Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b9e33d9cce | ||
|
|
e94465e304 | ||
|
|
8b9e2015f3 | ||
|
|
f64da6cabb | ||
|
|
6954eceb80 | ||
|
|
378774821a | ||
|
|
40562e37ee | ||
|
|
e7256edf67 | ||
|
|
7edff5d2bb | ||
|
|
5fd05a6d88 | ||
|
|
3009554a0b | ||
|
|
7545b00842 | ||
|
|
396772811a | ||
|
|
c0494994f0 | ||
|
|
1970f078cf | ||
|
|
376d5996a1 | ||
|
|
65a483106e | ||
|
|
5f308740df | ||
|
|
a8c1bfd673 | ||
|
|
18c7fa2f93 | ||
|
|
3f8c9d92af | ||
|
|
393135d693 | ||
|
|
82354deeb1 | ||
|
|
c22b540e4c | ||
|
|
d92d70ac5d | ||
|
|
00ff44c7c2 | ||
|
|
2f13e0ef98 | ||
|
|
a80dc538bd | ||
|
|
40a90fbf89 | ||
|
|
31b6ae485e | ||
|
|
19f6a63184 | ||
|
|
14e9925868 | ||
|
|
7bc5d7f5e8 | ||
|
|
1dc8208a89 | ||
|
|
6ead410268 | ||
|
|
a573b93b46 | ||
|
|
165df18f75 | ||
|
|
9bb32395b2 | ||
|
|
8993ecd06a | ||
|
|
2f4e0e5a81 | ||
|
|
78e1d7cdde | ||
|
|
ba613d22bf | ||
|
|
858228febe | ||
|
|
5b2b9340fe | ||
|
|
6035d557c4 | ||
|
|
900215654b | ||
|
|
445cabb392 | ||
|
|
a197094d76 | ||
|
|
f975d0acaa | ||
|
|
656eed7c9b | ||
|
|
7a0188774f | ||
|
|
bcce55197a | ||
|
|
3bfc28a0d0 | ||
|
|
6f5cc4206d | ||
|
|
e2f9dcfd86 | ||
|
|
31975d85de | ||
|
|
3d905e0533 | ||
|
|
3def40b01b | ||
|
|
04934b28ea | ||
|
|
8c1b8dd55d | ||
|
|
6bbbf12936 | ||
|
|
9eb5aa40aa | ||
|
|
f581ac4726 | ||
|
|
c0e3e1fe44 | ||
|
|
312c84c73a | ||
|
|
b231ddc65d | ||
|
|
0cba7ca6af | ||
|
|
f4b2356359 | ||
|
|
a1aa42b9cd | ||
|
|
c999531fa4 | ||
|
|
00827f59d2 | ||
|
|
e03e455cd5 | ||
|
|
a1a5145867 | ||
|
|
4034b098d8 | ||
|
|
27bf48327c | ||
|
|
c652213857 | ||
|
|
5b1e929b8b | ||
|
|
a41e41d6a4 | ||
|
|
0e29543a3d | ||
|
|
f13c1c09e9 | ||
|
|
e3d9aafff0 | ||
|
|
23b81977fe | ||
|
|
2a390b2537 | ||
|
|
e6801bf89e | ||
|
|
3300f6aeda | ||
|
|
b819a478b7 | ||
|
|
7e1df5182c | ||
|
|
72ddd51e74 | ||
|
|
c3d0ccdc8f | ||
|
|
f305a705c4 | ||
|
|
490c321e25 | ||
|
|
e7b53943fe | ||
|
|
8d23105547 | ||
|
|
95dce4e68c | ||
|
|
9bb007fd2d | ||
|
|
3b5718a8c9 | ||
|
|
40298d8bee | ||
|
|
92bbc9914c | ||
|
|
4359be18f4 | ||
|
|
0698ad8503 | ||
|
|
9b3fc207df | ||
|
|
db15f78ad7 | ||
|
|
ff30290b48 | ||
|
|
7bbb034952 | ||
|
|
a51352c4a4 | ||
|
|
37039792cb | ||
|
|
41b1a98545 | ||
|
|
dd61c4ad3e | ||
|
|
85bd975d3d | ||
|
|
ee42f734d5 | ||
|
|
6e02359034 | ||
|
|
0ed0c4b1a5 | ||
|
|
facf811847 | ||
|
|
4ae8f28711 | ||
|
|
2658ebbcba | ||
|
|
45d4d62a0c | ||
|
|
63d83632d7 | ||
|
|
40e1e659b6 | ||
|
|
f5e1b555c5 | ||
|
|
4e2ba60f3c | ||
|
|
625f656aa8 | ||
|
|
278b68ced5 | ||
|
|
c6c1193e39 | ||
|
|
8f532a13cb | ||
|
|
497f3f913e | ||
|
|
01139573bc | ||
|
|
4cbaa08602 | ||
|
|
c9f8165a06 | ||
|
|
1d57d460d4 | ||
|
|
959d294067 | ||
|
|
864bc6b56e | ||
|
|
06049b1c6c | ||
|
|
3b4f23cdbf | ||
|
|
08f18efba2 | ||
|
|
f808b5e0d2 | ||
|
|
a4bf990ed7 | ||
|
|
c341e524dc | ||
|
|
63270d33f1 | ||
|
|
09baa0cbb1 | ||
|
|
87387d8a41 | ||
|
|
5c76f3664c | ||
|
|
5b69d3da83 | ||
|
|
89d1777560 | ||
|
|
d3e8e9bdbb | ||
|
|
3056d6f532 | ||
|
|
96ebb55501 | ||
|
|
8e2a8a3855 | ||
|
|
81570e84a2 | ||
|
|
6a59e53a69 | ||
|
|
2bbca9594f | ||
|
|
eb2ef7b53e | ||
|
|
aebdc6cd7d | ||
|
|
910a01550a | ||
|
|
65314b0fd8 | ||
|
|
80739779fc | ||
|
|
a53e03205a | ||
|
|
ea055a82cd | ||
|
|
89c95e7141 | ||
|
|
79e78994d0 | ||
|
|
21761bfe79 | ||
|
|
969d923536 | ||
|
|
6b8e4d6e69 | ||
|
|
a94d68ce43 | ||
|
|
7810817b71 | ||
|
|
b49042a6a5 | ||
|
|
b1042e011c | ||
|
|
0207f6ff9e | ||
|
|
65f8b51893 | ||
|
|
5bead588b7 | ||
|
|
3f2e5f840a | ||
|
|
c9438ee2e0 | ||
|
|
a59d687db4 | ||
|
|
89636d8f30 | ||
|
|
34ee1cdb56 | ||
|
|
6853af8fc5 | ||
|
|
2e662cf514 | ||
|
|
321b8429f5 | ||
|
|
172aa40e8f | ||
|
|
0fc861dea9 | ||
|
|
b284857f96 | ||
|
|
807ad469fe | ||
|
|
5ff48dca18 | ||
|
|
66258ca349 | ||
|
|
2115e319ba | ||
|
|
429a43b720 | ||
|
|
bf9b90f977 | ||
|
|
d8442c1a15 | ||
|
|
9e5439a6d8 | ||
|
|
0fab171196 | ||
|
|
583e355951 | ||
|
|
fe79e2efbf | ||
|
|
b7b8e298f6 | ||
|
|
d99d5249b7 | ||
|
|
208abf3fc7 | ||
|
|
6e87e723a4 | ||
|
|
4f554c2445 | ||
|
|
30419509dd | ||
|
|
2361003a88 | ||
|
|
94d96121b9 | ||
|
|
31275c3f39 | ||
|
|
d63943f063 | ||
|
|
ebf5459c44 | ||
|
|
9d47a267c4 |
@@ -1,3 +1,195 @@
|
||||
4830. [bug] Failure to configure ATF when requested did not cause
|
||||
an error in top-level configure script. [RT #46655]
|
||||
|
||||
4829. [bug] isc_heap_delete did not zero the index value when
|
||||
the heap was created with a callback to do that.
|
||||
[RT #46709]
|
||||
|
||||
4828. [bug] Do not use thread-local storage for storing LMDB reader
|
||||
locktable slots. [RT #46556]
|
||||
|
||||
4827. [misc] Add a precommit check script util/checklibs.sh
|
||||
[RT #46215]
|
||||
|
||||
4826. [cleanup] Prevent potential build failures in bin/confgen/ and
|
||||
bin/named/ when using parallel make. [RT #46648]
|
||||
|
||||
4825. [bug] Prevent a bogus "error during managed-keys processing
|
||||
(no more)" warning from being logged. [RT #46645]
|
||||
|
||||
4824. [port] Add iOS hooks to dig. [RT #42011]
|
||||
|
||||
4823. [test] Refactor reclimit system test to improve its
|
||||
reliability and speed. [RT #46632]
|
||||
|
||||
4822. [bug] Use resign_sooner in dns_db_setsigningtime. [RT #46473]
|
||||
|
||||
4821. [bug] When resigning ensure that the SOA's expire time is
|
||||
always later that the resigning time of other records.
|
||||
[RT #46473]
|
||||
|
||||
4820. [bug] dns_db_subtractrdataset should transfer the resigning
|
||||
information to the new header. [RT #46473]
|
||||
|
||||
4819. [bug] Fully backout the transaction when adding a RRset
|
||||
to the resigning / removal heaps fails. [RT #46473]
|
||||
|
||||
4818. [test] The logfileconfig system test could intermittently
|
||||
report false negatives on some platforms. [RT #46615]
|
||||
|
||||
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
|
||||
[RT #45433]
|
||||
|
||||
4816. [bug] Don't use a common array for storing EDNS options
|
||||
in DiG as it could fill up. [RT #45611]
|
||||
|
||||
4815. [bug] rbt_test.c:insert_and_delete needed to call
|
||||
dns_rbt_addnode instead of dns_rbt_addname. [RT #46553]
|
||||
|
||||
4814. [cleanup] Use AS_HELP_STRING for consistent help text. [RT #46521]
|
||||
|
||||
4813. [bug] Address potential read after free errors from
|
||||
query_synthnodata, query_synthwildcard and
|
||||
query_synthnxdomain. [RT #46547]
|
||||
|
||||
4812. [bug] Minor improvements to stability and consistency of code
|
||||
handling managed keys. [RT #46468]
|
||||
|
||||
4811. [bug] Revert api changes to use <isc/buffer.h> inline
|
||||
macros. Provide a alternative mechanism to turn
|
||||
on the use of inline macros when building BIND.
|
||||
[RT #46520]
|
||||
|
||||
4810. [test] The chain system test failed if the IPv6 interfaces
|
||||
were not configured. [RT #46508]
|
||||
|
||||
--- 9.12.0b2 released ---
|
||||
|
||||
4809. [port] Check at configure time whether -latomic is needed
|
||||
for stdatomic.h. [RT #46324]
|
||||
|
||||
4808. [bug] Properly test for zlib.h. [RT #46504]
|
||||
|
||||
4807. [cleanup] isc_rng_randombytes() returns a specified number of
|
||||
bytes from the PRNG; this is now used instead of
|
||||
calling isc_rng_random() multiple times. [RT #46230]
|
||||
|
||||
4806. [func] Log messages related to loading of zones are now
|
||||
directed to the "zoneload" logging category.
|
||||
[RT #41640]
|
||||
|
||||
4805. [bug] TCP4Active and TCP6Active weren't being updated
|
||||
correctly. [RT #46454]
|
||||
|
||||
4804. [port] win32: access() does not work on directories as
|
||||
required by POSIX. Supply a alternative in
|
||||
isc_file_isdirwritable. [RT #46394]
|
||||
|
||||
4803. [placeholder]
|
||||
|
||||
4802. [test] Refactor mkeys system test to make it quicker and more
|
||||
reliable. [RT #45293]
|
||||
|
||||
4801. [func] 'dnssec-lookaside auto;' and 'dnssec-lookaside .
|
||||
trust-anchor dlv.isc.org;' now elicit warnings rather
|
||||
than being fatal configuration errors. [RT #46410]
|
||||
|
||||
4800. [bug] When processing delzone, write one zone config per
|
||||
line to the NZF. [RT #46323]
|
||||
|
||||
4799. [cleanup] Improve clarity of keytable unit tests. [RT #46407]
|
||||
|
||||
4798. [func] Keys specified in "managed-keys" statements
|
||||
are tagged as "initializing" until they have been
|
||||
updated by a key refresh query. If initialization
|
||||
fails it will be visible from "rndc secroots".
|
||||
[RT #46267]
|
||||
|
||||
4797. [func] Removed "isc-hmac-fixup", as the versions of BIND that
|
||||
had the bug it worked around are long past end of
|
||||
life. [RT #46411]
|
||||
|
||||
4796. [bug] Increase the maximum configurable TCP keepalive
|
||||
timeout to 65535. [RT #44710]
|
||||
|
||||
4795. [func] A new statistics counter has been added to track
|
||||
priming queries. [RT #46313]
|
||||
|
||||
4794. [func] "dnssec-checkds -s" specifies a file from which
|
||||
to read a DS set rather than querying the parent.
|
||||
[RT #44667]
|
||||
|
||||
4793. [bug] nsupdate -[46] could overflow the array of server
|
||||
addresses. [RT #46402]
|
||||
|
||||
4792. [bug] Fix map file header correctness check. [RT #38418]
|
||||
|
||||
4791. [doc] Fixed outdated documentation about export libraries.
|
||||
[RT #46341]
|
||||
|
||||
4790. [bug] nsupdate could trigger a require when sending a
|
||||
update to the second address of the server.
|
||||
[RT #45731]
|
||||
|
||||
4789. [cleanup] Check writability of new-zones-directory. [RT #46308]
|
||||
|
||||
4788. [cleanup] When using "update-policy local", log a warning
|
||||
when an update matching the session key is received
|
||||
from a remote host. [RT #46213]
|
||||
|
||||
4787. [cleanup] Turn nsec3param_salt_totext() into a public function,
|
||||
dns_nsec3param_salttotext(), and add unit tests for it.
|
||||
[RT #46289]
|
||||
|
||||
4786. [func] The "filter-aaaa-on-v4" and "filter-aaaa-on-v6"
|
||||
options are no longer conditionally compiled.
|
||||
[RT #46340]
|
||||
|
||||
4785. [func] The hmac-md5 algorithm is no longer recommended for
|
||||
use with RNDC keys. The default in rndc-confgen
|
||||
is now hmac-sha256. [RT #42272]
|
||||
|
||||
4784. [func] The use of dnssec-keygen to generate HMAC keys is
|
||||
deprecated in favor of tsig-keygen. dnssec-keygen
|
||||
will print a warning when used for this purpose.
|
||||
All HMAC algorithms will be removed from
|
||||
dnssec-keygen in a future release. [RT #42272]
|
||||
|
||||
4783. [test] dnssec: 'check that NOTIFY is sent at the end of
|
||||
NSEC3 chain generation failed' required more time
|
||||
on some machines for the IXFR to complete. [RT #46388]
|
||||
|
||||
4782. [test] dnssec: 'checking positive and negative validation
|
||||
with negative trust anchors' required more time to
|
||||
complete on some machines. [RT #46386]
|
||||
|
||||
4781. [maint] B.ROOT-SERVERS.NET is now 199.9.14.201. [RT #45889]
|
||||
|
||||
4780. [bug] When answering ANY queries, don't include the NS
|
||||
RRset in the authority section if it was already
|
||||
in the answer section. [RT #44543]
|
||||
|
||||
4779. [bug] Expire NTA at the start of the second. Don't update
|
||||
the expiry value if the record has already expired
|
||||
after a successful check. [RT #46368]
|
||||
|
||||
4778. [test] Improve synth-from-dnssec testing. [RT #46352]
|
||||
|
||||
4777. [cleanup] Removed a redundant call to configure_view_acl().
|
||||
[RT #46369]
|
||||
|
||||
4776. [bug] Improve portability of ht_test. [RT #46333]
|
||||
|
||||
4775. [bug] Address Coverity warnings in ht_test.c and mem_test.c
|
||||
[RT #46281]
|
||||
|
||||
4774. [bug] <isc/util.h> was incorrectly included in several
|
||||
header files. [RT #46311]
|
||||
|
||||
4773. [doc] Fixed generating Doxygen documentation for functions
|
||||
annotated using certain macros. Miscellaneous
|
||||
Doxygen-related cleanups. [RT #46276]
|
||||
|
||||
--- 9.12.0b1 released ---
|
||||
|
||||
4772. [test] Expanded unit testing framework for libns, using
|
||||
@@ -104,7 +296,7 @@
|
||||
- Removed DLV key from bind.keys
|
||||
- No longer use ISC DLV by default in delv
|
||||
- "dnssec-lookaside auto" and configuration of
|
||||
"dnssec-lookaide" with dlv.isc.org as trust
|
||||
"dnssec-lookaide" with dlv.isc.org as the trust
|
||||
anchor are both now fatal errors.
|
||||
[RT #46155]
|
||||
|
||||
@@ -244,8 +436,8 @@
|
||||
4713. [func] Added support for the DNS Response Policy Service
|
||||
(DNSRPS) API, which allows named to use an external
|
||||
response policy daemon when built with
|
||||
"configure --enable-dnsrps". Thanks to Vernon
|
||||
Schryver and Farsight Security. [RT #43376]
|
||||
"configure --enable-dnsrps". Thanks to Farsight
|
||||
Security. [RT #43376]
|
||||
|
||||
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
||||
search domain when retrying with TCP. [RT #45547]
|
||||
|
||||
@@ -19,4 +19,12 @@ Setting Description
|
||||
named-checkzone
|
||||
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
||||
rather than ${localstatedir}/run/named/
|
||||
Increase the maximum number of configurable
|
||||
-DNS_RPZ_MAX_ZONES=64 response policy zones from 32 to 64; this is the
|
||||
highest possible setting
|
||||
Disable the use of inline functions to implement
|
||||
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
||||
may be useful when debugging
|
||||
-DISC_HEAP_CHECK Test heap consistency after every heap
|
||||
operation; used when debugging
|
||||
|
||||
|
||||
@@ -20,3 +20,6 @@ Some of these settings are:
|
||||
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
||||
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
||||
|`-DISC_HEAP_CHECK`|Test heap consistency after every heap operation; used when debugging|
|
||||
|
||||
@@ -56,12 +56,12 @@ General bug reports can be sent to bind9-bugs@isc.org.
|
||||
|
||||
Feature requests can be sent to bind-suggest@isc.org.
|
||||
|
||||
Please note that, while ISC's ticketing system is not currently publicly
|
||||
readable, this may change in the future. Please do not include information
|
||||
in bug reports that you consider to be confidential. For example, when
|
||||
sending the contents of your configuration file, it is advisable to
|
||||
obscure key secrets; this can be done automatically by using
|
||||
named-checkconf -px.
|
||||
Please note that, while tickets submitted to ISC's ticketing system are
|
||||
not initially publicly readable by default, they can be made publicly
|
||||
acessible afterward. Please do not include information in bug reports that
|
||||
you consider to be confidential. In particular, when sending the contents
|
||||
of your configuration file, it is advisable to obscure key secrets: this
|
||||
can be done automatically by using named-checkconf -px.
|
||||
|
||||
Professional support and training for BIND are available from ISC at
|
||||
https://www.isc.org/support.
|
||||
@@ -75,8 +75,9 @@ mailman/listinfo/bind-workers.
|
||||
|
||||
Contributing to BIND
|
||||
|
||||
A public git repository for BIND is maintained at http://www.isc.org/git/,
|
||||
and also on Github at https://github.com/isc-projects.
|
||||
ISC maintains a public git repository for BIND; details can be found at
|
||||
http://www.isc.org/git/, and also on Github at https://github.com/
|
||||
isc-projects.
|
||||
|
||||
Information for BIND contributors can be found in the following files: -
|
||||
General information: doc/dev/contrib.md - BIND 9 code style: doc/dev/
|
||||
@@ -103,10 +104,8 @@ include:
|
||||
* Cached, validated NSEC and other records can now be used to synthesize
|
||||
NXDOMAIN responses.
|
||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||
* Setting max-journal-size default now limits the size of journal files
|
||||
to twice the size of the zone.
|
||||
* The query handling code has been substantially refactored for improved
|
||||
readability, maintainability and testability .
|
||||
* Setting 'max-journal-size default' now limits the size of journal
|
||||
files to twice the size of the zone.
|
||||
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
||||
message.
|
||||
* dnstap output files can now be configured to roll automatically when
|
||||
@@ -115,10 +114,14 @@ include:
|
||||
ISO 8601 (UTC) formats.
|
||||
* Logging channels and dnstap output files can now be configured to use
|
||||
a timestamp as the suffix when rolling to a new file.
|
||||
* named-checkconf -l lists zones found in named.conf.
|
||||
* 'named-checkconf -l' lists zones found in named.conf.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
data for zones added by rndc addzone is stored.
|
||||
* The default key algorithm in rndc-confgen is now hmac-sha256.
|
||||
* filter-aaaa-on-v4 and filter-aaaa-on-v6 options are now available by
|
||||
default without a configure option.
|
||||
* The obsolete isc-hmac-fixup command has been removed.
|
||||
|
||||
Building BIND
|
||||
|
||||
@@ -128,8 +131,8 @@ on many versions of Linux and UNIX, including RedHat, Fedora, Debian,
|
||||
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
||||
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||
win32utils/readme1st.txt for details on building for Windows systems.
|
||||
BIND is also available for Windows 2008 and higher. See win32utils/
|
||||
readme1st.txt for details on building for Windows systems.
|
||||
|
||||
To build on a UNIX or Linux system, use:
|
||||
|
||||
@@ -189,10 +192,11 @@ smaller systems.
|
||||
For the server to support DNSSEC, you need to build it with crypto
|
||||
support. To use OpenSSL, you should have OpenSSL 1.0.2e or newer
|
||||
installed. If the OpenSSL library is installed in a nonstandard location,
|
||||
specify the prefix using "--with-openssl=/prefix" on the configure command
|
||||
line. To use a PKCS#11 hardware service module for cryptographic
|
||||
specify the prefix using "--with-openssl=<PREFIX>" on the configure
|
||||
command line. To use a PKCS#11 hardware service module for cryptographic
|
||||
operations, specify the path to the PKCS#11 provider library using
|
||||
"--with-pkcs11=/prefix", and configure BIND with "--enable-native-pkcs11".
|
||||
"--with-pkcs11=<PREFIX>", and configure BIND with
|
||||
"--enable-native-pkcs11".
