Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b9e33d9cce | ||
|
|
e94465e304 | ||
|
|
8b9e2015f3 | ||
|
|
f64da6cabb | ||
|
|
6954eceb80 | ||
|
|
378774821a | ||
|
|
40562e37ee | ||
|
|
e7256edf67 | ||
|
|
7edff5d2bb | ||
|
|
5fd05a6d88 | ||
|
|
3009554a0b | ||
|
|
7545b00842 | ||
|
|
396772811a | ||
|
|
c0494994f0 | ||
|
|
1970f078cf | ||
|
|
376d5996a1 | ||
|
|
65a483106e | ||
|
|
5f308740df | ||
|
|
a8c1bfd673 | ||
|
|
18c7fa2f93 | ||
|
|
3f8c9d92af | ||
|
|
393135d693 | ||
|
|
82354deeb1 | ||
|
|
c22b540e4c | ||
|
|
d92d70ac5d | ||
|
|
00ff44c7c2 | ||
|
|
2f13e0ef98 | ||
|
|
a80dc538bd | ||
|
|
40a90fbf89 | ||
|
|
31b6ae485e | ||
|
|
19f6a63184 | ||
|
|
14e9925868 | ||
|
|
7bc5d7f5e8 | ||
|
|
1dc8208a89 | ||
|
|
6ead410268 | ||
|
|
a573b93b46 | ||
|
|
165df18f75 | ||
|
|
9bb32395b2 | ||
|
|
8993ecd06a | ||
|
|
2f4e0e5a81 | ||
|
|
78e1d7cdde | ||
|
|
ba613d22bf | ||
|
|
858228febe | ||
|
|
5b2b9340fe | ||
|
|
6035d557c4 | ||
|
|
900215654b | ||
|
|
445cabb392 | ||
|
|
a197094d76 | ||
|
|
f975d0acaa | ||
|
|
656eed7c9b | ||
|
|
7a0188774f | ||
|
|
bcce55197a | ||
|
|
3bfc28a0d0 | ||
|
|
6f5cc4206d | ||
|
|
e2f9dcfd86 | ||
|
|
31975d85de | ||
|
|
3d905e0533 | ||
|
|
3def40b01b | ||
|
|
04934b28ea | ||
|
|
8c1b8dd55d | ||
|
|
6bbbf12936 | ||
|
|
9eb5aa40aa | ||
|
|
f581ac4726 | ||
|
|
c0e3e1fe44 | ||
|
|
312c84c73a | ||
|
|
b231ddc65d | ||
|
|
0cba7ca6af | ||
|
|
f4b2356359 | ||
|
|
a1aa42b9cd | ||
|
|
c999531fa4 | ||
|
|
00827f59d2 | ||
|
|
e03e455cd5 | ||
|
|
a1a5145867 | ||
|
|
4034b098d8 | ||
|
|
27bf48327c | ||
|
|
c652213857 | ||
|
|
5b1e929b8b | ||
|
|
a41e41d6a4 | ||
|
|
0e29543a3d | ||
|
|
f13c1c09e9 | ||
|
|
e3d9aafff0 | ||
|
|
23b81977fe | ||
|
|
2a390b2537 | ||
|
|
e6801bf89e | ||
|
|
3300f6aeda | ||
|
|
b819a478b7 | ||
|
|
7e1df5182c | ||
|
|
72ddd51e74 | ||
|
|
c3d0ccdc8f | ||
|
|
f305a705c4 | ||
|
|
490c321e25 | ||
|
|
e7b53943fe | ||
|
|
8d23105547 | ||
|
|
95dce4e68c | ||
|
|
9bb007fd2d | ||
|
|
3b5718a8c9 | ||
|
|
40298d8bee | ||
|
|
92bbc9914c | ||
|
|
4359be18f4 | ||
|
|
0698ad8503 | ||
|
|
9b3fc207df | ||
|
|
db15f78ad7 | ||
|
|
ff30290b48 | ||
|
|
7bbb034952 | ||
|
|
a51352c4a4 | ||
|
|
37039792cb | ||
|
|
41b1a98545 | ||
|
|
dd61c4ad3e | ||
|
|
85bd975d3d | ||
|
|
ee42f734d5 | ||
|
|
6e02359034 | ||
|
|
0ed0c4b1a5 | ||
|
|
facf811847 | ||
|
|
4ae8f28711 | ||
|
|
2658ebbcba | ||
|
|
45d4d62a0c | ||
|
|
63d83632d7 | ||
|
|
40e1e659b6 | ||
|
|
f5e1b555c5 | ||
|
|
4e2ba60f3c | ||
|
|
625f656aa8 | ||
|
|
278b68ced5 | ||
|
|
c6c1193e39 | ||
|
|
8f532a13cb | ||
|
|
497f3f913e | ||
|
|
01139573bc | ||
|
|
4cbaa08602 | ||
|
|
c9f8165a06 | ||
|
|
1d57d460d4 | ||
|
|
959d294067 | ||
|
|
864bc6b56e | ||
|
|
06049b1c6c | ||
|
|
3b4f23cdbf | ||
|
|
08f18efba2 | ||
|
|
f808b5e0d2 | ||
|
|
a4bf990ed7 | ||
|
|
c341e524dc | ||
|
|
63270d33f1 | ||
|
|
09baa0cbb1 | ||
|
|
87387d8a41 | ||
|
|
5c76f3664c | ||
|
|
5b69d3da83 | ||
|
|
89d1777560 | ||
|
|
d3e8e9bdbb | ||
|
|
3056d6f532 | ||
|
|
96ebb55501 | ||
|
|
8e2a8a3855 | ||
|
|
81570e84a2 | ||
|
|
6a59e53a69 | ||
|
|
2bbca9594f | ||
|
|
eb2ef7b53e | ||
|
|
aebdc6cd7d | ||
|
|
910a01550a | ||
|
|
65314b0fd8 | ||
|
|
80739779fc | ||
|
|
a53e03205a | ||
|
|
ea055a82cd | ||
|
|
89c95e7141 | ||
|
|
79e78994d0 | ||
|
|
21761bfe79 | ||
|
|
969d923536 | ||
|
|
6b8e4d6e69 | ||
|
|
a94d68ce43 | ||
|
|
7810817b71 | ||
|
|
b49042a6a5 | ||
|
|
b1042e011c | ||
|
|
0207f6ff9e | ||
|
|
65f8b51893 | ||
|
|
5bead588b7 | ||
|
|
3f2e5f840a | ||
|
|
c9438ee2e0 | ||
|
|
a59d687db4 | ||
|
|
89636d8f30 | ||
|
|
34ee1cdb56 | ||
|
|
6853af8fc5 | ||
|
|
2e662cf514 | ||
|
|
321b8429f5 | ||
|
|
172aa40e8f | ||
|
|
0fc861dea9 | ||
|
|
b284857f96 | ||
|
|
807ad469fe | ||
|
|
5ff48dca18 | ||
|
|
66258ca349 | ||
|
|
2115e319ba | ||
|
|
429a43b720 | ||
|
|
bf9b90f977 | ||
|
|
d8442c1a15 | ||
|
|
9e5439a6d8 | ||
|
|
0fab171196 | ||
|
|
583e355951 | ||
|
|
fe79e2efbf | ||
|
|
b7b8e298f6 | ||
|
|
d99d5249b7 | ||
|
|
208abf3fc7 | ||
|
|
6e87e723a4 | ||
|
|
4f554c2445 | ||
|
|
30419509dd | ||
|
|
2361003a88 | ||
|
|
94d96121b9 | ||
|
|
31275c3f39 | ||
|
|
d63943f063 | ||
|
|
ebf5459c44 | ||
|
