
|
||||
|
||||
4789. [cleanup] Check writability of new-zones-directory. [RT #46308]
|
||||
|
||||
4788. [cleanup] When using "update-policy local", log a warning
|
||||
when an update matching the session key is received
|
||||
from a remote host. [RT #46213]
|
||||
|
||||
4787. [cleanup] Turn nsec3param_salt_totext() into a public function,
|
||||
dns_nsec3param_salttotext(), and add unit tests for it.
|
||||
[RT #46289]
|
||||
|
||||
4786. [func] The "filter-aaaa-on-v4" and "filter-aaaa-on-v6"
|
||||
options are no longer conditionally compiled.
|
||||
[RT #46340]
|
||||
|
||||
4785. [func] The hmac-md5 algorithm is no longer recommended for
|
||||
use with RNDC keys. The default in rndc-confgen
|
||||
is now hmac-sha256. [RT #42272]
|
||||
|
||||
4784. [func] The use of dnssec-keygen to generate HMAC keys is
|
||||
deprecated in favor of tsig-keygen. dnssec-keygen
|
||||
will print a warning when used for this purpose.
|
||||
All HMAC algorithms will be removed from
|
||||
dnssec-keygen in a future release. [RT #42272]
|
||||
|
||||
4783. [test] dnssec: 'check that NOTIFY is sent at the end of
|
||||
NSEC3 chain generation failed' required more time
|
||||
on some machines for the IXFR to complete. [RT #46388]
|
||||
|
||||
4782. [test] dnssec: 'checking positive and negative validation
|
||||
with negative trust anchors' required more time to
|
||||
complete on some machines. [RT #46386]
|
||||
|
||||
4781. [maint] B.ROOT-SERVERS.NET is now 199.9.14.201. [RT #45889]
|
||||
|
||||
4780. [bug] When answering ANY queries, don't include the NS
|
||||
RRset in the authority section if it was already
|
||||
in the answer section. [RT #44543]
|
||||
|
||||
4779. [bug] Expire NTA at the start of the second. Don't update
|
||||
the expiry value if the record has already expired
|
||||
after a successful check. [RT #46368]
|
||||
|
||||
4778. [test] Improve synth-from-dnssec testing. [RT #46352]
|
||||
|
||||
4777. [cleanup] Removed a redundant call to configure_view_acl().
|
||||
[RT #46369]
|
||||
|
||||
4776. [bug] Improve portability of ht_test. [RT #46333]
|
||||
|
||||
4775. [bug] Address Coverity warnings in ht_test.c and mem_test.c
|
||||
[RT #46281]
|
||||
|
||||
4774. [bug] <isc/util.h> was incorrectly included in several
|
||||
header files. [RT #46311]
|
||||
|
||||
4773. [doc] Fixed generating Doxygen documentation for functions
|
||||
annotated using certain macros. Miscellaneous
|
||||
Doxygen-related cleanups. [RT #46276]
|
||||
|
||||
--- 9.12.0b1 released ---
|
||||
|
||||
4772. [test] Expanded unit testing framework for libns, using
|
||||
@@ -244,8 +340,8 @@
|
||||
4713. [func] Added support for the DNS Response Policy Service
|
||||
(DNSRPS) API, which allows named to use an external
|
||||
response policy daemon when built with
|
||||
"configure --enable-dnsrps". Thanks to Vernon
|
||||
Schryver and Farsight Security. [RT #43376]
|
||||
"configure --enable-dnsrps". Thanks to Farsight
|
||||
Security. [RT #43376]
|
||||
|
||||
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
||||
search domain when retrying with TCP. [RT #45547]
|
||||
|
||||
@@ -19,4 +19,10 @@ Setting Description
|
||||
named-checkzone
|
||||
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
||||
rather than ${localstatedir}/run/named/
|
||||
Increase the maximum number of configurable
|
||||
-DNS_RPZ_MAX_ZONES=64 response policy zones from 32 to 64; this is the
|
||||
highest possible setting
|
||||
Disable the use of inline functions to implement
|
||||
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
||||
may be useful when debugging
|
||||
|
||||
|
||||
@@ -20,3 +20,5 @@ Some of these settings are:
|
||||
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
||||
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
||||
|
||||
@@ -56,12 +56,12 @@ General bug reports can be sent to bind9-bugs@isc.org.
|
||||
|
||||
Feature requests can be sent to bind-suggest@isc.org.
|
||||
|
||||
Please note that, while ISC's ticketing system is not currently publicly
|
||||
readable, this may change in the future. Please do not include information
|
||||
in bug reports that you consider to be confidential. For example, when
|
||||
sending the contents of your configuration file, it is advisable to
|
||||
obscure key secrets; this can be done automatically by using
|
||||
named-checkconf -px.
|
||||
Please note that, while tickets submitted to ISC's ticketing system are
|
||||
not initially publicly readable by default, they can be made publicly
|
||||
acessible afterward. Please do not include information in bug reports that
|
||||
you consider to be confidential. In particular, when sending the contents
|
||||
of your configuration file, it is advisable to obscure key secrets: this
|
||||
can be done automatically by using named-checkconf -px.
|
||||
|
||||
Professional support and training for BIND are available from ISC at
|
||||
https://www.isc.org/support.
|
||||
@@ -75,8 +75,9 @@ mailman/listinfo/bind-workers.
|
||||
|
||||
Contributing to BIND
|
||||
|
||||
A public git repository for BIND is maintained at http://www.isc.org/git/,
|
||||
and also on Github at https://github.com/isc-projects.
|
||||
ISC maintains a public git repository for BIND; details can be found at
|
||||
http://www.isc.org/git/, and also on Github at https://github.com/
|
||||
isc-projects.
|
||||
|
||||
Information for BIND contributors can be found in the following files: -
|
||||
General information: doc/dev/contrib.md - BIND 9 code style: doc/dev/
|
||||
@@ -103,10 +104,8 @@ include:
|
||||
* Cached, validated NSEC and other records can now be used to synthesize
|
||||
NXDOMAIN responses.
|
||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||
* Setting max-journal-size default now limits the size of journal files
|
||||
to twice the size of the zone.
|
||||
* The query handling code has been substantially refactored for improved
|
||||
readability, maintainability and testability .
|
||||
* Setting 'max-journal-size default' now limits the size of journal
|
||||
files to twice the size of the zone.
|
||||
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
||||
message.
|
||||
* dnstap output files can now be configured to roll automatically when
|
||||
@@ -115,7 +114,7 @@ include:
|
||||
ISO 8601 (UTC) formats.
|
||||
* Logging channels and dnstap output files can now be configured to use
|
||||
a timestamp as the suffix when rolling to a new file.
|
||||
* named-checkconf -l lists zones found in named.conf.
|
||||
* 'named-checkconf -l' lists zones found in named.conf.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
@@ -189,10 +188,11 @@ smaller systems.
|
||||
For the server to support DNSSEC, you need to build it with crypto
|
||||
support. To use OpenSSL, you should have OpenSSL 1.0.2e or newer
|
||||
installed. If the OpenSSL library is installed in a nonstandard location,
|
||||
specify the prefix using "--with-openssl=/prefix" on the configure command
|
||||
line. To use a PKCS#11 hardware service module for cryptographic
|
||||
specify the prefix using "--with-openssl=<PREFIX>" on the configure
|
||||
command line. To use a PKCS#11 hardware service module for cryptographic
|
||||
operations, specify the path to the PKCS#11 provider library using
|
||||
"--with-pkcs11=/prefix", and configure BIND with "--enable-native-pkcs11".
|
||||
"--with-pkcs11=<PREFIX>", and configure BIND with
|
||||
"--enable-native-pkcs11".
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
||||
@@ -212,13 +212,16 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||
specify the prefix using "--with-geoip=/prefix".
|
||||
|
||||
For DNSTAP packet logging, you must have libfstrm https://github.com/
|
||||
farsightsec/fstrm and libprotobuf-c https://developers.google.com/
|
||||
protocol-buffers, and BIND must be configured with "--enable-dnstap".
|
||||
For DNSTAP packet logging, you must have installed libfstrm https://
|
||||
github.com/farsightsec/fstrm and libprotobuf-c https://
|
||||
developers.google.com/protocol-buffers, and BIND must be configured with
|
||||
"--enable-dnstap".
|
||||
|
||||
Python requires the 'argparse' and 'ply' modules to be available.
|
||||
'argparse' is a standard module as of Python 2.7 and Python 3.2. 'ply' is
|
||||
available from https://pypi.python.org/pypi/ply.
|
||||
Portions of BIND that are written in Python, including dnssec-keymgr,
|
||||
dnssec-coverage, dnssec-checkds, and some of the system tests, require the
|
||||
'argparse' and 'ply' modules to be available. 'argparse' is a standard
|
||||
module as of Python 2.7 and Python 3.2. 'ply' is available from https://
|
||||
pypi.python.org/pypi/ply.
|
||||
|
||||
On some platforms it is necessary to explicitly request large file support
|
||||
to handle files bigger than 2GB. This can be done by using
|
||||
@@ -250,7 +253,7 @@ Automated testing
|
||||
A system test suite can be run with make test. The system tests require
|
||||
you to configure a set of virtual IP addresses on your system (this allows
|
||||
multiple servers to run locally and communicate with one another). These
|
||||
IP addresses can be configured by by running the script bin/tests/system/
|
||||
IP addresses can be configured by running the command bin/tests/system/
|
||||
ifconfig.sh up as root.
|
||||
|
||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||
|
||||
@@ -66,12 +66,12 @@ General bug reports can be sent to
|
||||
Feature requests can be sent to
|
||||
[bind-suggest@isc.org](mailto:bind-suggest@isc.org).
|
||||
|
||||
Please note that, while ISC's ticketing system is not currently publicly
|
||||
readable, this may change in the future. Please do not include information
|
||||
in bug reports that you consider to be confidential. For example, when
|
||||
sending the contents of your configuration file, it is advisable to obscure
|
||||
key secrets; this can be done automatically by using `named-checkconf
|
||||
-px`.
|
||||
Please note that, while tickets submitted to ISC's ticketing system
|
||||
are not initially publicly readable by default, they can be made publicly
|
||||
acessible afterward. Please do not include information in bug reports that
|
||||
you consider to be confidential. In particular, when sending the contents of
|
||||
your configuration file, it is advisable to obscure key secrets: this can
|
||||
be done automatically by using `named-checkconf -px`.
|
||||
|
||||
Professional support and training for BIND are available from
|
||||
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
||||
@@ -85,8 +85,8 @@ may also want to join the __BIND Workers__ mailing list, at
|
||||
|
||||
### <a name="contrib"/> Contributing to BIND
|
||||
|
||||
A public git repository for BIND is maintained at
|
||||
[http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||
ISC maintains a public git repository for BIND; details can be found
|
||||
at [http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||
at [https://github.com/isc-projects](https://github.com/isc-projects).
|
||||
|
||||
Information for BIND contributors can be found in the following files:
|
||||
@@ -116,10 +116,8 @@ include:
|
||||
* Cached, validated NSEC and other records can now be used to synthesize
|
||||
NXDOMAIN responses.
|
||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||
* Setting `max-journal-size default` now limits the size of journal files
|
||||
* Setting `'max-journal-size default'` now limits the size of journal files
|
||||
to twice the size of the zone.
|
||||
* The query handling code has been substantially refactored for improved
|
||||
readability, maintainability and testability .
|
||||
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
||||
DNS message.
|
||||
* `dnstap` output files can now be configured to roll automatically when
|
||||
@@ -128,7 +126,7 @@ include:
|
||||
8601 (UTC) formats.
|
||||
* Logging channels and `dnstap` output files can now be configured to use a
|
||||
timestamp as the suffix when rolling to a new file.
|
||||
* `named-checkconf -l` lists zones found in `named.conf`.
|
||||
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
@@ -195,9 +193,9 @@ performance on smaller systems.
|
||||
For the server to support DNSSEC, you need to build it with crypto support.
|
||||
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||
using "--with-openssl=/prefix" on the configure command line. To use a
|
||||
using "--with-openssl=<PREFIX>" on the configure command line. To use a
|
||||
PKCS#11 hardware service module for cryptographic operations, specify the
|
||||
path to the PKCS#11 provider library using "--with-pkcs11=/prefix", and
|
||||
path to the PKCS#11 provider library using "--with-pkcs11=<PREFIX>", and
|
||||
configure BIND with "--enable-native-pkcs11".
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
@@ -220,13 +218,15 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||
specify the prefix using "--with-geoip=/prefix".
|
||||
|
||||
For DNSTAP packet logging, you must have libfstrm
|
||||
For DNSTAP packet logging, you must have installed libfstrm
|
||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||
and libprotobuf-c
|
||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
||||
and BIND must be configured with "--enable-dnstap".
|
||||
|
||||
Python requires the 'argparse' and 'ply' modules to be available.
|
||||
Portions of BIND that are written in Python, including
|
||||
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||
system tests, require the 'argparse' and 'ply' modules to be available.
|
||||
'argparse' is a standard module as of Python 2.7 and Python 3.2.
|
||||
'ply' is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||
|
||||
@@ -260,7 +260,7 @@ localstatedir defaults to `$prefix/var`.
|
||||
A system test suite can be run with `make test`. The system tests require
|
||||
you to configure a set of virtual IP addresses on your system (this allows
|
||||
multiple servers to run locally and communicate with one another). These
|
||||
IP addresses can be configured by by running the script
|
||||
IP addresses can be configured by running the command
|
||||
`bin/tests/system/ifconfig.sh up` as root.
|
||||
|
||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -111,7 +111,7 @@ as directed\&.
|
||||
.PP
|
||||
\-A \fIalgorithm\fR
|
||||
.RS 4
|
||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-md5 or if MD5 was disabled hmac\-sha256\&.
|
||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-sha256\&.
|
||||
.RE
|
||||
.PP
|
||||
\-b \fIkeysize\fR
|
||||
@@ -217,5 +217,5 @@ BIND 9 Administrator Reference Manual\&.
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -1,13 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* $Id: rndc-confgen.c,v 1.7 2011/03/12 04:59:46 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
/**
|
||||
@@ -67,23 +65,6 @@ usage(int status) ISC_PLATFORM_NORETURN_POST;
|
||||
static void
|
||||
usage(int status) {
|
||||
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
fprintf(stderr, "\
|
||||
Usage:\n\
|
||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||
[-s addr] [-t chrootdir] [-u user]\n\
|
||||
-a: generate just the key clause and write it to keyfile (%s)\n\
|
||||
-A alg: algorithm (default hmac-md5)\n\
|
||||
-b bits: from 1 through 512, default 256; total length of the secret\n\
|
||||
-c keyfile: specify an alternate key file (requires -a)\n\
|
||||
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
||||
-p port: the port named will listen on and rndc will connect to\n\
|
||||
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
||||
-s addr: the address to which rndc should connect\n\
|
||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||
progname, keydef);
|
||||
#else
|
||||
fprintf(stderr, "\
|
||||
Usage:\n\
|
||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||
@@ -99,7 +80,6 @@ Usage:\n\
|
||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||
progname, keydef);
|
||||
#endif
|
||||
|
||||
exit (status);
|
||||
}
|
||||
@@ -135,11 +115,7 @@ main(int argc, char **argv) {
|
||||
progname = program;
|
||||
|
||||
keyname = DEFAULT_KEYNAME;
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
alg = DST_ALG_HMACMD5;
|
||||
#else
|
||||
alg = DST_ALG_HMACSHA256;
|
||||
#endif
|
||||
serveraddr = DEFAULT_SERVER;
|
||||
port = DEFAULT_PORT;
|
||||
|
||||
@@ -225,6 +201,12 @@ main(int argc, char **argv) {
|
||||
if (argc > 0)
|
||||
usage(1);
|
||||
|
||||
if (alg == DST_ALG_HMACMD5) {
|
||||
fprintf(stderr,
|
||||
"warning: use of hmac-md5 for RNDC keys "
|
||||
"is deprecated; hmac-sha256 is now recommended.\n");
|
||||
}
|
||||
|
||||
if (keysize < 0)
|
||||
keysize = alg_bits(alg);
|
||||
algname = alg_totext(alg);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -39,6 +39,7 @@
|
||||
<year>2014</year>
|
||||
<year>2015</year>
|
||||
<year>2016</year>
|
||||
<year>2017</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -128,8 +129,7 @@
|
||||
<para>
|
||||
Specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
||||
if MD5 was disabled hmac-sha256.
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -113,8 +113,7 @@
|
||||
<p>
|
||||
Specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
||||
if MD5 was disabled hmac-sha256.
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
||||
|
||||
@@ -62,12 +62,15 @@ may be preferable to direct use of
|
||||
.RS 4
|
||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||
\fBalgorithm\fR
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TSIG/TKEY keys, the value must be one of DH (Diffie Hellman), HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512; specifying any of these algorithms will automatically set the
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY and SIG(0) keys, the value must be DH (Diffie Hellman); specifying this value will automatically set the
|
||||
\fB\-T KEY\fR
|
||||
option as well\&. (Note:
|
||||
option as well\&.
|
||||
.sp
|
||||
TSIG keys can also by generated by setting the value to one of HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512\&. As with DH, specifying these values will automatically set
|
||||
\fB\-T KEY\fR\&. Note, however, that
|
||||
\fBtsig\-keygen\fR
|
||||
produces TSIG keys in a more useful format than
|
||||
\fBdnssec\-keygen\fR\&.)
|
||||
produces TSIG keys in a more useful format\&. These algorithms have been deprecated in
|
||||
\fBdnssec\-keygen\fR, and will be removed in a future release\&.
|
||||
.sp
|
||||
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
||||
\fB\-3\fR
|
||||
@@ -75,7 +78,7 @@ option, then NSEC3RSASHA1 or NSEC3DSA will be used instead\&.
|
||||
.sp
|
||||
As of BIND 9\&.12\&.0, this option is mandatory except when using the
|
||||
\fB\-S\fR
|
||||
option (which copies the algorithm from the predecessor key)\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||
option, which copies the algorithm from the predecessor key\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||
.RE
|
||||
.PP
|
||||
\-b \fIkeysize\fR
|
||||
|
||||
@@ -582,6 +582,16 @@ main(int argc, char **argv) {
|
||||
INSIST((alg != DNS_KEYALG_RSAMD5) && (alg != DST_ALG_HMACMD5));
|
||||
#endif
|
||||
|
||||
|
||||
if (alg == DST_ALG_HMACMD5 || alg == DST_ALG_HMACSHA1 ||
|
||||
alg == DST_ALG_HMACSHA224 || alg == DST_ALG_HMACSHA256 ||
|
||||
alg == DST_ALG_HMACSHA384 || alg == DST_ALG_HMACSHA512)
|
||||
{
|
||||
fprintf(stderr,
|
||||
"Use of dnssec-keygen for HMAC keys is "
|
||||
"deprecated: use tsig-keygen\n");
|
||||
}
|
||||
|
||||
if (!dst_algorithm_supported(alg))
|
||||
fatal("unsupported algorithm: %d", alg);
|
||||
|
||||
|
||||
@@ -122,12 +122,19 @@
|
||||
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||
or HMAC-SHA512; specifying any of these algorithms will
|
||||
automatically set the <option>-T KEY</option> option as well.
|
||||
(Note: <command>tsig-keygen</command> produces TSIG keys in a
|
||||
more useful format than <command>dnssec-keygen</command>.)
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<option>-T KEY</option> option as well.
|
||||
</para>
|
||||
<para>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <option>-T KEY</option>. Note,
|
||||
however, that <command>tsig-keygen</command> produces TSIG keys
|
||||
in a more useful format. These algorithms have been deprecated
|
||||
in <command>dnssec-keygen</command>, and will be removed in a
|
||||
future release.
|
||||
</para>
|
||||
<para>
|
||||
These values are case insensitive. In some cases, abbreviations
|
||||
@@ -138,8 +145,8 @@
|
||||
</para>
|
||||
<para>
|
||||
As of BIND 9.12.0, this option is mandatory except when using
|
||||
the <option>-S</option> option (which copies the algorithm from
|
||||
the predecessor key). Previously, the default for newly
|
||||
the <option>-S</option> option, which copies the algorithm from
|
||||
the predecessor key. Previously, the default for newly
|
||||
generated keys was RSASHA1.
|
||||
</para>
|
||||
</listitem>
|
||||
|
||||
@@ -103,12 +103,19 @@
|
||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||
or HMAC-SHA512; specifying any of these algorithms will
|
||||
automatically set the <code class="option">-T KEY</code> option as well.
|
||||
(Note: <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys in a
|
||||
more useful format than <span class="command"><strong>dnssec-keygen</strong></span>.)