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
||||
@@ -212,13 +216,16 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||
specify the prefix using "--with-geoip=/prefix".
|
||||
|
||||
For DNSTAP packet logging, you must have libfstrm https://github.com/
|
||||
farsightsec/fstrm and libprotobuf-c https://developers.google.com/
|
||||
protocol-buffers, and BIND must be configured with "--enable-dnstap".
|
||||
For DNSTAP packet logging, you must have installed libfstrm https://
|
||||
github.com/farsightsec/fstrm and libprotobuf-c https://
|
||||
developers.google.com/protocol-buffers, and BIND must be configured with
|
||||
"--enable-dnstap".
|
||||
|
||||
Python requires the 'argparse' and 'ply' modules to be available.
|
||||
'argparse' is a standard module as of Python 2.7 and Python 3.2. 'ply' is
|
||||
available from https://pypi.python.org/pypi/ply.
|
||||
Portions of BIND that are written in Python, including dnssec-keymgr,
|
||||
dnssec-coverage, dnssec-checkds, and some of the system tests, require the
|
||||
'argparse' and 'ply' modules to be available. 'argparse' is a standard
|
||||
module as of Python 2.7 and Python 3.2. 'ply' is available from https://
|
||||
pypi.python.org/pypi/ply.
|
||||
|
||||
On some platforms it is necessary to explicitly request large file support
|
||||
to handle files bigger than 2GB. This can be done by using
|
||||
@@ -250,7 +257,7 @@ Automated testing
|
||||
A system test suite can be run with make test. The system tests require
|
||||
you to configure a set of virtual IP addresses on your system (this allows
|
||||
multiple servers to run locally and communicate with one another). These
|
||||
IP addresses can be configured by by running the script bin/tests/system/
|
||||
IP addresses can be configured by running the command bin/tests/system/
|
||||
ifconfig.sh up as root.
|
||||
|
||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||
|
||||
@@ -66,12 +66,12 @@ General bug reports can be sent to
|
||||
Feature requests can be sent to
|
||||
[bind-suggest@isc.org](mailto:bind-suggest@isc.org).
|
||||
|
||||
Please note that, while ISC's ticketing system is not currently publicly
|
||||
readable, this may change in the future. Please do not include information
|
||||
in bug reports that you consider to be confidential. For example, when
|
||||
sending the contents of your configuration file, it is advisable to obscure
|
||||
key secrets; this can be done automatically by using `named-checkconf
|
||||
-px`.
|
||||
Please note that, while tickets submitted to ISC's ticketing system
|
||||
are not initially publicly readable by default, they can be made publicly
|
||||
acessible afterward. Please do not include information in bug reports that
|
||||
you consider to be confidential. In particular, when sending the contents of
|
||||
your configuration file, it is advisable to obscure key secrets: this can
|
||||
be done automatically by using `named-checkconf -px`.
|
||||
|
||||
Professional support and training for BIND are available from
|
||||
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
||||
@@ -85,8 +85,8 @@ may also want to join the __BIND Workers__ mailing list, at
|
||||
|
||||
### <a name="contrib"/> Contributing to BIND
|
||||
|
||||
A public git repository for BIND is maintained at
|
||||
[http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||
ISC maintains a public git repository for BIND; details can be found
|
||||
at [http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||
at [https://github.com/isc-projects](https://github.com/isc-projects).
|
||||
|
||||
Information for BIND contributors can be found in the following files:
|
||||
@@ -116,10 +116,8 @@ include:
|
||||
* Cached, validated NSEC and other records can now be used to synthesize
|
||||
NXDOMAIN responses.
|
||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||
* Setting `max-journal-size default` now limits the size of journal files
|
||||
* Setting `'max-journal-size default'` now limits the size of journal files
|
||||
to twice the size of the zone.
|
||||
* The query handling code has been substantially refactored for improved
|
||||
readability, maintainability and testability .
|
||||
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
||||
DNS message.
|
||||
* `dnstap` output files can now be configured to roll automatically when
|
||||
@@ -128,10 +126,14 @@ include:
|
||||
8601 (UTC) formats.
|
||||
* Logging channels and `dnstap` output files can now be configured to use a
|
||||
timestamp as the suffix when rolling to a new file.
|
||||
* `named-checkconf -l` lists zones found in `named.conf`.
|
||||
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
data for zones added by rndc addzone is stored.
|
||||
* The default key algorithm in `rndc-confgen` is now hmac-sha256.
|
||||
* `filter-aaaa-on-v4` and `filter-aaaa-on-v6` options are now available
|
||||
by default without a configure option.
|
||||
* The obsolete `isc-hmac-fixup` command has been removed.
|
||||
|
||||
### <a name="build"/> Building BIND
|
||||
|
||||
@@ -141,8 +143,9 @@ many versions of Linux and UNIX, including RedHat, Fedora, Debian, Ubuntu,
|
||||
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
||||
SCO OpenServer, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||
`win32utils/readme1st.txt` for details on building for Windows systems.
|
||||
BIND is also available for Windows 2008 and higher. See
|
||||
`win32utils/readme1st.txt` for details on building for Windows
|
||||
systems.
|
||||
|
||||
To build on a UNIX or Linux system, use:
|
||||
|
||||
@@ -195,9 +198,9 @@ performance on smaller systems.
|
||||
For the server to support DNSSEC, you need to build it with crypto support.
|
||||
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||
using "--with-openssl=/prefix" on the configure command line. To use a
|
||||
using "--with-openssl=<PREFIX>" on the configure command line. To use a
|
||||
PKCS#11 hardware service module for cryptographic operations, specify the
|
||||
path to the PKCS#11 provider library using "--with-pkcs11=/prefix", and
|
||||
path to the PKCS#11 provider library using "--with-pkcs11=<PREFIX>", and
|
||||
configure BIND with "--enable-native-pkcs11".
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
@@ -220,13 +223,15 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||
specify the prefix using "--with-geoip=/prefix".
|
||||
|
||||
For DNSTAP packet logging, you must have libfstrm
|
||||
For DNSTAP packet logging, you must have installed libfstrm
|
||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||
and libprotobuf-c
|
||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
||||
and BIND must be configured with "--enable-dnstap".
|
||||
|
||||
Python requires the 'argparse' and 'ply' modules to be available.
|
||||
Portions of BIND that are written in Python, including
|
||||
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||
system tests, require the 'argparse' and 'ply' modules to be available.
|
||||
'argparse' is a standard module as of Python 2.7 and Python 3.2.
|
||||
'ply' is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||
|
||||
@@ -260,7 +265,7 @@ localstatedir defaults to `$prefix/var`.
|
||||
A system test suite can be run with `make test`. The system tests require
|
||||
you to configure a set of virtual IP addresses on your system (this allows
|
||||
multiple servers to run locally and communicate with one another). These
|
||||
IP addresses can be configured by by running the script
|
||||
IP addresses can be configured by running the command
|
||||
`bin/tests/system/ifconfig.sh up` as root.
|
||||
|
||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
@@ -64,11 +68,11 @@ rndc-confgen.@O@: rndc-confgen.c
|
||||
ddns-confgen.@O@: ddns-confgen.c
|
||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
||||
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -111,7 +111,7 @@ as directed\&.
|
||||
.PP
|
||||
\-A \fIalgorithm\fR
|
||||
.RS 4
|
||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-md5 or if MD5 was disabled hmac\-sha256\&.
|
||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-sha256\&.
|
||||
.RE
|
||||
.PP
|
||||
\-b \fIkeysize\fR
|
||||
@@ -217,5 +217,5 @@ BIND 9 Administrator Reference Manual\&.
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -1,13 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* $Id: rndc-confgen.c,v 1.7 2011/03/12 04:59:46 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
/**
|
||||
@@ -67,23 +65,6 @@ usage(int status) ISC_PLATFORM_NORETURN_POST;
|
||||
static void
|
||||
usage(int status) {
|
||||
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
fprintf(stderr, "\
|
||||
Usage:\n\
|
||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||
[-s addr] [-t chrootdir] [-u user]\n\
|
||||
-a: generate just the key clause and write it to keyfile (%s)\n\
|
||||
-A alg: algorithm (default hmac-md5)\n\
|
||||
-b bits: from 1 through 512, default 256; total length of the secret\n\
|
||||
-c keyfile: specify an alternate key file (requires -a)\n\
|
||||
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
||||
-p port: the port named will listen on and rndc will connect to\n\
|
||||
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
||||
-s addr: the address to which rndc should connect\n\
|
||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||
progname, keydef);
|
||||
#else
|
||||
fprintf(stderr, "\
|
||||
Usage:\n\
|
||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||
@@ -99,7 +80,6 @@ Usage:\n\
|
||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||
progname, keydef);
|
||||
#endif
|
||||
|
||||
exit (status);
|
||||
}
|
||||
@@ -135,11 +115,7 @@ main(int argc, char **argv) {
|
||||
progname = program;
|
||||
|
||||
keyname = DEFAULT_KEYNAME;
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
alg = DST_ALG_HMACMD5;
|
||||
#else
|
||||
alg = DST_ALG_HMACSHA256;
|
||||
#endif
|
||||
serveraddr = DEFAULT_SERVER;
|
||||
port = DEFAULT_PORT;
|
||||
|
||||
@@ -225,6 +201,12 @@ main(int argc, char **argv) {
|
||||
if (argc > 0)
|
||||
usage(1);
|
||||
|
||||
if (alg == DST_ALG_HMACMD5) {
|
||||
fprintf(stderr,
|
||||
"warning: use of hmac-md5 for RNDC keys "
|
||||
"is deprecated; hmac-sha256 is now recommended.\n");
|
||||
}
|
||||
|
||||
if (keysize < 0)
|
||||
keysize = alg_bits(alg);
|
||||
algname = alg_totext(alg);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -39,6 +39,7 @@
|
||||
<year>2014</year>
|
||||
<year>2015</year>
|
||||
<year>2016</year>
|
||||
<year>2017</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -128,8 +129,7 @@
|
||||
<para>
|
||||
Specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
||||
if MD5 was disabled hmac-sha256.
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -113,8 +113,7 @@
|
||||
<p>
|
||||
Specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
||||
if MD5 was disabled hmac-sha256.
|
||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
||||
|
||||
@@ -469,6 +469,11 @@ Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to hav
|
||||
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]keepalive\fR
|
||||
.RS 4
|
||||
Send [or do not send] an EDNS Keepalive option\&.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]keepopen\fR
|
||||
.RS 4
|
||||
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
||||
|
||||
+74
-38
@@ -109,6 +109,11 @@ print_usage(FILE *fp) {
|
||||
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
||||
}
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
static void usage(void) {
|
||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||
}
|
||||
#else
|
||||
ISC_PLATFORM_NORETURN_PRE static void
|
||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
@@ -119,6 +124,7 @@ usage(void) {
|
||||
"for complete list of options\n", stderr);
|
||||
exit(1);
|
||||
}
|
||||
#endif
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
@@ -414,14 +420,8 @@ isdotlocal(dns_message_t *msg) {
|
||||
isc_result_t result;
|
||||
static unsigned char local_ndata[] = { "\005local\0" };
|
||||
static unsigned char local_offsets[] = { 0, 6 };
|
||||
static dns_name_t local = {
|
||||
DNS_NAME_MAGIC,
|
||||
local_ndata, 7, 2,
|
||||
DNS_NAMEATTR_READONLY | DNS_NAMEATTR_ABSOLUTE,
|
||||
local_offsets, NULL,
|
||||
{(void *)-1, (void *)-1},
|
||||
{NULL, NULL}
|
||||
};
|
||||
static dns_name_t local =
|
||||
DNS_NAME_INITABSOLUTE(local_ndata, local_offsets);
|
||||
|
||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||
result == ISC_R_SUCCESS;
|
||||
@@ -824,8 +824,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, COMMSIZE,
|
||||
"buffer size");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse buffer size");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse buffer size");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->udpsize = num;
|
||||
break;
|
||||
default:
|
||||
@@ -870,8 +872,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value != NULL) {
|
||||
n = strlcpy(hexcookie, value,
|
||||
sizeof(hexcookie));
|
||||
if (n >= sizeof(hexcookie))
|
||||
fatal("COOKIE data too large");
|
||||
if (n >= sizeof(hexcookie)) {
|
||||
warn("COOKIE data too large");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->cookie = hexcookie;
|
||||
} else
|
||||
lookup->cookie = NULL;
|
||||
@@ -922,8 +926,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 0x3f, "DSCP");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse DSCP value");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse DSCP value");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->dscp = num;
|
||||
break;
|
||||
default:
|
||||
@@ -952,9 +958,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
255,
|
||||
"edns");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"edns");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->edns = num;
|
||||
break;
|
||||
case 'f':
|
||||
@@ -971,9 +979,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
value,
|
||||
0xffff,
|
||||
"ednsflags");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse "
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse "
|
||||
"ednsflags");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->ednsflags = num;
|
||||
break;
|
||||
case 'n':
|
||||
@@ -986,10 +996,12 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ednsoptscnt = 0;
|
||||
break;
|
||||
}
|
||||
if (value == NULL)
|
||||
fatal("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
if (value == NULL) {
|
||||
warn("ednsopt no "
|
||||
"code point "
|
||||
"specified");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
code = next_token(&value, ":");
|
||||
save_opt(lookup, code, value);
|
||||
break;
|
||||
@@ -1104,8 +1116,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (!state)
|
||||
goto invalid_option;
|
||||
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse ndots");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse ndots");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
ndots = num;
|
||||
break;
|
||||
case 's':
|
||||
@@ -1167,8 +1181,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
break;
|
||||
}
|
||||
result = parse_uint(&num, value, 15, "opcode");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse opcode");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse opcode");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->opcode = (dns_opcode_t)num;
|
||||
break;
|
||||
default:
|
||||
@@ -1182,8 +1198,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
if (value == NULL)
|
||||
goto need_value;
|
||||
result = parse_uint(&num, value, 512, "padding");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse padding");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse padding");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->padding = (isc_uint16_t)num;
|
||||
break;
|
||||
case 'q':
|
||||
@@ -1222,8 +1240,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES - 1, "retries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse retries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse retries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
lookup->retries++;
|
||||
break;
|
||||
default:
|
||||
@@ -1306,8 +1326,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
*/
|
||||
if (splitwidth)
|
||||
splitwidth += 3;
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse split");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse split");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
case 't': /* stats */
|
||||
FULLCHECK("stats");
|
||||
@@ -1331,8 +1353,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
lookup->ecs_addr = NULL;
|
||||
}
|
||||
result = parse_netprefix(&lookup->ecs_addr, value);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse client");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse client");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
@@ -1355,8 +1379,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
||||
"timeout");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse timeout");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse timeout");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (timeout == 0)
|
||||
timeout = 1;
|
||||
break;
|
||||
@@ -1392,8 +1418,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto invalid_option;
|
||||
result = parse_uint(&lookup->retries, value,
|
||||
MAXTRIES, "tries");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Couldn't parse tries");
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
warn("Couldn't parse tries");
|
||||
goto exit_or_usage;
|
||||
}
|
||||
if (lookup->retries == 0)
|
||||
lookup->retries = 1;
|
||||
break;
|
||||
@@ -1450,11 +1478,19 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
default:
|
||||
invalid_option:
|
||||
need_value:
|
||||
#if TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
#endif
|
||||
fprintf(stderr, "Invalid option: +%s\n",
|
||||
option);
|
||||
usage();
|
||||
}
|
||||
return;
|
||||
|
||||
#if ! TARGET_OS_IPHONE
|
||||
exit_or_usage:
|
||||
digexit();
|
||||
#endif
|
||||
}
|
||||
|
||||
/*%
|
||||
|
||||
@@ -784,6 +784,15 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><option>+[no]keepalive</option></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Send [or do not send] an EDNS Keepalive option.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><option>+[no]keepopen</option></term>
|
||||
<listitem>
|
||||
|
||||
@@ -628,6 +628,12 @@
|
||||
with TCP. By default, TCP retries are performed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepalive</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Send [or do not send] an EDNS Keepalive option.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
+112
-31
@@ -375,6 +375,46 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
||||
}
|
||||
}
|
||||
|
||||
void (*dighost_pre_exit_hook)(void) = NULL;
|
||||
|
||||
#if TARGET_OS_IPHONE
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, ";; Warning: ");
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#else
|
||||
void
|
||||
warn(const char *format, ...) {
|
||||
va_list args;
|
||||
|
||||
fflush(stdout);
|
||||
fprintf(stderr, "%s: ", progname);
|
||||
va_start(args, format);
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
}
|
||||
#endif
|
||||
|
||||
void
|
||||
digexit(void) {
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
if (dighost_pre_exit_hook != NULL) {
|
||||
dighost_pre_exit_hook();
|
||||
}
|
||||
exit(exitcode);
|
||||
}
|
||||
|
||||
void
|
||||
fatal(const char *format, ...) {
|
||||
va_list args;
|
||||
@@ -385,11 +425,7 @@ fatal(const char *format, ...) {
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
if (exitcode < 10)
|
||||
exitcode = 10;
|
||||
if (fatalexit != 0)
|
||||
exitcode = fatalexit;
|
||||
exit(exitcode);
|
||||
digexit();
|
||||
}
|
||||
|
||||
void
|
||||
@@ -655,6 +691,41 @@ make_empty_lookup(void) {
|
||||
return (looknew);
|
||||
}
|
||||
|
||||
#define EDNSOPT_OPTIONS 100U
|
||||
|
||||
static void
|
||||
cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
||||
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
||||
size_t i;
|
||||
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
||||
if (looknew->ednsopts == NULL)
|
||||
fatal("out of memory");
|
||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||
looknew->ednsopts[i].code = 0;
|
||||
looknew->ednsopts[i].length = 0;
|
||||
looknew->ednsopts[i].value = NULL;
|
||||
}
|
||||
looknew->ednsoptscnt = 0;
|
||||
if (lookold == NULL || lookold->ednsopts == NULL)
|
||||
return;
|
||||
|
||||
for (i = 0; i < lookold->ednsoptscnt; i++) {
|
||||
len = lookold->ednsopts[i].length;
|
||||
if (len != 0) {
|
||||
INSIST(lookold->ednsopts[i].value != NULL);
|
||||
looknew->ednsopts[i].value =
|
||||
isc_mem_allocate(mctx, len);
|
||||
if (looknew->ednsopts[i].value == NULL)
|
||||
fatal("out of memory");
|
||||
memmove(looknew->ednsopts[i].value,
|
||||
lookold->ednsopts[i].value, len);
|
||||
}
|
||||
looknew->ednsopts[i].code = lookold->ednsopts[i].code;
|
||||
looknew->ednsopts[i].length = len;
|
||||
}
|
||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||
}
|
||||
|
||||
/*%
|
||||
* Clone a lookup, perhaps copying the server list. This does not clone
|
||||
* the query list, since it will be regenerated by the setup_lookup()
|
||||
@@ -700,8 +771,12 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||
looknew->badcookie = lookold->badcookie;
|
||||
looknew->cookie = lookold->cookie;
|
||||
looknew->ednsopts = lookold->ednsopts;
|
||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||
if (lookold->ednsopts != NULL) {
|
||||
cloneopts(looknew, lookold);
|
||||
} else {
|
||||
looknew->ednsopts = NULL;
|
||||
looknew->ednsoptscnt = 0;
|
||||
}
|
||||
looknew->ednsneg = lookold->ednsneg;
|
||||
looknew->padding = lookold->padding;
|
||||
looknew->mapped = lookold->mapped;
|
||||
@@ -1317,13 +1392,6 @@ setup_libs(void) {
|
||||
check_result(result, "isc_mutex_init");
|
||||
}
|
||||
|
||||
/*
|
||||
* Array of up to 100 options configured by +ednsopt
|
||||
*/
|
||||
#define EDNSOPT_OPTIONS 100U
|
||||
static dns_ednsopt_t ednsopts[EDNSOPT_OPTIONS];
|
||||
static unsigned char ednsoptscnt = 0;
|
||||
|
||||
typedef struct dig_ednsoptname {
|
||||
isc_uint32_t code;
|
||||
const char *name;
|
||||
@@ -1350,12 +1418,12 @@ dig_ednsoptname_t optnames[] = {
|
||||
void
|
||||
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
isc_result_t result;
|
||||
isc_uint32_t num;
|
||||
isc_uint32_t num = 0;
|
||||
isc_buffer_t b;
|
||||
isc_boolean_t found = ISC_FALSE;
|
||||
unsigned int i;
|
||||
|
||||
if (ednsoptscnt == EDNSOPT_OPTIONS)
|
||||
if (lookup->ednsoptscnt >= EDNSOPT_OPTIONS)
|
||||
fatal("too many ednsopts");
|
||||
|
||||
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
||||
@@ -1372,9 +1440,16 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
fatal("bad edns code point: %s", code);
|
||||
}
|
||||
|
||||
ednsopts[ednsoptscnt].code = num;
|
||||
ednsopts[ednsoptscnt].length = 0;
|
||||
ednsopts[ednsoptscnt].value = NULL;
|
||||
if (lookup->ednsopts == NULL) {
|
||||
cloneopts(lookup, NULL);
|
||||
}
|
||||
|
||||
if (lookup->ednsopts[lookup->ednsoptscnt].value != NULL)
|
||||
isc_mem_free(mctx, lookup->ednsopts[lookup->ednsoptscnt].value);
|
||||
|
||||
lookup->ednsopts[lookup->ednsoptscnt].code = num;
|
||||
lookup->ednsopts[lookup->ednsoptscnt].length = 0;
|
||||
lookup->ednsopts[lookup->ednsoptscnt].value = NULL;
|
||||
|
||||
if (value != NULL) {
|
||||
char *buf;
|
||||
@@ -1384,14 +1459,13 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
||||
result = isc_hex_decodestring(value, &b);
|
||||
check_result(result, "isc_hex_decodestring");
|
||||
ednsopts[ednsoptscnt].value = isc_buffer_base(&b);
|
||||
ednsopts[ednsoptscnt].length = isc_buffer_usedlength(&b);
|
||||
lookup->ednsopts[lookup->ednsoptscnt].value =
|
||||
isc_buffer_base(&b);
|
||||
lookup->ednsopts[lookup->ednsoptscnt].length =
|
||||
isc_buffer_usedlength(&b);
|
||||
}
|
||||
|
||||
if (lookup->ednsoptscnt == 0)
|
||||
lookup->ednsopts = &ednsopts[ednsoptscnt];
|
||||
lookup->ednsoptscnt++;
|
||||
ednsoptscnt++;
|
||||
}
|
||||
|
||||
/*%
|
||||
@@ -1570,6 +1644,15 @@ destroy_lookup(dig_lookup_t *lookup) {
|
||||
if (lookup->ecs_addr != NULL)
|
||||
isc_mem_free(mctx, lookup->ecs_addr);
|
||||
|
||||
if (lookup->ednsopts != NULL) {
|
||||
size_t i;
|
||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||
if (lookup->ednsopts[i].value != NULL)
|
||||
isc_mem_free(mctx, lookup->ednsopts[i].value);
|
||||
}
|
||||
isc_mem_free(mctx, lookup->ednsopts);
|
||||
}
|
||||
|
||||
isc_mem_free(mctx, lookup);
|
||||
}
|
||||
|
||||
@@ -2114,9 +2197,13 @@ setup_lookup(dig_lookup_t *lookup) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_message_puttempname(lookup->sendmsg,
|
||||
&lookup->name);
|
||||
fatal("'%s' is not a legal name "
|
||||
warn("'%s' is not a legal name "
|
||||
"(%s)", lookup->textname,
|
||||
isc_result_totext(result));
|
||||
#if TARGET_OS_IPHONE
|
||||
check_next_lookup(current_lookup);
|
||||
return (ISC_FALSE);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
dns_name_format(lookup->name, store, sizeof(store));
|
||||
@@ -4127,12 +4214,6 @@ destroy_libs(void) {
|
||||
debug("Removing log context");
|
||||
isc_log_destroy(&lctx);
|
||||
|
||||
while (ednsoptscnt > 0U) {
|
||||
ednsoptscnt--;
|
||||
if (ednsopts[ednsoptscnt].value != NULL)
|
||||
isc_mem_free(mctx, ednsopts[ednsoptscnt].value);
|
||||
}
|
||||
|
||||
debug("Destroy memory");
|
||||
if (memdebugging != 0)
|
||||
isc_mem_stats(mctx, stderr);
|
||||
|
||||
@@ -26,6 +26,10 @@
|
||||
#include <isc/sockaddr.h>
|
||||
#include <isc/socket.h>
|
||||
|
||||
#ifdef __APPLE__
|
||||
#include <TargetConditionals.h>
|
||||
#endif
|
||||
|
||||
#define MXSERV 20
|
||||
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
||||
#define MXRD 32
|
||||
@@ -282,6 +286,13 @@ ISC_PLATFORM_NORETURN_PRE void
|
||||
fatal(const char *format, ...)