|
9d47a267c4 |
@@ -1,3 +1,195 @@
|
|||||||
|
4830. [bug] Failure to configure ATF when requested did not cause
|
||||||
|
an error in top-level configure script. [RT #46655]
|
||||||
|
|
||||||
|
4829. [bug] isc_heap_delete did not zero the index value when
|
||||||
|
the heap was created with a callback to do that.
|
||||||
|
[RT #46709]
|
||||||
|
|
||||||
|
4828. [bug] Do not use thread-local storage for storing LMDB reader
|
||||||
|
locktable slots. [RT #46556]
|
||||||
|
|
||||||
|
4827. [misc] Add a precommit check script util/checklibs.sh
|
||||||
|
[RT #46215]
|
||||||
|
|
||||||
|
4826. [cleanup] Prevent potential build failures in bin/confgen/ and
|
||||||
|
bin/named/ when using parallel make. [RT #46648]
|
||||||
|
|
||||||
|
4825. [bug] Prevent a bogus "error during managed-keys processing
|
||||||
|
(no more)" warning from being logged. [RT #46645]
|
||||||
|
|
||||||
|
4824. [port] Add iOS hooks to dig. [RT #42011]
|
||||||
|
|
||||||
|
4823. [test] Refactor reclimit system test to improve its
|
||||||
|
reliability and speed. [RT #46632]
|
||||||
|
|
||||||
|
4822. [bug] Use resign_sooner in dns_db_setsigningtime. [RT #46473]
|
||||||
|
|
||||||
|
4821. [bug] When resigning ensure that the SOA's expire time is
|
||||||
|
always later that the resigning time of other records.
|
||||||
|
[RT #46473]
|
||||||
|
|
||||||
|
4820. [bug] dns_db_subtractrdataset should transfer the resigning
|
||||||
|
information to the new header. [RT #46473]
|
||||||
|
|
||||||
|
4819. [bug] Fully backout the transaction when adding a RRset
|
||||||
|
to the resigning / removal heaps fails. [RT #46473]
|
||||||
|
|
||||||
|
4818. [test] The logfileconfig system test could intermittently
|
||||||
|
report false negatives on some platforms. [RT #46615]
|
||||||
|
|
||||||
|
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
|
||||||
|
[RT #45433]
|
||||||
|
|
||||||
|
4816. [bug] Don't use a common array for storing EDNS options
|
||||||
|
in DiG as it could fill up. [RT #45611]
|
||||||
|
|
||||||
|
4815. [bug] rbt_test.c:insert_and_delete needed to call
|
||||||
|
dns_rbt_addnode instead of dns_rbt_addname. [RT #46553]
|
||||||
|
|
||||||
|
4814. [cleanup] Use AS_HELP_STRING for consistent help text. [RT #46521]
|
||||||
|
|
||||||
|
4813. [bug] Address potential read after free errors from
|
||||||
|
query_synthnodata, query_synthwildcard and
|
||||||
|
query_synthnxdomain. [RT #46547]
|
||||||
|
|
||||||
|
4812. [bug] Minor improvements to stability and consistency of code
|
||||||
|
handling managed keys. [RT #46468]
|
||||||
|
|
||||||
|
4811. [bug] Revert api changes to use <isc/buffer.h> inline
|
||||||
|
macros. Provide a alternative mechanism to turn
|
||||||
|
on the use of inline macros when building BIND.
|
||||||
|
[RT #46520]
|
||||||
|
|
||||||
|
4810. [test] The chain system test failed if the IPv6 interfaces
|
||||||
|
were not configured. [RT #46508]
|
||||||
|
|
||||||
|
--- 9.12.0b2 released ---
|
||||||
|
|
||||||
|
4809. [port] Check at configure time whether -latomic is needed
|
||||||
|
for stdatomic.h. [RT #46324]
|
||||||
|
|
||||||
|
4808. [bug] Properly test for zlib.h. [RT #46504]
|
||||||
|
|
||||||
|
4807. [cleanup] isc_rng_randombytes() returns a specified number of
|
||||||
|
bytes from the PRNG; this is now used instead of
|
||||||
|
calling isc_rng_random() multiple times. [RT #46230]
|
||||||
|
|
||||||
|
4806. [func] Log messages related to loading of zones are now
|
||||||
|
directed to the "zoneload" logging category.
|
||||||
|
[RT #41640]
|
||||||
|
|
||||||
|
4805. [bug] TCP4Active and TCP6Active weren't being updated
|
||||||
|
correctly. [RT #46454]
|
||||||
|
|
||||||
|
4804. [port] win32: access() does not work on directories as
|
||||||
|
required by POSIX. Supply a alternative in
|
||||||
|
isc_file_isdirwritable. [RT #46394]
|
||||||
|
|
||||||
|
4803. [placeholder]
|
||||||
|
|
||||||
|
4802. [test] Refactor mkeys system test to make it quicker and more
|
||||||
|
reliable. [RT #45293]
|
||||||
|
|
||||||
|
4801. [func] 'dnssec-lookaside auto;' and 'dnssec-lookaside .