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<code class="option">-T KEY</code> option as well.
|
||||
</p>
|
||||
<p>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||
however, that <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys
|
||||
in a more useful format. These algorithms have been deprecated
|
||||
in <span class="command"><strong>dnssec-keygen</strong></span>, and will be removed in a
|
||||
future release.
|
||||
</p>
|
||||
<p>
|
||||
These values are case insensitive. In some cases, abbreviations
|
||||
@@ -119,8 +126,8 @@
|
||||
</p>
|
||||
<p>
|
||||
As of BIND 9.12.0, this option is mandatory except when using
|
||||
the <code class="option">-S</code> option (which copies the algorithm from
|
||||
the predecessor key). Previously, the default for newly
|
||||
the <code class="option">-S</code> option, which copies the algorithm from
|
||||
the predecessor key. Previously, the default for newly
|
||||
generated keys was RSASHA1.
|
||||
</p>
|
||||
</dd>
|
||||
|
||||
@@ -349,6 +349,14 @@ If the key\*(Aqs revocation date is set and in the past, and the key is publishe
|
||||
.RS 4
|
||||
If either of the key\*(Aqs unpublication or deletion dates are set and in the past, the key is NOT published or used to sign the zone, regardless of any other metadata\&.
|
||||
.RE
|
||||
.PP
|
||||
.RS 4
|
||||
If key\*(Aqs sync publication date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are created\&.
|
||||
.RE
|
||||
.PP
|
||||
.RS 4
|
||||
If key\*(Aqs sync deletion date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are removed\&.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
\-T \fIttl\fR
|
||||
|
||||
@@ -1958,7 +1958,7 @@ addnsec3(dns_name_t *name, dns_dbnode_t *node,
|
||||
* any NSEC3 records which have the same parameters as the chain we
|
||||
* are building.
|
||||
*
|
||||
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
||||
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
||||
*/
|
||||
static void
|
||||
nsec3clean(dns_name_t *name, dns_dbnode_t *node,
|
||||
|
||||
@@ -646,6 +646,26 @@
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<listitem>
|
||||
<para>
|
||||
If key's sync publication date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
created.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<listitem>
|
||||
<para>
|
||||
If key's sync deletion date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
removed.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -519,6 +519,22 @@
|
||||
zone, regardless of any other metadata.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync publication date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
created.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync deletion date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
removed.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</dd>
|
||||
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@
|
||||
|
||||
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
||||
<xsl:output method="html" indent="yes" version="4.0"/>
|
||||
<xsl:template match="statistics[@version="3.10"]">
|
||||
<xsl:template match="statistics[@version="3.11"]">
|
||||
<html>
|
||||
<head>
|
||||
<xsl:if test="system-property('xsl:vendor')!='Transformiix'">
|
||||
|
||||
@@ -14,7 +14,7 @@ static char xslmsg[] =
|
||||
"\n"
|
||||
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
||||
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
||||
" <xsl:template match=\"statistics[@version="3.10"]\">\n"
|
||||
" <xsl:template match=\"statistics[@version="3.11"]\">\n"
|
||||
" <html>\n"
|
||||
" <head>\n"
|
||||
" <xsl:if test=\"system-property('xsl:vendor')!='Transformiix'\">\n"
|
||||
|
||||
+2
-4
@@ -156,12 +156,10 @@ options {\n\
|
||||
# fetch-glue <obsolete>;\n\
|
||||
fetch-quota-params 100 0.1 0.3 0.7;\n\
|
||||
fetches-per-server 0;\n\
|
||||
fetches-per-zone 0;\n"
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
" filter-aaaa-on-v4 no;\n\
|
||||
fetches-per-zone 0;\n\
|
||||
filter-aaaa-on-v4 no;\n\
|
||||
filter-aaaa-on-v6 no;\n\
|
||||
filter-aaaa { any; };\n"
|
||||
#endif
|
||||
#ifdef HAVE_GEOIP
|
||||
" geoip-use-ecs yes;\n"
|
||||
#endif
|
||||
|
||||
@@ -456,9 +456,8 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
*/
|
||||
if (conn->nonce == 0) {
|
||||
while (conn->nonce == 0) {
|
||||
isc_uint16_t r1 = isc_rng_random(server->sctx->rngctx);
|
||||
isc_uint16_t r2 = isc_rng_random(server->sctx->rngctx);
|
||||
conn->nonce = (r1 << 16) | r2;
|
||||
isc_rng_randombytes(server->sctx->rngctx, &conn->nonce,
|
||||
sizeof(conn->nonce));
|
||||
}
|
||||
eresult = ISC_R_SUCCESS;
|
||||
} else
|
||||
|
||||
@@ -17,6 +17,7 @@
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/syslog.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <isccfg/cfg.h>
|
||||
#include <isccfg/log.h>
|
||||
|
||||
+91
-49
@@ -160,6 +160,8 @@
|
||||
#define DIR_PERM_OK W_OK|X_OK
|
||||
#endif
|
||||
|
||||
#define MAX_TCP_TIMEOUT 65535
|
||||
|
||||
/*%
|
||||
* Check an operation for failure. Assumes that the function
|
||||
* using it has a 'result' variable and a 'cleanup' label.
|
||||
@@ -803,6 +805,11 @@ dstkey_fromconfig(const cfg_obj_t *vconfig, const cfg_obj_t *key,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Load keys from configuration into key table. If 'keyname' is specified,
|
||||
* only load keys matching that name. If 'managed' is true, load the key as
|
||||
* an initializing key.
|
||||
*/
|
||||
static isc_result_t
|
||||
load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
dns_view_t *view, isc_boolean_t managed,
|
||||
@@ -818,12 +825,14 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
|
||||
for (elt = cfg_list_first(keys);
|
||||
elt != NULL;
|
||||
elt = cfg_list_next(elt)) {
|
||||
elt = cfg_list_next(elt))
|
||||
{
|
||||
keylist = cfg_listelt_value(elt);
|
||||
|
||||
for (elt2 = cfg_list_first(keylist);
|
||||
elt2 != NULL;
|
||||
elt2 = cfg_list_next(elt2)) {
|
||||
elt2 = cfg_list_next(elt2))
|
||||
{
|
||||
key = cfg_listelt_value(elt2);
|
||||
result = dstkey_fromconfig(vconfig, key, managed,
|
||||
&dstkey, mctx);
|
||||
@@ -831,8 +840,9 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
result = ISC_R_SUCCESS;
|
||||
continue;
|
||||
}
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/*
|
||||
* If keyname was specified, we only add that key.
|
||||
@@ -844,17 +854,27 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
continue;
|
||||
}
|
||||
|
||||
CHECK(dns_keytable_add(secroots, managed, &dstkey));
|
||||
/*
|
||||
* This key is taken from the configuration, so
|
||||
* if it's a managed key then it's an
|
||||
* initializing key; that's why 'managed'
|
||||
* is duplicated below.
|
||||
*/
|
||||
CHECK(dns_keytable_add2(secroots, managed,
|
||||
managed, &dstkey));
|
||||
}
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (dstkey != NULL)
|
||||
if (dstkey != NULL) {
|
||||
dst_key_free(&dstkey);
|
||||
if (secroots != NULL)
|
||||
}
|
||||
if (secroots != NULL) {
|
||||
dns_keytable_detach(&secroots);
|
||||
if (result == DST_R_NOCRYPTO)
|
||||
}
|
||||
if (result == DST_R_NOCRYPTO) {
|
||||
result = ISC_R_SUCCESS;
|
||||
}
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -1024,7 +1044,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
}
|
||||
|
||||
/*
|
||||
* Add key zone for managed-keys.
|
||||
* Add key zone for managed keys.
|
||||
*/
|
||||
obj = NULL;
|
||||
(void)named_config_get(maps, "managed-keys-directory", &obj);
|
||||
@@ -1048,6 +1068,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
CHECK(add_keydata_zone(view, directory, named_g_mctx));
|
||||
|
||||
cleanup:
|
||||
@@ -4681,20 +4702,19 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
* "allow-recursion" inherits from "allow-query-cache" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
*/
|
||||
if (view->cacheacl == NULL && view->recursionacl != NULL)
|
||||
if (view->cacheacl == NULL && view->recursionacl != NULL) {
|
||||
dns_acl_attach(view->recursionacl, &view->cacheacl);
|
||||
/*
|
||||
* XXXEACH: This call to configure_view_acl() is redundant. We
|
||||
* are leaving it as it is because we are making a minimal change
|
||||
* for a patch release. In the future this should be changed to
|
||||
* dns_acl_attach(view->queryacl, &view->cacheacl).
|
||||
*/
|
||||
if (view->cacheacl == NULL && view->recursion)
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-query", NULL,
|
||||
actx, named_g_mctx, &view->cacheacl));
|
||||
}
|
||||
|
||||
if (view->cacheacl == NULL && view->recursion) {
|
||||
dns_acl_attach(view->queryacl, &view->cacheacl);
|
||||
}
|
||||
|
||||
if (view->recursion &&
|
||||
view->recursionacl == NULL && view->cacheacl != NULL)
|
||||
{
|
||||
dns_acl_attach(view->cacheacl, &view->recursionacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set default "allow-recursion", "allow-recursion-on" and
|
||||
@@ -4875,7 +4895,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
dns_quotatype_zone, r);
|
||||
}
|
||||
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "filter-aaaa-on-v4", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -4910,7 +4929,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
|
||||
CHECK(configure_view_acl(vconfig, config, "filter-aaaa", NULL,
|
||||
actx, named_g_mctx, &view->aaaa_acl));
|
||||
#endif
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "prefetch", &obj);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
@@ -6443,16 +6462,19 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
}
|
||||
nextnode = NULL;
|
||||
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
||||
if (keynode != firstnode)
|
||||
if (keynode != firstnode) {
|
||||
dns_keytable_detachkeynode(keytable, &keynode);
|
||||
}
|
||||
keynode = nextnode;
|
||||
} while (keynode != NULL);
|
||||
|
||||
if (n == 0)
|
||||
if (n == 0) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (n > 1)
|
||||
if (n > 1) {
|
||||
qsort(ids, n, sizeof(ids[0]), cid);
|
||||
}
|
||||
|
||||
/*
|
||||
* Encoded as "_ta-xxxx\(-xxxx\)*" where xxxx is the hex version of
|
||||
@@ -6460,22 +6482,25 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
*/
|
||||
label[0] = 0;
|
||||
r.base = label;
|
||||
r.length = sizeof(label);;
|
||||
r.length = sizeof(label);
|
||||
m = snprintf(r.base, r.length, "_ta");
|
||||
if (m < 0 || (unsigned)m > r.length)
|
||||
if (m < 0 || (unsigned)m > r.length) {
|
||||
return;
|
||||
}
|
||||
isc_textregion_consume(&r, m);
|
||||
for (i = 0; i < n; i++) {
|
||||
m = snprintf(r.base, r.length, "-%04x", ids[i]);
|
||||
if (m < 0 || (unsigned)m > r.length)
|
||||
if (m < 0 || (unsigned)m > r.length) {
|
||||
return;
|
||||
}
|
||||
isc_textregion_consume(&r, m);
|
||||
}
|
||||
dns_fixedname_init(&fixed);
|
||||
tatname = dns_fixedname_name(&fixed);
|
||||
result = dns_name_fromstring2(tatname, label, name, 0, NULL);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
return;
|
||||
}
|
||||
|
||||
dns_name_format(tatname, namebuf, sizeof(namebuf));
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -6484,8 +6509,9 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
view->name, namebuf);
|
||||
|
||||
tat = isc_mem_get(dotat_arg->view->mctx, sizeof(*tat));
|
||||
if (tat == NULL)
|
||||
if (tat == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
tat->mctx = NULL;
|
||||
tat->task = NULL;
|
||||
@@ -7053,6 +7079,13 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
dir, isc_result_totext(result));
|
||||
return (result);
|
||||
}
|
||||
if (access(dir, DIR_PERM_OK) != 0) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"new-zones-directory '%s' "
|
||||
"is not writable", dir);
|
||||
return (ISC_R_NOPERM);
|
||||
}
|
||||
|
||||
dns_view_setnewzonedir(view, dir);
|
||||
}
|
||||
@@ -7881,11 +7914,11 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
result = named_config_get(maps, "tcp-keepalive-timeout", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
keepalive = cfg_obj_asuint32(obj);
|
||||
if (keepalive > 1200) {
|
||||
if (keepalive > MAX_TCP_TIMEOUT) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-keepalive-timeout value is out of range: "
|
||||
"lowering to 1200");
|
||||
keepalive = 1200;
|
||||
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||
keepalive = MAX_TCP_TIMEOUT;
|
||||
} else if (keepalive < 1) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-keepalive-timeout value is out of range: "
|
||||
@@ -7897,11 +7930,11 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
result = named_config_get(maps, "tcp-advertised-timeout", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
advertised = cfg_obj_asuint32(obj);
|
||||
if (advertised > 1200) {
|
||||
if (advertised > MAX_TCP_TIMEOUT) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-advertized-timeout value is out of range: "
|
||||
"lowering to 1200");
|
||||
advertised = 1200;
|
||||
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||
advertised = MAX_TCP_TIMEOUT;
|
||||
}
|
||||
|
||||
ns_server_settimeouts(named_g_server->sctx,
|
||||
@@ -11739,6 +11772,10 @@ nzf_append(dns_view_t *view, const cfg_obj_t *zconfig) {
|
||||
|
||||
static isc_result_t
|
||||
nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
||||
const cfg_obj_t *zl = NULL;
|
||||
cfg_list_t *list;
|
||||
const cfg_listelt_t *elt;
|
||||
|
||||
FILE *fp = NULL;
|
||||
char tmp[1024];
|
||||
isc_result_t result;
|
||||
@@ -11750,9 +11787,24 @@ nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
cfg_map_get(config, "zone", &zl);
|
||||
if (!cfg_obj_islist(zl))
|
||||
CHECK(ISC_R_FAILURE);
|
||||
|
||||
DE_CONST(&zl->value.list, list);
|
||||
|
||||
CHECK(add_comment(fp, view->name)); /* force a comment */
|
||||
|
||||
cfg_printx(config, CFG_PRINTER_ONELINE, dumpzone, fp);
|
||||
for (elt = ISC_LIST_HEAD(*list);
|
||||
elt != NULL;
|
||||
elt = ISC_LIST_NEXT(elt, link))
|
||||
{
|
||||
const cfg_obj_t *zconfig = cfg_listelt_value(elt);
|
||||
|
||||
CHECK(isc_stdio_write("zone ", 5, 1, fp, NULL));
|
||||
cfg_printx(zconfig, CFG_PRINTER_ONELINE, dumpzone, fp);
|
||||
CHECK(isc_stdio_write(";\n", 2, 1, fp, NULL));
|
||||
}
|
||||
|
||||
CHECK(isc_stdio_flush(fp));
|
||||
result = isc_stdio_close(fp);
|
||||
@@ -13442,11 +13494,6 @@ newzone_cfgctx_destroy(void **cfgp) {
|
||||
|
||||
static isc_result_t
|
||||
generate_salt(unsigned char *salt, size_t saltlen) {
|
||||
size_t i, n;
|
||||
union {
|
||||
unsigned char rnd[256];
|
||||
isc_uint16_t rnd16[128];
|
||||
} rnd;
|
||||
unsigned char text[512 + 1];
|
||||
isc_region_t r;
|
||||
isc_buffer_t buf;
|
||||
@@ -13455,14 +13502,9 @@ generate_salt(unsigned char *salt, size_t saltlen) {
|
||||
if (saltlen > 256U)
|
||||
return (ISC_R_RANGE);
|
||||
|
||||
n = (saltlen + sizeof(isc_uint16_t) - 1) / sizeof(isc_uint16_t);
|
||||
for (i = 0; i < n; i++) {
|
||||
rnd.rnd16[i] = isc_rng_random(named_g_server->sctx->rngctx);
|
||||
}
|
||||
isc_rng_randombytes(named_g_server->sctx->rngctx, salt, saltlen);
|
||||
|
||||
memmove(salt, rnd.rnd, saltlen);
|
||||
|
||||
r.base = rnd.rnd;
|
||||
r.base = salt;
|
||||
r.length = (unsigned int) saltlen;
|
||||
|
||||
isc_buffer_init(&buf, text, sizeof(text));
|
||||
@@ -14695,7 +14737,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
if (ptr == NULL)
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
CHECK(isc_parse_uint32(&keepalive, ptr, 10));
|
||||
if (keepalive > 1200)
|
||||
if (keepalive > MAX_TCP_TIMEOUT)
|
||||
CHECK(ISC_R_RANGE);
|
||||
if (keepalive < 1)
|
||||
CHECK(ISC_R_RANGE);
|
||||
@@ -14704,7 +14746,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
if (ptr == NULL)
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
CHECK(isc_parse_uint32(&advertised, ptr, 10));
|
||||
if (advertised > 1200)
|
||||
if (advertised > MAX_TCP_TIMEOUT)
|
||||
CHECK(ISC_R_RANGE);
|
||||
|
||||
result = isc_task_beginexclusive(named_g_server->task);
|
||||
|
||||
@@ -20,6 +20,7 @@
|
||||
#include <isc/stats.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/cache.h>
|
||||
#include <dns/db.h>
|
||||
@@ -394,6 +395,7 @@ init_desc(void) {
|
||||
SET_RESSTATDESC(serverquota, "spilled due to server quota",
|
||||
"ServerQuota");
|
||||
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
||||
SET_RESSTATDESC(priming, "priming queries", "Priming");
|
||||
|
||||
INSIST(i == dns_resstatscounter_max);
|
||||
|
||||
@@ -1614,7 +1616,7 @@ generatexml(named_server_t *server, isc_uint32_t flags,
|
||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
||||
ISC_XMLCHAR "3.10"));
|
||||
ISC_XMLCHAR "3.11"));
|
||||
|
||||
/* Set common fields for statistics dump */
|
||||
dumparg.type = isc_statsformat_xml;
|
||||
@@ -2410,7 +2412,7 @@ generatejson(named_server_t *server, size_t *msglen,
|
||||
/*
|
||||
* These statistics are included no matter which URL we use.
|
||||
*/
|
||||
obj = json_object_new_string("1.4");
|
||||
obj = json_object_new_string("1.5");
|
||||
CHECKMEM(obj);
|
||||
json_object_object_add(bindstats, "json-stats-version", obj);
|
||||
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <isccfg/cfg.h>
|
||||
|
||||
|
||||
+16
-7
@@ -150,6 +150,7 @@ static dns_dispatch_t *dispatchv4 = NULL;
|
||||
static dns_dispatch_t *dispatchv6 = NULL;
|
||||
static dns_message_t *updatemsg = NULL;
|
||||
static dns_fixedname_t fuserzone;
|
||||
static dns_fixedname_t fzname;
|
||||
static dns_name_t *userzone = NULL;
|
||||
static dns_name_t *zname = NULL;
|
||||
static dns_name_t tmpzonename;
|
||||
@@ -943,16 +944,21 @@ setup_system(void) {
|
||||
case AF_INET:
|
||||
if (have_ipv4) {
|
||||
sa->type.sin.sin_port = htons(dnsport);
|
||||
} else {
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
case AF_INET6:
|
||||
if (have_ipv6) {
|
||||
sa->type.sin6.sin6_port = htons(dnsport);
|
||||
} else {
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
fatal("bad family");
|
||||
}
|
||||
INSIST(i < ns_alloc);
|
||||
servers[i++] = *sa;
|
||||
}
|
||||
}
|
||||
@@ -2390,7 +2396,6 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
||||
dns_request_destroy(&request);
|
||||
dns_message_renderreset(updatemsg);
|
||||
dns_message_settsigkey(updatemsg, NULL);
|
||||
/* XXX MPA fix zonename is freed already */
|
||||
send_update(zname, &master_servers[master_inuse]);
|
||||
isc_event_free(&event);
|
||||
return;
|
||||
@@ -2693,13 +2698,17 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
dns_name_init(&master, NULL);
|
||||
dns_name_clone(&soa.origin, &master);
|
||||
|
||||
/*
|
||||
* XXXMPA
|
||||
*/
|
||||
if (userzone != NULL)
|
||||
if (userzone != NULL) {
|
||||
zname = userzone;
|
||||
else
|
||||
zname = name;
|
||||
} else {
|
||||
/*
|
||||
* Save the zone name in case we need to try a second
|
||||
* address.
|
||||
*/
|
||||
dns_fixedname_init(&fzname);
|
||||
zname = dns_fixedname_name(&fzname);
|
||||
dns_name_copy(name, zname, NULL);
|
||||
}
|
||||
|
||||
if (debugging) {
|
||||
char namestr[DNS_NAME_FORMATSIZE];
|
||||
|
||||
@@ -39,9 +39,7 @@
|
||||
dnssec-checkds \- DNSSEC delegation consistency checking tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-checkds\fR\ 'u
|
||||
\fBdnssec\-checkds\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
.HP \w'\fBdnssec\-dsfromkey\fR\ 'u
|
||||
\fBdnssec\-dsfromkey\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
\fBdnssec\-checkds\fR [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-s\ \fR\fB\fIfile\fR\fR] {zone}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-checkds\fR
|
||||
@@ -60,6 +58,12 @@ is specified, then the zone is read from that file to find the DNSKEY records\&.
|
||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&.
|
||||
.RE
|
||||
.PP
|
||||
\-s \fIfile\fR
|
||||
.RS 4
|
||||
Specifies a prepared dsset file, such as would be generated by
|
||||
\fBdnssec\-signzone\fR, to use as a source for the DS RRset instead of querying the parent\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIdig path\fR
|
||||
.RS 4
|
||||
Specifies a path to a
|
||||
|
||||
@@ -42,20 +42,13 @@
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>dnssec-checkds</command>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="req" rep="norepeat">zone</arg>
|
||||
</cmdsynopsis>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>dnssec-dsfromkey</command>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="req" rep="norepeat">zone</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsection><info><title>DESCRIPTION</title></info>
|
||||
@@ -92,6 +85,17 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-s <replaceable class="parameter">file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a prepared dsset file, such as would be generated
|
||||
by <command>dnssec-signzone</command>, to use as a source for
|
||||
the DS RRset instead of querying the parent.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-d <replaceable class="parameter">dig path</replaceable></term>
|
||||
<listitem>
|
||||
|
||||
@@ -33,20 +33,13 @@
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-checkds</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-s <em class="replaceable"><code>file</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-dsfromkey</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
@@ -79,6 +72,14 @@
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies a prepared dsset file, such as would be generated
|
||||
by <span class="command"><strong>dnssec-signzone</strong></span>, to use as a source for
|
||||
the DS RRset instead of querying the parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
############################################################################
|
||||
# Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -34,7 +34,11 @@ class SECRR:
|
||||
if not rrtext:
|
||||
raise Exception
|
||||
|
||||
fields = rrtext.decode('ascii').split()
|
||||
# 'str' does not have decode method in python3
|
||||
if type(rrtext) is not str:
|
||||
fields = rrtext.decode('ascii').split()
|
||||
else:
|
||||
fields = rrtext.split()
|
||||
if len(fields) < 7:
|
||||
raise Exception
|
||||
|
||||
@@ -89,35 +93,39 @@ class SECRR:
|
||||
# Generate a set of expected DS/DLV records from the DNSKEY RRset,
|
||||
# and report on congruency.
|
||||
############################################################################
|
||||
def check(zone, args, masterfile=None, lookaside=None):
|
||||
def check(zone, args):
|
||||
rrlist = []
|
||||
cmd = [args.dig, "+noall", "+answer", "-t", "dlv" if lookaside else "ds",
|
||||
"-q", zone + "." + lookaside if lookaside else zone]
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
if args.dssetfile:
|
||||
fp = open(args.dssetfile).read()
|
||||
else:
|
||||
cmd = [args.dig, "+noall", "+answer", "-t",
|
||||
"dlv" if args.lookaside else "ds", "-q",
|
||||
zone + "." + args.lookaside if args.lookaside else zone]
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
|
||||
for line in fp.splitlines():
|
||||
rrlist.append(SECRR(line, lookaside))
|
||||
rrlist.append(SECRR(line, args.lookaside))
|
||||
rrlist = sorted(rrlist, key=lambda rr: (rr.keyid, rr.keyalg, rr.hashalg))
|
||||
|
||||
klist = []
|
||||
|
||||
if masterfile:
|
||||
cmd = [args.dsfromkey, "-f", masterfile]
|
||||
if lookaside:
|
||||
cmd += ["-l", lookaside]
|
||||
if args.masterfile:
|
||||
cmd = [args.dsfromkey, "-f", args.masterfile]
|
||||
if args.lookaside:
|
||||
cmd += ["-l", args.lookaside]
|
||||
cmd.append(zone)
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
else:
|
||||
intods, _ = Popen([args.dig, "+noall", "+answer", "-t", "dnskey",
|
||||
"-q", zone], stdout=PIPE).communicate()
|
||||
cmd = [args.dsfromkey, "-f", "-"]
|
||||
if lookaside:
|
||||
cmd += ["-l", lookaside]
|
||||
if args.lookaside:
|
||||
cmd += ["-l", args.lookaside]
|
||||
cmd.append(zone)
|
||||
fp, _ = Popen(cmd, stdin=PIPE, stdout=PIPE).communicate(intods)
|
||||
|
||||
for line in fp.splitlines():
|
||||
klist.append(SECRR(line, lookaside))
|
||||
klist.append(SECRR(line, args.lookaside))
|
||||
|
||||
if len(klist) < 1:
|
||||
print("No DNSKEY records found in zone apex")
|
||||
@@ -136,7 +144,8 @@ def check(zone, args, masterfile=None, lookaside=None):
|
||||
rr.keyid, SECRR.hashalgs[rr.hashalg]))
|
||||
|
||||
if not found:
|
||||
print("No %s records were found for any DNSKEY" % ("DLV" if lookaside else "DS"))
|
||||
print("No %s records were found for any DNSKEY" %
|
||||
("DLV" if args.lookaside else "DS"))
|
||||
|
||||
return found
|
||||
|
||||
@@ -151,10 +160,6 @@ def parse_args():
|
||||
sbindir = 'bin' if os.name == 'nt' else 'sbin'
|
||||
|
||||
parser.add_argument('zone', type=str, help='zone to check')
|
||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||
help='zone master file')
|
||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||
help='DLV lookaside zone')
|
||||
parser.add_argument('-d', '--dig', dest='dig',
|
||||
default=os.path.join(prefix(bindir), 'dig'),
|
||||
type=str, help='path to \'dig\'')
|
||||
@@ -162,6 +167,12 @@ def parse_args():
|
||||
default=os.path.join(prefix(sbindir),
|
||||
'dnssec-dsfromkey'),
|
||||
type=str, help='path to \'dig\'')
|
||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||
help='zone master file')
|
||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||
help='DLV lookaside zone')
|
||||
parser.add_argument('-s', '--dsset', dest='dssetfile', type=str,
|
||||
help='prepared DSset file')
|
||||
parser.add_argument('-v', '--version', action='version',
|
||||
version=version)
|
||||
args = parser.parse_args()
|
||||
@@ -178,5 +189,5 @@ def parse_args():
|
||||
############################################################################
|
||||
def main():
|
||||
args = parse_args()
|
||||
found = check(args.zone, args, args.masterfile, args.lookaside)
|
||||
found = check(args.zone, args)
|
||||
exit(0 if found else 1)
|
||||
|
||||
@@ -1,19 +1,17 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id: clean.sh,v 1.6 2007/09/26 03:22:44 marka Exp $
|
||||
|
||||
#
|
||||
# Clean up after tests.
|
||||
#
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f */named.memstats
|
||||
rm -f */named.conf
|
||||
rm -f ns1/named.conf
|
||||
rm -f */named.run
|
||||
rm -f ns*/named.lock
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.3;
|
||||
notify-source 10.53.0.3;
|
||||
transfer-source 10.53.0.3;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.3; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "root.hint";
|
||||
};
|
||||
@@ -0,0 +1,8 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
. NS ns1.