|
||||
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_PLATFORM_NORETURN_PRE void
|
||||
digexit(void)
|
||||
ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
void
|
||||
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
@@ -384,6 +395,9 @@ extern void
|
||||
extern void
|
||||
(*dighost_shutdown)(void);
|
||||
|
||||
extern void
|
||||
(*dighost_pre_exit_hook)(void);
|
||||
|
||||
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
||||
|
||||
void setup_file_key(void);
|
||||
|
||||
@@ -62,12 +62,15 @@ may be preferable to direct use of
|
||||
.RS 4
|
||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||
\fBalgorithm\fR
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TSIG/TKEY keys, the value must be one of DH (Diffie Hellman), HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512; specifying any of these algorithms will automatically set the
|
||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
|
||||
\fB\-T KEY\fR
|
||||
option as well\&. (Note:
|
||||
option as well\&.
|
||||
.sp
|
||||
TSIG keys can also be generated by setting the value to one of HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512\&. As with DH, specifying these values will automatically set
|
||||
\fB\-T KEY\fR\&. Note, however, that
|
||||
\fBtsig\-keygen\fR
|
||||
produces TSIG keys in a more useful format than
|
||||
\fBdnssec\-keygen\fR\&.)
|
||||
produces TSIG keys in a more useful format\&. These algorithms have been deprecated in
|
||||
\fBdnssec\-keygen\fR, and will be removed in a future release\&.
|
||||
.sp
|
||||
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
||||
\fB\-3\fR
|
||||
@@ -75,7 +78,7 @@ option, then NSEC3RSASHA1 or NSEC3DSA will be used instead\&.
|
||||
.sp
|
||||
As of BIND 9\&.12\&.0, this option is mandatory except when using the
|
||||
\fB\-S\fR
|
||||
option (which copies the algorithm from the predecessor key)\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||
option, which copies the algorithm from the predecessor key\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||
.RE
|
||||
.PP
|
||||
\-b \fIkeysize\fR
|
||||
|
||||
@@ -582,6 +582,16 @@ main(int argc, char **argv) {
|
||||
INSIST((alg != DNS_KEYALG_RSAMD5) && (alg != DST_ALG_HMACMD5));
|
||||
#endif
|
||||
|
||||
|
||||
if (alg == DST_ALG_HMACMD5 || alg == DST_ALG_HMACSHA1 ||
|
||||
alg == DST_ALG_HMACSHA224 || alg == DST_ALG_HMACSHA256 ||
|
||||
alg == DST_ALG_HMACSHA384 || alg == DST_ALG_HMACSHA512)
|
||||
{
|
||||
fprintf(stderr,
|
||||
"Use of dnssec-keygen for HMAC keys is "
|
||||
"deprecated: use tsig-keygen\n");
|
||||
}
|
||||
|
||||
if (!dst_algorithm_supported(alg))
|
||||
fatal("unsupported algorithm: %d", alg);
|
||||
|
||||
|
||||
@@ -122,12 +122,19 @@
|
||||
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||
or HMAC-SHA512; specifying any of these algorithms will
|
||||
automatically set the <option>-T KEY</option> option as well.
|
||||
(Note: <command>tsig-keygen</command> produces TSIG keys in a
|
||||
more useful format than <command>dnssec-keygen</command>.)
|
||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||
his value will automatically set the <option>-T KEY</option>
|
||||
option as well.
|
||||
</para>
|
||||
<para>
|
||||
TSIG keys can also be generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <option>-T KEY</option>. Note,
|
||||
however, that <command>tsig-keygen</command> produces TSIG keys
|
||||
in a more useful format. These algorithms have been deprecated
|
||||
in <command>dnssec-keygen</command>, and will be removed in a
|
||||
future release.
|
||||
</para>
|
||||
<para>
|
||||
These values are case insensitive. In some cases, abbreviations
|
||||
@@ -138,8 +145,8 @@
|
||||
</para>
|
||||
<para>
|
||||
As of BIND 9.12.0, this option is mandatory except when using
|
||||
the <option>-S</option> option (which copies the algorithm from
|
||||
the predecessor key). Previously, the default for newly
|
||||
the <option>-S</option> option, which copies the algorithm from
|
||||
the predecessor key. Previously, the default for newly
|
||||
generated keys was RSASHA1.
|
||||
</para>
|
||||
</listitem>
|
||||
|
||||
@@ -103,12 +103,19 @@
|
||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||
or HMAC-SHA512; specifying any of these algorithms will
|
||||
automatically set the <code class="option">-T KEY</code> option as well.
|
||||
(Note: <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys in a
|
||||
more useful format than <span class="command"><strong>dnssec-keygen</strong></span>.)
|
||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||
his value will automatically set the <code class="option">-T KEY</code>
|
||||
option as well.
|
||||
</p>
|
||||
<p>
|
||||
TSIG keys can also be generated by setting the value to
|
||||
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||
however, that <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys
|
||||
in a more useful format. These algorithms have been deprecated
|
||||
in <span class="command"><strong>dnssec-keygen</strong></span>, and will be removed in a
|
||||
future release.
|
||||
</p>
|
||||
<p>
|
||||
These values are case insensitive. In some cases, abbreviations
|
||||
@@ -119,8 +126,8 @@
|
||||
</p>
|
||||
<p>
|
||||
As of BIND 9.12.0, this option is mandatory except when using
|
||||
the <code class="option">-S</code> option (which copies the algorithm from
|
||||
the predecessor key). Previously, the default for newly
|
||||
the <code class="option">-S</code> option, which copies the algorithm from
|
||||
the predecessor key. Previously, the default for newly
|
||||
generated keys was RSASHA1.
|
||||
</p>
|
||||
</dd>
|
||||
|
||||
@@ -349,6 +349,14 @@ If the key\*(Aqs revocation date is set and in the past, and the key is publishe
|
||||
.RS 4
|
||||
If either of the key\*(Aqs unpublication or deletion dates are set and in the past, the key is NOT published or used to sign the zone, regardless of any other metadata\&.
|
||||
.RE
|
||||
.PP
|
||||
.RS 4
|
||||
If key\*(Aqs sync publication date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are created\&.
|
||||
.RE
|
||||
.PP
|
||||
.RS 4
|
||||
If key\*(Aqs sync deletion date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are removed\&.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
\-T \fIttl\fR
|
||||
|
||||
@@ -1958,7 +1958,7 @@ addnsec3(dns_name_t *name, dns_dbnode_t *node,
|
||||
* any NSEC3 records which have the same parameters as the chain we
|
||||
* are building.
|
||||
*
|
||||
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
||||
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
||||
*/
|
||||
static void
|
||||
nsec3clean(dns_name_t *name, dns_dbnode_t *node,
|
||||
|
||||
@@ -646,6 +646,26 @@
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<listitem>
|
||||
<para>
|
||||
If key's sync publication date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
created.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<listitem>
|
||||
<para>
|
||||
If key's sync deletion date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
removed.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -519,6 +519,22 @@
|
||||
zone, regardless of any other metadata.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync publication date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
created.
|
||||
</p>
|
||||
</dd>
|
||||
<dt></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If key's sync deletion date is set and in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are
|
||||
removed.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</dd>
|
||||
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||
|
||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
# Attempt to disable parallel processing.
|
||||
.NOTPARALLEL:
|
||||
.NO_PARALLEL:
|
||||
|
||||
VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_PRODUCT@
|
||||
@@ -130,7 +134,7 @@ server.@O@: server.c
|
||||
-DPRODUCT=\"${PRODUCT}\" \
|
||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||
|
||||
named@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
||||
named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||
export MAKE_SYMTABLE="yes"; \
|
||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@
|
||||
|
||||
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
||||
<xsl:output method="html" indent="yes" version="4.0"/>
|
||||
<xsl:template match="statistics[@version="3.10"]">
|
||||
<xsl:template match="statistics[@version="3.11"]">
|
||||
<html>
|
||||
<head>
|
||||
<xsl:if test="system-property('xsl:vendor')!='Transformiix'">
|
||||
|
||||
@@ -14,7 +14,7 @@ static char xslmsg[] =
|
||||
"\n"
|
||||
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
||||
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
||||
" <xsl:template match=\"statistics[@version="3.10"]\">\n"
|
||||
" <xsl:template match=\"statistics[@version="3.11"]\">\n"
|
||||
" <html>\n"
|
||||
" <head>\n"
|
||||
" <xsl:if test=\"system-property('xsl:vendor')!='Transformiix'\">\n"
|
||||
|
||||
+2
-4
@@ -156,12 +156,10 @@ options {\n\
|
||||
# fetch-glue <obsolete>;\n\
|
||||
fetch-quota-params 100 0.1 0.3 0.7;\n\
|
||||
fetches-per-server 0;\n\
|
||||
fetches-per-zone 0;\n"
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
" filter-aaaa-on-v4 no;\n\
|
||||
fetches-per-zone 0;\n\
|
||||
filter-aaaa-on-v4 no;\n\
|
||||
filter-aaaa-on-v6 no;\n\
|
||||
filter-aaaa { any; };\n"
|
||||
#endif
|
||||
#ifdef HAVE_GEOIP
|
||||
" geoip-use-ecs yes;\n"
|
||||
#endif
|
||||
|
||||
@@ -456,9 +456,8 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
*/
|
||||
if (conn->nonce == 0) {
|
||||
while (conn->nonce == 0) {
|
||||
isc_uint16_t r1 = isc_rng_random(server->sctx->rngctx);
|
||||
isc_uint16_t r2 = isc_rng_random(server->sctx->rngctx);
|
||||
conn->nonce = (r1 << 16) | r2;
|
||||
isc_rng_randombytes(server->sctx->rngctx, &conn->nonce,
|
||||
sizeof(conn->nonce));
|
||||
}
|
||||
eresult = ISC_R_SUCCESS;
|
||||
} else
|
||||
|
||||
@@ -26,6 +26,8 @@
|
||||
int scmp_syscalls[] = {
|
||||
SCMP_SYS(access),
|
||||
SCMP_SYS(open),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(clock_gettime),
|
||||
SCMP_SYS(time),
|
||||
SCMP_SYS(read),
|
||||
@@ -54,6 +56,7 @@ int scmp_syscalls[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
SCMP_SYS(getrandom),
|
||||
#endif
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(unlink),
|
||||
SCMP_SYS(socket),
|
||||
SCMP_SYS(sendto),
|
||||
@@ -72,7 +75,6 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(getsockopt),
|
||||
SCMP_SYS(getsockname),
|
||||
SCMP_SYS(lstat),
|
||||
SCMP_SYS(lseek),
|
||||
SCMP_SYS(getgid),
|
||||
SCMP_SYS(getegid),
|
||||
SCMP_SYS(getuid),
|
||||
@@ -83,9 +85,7 @@ int scmp_syscalls[] = {
|
||||
SCMP_SYS(setuid),
|
||||
SCMP_SYS(prctl),
|
||||
SCMP_SYS(epoll_wait),
|
||||
SCMP_SYS(openat),
|
||||
SCMP_SYS(getdents),
|
||||
SCMP_SYS(rename),
|
||||
SCMP_SYS(utimes),
|
||||
SCMP_SYS(dup),
|
||||
#endif
|
||||
@@ -93,6 +93,8 @@ int scmp_syscalls[] = {
|
||||
const char *scmp_syscall_names[] = {
|
||||
"access",
|
||||
"open",
|
||||
"openat",
|
||||
"lseek",
|
||||
"clock_gettime",
|
||||
"time",
|
||||
"read",
|
||||
@@ -121,6 +123,7 @@ const char *scmp_syscall_names[] = {
|
||||
#ifdef HAVE_GETRANDOM
|
||||
"getrandom",
|
||||
#endif
|
||||
"rename",
|
||||
"unlink",
|
||||
"socket",
|
||||
"sendto",
|
||||
@@ -139,7 +142,6 @@ const char *scmp_syscall_names[] = {
|
||||
"getsockopt",
|
||||
"getsockname",
|
||||
"lstat",
|
||||
"lseek",
|
||||
"getgid",
|
||||
"getegid",
|
||||
"getuid",
|
||||
@@ -150,9 +152,7 @@ const char *scmp_syscall_names[] = {
|
||||
"setuid",
|
||||
"prctl",
|
||||
"epoll_wait",
|
||||
"openat",
|
||||
"getdents",
|
||||
"rename",
|
||||
"utimes",
|
||||
"dup",
|
||||
#endif
|
||||
|
||||
@@ -17,6 +17,7 @@
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/syslog.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <isccfg/cfg.h>
|
||||
#include <isccfg/log.h>
|
||||
|
||||
+299
-209
@@ -154,11 +154,7 @@
|
||||
#define EXCLBUFFERS 4096
|
||||
#endif /* TUNE_LARGE */
|
||||
|
||||
#ifdef WIN32
|
||||
#define DIR_PERM_OK W_OK
|
||||
#else
|
||||
#define DIR_PERM_OK W_OK|X_OK
|
||||
#endif
|
||||
#define MAX_TCP_TIMEOUT 65535
|
||||
|
||||
/*%
|
||||
* Check an operation for failure. Assumes that the function
|
||||
@@ -803,6 +799,11 @@ dstkey_fromconfig(const cfg_obj_t *vconfig, const cfg_obj_t *key,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Load keys from configuration into key table. If 'keyname' is specified,
|
||||
* only load keys matching that name. If 'managed' is true, load the key as
|
||||
* an initializing key.
|
||||
*/
|
||||
static isc_result_t
|
||||
load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
dns_view_t *view, isc_boolean_t managed,
|
||||
@@ -818,12 +819,14 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
|
||||
for (elt = cfg_list_first(keys);
|
||||
elt != NULL;
|
||||
elt = cfg_list_next(elt)) {
|
||||
elt = cfg_list_next(elt))
|
||||
{
|
||||
keylist = cfg_listelt_value(elt);
|
||||
|
||||
for (elt2 = cfg_list_first(keylist);
|
||||
elt2 != NULL;
|
||||
elt2 = cfg_list_next(elt2)) {
|
||||
elt2 = cfg_list_next(elt2))
|
||||
{
|
||||
key = cfg_listelt_value(elt2);
|
||||
result = dstkey_fromconfig(vconfig, key, managed,
|
||||
&dstkey, mctx);
|
||||
@@ -831,8 +834,9 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
result = ISC_R_SUCCESS;
|
||||
continue;
|
||||
}
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/*
|
||||
* If keyname was specified, we only add that key.
|
||||
@@ -844,17 +848,27 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||
continue;
|
||||
}
|
||||
|
||||
CHECK(dns_keytable_add(secroots, managed, &dstkey));
|
||||
/*
|
||||
* This key is taken from the configuration, so
|
||||
* if it's a managed key then it's an
|
||||
* initializing key; that's why 'managed'
|
||||
* is duplicated below.
|
||||
*/
|
||||
CHECK(dns_keytable_add2(secroots, managed,
|
||||
managed, &dstkey));
|
||||
}
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (dstkey != NULL)
|
||||
if (dstkey != NULL) {
|
||||
dst_key_free(&dstkey);
|
||||
if (secroots != NULL)
|
||||
}
|
||||
if (secroots != NULL) {
|
||||
dns_keytable_detach(&secroots);
|
||||
if (result == DST_R_NOCRYPTO)
|
||||
}
|
||||
if (result == DST_R_NOCRYPTO) {
|
||||
result = ISC_R_SUCCESS;
|
||||
}
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -1024,7 +1038,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
}
|
||||
|
||||
/*
|
||||
* Add key zone for managed-keys.
|
||||
* Add key zone for managed keys.
|
||||
*/
|
||||
obj = NULL;
|
||||
(void)named_config_get(maps, "managed-keys-directory", &obj);
|
||||
@@ -1039,7 +1053,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
goto cleanup;
|
||||
|
||||
} else if (directory != NULL) {
|
||||
if (access(directory, DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(directory)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"managed-keys-directory '%s' "
|
||||
@@ -1048,6 +1062,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
CHECK(add_keydata_zone(view, directory, named_g_mctx));
|
||||
|
||||
cleanup:
|
||||
@@ -3323,7 +3338,7 @@ create_empty_zone(dns_zone_t *zone, dns_name_t *name, dns_view_t *view,
|
||||
viewname = "";
|
||||
}
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_ZONELOAD,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"automatic empty zone%s%s: %s",
|
||||
sep, viewname, namebuf);
|
||||
@@ -4681,20 +4696,19 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
* "allow-recursion" inherits from "allow-query-cache" if set,
|
||||
* otherwise from "allow-query" if set.
|
||||
*/
|
||||
if (view->cacheacl == NULL && view->recursionacl != NULL)
|
||||
if (view->cacheacl == NULL && view->recursionacl != NULL) {
|
||||
dns_acl_attach(view->recursionacl, &view->cacheacl);
|
||||
/*
|
||||
* XXXEACH: This call to configure_view_acl() is redundant. We
|
||||
* are leaving it as it is because we are making a minimal change
|
||||
* for a patch release. In the future this should be changed to
|
||||
* dns_acl_attach(view->queryacl, &view->cacheacl).
|
||||
*/
|
||||
if (view->cacheacl == NULL && view->recursion)
|
||||
CHECK(configure_view_acl(vconfig, config, "allow-query", NULL,
|
||||
actx, named_g_mctx, &view->cacheacl));
|
||||
}
|
||||
|
||||
if (view->cacheacl == NULL && view->recursion) {
|
||||
dns_acl_attach(view->queryacl, &view->cacheacl);
|
||||
}
|
||||
|
||||
if (view->recursion &&
|
||||
view->recursionacl == NULL && view->cacheacl != NULL)
|
||||
{
|
||||
dns_acl_attach(view->cacheacl, &view->recursionacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set default "allow-recursion", "allow-recursion-on" and
|
||||
@@ -4875,7 +4889,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
dns_quotatype_zone, r);
|
||||
}
|
||||
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "filter-aaaa-on-v4", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -4910,7 +4923,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
|
||||
CHECK(configure_view_acl(vconfig, config, "filter-aaaa", NULL,
|
||||
actx, named_g_mctx, &view->aaaa_acl));
|
||||
#endif
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "prefetch", &obj);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
@@ -4956,11 +4969,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
if (!strcasecmp(dom, "no")) {
|
||||
result = ISC_R_NOTFOUND;
|
||||
} else if (!strcasecmp(dom, "auto")) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"WARNING: the DLV server at "
|
||||
"'dlv.isc.org' is no longer "
|
||||
"in service; dnssec-lookaside "
|
||||
"ignored");
|
||||
/*
|
||||
* Warning logged by libbind9.
|
||||
*/
|
||||
result = ISC_R_NOTFOUND;
|
||||
}
|
||||
}
|
||||
@@ -4986,11 +4997,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
||||
CHECK(dns_name_fromstring(dlv, cfg_obj_asstring(obj),
|
||||
DNS_NAME_DOWNCASE, NULL));
|
||||
if (dns_name_equal(dlv, iscdlv)) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"WARNING: the DLV server at "
|
||||
"'dlv.isc.org' is no longer "
|
||||
"in service; dnssec-lookaside "
|
||||
"ignored");
|
||||
/*
|
||||
* Warning logged by libbind9.
|
||||
*/
|
||||
view->dlv = NULL;
|
||||
} else {
|
||||
view->dlv = dlv;
|
||||
@@ -6007,7 +6016,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
* Add the zone to its view in the new view list.