|
||||||
|
trust-anchor dlv.isc.org;' now elicit warnings rather
|
||||||
|
than being fatal configuration errors. [RT #46410]
|
||||||
|
|
||||||
|
4800. [bug] When processing delzone, write one zone config per
|
||||||
|
line to the NZF. [RT #46323]
|
||||||
|
|
||||||
|
4799. [cleanup] Improve clarity of keytable unit tests. [RT #46407]
|
||||||
|
|
||||||
|
4798. [func] Keys specified in "managed-keys" statements
|
||||||
|
are tagged as "initializing" until they have been
|
||||||
|
updated by a key refresh query. If initialization
|
||||||
|
fails it will be visible from "rndc secroots".
|
||||||
|
[RT #46267]
|
||||||
|
|
||||||
|
4797. [func] Removed "isc-hmac-fixup", as the versions of BIND that
|
||||||
|
had the bug it worked around are long past end of
|
||||||
|
life. [RT #46411]
|
||||||
|
|
||||||
|
4796. [bug] Increase the maximum configurable TCP keepalive
|
||||||
|
timeout to 65535. [RT #44710]
|
||||||
|
|
||||||
|
4795. [func] A new statistics counter has been added to track
|
||||||
|
priming queries. [RT #46313]
|
||||||
|
|
||||||
|
4794. [func] "dnssec-checkds -s" specifies a file from which
|
||||||
|
to read a DS set rather than querying the parent.
|
||||||
|
[RT #44667]
|
||||||
|
|
||||||
|
4793. [bug] nsupdate -[46] could overflow the array of server
|
||||||
|
addresses. [RT #46402]
|
||||||
|
|
||||||
|
4792. [bug] Fix map file header correctness check. [RT #38418]
|
||||||
|
|
||||||
|
4791. [doc] Fixed outdated documentation about export libraries.
|
||||||
|
[RT #46341]
|
||||||
|
|
||||||
|
4790. [bug] nsupdate could trigger a require when sending a
|
||||||
|
update to the second address of the server.
|
||||||
|
[RT #45731]
|
||||||
|
|
||||||
|
4789. [cleanup] Check writability of new-zones-directory. [RT #46308]
|
||||||
|
|
||||||
|
4788. [cleanup] When using "update-policy local", log a warning
|
||||||
|
when an update matching the session key is received
|
||||||
|
from a remote host. [RT #46213]
|
||||||
|
|
||||||
|
4787. [cleanup] Turn nsec3param_salt_totext() into a public function,
|
||||||
|
dns_nsec3param_salttotext(), and add unit tests for it.
|
||||||
|
[RT #46289]
|
||||||
|
|
||||||
|
4786. [func] The "filter-aaaa-on-v4" and "filter-aaaa-on-v6"
|
||||||
|
options are no longer conditionally compiled.
|
||||||
|
[RT #46340]
|
||||||
|
|
||||||
|
4785. [func] The hmac-md5 algorithm is no longer recommended for
|
||||||
|
use with RNDC keys. The default in rndc-confgen
|
||||||
|
is now hmac-sha256. [RT #42272]
|
||||||
|
|
||||||
|
4784. [func] The use of dnssec-keygen to generate HMAC keys is
|
||||||
|
deprecated in favor of tsig-keygen. dnssec-keygen
|
||||||
|
will print a warning when used for this purpose.
|
||||||
|
All HMAC algorithms will be removed from
|
||||||
|
dnssec-keygen in a future release. [RT #42272]
|
||||||
|
|
||||||
|
4783. [test] dnssec: 'check that NOTIFY is sent at the end of
|
||||||
|
NSEC3 chain generation failed' required more time
|
||||||
|
on some machines for the IXFR to complete. [RT #46388]
|
||||||
|
|
||||||
|
4782. [test] dnssec: 'checking positive and negative validation
|
||||||
|
with negative trust anchors' required more time to
|
||||||
|
complete on some machines. [RT #46386]
|
||||||
|
|
||||||
|
4781. [maint] B.ROOT-SERVERS.NET is now 199.9.14.201. [RT #45889]
|
||||||
|
|
||||||
|
4780. [bug] When answering ANY queries, don't include the NS
|
||||||
|
RRset in the authority section if it was already
|
||||||
|
in the answer section. [RT #44543]
|
||||||
|
|
||||||
|
4779. [bug] Expire NTA at the start of the second. Don't update
|
||||||
|
the expiry value if the record has already expired
|
||||||
|
after a successful check. [RT #46368]
|
||||||
|
|
||||||
|
4778. [test] Improve synth-from-dnssec testing. [RT #46352]
|
||||||
|
|
||||||
|
4777. [cleanup] Removed a redundant call to configure_view_acl().
|
||||||
|
[RT #46369]
|
||||||
|
|
||||||
|
4776. [bug] Improve portability of ht_test. [RT #46333]
|
||||||
|
|
||||||
|
4775. [bug] Address Coverity warnings in ht_test.c and mem_test.c
|
||||||
|
[RT #46281]
|
||||||
|
|
||||||
|
4774. [bug] <isc/util.h> was incorrectly included in several
|
||||||
|
header files. [RT #46311]
|
||||||
|
|
||||||
|
4773. [doc] Fixed generating Doxygen documentation for functions
|
||||||
|
annotated using certain macros. Miscellaneous
|
||||||
|
Doxygen-related cleanups. [RT #46276]
|
||||||
|
|
||||||
--- 9.12.0b1 released ---
|
--- 9.12.0b1 released ---
|
||||||
|
|
||||||
4772. [test] Expanded unit testing framework for libns, using
|
4772. [test] Expanded unit testing framework for libns, using
|
||||||
@@ -104,7 +296,7 @@
|
|||||||
- Removed DLV key from bind.keys
|
- Removed DLV key from bind.keys
|
||||||
- No longer use ISC DLV by default in delv
|
- No longer use ISC DLV by default in delv
|
||||||
- "dnssec-lookaside auto" and configuration of
|
- "dnssec-lookaside auto" and configuration of
|
||||||
"dnssec-lookaide" with dlv.isc.org as trust
|
"dnssec-lookaide" with dlv.isc.org as the trust
|
||||||
anchor are both now fatal errors.