|
||||
ns1. A 10.53.0.1
|
||||
@@ -212,7 +212,7 @@ echo "I:testing with 'minimal-responses yes;'"
|
||||
minimal=yes
|
||||
dotests
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-responses no"
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -230,7 +230,7 @@ if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-any yes"
|
||||
cp ns1/named3.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -266,7 +266,7 @@ echo "I:testing with 'minimal-responses no-auth;'"
|
||||
minimal=no-auth
|
||||
dotests
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-responses no-auth-recursive"
|
||||
cp ns1/named4.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -297,5 +297,30 @@ if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:reconfiguring server: minimal-responses no"
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing NS handling in ANY responses (authoritative) ($n)"
|
||||
ret=0
|
||||
$DIG -t ANY rt.example @10.53.0.1 -p 5300 > dig.out.$n || ret=1
|
||||
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||
if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing NS handling in ANY responses (recursive) ($n)"
|
||||
ret=0
|
||||
$DIG -t ANY rt.example @10.53.0.3 -p 5300 > dig.out.$n || ret=1
|
||||
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||
if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -43,7 +43,7 @@ check_stderr() {
|
||||
[ -s err.$n ] || return 0
|
||||
fi
|
||||
echo "D:stderr did not match '$err'"
|
||||
sed 's/^/D:/' err
|
||||
sed 's/^/D:/' err.$n
|
||||
fail
|
||||
}
|
||||
|
||||
|
||||
@@ -1,12 +1,10 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
rm -f checkds.*
|
||||
rm -f ns*/named.lock
|
||||
|
||||
@@ -1,13 +1,11 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
my $arg;
|
||||
my $ext;
|
||||
my $file;
|
||||
|
||||
@@ -1,14 +1,11 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012, 2013, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012, 2013, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
|
||||
while [ "$#" != 0 ]; do
|
||||
case $1 in
|
||||
+*) shift ;;
|
||||
|
||||
@@ -0,0 +1,121 @@
|
||||
; File written on Thu Oct 5 23:44:34 2017
|
||||
; dnssec_signzone version 9.12.0a1
|
||||
prep.example. 300 IN SOA ns1.prep.example. hostmaster.prep.example. (
|
||||
1 ; serial
|
||||
2000 ; refresh (33 minutes 20 seconds)
|
||||
2000 ; retry (33 minutes 20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
300 RRSIG SOA 8 2 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
1fX0z7Swu4gMPews/ZE8bzNg+JXNedFBDGIH
|
||||
PTSfVQtVLIvRWpME+PylX7MdVMZE/PST+x4/
|
||||
mWyveyjetEOo7/7aQL236FfI0y6TxQFy7HwC
|
||||
FMieqoQCUluuKOvToxg4vUp4GOdlUGbqC63h
|
||||
DbX5Z37VptJXLkt4niF4Kl2iD+U9/bk7HAEU
|
||||
4zDiKroYnusGKfVB9xAWddzoHdLxhVuPi7ut
|
||||
328suPdgX0bfs7uB+y4cikhGzAmPpNMlGHju
|
||||
qYG74NcFGQNutLB7ayx/m87t7mTty7jbNKm3
|
||||
QWJSPf5IR8/kmzAi8HMnapY5vUmm+hX8JOfU
|
||||
UtH7i0iEsUqRbEwu5A== )
|
||||
300 NS ns1.prep.example.
|
||||
300 RRSIG NS 8 2 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
u5sU2cfqNqIyCLw18ZNnFw28/GyRt0EOiPYS
|
||||
dygmpfMDrvDaxjiiai8zWYjnl/E3qzVH9Zku
|
||||
07lEDORZdVb0uCDe1NynjAyw4AHps85cAwVc
|
||||
8HTSbzdVZsQTELpunYFJffh24PDr9unw7KOY
|
||||
jzTP6qNedJ1uM54TOr177zfmBh7N2fkAoGyV
|
||||
NjvTKrlgDYGNIn8/YMgHb4sNgyfe54MYY00f
|
||||
kehVxfKnRCgDsbJ0Pk6jhBMCQWvOh8jG8WyV
|
||||
ElAa/eMqlxUC1idF8ydWefjsI/7lPcjSalw9
|
||||
qZw4CDCLHHZy0TOSmCYRRZuIeVXzBfDPJyi4
|
||||
2A3iLntKFJ4AOLFMJg== )
|
||||
3600 NSEC ns1.prep.example. NS SOA RRSIG NSEC DNSKEY
|
||||
3600 RRSIG NSEC 8 2 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
Aed99/jdG82YAkKVWjoKOsAGtB3JnyKkCaAq
|
||||
zgMrYkXU41y3KDCAmGzooGPQY7NN+WxX7FJ2
|
||||
1nXkgljma/azgpsbi9ssneFtv7PPFClVmN+u
|
||||
j+mM4MK/ZR7eJOsMqETg4PAO5VAh6c/GVmyA
|
||||
RD/m6EhJVZEjPfLWbDoC4hVAgem7DP/NMjyI
|
||||
GfztpDjMmyLQyv6tL+UEXSJHGp3ZEa5Z5i7X
|
||||
Nl/bRTUlZs7L4rTgoqHv6LEmsXKAf9rZYq4b
|
||||
eP6GF9I1Ry41MfHLc7lPUmtR38ErEsM5uGzw
|
||||
trCQYEFhuRWUBxZ8OSL2EZK9rUBXZX+cwK/8
|
||||
ZP7mIfDfljkXPQcmow== )
|
||||
3600 DNSKEY 256 3 8 (
|
||||
AwEAAfMzj6aZIgZDVcpH1pKOtq998E85+nEY
|
||||
YJa0lLS8+QTCC1Efke8GLwsXT0IPTuwnOuXM
|
||||
RjySirab0NuEr69T8KP/43YxcRdmCg89mjjN
|
||||
szoVPPstC9xBKVOc0pRMDF7sfsTrSye3RY7+
|
||||
Z6uZEH5FOAkz2hNbJJHOn4HpNUhLPJGRauhf
|
||||
0evamwUmQ/mlhkVW5q4WmqPCDMNY3K6XtkEm
|
||||
cvm8n9ZCXC9Z5AX6KpynujzLdKyxpdGqUk6r
|
||||
lavp9ILPpRKoTZDX+2q1pDgP5cDndwtgNSvU
|
||||
DBQZoD0psS2cyB3PHo+dPwwpEyM//ZSKsH9m
|
||||
e85Ti0413TOWFyFd/jUOUA8=
|
||||
) ; ZSK; alg = RSASHA256 ; key id = 19260
|
||||
3600 DNSKEY 257 3 8 (
|
||||
AwEAAbV8X06Qvk350aZ6eZ1d7WbT1H/Y0Sv7
|
||||
qAdbk5fbYIKpMvZ8D9xqoTHgD0z0uCgWWIcm
|
||||
/xyKBfmax76oLwMBpR/kdtuJz0irgFITnJCH
|
||||
pEfR9AJ/Mfm7NyMglq+/39I03E1/LXvpXQLG
|
||||
tg+Mo/2CUE5sbG31jmPNK/2J8RMESkIi87fW
|
||||
azZU/oyUEtECE5PGbdyw+4PacAsXNjnwl30T
|
||||
aatL277wX4pt+IUPdE6EIph3t+dxXJ7OpHgW
|
||||
8g+YSHLlCImLVapdg3oD/cs6ncaBq9z7la5Y
|
||||
dHNw2QAIAvQ11EsonrkonPqO6zNVZAVdT2VB
|
||||
X5YzGAoCFUvbCvlnl2a7SxM=
|
||||
) ; KSK; alg = RSASHA256 ; key id = 65482
|
||||
3600 RRSIG DNSKEY 8 2 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
pPw81pJ3PeF+tqEswTul9N8Qsl9JKgK4v8SV
|
||||
lPfP0pnlMBMbtMFFkx5ZmhQg3Z3U8SdE64Bt
|
||||
C5St3qItyyKdTQ0Rbm9mfV6twxDB8lVry8F7
|
||||
Pv7gJmmcWzBcbLGcrXIrVNSZhigkemQXTElj
|
||||
P8y1j7kaNFWBWbDMn7KesiZ9BiC6sqvuKa3R
|
||||
wSofjwXTESspWZP0NtXr5ymaBIMR9UtNj5Wh
|
||||
jm1+tg6BxNBKxhCHlSC0ltPS/qq9J1ZUmtJz
|
||||
sj/EAFfPVJVuEveebMvi1oDWPTgajO9+EHl4
|
||||
ELrgnQHCgaybMzbpd/A5+Tr1hQkv48I8Mb0/
|
||||
8LJ2/6xrvJm64yRteg== )
|
||||
3600 RRSIG DNSKEY 8 2 3600 (
|
||||
20171105054434 20171006054434 65482 prep.example.
|
||||
WeIWiC9SnBe2+UocVjpap62O8Rz+iljwJiu9
|
||||
VlGUwct3Vydq4/4FVAKdPklXV5cYbBLhO2MB
|
||||
3R4toX8RNU/0Ny8DnugQzLKvVfg0xoyU/UAJ
|
||||
k4aWa/vPivSLGouLQPiNp71bdXN4LB/2xmzu
|
||||
cPYXzS9ePpwCOp/9JLoNjBSMQkfjfWAcaNtj
|
||||
1DKDmHHL1sPMizninxSJLQOAKb+JwUAjAkOM
|
||||
O1JqwkB12/IZuzxN5hly+uNsbFFxPzQkcnJ4
|
||||
5bhzxuh5D/JRXW0nF5aO4aR+9X+lSUpDJQZ1
|
||||
5fOt1cybZCn/ag68RA92zrnisdbrggJGS003
|
||||
wn/VKbLVfFj3eQrfNA== )
|
||||
ns1.prep.example. 300 IN A 1.1.1.1
|
||||
300 RRSIG A 8 3 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
QUyDyJVk3JGEq+VTZtY3firzsRqOA0LUm3Tf
|
||||
/fnemQBeOlMda2ErA7DqYVriIGfM8jph416E
|
||||
YX8SKAZXGEAlsEbC9cWBVyc5TYH6tZ43sV51
|
||||
55kGTiUY92NnrH10Q+m2SLAEEaKCA/cgBwOR
|
||||
tN2Wb1meHgiLbGYN2LbANfDQzoEk4AYAgT6r
|
||||
wDKVVg/V9Ed7JnCnBQc9MN9+LQ3h4NBGUiEY
|
||||
mr7HX2w+yzqcGFNLI1aFPe2IwFt120QPLyyl
|
||||
cZgc6FUBX4YCnWoCb0aFyyOT76AQkKF5YBRn
|
||||
gAv6S8q1pZ/0B5w4gjaLEGlts3LG0bxZ1GJd
|
||||
gCQMEhgYgyXUchTtZA== )
|
||||
3600 NSEC prep.example. A RRSIG NSEC
|
||||
3600 RRSIG NSEC 8 3 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
rDWN40u1a3DSzWOrS+4YR2XOxaem0BAQ/glN
|
||||
QkXNDew1WsZo3fe0IHIhDKlJ/5MJAfAHq8Xs
|
||||
A5UGUw2efoNAN/0LuWsI/9IPm4dwQOXiTCly
|
||||
uxugXf5islPYyvn1Z14ay/7/2P3W6HZknXzo
|
||||
lZFpwqfFZQCxz7c/1aH+2ntAMeqx8LHuewSr
|
||||
Rz/sLsSiCcZQ6NMWnZdoC5SGy4CTcIIPPS8z
|
||||
9dQ6QYTC5iq4MKRfyJUyvODyU9be4e6jbo5b
|
||||
mjRcov4ttbImhD5jrLAZIfjO6DSazGNVFf/x
|
||||
6rjxjrc8SISPkt2xYwcOlYch9OZuoH86wcZu
|
||||
3Don6yAnLDYDrZylAA== )
|
||||
@@ -0,0 +1,8 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
prep.example. IN DS 65482 8 1 F3673708FBADDEC3EB55933E2E393ACE85EAC2BB
|
||||
prep.example. IN DS 65482 8 2 51A7C97AAC42803DA515D1CAFEE28031A5018F6345F12F4B6C1B6D20 02B59820
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -171,6 +171,15 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:checking with prepared dsset file ($n)"
|
||||
ret=0
|
||||
$CHECKDS -f prep.example.db -s prep.example.ds.db prep.example > checkds.out.$n || ret=1
|
||||
grep 'SHA-1.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||
grep 'SHA-256.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
if [ $status = 0 ]; then $SHELL clean.sh; fi
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -24,8 +24,8 @@ options {
|
||||
dnssec-must-be-secure mustbesecure.example yes;
|
||||
minimal-responses no;
|
||||
|
||||
nta-lifetime 10s;
|
||||
nta-recheck 7s;
|
||||
nta-lifetime 12s;
|
||||
nta-recheck 9s;
|
||||
|
||||
# Note: We only reference the bind.keys file here to confirm that it
|
||||
# is *not* being used. It contains the real root key, and we're
|
||||
|
||||
@@ -1722,7 +1722,7 @@ echo "I: waiting for NTA rechecks/expirations"
|
||||
# fakenode.secure.example should both be lifted, but badds.example
|
||||
# should still be going.
|
||||
#
|
||||
$PERL -e 'my $delay = '$start' + 8 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$PERL -e 'my $delay = '$start' + 10 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$DIG $DIGOPTS b.secure.example. a @10.53.0.4 > dig.out.ns4.test$n.8 || ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns4.test$n.8 > /dev/null && ret=1
|
||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.8 > /dev/null || ret=1
|
||||
@@ -1742,7 +1742,7 @@ ret=0
|
||||
# it should still be NTA'd, but badds.example used the default
|
||||
# lifetime of 10s, so it should revert to SERVFAIL now.
|
||||
#
|
||||
$PERL -e 'my $delay = '$start' + 11 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$PERL -e 'my $delay = '$start' + 13 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
# check nta table
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 nta -d > rndc.out.ns4.test$n._11
|
||||
lines=`grep " expiry " rndc.out.ns4.test$n._11 | wc -l`
|
||||
@@ -2501,9 +2501,15 @@ do
|
||||
done;
|
||||
grep "ANSWER: 3," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:nsec3 chain generation not complete"; fi
|
||||
sleep 3
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.2 > dig.out.ns2.test$n || ret=1
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||
s2=`awk '$4 == "SOA" { print $7}' dig.out.ns2.test$n`
|
||||
for i in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||
s3=`awk '$4 == "SOA" { print $7}' dig.out.ns3.test$n`
|
||||
test "$s2" = "$s3" && break
|
||||
sleep 1
|
||||
done
|
||||
$PERL ../digcomp.pl dig.out.ns2.test$n dig.out.ns3.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
|
||||
@@ -13,6 +13,7 @@
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
#include <dns/diff.h>
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
#include <isc/eventclass.h>
|
||||
#include <isc/netaddr.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/byaddr.h>
|
||||
#include <dns/db.h>
|
||||
|
||||
@@ -36,7 +36,6 @@ usage() {
|
||||
fprintf(stderr, "args:\n");
|
||||
fprintf(stderr, " --edns-version\n");
|
||||
fprintf(stderr, " --enable-dnsrps\n");
|
||||
fprintf(stderr, " --enable-filter-aaaa\n");
|
||||
fprintf(stderr, " --gethostname\n");
|
||||
fprintf(stderr, " --gssapi\n");
|
||||
fprintf(stderr, " --have-dlopen\n");
|
||||
@@ -63,14 +62,6 @@ main(int argc, char **argv) {
|
||||
#endif
|
||||
}
|
||||
|
||||
if (strcmp(argv[1], "--enable-filter-aaaa") == 0) {
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
return (0);
|
||||
#else
|
||||
return (1);
|
||||
#endif
|
||||
}
|
||||
|
||||
if (strcmp(argv[1], "--edns-version") == 0) {
|
||||
#ifdef DNS_EDNS_VERSION
|
||||
printf("%d\n", DNS_EDNS_VERSION);
|
||||
|
||||
@@ -1,110 +1,125 @@
|
||||
; File written on Thu May 1 12:16:00 2014
|
||||
; dnssec_signzone version 9.8.5-P1
|
||||
signed. 120 IN SOA ns.utld. hostmaster.ns.utld. (
|
||||
; File written on Mon Oct 16 09:16:28 2017
|
||||
; dnssec_signzone version 9.11.2
|
||||
signed. 120 IN SOA ns.signed. hostmaster.ns.signed. (
|
||||
1 ; serial
|
||||
3600 ; refresh (1 hour)
|
||||
1200 ; retry (20 minutes)
|
||||
604800 ; expire (1 week)
|
||||
60 ; minimum (1 minute)
|
||||
)
|
||||
120 RRSIG SOA 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BEFlElqfz17JeL/ISbgEz7yenWy2QjhgdMUx
|
||||
VDLBx3+Eiz1nyB1CpWw= )
|
||||
120 NS ns.utld.
|
||||
120 RRSIG NS 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BC4nYbfEyROe0CZPj/cHRl7BCIc0MbzpDBwz
|
||||
an8bPTHrbaHpC8rdX54= )
|
||||
120 RRSIG SOA 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BJDbUrXS4UzBrTeNUMA0sSGYd+h9M5d8qzsE
|
||||
q7RJyDtUNJIwP5vAnSQ= )
|
||||
120 NS ns.signed.
|
||||
120 RRSIG NS 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGoYuOkkcTAYnym27q2BgqkjUgP/0/Tip1yc
|
||||
txRS1D0CipTUZhCNrXc= )
|
||||
120 MX 10 mx.signed.
|
||||
120 RRSIG MX 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BEp7iUXEnBCXVtKHcIRfkiK34J83ZbC3g7qQ
|
||||
XY+wdpJ7TxavEBtZO94= )
|
||||
120 RRSIG MX 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BOUPCSEEJ8dZ0oWeiYEvGIonjagvM1OS+mEY
|
||||
i5VUmysn7kArWqeFERs= )
|
||||
60 NSEC a-only.signed. NS SOA MX RRSIG NSEC DNSKEY
|
||||
60 RRSIG NSEC 3 1 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BAjeMFAXkfL9AypyihxU7lvhGCENKAwpoGt6
|
||||
WYd6G0kb6zdpZ/AR1GQ= )
|
||||
60 RRSIG NSEC 3 1 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BBzvCsFw4EgfrIsFOu5IjP2gncm8dntwHaMD
|
||||
IeJ6g6s7IOwFT5nyrOU= )
|
||||
120 DNSKEY 256 3 3 (
|
||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
||||
GimMrtxmA5Wf1xoJ
|
||||
) ; key id = 12955
|
||||
BPXo3mJOeCCuorn7Hc7bxR3QDHrJvq9gUpPS
|
||||
s8QYF3eiSpB97c8Br7fFzFYHQCJWWnCtpt1E
|
||||
h7SveJSl1ASNl9W2KE6hDNXfDX+ixDOtFZ/7
|
||||
PCh/obX36VK86EH+ZBNLxxEy9tHHCGO08zy8
|
||||
3lWI3E5bk9a1sks2dy6hbQfMmyXWI5QwYS9D
|
||||
j5Vs5yeUQ5e6SPmIqgqpn6VnDtAIfR2My7/r
|
||||
/Jgf73gpZugZmn6wDbzNCyGIvtOJCHAY2OEg
|
||||
ZfACKVdJrXZ42NKcJCgSTd1xY81UyMI9QAMq
|
||||
64Lx/tENCo1GKBCk/1HMdiO6WKeXCJd1SYzN
|
||||
VM+n4fRzEkmVT9wfyiSmoq6SxjeqrRebDz8G
|
||||
42d4lsm2/0bmOlle+fva7LwtGOaS+tBqtD8K
|
||||
kexFaixL5iY+LB0Q
|
||||
) ; ZSK; alg = DSA ; key id = 17876
|
||||
120 DNSKEY 257 3 3 (
|
||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
||||
GimMrtxmA5Wf1xoJ
|
||||
) ; key id = 12956
|
||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BG/sW/I/ZVcUCjGfAicxv4kYLLYoMZlivDqU
|
||||
V3GfAXR5Bp69ywKp1OA= )
|
||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
||||
20140501011600 12956 signed.
|
||||
BAoQwXiKVoWwY+IDfzRndz9ndLPTSShDHpxS
|
||||
Z9+uTx+KCPzUsZYQy4k= )
|
||||
BOOhXnn+YV6RQ+jRPdayrnC2cd9x5P77c1/6
|
||||
Ev41qaWl1N7QRDXYh7VDS1UowoPbvQOvgQU0
|
||||
X7+zKWrB8UQcdsUe96IH/wPab1qkJlKanZni
|
||||
uFdB/2sTvQ6yabIC41dItnGeuN9VY1qwCa7T
|
||||
4QFRVYyDPKgxo7MRLq9YoUN8RTcB6lY1BH9Z
|
||||
QgcHZljAFVgU1Zc/6DZlQeBZyJafwIR+I7Eq
|
||||
Oe+rR44ZeD5JRgI1OwGyw/b1wKUxFhM+4XJi
|
||||
i8mQ1mrvzZ27iQbYP4WEzaskU6P5X+nPrTFi
|
||||
tLEaPugt8Oe7+lHLjpHvHzSOJZ5Radfiqgzg
|
||||
GGOzj1qmLfKLdRmp4VuBQ+1kguiz9D3ev89d
|
||||
pzP7dYHuSdCjc9X0fLmPjU1xD6RyLCDEmUm7
|
||||
eeRP55SiTiQCzJFr
|
||||
) ; KSK; alg = DSA ; key id = 3746
|
||||
120 RRSIG DNSKEY 3 1 120 (
|
||||
20820519023008 20140501011600 3746 signed.