|
||||
*/
|
||||
if (!modify)
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
CHECK(dns_view_addzone(view, zone));
|
||||
|
||||
if (zone_is_catz) {
|
||||
/*
|
||||
@@ -6165,7 +6174,7 @@ directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
|
||||
"option 'directory' contains relative path '%s'",
|
||||
directory);
|
||||
|
||||
if (access(directory, DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(directory)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"directory '%s' is not writable",
|
||||
@@ -6443,16 +6452,19 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
}
|
||||
nextnode = NULL;
|
||||
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
||||
if (keynode != firstnode)
|
||||
if (keynode != firstnode) {
|
||||
dns_keytable_detachkeynode(keytable, &keynode);
|
||||
}
|
||||
keynode = nextnode;
|
||||
} while (keynode != NULL);
|
||||
|
||||
if (n == 0)
|
||||
if (n == 0) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (n > 1)
|
||||
if (n > 1) {
|
||||
qsort(ids, n, sizeof(ids[0]), cid);
|
||||
}
|
||||
|
||||
/*
|
||||
* Encoded as "_ta-xxxx\(-xxxx\)*" where xxxx is the hex version of
|
||||
@@ -6460,22 +6472,25 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
*/
|
||||
label[0] = 0;
|
||||
r.base = label;
|
||||
r.length = sizeof(label);;
|
||||
r.length = sizeof(label);
|
||||
m = snprintf(r.base, r.length, "_ta");
|
||||
if (m < 0 || (unsigned)m > r.length)
|
||||
if (m < 0 || (unsigned)m > r.length) {
|
||||
return;
|
||||
}
|
||||
isc_textregion_consume(&r, m);
|
||||
for (i = 0; i < n; i++) {
|
||||
m = snprintf(r.base, r.length, "-%04x", ids[i]);
|
||||
if (m < 0 || (unsigned)m > r.length)
|
||||
if (m < 0 || (unsigned)m > r.length) {
|
||||
return;
|
||||
}
|
||||
isc_textregion_consume(&r, m);
|
||||
}
|
||||
dns_fixedname_init(&fixed);
|
||||
tatname = dns_fixedname_name(&fixed);
|
||||
result = dns_name_fromstring2(tatname, label, name, 0, NULL);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
return;
|
||||
}
|
||||
|
||||
dns_name_format(tatname, namebuf, sizeof(namebuf));
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
@@ -6484,8 +6499,9 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
view->name, namebuf);
|
||||
|
||||
tat = isc_mem_get(dotat_arg->view->mctx, sizeof(*tat));
|
||||
if (tat == NULL)
|
||||
if (tat == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
tat->mctx = NULL;
|
||||
tat->task = NULL;
|
||||
@@ -7053,6 +7069,13 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
dir, isc_result_totext(result));
|
||||
return (result);
|
||||
}
|
||||
if (!isc_file_isdirwritable(dir)) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"new-zones-directory '%s' "
|
||||
"is not writable", dir);
|
||||
return (ISC_R_NOPERM);
|
||||
}
|
||||
|
||||
dns_view_setnewzonedir(view, dir);
|
||||
}
|
||||
@@ -7310,18 +7333,128 @@ data_to_cfg(dns_view_t *view, MDB_val *key, MDB_val *data,
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Prototype for a callback which can be used with for_all_newzone_cfgs().
|
||||
*/
|
||||
typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx);
|
||||
|
||||
/*%
|
||||
* For each zone found in a NZD opened by the caller, create an object
|
||||
* representing its configuration and invoke "callback" with the created
|
||||
* object, "config", "vconfig", "mctx", "view" and "actx" as arguments (all
|
||||
* these are non-global variables required to invoke configure_zone()).
|
||||
* Immediately interrupt processing if an error is encountered while
|
||||
* transforming NZD data into a zone configuration object or if "callback"
|
||||
* returns an error.
|
||||
*/
|
||||
static isc_result_t
|
||||
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx, MDB_txn *txn, MDB_dbi dbi)
|
||||
{
|
||||
const cfg_obj_t *zconfig, *zlist = NULL;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
cfg_obj_t *zconfigobj = NULL;
|
||||
isc_buffer_t *text = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
MDB_val data, key;
|
||||
int status;
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != MDB_SUCCESS) {
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||
status == MDB_SUCCESS;
|
||||
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT))
|
||||
{
|
||||
/*
|
||||
* Create a configuration object from data fetched from NZD.
|
||||
*/
|
||||
result = data_to_cfg(view, &key, &data, &text, &zconfigobj);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Extract zone configuration from configuration object.
|
||||
*/
|
||||
result = cfg_map_get(zconfigobj, "zone", &zlist);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
} else if (!cfg_obj_islist(zlist)) {
|
||||
result = ISC_R_FAILURE;
|
||||
break;
|
||||
}
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
|
||||
/*
|
||||
* Invoke callback.
|
||||
*/
|
||||
result = callback(zconfig, config, vconfig, mctx, view, actx);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
|
||||
/*
|
||||
* Destroy the configuration object created in this iteration.
|
||||
*/
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zconfigobj != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||
}
|
||||
mdb_cursor_close(cursor);
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Attempt to configure a zone found in NZD and return the result.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
return (configure_zone(config, zconfig, vconfig, mctx, view,
|
||||
&named_g_server->viewlist, actx, ISC_TRUE,
|
||||
ISC_FALSE, ISC_FALSE));
|
||||
}
|
||||
|
||||
/*%
|
||||
* Revert new view assignment for a zone found in NZD.
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx)
|
||||
{
|
||||
UNUSED(config);
|
||||
UNUSED(vconfig);
|
||||
UNUSED(mctx);
|
||||
UNUSED(actx);
|
||||
|
||||
configure_zone_setviewcommit(ISC_R_FAILURE, zconfig, view);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx)
|
||||
{
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
int status;
|
||||
isc_buffer_t *text = NULL;
|
||||
cfg_obj_t *zoneconf = NULL;
|
||||
MDB_cursor *cursor = NULL;
|
||||
isc_result_t result;
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
MDB_val key, data;
|
||||
|
||||
if (view->new_zone_config == NULL) {
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -7338,82 +7471,22 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
"for view '%s'",
|
||||
view->new_zone_db, view->name);
|
||||
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zoneobj = NULL;
|
||||
|
||||
result = data_to_cfg(view, &key, &data, &text, &zoneconf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
CHECK(cfg_map_get(zoneconf, "zone", &zlist));
|
||||
if (!cfg_obj_islist(zlist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
zoneobj = cfg_listelt_value(cfg_list_first(zlist));
|
||||
CHECK(configure_zone(config, zoneobj, vconfig, mctx,
|
||||
view, &named_g_server->viewlist, actx,
|
||||
ISC_TRUE, ISC_FALSE, ISC_FALSE));
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
cursor = NULL;
|
||||
}
|
||||
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, mctx,
|
||||
view, actx, txn, dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||
if (status != 0) {
|
||||
goto cleanup2;
|
||||
}
|
||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
||||
const cfg_obj_t *zlist = NULL;
|
||||
const cfg_obj_t *zconfig = NULL;
|
||||
isc_result_t result2;
|
||||
|
||||
result2 = data_to_cfg(view, &key, &data, &text,
|
||||
&zoneconf);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
result2 = cfg_map_get(zoneconf, "zone", &zlist);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
goto cleanup2;
|
||||
}
|
||||
|
||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||
configure_zone_setviewcommit(result, zconfig, view);
|
||||
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
/*
|
||||
* An error was encountered while attempting to configure zones
|
||||
* found in NZD. As this error may have been caused by a
|
||||
* configure_zone() failure, try restoring a sane configuration
|
||||
* by reattaching all zones found in NZD to the old view. If
|
||||
* this also fails, too bad, there is nothing more we can do in
|
||||
* terms of trying to make things right.
|
||||
*/
|
||||
(void) for_all_newzone_cfgs(configure_newzone_revert, config,
|
||||
vconfig, mctx, view, actx, txn,
|
||||
dbi);
|
||||
}
|
||||
|
||||
cleanup2:
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
if (zoneconf != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
||||
}
|
||||
if (cursor != NULL) {
|
||||
mdb_cursor_close(cursor);
|
||||
}
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
return (result);
|
||||
}
|
||||
@@ -7457,8 +7530,9 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
||||
key.mv_size = strlen(zname);
|
||||
|
||||
status = mdb_get(txn, dbi, &key, &data);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(data_to_cfg(view, &key, &data, &text, &zoneconf));
|
||||
|
||||
@@ -7881,11 +7955,11 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
result = named_config_get(maps, "tcp-keepalive-timeout", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
keepalive = cfg_obj_asuint32(obj);
|
||||
if (keepalive > 1200) {
|
||||
if (keepalive > MAX_TCP_TIMEOUT) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-keepalive-timeout value is out of range: "
|
||||
"lowering to 1200");
|
||||
keepalive = 1200;
|
||||
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||
keepalive = MAX_TCP_TIMEOUT;
|
||||
} else if (keepalive < 1) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-keepalive-timeout value is out of range: "
|
||||
@@ -7897,11 +7971,11 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
result = named_config_get(maps, "tcp-advertised-timeout", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
advertised = cfg_obj_asuint32(obj);
|
||||
if (advertised > 1200) {
|
||||
if (advertised > MAX_TCP_TIMEOUT) {
|
||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||
"tcp-advertized-timeout value is out of range: "
|
||||
"lowering to 1200");
|
||||
advertised = 1200;
|
||||
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||
advertised = MAX_TCP_TIMEOUT;
|
||||
}
|
||||
|
||||
ns_server_settimeouts(named_g_server->sctx,
|
||||
@@ -8487,7 +8561,7 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
/*
|
||||
* Check that the working directory is writable.
|
||||
*/
|
||||
if (access(".", DIR_PERM_OK) != 0) {
|
||||
if (!isc_file_isdirwritable(".")) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"the working directory is not writable");
|
||||
@@ -11739,6 +11813,10 @@ nzf_append(dns_view_t *view, const cfg_obj_t *zconfig) {
|
||||
|
||||
static isc_result_t
|
||||
nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
||||
const cfg_obj_t *zl = NULL;
|
||||
cfg_list_t *list;
|
||||
const cfg_listelt_t *elt;
|
||||
|
||||
FILE *fp = NULL;
|
||||
char tmp[1024];
|
||||
isc_result_t result;
|
||||
@@ -11750,9 +11828,24 @@ nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
cfg_map_get(config, "zone", &zl);
|
||||
if (!cfg_obj_islist(zl))
|
||||
CHECK(ISC_R_FAILURE);
|
||||
|
||||
DE_CONST(&zl->value.list, list);
|
||||
|
||||
CHECK(add_comment(fp, view->name)); /* force a comment */
|
||||
|
||||
cfg_printx(config, CFG_PRINTER_ONELINE, dumpzone, fp);
|
||||
for (elt = ISC_LIST_HEAD(*list);
|
||||
elt != NULL;
|
||||
elt = ISC_LIST_NEXT(elt, link))
|
||||
{
|
||||
const cfg_obj_t *zconfig = cfg_listelt_value(elt);
|
||||
|
||||
CHECK(isc_stdio_write("zone ", 5, 1, fp, NULL));
|
||||
cfg_printx(zconfig, CFG_PRINTER_ONELINE, dumpzone, fp);
|
||||
CHECK(isc_stdio_write(";\n", 2, 1, fp, NULL));
|
||||
}
|
||||
|
||||
CHECK(isc_stdio_flush(fp));
|
||||
result = isc_stdio_close(fp);
|
||||
@@ -11811,7 +11904,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
if (zconfig == NULL) {
|
||||
/* We're deleting the zone from the database */
|
||||
status = mdb_del(*txnp, dbi, &key, NULL);
|
||||
if (status != 0 && status != MDB_NOTFOUND) {
|
||||
if (status != MDB_SUCCESS && status != MDB_NOTFOUND) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11821,8 +11914,9 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
namebuf, mdb_strerror(status));
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
} else if (status != MDB_NOTFOUND)
|
||||
} else if (status != MDB_NOTFOUND) {
|
||||
commit = ISC_TRUE;
|
||||
}
|
||||
} else {
|
||||
/* We're creating or overwriting the zone */
|
||||
const cfg_obj_t *zoptions;
|
||||
@@ -11857,7 +11951,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(*txnp, dbi, &key, &data, 0);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11875,11 +11969,11 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (!commit || result != ISC_R_SUCCESS)
|
||||
if (!commit || result != ISC_R_SUCCESS) {
|
||||
(void) mdb_txn_abort(*txnp);
|
||||
else {
|
||||
} else {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -11894,8 +11988,10 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -11909,7 +12005,7 @@ nzd_writable(dns_view_t *view) {
|
||||
REQUIRE(view != NULL);
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0, 0, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_txn_begin: %s",
|
||||
@@ -11918,7 +12014,7 @@ nzd_writable(dns_view_t *view) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_dbi_open: %s",
|
||||
@@ -11941,7 +12037,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
|
||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0,
|
||||
flags, &txn);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_txn_begin: %s",
|
||||
@@ -11950,7 +12046,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
}
|
||||
|
||||
status = mdb_dbi_open(txn, NULL, 0, dbi);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_dbi_open: %s",
|
||||
@@ -11961,9 +12057,10 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*txnp = txn;
|
||||
|
||||
cleanup:
|
||||
if (status != 0) {
|
||||
if (txn != NULL)
|
||||
if (status != MDB_SUCCESS) {
|
||||
if (txn != NULL) {
|
||||
mdb_txn_abort(txn);
|
||||
}
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
@@ -11977,38 +12074,34 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
||||
*/
|
||||
static void
|
||||
nzd_env_close(dns_view_t *view) {
|
||||
if (view->new_zone_dbenv != NULL) {
|
||||
const char *dbpath = NULL;
|
||||
isc_boolean_t have_dbpath = ISC_FALSE;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int ret;
|
||||
const char *dbpath = NULL;
|
||||
char dbpath_copy[PATH_MAX];
|
||||
char lockpath[PATH_MAX];
|
||||
int status, ret;
|
||||
|
||||
if (mdb_env_get_path(view->new_zone_dbenv, &dbpath) == 0) {
|
||||
have_dbpath = ISC_TRUE;
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock",
|
||||
dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
}
|
||||
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
view->new_zone_dbenv = NULL;
|
||||
|
||||
if (have_dbpath) {
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not
|
||||
* by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we
|
||||
* reopen the environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
}
|
||||
if (view->new_zone_dbenv == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
status = mdb_env_get_path(view->new_zone_dbenv, &dbpath);
|
||||
INSIST(status == MDB_SUCCESS);
|
||||
snprintf(lockpath, sizeof(lockpath), "%s-lock", dbpath);
|
||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||
|
||||
/*
|
||||
* Database files must be owned by the eventual user, not by root.
|
||||
*/
|
||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||
UNUSED(ret);
|
||||
|
||||
/*
|
||||
* Some platforms need the lockfile not to exist when we reopen the
|
||||
* environment.
|
||||
*/
|
||||
(void) isc_file_remove(lockpath);
|
||||
|
||||
view->new_zone_dbenv = NULL;
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
@@ -12024,7 +12117,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
nzd_env_close(view);
|
||||
|
||||
status = mdb_env_create(&env);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_create failed: %s",
|
||||
@@ -12034,7 +12127,7 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
|
||||
if (view->new_zone_mapsize != 0ULL) {
|
||||
status = mdb_env_set_mapsize(env, view->new_zone_mapsize);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_set_mapsize failed: %s",
|
||||
@@ -12043,9 +12136,8 @@ nzd_env_reopen(dns_view_t *view) {
|
||||
}
|
||||
}
|
||||
|
||||
status = mdb_env_open(env, view->new_zone_db,
|
||||
MDB_NOSUBDIR|MDB_CREATE, 0600);
|
||||
if (status != 0) {
|
||||
status = mdb_env_open(env, view->new_zone_db, DNS_LMDB_FLAGS, 0600);
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||
"mdb_env_open of '%s' failed: %s",
|
||||
@@ -12074,10 +12166,12 @@ nzd_close(MDB_txn **txnp, isc_boolean_t commit) {
|
||||
if (*txnp != NULL) {
|
||||
if (commit) {
|
||||
status = mdb_txn_commit(*txnp);
|
||||
if (status != 0)
|
||||
if (status != MDB_SUCCESS) {
|
||||
result = ISC_R_FAILURE;
|
||||
} else
|
||||
}
|
||||
} else {
|
||||
mdb_txn_abort(*txnp);
|
||||
}
|
||||
*txnp = NULL;
|
||||
}
|
||||
|
||||
@@ -12095,11 +12189,12 @@ nzd_count(dns_view_t *view, int *countp) {
|
||||
REQUIRE(countp != NULL);
|
||||
|
||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
status = mdb_stat(txn, dbi, &statbuf);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_WARNING, "mdb_stat: %s",
|
||||
@@ -12172,8 +12267,9 @@ migrate_nzf(dns_view_t *view) {
|
||||
|
||||
zonelist = NULL;
|
||||
CHECK(cfg_map_get(nzf_config, "zone", &zonelist));
|
||||
if (!cfg_obj_islist(zonelist))
|
||||
if (!cfg_obj_islist(zonelist)) {
|
||||
CHECK(ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
CHECK(nzd_open(view, 0, &txn, &dbi));
|
||||
|
||||
@@ -12224,7 +12320,7 @@ migrate_nzf(dns_view_t *view) {
|
||||
data.mv_size = isc_buffer_usedlength(text);
|
||||
|
||||
status = mdb_put(txn, dbi, &key, &data, MDB_NOOVERWRITE);
|
||||
if (status != 0) {
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
@@ -12253,15 +12349,19 @@ migrate_nzf(dns_view_t *view) {
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
(void) nzd_close(&txn, ISC_FALSE);
|
||||
else
|
||||
} else {
|
||||
result = nzd_close(&txn, commit);
|
||||
}
|
||||
|
||||
if (text != NULL)
|
||||
if (text != NULL) {
|
||||
isc_buffer_free(&text);
|
||||
if (nzf_config != NULL)
|
||||
}
|
||||
|
||||
if (nzf_config != NULL) {
|
||||
cfg_obj_destroy(named_g_addparser, &nzf_config);
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
@@ -13442,11 +13542,6 @@ newzone_cfgctx_destroy(void **cfgp) {
|
||||
|
||||
static isc_result_t
|
||||
generate_salt(unsigned char *salt, size_t saltlen) {
|
||||
size_t i, n;
|
||||
union {
|
||||
unsigned char rnd[256];
|
||||
isc_uint16_t rnd16[128];
|
||||
} rnd;
|
||||
unsigned char text[512 + 1];
|
||||
isc_region_t r;
|
||||
isc_buffer_t buf;
|
||||
@@ -13455,14 +13550,9 @@ generate_salt(unsigned char *salt, size_t saltlen) {
|
||||
if (saltlen > 256U)
|
||||
return (ISC_R_RANGE);
|
||||
|
||||
n = (saltlen + sizeof(isc_uint16_t) - 1) / sizeof(isc_uint16_t);
|
||||
for (i = 0; i < n; i++) {
|
||||
rnd.rnd16[i] = isc_rng_random(named_g_server->sctx->rngctx);
|
||||
}
|
||||
isc_rng_randombytes(named_g_server->sctx->rngctx, salt, saltlen);
|
||||
|
||||
memmove(salt, rnd.rnd, saltlen);
|
||||
|
||||
r.base = rnd.rnd;
|
||||
r.base = salt;
|
||||
r.length = (unsigned int) saltlen;
|
||||
|
||||
isc_buffer_init(&buf, text, sizeof(text));
|
||||
@@ -14423,10 +14513,10 @@ mkey_dumpzone(dns_view_t *view, isc_buffer_t **text) {
|
||||
else if (revoked)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrust revoked");
|
||||
else if (kd.addhd < now)
|
||||
else if (kd.addhd <= now)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrusted since: %s", tbuf);
|
||||
else if (kd.addhd >= now)
|
||||
else if (kd.addhd > now)
|
||||
snprintf(buf, sizeof(buf),
|
||||
"\n\ttrust pending: %s", tbuf);
|
||||
CHECK(putstr(text, buf));
|
||||
@@ -14695,7 +14785,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
if (ptr == NULL)
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
CHECK(isc_parse_uint32(&keepalive, ptr, 10));
|
||||
if (keepalive > 1200)
|
||||
if (keepalive > MAX_TCP_TIMEOUT)
|
||||
CHECK(ISC_R_RANGE);
|
||||
if (keepalive < 1)
|
||||
CHECK(ISC_R_RANGE);
|
||||
@@ -14704,7 +14794,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
if (ptr == NULL)
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
CHECK(isc_parse_uint32(&advertised, ptr, 10));
|
||||
if (advertised > 1200)
|
||||
if (advertised > MAX_TCP_TIMEOUT)
|
||||
CHECK(ISC_R_RANGE);
|
||||
|
||||
result = isc_task_beginexclusive(named_g_server->task);
|
||||
|
||||
@@ -20,6 +20,7 @@
|
||||
#include <isc/stats.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/cache.h>
|
||||
#include <dns/db.h>
|
||||
@@ -394,6 +395,7 @@ init_desc(void) {
|
||||
SET_RESSTATDESC(serverquota, "spilled due to server quota",
|
||||
"ServerQuota");
|
||||
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
||||
SET_RESSTATDESC(priming, "priming queries", "Priming");
|
||||
|
||||
INSIST(i == dns_resstatscounter_max);
|
||||
|
||||
@@ -1614,7 +1616,7 @@ generatexml(named_server_t *server, isc_uint32_t flags,
|
||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
||||
ISC_XMLCHAR "3.10"));
|
||||
ISC_XMLCHAR "3.11"));
|
||||
|
||||
/* Set common fields for statistics dump */
|
||||
dumparg.type = isc_statsformat_xml;
|
||||
@@ -2410,7 +2412,7 @@ generatejson(named_server_t *server, size_t *msglen,
|
||||
/*
|
||||
* These statistics are included no matter which URL we use.
|
||||
*/
|
||||
obj = json_object_new_string("1.4");
|
||||
obj = json_object_new_string("1.5");
|
||||
CHECKMEM(obj);
|
||||
json_object_object_add(bindstats, "json-stats-version", obj);
|
||||
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <isccfg/cfg.h>
|
||||
|
||||
|
||||
+16
-7
@@ -150,6 +150,7 @@ static dns_dispatch_t *dispatchv4 = NULL;
|
||||
static dns_dispatch_t *dispatchv6 = NULL;
|
||||
static dns_message_t *updatemsg = NULL;
|
||||
static dns_fixedname_t fuserzone;
|
||||
static dns_fixedname_t fzname;
|
||||
static dns_name_t *userzone = NULL;
|
||||
static dns_name_t *zname = NULL;
|
||||
static dns_name_t tmpzonename;
|
||||
@@ -943,16 +944,21 @@ setup_system(void) {
|
||||
case AF_INET:
|
||||
if (have_ipv4) {
|
||||
sa->type.sin.sin_port = htons(dnsport);
|
||||
} else {
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
case AF_INET6:
|
||||
if (have_ipv6) {
|
||||
sa->type.sin6.sin6_port = htons(dnsport);
|
||||
} else {
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
fatal("bad family");
|
||||
}
|
||||
INSIST(i < ns_alloc);
|
||||
servers[i++] = *sa;
|
||||
}
|
||||
}
|
||||
@@ -2390,7 +2396,6 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
||||
dns_request_destroy(&request);
|
||||
dns_message_renderreset(updatemsg);
|
||||
dns_message_settsigkey(updatemsg, NULL);
|
||||
/* XXX MPA fix zonename is freed already */
|
||||
send_update(zname, &master_servers[master_inuse]);
|
||||
isc_event_free(&event);
|
||||
return;
|
||||
@@ -2693,13 +2698,17 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
dns_name_init(&master, NULL);
|
||||
dns_name_clone(&soa.origin, &master);
|
||||
|
||||
/*
|
||||
* XXXMPA
|
||||
*/
|
||||
if (userzone != NULL)
|
||||
if (userzone != NULL) {
|
||||
zname = userzone;
|
||||
else
|
||||
zname = name;
|
||||
} else {
|
||||
/*
|
||||
* Save the zone name in case we need to try a second
|
||||
* address.