|
anchor are both now fatal errors.
|
||||||
[RT #46155]
|
[RT #46155]
|
||||||
|
|
||||||
@@ -244,8 +436,8 @@
|
|||||||
4713. [func] Added support for the DNS Response Policy Service
|
4713. [func] Added support for the DNS Response Policy Service
|
||||||
(DNSRPS) API, which allows named to use an external
|
(DNSRPS) API, which allows named to use an external
|
||||||
response policy daemon when built with
|
response policy daemon when built with
|
||||||
"configure --enable-dnsrps". Thanks to Vernon
|
"configure --enable-dnsrps". Thanks to Farsight
|
||||||
Schryver and Farsight Security. [RT #43376]
|
Security. [RT #43376]
|
||||||
|
|
||||||
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
||||||
search domain when retrying with TCP. [RT #45547]
|
search domain when retrying with TCP. [RT #45547]
|
||||||
|
|||||||
@@ -19,4 +19,12 @@ Setting Description
|
|||||||
named-checkzone
|
named-checkzone
|
||||||
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
||||||
rather than ${localstatedir}/run/named/
|
rather than ${localstatedir}/run/named/
|
||||||
|
Increase the maximum number of configurable
|
||||||
|
-DNS_RPZ_MAX_ZONES=64 response policy zones from 32 to 64; this is the
|
||||||
|
highest possible setting
|
||||||
|
Disable the use of inline functions to implement
|
||||||
|
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
||||||
|
may be useful when debugging
|
||||||
|
-DISC_HEAP_CHECK Test heap consistency after every heap
|
||||||
|
operation; used when debugging
|
||||||
|
|
||||||
|
|||||||
@@ -20,3 +20,6 @@ Some of these settings are:
|
|||||||
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
||||||
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
||||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||||
|
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||||
|
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
||||||
|
|`-DISC_HEAP_CHECK`|Test heap consistency after every heap operation; used when debugging|
|
||||||
|
|||||||
@@ -56,12 +56,12 @@ General bug reports can be sent to bind9-bugs@isc.org.
|
|||||||
|
|
||||||
Feature requests can be sent to bind-suggest@isc.org.
|
Feature requests can be sent to bind-suggest@isc.org.
|
||||||
|
|
||||||
Please note that, while ISC's ticketing system is not currently publicly
|
Please note that, while tickets submitted to ISC's ticketing system are
|
||||||
readable, this may change in the future. Please do not include information
|
not initially publicly readable by default, they can be made publicly
|
||||||
in bug reports that you consider to be confidential. For example, when
|
acessible afterward. Please do not include information in bug reports that
|
||||||
sending the contents of your configuration file, it is advisable to
|
you consider to be confidential. In particular, when sending the contents
|
||||||
obscure key secrets; this can be done automatically by using
|
of your configuration file, it is advisable to obscure key secrets: this
|
||||||
named-checkconf -px.
|
can be done automatically by using named-checkconf -px.
|
||||||
|
|
||||||
Professional support and training for BIND are available from ISC at
|
Professional support and training for BIND are available from ISC at
|
||||||
https://www.isc.org/support.
|
https://www.isc.org/support.
|
||||||
@@ -75,8 +75,9 @@ mailman/listinfo/bind-workers.
|
|||||||
|
|
||||||
Contributing to BIND
|
Contributing to BIND
|
||||||
|
|
||||||
A public git repository for BIND is maintained at http://www.isc.org/git/,
|
ISC maintains a public git repository for BIND; details can be found at
|
||||||
and also on Github at https://github.com/isc-projects.
|
http://www.isc.org/git/, and also on Github at https://github.com/
|
||||||
|
isc-projects.
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files: -
|
Information for BIND contributors can be found in the following files: -
|
||||||
General information: doc/dev/contrib.md - BIND 9 code style: doc/dev/
|
General information: doc/dev/contrib.md - BIND 9 code style: doc/dev/
|
||||||
@@ -103,10 +104,8 @@ include:
|
|||||||
* Cached, validated NSEC and other records can now be used to synthesize
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
NXDOMAIN responses.
|
NXDOMAIN responses.
|
||||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
* Setting max-journal-size default now limits the size of journal files
|
* Setting 'max-journal-size default' now limits the size of journal
|
||||||
to twice the size of the zone.
|
files to twice the size of the zone.
|
||||||
* The query handling code has been substantially refactored for improved
|
|
||||||
readability, maintainability and testability .
|
|
||||||
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
||||||
message.
|
message.
|
||||||
* dnstap output files can now be configured to roll automatically when
|
* dnstap output files can now be configured to roll automatically when
|
||||||
@@ -115,10 +114,14 @@ include:
|
|||||||
ISO 8601 (UTC) formats.
|
ISO 8601 (UTC) formats.
|
||||||
* Logging channels and dnstap output files can now be configured to use
|
* Logging channels and dnstap output files can now be configured to use
|
||||||
a timestamp as the suffix when rolling to a new file.
|
a timestamp as the suffix when rolling to a new file.
|
||||||
* named-checkconf -l lists zones found in named.conf.
|
* 'named-checkconf -l' lists zones found in named.conf.
|
||||||
* Added support for the EDNS Padding and Keepalive options.