|
||||
BFuLN7ACQrD6/3WaieXRD1JpSXW9s+/xCZ1x
|
||||
0ihUT1iKNvJS8F4Pafc= )
|
||||
120 RRSIG DNSKEY 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BN+8hbh1FGTNqHds0In57dPr5fVRU/P28dZa
|
||||
zIP19bAwTH/ZvgrqUF0= )
|
||||
a-only.signed. 120 IN NS 1.0.0.1.signed.
|
||||
60 NSEC aaaa-only.signed. NS RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BBRjTWMwkjpanDw386nblW6fwyliYRUeNNo+
|
||||
OHwhqHXXd4bathApttg= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BHpGpjMihpoIykHTpK1XmkVn0jqSST3/K6Fx
|
||||
vTaIb24rpkTriaXxChM= )
|
||||
aaaa-only.signed. 120 IN AAAA 2001:db8::2
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BDukZxGM62Wmk9JE7F5etkcX4LZyFLK0YS0H
|
||||
CF0lovOlBeK5zLgi/MA= )
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BOvYax/3CDnEKTtbc6zoP4hYwhMe5SoXZh0w
|
||||
muzBWw9bEH+Bdt1ZEQ4= )
|
||||
60 NSEC dual.signed. AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BH1TJpK7j1Gu01hb2PimefFISv59NDLfZ9Gr
|
||||
ojpnjDQNV6bA7HcHeEM= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BIqxE79TUnT2DUuocTitGhTNGnLs0+3sLJdz
|
||||
8haJbyH8pig1h7mqimU= )
|
||||
dual.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BBIDPDxbSm3X/Xf5xh/MYIkAvZ9CWpEzSwbM
|
||||
Pks77CGb4rW8IF8WXxs= )
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BIGL70eEIGVDW0gcYpEWgCFv4ne14hutQCMh
|
||||
gQ6kcEbl2qszosJA60E= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BHKD6egOF6e2DfY7+iPNDPcMS6TdU8/OCm8u
|
||||
OYjmr11t5cI8S0R1Iqk= )
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BCmwk+ng/x1O7MhheK8MgAXYFVDDbyiZ76RV
|
||||
iwQrPRm0ThNRtsQU+UY= )
|
||||
60 NSEC mx.signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BHeXsjvM4Bmr/Ih4eDgR9VTC7R/UFlz5ns+g
|
||||
7LPl+H9Oe6zGnM5rGOs= )
|
||||
mx.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BAq3t2X4XDI/dIofEkALZsNn1ezNWDYFH0M2
|
||||
2GI5F0JHr/iZPlAzRbk= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BFts4Mon2FQaLQb6kPOKTEFkHaPIE1xUgrI6
|
||||
qV8tEaAyFXfhH4su6Y0= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BLlLAIHF4SX/eWMCkUvj0XTFmaOp3xnifqkL
|
||||
nSWOAqtzJ5fwAdbNBdM= )
|
||||
ns.signed. 120 IN A 10.53.0.1
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BJ+Wll7VfNEjM4EfLY2rlx74oIwKRg9pjcJO
|
||||
Zxt6GHQIJ2D6EfyMZ00= )
|
||||
120 AAAA fd92:7065:b8e:ffff::1
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGT/agHn4qcHzLV2hYcGeLJ6Tz1to9sTB8LI
|
||||
lMwkV/KUu6UO7yvrnYk= )
|
||||
60 NSEC signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BCQWnlB8hrID+v5xG/o8t8E+YDb3Fz7Qodmw
|
||||
kBQ+ZwyIeLOoH2+as5A= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BNe3XmEGd/xxoh8FN3T3V9G1enCzNQJ7l3G+
|
||||
D3QPrp7mYtPAGMxCLlc= )
|
||||
mx.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BMlIQp1acUSUvgzV1CWlM0+cS1bGkFsbS6HQ
|
||||
d0S6TbNV+uNw0S1q0Dk= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGtSuYQF7sRVT5OdVHPJjm0PERzSp4v+d/DP
|
||||
Vp2UD0vSVSr3Vj2Wi4M= )
|
||||
60 NSEC ns.signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BMzQWws37wYfHvLnqgvjd+j5dkzBb2RYhrQk
|
||||
ykM0GnTAR6ZpmgQO6jc= )
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
$FEATURETEST --enable-filter-aaaa || {
|
||||
echo "I:This test requires --enable-filter-aaaa at compile time." >&2
|
||||
exit 255
|
||||
}
|
||||
exit 0
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2005, 2007, 2011-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005, 2007, 2011-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -238,6 +238,16 @@ done
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# stomp on the file header
|
||||
echo "I:checking corrupt map files fail to load (bad file header)"
|
||||
ret=0
|
||||
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
||||
cp map.5 badmap
|
||||
stomp badmap 0 32 99
|
||||
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||
[ $? = 1 ] || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
# stomp on the file data so it hashes differently.
|
||||
# these are small and subtle changes, so that the resulting file
|
||||
# would appear to be a legitimate map file and would not trigger an
|
||||
@@ -245,7 +255,6 @@ status=`expr $status + $ret`
|
||||
# load because of a SHA1 hash mismatch.
|
||||
echo "I:checking corrupt map files fail to load (bad node header)"
|
||||
ret=0
|
||||
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
||||
cp map.5 badmap
|
||||
stomp badmap 2754 2 99
|
||||
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||
|
||||
@@ -16,16 +16,8 @@ is used so it will send TAT queries once per second.
|
||||
|
||||
ns3 is a validator with a broken key in managed-keys.
|
||||
|
||||
Tests TODO:
|
||||
ns4 is a validator with a deliberately broken managed-keys.bind and
|
||||
managed-keys.jnl, causing RFC 5011 initialization to fail.
|
||||
|
||||
- initial working KSK
|
||||
|
||||
TODO: test using delv with new trusted key too
|
||||
|
||||
- introduce a REVOKE bit
|
||||
|
||||
- later remove a signature
|
||||
|
||||
- corrupt a signature
|
||||
|
||||
TODO: also same things with dlv auto updates of trust anchor
|
||||
ns5 is a validator which is prevented from getting a response from the
|
||||
root server, causing key refresh queries to fail.
|
||||
|
||||
@@ -10,8 +10,10 @@ rm -f */K* */*.signed */trusted.conf */*.jnl */*.bk
|
||||
rm -f dsset-. ns1/dsset-.
|
||||
rm -f ns*/named.lock
|
||||
rm -f */managed-keys.bind* */named.secroots
|
||||
rm -f */managed.conf ns1/managed.key ns1/managed.key.id
|
||||
rm -f */managed*.conf ns1/managed.key ns1/managed.key.id
|
||||
rm -f */named.memstats */named.run
|
||||
rm -f dig.out* delv.out* rndc.out* signer.out*
|
||||
rm -f ns1/named.secroots ns1/root.db.signed* ns1/root.db.tmp
|
||||
rm -f ns1/named.conf
|
||||
rm -rf ns4/nope
|
||||
rm -f ns5/named.args
|
||||
|
||||
@@ -10,6 +10,11 @@
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
acl allowed {
|
||||
! 10.53.0.5;
|
||||
any;
|
||||
};
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
@@ -22,6 +27,7 @@ options {
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
allow-query { allowed; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -10,6 +10,11 @@
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
acl allowed {
|
||||
! 10.53.0.5;
|
||||
any;
|
||||
};
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
@@ -22,6 +27,7 @@ options {
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
allow-query { allowed; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS1
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
transfer-source 10.53.0.1;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.1 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type master;
|
||||
file "root.db.signed";
|
||||
};
|
||||
@@ -28,6 +28,8 @@ managed-keys {
|
||||
EOF
|
||||
' > managed.conf
|
||||
cp managed.conf ../ns2/managed.conf
|
||||
cp managed.conf ../ns4/managed.conf
|
||||
cp managed.conf ../ns5/managed.conf
|
||||
|
||||
# Configure a trusted key statement (used by delve)
|
||||
cat $keyname.key | grep -v '^; ' | $PERL -n -e '
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40 -T tat=1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS4
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.4;
|
||||
notify-source 10.53.0.4;
|
||||
transfer-source 10.53.0.4;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.4; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation auto;
|
||||
bindkeys-file "managed.conf";
|
||||
managed-keys-directory "nope";
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.4 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
@@ -0,0 +1,38 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS5
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.5;
|
||||
notify-source 10.53.0.5;
|
||||
transfer-source 10.53.0.5;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.5; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation auto;
|
||||
bindkeys-file "managed.conf";
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.5 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
@@ -0,0 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g
|
||||
@@ -0,0 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
||||
@@ -14,5 +14,14 @@ $SHELL clean.sh
|
||||
test -r $RANDFILE || $GENRANDOM 800 $RANDFILE
|
||||
|
||||
cp ns1/named1.conf ns1/named.conf
|
||||
cp ns5/named1.args ns5/named.args
|
||||
|
||||
cd ns1 && $SHELL sign.sh
|
||||
( cd ns1 && $SHELL sign.sh )
|
||||
|
||||
cp ns2/managed.conf ns2/managed1.conf
|
||||
|
||||
cd ns4
|
||||
mkdir nope
|
||||
touch nope/managed-keys.bind
|
||||
touch nope/managed.keys.bind.jnl
|
||||
chmod 444 nope/*
|
||||
|
||||
@@ -215,9 +215,36 @@ t2=`grep "trust pending" ns2/managed-keys.bind`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I: reinitialize trust anchors"
|
||||
echo "I: reinitialize trust anchors, add second key to bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
cat ns1/$standby1.key | grep -v '^; ' | $PERL -n -e '
|
||||
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
|
||||
local $key = join("", @rest);
|
||||
local $originalkey = `grep initial-key ns2/managed1.conf`;
|
||||
print <<EOF
|
||||
managed-keys {
|
||||
$originalkey
|
||||
"$dn" initial-key $flags $proto $alg "$key";
|
||||
};
|
||||
EOF
|
||||
' > ns2/managed.conf
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that no key from bind.keys is marked as an initializing key ($n)"
|
||||
ret=0
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
grep '; initializing' ns2/named.secroots > /dev/null 2>&1 && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I: reinitialize trust anchors, revert to one key in bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
mv ns2/managed1.conf ns2/managed.conf
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
@@ -446,7 +473,6 @@ rm -f ${revoked}.key ${revoked}.private
|
||||
$SETTIME -D none -R none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby2 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 flush | sed 's/^/I: ns1 /'
|
||||
sleep 1
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
@@ -454,6 +480,7 @@ sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 flush | sed 's/^/I: ns1 /'
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -537,14 +564,14 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries are logged ($n)"
|
||||
ret=0
|
||||
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns3/named.run > /dev/null || ret=1
|
||||
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns2/named.run > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries are received ($n)"
|
||||
ret=0
|
||||
grep "query '_ta-[0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
||||
grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -562,5 +589,82 @@ grep "name: \." rndc.out.$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries contain the correct key ($n)"
|
||||
ret=0
|
||||
# convert the hexadecimal key from the TAT query into decimal and
|
||||
# compare against the known key.
|
||||
tathex=`grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run | awk '{print $6; exit 0}' | sed -e 's/(_ta-\([0-9a-f][0-9a-f]*\)):/\1/'`
|
||||
tatkey=`$PERL -e 'printf("%d\n", hex(@ARGV[0]));' $tathex`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | grep '; managed' | sed 's#.*SHA256/\([0-9][0-9]*\) ; managed.*#\1#'`
|
||||
[ "$tatkey" -eq "$realkey" ] || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check initialization fails if managed-keys can't be created ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
grep '; initializing managed' ns4/named.secroots > /dev/null 2>&1 || ret=1
|
||||
grep '; managed' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
grep '; trusted' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check failure to contact root servers does not prevent key refreshes after restart ($n)"
|
||||
ret=0
|
||||
# By the time we get here, ns5 should have attempted refreshing its managed
|
||||
# keys. These attempts should fail as ns1 is configured to REFUSE all queries
|
||||
# from ns5. Note that named1.args does not contain "-T mkeytimers"; this is to
|
||||
# ensure key refresh retry will be scheduled to one actual hour after the first
|
||||
# key refresh failure instead of just a few seconds, in order to prevent races
|
||||
# between the next scheduled key refresh time and startup time of restarted ns5.
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
sleep 2
|
||||
# ns5/named.run will contain logs from both the old instance and the new
|
||||
# instance. In order for the test to pass, both must attempt a fetch.
|
||||
count=`grep -c "Creating key fetch" ns5/named.run`
|
||||
[ $count -lt 2 ] && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check key refreshes are resumed after root servers become available ($n)"
|
||||
ret=0
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
# Prevent previous check from affecting this one
|
||||
rm -f ns2/managed-keys.bind*
|
||||
# named2.args adds "-T mkeytimers=2/20/40" to named1.args as we need to wait for
|
||||
# an "hour" until keys are refreshed again after initial failure
|
||||
cp ns5/named2.args ns5/named.args
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
sleep 2
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.5 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
sleep 1
|
||||
grep '; initializing managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should still REFUSE queries from ns5, so resolving should be impossible
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.a.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns5.a.test$n > /dev/null || ret=1
|
||||
# Allow queries from ns5 to ns1
|
||||
cp ns1/named3.conf ns1/named.conf
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.5 -p 9953 secroots | sed 's/^/I: ns4 /'
|
||||
sleep 1
|
||||
grep '; managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should not longer REFUSE queries from ns5, so managed keys should be
|
||||
# correctly refreshed and resolving should succeed
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.b.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -486,6 +486,7 @@ fi
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that 'update-policy local' fails from non-localhost address ($n)"
|
||||
grep 'match on session key not from localhost' ns5/named.run > /dev/null && ret=1
|
||||
$NSUPDATE -p 5300 -k ns5/session.key > nsupdate.out.$n 2>&1 << END && ret=1
|
||||
server 10.53.0.5 5300
|
||||
local 10.53.0.1
|
||||
@@ -493,6 +494,7 @@ update add nonlocal.local.nil. 600 A 4.3.2.1
|
||||
send
|
||||
END
|
||||
grep REFUSED nsupdate.out.$n > /dev/null 2>&1 || ret=1
|
||||
grep 'match on session key not from localhost' ns5/named.run > /dev/null || ret=1
|
||||
$DIG @10.53.0.5 -p 5300 \
|
||||
+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd \
|
||||
nonlocal.local.nil. > dig.out.ns5.$n || ret=1
|
||||
|
||||
+17
-16
@@ -100,26 +100,27 @@ $PERL stop.pl $test
|
||||
status=`expr $status + $?`
|
||||
|
||||
if [ $status != 0 ]; then
|
||||
echofail "R:FAIL"
|
||||
# Don't clean up - we need the evidence.
|
||||
find . -name core -exec chmod 0644 '{}' \;
|
||||
echofail "R:FAIL"
|
||||
# Don't clean up - we need the evidence.
|
||||
find . -name core -exec chmod 0644 '{}' \;
|
||||
else
|
||||
echopass "R:PASS"
|
||||
echopass "R:PASS"
|
||||
|
||||
if $clean
|
||||
if $clean
|
||||
then
|
||||
rm -f $SYSTEMTESTTOP/random.data
|
||||
if test -f $test/clean.sh
|
||||
then
|
||||
rm -f $SYSTEMTESTTOP/random.data
|
||||
if test -f $test/clean.sh
|
||||
then
|
||||
( cd $test && $SHELL clean.sh "$@" )
|
||||
fi
|
||||
if test -d ../../../.git
|
||||
then
|
||||
git status -su $test |
|
||||
sed -n 's/^?? \(.*\)/I:file \1 not removed/p'
|
||||
fi
|
||||
|
||||
( cd $test && $SHELL clean.sh "$@" )
|
||||
fi
|
||||
if test -d ../../../.git
|
||||
then
|
||||
git status -su --ignored $test |
|
||||
sed -n -e 's|^?? \(.*\)|I:file \1 not removed|p' \
|
||||
-e 's|^!! \(.*/named.run\)$|I:file \1 not removed|p' \
|
||||
-e 's|^!! \(.*/named.memstats\)$|I:file \1 not removed|p'
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
echoinfo "E:$test:`date`"
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
new-zones-directory "./nope";
|
||||
port 5300;
|
||||
pid-file "../named.pid";
|
||||
listen-on { 127.0.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
};
|
||||
@@ -73,6 +73,17 @@ grep "managed-keys-directory './nope' is not writable" ns2/named.run > /dev/null
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking that named refuses to reconfigure if new-zones-directory is not writable ($n)"
|
||||
ret=0
|
||||
cp -f ns2/named-alt6.conf ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig > rndc.out.$n 2>&1
|
||||
grep "failed: permission denied" rndc.out.$n > /dev/null 2>&1 || ret=1
|
||||
sleep 1
|
||||
grep "new-zones-directory './nope' is not writable" ns2/named.run > /dev/null 2>&1 || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking that named refuses to start if working directory is not writable ($n)"
|
||||
ret=0
|
||||
|
||||
@@ -342,8 +342,8 @@ status=`expr $status + $ret`
|
||||
|
||||
echo "I:checking sync record publication"
|
||||
ret=0
|
||||
grep CDNSKEY $cfile.signed > /dev/null || ret=1
|
||||
grep CDS $cfile.signed > /dev/null || ret=1
|
||||
grep -w CDNSKEY $cfile.signed > /dev/null || ret=1
|
||||
grep -w CDS $cfile.signed > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -352,8 +352,8 @@ ret=0
|
||||
$SETTIME -P now -A now -Dsync now ${cksk5} > /dev/null
|
||||
$SIGNER -Sg -r $RANDFILE -o $czone -f $cfile.new $cfile.signed > /dev/null 2>&1
|
||||
mv $cfile.new $cfile.signed
|
||||
grep CDNSKEY $cfile.signed > /dev/null && ret=1
|
||||
grep CDS $cfile.signed > /dev/null && ret=1
|
||||
grep -w CDNSKEY $cfile.signed > /dev/null && ret=1
|
||||
grep -w CDS $cfile.signed > /dev/null && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012, 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012, 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -137,5 +137,12 @@ fi
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
ret=0
|
||||
n=`expr $n + 1`
|
||||
echo "I:checking priming queries are counted ($n)"
|
||||
grep "1 priming queries" ns3/named.stats
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -4,6 +4,8 @@
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
rm -f */named.memstats
|
||||
rm -f */named.run
|
||||
rm -f dig.out.*
|
||||
rm -f ns1/K*+*+*.key
|
||||
rm -f ns1/K*+*+*.private
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS4
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.4;
|
||||
notify-source 10.53.0.4;
|
||||
transfer-source 10.53.0.4;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.4; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
synth-from-dnssec no;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "root.hints";
|
||||
};
|
||||
|
||||
include "../ns1/trusted.conf";
|
||||
// include "../../common/controls.conf";
|
||||
@@ -0,0 +1,8 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
. NS ns1
|
||||
ns1 A 10.53.0.1
|
||||
@@ -0,0 +1,33 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS5
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.5;
|
||||
notify-source 10.53.0.5;
|
||||
transfer-source 10.53.0.5;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.5; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
synth-from-dnssec yes;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "root.hints";
|
||||
};
|
||||
|
||||
include "../ns1/trusted.conf";
|
||||
@@ -0,0 +1,8 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
. NS ns1
|
||||
ns1 A 10.53.0.1
|
||||
@@ -17,49 +17,58 @@ rm -f dig.out.*
|
||||
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd +dnssec -p 5300"
|
||||
DELVOPTS="-a ns1/trusted.conf -p 5300"
|
||||
|
||||
echo "I:prime negative NXDOMAIN response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
nxdomain=dig.out.ns2.test$n
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
for ns in 2 4 5
|
||||
do
|
||||
case $ns in
|
||||
2) description="<default>";;
|
||||
4) description="no";;
|
||||
5) description="yes";;
|
||||
*) exit 1;;
|
||||
esac
|
||||
echo "I:prime negative NXDOMAIN response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
[ $ns -eq ${ns} ] && nxdomain=dig.out.ns${ns}.test$n
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:prime negative NODATA response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS nodata.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
nodata=dig.out.ns2.test$n
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:prime negative NODATA response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS nodata.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
[ $ns -eq 2 ] && nodata=dig.out.ns${ns}.test$n
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:prime wildcard response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.wild-a.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "a.wild-a.example.*3600.IN.A" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:prime wildcard response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.wild-a.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "a.wild-a.example.*3600.IN.A" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:prime wildcard CNAME response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.wild-cname.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "a.wild-cname.example.*3600.IN.CNAME" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:prime wildcard CNAME response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS a.wild-cname.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "a.wild-cname.example.*3600.IN.CNAME" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
done
|
||||
|
||||
echo "I:prime redirect response (+nodnssec) ($n)"
|
||||
echo "I:prime redirect response (+nodnssec) (synth-from-dnssec <default>;) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +nodnssec a.redirect. @10.53.0.3 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