|
||||
*/
|
||||
dns_fixedname_init(&fzname);
|
||||
zname = dns_fixedname_name(&fzname);
|
||||
dns_name_copy(name, zname, NULL);
|
||||
}
|
||||
|
||||
if (debugging) {
|
||||
char namestr[DNS_NAME_FORMATSIZE];
|
||||
|
||||
@@ -39,9 +39,7 @@
|
||||
dnssec-checkds \- DNSSEC delegation consistency checking tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-checkds\fR\ 'u
|
||||
\fBdnssec\-checkds\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
.HP \w'\fBdnssec\-dsfromkey\fR\ 'u
|
||||
\fBdnssec\-dsfromkey\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
\fBdnssec\-checkds\fR [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-s\ \fR\fB\fIfile\fR\fR] {zone}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-checkds\fR
|
||||
@@ -60,6 +58,12 @@ is specified, then the zone is read from that file to find the DNSKEY records\&.
|
||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&.
|
||||
.RE
|
||||
.PP
|
||||
\-s \fIfile\fR
|
||||
.RS 4
|
||||
Specifies a prepared dsset file, such as would be generated by
|
||||
\fBdnssec\-signzone\fR, to use as a source for the DS RRset instead of querying the parent\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIdig path\fR
|
||||
.RS 4
|
||||
Specifies a path to a
|
||||
|
||||
@@ -42,20 +42,13 @@
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>dnssec-checkds</command>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="req" rep="norepeat">zone</arg>
|
||||
</cmdsynopsis>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>dnssec-dsfromkey</command>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="req" rep="norepeat">zone</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsection><info><title>DESCRIPTION</title></info>
|
||||
@@ -92,6 +85,17 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-s <replaceable class="parameter">file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a prepared dsset file, such as would be generated
|
||||
by <command>dnssec-signzone</command>, to use as a source for
|
||||
the DS RRset instead of querying the parent.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-d <replaceable class="parameter">dig path</replaceable></term>
|
||||
<listitem>
|
||||
|
||||
@@ -33,20 +33,13 @@
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-checkds</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-s <em class="replaceable"><code>file</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-dsfromkey</code>
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||
{zone}
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
@@ -79,6 +72,14 @@
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies a prepared dsset file, such as would be generated
|
||||
by <span class="command"><strong>dnssec-signzone</strong></span>, to use as a source for
|
||||
the DS RRset instead of querying the parent.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
############################################################################
|
||||
# Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -34,7 +34,11 @@ class SECRR:
|
||||
if not rrtext:
|
||||
raise Exception
|
||||
|
||||
fields = rrtext.decode('ascii').split()
|
||||
# 'str' does not have decode method in python3
|
||||
if type(rrtext) is not str:
|
||||
fields = rrtext.decode('ascii').split()
|
||||
else:
|
||||
fields = rrtext.split()
|
||||
if len(fields) < 7:
|
||||
raise Exception
|
||||
|
||||
@@ -89,35 +93,39 @@ class SECRR:
|
||||
# Generate a set of expected DS/DLV records from the DNSKEY RRset,
|
||||
# and report on congruency.
|
||||
############################################################################
|
||||
def check(zone, args, masterfile=None, lookaside=None):
|
||||
def check(zone, args):
|
||||
rrlist = []
|
||||
cmd = [args.dig, "+noall", "+answer", "-t", "dlv" if lookaside else "ds",
|
||||
"-q", zone + "." + lookaside if lookaside else zone]
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
if args.dssetfile:
|
||||
fp = open(args.dssetfile).read()
|
||||
else:
|
||||
cmd = [args.dig, "+noall", "+answer", "-t",
|
||||
"dlv" if args.lookaside else "ds", "-q",
|
||||
zone + "." + args.lookaside if args.lookaside else zone]
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
|
||||
for line in fp.splitlines():
|
||||
rrlist.append(SECRR(line, lookaside))
|
||||
rrlist.append(SECRR(line, args.lookaside))
|
||||
rrlist = sorted(rrlist, key=lambda rr: (rr.keyid, rr.keyalg, rr.hashalg))
|
||||
|
||||
klist = []
|
||||
|
||||
if masterfile:
|
||||
cmd = [args.dsfromkey, "-f", masterfile]
|
||||
if lookaside:
|
||||
cmd += ["-l", lookaside]
|
||||
if args.masterfile:
|
||||
cmd = [args.dsfromkey, "-f", args.masterfile]
|
||||
if args.lookaside:
|
||||
cmd += ["-l", args.lookaside]
|
||||
cmd.append(zone)
|
||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||
else:
|
||||
intods, _ = Popen([args.dig, "+noall", "+answer", "-t", "dnskey",
|
||||
"-q", zone], stdout=PIPE).communicate()
|
||||
cmd = [args.dsfromkey, "-f", "-"]
|
||||
if lookaside:
|
||||
cmd += ["-l", lookaside]
|
||||
if args.lookaside:
|
||||
cmd += ["-l", args.lookaside]
|
||||
cmd.append(zone)
|
||||
fp, _ = Popen(cmd, stdin=PIPE, stdout=PIPE).communicate(intods)
|
||||
|
||||
for line in fp.splitlines():
|
||||
klist.append(SECRR(line, lookaside))
|
||||
klist.append(SECRR(line, args.lookaside))
|
||||
|
||||
if len(klist) < 1:
|
||||
print("No DNSKEY records found in zone apex")
|
||||
@@ -136,7 +144,8 @@ def check(zone, args, masterfile=None, lookaside=None):
|
||||
rr.keyid, SECRR.hashalgs[rr.hashalg]))
|
||||
|
||||
if not found:
|
||||
print("No %s records were found for any DNSKEY" % ("DLV" if lookaside else "DS"))
|
||||
print("No %s records were found for any DNSKEY" %
|
||||
("DLV" if args.lookaside else "DS"))
|
||||
|
||||
return found
|
||||
|
||||
@@ -151,10 +160,6 @@ def parse_args():
|
||||
sbindir = 'bin' if os.name == 'nt' else 'sbin'
|
||||
|
||||
parser.add_argument('zone', type=str, help='zone to check')
|
||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||
help='zone master file')
|
||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||
help='DLV lookaside zone')
|
||||
parser.add_argument('-d', '--dig', dest='dig',
|
||||
default=os.path.join(prefix(bindir), 'dig'),
|
||||
type=str, help='path to \'dig\'')
|
||||
@@ -162,6 +167,12 @@ def parse_args():
|
||||
default=os.path.join(prefix(sbindir),
|
||||
'dnssec-dsfromkey'),
|
||||
type=str, help='path to \'dig\'')
|
||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||
help='zone master file')
|
||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||
help='DLV lookaside zone')
|
||||
parser.add_argument('-s', '--dsset', dest='dssetfile', type=str,
|
||||
help='prepared DSset file')
|
||||
parser.add_argument('-v', '--version', action='version',
|
||||
version=version)
|
||||
args = parser.parse_args()
|
||||
@@ -178,5 +189,5 @@ def parse_args():
|
||||
############################################################################
|
||||
def main():
|
||||
args = parse_args()
|
||||
found = check(args.zone, args, args.masterfile, args.lookaside)
|
||||
found = check(args.zone, args)
|
||||
exit(0 if found else 1)
|
||||
|
||||
+4
-1
@@ -516,7 +516,10 @@ Status will report whether serving of stale answers is currently enabled, disabl
|
||||
.PP
|
||||
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
|
||||
.RS 4
|
||||
Dump the server\*(Aqs security roots and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&.
|
||||
Dump the security roots (i\&.e\&., trust anchors configured via
|
||||
\fBtrusted\-keys\fR,
|
||||
\fBmanaged\-keys\fR, or
|
||||
\fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&.
|
||||
.sp
|
||||
If the first argument is "\-", then the output is returned via the
|
||||
\fBrndc\fR
|
||||
|
||||
+15
-9
@@ -774,9 +774,15 @@
|
||||
<term><userinput>secroots <optional>-</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Dump the server's security roots and negative trust anchors
|
||||
for the specified views. If no view is specified, all views
|
||||
are dumped.
|
||||
Dump the security roots (i.e., trust anchors
|
||||
configured via <command>trusted-keys</command>,
|
||||
<command>managed-keys</command>, or
|
||||
<command>dnssec-validation auto</command>) and negative trust
|
||||
anchors for the specified views. If no view is specified, all
|
||||
views are dumped. Security roots will indicate whether
|
||||
they are configured as trusted keys, managed keys, or
|
||||
initializing managed keys (managed keys that have not yet
|
||||
been updated by a successful key refresh query).
|
||||
</para>
|
||||
<para>
|
||||
If the first argument is "-", then the output is
|
||||
@@ -963,15 +969,15 @@
|
||||
<listitem>
|
||||
<para>
|
||||
When called without arguments, display the current
|
||||
values of the <command>tcp-initial-timeout</command>,
|
||||
values of the <command>tcp-initial-timeout</command>,
|
||||
<command>tcp-idle-timeout</command>,
|
||||
<command>tcp-keepalive-timeout</command> and
|
||||
<command>tcp-advertised-timeout</command> options.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+15
-9
@@ -657,9 +657,15 @@
|
||||
<dt><span class="term"><strong class="userinput"><code>secroots [<span class="optional">-</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Dump the server's security roots and negative trust anchors
|
||||
for the specified views. If no view is specified, all views
|
||||
are dumped.
|
||||
Dump the security roots (i.e., trust anchors
|
||||
configured via <span class="command"><strong>trusted-keys</strong></span>,
|
||||
<span class="command"><strong>managed-keys</strong></span>, or
|
||||
<span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust
|
||||
anchors for the specified views. If no view is specified, all
|
||||
views are dumped. Security roots will indicate whether
|
||||
they are configured as trusted keys, managed keys, or
|
||||
initializing managed keys (managed keys that have not yet
|
||||
been updated by a successful key refresh query).
|
||||
</p>
|
||||
<p>
|
||||
If the first argument is "-", then the output is
|
||||
@@ -822,15 +828,15 @@
|
||||
<dd>
|
||||
<p>
|
||||
When called without arguments, display the current
|
||||
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
||||
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
||||
<span class="command"><strong>tcp-idle-timeout</strong></span>,
|
||||
<span class="command"><strong>tcp-keepalive-timeout</strong></span> and
|
||||
<span class="command"><strong>tcp-advertised-timeout</strong></span> options.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
When called with arguments, update these values. This
|
||||
allows an administrator to make rapid adjustments when
|
||||
under a denial of service attack. See the descriptions of
|
||||
these options in the BIND 9 Administrator Reference Manual
|
||||
for details of their use.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><strong class="userinput"><code>thaw [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
|
||||
|
||||
@@ -1,19 +1,17 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id: clean.sh,v 1.6 2007/09/26 03:22:44 marka Exp $
|
||||
|
||||
#
|
||||
# Clean up after tests.
|
||||
#
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f */named.memstats
|
||||
rm -f */named.conf
|
||||
rm -f ns1/named.conf
|
||||
rm -f */named.run
|
||||
rm -f ns*/named.lock
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.3;
|
||||
notify-source 10.53.0.3;
|
||||
transfer-source 10.53.0.3;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.3; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "root.hint";
|
||||
};
|
||||
@@ -0,0 +1,8 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
. NS ns1.
|
||||
ns1. A 10.53.0.1
|
||||
@@ -212,7 +212,7 @@ echo "I:testing with 'minimal-responses yes;'"
|
||||
minimal=yes
|
||||
dotests
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-responses no"
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -230,7 +230,7 @@ if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-any yes"
|
||||
cp ns1/named3.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -266,7 +266,7 @@ echo "I:testing with 'minimal-responses no-auth;'"
|
||||
minimal=no-auth
|
||||
dotests
|
||||
|
||||
echo "I:reconfiguring server"
|
||||
echo "I:reconfiguring server: minimal-responses no-auth-recursive"
|
||||
cp ns1/named4.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
@@ -297,5 +297,30 @@ if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:reconfiguring server: minimal-responses no"
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing NS handling in ANY responses (authoritative) ($n)"
|
||||
ret=0
|
||||
$DIG -t ANY rt.example @10.53.0.1 -p 5300 > dig.out.$n || ret=1
|
||||
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||
if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing NS handling in ANY responses (recursive) ($n)"
|
||||
ret=0
|
||||
$DIG -t ANY rt.example @10.53.0.3 -p 5300 > dig.out.$n || ret=1
|
||||
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||
if [ $ret -eq 1 ] ; then
|
||||
echo "I: failed"; status=1
|
||||
fi
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -10,4 +10,4 @@ my $target = shift;
|
||||
my $file = shift;
|
||||
my $mtime = time - (stat $file)[9];
|
||||
die "bad mtime $mtime"
|
||||
unless abs($mtime - $target) < 3;
|
||||
unless abs($mtime - $target) < 10;
|
||||
|
||||
@@ -43,7 +43,7 @@ check_stderr() {
|
||||
[ -s err.$n ] || return 0
|
||||
fi
|
||||
echo "D:stderr did not match '$err'"
|
||||
sed 's/^/D:/' err
|
||||
sed 's/^/D:/' err.$n
|
||||
fail
|
||||
}
|
||||
|
||||
|
||||
@@ -254,7 +254,7 @@ def create_response(msg):
|
||||
def sigterm(signum, frame):
|
||||
print ("Shutting down now...")
|
||||
os.remove('ans.pid')
|
||||
running = 0
|
||||
running = False
|
||||
sys.exit(0)
|
||||
|
||||
############################################################################
|
||||
@@ -270,8 +270,17 @@ sock = 5300
|
||||
|
||||
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||
query4_socket.bind((ip4, sock))
|
||||
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||
query6_socket.bind((ip6, sock))
|
||||
|
||||
havev6 = True
|
||||
try:
|
||||
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||
try:
|
||||
query6_socket.bind((ip6, sock))
|
||||
except:
|
||||
query6_socket.close()
|
||||
havev6 = False
|
||||
except:
|
||||
havev6 = False
|
||||
|
||||
ctrl_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||
ctrl_socket.bind((ip4, sock + 1))
|
||||
@@ -284,14 +293,18 @@ pid = os.getpid()
|
||||
print (pid, file=f)
|
||||
f.close()
|
||||
|
||||
running = 1
|
||||
running = True
|
||||
|
||||
print ("Listening on %s port %d" % (ip4, sock))
|
||||
print ("Listening on %s port %d" % (ip6, sock))
|
||||
if havev6:
|
||||
print ("Listening on %s port %d" % (ip6, sock))
|
||||
print ("Control channel on %s port %d" % (ip4, sock + 1))
|
||||
print ("Ctrl-c to quit")
|
||||
|
||||
input = [query4_socket, query6_socket, ctrl_socket]
|
||||
if havev6:
|
||||
input = [query4_socket, query6_socket, ctrl_socket]
|
||||
else:
|
||||
input = [query4_socket, ctrl_socket]
|
||||
|
||||
while running:
|
||||
try:
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
dnssec-lookaside . trust-anchor dlv.example.com;
|
||||
};
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2005, 2007, 2010-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005, 2007, 2010-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -135,6 +135,7 @@ done
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking options allowed in inline-signing slaves ($n)"
|
||||
ret=0
|
||||
l=`$CHECKCONF bad-dnssec.conf 2>&1 | grep "dnssec-dnskey-kskonly.*requires inline" | wc -l`
|
||||
@@ -327,5 +328,29 @@ diff good.zonelist checkconf.out$n > diff.out$n || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside auto;' generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF warn-dlv-auto.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "dnssec-lookaside 'auto' is no longer supported" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.isc.org;' generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF warn-dlv-dlv.isc.org.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "dlv.isc.org has been shut down" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.example.com;' doesn't generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF good-dlv-dlv.example.com.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
[ -s checkconf.out$n ] && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -1,12 +1,10 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
rm -f checkds.*
|
||||
rm -f ns*/named.lock
|
||||
|
||||
@@ -1,13 +1,11 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
my $arg;
|
||||
my $ext;
|
||||
my $file;
|
||||
|
||||
@@ -1,14 +1,11 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012, 2013, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012, 2013, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id$
|
||||
|
||||
|
||||
while [ "$#" != 0 ]; do
|
||||
case $1 in
|
||||
+*) shift ;;
|
||||
|
||||
@@ -0,0 +1,121 @@
|
||||
; File written on Thu Oct 5 23:44:34 2017
|
||||
; dnssec_signzone version 9.12.0a1
|
||||
prep.example. 300 IN SOA ns1.prep.example. hostmaster.prep.example. (
|
||||
1 ; serial
|
||||
2000 ; refresh (33 minutes 20 seconds)
|
||||
2000 ; retry (33 minutes 20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
300 RRSIG SOA 8 2 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
1fX0z7Swu4gMPews/ZE8bzNg+JXNedFBDGIH
|
||||
PTSfVQtVLIvRWpME+PylX7MdVMZE/PST+x4/
|
||||
mWyveyjetEOo7/7aQL236FfI0y6TxQFy7HwC
|
||||
FMieqoQCUluuKOvToxg4vUp4GOdlUGbqC63h
|
||||
DbX5Z37VptJXLkt4niF4Kl2iD+U9/bk7HAEU
|
||||
4zDiKroYnusGKfVB9xAWddzoHdLxhVuPi7ut
|
||||
328suPdgX0bfs7uB+y4cikhGzAmPpNMlGHju
|
||||
qYG74NcFGQNutLB7ayx/m87t7mTty7jbNKm3
|
||||
QWJSPf5IR8/kmzAi8HMnapY5vUmm+hX8JOfU
|
||||
UtH7i0iEsUqRbEwu5A== )
|
||||
300 NS ns1.prep.example.
|
||||
300 RRSIG NS 8 2 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
u5sU2cfqNqIyCLw18ZNnFw28/GyRt0EOiPYS
|
||||
dygmpfMDrvDaxjiiai8zWYjnl/E3qzVH9Zku
|
||||
07lEDORZdVb0uCDe1NynjAyw4AHps85cAwVc
|
||||
8HTSbzdVZsQTELpunYFJffh24PDr9unw7KOY
|
||||
jzTP6qNedJ1uM54TOr177zfmBh7N2fkAoGyV
|
||||
NjvTKrlgDYGNIn8/YMgHb4sNgyfe54MYY00f
|
||||
kehVxfKnRCgDsbJ0Pk6jhBMCQWvOh8jG8WyV
|
||||
ElAa/eMqlxUC1idF8ydWefjsI/7lPcjSalw9
|
||||
qZw4CDCLHHZy0TOSmCYRRZuIeVXzBfDPJyi4
|
||||
2A3iLntKFJ4AOLFMJg== )
|
||||
3600 NSEC ns1.prep.example. NS SOA RRSIG NSEC DNSKEY
|
||||
3600 RRSIG NSEC 8 2 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
Aed99/jdG82YAkKVWjoKOsAGtB3JnyKkCaAq
|
||||
zgMrYkXU41y3KDCAmGzooGPQY7NN+WxX7FJ2
|
||||
1nXkgljma/azgpsbi9ssneFtv7PPFClVmN+u
|
||||
j+mM4MK/ZR7eJOsMqETg4PAO5VAh6c/GVmyA
|
||||
RD/m6EhJVZEjPfLWbDoC4hVAgem7DP/NMjyI
|
||||
GfztpDjMmyLQyv6tL+UEXSJHGp3ZEa5Z5i7X
|
||||
Nl/bRTUlZs7L4rTgoqHv6LEmsXKAf9rZYq4b
|
||||
eP6GF9I1Ry41MfHLc7lPUmtR38ErEsM5uGzw
|
||||
trCQYEFhuRWUBxZ8OSL2EZK9rUBXZX+cwK/8
|
||||
ZP7mIfDfljkXPQcmow== )
|
||||
3600 DNSKEY 256 3 8 (
|
||||
AwEAAfMzj6aZIgZDVcpH1pKOtq998E85+nEY
|
||||
YJa0lLS8+QTCC1Efke8GLwsXT0IPTuwnOuXM
|
||||
RjySirab0NuEr69T8KP/43YxcRdmCg89mjjN
|
||||
szoVPPstC9xBKVOc0pRMDF7sfsTrSye3RY7+
|
||||
Z6uZEH5FOAkz2hNbJJHOn4HpNUhLPJGRauhf
|
||||
0evamwUmQ/mlhkVW5q4WmqPCDMNY3K6XtkEm
|
||||
cvm8n9ZCXC9Z5AX6KpynujzLdKyxpdGqUk6r
|
||||
lavp9ILPpRKoTZDX+2q1pDgP5cDndwtgNSvU
|
||||
DBQZoD0psS2cyB3PHo+dPwwpEyM//ZSKsH9m
|
||||
e85Ti0413TOWFyFd/jUOUA8=
|
||||
) ; ZSK; alg = RSASHA256 ; key id = 19260
|
||||
3600 DNSKEY 257 3 8 (
|
||||
AwEAAbV8X06Qvk350aZ6eZ1d7WbT1H/Y0Sv7
|
||||
qAdbk5fbYIKpMvZ8D9xqoTHgD0z0uCgWWIcm
|
||||
/xyKBfmax76oLwMBpR/kdtuJz0irgFITnJCH
|
||||
pEfR9AJ/Mfm7NyMglq+/39I03E1/LXvpXQLG
|
||||
tg+Mo/2CUE5sbG31jmPNK/2J8RMESkIi87fW
|
||||
azZU/oyUEtECE5PGbdyw+4PacAsXNjnwl30T
|
||||
aatL277wX4pt+IUPdE6EIph3t+dxXJ7OpHgW
|
||||
8g+YSHLlCImLVapdg3oD/cs6ncaBq9z7la5Y
|
||||
dHNw2QAIAvQ11EsonrkonPqO6zNVZAVdT2VB
|
||||
X5YzGAoCFUvbCvlnl2a7SxM=
|
||||
) ; KSK; alg = RSASHA256 ; key id = 65482
|
||||
3600 RRSIG DNSKEY 8 2 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
pPw81pJ3PeF+tqEswTul9N8Qsl9JKgK4v8SV
|
||||
lPfP0pnlMBMbtMFFkx5ZmhQg3Z3U8SdE64Bt
|
||||
C5St3qItyyKdTQ0Rbm9mfV6twxDB8lVry8F7
|
||||
Pv7gJmmcWzBcbLGcrXIrVNSZhigkemQXTElj
|
||||
P8y1j7kaNFWBWbDMn7KesiZ9BiC6sqvuKa3R
|
||||
wSofjwXTESspWZP0NtXr5ymaBIMR9UtNj5Wh
|
||||
jm1+tg6BxNBKxhCHlSC0ltPS/qq9J1ZUmtJz
|
||||
sj/EAFfPVJVuEveebMvi1oDWPTgajO9+EHl4
|
||||
ELrgnQHCgaybMzbpd/A5+Tr1hQkv48I8Mb0/
|
||||
8LJ2/6xrvJm64yRteg== )
|
||||
3600 RRSIG DNSKEY 8 2 3600 (
|
||||
20171105054434 20171006054434 65482 prep.example.