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
* 'new-zones-directory' option sets the location where the configuration
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
data for zones added by rndc addzone is stored
|
data for zones added by rndc addzone is stored.
|
||||||
|
* The default key algorithm in rndc-confgen is now hmac-sha256.
|
||||||
|
* filter-aaaa-on-v4 and filter-aaaa-on-v6 options are now available by
|
||||||
|
default without a configure option.
|
||||||
|
* The obsolete isc-hmac-fixup command has been removed.
|
||||||
|
|
||||||
Building BIND
|
Building BIND
|
||||||
|
|
||||||
@@ -128,8 +131,8 @@ on many versions of Linux and UNIX, including RedHat, Fedora, Debian,
|
|||||||
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
||||||
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
||||||
|
|
||||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
BIND is also available for Windows 2008 and higher. See win32utils/
|
||||||
win32utils/readme1st.txt for details on building for Windows systems.
|
readme1st.txt for details on building for Windows systems.
|
||||||
|
|
||||||
To build on a UNIX or Linux system, use:
|
To build on a UNIX or Linux system, use:
|
||||||
|
|
||||||
@@ -189,10 +192,11 @@ smaller systems.
|
|||||||
For the server to support DNSSEC, you need to build it with crypto
|
For the server to support DNSSEC, you need to build it with crypto
|
||||||
support. To use OpenSSL, you should have OpenSSL 1.0.2e or newer
|
support. To use OpenSSL, you should have OpenSSL 1.0.2e or newer
|
||||||
installed. If the OpenSSL library is installed in a nonstandard location,
|
installed. If the OpenSSL library is installed in a nonstandard location,
|
||||||
specify the prefix using "--with-openssl=/prefix" on the configure command
|
specify the prefix using "--with-openssl=<PREFIX>" on the configure
|
||||||
line. To use a PKCS#11 hardware service module for cryptographic
|
command line. To use a PKCS#11 hardware service module for cryptographic
|
||||||
operations, specify the path to the PKCS#11 provider library using
|
operations, specify the path to the PKCS#11 provider library using
|
||||||
"--with-pkcs11=/prefix", and configure BIND with "--enable-native-pkcs11".
|
"--with-pkcs11=<PREFIX>", and configure BIND with
|
||||||
|
"--enable-native-pkcs11".
|
||||||
|
|
||||||
To support the HTTP statistics channel, the server must be linked with at
|
To support the HTTP statistics channel, the server must be linked with at
|
||||||
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
||||||
@@ -212,13 +216,16 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
|||||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||||
specify the prefix using "--with-geoip=/prefix".
|
specify the prefix using "--with-geoip=/prefix".
|
||||||
|
|
||||||
For DNSTAP packet logging, you must have libfstrm https://github.com/
|
For DNSTAP packet logging, you must have installed libfstrm https://
|
||||||
farsightsec/fstrm and libprotobuf-c https://developers.google.com/
|
github.com/farsightsec/fstrm and libprotobuf-c https://
|
||||||
protocol-buffers, and BIND must be configured with "--enable-dnstap".
|
developers.google.com/protocol-buffers, and BIND must be configured with
|
||||||
|
"--enable-dnstap".
|
||||||
|
|
||||||
Python requires the 'argparse' and 'ply' modules to be available.
|
Portions of BIND that are written in Python, including dnssec-keymgr,
|
||||||
'argparse' is a standard module as of Python 2.7 and Python 3.2. 'ply' is
|
dnssec-coverage, dnssec-checkds, and some of the system tests, require the
|
||||||
available from https://pypi.python.org/pypi/ply.
|
'argparse' and 'ply' modules to be available. 'argparse' is a standard
|
||||||
|
module as of Python 2.7 and Python 3.2. 'ply' is available from https://
|
||||||
|
pypi.python.org/pypi/ply.
|
||||||
|
|
||||||
On some platforms it is necessary to explicitly request large file support
|
On some platforms it is necessary to explicitly request large file support
|
||||||
to handle files bigger than 2GB. This can be done by using
|
to handle files bigger than 2GB. This can be done by using
|
||||||
@@ -250,7 +257,7 @@ Automated testing
|
|||||||
A system test suite can be run with make test. The system tests require
|
A system test suite can be run with make test. The system tests require
|
||||||
you to configure a set of virtual IP addresses on your system (this allows
|
you to configure a set of virtual IP addresses on your system (this allows
|
||||||
multiple servers to run locally and communicate with one another). These
|
multiple servers to run locally and communicate with one another). These
|
||||||
IP addresses can be configured by by running the script bin/tests/system/
|
IP addresses can be configured by running the command bin/tests/system/
|
||||||
ifconfig.sh up as root.
|
ifconfig.sh up as root.
|
||||||
|
|
||||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||||
|
|||||||
@@ -66,12 +66,12 @@ General bug reports can be sent to
|
|||||||
Feature requests can be sent to
|
Feature requests can be sent to
|
||||||
[bind-suggest@isc.org](mailto:bind-suggest@isc.org).
|
[bind-suggest@isc.org](mailto:bind-suggest@isc.org).
|
||||||
|
|
||||||
Please note that, while ISC's ticketing system is not currently publicly
|
Please note that, while tickets submitted to ISC's ticketing system
|
||||||
readable, this may change in the future. Please do not include information
|
are not initially publicly readable by default, they can be made publicly
|
||||||
in bug reports that you consider to be confidential. For example, when
|
acessible afterward. Please do not include information in bug reports that
|
||||||
sending the contents of your configuration file, it is advisable to obscure
|
you consider to be confidential. In particular, when sending the contents of
|
||||||
key secrets; this can be done automatically by using `named-checkconf
|
your configuration file, it is advisable to obscure key secrets: this can
|
||||||
-px`.
|
be done automatically by using `named-checkconf -px`.
|
||||||
|
|
||||||
Professional support and training for BIND are available from
|
Professional support and training for BIND are available from
|
||||||
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
||||||
@@ -85,8 +85,8 @@ may also want to join the __BIND Workers__ mailing list, at
|
|||||||
|
|
||||||
### <a name="contrib"/> Contributing to BIND
|
### <a name="contrib"/> Contributing to BIND
|
||||||
|
|
||||||
A public git repository for BIND is maintained at
|
ISC maintains a public git repository for BIND; details can be found
|
||||||
[http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
at [http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||||
at [https://github.com/isc-projects](https://github.com/isc-projects).
|
at [https://github.com/isc-projects](https://github.com/isc-projects).