@@ -69,54 +78,88 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
#
|
||||
# ensure TTL of synthesised answers differs from direct answers.
|
||||
#
|
||||
sleep 1
|
||||
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 dumpdb
|
||||
for ns in 2 4 5
|
||||
do
|
||||
case $ns in
|
||||
2) synth=yes description="<default>";;
|
||||
4) synth=no description="no";;
|
||||
5) synth=yes description="yes";;
|
||||
*) exit 1;;
|
||||
esac
|
||||
echo "I:check synthesized NXDOMAIN response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
if [ ${synth} = yes ]
|
||||
then
|
||||
grep "example.*IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null && ret=1
|
||||
else
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$PERL ../digcomp.pl $nxdomain dig.out.ns${ns}.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check synthesized NXDOMAIN response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
$PERL ../digcomp.pl $nxdomain dig.out.ns2.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:check synthesized NODATA response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS nodata.example. @10.53.0.${ns} aaaa > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
if [ ${synth} = yes ]
|
||||
then
|
||||
grep "example.*IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null && ret=1
|
||||
else
|
||||
grep "example.*3600.IN.SOA" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$PERL ../digcomp.pl $nodata dig.out.ns${ns}.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check synthesized NODATA response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS nodata.example. @10.53.0.2 aaaa > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example.*3600.IN.SOA" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
$PERL ../digcomp.pl $nodata dig.out.ns2.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:check synthesized wildcard response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.wild-a.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
if [ ${synth} = yes ]
|
||||
then
|
||||
grep "b\.wild-a\.example\..*IN.A" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "b\.wild-a\.example\..*3600.IN.A" dig.out.ns${ns}.test$n > /dev/null && ret=1
|
||||
else
|
||||
grep "b\.wild-a\.example\..*3600.IN.A" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
fi
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check synthesized wildcard response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.wild-a.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "b\.wild-a\.example\..*3600.IN.A" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
echo "I:check synthesized wildcard CNAME response (synth-from-dnssec ${description};) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.wild-cname.example. @10.53.0.${ns} a > dig.out.ns${ns}.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
if [ ${synth} = yes ]
|
||||
then
|
||||
grep "b.wild-cname.example.*IN.CNAME" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
grep "b.wild-cname.example.*3600.IN.CNAME" dig.out.ns${ns}.test$n > /dev/null && ret=1
|
||||
else
|
||||
grep "b.wild-cname.example.*3600.IN.CNAME" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
fi
|
||||
grep "ns1.example.*.IN.A" dig.out.ns${ns}.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
done
|
||||
|
||||
echo "I:check synthesized wildcard CNAME response ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.wild-cname.example. @10.53.0.2 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "b.wild-cname.example.*3600.IN.CNAME" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
grep "ns1.example.*.IN.A" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check redirect response (+dnssec) ($n)"
|
||||
echo "I:check redirect response (+dnssec) (synth-from-dnssec <default>;) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS b.redirect. @10.53.0.3 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -126,7 +169,7 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check redirect response (+nodnssec) ($n)"
|
||||
echo "I:check redirect response (+nodnssec) (synth-from-dnssec <default>;) ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +nodnssec b.redirect. @10.53.0.3 a > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:[^;]* ad[ ;]" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
arpaname
|
||||
dnstap-read
|
||||
genrandom
|
||||
isc-hmac-fixup
|
||||
mdig
|
||||
named-journalprint
|
||||
named-nzd2nzf
|
||||
|
||||
+4
-15
@@ -38,21 +38,21 @@ DNSTAPTARGETS = dnstap-read@EXEEXT@
|
||||
NZDTARGETS = named-nzd2nzf@EXEEXT@
|
||||
TARGETS = arpaname@EXEEXT@ named-journalprint@EXEEXT@ \
|
||||
named-rrchecker@EXEEXT@ nsec3hash@EXEEXT@ \
|
||||
genrandom@EXEEXT@ isc-hmac-fixup@EXEEXT@ mdig@EXEEXT@ \
|
||||
genrandom@EXEEXT@ mdig@EXEEXT@ \
|
||||
@DNSTAPTARGETS@ @NZDTARGETS@
|
||||
|
||||
DNSTAPSRCS = dnstap-read.c
|
||||
NZDSRCS = named-nzd2nzf.c
|
||||
SRCS = arpaname.c named-journalprint.c named-rrchecker.c \
|
||||
nsec3hash.c genrandom.c isc-hmac-fixup.c mdig.c \
|
||||
nsec3hash.c genrandom.c mdig.c \
|
||||
@DNSTAPSRCS@ @NZDSRCS@
|
||||
|
||||
MANPAGES = arpaname.1 dnstap-read.1 genrandom.8 \
|
||||
isc-hmac-fixup.8 mdig.1 named-journalprint.8 \
|
||||
mdig.1 named-journalprint.8 \
|
||||
named-nzd2nzf.8 named-rrchecker.1 nsec3hash.8
|
||||
|
||||
HTMLPAGES = arpaname.html dnstap-read.html genrandom.html \
|
||||
isc-hmac-fixup.html mdig.html named-journalprint.html \
|
||||
mdig.html named-journalprint.html \
|
||||
named-nzd2nzf.html named-rrchecker.html nsec3hash.html
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
@@ -78,11 +78,6 @@ nsec3hash@EXEEXT@: nsec3hash.@O@ ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||
export LIBS0="${DNSLIBS} ${ISCLIBS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
isc-hmac-fixup@EXEEXT@: isc-hmac-fixup.@O@ ${ISCDEPLIBS}
|
||||
export BASEOBJS="isc-hmac-fixup.@O@"; \
|
||||
export LIBS0="${ISCLIBS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
genrandom@EXEEXT@: genrandom.@O@
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||
-o $@ genrandom.@O@ @GENRANDOMLIB@ ${LIBS}
|
||||
@@ -134,12 +129,9 @@ install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@
|
||||
${DESTDIR}${sbindir}
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} genrandom@EXEEXT@ \
|
||||
${DESTDIR}${sbindir}
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} isc-hmac-fixup@EXEEXT@ \
|
||||
${DESTDIR}${sbindir}
|
||||
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} mdig@EXEEXT@ \
|
||||
${DESTDIR}${bindir}
|
||||
${INSTALL_DATA} ${srcdir}/arpaname.1 ${DESTDIR}${mandir}/man1
|
||||
${INSTALL_DATA} ${srcdir}/isc-hmac-fixup.8 ${DESTDIR}${mandir}/man8
|
||||
${INSTALL_DATA} ${srcdir}/named-journalprint.8 ${DESTDIR}${mandir}/man8
|
||||
${INSTALL_DATA} ${srcdir}/named-rrchecker.1 ${DESTDIR}${mandir}/man1
|
||||
${INSTALL_DATA} ${srcdir}/nsec3hash.8 ${DESTDIR}${mandir}/man8
|
||||
@@ -152,12 +144,9 @@ uninstall::
|
||||
rm -f ${DESTDIR}${mandir}/man8/nsec3hash.8
|
||||
rm -f ${DESTDIR}${mandir}/man1/named-rrchecker.1
|
||||
rm -f ${DESTDIR}${mandir}/man8/named-journalprint.8
|
||||
rm -f ${DESTDIR}${mandir}/man8/isc-hmac-fixup.8
|
||||
rm -f ${DESTDIR}${mandir}/man1/arpaname.1
|
||||
${LIBTOOL_MODE_UNINSTALL} rm -f \
|
||||
${DESTDIR}${bindir}/mdig@EXEEXT@
|
||||
${LIBTOOL_MODE_UNINSTALL} rm -f \
|
||||
${DESTDIR}${sbindir}/isc-hmac-fixup@EXEEXT@
|
||||
${LIBTOOL_MODE_UNINSTALL} rm -f \
|
||||
${DESTDIR}${sbindir}/genrandom@EXEEXT@
|
||||
${LIBTOOL_MODE_UNINSTALL} rm -f \
|
||||
|
||||
@@ -1,69 +0,0 @@
|
||||
.\" Copyright (C) 2010, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.\" file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
'\" t
|
||||
.\" Title: isc-hmac-fixup
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||
.\" Date: 2013-04-28
|
||||
.\" Manual: BIND9
|
||||
.\" Source: ISC
|
||||
.\" Language: English
|
||||
.\"
|
||||
.TH "ISC\-HMAC\-FIXUP" "8" "2013\-04\-28" "ISC" "BIND9"
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * Define some portability stuff
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
.\" http://bugs.debian.org/507673
|
||||
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
|
||||
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
.ie \n(.g .ds Aq \(aq
|
||||
.el .ds Aq '
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * set default formatting
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" disable hyphenation
|
||||
.nh
|
||||
.\" disable justification (adjust text to left margin only)
|
||||
.ad l
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * MAIN CONTENT STARTS HERE *
|
||||
.\" -----------------------------------------------------------------
|
||||
.SH "NAME"
|
||||
isc-hmac-fixup \- fixes HMAC keys generated by older versions of BIND
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBisc\-hmac\-fixup\fR\ 'u
|
||||
\fBisc\-hmac\-fixup\fR {\fIalgorithm\fR} {\fIsecret\fR}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
Versions of BIND 9 up to and including BIND 9\&.6 had a bug causing HMAC\-SHA* TSIG keys which were longer than the digest length of the hash algorithm (i\&.e\&., SHA1 keys longer than 160 bits, SHA256 keys longer than 256 bits, etc) to be used incorrectly, generating a message authentication code that was incompatible with other DNS implementations\&.
|
||||
.PP
|
||||
This bug has been fixed in BIND 9\&.7\&. However, the fix may cause incompatibility between older and newer versions of BIND, when using long keys\&.
|
||||
\fBisc\-hmac\-fixup\fR
|
||||
modifies those keys to restore compatibility\&.
|
||||
.PP
|
||||
To modify a key, run
|
||||
\fBisc\-hmac\-fixup\fR
|
||||
and specify the key\*(Aqs algorithm and secret on the command line\&. If the secret is longer than the digest length of the algorithm (64 bytes for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a new secret will be generated consisting of a hash digest of the old secret\&. (If the secret did not require conversion, then it will be printed without modification\&.)
|
||||
.SH "SECURITY CONSIDERATIONS"
|
||||
.PP
|
||||
Secrets that have been converted by
|
||||
\fBisc\-hmac\-fixup\fR
|
||||
are shortened, but as this is how the HMAC protocol works in operation anyway, it does not affect security\&. RFC 2104 notes, "Keys longer than [the digest length] are acceptable but the extra length would not significantly increase the function strength\&."
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
BIND 9 Administrator Reference Manual,
|
||||
RFC 2104\&.
|
||||
.SH "AUTHOR"
|
||||
.PP
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2010, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
@@ -1,139 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2010, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* $Id: isc-hmac-fixup.c,v 1.4 2010/03/10 02:17:52 marka Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/base64.h>
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/md5.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/result.h>
|
||||
#include <isc/sha1.h>
|
||||
#include <isc/sha2.h>
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/string.h>
|
||||
|
||||
#include <pk11/site.h>
|
||||
|
||||
#define HMAC_LEN 64
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
isc_buffer_t buf;
|
||||
unsigned char key[1024];
|
||||
char secret[1024];
|
||||
char base64[(1024*4)/3];
|
||||
isc_region_t r;
|
||||
isc_result_t result;
|
||||
|
||||
if (argc != 3) {
|
||||
fprintf(stderr, "Usage:\t%s algorithm secret\n", argv[0]);
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
fprintf(stderr, "\talgorithm: (MD5 | SHA1 | SHA224 | "
|
||||
"SHA256 | SHA384 | SHA512)\n");
|
||||
#else
|
||||
fprintf(stderr, "\talgorithm: (SHA1 | SHA224 | "
|
||||
"SHA256 | SHA384 | SHA512)\n");
|
||||
#endif
|
||||
return (1);
|
||||
}
|
||||
|
||||
isc_buffer_init(&buf, secret, sizeof(secret));
|
||||
result = isc_base64_decodestring(argv[2], &buf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "error: %s\n", isc_result_totext(result));
|
||||
return (1);
|
||||
}
|
||||
isc_buffer_usedregion(&buf, &r);
|
||||
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
if (!strcasecmp(argv[1], "md5") ||
|
||||
!strcasecmp(argv[1], "hmac-md5")) {
|
||||
if (r.length > HMAC_LEN) {
|
||||
isc_md5_t md5ctx;
|
||||
isc_md5_init(&md5ctx);
|
||||
isc_md5_update(&md5ctx, r.base, r.length);
|
||||
isc_md5_final(&md5ctx, key);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_MD5_DIGESTLENGTH;
|
||||
}
|
||||
} else
|
||||
#endif
|
||||
if (!strcasecmp(argv[1], "sha1") ||
|
||||
!strcasecmp(argv[1], "hmac-sha1")) {
|
||||
if (r.length > ISC_SHA1_DIGESTLENGTH) {
|
||||
isc_sha1_t sha1ctx;
|
||||
isc_sha1_init(&sha1ctx);
|
||||
isc_sha1_update(&sha1ctx, r.base, r.length);
|
||||
isc_sha1_final(&sha1ctx, key);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_SHA1_DIGESTLENGTH;
|
||||
}
|
||||
} else if (!strcasecmp(argv[1], "sha224") ||
|
||||
!strcasecmp(argv[1], "hmac-sha224")) {
|
||||
if (r.length > ISC_SHA224_DIGESTLENGTH) {
|
||||
isc_sha224_t sha224ctx;
|
||||
isc_sha224_init(&sha224ctx);
|
||||
isc_sha224_update(&sha224ctx, r.base, r.length);
|
||||
isc_sha224_final(key, &sha224ctx);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_SHA224_DIGESTLENGTH;
|
||||
}
|
||||
} else if (!strcasecmp(argv[1], "sha256") ||
|
||||
!strcasecmp(argv[1], "hmac-sha256")) {
|
||||
if (r.length > ISC_SHA256_DIGESTLENGTH) {
|
||||
isc_sha256_t sha256ctx;
|
||||
isc_sha256_init(&sha256ctx);
|
||||
isc_sha256_update(&sha256ctx, r.base, r.length);
|
||||
isc_sha256_final(key, &sha256ctx);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_SHA256_DIGESTLENGTH;
|
||||
}
|
||||
} else if (!strcasecmp(argv[1], "sha384") ||
|
||||
!strcasecmp(argv[1], "hmac-sha384")) {
|
||||
if (r.length > ISC_SHA384_DIGESTLENGTH) {
|
||||
isc_sha384_t sha384ctx;
|
||||
isc_sha384_init(&sha384ctx);
|
||||
isc_sha384_update(&sha384ctx, r.base, r.length);
|
||||
isc_sha384_final(key, &sha384ctx);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_SHA384_DIGESTLENGTH;
|
||||
}
|
||||
} else if (!strcasecmp(argv[1], "sha512") ||
|
||||
!strcasecmp(argv[1], "hmac-sha512")) {
|
||||
if (r.length > ISC_SHA512_DIGESTLENGTH) {
|
||||
isc_sha512_t sha512ctx;
|
||||
isc_sha512_init(&sha512ctx);
|
||||
isc_sha512_update(&sha512ctx, r.base, r.length);
|
||||
isc_sha512_final(key, &sha512ctx);
|
||||
|
||||
r.base = key;
|
||||
r.length = ISC_SHA512_DIGESTLENGTH;
|
||||
}
|
||||
} else {
|
||||
fprintf(stderr, "unknown hmac/digest algorithm: %s\n", argv[1]);
|
||||
return (1);
|
||||
}
|
||||
|
||||
isc_buffer_init(&buf, base64, sizeof(base64));
|
||||
result = isc_base64_totext(&r, 0, "", &buf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "error: %s\n", isc_result_totext(result));
|
||||
return (1);
|
||||
}
|
||||
fprintf(stdout, "%.*s\n", (int)isc_buffer_usedlength(&buf), base64);
|
||||
return (0);
|
||||
}
|
||||
@@ -1,96 +0,0 @@
|
||||
<!--
|
||||
- Copyright (C) 2010, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
-->
|
||||
|
||||
<!-- Converted by db4-upgrade version 1.0 -->
|
||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.isc-hmac-fixup">
|
||||
<info>
|
||||
<date>2013-04-28</date>
|
||||
</info>
|
||||
<refentryinfo>
|
||||
<corpname>ISC</corpname>
|
||||
<corpauthor>Internet Systems Consortium, Inc.</corpauthor>
|
||||
</refentryinfo>
|
||||
|
||||
<refmeta>
|
||||
<refentrytitle><application>isc-hmac-fixup</application></refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
<refmiscinfo>BIND9</refmiscinfo>
|
||||
</refmeta>
|
||||
|
||||
<refnamediv>
|
||||
<refname><application>isc-hmac-fixup</application></refname>
|
||||
<refpurpose>fixes HMAC keys generated by older versions of BIND</refpurpose>
|
||||
</refnamediv>
|
||||
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2010</year>
|
||||
<year>2013</year>
|
||||
<year>2014</year>
|
||||
<year>2015</year>
|
||||
<year>2016</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>isc-hmac-fixup</command>
|
||||
<arg choice="req" rep="norepeat"><replaceable class="parameter">algorithm</replaceable></arg>
|
||||
<arg choice="req" rep="norepeat"><replaceable class="parameter">secret</replaceable></arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsection><info><title>DESCRIPTION</title></info>
|
||||
|
||||
<para>
|
||||
Versions of BIND 9 up to and including BIND 9.6 had a bug causing
|
||||
HMAC-SHA* TSIG keys which were longer than the digest length of the
|
||||
hash algorithm (i.e., SHA1 keys longer than 160 bits, SHA256 keys
|
||||
longer than 256 bits, etc) to be used incorrectly, generating a
|
||||
message authentication code that was incompatible with other DNS
|
||||
implementations.
|
||||
</para>
|
||||
<para>
|
||||
This bug has been fixed in BIND 9.7. However, the fix may
|
||||
cause incompatibility between older and newer versions of
|
||||
BIND, when using long keys. <command>isc-hmac-fixup</command>
|
||||
modifies those keys to restore compatibility.
|
||||
</para>
|
||||
<para>
|
||||
To modify a key, run <command>isc-hmac-fixup</command> and
|
||||
specify the key's algorithm and secret on the command line. If the
|
||||
secret is longer than the digest length of the algorithm (64 bytes
|
||||
for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a
|
||||
new secret will be generated consisting of a hash digest of the old
|
||||
secret. (If the secret did not require conversion, then it will be
|
||||
printed without modification.)
|
||||
</para>
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>SECURITY CONSIDERATIONS</title></info>
|
||||
|
||||
<para>
|
||||
Secrets that have been converted by <command>isc-hmac-fixup</command>
|
||||
are shortened, but as this is how the HMAC protocol works in
|
||||
operation anyway, it does not affect security. RFC 2104 notes,
|
||||
"Keys longer than [the digest length] are acceptable but the
|
||||
extra length would not significantly increase the function
|
||||
strength."
|
||||
</para>
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>SEE ALSO</title></info>
|
||||
|
||||
<para>
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>,
|
||||
<citetitle>RFC 2104</citetitle>.
|
||||
</para>
|
||||
</refsection>
|
||||
|
||||
</refentry>
|
||||
@@ -1,92 +0,0 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2010, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
-->
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>isc-hmac-fixup</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry">
|
||||
<a name="man.isc-hmac-fixup"></a><div class="titlepage"></div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<div class="refnamediv">
|
||||
<h2>Name</h2>
|
||||
<p>
|
||||
<span class="application">isc-hmac-fixup</span>
|
||||
— fixes HMAC keys generated by older versions of BIND
|
||||
</p>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">isc-hmac-fixup</code>
|
||||
{<em class="replaceable"><code>algorithm</code></em>}
|
||||
{<em class="replaceable"><code>secret</code></em>}
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.7"></a><h2>DESCRIPTION</h2>
|
||||
|
||||
<p>
|
||||
Versions of BIND 9 up to and including BIND 9.6 had a bug causing
|
||||
HMAC-SHA* TSIG keys which were longer than the digest length of the
|
||||
hash algorithm (i.e., SHA1 keys longer than 160 bits, SHA256 keys
|
||||
longer than 256 bits, etc) to be used incorrectly, generating a
|
||||
message authentication code that was incompatible with other DNS
|
||||
implementations.
|
||||
</p>
|
||||
<p>
|
||||
This bug has been fixed in BIND 9.7. However, the fix may
|
||||
cause incompatibility between older and newer versions of
|
||||
BIND, when using long keys. <span class="command"><strong>isc-hmac-fixup</strong></span>
|
||||
modifies those keys to restore compatibility.
|
||||
</p>
|
||||
<p>
|
||||
To modify a key, run <span class="command"><strong>isc-hmac-fixup</strong></span> and
|
||||
specify the key's algorithm and secret on the command line. If the
|
||||
secret is longer than the digest length of the algorithm (64 bytes
|
||||
for SHA1 through SHA256, or 128 bytes for SHA384 and SHA512), then a
|
||||
new secret will be generated consisting of a hash digest of the old
|
||||
secret. (If the secret did not require conversion, then it will be
|
||||
printed without modification.)
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.8"></a><h2>SECURITY CONSIDERATIONS</h2>
|
||||
|
||||
<p>
|
||||
Secrets that have been converted by <span class="command"><strong>isc-hmac-fixup</strong></span>
|
||||
are shortened, but as this is how the HMAC protocol works in
|
||||
operation anyway, it does not affect security. RFC 2104 notes,
|
||||
"Keys longer than [the digest length] are acceptable but the
|
||||
extra length would not significantly increase the function
|
||||
strength."
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.9"></a><h2>SEE ALSO</h2>
|
||||
|
||||
<p>
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
<em class="citetitle">RFC 2104</em>.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
</div></body>
|
||||
</html>
|
||||
@@ -1,18 +0,0 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup>
|
||||
<Filter Include="Source Files">
|
||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
||||
<Extensions>cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="Resource Files">
|
||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
||||
</Filter>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="..\isc-hmac-fixup.c">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -1,112 +0,0 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project DefaultTargets="Build" ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup Label="ProjectConfigurations">
|
||||
<ProjectConfiguration Include="Debug|@PLATFORM@">
|
||||
<Configuration>Debug</Configuration>
|
||||
<Platform>@PLATFORM@</Platform>
|
||||
</ProjectConfiguration>
|
||||
<ProjectConfiguration Include="Release|@PLATFORM@">
|
||||
<Configuration>Release</Configuration>
|
||||
<Platform>@PLATFORM@</Platform>
|
||||
</ProjectConfiguration>
|
||||
</ItemGroup>
|
||||
<PropertyGroup Label="Globals">
|
||||
<ProjectGuid>{70F2F0DF-665D-4444-A982-AEA31A861A22}</ProjectGuid>
|
||||
<Keyword>Win32Proj</Keyword>
|
||||
<RootNamespace>ischmacfixup</RootNamespace>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'" Label="Configuration">
|
||||
<ConfigurationType>Application</ConfigurationType>
|
||||
<UseDebugLibraries>true</UseDebugLibraries>
|
||||
<CharacterSet>MultiByte</CharacterSet>
|
||||
</PropertyGroup>
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'" Label="Configuration">
|
||||
<ConfigurationType>Application</ConfigurationType>
|
||||
<UseDebugLibraries>false</UseDebugLibraries>
|
||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
||||
<CharacterSet>MultiByte</CharacterSet>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
||||
<ImportGroup Label="ExtensionSettings">
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
||||
</ImportGroup>
|
||||
<PropertyGroup Label="UserMacros" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
||||
<LinkIncremental>true</LinkIncremental>
|
||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
||||
<IntDir>.\$(Configuration)\</IntDir>
|
||||
<TargetName>isc-hmac-fixup</TargetName>
|
||||
</PropertyGroup>
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
<LinkIncremental>false</LinkIncremental>
|
||||
<OutDir>..\..\..\Build\$(Configuration)\</OutDir>
|
||||
<IntDir>.\$(Configuration)\</IntDir>
|
||||
<TargetName>isc-hmac-fixup</TargetName>
|
||||
</PropertyGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|@PLATFORM@'">
|
||||
<ClCompile>
|
||||
<PrecompiledHeader>
|
||||
</PrecompiledHeader>
|
||||
<WarningLevel>Level3</WarningLevel>
|
||||
<Optimization>Disabled</Optimization>
|
||||
<PreprocessorDefinitions>WIN32;@CRYPTO@_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<BrowseInformation>true</BrowseInformation>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>Console</SubSystem>
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>libisc.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
<ClCompile>
|
||||
<WarningLevel>Level3</WarningLevel>
|
||||
<PrecompiledHeader>
|
||||
</PrecompiledHeader>
|
||||
<Optimization>MaxSpeed</Optimization>
|
||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
||||
<IntrinsicFunctions>@INTRINSIC@</IntrinsicFunctions>
|
||||
<PreprocessorDefinitions>WIN32;@CRYPTO@NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
||||
<InlineFunctionExpansion>OnlyExplicitInline</InlineFunctionExpansion>
|
||||
<WholeProgramOptimization>false</WholeProgramOptimization>
|
||||
<StringPooling>true</StringPooling>
|
||||
<PrecompiledHeaderOutputFile>.\$(Configuration)\$(ProjectName).pch</PrecompiledHeaderOutputFile>
|
||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>Console</SubSystem>
|
||||
<GenerateDebugInformation>false</GenerateDebugInformation>
|
||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
||||
<OptimizeReferences>true</OptimizeReferences>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
||||
<AdditionalLibraryDirectories>..\..\..\lib\isc\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>libisc.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="..\isc-hmac-fixup.c" />
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
@@ -1,3 +0,0 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
</Project>
|
||||
@@ -186,7 +186,6 @@ const FileData installFiles[] =
|
||||
{"named-compilezone.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
{"named-journalprint.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
{"named-rrchecker.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
{"isc-hmac-fixup.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
#ifdef USE_PKCS11
|
||||
{"pkcs11-destroy.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
{"pkcs11-keygen.exe", FileData::BinDir, FileData::Normal, FALSE, FALSE},
|
||||
|
||||
@@ -141,10 +141,6 @@ int sigwait(const unsigned int *set, int *sig);
|
||||
/* Use AES for Client Cookie generation */
|
||||
#undef AES_CC
|
||||
|
||||
/* Define to enable the "filter-aaaa-on-v4" and "filter-aaaa-on-v6" options.