|
||||
WeIWiC9SnBe2+UocVjpap62O8Rz+iljwJiu9
|
||||
VlGUwct3Vydq4/4FVAKdPklXV5cYbBLhO2MB
|
||||
3R4toX8RNU/0Ny8DnugQzLKvVfg0xoyU/UAJ
|
||||
k4aWa/vPivSLGouLQPiNp71bdXN4LB/2xmzu
|
||||
cPYXzS9ePpwCOp/9JLoNjBSMQkfjfWAcaNtj
|
||||
1DKDmHHL1sPMizninxSJLQOAKb+JwUAjAkOM
|
||||
O1JqwkB12/IZuzxN5hly+uNsbFFxPzQkcnJ4
|
||||
5bhzxuh5D/JRXW0nF5aO4aR+9X+lSUpDJQZ1
|
||||
5fOt1cybZCn/ag68RA92zrnisdbrggJGS003
|
||||
wn/VKbLVfFj3eQrfNA== )
|
||||
ns1.prep.example. 300 IN A 1.1.1.1
|
||||
300 RRSIG A 8 3 300 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
QUyDyJVk3JGEq+VTZtY3firzsRqOA0LUm3Tf
|
||||
/fnemQBeOlMda2ErA7DqYVriIGfM8jph416E
|
||||
YX8SKAZXGEAlsEbC9cWBVyc5TYH6tZ43sV51
|
||||
55kGTiUY92NnrH10Q+m2SLAEEaKCA/cgBwOR
|
||||
tN2Wb1meHgiLbGYN2LbANfDQzoEk4AYAgT6r
|
||||
wDKVVg/V9Ed7JnCnBQc9MN9+LQ3h4NBGUiEY
|
||||
mr7HX2w+yzqcGFNLI1aFPe2IwFt120QPLyyl
|
||||
cZgc6FUBX4YCnWoCb0aFyyOT76AQkKF5YBRn
|
||||
gAv6S8q1pZ/0B5w4gjaLEGlts3LG0bxZ1GJd
|
||||
gCQMEhgYgyXUchTtZA== )
|
||||
3600 NSEC prep.example. A RRSIG NSEC
|
||||
3600 RRSIG NSEC 8 3 3600 (
|
||||
20171105054434 20171006054434 19260 prep.example.
|
||||
rDWN40u1a3DSzWOrS+4YR2XOxaem0BAQ/glN
|
||||
QkXNDew1WsZo3fe0IHIhDKlJ/5MJAfAHq8Xs
|
||||
A5UGUw2efoNAN/0LuWsI/9IPm4dwQOXiTCly
|
||||
uxugXf5islPYyvn1Z14ay/7/2P3W6HZknXzo
|
||||
lZFpwqfFZQCxz7c/1aH+2ntAMeqx8LHuewSr
|
||||
Rz/sLsSiCcZQ6NMWnZdoC5SGy4CTcIIPPS8z
|
||||
9dQ6QYTC5iq4MKRfyJUyvODyU9be4e6jbo5b
|
||||
mjRcov4ttbImhD5jrLAZIfjO6DSazGNVFf/x
|
||||
6rjxjrc8SISPkt2xYwcOlYch9OZuoH86wcZu
|
||||
3Don6yAnLDYDrZylAA== )
|
||||
@@ -0,0 +1,2 @@
|
||||
prep.example. IN DS 65482 8 1 F3673708FBADDEC3EB55933E2E393ACE85EAC2BB
|
||||
prep.example. IN DS 65482 8 2 51A7C97AAC42803DA515D1CAFEE28031A5018F6345F12F4B6C1B6D20 02B59820
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -171,6 +171,15 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:checking with prepared dsset file ($n)"
|
||||
ret=0
|
||||
$CHECKDS -f prep.example.db -s prep.example.ds.db prep.example > checkds.out.$n || ret=1
|
||||
grep 'SHA-1.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||
grep 'SHA-256.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
if [ $status = 0 ]; then $SHELL clean.sh; fi
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -186,6 +186,19 @@ else
|
||||
}
|
||||
fi
|
||||
|
||||
#
|
||||
# Useful functions in test scripts
|
||||
#
|
||||
|
||||
# nextpart: read everything that's been appended to a file since the
|
||||
# last time 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "NR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
|
||||
@@ -58,6 +58,8 @@ MDIG=$TOP/Build/$VSCONF/mdig@EXEEXT@
|
||||
NZD2NZF=$TOP/Build/$VSCONF/named-nzd2nzf@EXEEXT@
|
||||
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||
FEATURETEST=$TOP/Build/$VSCONF/feature-test@EXEEXT@
|
||||
SAMPLEUPDATE=$TOP/Build/$VSCONF/update@EXEEXT@
|
||||
|
||||
# to port WIRETEST=$TOP/Build/$VSCONF/wire_test@EXEEXT@
|
||||
|
||||
# this is given as argument to native WIN32 executables
|
||||
@@ -176,6 +178,19 @@ echoinfo () {
|
||||
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
#
|
||||
# Useful functions in test scripts
|
||||
#
|
||||
|
||||
# nextpart: read everything that's been appended to a file since the
|
||||
# last time 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "NR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
@@ -211,6 +226,7 @@ export RANDFILE
|
||||
export RESOLVE
|
||||
export RNDC
|
||||
export RRCHECKER
|
||||
export SAMPLEUPDATE
|
||||
export SIGNER
|
||||
export SUBDIRS
|
||||
export TESTSOCK6
|
||||
|
||||
@@ -24,8 +24,8 @@ options {
|
||||
dnssec-must-be-secure mustbesecure.example yes;
|
||||
minimal-responses no;
|
||||
|
||||
nta-lifetime 10s;
|
||||
nta-recheck 7s;
|
||||
nta-lifetime 12s;
|
||||
nta-recheck 9s;
|
||||
|
||||
# Note: We only reference the bind.keys file here to confirm that it
|
||||
# is *not* being used. It contains the real root key, and we're
|
||||
|
||||
@@ -1722,7 +1722,7 @@ echo "I: waiting for NTA rechecks/expirations"
|
||||
# fakenode.secure.example should both be lifted, but badds.example
|
||||
# should still be going.
|
||||
#
|
||||
$PERL -e 'my $delay = '$start' + 8 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$PERL -e 'my $delay = '$start' + 10 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$DIG $DIGOPTS b.secure.example. a @10.53.0.4 > dig.out.ns4.test$n.8 || ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns4.test$n.8 > /dev/null && ret=1
|
||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.8 > /dev/null || ret=1
|
||||
@@ -1742,7 +1742,7 @@ ret=0
|
||||
# it should still be NTA'd, but badds.example used the default
|
||||
# lifetime of 10s, so it should revert to SERVFAIL now.
|
||||
#
|
||||
$PERL -e 'my $delay = '$start' + 11 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
$PERL -e 'my $delay = '$start' + 13 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||
# check nta table
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 nta -d > rndc.out.ns4.test$n._11
|
||||
lines=`grep " expiry " rndc.out.ns4.test$n._11 | wc -l`
|
||||
@@ -2501,9 +2501,15 @@ do
|
||||
done;
|
||||
grep "ANSWER: 3," dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:nsec3 chain generation not complete"; fi
|
||||
sleep 3
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.2 > dig.out.ns2.test$n || ret=1
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||
s2=`awk '$4 == "SOA" { print $7}' dig.out.ns2.test$n`
|
||||
for i in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||
s3=`awk '$4 == "SOA" { print $7}' dig.out.ns3.test$n`
|
||||
test "$s2" = "$s3" && break
|
||||
sleep 1
|
||||
done
|
||||
$PERL ../digcomp.pl dig.out.ns2.test$n dig.out.ns3.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
|
||||
@@ -13,6 +13,7 @@
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
#include <dns/diff.h>
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
#include <isc/eventclass.h>
|
||||
#include <isc/netaddr.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/byaddr.h>
|
||||
#include <dns/db.h>
|
||||
|
||||
@@ -36,7 +36,6 @@ usage() {
|
||||
fprintf(stderr, "args:\n");
|
||||
fprintf(stderr, " --edns-version\n");
|
||||
fprintf(stderr, " --enable-dnsrps\n");
|
||||
fprintf(stderr, " --enable-filter-aaaa\n");
|
||||
fprintf(stderr, " --gethostname\n");
|
||||
fprintf(stderr, " --gssapi\n");
|
||||
fprintf(stderr, " --have-dlopen\n");
|
||||
@@ -63,14 +62,6 @@ main(int argc, char **argv) {
|
||||
#endif
|
||||
}
|
||||
|
||||
if (strcmp(argv[1], "--enable-filter-aaaa") == 0) {
|
||||
#ifdef ALLOW_FILTER_AAAA
|
||||
return (0);
|
||||
#else
|
||||
return (1);
|
||||
#endif
|
||||
}
|
||||
|
||||
if (strcmp(argv[1], "--edns-version") == 0) {
|
||||
#ifdef DNS_EDNS_VERSION
|
||||
printf("%d\n", DNS_EDNS_VERSION);
|
||||
|
||||
@@ -1,110 +1,125 @@
|
||||
; File written on Thu May 1 12:16:00 2014
|
||||
; dnssec_signzone version 9.8.5-P1
|
||||
signed. 120 IN SOA ns.utld. hostmaster.ns.utld. (
|
||||
; File written on Mon Oct 16 09:16:28 2017
|
||||
; dnssec_signzone version 9.11.2
|
||||
signed. 120 IN SOA ns.signed. hostmaster.ns.signed. (
|
||||
1 ; serial
|
||||
3600 ; refresh (1 hour)
|
||||
1200 ; retry (20 minutes)
|
||||
604800 ; expire (1 week)
|
||||
60 ; minimum (1 minute)
|
||||
)
|
||||
120 RRSIG SOA 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BEFlElqfz17JeL/ISbgEz7yenWy2QjhgdMUx
|
||||
VDLBx3+Eiz1nyB1CpWw= )
|
||||
120 NS ns.utld.
|
||||
120 RRSIG NS 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BC4nYbfEyROe0CZPj/cHRl7BCIc0MbzpDBwz
|
||||
an8bPTHrbaHpC8rdX54= )
|
||||
120 RRSIG SOA 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BJDbUrXS4UzBrTeNUMA0sSGYd+h9M5d8qzsE
|
||||
q7RJyDtUNJIwP5vAnSQ= )
|
||||
120 NS ns.signed.
|
||||
120 RRSIG NS 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGoYuOkkcTAYnym27q2BgqkjUgP/0/Tip1yc
|
||||
txRS1D0CipTUZhCNrXc= )
|
||||
120 MX 10 mx.signed.
|
||||
120 RRSIG MX 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BEp7iUXEnBCXVtKHcIRfkiK34J83ZbC3g7qQ
|
||||
XY+wdpJ7TxavEBtZO94= )
|
||||
120 RRSIG MX 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BOUPCSEEJ8dZ0oWeiYEvGIonjagvM1OS+mEY
|
||||
i5VUmysn7kArWqeFERs= )
|
||||
60 NSEC a-only.signed. NS SOA MX RRSIG NSEC DNSKEY
|
||||
60 RRSIG NSEC 3 1 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BAjeMFAXkfL9AypyihxU7lvhGCENKAwpoGt6
|
||||
WYd6G0kb6zdpZ/AR1GQ= )
|
||||
60 RRSIG NSEC 3 1 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BBzvCsFw4EgfrIsFOu5IjP2gncm8dntwHaMD
|
||||
IeJ6g6s7IOwFT5nyrOU= )
|
||||
120 DNSKEY 256 3 3 (
|
||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
||||
GimMrtxmA5Wf1xoJ
|
||||
) ; key id = 12955
|
||||
BPXo3mJOeCCuorn7Hc7bxR3QDHrJvq9gUpPS
|
||||
s8QYF3eiSpB97c8Br7fFzFYHQCJWWnCtpt1E
|
||||
h7SveJSl1ASNl9W2KE6hDNXfDX+ixDOtFZ/7
|
||||
PCh/obX36VK86EH+ZBNLxxEy9tHHCGO08zy8
|
||||
3lWI3E5bk9a1sks2dy6hbQfMmyXWI5QwYS9D
|
||||
j5Vs5yeUQ5e6SPmIqgqpn6VnDtAIfR2My7/r
|
||||
/Jgf73gpZugZmn6wDbzNCyGIvtOJCHAY2OEg
|
||||
ZfACKVdJrXZ42NKcJCgSTd1xY81UyMI9QAMq
|
||||
64Lx/tENCo1GKBCk/1HMdiO6WKeXCJd1SYzN
|
||||
VM+n4fRzEkmVT9wfyiSmoq6SxjeqrRebDz8G
|
||||
42d4lsm2/0bmOlle+fva7LwtGOaS+tBqtD8K
|
||||
kexFaixL5iY+LB0Q
|
||||
) ; ZSK; alg = DSA ; key id = 17876
|
||||
120 DNSKEY 257 3 3 (
|
||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
||||
GimMrtxmA5Wf1xoJ
|
||||
) ; key id = 12956
|
||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BG/sW/I/ZVcUCjGfAicxv4kYLLYoMZlivDqU
|
||||
V3GfAXR5Bp69ywKp1OA= )
|
||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
||||
20140501011600 12956 signed.
|
||||
BAoQwXiKVoWwY+IDfzRndz9ndLPTSShDHpxS
|
||||
Z9+uTx+KCPzUsZYQy4k= )
|
||||
BOOhXnn+YV6RQ+jRPdayrnC2cd9x5P77c1/6
|
||||
Ev41qaWl1N7QRDXYh7VDS1UowoPbvQOvgQU0
|
||||
X7+zKWrB8UQcdsUe96IH/wPab1qkJlKanZni
|
||||
uFdB/2sTvQ6yabIC41dItnGeuN9VY1qwCa7T
|
||||
4QFRVYyDPKgxo7MRLq9YoUN8RTcB6lY1BH9Z
|
||||
QgcHZljAFVgU1Zc/6DZlQeBZyJafwIR+I7Eq
|
||||
Oe+rR44ZeD5JRgI1OwGyw/b1wKUxFhM+4XJi
|
||||
i8mQ1mrvzZ27iQbYP4WEzaskU6P5X+nPrTFi
|
||||
tLEaPugt8Oe7+lHLjpHvHzSOJZ5Radfiqgzg
|
||||
GGOzj1qmLfKLdRmp4VuBQ+1kguiz9D3ev89d
|
||||
pzP7dYHuSdCjc9X0fLmPjU1xD6RyLCDEmUm7
|
||||
eeRP55SiTiQCzJFr
|
||||
) ; KSK; alg = DSA ; key id = 3746
|
||||
120 RRSIG DNSKEY 3 1 120 (
|
||||
20820519023008 20140501011600 3746 signed.
|
||||
BFuLN7ACQrD6/3WaieXRD1JpSXW9s+/xCZ1x
|
||||
0ihUT1iKNvJS8F4Pafc= )
|
||||
120 RRSIG DNSKEY 3 1 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BN+8hbh1FGTNqHds0In57dPr5fVRU/P28dZa
|
||||
zIP19bAwTH/ZvgrqUF0= )
|
||||
a-only.signed. 120 IN NS 1.0.0.1.signed.
|
||||
60 NSEC aaaa-only.signed. NS RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BBRjTWMwkjpanDw386nblW6fwyliYRUeNNo+
|
||||
OHwhqHXXd4bathApttg= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BHpGpjMihpoIykHTpK1XmkVn0jqSST3/K6Fx
|
||||
vTaIb24rpkTriaXxChM= )
|
||||
aaaa-only.signed. 120 IN AAAA 2001:db8::2
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BDukZxGM62Wmk9JE7F5etkcX4LZyFLK0YS0H
|
||||
CF0lovOlBeK5zLgi/MA= )
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BOvYax/3CDnEKTtbc6zoP4hYwhMe5SoXZh0w
|
||||
muzBWw9bEH+Bdt1ZEQ4= )
|
||||
60 NSEC dual.signed. AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BH1TJpK7j1Gu01hb2PimefFISv59NDLfZ9Gr
|
||||
ojpnjDQNV6bA7HcHeEM= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BIqxE79TUnT2DUuocTitGhTNGnLs0+3sLJdz
|
||||
8haJbyH8pig1h7mqimU= )
|
||||
dual.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BBIDPDxbSm3X/Xf5xh/MYIkAvZ9CWpEzSwbM
|
||||
Pks77CGb4rW8IF8WXxs= )
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BIGL70eEIGVDW0gcYpEWgCFv4ne14hutQCMh
|
||||
gQ6kcEbl2qszosJA60E= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BHKD6egOF6e2DfY7+iPNDPcMS6TdU8/OCm8u
|
||||
OYjmr11t5cI8S0R1Iqk= )
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BCmwk+ng/x1O7MhheK8MgAXYFVDDbyiZ76RV
|
||||
iwQrPRm0ThNRtsQU+UY= )
|
||||
60 NSEC mx.signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BHeXsjvM4Bmr/Ih4eDgR9VTC7R/UFlz5ns+g
|
||||
7LPl+H9Oe6zGnM5rGOs= )
|
||||
mx.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BAq3t2X4XDI/dIofEkALZsNn1ezNWDYFH0M2
|
||||
2GI5F0JHr/iZPlAzRbk= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BFts4Mon2FQaLQb6kPOKTEFkHaPIE1xUgrI6
|
||||
qV8tEaAyFXfhH4su6Y0= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BLlLAIHF4SX/eWMCkUvj0XTFmaOp3xnifqkL
|
||||
nSWOAqtzJ5fwAdbNBdM= )
|
||||
ns.signed. 120 IN A 10.53.0.1
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BJ+Wll7VfNEjM4EfLY2rlx74oIwKRg9pjcJO
|
||||
Zxt6GHQIJ2D6EfyMZ00= )
|
||||
120 AAAA fd92:7065:b8e:ffff::1
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGT/agHn4qcHzLV2hYcGeLJ6Tz1to9sTB8LI
|
||||
lMwkV/KUu6UO7yvrnYk= )
|
||||
60 NSEC signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
||||
20140501011600 12955 signed.
|
||||
BCQWnlB8hrID+v5xG/o8t8E+YDb3Fz7Qodmw
|
||||
kBQ+ZwyIeLOoH2+as5A= )
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BNe3XmEGd/xxoh8FN3T3V9G1enCzNQJ7l3G+
|
||||
D3QPrp7mYtPAGMxCLlc= )
|
||||
mx.signed. 120 IN A 1.0.0.3
|
||||
120 RRSIG A 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BMlIQp1acUSUvgzV1CWlM0+cS1bGkFsbS6HQ
|
||||
d0S6TbNV+uNw0S1q0Dk= )
|
||||
120 AAAA 2001:db8::3
|
||||
120 RRSIG AAAA 3 2 120 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BGtSuYQF7sRVT5OdVHPJjm0PERzSp4v+d/DP
|
||||
Vp2UD0vSVSr3Vj2Wi4M= )
|
||||
60 NSEC ns.signed. A AAAA RRSIG NSEC
|
||||
60 RRSIG NSEC 3 2 60 (
|
||||
20820519023008 20140501011600 17876 signed.