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files:
|
Information for BIND contributors can be found in the following files:
|
||||||
@@ -116,10 +116,8 @@ include:
|
|||||||
* Cached, validated NSEC and other records can now be used to synthesize
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
NXDOMAIN responses.
|
NXDOMAIN responses.
|
||||||
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
* Setting `max-journal-size default` now limits the size of journal files
|
* Setting `'max-journal-size default'` now limits the size of journal files
|
||||||
to twice the size of the zone.
|
to twice the size of the zone.
|
||||||
* The query handling code has been substantially refactored for improved
|
|
||||||
readability, maintainability and testability .
|
|
||||||
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
||||||
DNS message.
|
DNS message.
|
||||||
* `dnstap` output files can now be configured to roll automatically when
|
* `dnstap` output files can now be configured to roll automatically when
|
||||||
@@ -128,10 +126,14 @@ include:
|
|||||||
8601 (UTC) formats.
|
8601 (UTC) formats.
|
||||||
* Logging channels and `dnstap` output files can now be configured to use a
|
* Logging channels and `dnstap` output files can now be configured to use a
|
||||||
timestamp as the suffix when rolling to a new file.
|
timestamp as the suffix when rolling to a new file.
|
||||||
* `named-checkconf -l` lists zones found in `named.conf`.
|
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||||
* Added support for the EDNS Padding and Keepalive options.
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
* 'new-zones-directory' option sets the location where the configuration
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
data for zones added by rndc addzone is stored
|
data for zones added by rndc addzone is stored.
|
||||||
|
* The default key algorithm in `rndc-confgen` is now hmac-sha256.
|
||||||
|
* `filter-aaaa-on-v4` and `filter-aaaa-on-v6` options are now available
|
||||||
|
by default without a configure option.
|
||||||
|
* The obsolete `isc-hmac-fixup` command has been removed.
|
||||||
|
|
||||||
### <a name="build"/> Building BIND
|
### <a name="build"/> Building BIND
|
||||||
|
|
||||||
@@ -141,8 +143,9 @@ many versions of Linux and UNIX, including RedHat, Fedora, Debian, Ubuntu,
|
|||||||
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
||||||
SCO OpenServer, and OpenWRT.
|
SCO OpenServer, and OpenWRT.
|
||||||
|
|
||||||
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
BIND is also available for Windows 2008 and higher. See
|
||||||
`win32utils/readme1st.txt` for details on building for Windows systems.
|
`win32utils/readme1st.txt` for details on building for Windows
|
||||||
|
systems.
|
||||||
|
|
||||||
To build on a UNIX or Linux system, use:
|
To build on a UNIX or Linux system, use:
|
||||||
|
|
||||||
@@ -195,9 +198,9 @@ performance on smaller systems.
|
|||||||
For the server to support DNSSEC, you need to build it with crypto support.
|
For the server to support DNSSEC, you need to build it with crypto support.
|
||||||
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
To use OpenSSL, you should have OpenSSL 1.0.2e or newer installed. If the
|
||||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||||
using "--with-openssl=/prefix" on the configure command line. To use a
|
using "--with-openssl=<PREFIX>" on the configure command line. To use a
|
||||||
PKCS#11 hardware service module for cryptographic operations, specify the
|
PKCS#11 hardware service module for cryptographic operations, specify the
|
||||||
path to the PKCS#11 provider library using "--with-pkcs11=/prefix", and
|
path to the PKCS#11 provider library using "--with-pkcs11=<PREFIX>", and
|
||||||
configure BIND with "--enable-native-pkcs11".
|
configure BIND with "--enable-native-pkcs11".
|
||||||
|
|
||||||
To support the HTTP statistics channel, the server must be linked with at
|
To support the HTTP statistics channel, the server must be linked with at
|
||||||
@@ -220,13 +223,15 @@ libGeoIP. This is not turned on by default; BIND must be configured with
|
|||||||
"--with-geoip". If the library is installed in a nonstandard location, use
|
"--with-geoip". If the library is installed in a nonstandard location, use
|
||||||
specify the prefix using "--with-geoip=/prefix".
|
specify the prefix using "--with-geoip=/prefix".
|
||||||
|
|
||||||
For DNSTAP packet logging, you must have libfstrm
|
For DNSTAP packet logging, you must have installed libfstrm
|
||||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||||
and libprotobuf-c
|
and libprotobuf-c
|
||||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
||||||
and BIND must be configured with "--enable-dnstap".
|
and BIND must be configured with "--enable-dnstap".
|
||||||
|
|
||||||
Python requires the 'argparse' and 'ply' modules to be available.
|
Portions of BIND that are written in Python, including
|
||||||
|
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||||
|
system tests, require the 'argparse' and 'ply' modules to be available.
|
||||||
'argparse' is a standard module as of Python 2.7 and Python 3.2.
|
'argparse' is a standard module as of Python 2.7 and Python 3.2.
|
||||||
'ply' is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
'ply' is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||||
|
|
||||||
@@ -260,7 +265,7 @@ localstatedir defaults to `$prefix/var`.
|
|||||||
A system test suite can be run with `make test`. The system tests require
|
A system test suite can be run with `make test`. The system tests require
|
||||||
you to configure a set of virtual IP addresses on your system (this allows
|
you to configure a set of virtual IP addresses on your system (this allows
|
||||||
multiple servers to run locally and communicate with one another). These
|
multiple servers to run locally and communicate with one another). These
|
||||||
IP addresses can be configured by by running the script
|
IP addresses can be configured by running the command
|
||||||
`bin/tests/system/ifconfig.sh up` as root.
|
`bin/tests/system/ifconfig.sh up` as root.
|
||||||
|
|
||||||
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
Some tests require Perl and the Net::DNS and/or IO::Socket::INET6 modules,
|
||||||
|
|||||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
|||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
# Attempt to disable parallel processing.
|
||||||
|
.NOTPARALLEL:
|
||||||
|
.NO_PARALLEL:
|
||||||
|
|
||||||
VERSION=@BIND9_VERSION@
|
VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
@@ -64,11 +68,11 @@ rndc-confgen.@O@: rndc-confgen.c
|
|||||||
ddns-confgen.@O@: ddns-confgen.c
|
ddns-confgen.@O@: ddns-confgen.c
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
||||||
|
|
||||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||||
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
||||||
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -111,7 +111,7 @@ as directed\&.
|
|||||||
.PP
|
.PP
|
||||||
\-A \fIalgorithm\fR
|
\-A \fIalgorithm\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-md5 or if MD5 was disabled hmac\-sha256\&.