|
||||
*/
|
||||
#undef ALLOW_FILTER_AAAA
|
||||
|
||||
/* define if ATF unit tests are to be built. */
|
||||
#undef ATF_TEST
|
||||
|
||||
|
||||
@@ -306,10 +306,6 @@ typedef __int64 off_t;
|
||||
/* Define to the sockaddr length type used by getnameinfo(3). */
|
||||
#define IRS_GETNAMEINFO_SOCKLEN_T socklen_t
|
||||
|
||||
/* Define to enable the "filter-aaaa-on-v4" and "filter-aaaa-on-v6" options.
|
||||
*/
|
||||
@ALLOW_FILTER_AAAA@
|
||||
|
||||
/* Define to enable "rrset-order fixed" syntax. */
|
||||
@DNS_RDATASET_FIXED@
|
||||
|
||||
|
||||
@@ -1033,7 +1033,6 @@ enable_dnsrps_dl
|
||||
with_dnsrps_libname
|
||||
with_dnsrps_dir
|
||||
enable_dnsrps
|
||||
enable_filter_aaaa
|
||||
enable_dnstap
|
||||
with_protobuf_c
|
||||
with_libfstrm
|
||||
@@ -1719,7 +1718,6 @@ Optional Features:
|
||||
--disable-rpz-nsdname disable rpz nsdname rules [default=enabled]
|
||||
--enable-dnsrps-dl DNS Response Policy Service delayed link [default=$librpz_dl]
|
||||
--enable-dnsrps enable DNS Response Policy Service API
|
||||
--enable-filter-aaaa enable filtering of AAAA records [default=no]
|
||||
--enable-dnstap enable dnstap support (requires fstrm, protobuf-c)
|
||||
--enable-querytrace enable very verbose query trace logging [default=no]
|
||||
--enable-full-report report values of all configure options
|
||||
@@ -11470,7 +11468,6 @@ yes)
|
||||
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
||||
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
||||
test "${with_atf+set}" = set || with_atf=yes
|
||||
test "${enable_filter_aaaa+set}" = set || enable_filter_aaaa=yes
|
||||
test "${with_dlz_filesystem+set}" = set || with_dlz_filesystem=yes
|
||||
test "${enable_symtable+set}" = set || enable_symtable=all
|
||||
test "${enable_warn_error+set}" = set || enable_warn_error=yes
|
||||
@@ -20944,28 +20941,6 @@ $as_echo "#define USE_DNSRPS 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
#
|
||||
# Activate "filter-aaaa-on-v4/v6" or not?
|
||||
#
|
||||
# Check whether --enable-filter-aaaa was given.
|
||||
if test "${enable_filter_aaaa+set}" = set; then :
|
||||
enableval=$enable_filter_aaaa; enable_filter="$enableval"
|
||||
else
|
||||
enable_filter="no"
|
||||
fi
|
||||
|
||||
case "$enable_filter" in
|
||||
yes)
|
||||
|
||||
$as_echo "#define ALLOW_FILTER_AAAA 1" >>confdefs.h
|
||||
|
||||
;;
|
||||
no)
|
||||
;;
|
||||
*)
|
||||
;;
|
||||
esac
|
||||
|
||||
#
|
||||
# Activate dnstap?
|
||||
#
|
||||
@@ -26238,8 +26213,6 @@ report() {
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
test "yes" = "$enable_fixed" && \
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
test "yes" = "$enable_filter" && \
|
||||
echo " AAAA filtering (--enable-filter-aaaa)"
|
||||
test "yes" = "$enable_seccomp" && \
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
test "yes" = "$want_backtrace" && \
|
||||
|
||||
@@ -66,7 +66,6 @@ yes)
|
||||
test "${enable_fixed_rrset+set}" = set || enable_fixed_rrset=yes
|
||||
test "${enable_querytrace+set}" = set || enable_querytrace=yes
|
||||
test "${with_atf+set}" = set || with_atf=yes
|
||||
test "${enable_filter_aaaa+set}" = set || enable_filter_aaaa=yes
|
||||
test "${with_dlz_filesystem+set}" = set || with_dlz_filesystem=yes
|
||||
test "${enable_symtable+set}" = set || enable_symtable=all
|
||||
test "${enable_warn_error+set}" = set || enable_warn_error=yes
|
||||
@@ -4413,24 +4412,6 @@ if test "x$enable_dnsrps" != "xno"; then
|
||||
AC_DEFINE([USE_DNSRPS], [1], [Enable DNS Response Policy Service API])
|
||||
fi
|
||||
|
||||
#
|
||||
# Activate "filter-aaaa-on-v4/v6" or not?
|
||||
#
|
||||
AC_ARG_ENABLE(filter-aaaa,
|
||||
[ --enable-filter-aaaa enable filtering of AAAA records [[default=no]]],
|
||||
enable_filter="$enableval",
|
||||
enable_filter="no")
|
||||
case "$enable_filter" in
|
||||
yes)
|
||||
AC_DEFINE(ALLOW_FILTER_AAAA, 1,
|
||||
[Define to enable the "filter-aaaa-on-v4" and "filter-aaaa-on-v6" options.])
|
||||
;;
|
||||
no)
|
||||
;;
|
||||
*)
|
||||
;;
|
||||
esac
|
||||
|
||||
#
|
||||
# Activate dnstap?
|
||||
#
|
||||
@@ -5481,8 +5462,6 @@ report() {
|
||||
echo " DNS Response Policy Service interface (--enable-dnsrps)"
|
||||
test "yes" = "$enable_fixed" && \
|
||||
echo " Allow 'fixed' rrset-order (--enable-fixed-rrset)"
|
||||
test "yes" = "$enable_filter" && \
|
||||
echo " AAAA filtering (--enable-filter-aaaa)"
|
||||
test "yes" = "$enable_seccomp" && \
|
||||
echo " Use libseccomp system call filtering (--enable-seccomp)"
|
||||
test "yes" = "$want_backtrace" && \
|
||||
|
||||
+52
-28
@@ -1171,7 +1171,7 @@ zone "eng.example.com" {
|
||||
"<userinput>hmac-sha256</userinput>",
|
||||
"<userinput>hmac-sha384</userinput>"
|
||||
and "<userinput>hmac-sha512</userinput>"
|
||||
have any meaning. The secret is a base-64 encoded string
|
||||
have any meaning. The secret is a Base64 encoded string
|
||||
as specified in RFC 3548.
|
||||
</para>
|
||||
|
||||
@@ -3552,7 +3552,7 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
|
||||
number of required bits preceded by a dash, e.g.
|
||||
<literal>hmac-sha1-80</literal>. The
|
||||
<replaceable>secret_string</replaceable> is the secret
|
||||
to be used by the algorithm, and is treated as a base-64
|
||||
to be used by the algorithm, and is treated as a Base64
|
||||
encoded string.
|
||||
</para>
|
||||
|
||||
@@ -3815,17 +3815,17 @@ notrace</command>. All debugging messages in the server have a debug
|
||||
<command>print-time</command> can be set to
|
||||
<userinput>yes</userinput>, <userinput>no</userinput>,
|
||||
or a time format specifier, which may be one of
|
||||
<option>local</option>, <option>iso8601</option> or
|
||||
<option>iso8601-utc</option>. If set to
|
||||
<userinput>local</userinput>, <userinput>iso8601</userinput> or
|
||||
<userinput>iso8601-utc</userinput>. If set to
|
||||
<userinput>no</userinput>, then the date and time will
|
||||
not be logged. If set to <userinput>yes</userinput>
|
||||
or <option>local</option>, the date and time are logged
|
||||
or <userinput>local</userinput>, the date and time are logged
|
||||
in a human readable format, using the local time zone.
|
||||
If set to <option>iso8601</option> the local time is
|
||||
If set to <userinput>iso8601</userinput> the local time is
|
||||
logged in ISO8601 format. If set to
|
||||
<option>iso8601-utc</option>, then the date and time
|
||||
<userinput>iso8601-utc</userinput>, then the date and time
|
||||
are logged in ISO8601 format, with time zone set to
|
||||
UTC. The default is <option>local</option>.
|
||||
UTC. The default is <userinput>local</userinput>.
|
||||
</para>
|
||||
<para>
|
||||
<command>print-time</command> may
|
||||
@@ -4309,6 +4309,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
[ <command>maintain-ixfr-base</command> <replaceable>yes_or_no</replaceable> ; ]
|
||||
[ <command>ixfr-from-differences</command> ( <replaceable>yes_or_no</replaceable> | <option>master</option> | <option>slave</option> ) ; ]
|
||||
[ <command>auto-dnssec</command> ( <option>allow</option> | <option>maintain</option> | <option>off</option> ) ; ]
|
||||
[ <command>inline-signing</command> <replaceable>yes_or_no</replaceable> ; ]
|
||||
[ <command>dnssec-enable</command> <replaceable>yes_or_no</replaceable> ; ]
|
||||
[ <command>dnssec-validation</command> ( <replaceable>yes_or_no</replaceable> | <option>auto</option> ) ; ]
|
||||
[ <command>dnssec-lookaside</command> ( <option>auto</option> | <option>no</option> | <replaceable>domain</replaceable> trust-anchor <replaceable>domain</replaceable> ) ; ]
|
||||
@@ -4548,6 +4549,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
...
|
||||
<command>}</command> ; ]
|
||||
[ <command>v6-bias</command> <replaceable>number</replaceable> ; ]
|
||||
[ <command>trust-anchor-telemetry</command> <replaceable>yes_or_no</replaceable> ; ]
|
||||
<command>}</command> ; ]
|
||||
</programlisting>
|
||||
|
||||
@@ -4987,7 +4989,10 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<para>
|
||||
Specifies the directory in which to store the configuration
|
||||
parameters for zones added via <command>rndc addzone</command>.
|
||||
By default, this is the working directory.
|
||||
By default, this is the working directory. If set to a relative
|
||||
path, it will be relative to the working directory. The
|
||||
directory <emphasis>must</emphasis> be writable by the
|
||||
effective user ID of the <command>named</command> process.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -5710,12 +5715,14 @@ options {
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies the TTL to be returned on stale answers.
|
||||
The default is 1 second. The minimal allowed is
|
||||
The default is 1 second. The minimum allowed is
|
||||
also 1 second; a value of 0 will be updated silently
|
||||
to 1 second. For stale answers to be returned
|
||||
to 1 second. For stale answers to be returned,
|
||||
they must be enabled (either in the configuration file
|
||||
using <command>stale-answer-enable</command> or via
|
||||
<command>rndc</command>), and
|
||||
<option>max-stale-ttl</option> must be set to a
|
||||
non zero value and they must not have been disabled
|
||||
by <command>rndc</command>.
|
||||
nonzero value.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -6448,17 +6455,21 @@ options {
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><command>serve-stale-enable</command></term>
|
||||
<term><command>stale-answer-enable</command></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Enable the returning of stale answers when the
|
||||
nameservers for the zone are not answering. This
|
||||
is off by default but can be enabled/disabled via
|
||||
<command>rndc server-stale on</command> and
|
||||
<command>rndc server-stale off</command> which
|
||||
override the named.conf setting. <command>rndc
|
||||
server-stale reset</command> will restore control
|
||||
via named.conf.
|
||||
is off by default, but can be enabled/disabled via
|
||||
<command>rndc serve-stale on</command> and
|
||||
<command>rndc serve-stale off</command>, which
|
||||
override the <filename>named.conf</filename>
|
||||
setting. <command>rndc serve-stale reset</command>
|
||||
restores the setting to the one specified in
|
||||
<filename>named.conf</filename>. Note that
|
||||
reloading or reconfiguring <command>named</command>
|
||||
will not re-enable serving of stale records if they
|
||||
have been disabled via <command>rndc</command>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -6707,10 +6718,7 @@ options {
|
||||
<term><command>filter-aaaa-on-v4</command></term>
|
||||
<listitem>
|
||||
<para>
|
||||
This option is only available when
|
||||
<acronym>BIND</acronym> 9 is compiled with the
|
||||
<userinput>--enable-filter-aaaa</userinput> option on the
|
||||
"configure" command line. It is intended to help the
|
||||
This option is intended to help the
|
||||
transition from IPv4 to IPv6 by not giving IPv6 addresses
|
||||
to DNS clients unless they have connections to the IPv6
|
||||
Internet. This is not recommended unless absolutely
|
||||
@@ -8824,7 +8832,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
server waits on an idle TCP connection before closing
|
||||
it when the client is using the EDNS TCP keepalive
|
||||
option. The default is 300 (30 seconds), the maximum
|
||||
is 1200 (two minutes), and the minimum is 1 (one tenth
|
||||
is 65535 (about 1.8 hours), and the minimum is 1 (one tenth
|
||||
of a second). Values above the maximum or below the minimum
|
||||
will be adjusted with a logged warning.
|
||||
This value may be greater than
|
||||
@@ -8846,7 +8854,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
keepalive option. This informs a client of the
|
||||
amount of time it may keep the session open.
|
||||
The default is 300 (30 seconds), the maximum is
|
||||
1200 (two minutes), and the minimum is 0, which
|
||||
65535 (about 1.8 hours), and the minimum is 0, which
|
||||
signals that the clients must close TCP connections
|
||||
immediately. Ordinarily this should be set to the
|
||||
same value as <command>tcp-keepalive-timeout</command>.
|
||||
@@ -11356,7 +11364,7 @@ example.com CNAME rpz-tcp-only.
|
||||
<para>
|
||||
The <command>trusted-keys</command> statement can contain
|
||||
multiple key entries, each consisting of the key's
|
||||
domain name, flags, protocol, algorithm, and the Base-64
|
||||
domain name, flags, protocol, algorithm, and the Base64
|
||||
representation of the key data.
|
||||
Spaces, tabs, newlines and carriage returns are ignored
|
||||
in the key data, so the configuration may be split up into
|
||||
@@ -12503,6 +12511,23 @@ view "external" {
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><command>file</command></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Set the zone's filename. In <command>master</command>,
|
||||
<command>hint</command>, and <command>redirect</command>
|
||||
zones which do not have <command>masters</command>
|
||||
defined, zone data is loaded from this file. In
|
||||
<command>slave</command>, <command>stub</command>, and
|
||||
<command>redirect</command> zones which do have
|
||||
<command>masters</command> defined, zone data is
|
||||
retrieved from another server and saved in this file.
|
||||
This option is not applicable to other zone types.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><command>forward</command></term>
|
||||
<listitem>
|
||||
@@ -18535,7 +18560,6 @@ allow-query { !{ !10/8; any; }; key example; };
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/tools/dnstap-read.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/tools/genrandom.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/dig/host.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/tools/isc-hmac-fixup.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/tools/mdig.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/check/named-checkconf.docbook"/>
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="../../bin/check/named-checkzone.docbook"/>
|
||||
|
||||
@@ -603,7 +603,7 @@ zone "eng.example.com" {
|
||||
"<strong class="userinput"><code>hmac-sha256</code></strong>",
|
||||
"<strong class="userinput"><code>hmac-sha384</code></strong>"
|
||||
and "<strong class="userinput"><code>hmac-sha512</code></strong>"
|
||||
have any meaning. The secret is a base-64 encoded string
|
||||
have any meaning. The secret is a Base64 encoded string
|
||||
as specified in RFC 3548.
|
||||
</p>
|
||||
|
||||
|
||||
+48
-26
@@ -1232,7 +1232,7 @@
|
||||
number of required bits preceded by a dash, e.g.
|
||||
<code class="literal">hmac-sha1-80</code>. The
|
||||
<em class="replaceable"><code>secret_string</code></em> is the secret
|
||||
to be used by the algorithm, and is treated as a base-64
|
||||
to be used by the algorithm, and is treated as a Base64
|
||||
encoded string.
|
||||
</p>
|
||||
|
||||
@@ -1501,17 +1501,17 @@ notrace</strong></span>. All debugging messages in the server have a debug
|
||||
<span class="command"><strong>print-time</strong></span> can be set to
|
||||
<strong class="userinput"><code>yes</code></strong>, <strong class="userinput"><code>no</code></strong>,
|
||||
or a time format specifier, which may be one of
|
||||
<code class="option">local</code>, <code class="option">iso8601</code> or
|
||||
<code class="option">iso8601-utc</code>. If set to
|
||||
<strong class="userinput"><code>local</code></strong>, <strong class="userinput"><code>iso8601</code></strong> or
|
||||
<strong class="userinput"><code>iso8601-utc</code></strong>. If set to
|
||||
<strong class="userinput"><code>no</code></strong>, then the date and time will
|
||||
not be logged. If set to <strong class="userinput"><code>yes</code></strong>
|
||||
or <code class="option">local</code>, the date and time are logged
|
||||
or <strong class="userinput"><code>local</code></strong>, the date and time are logged
|
||||
in a human readable format, using the local time zone.
|
||||
If set to <code class="option">iso8601</code> the local time is
|
||||
If set to <strong class="userinput"><code>iso8601</code></strong> the local time is
|
||||
logged in ISO8601 format. If set to
|
||||
<code class="option">iso8601-utc</code>, then the date and time
|
||||
<strong class="userinput"><code>iso8601-utc</code></strong>, then the date and time
|
||||
are logged in ISO8601 format, with time zone set to
|
||||
UTC. The default is <code class="option">local</code>.
|
||||
UTC. The default is <strong class="userinput"><code>local</code></strong>.
|
||||
</p>
|
||||
<p>
|
||||
<span class="command"><strong>print-time</strong></span> may
|
||||
@@ -2395,6 +2395,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
[ <span class="command"><strong>maintain-ixfr-base</strong></span> <em class="replaceable"><code>yes_or_no</code></em> ; ]
|
||||
[ <span class="command"><strong>ixfr-from-differences</strong></span> ( <em class="replaceable"><code>yes_or_no</code></em> | <code class="option">master</code> | <code class="option">slave</code> ) ; ]
|
||||
[ <span class="command"><strong>auto-dnssec</strong></span> ( <code class="option">allow</code> | <code class="option">maintain</code> | <code class="option">off</code> ) ; ]
|
||||
[ <span class="command"><strong>inline-signing</strong></span> <em class="replaceable"><code>yes_or_no</code></em> ; ]
|
||||
[ <span class="command"><strong>dnssec-enable</strong></span> <em class="replaceable"><code>yes_or_no</code></em> ; ]
|
||||
[ <span class="command"><strong>dnssec-validation</strong></span> ( <em class="replaceable"><code>yes_or_no</code></em> | <code class="option">auto</code> ) ; ]
|
||||
[ <span class="command"><strong>dnssec-lookaside</strong></span> ( <code class="option">auto</code> | <code class="option">no</code> | <em class="replaceable"><code>domain</code></em> trust-anchor <em class="replaceable"><code>domain</code></em> ) ; ]
|
||||
@@ -2634,6 +2635,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
...
|
||||
<span class="command"><strong>}</strong></span> ; ]
|
||||
[ <span class="command"><strong>v6-bias</strong></span> <em class="replaceable"><code>number</code></em> ; ]
|
||||
[ <span class="command"><strong>trust-anchor-telemetry</strong></span> <em class="replaceable"><code>yes_or_no</code></em> ; ]
|
||||
<span class="command"><strong>}</strong></span> ; ]
|
||||
</pre>
|
||||
|
||||
@@ -3045,7 +3047,10 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<p>
|
||||
Specifies the directory in which to store the configuration
|
||||
parameters for zones added via <span class="command"><strong>rndc addzone</strong></span>.
|
||||
By default, this is the working directory.
|
||||
By default, this is the working directory. If set to a relative
|
||||
path, it will be relative to the working directory. The
|
||||
directory <span class="emphasis"><em>must</em></span> be writable by the
|
||||
effective user ID of the <span class="command"><strong>named</strong></span> process.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>named-xfer</strong></span></span></dt>
|
||||
@@ -3671,12 +3676,14 @@ options {
|
||||
<dd>
|
||||
<p>
|
||||
Specifies the TTL to be returned on stale answers.
|
||||
The default is 1 second. The minimal allowed is
|
||||
The default is 1 second. The minimum allowed is
|
||||
also 1 second; a value of 0 will be updated silently
|
||||
to 1 second. For stale answers to be returned
|
||||
to 1 second. For stale answers to be returned,
|
||||
they must be enabled (either in the configuration file
|
||||
using <span class="command"><strong>stale-answer-enable</strong></span> or via
|
||||
<span class="command"><strong>rndc</strong></span>), and
|
||||
<code class="option">max-stale-ttl</code> must be set to a
|
||||
non zero value and they must not have been disabled
|
||||
by <span class="command"><strong>rndc</strong></span>.
|
||||
nonzero value.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>serial-update-method</strong></span></span></dt>
|
||||
@@ -4330,17 +4337,21 @@ options {
|
||||
<span class="command"><strong>nocookie-udp-size</strong></span> option.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>serve-stale-enable</strong></span></span></dt>
|
||||
<dt><span class="term"><span class="command"><strong>stale-answer-enable</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Enable the returning of stale answers when the
|
||||
nameservers for the zone are not answering. This
|
||||
is off by default but can be enabled/disabled via
|
||||
<span class="command"><strong>rndc server-stale on</strong></span> and
|
||||
<span class="command"><strong>rndc server-stale off</strong></span> which
|
||||
override the named.conf setting. <span class="command"><strong>rndc
|
||||
server-stale reset</strong></span> will restore control
|
||||
via named.conf.