|
||||
BMzQWws37wYfHvLnqgvjd+j5dkzBb2RYhrQk
|
||||
ykM0GnTAR6ZpmgQO6jc= )
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
$FEATURETEST --enable-filter-aaaa || {
|
||||
echo "I:This test requires --enable-filter-aaaa at compile time." >&2
|
||||
exit 255
|
||||
}
|
||||
exit 0
|
||||
@@ -35,6 +35,19 @@ PIDFILE="${THISDIR}/${CONFDIR}/named.pid"
|
||||
myRNDC="$RNDC -c ${THISDIR}/${CONFDIR}/rndc.conf"
|
||||
myNAMED="$NAMED -c ${THISDIR}/${CONFDIR}/named.conf -m record,size,mctx -T clienttest -T nosyslog -d 99 -X named.lock -U 4"
|
||||
|
||||
# Test given condition. If true, test again after a second. Used for testing
|
||||
# filesystem-dependent conditions in order to prevent false negatives caused by
|
||||
# directory contents not being synchronized immediately after rename() returns.
|
||||
test_with_retry() {
|
||||
if test "$@"; then
|
||||
sleep 1
|
||||
if test "$@"; then
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
waitforpidfile() {
|
||||
for _w in 1 2 3 4 5 6 7 8 9 10
|
||||
do
|
||||
@@ -48,9 +61,10 @@ n=0
|
||||
|
||||
cd $CONFDIR
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (named -g + only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (named -g + only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -58,9 +72,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -79,14 +93,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -103,14 +117,14 @@ then
|
||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -129,14 +143,14 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
# Stop the server and run through a series of tests with various config
|
||||
# files while controlling the stop/start of the server.
|
||||
@@ -155,9 +169,10 @@ fi
|
||||
|
||||
status=0
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:testing log file validity (only plain files allowed) ($n)"
|
||||
echo "I:testing log file validity (only plain files allowed)"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing plain file (named -g) ($n)"
|
||||
# First run with a known good config.
|
||||
echo > $PLAINFILE
|
||||
cp $PLAINCONF named.conf
|
||||
@@ -165,9 +180,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing plain file succeeded"
|
||||
echo "I: testing plain file succeeded"
|
||||
else
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I: testing plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -186,14 +201,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
echo "I: testing directory as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
echo "I: skipping directory test (unable to create directory)"
|
||||
fi
|
||||
|
||||
# Now try pipe file, expect failure
|
||||
@@ -210,14 +225,14 @@ then
|
||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
else
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
echo "I: testing pipe file as log file failed (expected)"
|
||||
fi
|
||||
else
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
echo "I: skipping pipe test (unable to create pipe)"
|
||||
fi
|
||||
|
||||
# Now try symlink file to plain file, expect success
|
||||
@@ -237,18 +252,18 @@ then
|
||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
echo "I: testing symlink to plain file succeeded"
|
||||
else
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I: testing symlink to plain file failed (unexpected)"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
echo "I: skipping symlink test (unable to create symlink)"
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing default logfile using named -L file ($n)"
|
||||
echo "I:testing default logfile using named -L file ($n)"
|
||||
# Now stop the server again and test the -L option
|
||||
rm -f $DLFILE
|
||||
$PERL ../../stop.pl .. ns1
|
||||
@@ -256,7 +271,7 @@ if ! test -f $PIDFILE; then
|
||||
cp $PLAINCONF named.conf
|
||||
$myNAMED -L $DLFILE > /dev/null 2>&1
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "I:failed to start $myNAMED"
|
||||
echo "I: failed to start $myNAMED"
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
fi
|
||||
@@ -272,7 +287,7 @@ if ! test -f $PIDFILE; then
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:failed to cleanly stop $myNAMED"
|
||||
echo "I: failed to cleanly stop $myNAMED"
|
||||
echo "I:exit status: 1"
|
||||
exit 1
|
||||
fi
|
||||
@@ -284,9 +299,9 @@ echo "I: testing iso8601 timestamp ($n)"
|
||||
cp $ISOCONF named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\.... ' $ISOFILE > /dev/null; then
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
echo "I: testing iso8601 timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
echo "I: testing iso8601 timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -295,14 +310,14 @@ echo "I: testing iso8601-utc timestamp ($n)"
|
||||
cp $ISOCONFUTC named.conf
|
||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||
if grep '^....-..-..T..:..:..\....Z' $ISOUTCFILE > /dev/null; then
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
echo "I: testing iso8601-utc timestamp succeeded"
|
||||
else
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
echo "I: testing iso8601-utc timestamp failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: testing explict versions ($n)"
|
||||
echo "I: testing explicit versions ($n)"
|
||||
cp $VERSCONF named.conf
|
||||
# a seconds since epoch version number
|
||||
touch $VERSFILE.1480039317
|
||||
@@ -313,27 +328,27 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing explict versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing explicit versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing explict versions failed DiG lookup failed"
|
||||
echo "I: testing explicit versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.1480039317
|
||||
if test_with_retry -f $VERSFILE.1480039317
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.1480039317 not removed"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $VERSFILE.5
|
||||
if test_with_retry -f $VERSFILE.5
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.5 exists"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.5 exists"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $VERSFILE.4
|
||||
if test_with_retry ! -f $VERSFILE.4
|
||||
then
|
||||
echo "I: testing explict versions failed $VERSFILE.4 does not exist"
|
||||
echo "I: testing explicit versions failed: $VERSFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -349,17 +364,17 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing timestamped versions failed cleanup of old entries took too long ($t secs)"
|
||||
echo "I: testing timestamped versions failed: cleanup of old entries took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing timestamped versions failed DiG lookup failed"
|
||||
echo "I: testing timestamped versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test -f $TSFILE.1480039317
|
||||
if test_with_retry -f $TSFILE.1480039317
|
||||
then
|
||||
echo "I: testing timestamped versions failed $TSFILE.1480039317 not removed"
|
||||
echo "I: testing timestamped versions failed: $TSFILE.1480039317 not removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
@@ -375,22 +390,22 @@ t2=`$PERL -e 'print time()."\n";'`
|
||||
t=`expr ${t2:-0} - ${t1:-0}`
|
||||
if test ${t:-1000} -gt 5
|
||||
then
|
||||
echo "I: testing unlimited versions failed took too long ($t secs)"
|
||||
echo "I: testing unlimited versions failed: took too long ($t secs)"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||
then
|
||||
echo "I: testing unlimited versions failed DiG lookup failed"
|
||||
echo "I: testing unlimited versions failed: DiG lookup failed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.1480039317
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.1480039317
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.1480039317 removed"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.1480039317 removed"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
if test ! -f $UNLIMITEDFILE.4
|
||||
if test_with_retry ! -f $UNLIMITEDFILE.4
|
||||
then
|
||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.4 does not"
|
||||
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.4 does not exist"
|
||||
status=`expr $status + 1`
|
||||
fi
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2005, 2007, 2011-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005, 2007, 2011-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -238,6 +238,16 @@ done
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# stomp on the file header
|
||||
echo "I:checking corrupt map files fail to load (bad file header)"
|
||||
ret=0
|
||||
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
||||
cp map.5 badmap
|
||||
stomp badmap 0 32 99
|
||||
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||
[ $? = 1 ] || ret=1
|
||||
[ $ret -eq 0 ] || echo "I:failed"
|
||||
status=`expr $status + $ret`
|
||||
# stomp on the file data so it hashes differently.
|
||||
# these are small and subtle changes, so that the resulting file
|
||||
# would appear to be a legitimate map file and would not trigger an
|
||||
@@ -245,7 +255,6 @@ status=`expr $status + $ret`
|
||||
# load because of a SHA1 hash mismatch.
|
||||
echo "I:checking corrupt map files fail to load (bad node header)"
|
||||
ret=0
|
||||
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
||||
cp map.5 badmap
|
||||
stomp badmap 2754 2 99
|
||||
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||
|
||||
@@ -16,16 +16,8 @@ is used so it will send TAT queries once per second.
|
||||
|
||||
ns3 is a validator with a broken key in managed-keys.
|
||||
|
||||
Tests TODO:
|
||||
ns4 is a validator with a deliberately broken managed-keys.bind and
|
||||
managed-keys.jnl, causing RFC 5011 initialization to fail.
|
||||
|
||||
- initial working KSK
|
||||
|
||||
TODO: test using delv with new trusted key too
|
||||
|
||||
- introduce a REVOKE bit
|
||||
|
||||
- later remove a signature
|
||||
|
||||
- corrupt a signature
|
||||
|
||||
TODO: also same things with dlv auto updates of trust anchor
|
||||
ns5 is a validator which is prevented from getting a response from the
|
||||
root server, causing key refresh queries to fail.
|
||||
|
||||
@@ -10,8 +10,10 @@ rm -f */K* */*.signed */trusted.conf */*.jnl */*.bk
|
||||
rm -f dsset-. ns1/dsset-.
|
||||
rm -f ns*/named.lock
|
||||
rm -f */managed-keys.bind* */named.secroots
|
||||
rm -f */managed.conf ns1/managed.key ns1/managed.key.id
|
||||
rm -f */named.memstats */named.run
|
||||
rm -f */managed*.conf ns1/managed.key ns1/managed.key.id
|
||||
rm -f */named.memstats */named.run */named.run.prev
|
||||
rm -f dig.out* delv.out* rndc.out* signer.out*
|
||||
rm -f ns1/named.secroots ns1/root.db.signed* ns1/root.db.tmp
|
||||
rm -f ns1/named.conf
|
||||
rm -rf ns4/nope
|
||||
rm -f ns5/named.args
|
||||
|
||||
@@ -10,6 +10,11 @@
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
acl allowed {
|
||||
! 10.53.0.5;
|
||||
any;
|
||||
};
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
@@ -22,6 +27,7 @@ options {
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
allow-query { allowed; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -10,6 +10,11 @@
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
acl allowed {
|
||||
! 10.53.0.5;
|
||||
any;
|
||||
};
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
@@ -22,6 +27,7 @@ options {
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
allow-query { allowed; };
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS1
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
transfer-source 10.53.0.1;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.1 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type master;
|
||||
file "root.db.signed";
|
||||
};
|
||||
@@ -1,10 +1,10 @@
|
||||
; Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
$TTL 2
|
||||
$TTL 20
|
||||
. IN SOA gson.nominum.com. a.root.servers.nil. (
|
||||
2000042100 ; serial
|
||||
600 ; refresh
|
||||
|
||||
@@ -28,6 +28,8 @@ managed-keys {
|
||||
EOF
|
||||
' > managed.conf
|
||||
cp managed.conf ../ns2/managed.conf
|
||||
cp managed.conf ../ns4/managed.conf
|
||||
cp managed.conf ../ns5/managed.conf
|
||||
|
||||
# Configure a trusted key statement (used by delve)
|
||||
cat $keyname.key | grep -v '^; ' | $PERL -n -e '
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20 -T tat=1
|
||||
|
||||
@@ -1 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40 -T tat=1
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -23,6 +23,7 @@ options {
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
bindkeys-file "managed.conf";
|
||||
trust-anchor-telemetry no;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS4
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.4;
|
||||
notify-source 10.53.0.4;
|
||||
transfer-source 10.53.0.4;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.4; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation auto;
|
||||
bindkeys-file "managed.conf";
|
||||
managed-keys-directory "nope";
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.4 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
@@ -0,0 +1,38 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
// NS5
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.5;
|
||||
notify-source 10.53.0.5;
|
||||
transfer-source 10.53.0.5;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.5; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify no;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation auto;
|
||||
bindkeys-file "managed.conf";
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.5 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
@@ -0,0 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g
|
||||
@@ -0,0 +1 @@
|
||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
||||
@@ -14,5 +14,14 @@ $SHELL clean.sh
|
||||
test -r $RANDFILE || $GENRANDOM 800 $RANDFILE
|
||||
|
||||
cp ns1/named1.conf ns1/named.conf
|
||||
cp ns5/named1.args ns5/named.args
|
||||
|
||||
cd ns1 && $SHELL sign.sh
|
||||
( cd ns1 && $SHELL sign.sh )
|
||||
|
||||
cp ns2/managed.conf ns2/managed1.conf
|
||||
|
||||
cd ns4
|
||||
mkdir nope
|
||||
touch nope/managed-keys.bind
|
||||
touch nope/managed.keys.bind.jnl
|
||||
chmod 444 nope/*
|
||||
|
||||
+297
-99
@@ -9,6 +9,74 @@
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
wait_for_log() {
|
||||
msg=$1
|
||||
file=$2
|
||||
for i in 1 2 3 4 5 6 7 8 9 10; do
|
||||
nextpart "$file" | grep "$msg" > /dev/null && return
|
||||
sleep 1
|
||||
done
|
||||
echo "I: exceeded time limit waiting for '$msg' in $file"
|
||||
ret=1
|
||||
}
|
||||
|
||||
mkeys_reconfig_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reconfig . | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
mkeys_reload_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reload . | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "loaded serial" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_loadkeys_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 loadkeys . | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "next key event" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_refresh_on() {
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys refresh | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_sync_on() {
|
||||
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||
# returns immediately after the expected log message is written, the
|
||||
# managed-keys zone is already locked and the command below calls
|
||||
# dns_zone_flush(), which also attempts to take that zone's lock
|
||||
nsidx=$1
|
||||
nextpart ns${nsidx}/named.run > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys sync | sed "s/^/I: ns${nsidx} /"
|
||||
wait_for_log "dump_done" ns${nsidx}/named.run
|
||||
}
|
||||
|
||||
mkeys_status_on() {
|
||||
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||
# returns immediately after the expected log message is written, the
|
||||
# managed-keys zone is already locked and the command below calls
|
||||
# mkey_status(), which in turn calls dns_zone_getrefreshkeytime(),
|
||||
# which also attempts to take that zone's lock
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys status
|
||||
}
|
||||
|
||||
mkeys_flush_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 flush | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
mkeys_secroots_on() {
|
||||
nsidx=$1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 secroots | sed "s/^/I: ns${nsidx} /"
|
||||
}
|
||||
|
||||
status=0
|
||||
n=1
|
||||
|
||||
@@ -58,11 +126,9 @@ n=`expr $n + 1`
|
||||
echo "I: check new trust anchor can be added ($n)"
|
||||
ret=0
|
||||
standby1=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 5
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# there should be two keys listed now
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -81,10 +147,8 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check new trust anchor can't be added with bad initial key ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys refresh | sed 's/^/I: ns3 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys sync | sed 's/^/I: ns3 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 3
|
||||
mkeys_status_on 3 > rndc.out.$n 2>&1
|
||||
# there should be one key listed now
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -100,14 +164,17 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: remove untrusted standby key, check timer restarts ($n)"
|
||||
ret=0
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
mkeys_sync_on 2
|
||||
t1=`grep "trust pending" ns2/managed-keys.bind`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
t2=`grep "trust pending" ns2/managed-keys.bind`
|
||||
# trust pending date must be different
|
||||
[ -n "$t2" ] || ret=1
|
||||
@@ -121,12 +188,15 @@ echo "I: restore untrusted standby key, revoke original key ($n)"
|
||||
t1=$t2
|
||||
$SETTIME -D none -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -153,10 +223,14 @@ n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I: refresh managed-keys, ensure same result ($n)"
|
||||
t1=$t2
|
||||
sleep 2
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -184,15 +258,17 @@ ret=0
|
||||
echo "I: restore revoked key, ensure same result ($n)"
|
||||
t1=$t2
|
||||
$SETTIME -R none -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
mkeys_loadkeys_on 1
|
||||
$SETTIME -D none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
mkeys_loadkeys_on 1
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||
# reset to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_sync_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -215,17 +291,44 @@ t2=`grep "trust pending" ns2/managed-keys.bind`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I: reinitialize trust anchors"
|
||||
echo "I: reinitialize trust anchors, add second key to bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
cat ns1/$standby1.key | grep -v '^; ' | $PERL -n -e '
|
||||
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
|
||||
local $key = join("", @rest);
|
||||
local $originalkey = `grep initial-key ns2/managed1.conf`;
|
||||
print <<EOF
|
||||
managed-keys {
|
||||
$originalkey
|
||||
"$dn" initial-key $flags $proto $alg "$key";
|
||||
};
|
||||
EOF
|
||||
' > ns2/managed.conf
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that no key from bind.keys is marked as an initializing key ($n)"
|
||||
ret=0
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
mkeys_secroots_on 2
|
||||
grep '; initializing' ns2/named.secroots > /dev/null 2>&1 && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I: reinitialize trust anchors, revert to one key in bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
mv ns2/managed1.conf ns2/managed.conf
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that standby key is now trusted ($n)"
|
||||
ret=0
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -243,12 +346,9 @@ echo "I: revoke original key, add new standby ($n)"
|
||||
ret=0
|
||||
standby2=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# three keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 3 ] || ret=1
|
||||
@@ -277,11 +377,9 @@ n=`expr $n + 1`
|
||||
echo "I: revoke standby before it is trusted ($n)"
|
||||
ret=0
|
||||
standby3=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.a.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.a.$n 2>&1
|
||||
# four keys listed
|
||||
count=`grep -c "keyid: " rndc.out.a.$n`
|
||||
[ "$count" -eq 4 ] || { echo "keyid: count ($count) != 4"; ret=1; }
|
||||
@@ -292,11 +390,9 @@ count=`grep -c "trust revoked" rndc.out.a.$n`
|
||||
count=`grep -c "trust pending" rndc.out.a.$n`
|
||||
[ "$count" -eq 2 ] || { echo "trust pending count ($count) != 2"; ret=1; }
|
||||
$SETTIME -R now -K ns1 $standby3 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.b.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.b.$n 2>&1
|
||||
# now three keys listed
|
||||
count=`grep -c "keyid: " rndc.out.b.$n`
|
||||
[ "$count" -eq 3 ] || { echo "keyid: count ($count) != 3"; ret=1; }
|
||||
@@ -307,18 +403,16 @@ count=`grep -c "trust revoked" rndc.out.b.$n`
|
||||
count=`grep -c "trust pending" rndc.out.b.$n`
|
||||
[ "$count" -eq 1 ] || { echo "trust pending count ($count) != 1"; ret=1; }
|
||||
$SETTIME -D now -K ns1 $standby3 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
mkeys_loadkeys_on 1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: wait 30 seconds for key add/remove holddowns to expire ($n)"
|
||||
echo "I: wait 20 seconds for key add/remove holddowns to expire ($n)"
|
||||
ret=0
|
||||
sleep 30
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
sleep 20
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -340,12 +434,9 @@ ret=0
|
||||
$SETTIME -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$SETTIME -R now -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -R now -K ns1 $standby2 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_loadkeys_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# two keys listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 2 ] || ret=1
|
||||
@@ -367,8 +458,10 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check for insecure response ($n)"
|
||||
ret=0
|
||||
mkeys_refresh_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null && ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -380,16 +473,18 @@ $SETTIME -D now -K ns1 $standby2 > /dev/null
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
cp ns1/named2.conf ns1/named.conf
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig
|
||||
mkeys_reconfig_on 1
|
||||
|
||||
echo "I: reinitialize trust anchors"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check positive validation ($n)"
|
||||
ret=0
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -403,17 +498,25 @@ orig=`cat ns1/managed.key`
|
||||
keyid=`cat ns1/managed.key.id`
|
||||
revoked=`$REVOKE -K ns1 $orig`
|
||||
rkeyid=`expr $revoked : 'ns1/K\.+00.+0*\([1-9]*[0-9]*[0-9]\)'`
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
# We need to activate at least one valid DNSKEY to prevent dnssec-signzone from
|
||||
# failing. Alternatively, we could use -P to disable post-sign verification,
|
||||
# but we actually do want post-sign verification to happen to ensure the zone
|
||||
# is correct before we break it on purpose.
|
||||
$SETTIME -R none -D none -K ns1 $standby1 > /dev/null
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -O full -o . -f signer.out.$n ns1/root.db > /dev/null 2>&-
|
||||
cp -f ns1/root.db.signed ns1/root.db.tmp
|
||||
BADSIG="SVn2tLDzpNX2rxR4xRceiCsiTqcWNKh7NQ0EQfCrVzp9WEmLw60sQ5kP xGk4FS/xSKfh89hO2O/H20Bzp0lMdtr2tKy8IMdU/mBZxQf2PXhUWRkg V2buVBKugTiOPTJSnaqYCN3rSfV1o7NtC1VNHKKK/D5g6bpDehdn5Gaq kpBhN+MSCCh9OZP2IT20luS1ARXxLlvuSVXJ3JYuuhTsQXUbX/SQpNoB Lo6ahCE55szJnmAxZEbb2KOVnSlZRA6ZBHDhdtO0S4OkvcmTutvcVV+7 w53CbKdaXhirvHIh0mZXmYk2PbPLDY7PU9wSH40UiWPOB9f00wwn6hUe uEQ1Qg=="
|
||||
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
# Less than a second may have passed since ns1 was started. If we call
|
||||
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||
# subsequent "rndc reload ." call on platforms which do not set the
|
||||
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||
# equal to master file modification time.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
||||
mkeys_reload_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || { echo "'keyid:' count ($count) != 1"; ret=1; }
|
||||
@@ -434,6 +537,7 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check validation fails with bad DNSKEY rrset ($n)"
|
||||
ret=0
|
||||
mkeys_flush_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
@@ -443,17 +547,18 @@ n=`expr $n + 1`
|
||||
echo "I: restore DNSKEY rrset, check validation succeeds again ($n)"
|
||||
ret=0
|
||||
rm -f ${revoked}.key ${revoked}.private
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$SETTIME -D none -R none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||
$SETTIME -D now -K ns1 $standby2 > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 flush | sed 's/^/I: ns1 /'
|
||||
# Less than a second may have passed since ns1 was started. If we call
|
||||
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||
# subsequent "rndc reload ." call on platforms which do not set the
|
||||
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||
# equal to master file modification time.
|
||||
sleep 1
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_reload_on 1
|
||||
mkeys_flush_on 2
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -462,15 +567,24 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: reset the root server with no keys, check for minimal update ($n)"
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
ret=0
|
||||
# Refresh keys first to prevent previous checks from influencing this one.
|
||||
# Note that we might still get occasional false negatives on some really slow
|
||||
# machines, when $t1 equals $t2 due to the time elapsed between "rndc
|
||||
# managed-keys status" calls being equal to the normal active refresh period
|
||||
# (as calculated per rules listed in RFC 5011 section 2.3) minus an "hour" (as
|
||||
# set using -T mkeytimers).
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
t1=`grep 'next refresh:' rndc.out.$n`
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
cp ns1/root.db ns1/root.db.signed
|
||||
nextpart ns1/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
wait_for_log "loaded serial" ns1/named.run
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -492,14 +606,23 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: reset the root server with no signatures, check for minimal update ($n)"
|
||||
t2=$t1
|
||||
ret=0
|
||||
# Refresh keys first to prevent previous checks from influencing this one
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
t1=`grep 'next refresh:' rndc.out.$n`
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
cat ns1/K*.key >> ns1/root.db.signed
|
||||
nextpart ns1/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
wait_for_log "loaded serial" ns1/named.run
|
||||
# Less than a second may have passed since the last time ns2 received a
|
||||
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||
# timestamp to prevent minimal update from resetting it to the same timestamp.
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
# one key listed
|
||||
count=`grep -c "keyid: " rndc.out.$n`
|
||||
[ "$count" -eq 1 ] || ret=1
|
||||
@@ -521,13 +644,12 @@ status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: restore root server, check validation succeeds again ($n)"
|
||||
ret=0
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
||||
sleep 3
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_reload_on 1
|
||||
mkeys_refresh_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
@@ -537,14 +659,14 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries are logged ($n)"
|
||||
ret=0
|
||||
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns3/named.run > /dev/null || ret=1
|
||||
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns2/named.run > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries are received ($n)"
|
||||
ret=0
|
||||
grep "query '_ta-[0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
||||
grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -552,15 +674,91 @@ n=`expr $n + 1`
|
||||
echo "I: check 'rndc-managed-keys destroy' ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys destroy | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
grep "no views with managed keys" rndc.out.$n > /dev/null || ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig | sed 's/^/I: ns2 /'
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
||||
mkeys_reconfig_on 2
|
||||
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||
grep "name: \." rndc.out.$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check that trust-anchor-telemetry queries contain the correct key ($n)"
|
||||
ret=0
|
||||
# convert the hexadecimal key from the TAT query into decimal and
|
||||
# compare against the known key.
|
||||
tathex=`grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run | awk '{print $6; exit 0}' | sed -e 's/(_ta-\([0-9a-f][0-9a-f]*\)):/\1/'`
|
||||
tatkey=`$PERL -e 'printf("%d\n", hex(@ARGV[0]));' $tathex`
|
||||
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | sed -n 's#.*SHA256/\([0-9][0-9]*\) ; .*managed.*#\1#p'`
|
||||
[ "$tatkey" -eq "$realkey" ] || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check initialization fails if managed-keys can't be created ($n)"
|
||||
ret=0
|
||||
mkeys_secroots_on 4
|
||||
grep '; initializing managed' ns4/named.secroots > /dev/null 2>&1 || ret=1
|
||||
grep '; managed' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
grep '; trusted' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check failure to contact root servers does not prevent key refreshes after restart ($n)"