|
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-sha256\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-b \fIkeysize\fR
|
\-b \fIkeysize\fR
|
||||||
@@ -217,5 +217,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,13 +1,11 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/* $Id: rndc-confgen.c,v 1.7 2011/03/12 04:59:46 tbox Exp $ */
|
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -67,23 +65,6 @@ usage(int status) ISC_PLATFORM_NORETURN_POST;
|
|||||||
static void
|
static void
|
||||||
usage(int status) {
|
usage(int status) {
|
||||||
|
|
||||||
#ifndef PK11_MD5_DISABLE
|
|
||||||
fprintf(stderr, "\
|
|
||||||
Usage:\n\
|
|
||||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
|
||||||
[-s addr] [-t chrootdir] [-u user]\n\
|
|
||||||
-a: generate just the key clause and write it to keyfile (%s)\n\
|
|
||||||
-A alg: algorithm (default hmac-md5)\n\
|
|
||||||
-b bits: from 1 through 512, default 256; total length of the secret\n\
|
|
||||||
-c keyfile: specify an alternate key file (requires -a)\n\
|
|
||||||
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
|
||||||
-p port: the port named will listen on and rndc will connect to\n\
|
|
||||||
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
|
||||||
-s addr: the address to which rndc should connect\n\
|
|
||||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
|
||||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
|
||||||
progname, keydef);
|
|
||||||
#else
|
|
||||||
fprintf(stderr, "\
|
fprintf(stderr, "\
|
||||||
Usage:\n\
|
Usage:\n\
|
||||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||||
@@ -99,7 +80,6 @@ Usage:\n\
|
|||||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||||
progname, keydef);
|
progname, keydef);
|
||||||
#endif
|
|
||||||
|
|
||||||
exit (status);
|
exit (status);
|
||||||
}
|
}
|
||||||
@@ -135,11 +115,7 @@ main(int argc, char **argv) {
|
|||||||
progname = program;
|
progname = program;
|
||||||
|
|
||||||
keyname = DEFAULT_KEYNAME;
|
keyname = DEFAULT_KEYNAME;
|
||||||
#ifndef PK11_MD5_DISABLE
|
|
||||||
alg = DST_ALG_HMACMD5;
|
|
||||||
#else
|
|
||||||
alg = DST_ALG_HMACSHA256;
|
alg = DST_ALG_HMACSHA256;
|
||||||
#endif
|
|
||||||
serveraddr = DEFAULT_SERVER;
|
serveraddr = DEFAULT_SERVER;
|
||||||
port = DEFAULT_PORT;
|
port = DEFAULT_PORT;
|
||||||
|
|
||||||
@@ -225,6 +201,12 @@ main(int argc, char **argv) {
|
|||||||
if (argc > 0)
|
if (argc > 0)
|
||||||
usage(1);
|
usage(1);
|
||||||
|
|
||||||
|
if (alg == DST_ALG_HMACMD5) {
|
||||||
|
fprintf(stderr,
|
||||||
|
"warning: use of hmac-md5 for RNDC keys "
|
||||||
|
"is deprecated; hmac-sha256 is now recommended.\n");
|
||||||
|
}
|
||||||
|
|
||||||
if (keysize < 0)
|
if (keysize < 0)
|
||||||
keysize = alg_bits(alg);
|
keysize = alg_bits(alg);
|
||||||
algname = alg_totext(alg);
|
algname = alg_totext(alg);
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,6 +39,7 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
|
<year>2017</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -128,8 +129,7 @@
|
|||||||
<para>
|
<para>
|
||||||
Specifies the algorithm to use for the TSIG key. Available
|
Specifies the algorithm to use for the TSIG key. Available
|
||||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||||
if MD5 was disabled hmac-sha256.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -113,8 +113,7 @@
|
|||||||
<p>
|
<p>
|
||||||
Specifies the algorithm to use for the TSIG key. Available
|
Specifies the algorithm to use for the TSIG key. Available
|
||||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||||
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
||||||
if MD5 was disabled hmac-sha256.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
||||||
|
|||||||
@@ -469,6 +469,11 @@ Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to hav
|
|||||||
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\fB+[no]keepalive\fR
|
||||||
|
.RS 4
|
||||||
|
Send [or do not send] an EDNS Keepalive option\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\fB+[no]keepopen\fR
|
\fB+[no]keepopen\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
||||||
|
|||||||
+74
-38
@@ -109,6 +109,11 @@ print_usage(FILE *fp) {
|
|||||||
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#if TARGET_OS_IPHONE
|
||||||
|
static void usage(void) {
|
||||||
|
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||||
|
}
|
||||||
|
#else
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
@@ -119,6 +124,7 @@ usage(void) {
|
|||||||
"for complete list of options\n", stderr);
|
"for complete list of options\n", stderr);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
/*% version */
|
/*% version */
|
||||||
static void
|
static void
|
||||||
@@ -414,14 +420,8 @@ isdotlocal(dns_message_t *msg) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
static unsigned char local_ndata[] = { "\005local\0" };
|
static unsigned char local_ndata[] = { "\005local\0" };
|
||||||
static unsigned char local_offsets[] = { 0, 6 };
|
static unsigned char local_offsets[] = { 0, 6 };
|
||||||
static dns_name_t local = {
|
static dns_name_t local =
|
||||||
DNS_NAME_MAGIC,
|
DNS_NAME_INITABSOLUTE(local_ndata, local_offsets);
|
||||||
local_ndata, 7, 2,
|
|
||||||
DNS_NAMEATTR_READONLY | DNS_NAMEATTR_ABSOLUTE,
|
|
||||||
local_offsets, NULL,
|
|
||||||
{(void *)-1, (void *)-1},
|
|
||||||
{NULL, NULL}
|
|
||||||
};
|
|
||||||
|
|
||||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -824,8 +824,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&num, value, COMMSIZE,
|
result = parse_uint(&num, value, COMMSIZE,
|
||||||
"buffer size");
|
"buffer size");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse buffer size");
|
warn("Couldn't parse buffer size");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->udpsize = num;
|
lookup->udpsize = num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -870,8 +872,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
n = strlcpy(hexcookie, value,
|
n = strlcpy(hexcookie, value,
|
||||||
sizeof(hexcookie));
|
sizeof(hexcookie));
|
||||||
if (n >= sizeof(hexcookie))
|
if (n >= sizeof(hexcookie)) {
|
||||||
fatal("COOKIE data too large");
|
warn("COOKIE data too large");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->cookie = hexcookie;
|
lookup->cookie = hexcookie;
|
||||||
} else
|
} else
|
||||||
lookup->cookie = NULL;
|
lookup->cookie = NULL;
|
||||||
@@ -922,8 +926,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value == NULL)