|
||||
is off by default, but can be enabled/disabled via
|
||||
<span class="command"><strong>rndc serve-stale on</strong></span> and
|
||||
<span class="command"><strong>rndc serve-stale off</strong></span>, which
|
||||
override the <code class="filename">named.conf</code>
|
||||
setting. <span class="command"><strong>rndc serve-stale reset</strong></span>
|
||||
restores the setting to the one specified in
|
||||
<code class="filename">named.conf</code>. Note that
|
||||
reloading or reconfiguring <span class="command"><strong>named</strong></span>
|
||||
will not re-enable serving of stale records if they
|
||||
have been disabled via <span class="command"><strong>rndc</strong></span>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>nocookie-udp-size</strong></span></span></dt>
|
||||
@@ -4551,10 +4562,7 @@ options {
|
||||
<dt><span class="term"><span class="command"><strong>filter-aaaa-on-v4</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
This option is only available when
|
||||
<acronym class="acronym">BIND</acronym> 9 is compiled with the
|
||||
<strong class="userinput"><code>--enable-filter-aaaa</code></strong> option on the
|
||||
"configure" command line. It is intended to help the
|
||||
This option is intended to help the
|
||||
transition from IPv4 to IPv6 by not giving IPv6 addresses
|
||||
to DNS clients unless they have connections to the IPv6
|
||||
Internet. This is not recommended unless absolutely
|
||||
@@ -6443,7 +6451,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
server waits on an idle TCP connection before closing
|
||||
it when the client is using the EDNS TCP keepalive
|
||||
option. The default is 300 (30 seconds), the maximum
|
||||
is 1200 (two minutes), and the minimum is 1 (one tenth
|
||||
is 65535 (about 1.8 hours), and the minimum is 1 (one tenth
|
||||
of a second). Values above the maximum or below the minimum
|
||||
will be adjusted with a logged warning.
|
||||
This value may be greater than
|
||||
@@ -6462,7 +6470,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
keepalive option. This informs a client of the
|
||||
amount of time it may keep the session open.
|
||||
The default is 300 (30 seconds), the maximum is
|
||||
1200 (two minutes), and the minimum is 0, which
|
||||
65535 (about 1.8 hours), and the minimum is 0, which
|
||||
signals that the clients must close TCP connections
|
||||
immediately. Ordinarily this should be set to the
|
||||
same value as <span class="command"><strong>tcp-keepalive-timeout</strong></span>.
|
||||
@@ -8884,7 +8892,7 @@ example.com CNAME rpz-tcp-only.
|
||||
<p>
|
||||
The <span class="command"><strong>trusted-keys</strong></span> statement can contain
|
||||
multiple key entries, each consisting of the key's
|
||||
domain name, flags, protocol, algorithm, and the Base-64
|
||||
domain name, flags, protocol, algorithm, and the Base64
|
||||
representation of the key data.
|
||||
Spaces, tabs, newlines and carriage returns are ignored
|
||||
in the key data, so the configuration may be split up into
|
||||
@@ -9981,6 +9989,20 @@ view "external" {
|
||||
See caveats in <a class="xref" href="Bv9ARM.ch06.html#root_delegation_only"><span class="command"><strong>root-delegation-only</strong></span></a>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>file</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the zone's filename. In <span class="command"><strong>master</strong></span>,
|
||||
<span class="command"><strong>hint</strong></span>, and <span class="command"><strong>redirect</strong></span>
|
||||
zones which do not have <span class="command"><strong>masters</strong></span>
|
||||
defined, zone data is loaded from this file. In
|
||||
<span class="command"><strong>slave</strong></span>, <span class="command"><strong>stub</strong></span>, and
|
||||
<span class="command"><strong>redirect</strong></span> zones which do have
|
||||
<span class="command"><strong>masters</strong></span> defined, zone data is
|
||||
retrieved from another server and saved in this file.
|
||||
This option is not applicable to other zone types.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>forward</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
+144
-34
@@ -41,9 +41,10 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Windows XP No Longer Supported</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_removed">Removed Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#proto_changes">Protocol Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
@@ -96,10 +97,11 @@
|
||||
anything other than the changes you made to our software.
|
||||
</p>
|
||||
<p>
|
||||
This requirement will not affect anyone who is using BIND
|
||||
without redistributing it, nor anyone redistributing it without
|
||||
changes, therefore this change will be without consequence
|
||||
for most individuals and organizations who are using BIND.
|
||||
This requirement will not affect anyone who is using BIND, with
|
||||
or without modifications, without redistributing it, nor anyone
|
||||
redistributing it without changes. Therefore, this change will be
|
||||
without consequence for most individuals and organizations who are
|
||||
using BIND.
|
||||
</p>
|
||||
<p>
|
||||
Those unsure whether or not the license change affects their
|
||||
@@ -111,10 +113,10 @@
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="win_support"></a>Windows XP No Longer Supported</h3></div></div></div>
|
||||
<a name="win_support"></a>Legacy Windows No Longer Supported</h3></div></div></div>
|
||||
<p>
|
||||
As of BIND 9.11.2, Windows XP is no longer a supported platform for
|
||||
BIND, and Windows XP binaries are no longer available for download
|
||||
As of BIND 9.11.2, Windows XP and Windows 2003 are no longer supported
|
||||
platforms for BIND; "XP" binaries are no longer available for download
|
||||
from ISC.
|
||||
</p>
|
||||
</div>
|
||||
@@ -143,10 +145,12 @@
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The additional cache ("acache") was found not to
|
||||
significantly improve performance and has been removed;
|
||||
the <span class="command"><strong>acache-enable</strong></span> and
|
||||
<span class="command"><strong>acache-cleaning-interval</strong></span> options are now
|
||||
deprecated.
|
||||
significantly improve performance and has been removed.
|
||||
As a result, the <span class="command"><strong>acache-enable</strong></span> and
|
||||
<span class="command"><strong>acache-cleaning-interval</strong></span> options no longer
|
||||
have any effect. For backwards compatibility, BIND will
|
||||
accept their presence in a configuration file, but
|
||||
will log a warning.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
@@ -159,15 +163,16 @@
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>additional-from-cache</strong></span>
|
||||
and <span class="command"><strong>additional-from-auth</strong></span> options have been
|
||||
deprecated.
|
||||
<span class="command"><strong>minimal-responses</strong></span> is now set
|
||||
to <code class="literal">no-auth-recursive</code> by default.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>minimal-responses</strong></span> is now set
|
||||
to <code class="literal">yes</code> by default.
|
||||
The <span class="command"><strong>additional-from-cache</strong></span>
|
||||
and <span class="command"><strong>additional-from-auth</strong></span> options no longer
|
||||
have any effect. <span class="command"><strong>named</strong></span> will log a warning
|
||||
if they are set.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
@@ -342,13 +347,14 @@
|
||||
zone's validated CDS or CDNSKEY records. It can produce a
|
||||
<code class="filename">dsset</code> file suitable for input to
|
||||
<span class="command"><strong>dnssec-signzone</strong></span>, or a series of
|
||||
<span class="command"><strong>nsupdate</strong></span> to update the parent zone via dynamic
|
||||
DNS. Thanks to Tony Finch for the contribution. [RT #46090]
|
||||
<span class="command"><strong>nsupdate</strong></span> commands to update the parent zone
|
||||
via dynamic DNS. Thanks to Tony Finch for the contribution.
|
||||
[RT #46090]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>nsupdate</strong></span> and <span class="command"><strong>rndc</strong></span> now accepts
|
||||
<span class="command"><strong>nsupdate</strong></span> and <span class="command"><strong>rndc</strong></span> now accept
|
||||
command line options <span class="command"><strong>-4</strong></span> and <span class="command"><strong>-6</strong></span>
|
||||
which force using only IPv4 or only IPv6, respectively. [RT #45632]
|
||||
</p>
|
||||
@@ -492,6 +498,72 @@
|
||||
<span class="command"><strong>dnssec-settime</strong></span>, etc. [RT #46149]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dnssec-checkds -s</strong></span> specifies a file from
|
||||
which to read a DS set rather than querying the parent zone.
|
||||
This can be used to check zone correctness prior to
|
||||
publication. Thanks to Niall O'Reilly [RT #44667]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service has been shut
|
||||
down; all DLV records in the dlv.isc.org zone have been removed.
|
||||
References to the service have been removed from BIND documentation.
|
||||
Lookaside validation is no longer used by default by
|
||||
<span class="command"><strong>delv</strong></span>. The DLV key has been removed from
|
||||
<code class="filename">bind.keys</code>. Setting
|
||||
<span class="command"><strong>dnssec-lookaside</strong></span> to
|
||||
<span class="command"><strong>auto</strong></span> or to use dlv.isc.org as a trust
|
||||
anchor is now a fatal configuration error. [RT #46155]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
As noted above, the <span class="command"><strong>acache-enable</strong></span>,
|
||||
<span class="command"><strong>acache-cleaning-interval</strong></span>,
|
||||
<span class="command"><strong>additional-from-cache</strong></span> and
|
||||
<span class="command"><strong>additional-from-auth</strong></span> options are no longer
|
||||
effective and <span class="command"><strong>named</strong></span> will log a warning if
|
||||
they are set.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The use of <span class="command"><strong>dnssec-keygen</strong></span> to generate
|
||||
HMAC keys for TSIG authentication has been deprecated in favor
|
||||
of <span class="command"><strong>tsig-keygen</strong></span>. If the algorithms HMAC-MD5,
|
||||
HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384, or
|
||||
HMAC-SHA512 are specified, <span class="command"><strong>dnssec-keygen</strong></span>
|
||||
will print a warning message. These algorithms will be
|
||||
removed from <span class="command"><strong>dnssec-keygen</strong></span> entirely in
|
||||
a future release. [RT #42272]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The use of HMAC-MD5 for RNDC keys is no longer recommended.
|
||||
The default algorithm generated by <span class="command"><strong>rndc-confgen</strong></span>,
|
||||
is now HMAC-256, and a warning message will be printed if
|
||||
HMAC-MD5 is used. [RT #42272]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>isc-hmac-fixup</strong></span> command, which was created
|
||||
to address an interoperability problem in TSIG keys between
|
||||
early versions of BIND and other DNS implmentations, is now
|
||||
obsolete and has been removed. [RT #46411]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
@@ -506,13 +578,17 @@
|
||||
these algorithms must be supported in OpenSSL;
|
||||
currently they are only available in the development branch
|
||||
of OpenSSL at
|
||||
<a class="link" href="https://github.com/openssl/openssl" target="_top">https://github.com/openssl/openssl</a>.
|
||||
<a class="link" href="https://github.com/openssl/openssl" target="_top">
|
||||
https://github.com/openssl/openssl</a>.
|
||||
[RT #44696]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
EDNS KEY TAG options are verified and printed.
|
||||
When parsing DNS messages, EDNS KEY TAG options are checked
|
||||
for correctness. When printing messages (for example, in
|
||||
<span class="command"><strong>dig</strong></span>), EDNS KEY TAG options are printed
|
||||
in readable format.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
@@ -530,7 +606,7 @@
|
||||
Lookaside validation is no longer used by default by
|
||||
<span class="command"><strong>delv</strong></span>. The DLV key has been removed from
|
||||
<code class="filename">bind.keys</code>. Setting
|
||||
<span class="command"><strong>dnssec-lookaside</strong></span> set to
|
||||
<span class="command"><strong>dnssec-lookaside</strong></span> to
|
||||
<span class="command"><strong>auto</strong></span> or to use dlv.isc.org as a trust
|
||||
anchor is now a fatal configuration error. [RT #46155]
|
||||
</p>
|
||||
@@ -544,6 +620,16 @@
|
||||
are not writable by the effective user ID. [RT #46077]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Initializing keys specified in a <span class="command"><strong>managed-keys</strong></span>
|
||||
statement or by <span class="command"><strong>dnssec-validation auto;</strong></span> are
|
||||
now tagged as "initializing", until they have been updated by a
|
||||
key refresh query. If key maintenance fails to initialize,
|
||||
this will be visible when running <span class="command"><strong>rndc secroots</strong></span>.
|
||||
[RT #46267]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Previously, <span class="command"><strong>update-policy local;</strong></span> accepted
|
||||
@@ -651,15 +737,6 @@
|
||||
are now fully rolled back in the event of failure. [RT #45841]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Fixed a bug that was introduced in an earlier development
|
||||
release which caused multi-packet AXFR and IXFR messages to fail
|
||||
validation if not all packets contained TSIG records; this
|
||||
caused interoperability problems with some other DNS
|
||||
implementations. [RT #45509]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Multiple <span class="command"><strong>cookie-secret</strong></span> clauses are now
|
||||
@@ -676,6 +753,12 @@
|
||||
queries. [RT #45847]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A new statistics counter has been added to track priming
|
||||
queries. [RT #46313]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-signzone -x</strong></span> flag and the
|
||||
@@ -686,19 +769,46 @@
|
||||
contribution. [RT #45689]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Trust anchor telemetry messages, as specified by
|
||||
RFC 8145, are now logged to the
|
||||
<span class="command"><strong>trust-anchor-telemetry</strong></span> logging
|
||||
catagory.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>filter-aaaa-on-v4</strong></span> and
|
||||
<span class="command"><strong>filter-aaaa-on-v6</strong></span> options are no longer
|
||||
conditionally compiled in <span class="command"><strong>named</strong></span>. [RT #46340]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The introduction of <span class="command"><strong>libns</strong></span> caused a bug
|
||||
in which TCP client objects were not recycled after use,
|
||||
leading to unconstrained memory growth. [RT #46029]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Some header files included <isc/util.h> incorrectly as
|
||||
it pollutes with namespace with non ISC_ macros and this should
|
||||
only be done by explicitly including <isc/util.h>. This
|
||||
has been corrected. Some code may depend on <isc/util.h>
|
||||
being implicitly included via other header files. Such
|
||||
code should explicitly include <isc/util.h>.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
|
||||
+403
-445
@@ -38,121 +38,97 @@
|
||||
<dl class="toc">
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#bind9.library">BIND 9 DNS Library Support</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.4">Prerequisite</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.5">Compilation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.6">Installation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.7">Known Defects/Restrictions</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.8">The dns.conf File</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.9">Sample Applications</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.10">Library References</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.5">Installation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.6">Known Defects/Restrictions</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.7">The dns.conf File</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.8">Sample Applications</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.9">Library References</a></span></dt>
|
||||
</dl></dd>
|
||||
</dl>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="bind9.library"></a>BIND 9 DNS Library Support</h2></div></div></div>
|
||||
|
||||
<p>This version of BIND 9 "exports" its internal libraries so
|
||||
that they can be used by third-party applications more easily (we
|
||||
call them "export" libraries in this document). In addition to
|
||||
all major DNS-related APIs BIND 9 is currently using, the export
|
||||
libraries provide the following features:</p>
|
||||
|
||||
<p>
|
||||
This version of BIND 9 "exports" its internal libraries so
|
||||
that they can be used by third-party applications more easily (we
|
||||
call them "export" libraries in this document). Certain library
|
||||
functions are altered from specific BIND-only behavior to more generic
|
||||
behavior when used by other applications; to enable this generic behavior,
|
||||
the calling program initializes the libraries by calling
|
||||
<span class="command"><strong>isc_lib_register()</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
In addition to DNS-related APIs that are used within BIND 9, the
|
||||
libraries provide the following features:
|
||||
</p>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>The newly created "DNS client" module. This is a higher
|
||||
level API that provides an interface to name resolution,
|
||||
single DNS transaction with a particular server, and dynamic
|
||||
update. Regarding name resolution, it supports advanced
|
||||
features such as DNSSEC validation and caching. This module
|
||||
supports both synchronous and asynchronous mode.</p>
|
||||
<p>
|
||||
The "DNS client" module. This is a higher level API that
|
||||
provides an interface to name resolution, single DNS transaction
|
||||
with a particular server, and dynamic update. Regarding name
|
||||
resolution, it supports advanced features such as DNSSEC validation
|
||||
and caching. This module supports both synchronous and asynchronous
|
||||
mode.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>The new "IRS" (Information Retrieval System) library.
|
||||
It provides an interface to parse the traditional resolv.conf
|
||||
file and more advanced, DNS-specific configuration file for
|
||||
the rest of this package (see the description for the
|
||||
dns.conf file below).</p>
|
||||
<p>
|
||||
The "IRS" (Information Retrieval System) library. It provides an
|
||||
interface to parse the traditional <code class="filename">resolv.conf</code>
|
||||
file and more advanced, DNS-specific configuration file for the
|
||||
rest of this package (see the description for the
|
||||
<code class="filename">dns.conf</code> file below).
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>As part of the IRS library, newly implemented standard
|
||||
address-name mapping functions, getaddrinfo() and
|
||||
getnameinfo(), are provided. They use the DNSSEC-aware
|
||||
validating resolver backend, and could use other advanced
|
||||
features of the BIND 9 libraries such as caching. The
|
||||
getaddrinfo() function resolves both A and AAAA RRs
|
||||
concurrently (when the address family is unspecified).</p>
|
||||
<p>
|
||||
As part of the IRS library, the standard address-name
|
||||
mapping functions, <span class="command"><strong>getaddrinfo()</strong></span> and
|
||||
<span class="command"><strong>getnameinfo()</strong></span>, are provided. They use the
|
||||
DNSSEC-aware validating resolver backend, and could use other
|
||||
advanced features of the BIND 9 libraries such as caching. The
|
||||
<span class="command"><strong>getaddrinfo()</strong></span> function resolves both A
|
||||
and AAAA RRs concurrently when the address family is
|
||||
unspecified.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>An experimental framework to support other event
|
||||
libraries than BIND 9's internal event task system.</p>
|
||||
<p>
|
||||
An experimental framework to support other event
|
||||
libraries than BIND 9's internal event task system.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.4"></a>Prerequisite</h3></div></div></div>
|
||||
|
||||
<p>GNU make is required to build the export libraries (other
|
||||
part of BIND 9 can still be built with other types of make). In
|
||||
the reminder of this document, "make" means GNU make. Note that
|
||||
in some platforms you may need to invoke a different command name
|
||||
than "make" (e.g. "gmake") to indicate it's GNU make.</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.5"></a>Compilation</h3></div></div></div>
|
||||
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>./configure --enable-exportlib <em class="replaceable"><code>[other flags]</code></em></code></strong>
|
||||
$ <strong class="userinput"><code>make</code></strong>
|
||||
</pre>
|
||||
<p>
|
||||
This will create (in addition to usual BIND 9 programs) and a
|
||||
separate set of libraries under the lib/export directory. For
|
||||
example, <code class="filename">lib/export/dns/libdns.a</code> is the archive file of the
|
||||
export version of the BIND 9 DNS library. Sample application
|
||||
programs using the libraries will also be built under the
|
||||
lib/export/samples directory (see below).</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.6"></a>Installation</h3></div></div></div>
|
||||
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>cd lib/export</code></strong>
|
||||
<a name="id-1.13.2.5"></a>Installation</h3></div></div></div>
|
||||
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>make install</code></strong>
|
||||
</pre>
|
||||
<p>
|
||||
This will install library object files under the directory
|
||||
specified by the --with-export-libdir configure option (default:
|
||||
EPREFIX/lib/bind9), and header files under the directory
|
||||
specified by the --with-export-includedir configure option
|
||||
(default: PREFIX/include/bind9).
|
||||
Root privilege is normally required.
|
||||
"<span class="command"><strong>make install</strong></span>" at the top directory will do the
|
||||
same.
|
||||
</p>
|
||||
<p>
|
||||
To see how to build your own
|
||||
application after the installation, see
|
||||
<code class="filename">lib/export/samples/Makefile-postinstall.in</code>.</p>
|
||||
</pre>
|
||||
<p>
|
||||
Normal installation of BIND will also install library object
|
||||
and header files. Root privilege is normally required.
|
||||
</p>
|
||||
<p>
|
||||
To see how to build your own application after the installation, see
|
||||
<code class="filename">lib/samples/Makefile-postinstall.in</code>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.7"></a>Known Defects/Restrictions</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="id-1.13.2.6"></a>Known Defects/Restrictions</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
|
||||
<p>Currently, win32 is not supported for the export
|
||||
library. (Normal BIND 9 application can be built as
|
||||
before).</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>The "fixed" RRset order is not (currently) supported in
|
||||
the export library. If you want to use "fixed" RRset order
|
||||
for, e.g. <span class="command"><strong>named</strong></span> while still building the
|
||||
export library even without the fixed order support, build
|
||||
them separately:
|
||||
<p>
|
||||
The "fixed" RRset order is not (currently) supported in the export
|
||||
library. If you want to use "fixed" RRset order for, e.g.
|
||||
<span class="command"><strong>named</strong></span> while still building the export library
|
||||
even without the fixed order support, build them separately:
|
||||
</p>
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>./configure --enable-fixed-rrset <em class="replaceable"><code>[other flags, but not --enable-exportlib]</code></em></code></strong>
|
||||
@@ -162,399 +138,381 @@ $ <strong class="userinput"><code>cd lib/export</code></strong>
|
||||
$ <strong class="userinput"><code>make</code></strong>
|
||||
</pre>
|
||||
<p>
|
||||
</p>
|
||||
</li>
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>The client module and the IRS library currently do not
|
||||
support DNSSEC validation using DLV (the underlying modules
|
||||
can handle it, but there is no tunable interface to enable
|
||||
the feature).</p>
|
||||
</li>
|
||||
<p>
|
||||
RFC 5011 is not supported in the validating stub resolver of the
|
||||
export library. In fact, it is not clear whether it should: trust
|
||||
anchors would be a system-wide configuration which would be managed
|
||||
by an administrator, while the stub resolver will be used by
|
||||
ordinary applications run by a normal user.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>RFC 5011 is not supported in the validating stub
|
||||
resolver of the export library. In fact, it is not clear
|
||||
whether it should: trust anchors would be a system-wide
|
||||
configuration which would be managed by an administrator,
|
||||
while the stub resolver will be used by ordinary applications
|
||||
run by a normal user.</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>Not all common <code class="filename">/etc/resolv.conf</code>
|
||||
options are supported
|
||||
in the IRS library. The only available options in this
|
||||
version are "debug" and "ndots".</p>
|
||||
</li>
|
||||
<p>
|
||||
Not all common <code class="filename">/etc/resolv.conf</code> options are
|
||||
supported in the IRS library. The only available options in this
|
||||
version are <span class="command"><strong>debug</strong></span> and <span class="command"><strong>ndots</strong></span>.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.8"></a>The dns.conf File</h3></div></div></div>
|
||||
|
||||
<p>The IRS library supports an "advanced" configuration file
|
||||
related to the DNS library for configuration parameters that
|
||||
would be beyond the capability of the
|
||||
<code class="filename">resolv.conf</code> file.
|
||||
Specifically, it is intended to provide DNSSEC related
|
||||
configuration parameters. By default the path to this
|
||||
configuration file is <code class="filename">/etc/dns.conf</code>.
|
||||
This module is very
|
||||
experimental and the configuration syntax or library interfaces
|
||||
may change in future versions. Currently, only the
|
||||
<span class="command"><strong>trusted-keys</strong></span>
|
||||
statement is supported, whose syntax is the same as the same name
|
||||
of statement for <code class="filename">named.conf</code>. (See
|
||||
<a class="xref" href="Bv9ARM.ch06.html#trusted-keys" title="trusted-keys Statement Grammar">the section called “<span class="command"><strong>trusted-keys</strong></span> Statement Grammar”</a> for details.)</p>
|
||||
<a name="id-1.13.2.7"></a>The dns.conf File</h3></div></div></div>
|
||||
|
||||
<p>
|
||||
The IRS library supports an "advanced" configuration file related to
|
||||
the DNS library for configuration parameters that would be beyond the
|
||||
capability of the <code class="filename">resolv.conf</code> file.
|
||||
Specifically, it is intended to provide DNSSEC related configuration
|
||||
parameters. By default the path to this configuration file is
|
||||
<code class="filename">/etc/dns.conf</code>. This module is very experimental
|
||||
and the configuration syntax or library interfaces may change in
|
||||
future versions. Currently, only the <span class="command"><strong>trusted-keys</strong></span>
|
||||
statement is supported, whose syntax is the same as the same
|
||||
statement in <code class="filename">named.conf</code>. (See
|
||||
<a class="xref" href="Bv9ARM.ch06.html#trusted-keys" title="trusted-keys Statement Grammar">the section called “<span class="command"><strong>trusted-keys</strong></span> Statement Grammar”</a> for details.)