|
||||
ret=0
|
||||
# By the time we get here, ns5 should have attempted refreshing its managed
|
||||
# keys. These attempts should fail as ns1 is configured to REFUSE all queries
|
||||
# from ns5. Note that named1.args does not contain "-T mkeytimers"; this is to
|
||||
# ensure key refresh retry will be scheduled to one actual hour after the first
|
||||
# key refresh failure instead of just a few seconds, in order to prevent races
|
||||
# between the next scheduled key refresh time and startup time of restarted ns5.
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
nextpart ns5/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
# ns5/named.run will contain logs from both the old instance and the new
|
||||
# instance. In order for the test to pass, both must attempt a fetch.
|
||||
count=`grep -c "Creating key fetch" ns5/named.run`
|
||||
[ $count -lt 2 ] && ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: check key refreshes are resumed after root servers become available ($n)"
|
||||
ret=0
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||
# Prevent previous check from affecting this one
|
||||
rm -f ns5/managed-keys.bind*
|
||||
# named2.args adds "-T mkeytimers=2/20/40" to named1.args as we need to wait for
|
||||
# an "hour" until keys are refreshed again after initial failure
|
||||
cp ns5/named2.args ns5/named.args
|
||||
nextpart ns5/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
mkeys_secroots_on 5
|
||||
grep '; initializing managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should still REFUSE queries from ns5, so resolving should be impossible
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.a.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||
grep "status: SERVFAIL" dig.out.ns5.a.test$n > /dev/null || ret=1
|
||||
# Allow queries from ns5 to ns1
|
||||
cp ns1/named3.conf ns1/named.conf
|
||||
rm -f ns1/root.db.signed.jnl
|
||||
mkeys_reconfig_on 1
|
||||
nextpart ns5/named.run > /dev/null
|
||||
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||
mkeys_secroots_on 5
|
||||
grep '; managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||
# ns1 should not longer REFUSE queries from ns5, so managed keys should be
|
||||
# correctly refreshed and resolving should succeed
|
||||
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.b.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
grep "example..*.RRSIG..*TXT" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -53,6 +53,7 @@ view "b" {
|
||||
type slave;
|
||||
masters { 10.53.0.5 key "a"; };
|
||||
file "x21.bk-b";
|
||||
notify no;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -62,5 +63,6 @@ view "c" {
|
||||
type slave;
|
||||
masters { 10.53.0.5 key "a"; };
|
||||
file "x21.bk-c";
|
||||
notify no;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -20,6 +20,7 @@ options {
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
notify yes;
|
||||
serial-query-rate 1; // workaround for KB AA-01213
|
||||
};
|
||||
|
||||
key altkey {
|
||||
|
||||
@@ -278,7 +278,7 @@ sleep 10
|
||||
if
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||
then
|
||||
echo "I:restarted server ns1"
|
||||
echo "I:restarted server ns1"
|
||||
else
|
||||
echo "I:could not restart server ns1"
|
||||
exit 1
|
||||
@@ -486,6 +486,7 @@ fi
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that 'update-policy local' fails from non-localhost address ($n)"
|
||||
grep 'match on session key not from localhost' ns5/named.run > /dev/null && ret=1
|
||||
$NSUPDATE -p 5300 -k ns5/session.key > nsupdate.out.$n 2>&1 << END && ret=1
|
||||
server 10.53.0.5 5300
|
||||
local 10.53.0.1
|
||||
@@ -493,6 +494,7 @@ update add nonlocal.local.nil. 600 A 4.3.2.1
|
||||
send
|
||||
END
|
||||
grep REFUSED nsupdate.out.$n > /dev/null 2>&1 || ret=1
|
||||
grep 'match on session key not from localhost' ns5/named.run > /dev/null || ret=1
|
||||
$DIG @10.53.0.5 -p 5300 \
|
||||
+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd \
|
||||
nonlocal.local.nil. > dig.out.ns5.$n || ret=1
|
||||
@@ -707,8 +709,12 @@ size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->siz
|
||||
[ "$size" -gt 6000 ] || ret=1
|
||||
sleep 1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 sync maxjournal.test
|
||||
sleep 1
|
||||
|
||||
for i in 1 2 3 4 5 6
|
||||
do
|
||||
sleep 1
|
||||
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||
[ "$size" -lt 5000 ] && break
|
||||
done
|
||||
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||
[ "$size" -lt 5000 ] || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
@@ -883,75 +889,81 @@ grep "address family not supported" nsupdate.out-$n > /dev/null 2>&1 || ret=1
|
||||
#
|
||||
# Add client library tests here
|
||||
#
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
|
||||
if test unset != "${SAMPLEUPDATE:-unset}" -a -x "${SAMPLEUPDATE}"
|
||||
then
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
add "nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||
add "check-nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
add "yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||
add "check-yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
add "nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||
add "check-nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
||||
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
||||
n=`expr $n + 1`
|
||||
ret=0
|
||||
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
||||
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
||||
-p "yxrrset no-txt.sample TXT" \
|
||||
add "yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
||||
add "check-yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
||||
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
||||
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||
|
||||
fi
|
||||
|
||||
#
|
||||
# End client library tests here
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -7,8 +7,9 @@ file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
system test for recursion limits
|
||||
|
||||
ns1 -- root server
|
||||
ans2 -- delegate to ns1.(n+1).example.com for all n, up to
|
||||
the value specified in ans.limit (or forever if limit is 0)
|
||||
ans2 -- for example.org: delegate to ns1.(n+1).example.org for all n, up to the
|
||||
value specified in ans.limit (or forever if limit is 0)
|
||||
for example.net: delegate every query to 15 more name servers, with
|
||||
"victim" address
|
||||
ns3 -- resolver under test
|
||||
ans4 -- delegates every query to 16 more name servers, with "victim" address
|
||||
ans7 -- "victim" server
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -10,9 +10,17 @@ use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
use Time::HiRes qw(usleep nanosleep);
|
||||
use IO::Socket;
|
||||
use Net::DNS;
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $limit = getlimit();
|
||||
my $no_more_waiting = 0;
|
||||
my @delayed_response;
|
||||
my $timeout;
|
||||
|
||||
my $udpsock = IO::Socket::INET->new(LocalAddr => "$localaddr",
|
||||
LocalPort => 5300, Proto => "udp", Reuse => 1) or die "$!";
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
@@ -39,21 +47,18 @@ sub getlimit {
|
||||
return 0;
|
||||
}
|
||||
|
||||
my $localaddr = "10.53.0.2";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
my $limit = getlimit();
|
||||
|
||||
# If $wait == 0 is returned, returned reply will be sent immediately.
|
||||
# If $wait == 1 is returned, sending the returned reply might be delayed; see
|
||||
# comments inside handle_UDP() for details.
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
my ($qname, $qclass, $qtype) = @_;
|
||||
my ($rcode, @ans, @auth, @add, $wait);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$wait = 0;
|
||||
$count += 1;
|
||||
# Sleep 100ms to make sure that named sends both A and AAAA queries.
|
||||
usleep(100000);
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
@@ -95,6 +100,7 @@ sub reply_handler {
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname =~ /^ns1\.(\d+)\.example\.org$/) {
|
||||
my $next = $1 + 1;
|
||||
$wait = 1;
|
||||
if ($limit == 0 || (! $send_response && $next <= $limit)) {
|
||||
my $rr = new Net::DNS::RR("$1.example.org 86400 $qclass NS ns1.$next.example.org");
|
||||
push @auth, $rr;
|
||||
@@ -108,24 +114,114 @@ sub reply_handler {
|
||||
}
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
return ($rcode, \@ans, \@auth, \@add, $wait);
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
sub handleUDP {
|
||||
my ($buf, $peer) = @_;
|
||||
my ($request, $rcode, $ans, $auth, $add, $wait);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
$request = new Net::DNS::Packet(\$buf, 0);
|
||||
$@ and die $@;
|
||||
|
||||
$ns->main_loop;
|
||||
my ($question) = $request->question;
|
||||
my $qname = $question->qname;
|
||||
my $qclass = $question->qclass;
|
||||
my $qtype = $question->qtype;
|
||||
|
||||
($rcode, $ans, $auth, $add, $wait) = reply_handler($qname, $qclass, $qtype);
|
||||
|
||||
my $reply = $request->reply();
|
||||
|
||||
$reply->header->rcode($rcode);
|
||||
$reply->header->aa(@$ans ? 1 : 0);
|
||||
$reply->header->id($request->header->id);
|
||||
$reply->{answer} = $ans if $ans;
|
||||
$reply->{authority} = $auth if $auth;
|
||||
$reply->{additional} = $add if $add;
|
||||
|
||||
if ($wait) {
|
||||
# reply_handler() asked us to delay sending this reply until
|
||||
# another reply with $wait == 1 is generated or a timeout
|
||||
# occurs.
|
||||
if (@delayed_response) {
|
||||
# A delayed reply is already queued, so we can now send
|
||||
# both the delayed reply and the current reply.
|
||||
send_delayed_response();
|
||||
return $reply;
|
||||
} elsif ($no_more_waiting) {
|
||||
# It was determined before that there is no point in
|
||||
# waiting for "accompanying" queries. Thus, send the
|
||||
# current reply immediately.
|
||||
return $reply;
|
||||
} else {
|
||||
# No delayed reply is queued and the client is expected
|
||||
# to send an "accompanying" query shortly. Do not send
|
||||
# the current reply right now, just save it for later
|
||||
# and wait for an "accompanying" query to be received.
|
||||
@delayed_response = ($reply, $peer);
|
||||
$timeout = 0.5;
|
||||
return;
|
||||
}
|
||||
} else {
|
||||
# Send reply immediately.
|
||||
return $reply;
|
||||
}
|
||||
}
|
||||
|
||||
sub send_delayed_response {
|
||||
my ($reply, $peer) = @delayed_response;
|
||||
# Truncation to 512 bytes is required for triggering "NS explosion" on
|
||||
# builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer);
|
||||
undef @delayed_response;
|
||||
undef $timeout;
|
||||
}
|
||||
|
||||
# Main
|
||||
my $rin;
|
||||
my $rout;
|
||||
for (;;) {
|
||||
$rin = '';
|
||||
vec($rin, fileno($udpsock), 1) = 1;
|
||||
|
||||
select($rout = $rin, undef, undef, $timeout);
|
||||
|
||||
if (vec($rout, fileno($udpsock), 1)) {
|
||||
my ($buf, $peer, $reply);
|
||||
$udpsock->recv($buf, 512);
|
||||
$peer = $udpsock->peername();
|
||||
$reply = handleUDP($buf, $peer);
|
||||
# Truncation to 512 bytes is required for triggering "NS
|
||||
# explosion" on builds without IPv6 support
|
||||
$udpsock->send($reply->data(512), 0, $peer) if $reply;
|
||||
} else {
|
||||
# An "accompanying" query was expected to come in, but did not.
|
||||
# Assume the client never sends "accompanying" queries to
|
||||
# prevent pointlessly waiting for them ever again.
|
||||
$no_more_waiting = 1;
|
||||
# Send the delayed reply to the query which caused us to wait.
|
||||
send_delayed_response();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,89 +0,0 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
use strict;
|
||||
use warnings;
|
||||
|
||||
use IO::File;
|
||||
use Getopt::Long;
|
||||
use Net::DNS::Nameserver;
|
||||
|
||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||
$pidf->close or die "cannot close pid file: $!";
|
||||
sub rmpid { unlink "ans.pid"; exit 1; };
|
||||
|
||||
$SIG{INT} = \&rmpid;
|
||||
$SIG{TERM} = \&rmpid;
|
||||
|
||||
my $count = 0;
|
||||
my $send_response = 0;
|
||||
|
||||
my $localaddr = "10.53.0.4";
|
||||
my $localport = 5300;
|
||||
my $verbose = 0;
|
||||
|
||||
sub reply_handler {
|
||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
||||
my ($rcode, @ans, @auth, @add);
|
||||
|
||||
print ("request: $qname/$qtype\n");
|
||||
STDOUT->flush();
|
||||
|
||||
$count += 1;
|
||||
|
||||
if ($qname eq "count" ) {
|
||||
if ($qtype eq "TXT") {
|
||||
my ($ttl, $rdata) = (0, "$count");
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
print ("\tcount: $count\n");
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "reset" ) {
|
||||
$count = 0;
|
||||
$send_response = 0;
|
||||
$rcode = "NOERROR";
|
||||
} elsif ($qname eq "direct.example.net" ) {
|
||||
if ($qtype eq "A") {
|
||||
my ($ttl, $rdata) = (3600, $localaddr);
|
||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||
push @ans, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||
my $next = ($1 + 1) * 16;
|
||||
for (my $i = 1; $i < 16; $i++) {
|
||||
my $s = $next + $i;
|
||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||
push @auth, $rr;
|
||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||
push @add, $rr;
|
||||
}
|
||||
$rcode = "NOERROR";
|
||||
} else {
|
||||
$rcode = "NXDOMAIN";
|
||||
}
|
||||
|
||||
# mark the answer as authoritive (by setting the 'aa' flag
|
||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
||||
}
|
||||
|
||||
GetOptions(
|
||||
'port=i' => \$localport,
|
||||
'verbose!' => \$verbose,
|
||||
);
|
||||
|
||||
my $ns = Net::DNS::Nameserver->new(
|
||||
LocalAddr => $localaddr,
|
||||
LocalPort => $localport,
|
||||
ReplyHandler => \&reply_handler,
|
||||
Verbose => $verbose,
|
||||
);
|
||||
|
||||
$ns->main_loop;
|
||||
@@ -1,4 +1,4 @@
|
||||
; Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
; Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -11,4 +11,4 @@ ns.tld1. 60 IN A 10.53.0.1
|
||||
example.org. 60 IN NS direct.example.org.
|
||||
direct.example.org. 60 IN A 10.53.0.2
|
||||
example.net. 60 IN NS direct.example.net.
|
||||
direct.example.net. 60 IN A 10.53.0.4
|
||||
direct.example.net. 60 IN A 10.53.0.2
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -9,6 +9,20 @@
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
if $PERL -e 'use Net::DNS;' 2>/dev/null
|
||||
then
|
||||
if $PERL -e 'use Net::DNS; die if ($Net::DNS::VERSION <= 0.78);' 2>/dev/null
|
||||
then
|
||||
:
|
||||
else
|
||||
echo "I:Net::DNS versions up to 0.78 have a bug that causes this test to fail: please update." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "I:This test requires the Net::DNS library." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
||||
then
|
||||
:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -14,101 +14,107 @@ DIGOPTS="-p 5300"
|
||||
status=0
|
||||
n=0
|
||||
|
||||
ns3_reset() {
|
||||
cp $1 ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns3 /'
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush | sed 's/^/I: ns3 /'
|
||||
}
|
||||
|
||||
ns3_sends_aaaa_queries() {
|
||||
if grep "started AAAA fetch" ns3/named.run >/dev/null; then
|
||||
return 0
|
||||
else
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Check whether the number of queries ans2 received from ns3 (this value is
|
||||
# read from dig output stored in file $1) is as expected. The expected query
|
||||
# count is variable:
|
||||
# - if ns3 sends AAAA queries, the query count should equal $2,
|
||||
# - if ns3 does not send AAAA queries, the query count should equal $3.
|
||||
check_query_count() {
|
||||
count=`sed 's/[^0-9]//g;' $1`
|
||||
expected_count_with_aaaa=$2
|
||||
expected_count_without_aaaa=$3
|
||||
|
||||
if ns3_sends_aaaa_queries; then
|
||||
expected_count=$expected_count_with_aaaa
|
||||
else
|
||||
expected_count=$expected_count_without_aaaa
|
||||
fi
|
||||
|
||||
if [ $count -ne $expected_count ]; then
|
||||
echo "I: count ($count) != $expected_count"
|
||||
ret=1
|
||||
fi
|
||||
}
|
||||
|
||||
echo "I: set max-recursion-depth=12"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "1000" > ans2/ans.limit
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect1.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
else
|
||||
[ $count -eq 14 ] || { ret=1; echo "I: count ($count) != 14"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 26 14
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
sleep 2
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named1.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect2.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 49 ] || { ret=1; echo "I: count ($count) != 49"; }
|
||||
else
|
||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 49 26
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named2.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=5"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
echo "I: attempt excessive-depth lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect3.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
else
|
||||
[ $count -eq 7 ] || { ret=1; echo "I: count ($count) != 7"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 12 7
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "5" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named2.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect4.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
[ $count -eq 21 ] || { ret=1; echo "I: count ($count) != 21"; }
|
||||
else
|
||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
||||
fi
|
||||
check_query_count dig.out.2.test$n 21 12
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-depth"
|
||||
cp ns3/named3.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=50"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "13" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect5.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -118,10 +124,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "12" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named3.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect6.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -131,20 +137,16 @@ eval count=`cat dig.out.2.test$n`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reset max-recursion-queries"
|
||||
cp ns3/named4.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||
sleep 2
|
||||
echo "I: set max-recursion-depth=100, max-recursion-queries=40"
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
echo "I: attempt excessive-queries lookup ($n)"
|
||||
ret=0
|
||||
echo "10" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect7.example.org > dig.out.1.test$n || ret=1
|
||||
if [ "$TESTSOCK6" != "false" ]
|
||||
then
|
||||
if ns3_sends_aaaa_queries; then
|
||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||
fi
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
@@ -154,10 +156,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
echo "I: attempt permissible lookup ($n)"
|
||||
ret=0
|
||||
echo "9" > ans2/ans.limit
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.3 indirect8.example.org > dig.out.1.test$n || ret=1
|
||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||
@@ -170,10 +172,10 @@ status=`expr $status + $ret`
|
||||
n=`expr $n + 1`
|
||||
echo "I: attempting NS explosion ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
||||
ns3_reset ns3/named4.conf
|
||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.3 ns1.1.example.net > dig.out.1.test$n || ret=1
|
||||
sleep 2
|
||||
$DIG $DIGOPTS +short @10.53.0.4 count txt > dig.out.2.test$n || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||
eval count=`cat dig.out.2.test$n`
|
||||
[ $count -lt 50 ] || ret=1
|
||||
$DIG $DIGOPTS +short @10.53.0.7 count txt > dig.out.3.test$n || ret=1
|
||||
|
||||
+17
-16
@@ -100,26 +100,27 @@ $PERL stop.pl $test
|
||||
status=`expr $status + $?`
|
||||
|
||||
if [ $status != 0 ]; then
|
||||
echofail "R:FAIL"
|
||||
# Don't clean up - we need the evidence.
|
||||
find . -name core -exec chmod 0644 '{}' \;
|
||||
echofail "R:FAIL"
|
||||
# Don't clean up - we need the evidence.
|
||||
find . -name core -exec chmod 0644 '{}' \;
|
||||
else
|
||||
echopass "R:PASS"
|
||||
echopass "R:PASS"
|
||||
|
||||
if $clean
|
||||
if $clean
|
||||
then
|
||||
rm -f $SYSTEMTESTTOP/random.data
|
||||
if test -f $test/clean.sh
|
||||
then
|
||||
rm -f $SYSTEMTESTTOP/random.data
|
||||
if test -f $test/clean.sh
|
||||
then
|
||||
( cd $test && $SHELL clean.sh "$@" )
|
||||
fi
|
||||
if test -d ../../../.git
|
||||
then
|
||||
git status -su $test |
|
||||
sed -n 's/^?? \(.*\)/I:file \1 not removed/p'
|
||||
fi
|
||||
|
||||
( cd $test && $SHELL clean.sh "$@" )
|
||||
fi
|
||||
if test -d ../../../.git
|
||||
then
|
||||
git status -su --ignored $test |
|
||||
sed -n -e 's|^?? \(.*\)|I:file \1 not removed|p' \
|
||||
-e 's|^!! \(.*/named.run\)$|I:file \1 not removed|p' \
|
||||
-e 's|^!! \(.*/named.memstats\)$|I:file \1 not removed|p'
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
echoinfo "E:$test:`date`"
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
new-zones-directory "./nope";
|
||||
port 5300;
|
||||
pid-file "../named.pid";
|
||||
listen-on { 127.0.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
};
|
||||
@@ -14,4 +14,10 @@ $SHELL clean.sh
|
||||
cp ns2/named1.conf ns2/named.conf
|
||||
|
||||
mkdir ns2/nope
|
||||
chmod 555 ns2/nope
|
||||
|
||||
if [ 1 = "${CYGWIN:-0}" ]
|
||||
then
|
||||
setfacl -s user::r-x,group::r-x,other::r-x ns2/nope
|
||||
else
|
||||
chmod 555 ns2/nope
|
||||
fi
|
||||
|
||||
@@ -73,6 +73,17 @@ grep "managed-keys-directory './nope' is not writable" ns2/named.run > /dev/null
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking that named refuses to reconfigure if new-zones-directory is not writable ($n)"
|
||||
ret=0
|
||||
cp -f ns2/named-alt6.conf ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig > rndc.out.$n 2>&1
|
||||
grep "failed: permission denied" rndc.out.$n > /dev/null 2>&1 || ret=1
|
||||
sleep 1
|
||||
grep "new-zones-directory './nope' is not writable" ns2/named.run > /dev/null 2>&1 || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I: checking that named refuses to start if working directory is not writable ($n)"
|
||||
ret=0
|
||||
|
||||
@@ -16,15 +16,6 @@ rm -f dig.out.*
|
||||
|
||||
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd -p 5300"
|
||||
|
||||
# read everything that's been appended to a file since the last time
|
||||
# 'nextpart' was called.
|
||||
nextpart () {
|
||||
[ -f $1.prev ] || echo "0" > $1.prev
|
||||
prev=`cat $1.prev`
|
||||
awk "FNR > $prev "'{ print }
|
||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||
}
|
||||
|
||||
echo "I:checking DNSSEC SERVFAIL is cached ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +dnssec foo.example. a @10.53.0.5 > dig.out.ns5.test$n || ret=1
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user