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.9"></a>Sample Applications</h3></div></div></div>
|
||||
|
||||
<p>Some sample application programs using this API are
|
||||
provided for reference. The following is a brief description of
|
||||
these applications.
|
||||
</p>
|
||||
<div class="section">
|
||||
<a name="id-1.13.2.8"></a>Sample Applications</h3></div></div></div>
|
||||
|
||||
<p>
|
||||
Some sample application programs using this API are provided for
|
||||
reference. The following is a brief description of these
|
||||
applications.
|
||||
</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.3"></a>sample: a simple stub resolver utility</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
It sends a query of a given name (of a given optional RR type) to a
|
||||
specified recursive server, and prints the result as a list of
|
||||
RRs. It can also act as a validating stub resolver if a trust
|
||||
anchor is given via a set of command line options.</p>
|
||||
<p>
|
||||
Usage: sample [options] server_address hostname
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">
|
||||
-t RRtype
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
specify the RR type of the query. The default is the A RR.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
[-a algorithm] [-e] -k keyname -K keystring
|
||||
</span></dt>
|
||||
<a name="id-1.13.2.8.3"></a>sample: a simple stub resolver utility</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Sends a query of a given name (of a given optional RR type) to a
|
||||
specified recursive server and prints the result as a list of RRs.
|
||||
It can also act as a validating stub resolver if a trust anchor is
|
||||
given via a set of command line options.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample [options] server_address hostname
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-t RRtype</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
specify a command-line DNS key to validate the answer. For
|
||||
example, to specify the following DNSKEY of example.com:
|
||||
</p>
|
||||
<p>
|
||||
specify the RR type of the query. The default is the A RR.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">[-a algorithm] [-e] -k keyname -K keystring</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
specify a command-line DNS key to validate the answer. For
|
||||
example, to specify the following DNSKEY of example.com:
|
||||
</p>
|
||||
<div class="literallayout"><p><br>
|
||||
example.com. 3600 IN DNSKEY 257 3 5 xxx<br>
|
||||
</p></div>
|
||||
example.com. 3600 IN DNSKEY 257 3 5 xxx<br>
|
||||
</p></div>
|
||||
<p>
|
||||
specify the options as follows:
|
||||
</p>
|
||||
specify the options as follows:
|
||||
</p>
|
||||
<pre class="screen">
|
||||
<strong class="userinput"><code>
|
||||
-e -k example.com -K "xxx"
|
||||
</code></strong>
|
||||
</pre>
|
||||
<strong class="userinput"><code>-e -k example.com -K "xxx"</code></strong>
|
||||
</pre>
|
||||
<p>
|
||||
-e means that this key is a zone's "key signing key" (as known
|
||||
as "secure Entry point").
|
||||
When -a is omitted rsasha1 will be used by default.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">
|
||||
-s domain:alt_server_address
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
specify a separate recursive server address for the specific
|
||||
"domain". Example: -s example.com:2001:db8::1234
|
||||
</p></dd>
|
||||
-e means that this key is a zone's "key signing key" (also known
|
||||
as "secure entry point").
|
||||
When -a is omitted rsasha1 will be used by default.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-s domain:alt_server_address</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
specify a separate recursive server address for the specific
|
||||
"domain". Example: -s example.com:2001:db8::1234
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">server_address</span></dt>
|
||||
<dd><p>
|
||||
an IP(v4/v6) address of the recursive server to which queries
|
||||
are sent.
|
||||
</p></dd>
|
||||
<dd>
|
||||
<p>
|
||||
an IP(v4/v6) address of the recursive server to which queries
|
||||
are sent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">hostname</span></dt>
|
||||
<dd><p>
|
||||
the domain name for the query
|
||||
</p></dd>
|
||||
<dd>
|
||||
<p>
|
||||
the domain name for the query
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="section">
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.4"></a>sample-async: a simple stub resolver, working asynchronously</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Similar to "sample", but accepts a list
|
||||
of (query) domain names as a separate file and resolves the names
|
||||
asynchronously.</p>
|
||||
<p>
|
||||
Usage: sample-async [-s server_address] [-t RR_type] input_file</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">
|
||||
-s server_address
|
||||
</span></dt>
|
||||
<a name="id-1.13.2.8.4"></a>sample-async: a simple stub resolver, working asynchronously</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Similar to "sample", but accepts a list
|
||||
of (query) domain names as a separate file and resolves the names
|
||||
asynchronously.</p>
|
||||
<p>
|
||||
Usage: sample-async [-s server_address] [-t RR_type] input_file</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-s server_address</span></dt>
|
||||
<dd>
|
||||
an IPv4 address of the recursive server to which queries are sent.
|
||||
(IPv6 addresses are not supported in this implementation)
|
||||
</dd>
|
||||
<dt><span class="term">
|
||||
-t RR_type
|
||||
</span></dt>
|
||||
an IPv4 address of the recursive server to which queries are sent.
|
||||
(IPv6 addresses are not supported in this implementation)
|
||||
</dd>
|
||||
<dt><span class="term">-t RR_type</span></dt>
|
||||
<dd>
|
||||
specify the RR type of the queries. The default is the A
|
||||
RR.
|
||||
</dd>
|
||||
<dt><span class="term">
|
||||
input_file
|
||||
</span></dt>
|
||||
specify the RR type of the queries. The default is the A
|
||||
RR.
|
||||
</dd>
|
||||
<dt><span class="term">input_file</span></dt>
|
||||
<dd>
|
||||
a list of domain names to be resolved. each line
|
||||
consists of a single domain name. Example:
|
||||
<div class="literallayout"><p><br>
|
||||
www.example.com<br>
|
||||
mx.example.net<br>
|
||||
ns.xxx.example<br>
|
||||
</p></div>
|
||||
</dd>
|
||||
a list of domain names to be resolved. each line consists of a
|
||||
single domain name. Example:
|
||||
<div class="literallayout"><p><br>
|
||||
www.example.com<br>
|
||||
mx.example.net<br>
|
||||
ns.xxx.example<br>
|
||||
</p></div>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="section">
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.5"></a>sample-request: a simple DNS transaction client</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
It sends a query to a specified server, and
|
||||
prints the response with minimal processing. It doesn't act as a
|
||||
"stub resolver": it stops the processing once it gets any
|
||||
response from the server, whether it's a referral or an alias
|
||||
(CNAME or DNAME) that would require further queries to get the
|
||||
ultimate answer. In other words, this utility acts as a very
|
||||
simplified <span class="command"><strong>dig</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-request [-t RRtype] server_address hostname
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">
|
||||
-t RRtype
|
||||
</span></dt>
|
||||
<a name="id-1.13.2.8.5"></a>sample-request: a simple DNS transaction client</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Sends a query to a specified server, and prints the response with
|
||||
minimal processing. It doesn't act as a "stub resolver": it stops
|
||||
the processing once it gets any response from the server, whether
|
||||
it's a referral or an alias (CNAME or DNAME) that would require
|
||||
further queries to get the ultimate answer. In other words, this
|
||||
utility acts as a very simplified <span class="command"><strong>dig</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-request [-t RRtype] server_address hostname
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-t RRtype</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
specify the RR type of
|
||||
the queries. The default is the A RR.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">
|
||||
server_address
|
||||
</span></dt>
|
||||
<p>
|
||||
specify the RR type of the queries. The default is the A RR.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">server_address</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
an IP(v4/v6)
|
||||
address of the recursive server to which the query is sent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">
|
||||
hostname
|
||||
</span></dt>
|
||||
<p>
|
||||
an IP(v4/v6) address of the recursive server to which
|
||||
the query is sent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">hostname</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
the domain name for the query
|
||||
</p>
|
||||
</dd>
|
||||
<p>
|
||||
the domain name for the query
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="section">
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.6"></a>sample-gai: getaddrinfo() and getnameinfo() test code</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
This is a test program
|
||||
to check getaddrinfo() and getnameinfo() behavior. It takes a
|
||||
host name as an argument, calls getaddrinfo() with the given host
|
||||
name, and calls getnameinfo() with the resulting IP addresses
|
||||
returned by getaddrinfo(). If the dns.conf file exists and
|
||||
defines a trust anchor, the underlying resolver will act as a
|
||||
validating resolver, and getaddrinfo()/getnameinfo() will fail
|
||||
with an EAI_INSECUREDATA error when DNSSEC validation fails.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-gai hostname
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<a name="id-1.13.2.8.6"></a>sample-gai: getaddrinfo() and getnameinfo() test code</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
This is a test program to check <span class="command"><strong>getaddrinfo()</strong></span> and
|
||||
<span class="command"><strong>getnameinfo()</strong></span> behavior. It takes a host name as an
|
||||
argument, calls <span class="command"><strong>getaddrinfo()</strong></span> with the given host
|
||||
name, and calls <span class="command"><strong>getnameinfo()</strong></span> with the resulting
|
||||
IP addresses returned by <span class="command"><strong>getaddrinfo()</strong></span>. If the
|
||||
dns.conf file exists and defines a trust anchor, the underlying
|
||||
resolver will act as a validating resolver, and
|
||||
<span class="command"><strong>getaddrinfo()</strong></span>/<span class="command"><strong>getnameinfo()</strong></span>
|
||||
will fail with an EAI_INSECUREDATA error when DNSSEC validation
|
||||
fails.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-gai hostname
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.7"></a>sample-update: a simple dynamic update client program</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
It accepts a single update command as a
|
||||
command-line argument, sends an update request message to the
|
||||
authoritative server, and shows the response from the server. In
|
||||
other words, this is a simplified <span class="command"><strong>nsupdate</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-update [options] (add|delete) "update data"
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">
|
||||
-a auth_server
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
An IP address of the authoritative server that has authority
|
||||
for the zone containing the update name. This should normally
|
||||
be the primary authoritative server that accepts dynamic
|
||||
updates. It can also be a secondary server that is configured
|
||||
to forward update requests to the primary server.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-k keyfile
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
A TSIG key file to secure the update transaction. The keyfile
|
||||
format is the same as that for the nsupdate utility.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-p prerequisite
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
A prerequisite for the update (only one prerequisite can be
|
||||
specified). The prerequisite format is the same as that is
|
||||
accepted by the nsupdate utility.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-r recursive_server
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
An IP address of a recursive server that this utility will
|
||||
use. A recursive server may be necessary to identify the
|
||||
authoritative server address to which the update request is
|
||||
sent.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-z zonename
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
The domain name of the zone that contains
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
(add|delete)
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Specify the type of update operation. Either "add" or "delete"
|
||||
must be specified.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
"update data"
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Specify the data to be updated. A typical example of the data
|
||||
would look like "name TTL RRtype RDATA".
|
||||
</p></dd>
|
||||
<a name="id-1.13.2.8.7"></a>sample-update: a simple dynamic update client program</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Accepts a single update command as a command-line argument, sends
|
||||
an update request message to the authoritative server, and shows
|
||||
the response from the server. In other words, this is a simplified
|
||||
<span class="command"><strong>nsupdate</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
Usage: sample-update [options] (add|delete) "update data"
|
||||
</p>
|
||||
<p>
|
||||
Options and Arguments:
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-a auth_server</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
An IP address of the authoritative server that has authority
|
||||
for the zone containing the update name. This should
|
||||
normally be the primary authoritative server that accepts
|
||||
dynamic updates. It can also be a secondary server that is
|
||||
configured to forward update requests to the primary server.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-k keyfile</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A TSIG key file to secure the update transaction. The
|
||||
keyfile format is the same as that for the nsupdate utility.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-p prerequisite</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A prerequisite for the update (only one prerequisite can be
|
||||
specified). The prerequisite format is the same as that is
|
||||
accepted by the nsupdate utility.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-r recursive_server</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
An IP address of a recursive server that this utility will
|
||||
use. A recursive server may be necessary to identify the
|
||||
authoritative server address to which the update request is
|
||||
sent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-z zonename</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The domain name of the zone that contains
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">(add|delete)</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specify the type of update operation. Either "add" or
|
||||
"delete" must be specified.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">"update data"</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specify the data to be updated. A typical example of the
|
||||
data would look like "name TTL RRtype RDATA".
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
|
||||
<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
|
||||
<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
|
||||
<h3 class="title">Note</h3>
|
||||
<p>
|
||||
In practice, either -a or -r must be specified. Others can
|
||||
be optional; the underlying library routine tries to identify the
|
||||
appropriate server and the zone name for the update.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<p>
|
||||
Examples: assuming the primary authoritative server of the
|
||||
dynamic.example.com zone has an IPv6 address 2001:db8::1234,
|
||||
</p>
|
||||
<pre class="screen">
|
||||
<p>
|
||||
In practice, either -a or -r must be specified. Others can be
|
||||
optional; the underlying library routine tries to identify the
|
||||
appropriate server and the zone name for the update.
|
||||
</p>
|
||||
</div>
|
||||
<p>
|
||||
Examples: assuming the primary authoritative server of the
|
||||
dynamic.example.com zone has an IPv6 address 2001:db8::1234,
|
||||
</p>
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mmmm.key add "foo.dynamic.example.com 30 IN A 192.168.2.1"</code></strong></pre>
|
||||
<p>
|
||||
adds an A RR for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
<pre class="screen">
|
||||
<p>
|
||||
adds an A RR for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com 30 IN A"</code></strong></pre>
|
||||
<p>
|
||||
removes all A RRs for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
<pre class="screen">
|
||||
<p>
|
||||
removes all A RRs for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
<pre class="screen">
|
||||
$ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com"</code></strong></pre>
|
||||
<p>
|
||||
removes all RRs for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<p>
|
||||
removes all RRs for foo.dynamic.example.com using the given key.
|
||||
</p>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="id-1.13.2.9.8"></a>nsprobe: domain/name server checker in terms of RFC 4074</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
It checks a set
|
||||
of domains to see the name servers of the domains behave
|
||||
correctly in terms of RFC 4074. This is included in the set of
|
||||
sample programs to show how the export library can be used in a
|
||||
DNS-related application.
|
||||
</p>
|
||||
<p>
|
||||
Usage: nsprobe [-d] [-v [-v...]] [-c cache_address] [input_file]
|
||||
</p>
|
||||
<p>
|
||||
Options
|
||||
</p>
|
||||
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">
|
||||
-d
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
run in the "debug" mode. with this option nsprobe will dump
|
||||
every RRs it receives.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-v
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
increase verbosity of other normal log messages. This can be
|
||||
specified multiple times
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
-c cache_address
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
specify an IP address of a recursive (caching) name server.
|
||||
nsprobe uses this server to get the NS RRset of each domain and
|
||||
the A and/or AAAA RRsets for the name servers. The default
|
||||
value is 127.0.0.1.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
input_file
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
a file name containing a list of domain (zone) names to be
|
||||
probed. when omitted the standard input will be used. Each
|
||||
line of the input file specifies a single domain name such as
|
||||
"example.com". In general this domain name must be the apex
|
||||
name of some DNS zone (unlike normal "host names" such as
|
||||
"www.example.com"). nsprobe first identifies the NS RRsets for
|
||||
the given domain name, and sends A and AAAA queries to these
|
||||
servers for some "widely used" names under the zone;
|
||||
specifically, adding "www" and "ftp" to the zone name.
|
||||
</p></dd>
|
||||
<a name="id-1.13.2.8.8"></a>nsprobe: domain/name server checker in terms of RFC 4074</h4></div></div></div>
|
||||
|
||||
<p>
|
||||
Checks a set of domains to see the name servers of the domains
|
||||
behave correctly in terms of RFC 4074. This is included in the set
|
||||
of sample programs to show how the export library can be used in a
|
||||
DNS-related application.
|
||||
</p>
|
||||
<p>
|
||||
Usage: nsprobe [-d] [-v [-v...]] [-c cache_address] [input_file]
|
||||
</p>
|
||||
<p>
|
||||
Options
|
||||
</p>
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-d</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Run in "debug" mode. With this option nsprobe will dump
|
||||
every RRs it receives.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-v</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Increase verbosity of other normal log messages. This can be
|
||||
specified multiple times.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-c cache_address</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specify an IP address of a recursive (caching) name server.
|
||||
nsprobe uses this server to get the NS RRset of each domain
|
||||
and the A and/or AAAA RRsets for the name servers. The
|
||||
default value is 127.0.0.1.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">input_file</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A file name containing a list of domain (zone) names to be
|
||||
probed. when omitted the standard input will be used. Each
|
||||
line of the input file specifies a single domain name such as
|
||||
"example.com". In general this domain name must be the apex
|
||||
name of some DNS zone (unlike normal "host names" such as
|
||||
"www.example.com"). nsprobe first identifies the NS RRsets
|
||||
for the given domain name, and sends A and AAAA queries to
|
||||
these servers for some "widely used" names under the zone;
|
||||
specifically, adding "www" and "ftp" to the zone name.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.13.2.10"></a>Library References</h3></div></div></div>
|
||||
|
||||
<p>As of this writing, there is no formal "manual" of the
|
||||
libraries, except this document, header files (some of them
|
||||
provide pretty detailed explanations), and sample application
|
||||
programs.</p>
|
||||
<a name="id-1.13.2.9"></a>Library References</h3></div></div></div>
|
||||
|
||||
<p>
|
||||
As of this writing, there is no formal "manual" for the libraries,
|
||||
except this document, header files (some of which provide pretty
|
||||
detailed explanations), and sample application programs.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -97,9 +97,6 @@
|
||||
<span class="refentrytitle"><a href="man.host.html">host</a></span><span class="refpurpose"> — DNS lookup utility</span>
|
||||
</dt>
|
||||
<dt>
|
||||
<span class="refentrytitle"><a href="man.isc-hmac-fixup.html"><span class="application">isc-hmac-fixup</span></a></span><span class="refpurpose"> — fixes HMAC keys generated by older versions of BIND</span>
|
||||
</dt>
|
||||
<dt>
|
||||
<span class="refentrytitle"><a href="man.mdig.html"><span class="application">mdig</span></a></span><span class="refpurpose"> — DNS pipelined lookup utility</span>
|
||||
</dt>
|
||||
<dt>
|
||||
@@ -192,7 +189,6 @@
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
</div>
|
||||
|
||||
+7
-11
@@ -241,9 +241,10 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Windows XP No Longer Supported</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_removed">Removed Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#proto_changes">Protocol Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
@@ -266,13 +267,11 @@
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#bind9.library">BIND 9 DNS Library Support</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.4">Prerequisite</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.5">Compilation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.6">Installation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.7">Known Defects/Restrictions</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.8">The dns.conf File</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.9">Sample Applications</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.10">Library References</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.5">Installation</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.6">Known Defects/Restrictions</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.7">The dns.conf File</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.8">Sample Applications</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch12.html#id-1.13.2.9">Library References</a></span></dt>
|
||||
</dl></dd>
|
||||
</dl></dd>
|
||||
<dt><span class="reference"><a href="Bv9ARM.ch13.html">I. Manual pages</a></span></dt>
|
||||
@@ -335,9 +334,6 @@
|
||||
<span class="refentrytitle"><a href="man.host.html">host</a></span><span class="refpurpose"> — DNS lookup utility</span>
|
||||
</dt>
|
||||
<dt>
|
||||
<span class="refentrytitle"><a href="man.isc-hmac-fixup.html"><span class="application">isc-hmac-fixup</span></a></span><span class="refpurpose"> — fixes HMAC keys generated by older versions of BIND</span>
|
||||
</dt>
|
||||
<dt>
|
||||
<span class="refentrytitle"><a href="man.mdig.html"><span class="application">mdig</span></a></span><span class="refpurpose"> — DNS pipelined lookup utility</span>
|
||||
</dt>
|
||||
<dt>
|
||||
|
||||
+485
-493
File diff suppressed because it is too large
Load Diff
@@ -51,20 +51,13 @@
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-checkds</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-s <em class="replaceable"><code>file</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-dsfromkey</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
@@ -97,6 +90,14 @@
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies a prepared dsset file, such as would be generated
|
||||
by <span class="command"><strong>dnssec-signzone</strong></span>, to use as a source for
|
||||
the DS RRset instead of querying the parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
@@ -121,12 +121,19 @@
|
||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||
or HMAC-SHA512; specifying any of these algorithms will
|
||||
automatically set the <code class="option">-T KEY</code> option as well.
|
||||
(Note: <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys in a
|
||||
more useful format than <span class="command"><strong>dnssec-keygen</strong></span>.)
|
||||
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||
specifying this value will automatically set the
|
||||
<code class="option">-T KEY</code> option as well.
|
||||
</p>
|
||||
<p>
|
||||
TSIG keys can also by generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||
however, that <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys
|
||||
in a more useful format. These algorithms have been deprecated
|
||||
in <span class="command"><strong>dnssec-keygen</strong></span>, and will be removed in a
|
||||
future release.
|
||||
</p>
|
||||
<p>
|
||||
These values are case insensitive. In some cases, abbreviations
|
||||
@@ -137,8 +144,8 @@
|
||||
</p>
|
||||
<p>
|
||||
As of BIND 9.12.0, this option is mandatory except when using
|
||||
the <code class="option">-S</code> option (which copies the algorithm from
|
||||
the predecessor key). Previously, the default for newly
|
||||
the <code class="option">-S</code> option, which copies the algorithm from
|
||||
the predecessor key. Previously, the default for newly
|
||||
generated keys was RSASHA1.
|
||||
</p>
|
||||
</dd>
|
||||
|
||||
@@ -537,6 +537,22 @@
|
||||
zone, regardless of any other metadata.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync publication date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
created.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync deletion date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
removed.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</dd>
|
||||
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
|
||||
<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
|
||||
<link rel="prev" href="man.genrandom.html" title="genrandom">
|
||||
<link rel="next" href="man.isc-hmac-fixup.html" title="isc-hmac-fixup">
|
||||
<link rel="next" href="man.mdig.html" title="mdig">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
|
||||
<div class="navheader">
|
||||
@@ -24,7 +24,7 @@
|
||||
<td width="20%" align="left">
|
||||
<a accesskey="p" href="man.genrandom.html">Prev</a> </td>
|
||||
<th width="60%" align="center">Manual pages</th>
|
||||
<td width="20%" align="right"> <a accesskey="n" href="man.isc-hmac-fixup.html">Next</a>
|
||||
<td width="20%" align="right"> <a accesskey="n" href="man.mdig.html">Next</a>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
@@ -363,14 +363,14 @@
|
||||
<td width="40%" align="left">
|
||||
<a accesskey="p" href="man.genrandom.html">Prev</a> </td>
|
||||
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
|
||||
<td width="40%" align="right"> <a accesskey="n" href="man.isc-hmac-fixup.html">Next</a>
|
||||
<td width="40%" align="right"> <a accesskey="n" href="man.mdig.html">Next</a>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width="40%" align="left" valign="top">
|
||||
<span class="application">genrandom</span> </td>
|
||||
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
|
||||
<td width="40%" align="right" valign="top"> <span class="application">isc-hmac-fixup</span>
|
||||
<td width="40%" align="right" valign="top"> <span class="application">mdig</span>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user