|
if (value == NULL)
|
||||||
goto need_value;
|
goto need_value;
|
||||||
result = parse_uint(&num, value, 0x3f, "DSCP");
|
result = parse_uint(&num, value, 0x3f, "DSCP");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse DSCP value");
|
warn("Couldn't parse DSCP value");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->dscp = num;
|
lookup->dscp = num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -952,9 +958,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
value,
|
value,
|
||||||
255,
|
255,
|
||||||
"edns");
|
"edns");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse "
|
warn("Couldn't parse "
|
||||||
"edns");
|
"edns");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->edns = num;
|
lookup->edns = num;
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
@@ -971,9 +979,11 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
value,
|
value,
|
||||||
0xffff,
|
0xffff,
|
||||||
"ednsflags");
|
"ednsflags");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse "
|
warn("Couldn't parse "
|
||||||
"ednsflags");
|
"ednsflags");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->ednsflags = num;
|
lookup->ednsflags = num;
|
||||||
break;
|
break;
|
||||||
case 'n':
|
case 'n':
|
||||||
@@ -986,10 +996,12 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
lookup->ednsoptscnt = 0;
|
lookup->ednsoptscnt = 0;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (value == NULL)
|
if (value == NULL) {
|
||||||
fatal("ednsopt no "
|
warn("ednsopt no "
|
||||||
"code point "
|
"code point "
|
||||||
"specified");
|
"specified");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
code = next_token(&value, ":");
|
code = next_token(&value, ":");
|
||||||
save_opt(lookup, code, value);
|
save_opt(lookup, code, value);
|
||||||
break;
|
break;
|
||||||
@@ -1104,8 +1116,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
if (!state)
|
if (!state)
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse ndots");
|
warn("Couldn't parse ndots");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
ndots = num;
|
ndots = num;
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
@@ -1167,8 +1181,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
result = parse_uint(&num, value, 15, "opcode");
|
result = parse_uint(&num, value, 15, "opcode");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse opcode");
|
warn("Couldn't parse opcode");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->opcode = (dns_opcode_t)num;
|
lookup->opcode = (dns_opcode_t)num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -1182,8 +1198,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value == NULL)
|
if (value == NULL)
|
||||||
goto need_value;
|
goto need_value;
|
||||||
result = parse_uint(&num, value, 512, "padding");
|
result = parse_uint(&num, value, 512, "padding");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse padding");
|
warn("Couldn't parse padding");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->padding = (isc_uint16_t)num;
|
lookup->padding = (isc_uint16_t)num;
|
||||||
break;
|
break;
|
||||||
case 'q':
|
case 'q':
|
||||||
@@ -1222,8 +1240,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&lookup->retries, value,
|
result = parse_uint(&lookup->retries, value,
|
||||||
MAXTRIES - 1, "retries");
|
MAXTRIES - 1, "retries");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse retries");
|
warn("Couldn't parse retries");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
lookup->retries++;
|
lookup->retries++;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -1306,8 +1326,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
*/
|
*/
|
||||||
if (splitwidth)
|
if (splitwidth)
|
||||||
splitwidth += 3;
|
splitwidth += 3;
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse split");
|
warn("Couldn't parse split");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case 't': /* stats */
|
case 't': /* stats */
|
||||||
FULLCHECK("stats");
|
FULLCHECK("stats");
|
||||||
@@ -1331,8 +1353,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
lookup->ecs_addr = NULL;
|
lookup->ecs_addr = NULL;
|
||||||
}
|
}
|
||||||
result = parse_netprefix(&lookup->ecs_addr, value);
|
result = parse_netprefix(&lookup->ecs_addr, value);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse client");
|
warn("Couldn't parse client");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
@@ -1355,8 +1379,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
||||||
"timeout");
|
"timeout");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse timeout");
|
warn("Couldn't parse timeout");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
if (timeout == 0)
|
if (timeout == 0)
|
||||||
timeout = 1;
|
timeout = 1;
|
||||||
break;
|
break;
|
||||||
@@ -1392,8 +1418,10 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&lookup->retries, value,
|
result = parse_uint(&lookup->retries, value,
|
||||||
MAXTRIES, "tries");
|
MAXTRIES, "tries");
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Couldn't parse tries");
|
warn("Couldn't parse tries");
|
||||||
|
goto exit_or_usage;
|
||||||
|
}
|
||||||
if (lookup->retries == 0)
|
if (lookup->retries == 0)
|
||||||
lookup->retries = 1;
|
lookup->retries = 1;
|
||||||
break;
|
break;
|
||||||
@@ -1450,11 +1478,19 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
|||||||
default:
|
default:
|
||||||
invalid_option:
|
invalid_option:
|
||||||
need_value:
|
need_value:
|
||||||
|
#if TARGET_OS_IPHONE
|
||||||
|
exit_or_usage:
|
||||||
|
#endif
|
||||||
fprintf(stderr, "Invalid option: +%s\n",
|
fprintf(stderr, "Invalid option: +%s\n",
|
||||||
option);
|
option);
|
||||||
usage();
|
usage();
|
||||||
}
|
}
|
||||||
return;
|
return;
|
||||||
|
|
||||||
|
#if ! TARGET_OS_IPHONE
|
||||||
|
exit_or_usage:
|
||||||
|
digexit();
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
|
|||||||
@@ -784,6 +784,15 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term><option>+[no]keepalive</option></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Send [or do not send] an EDNS Keepalive option.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]keepopen</option></term>
|
<term><option>+[no]keepopen</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -628,6 +628,12 @@
|
|||||||
with TCP. By default, TCP retries are performed.
|
with TCP. By default, TCP retries are performed.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term"><code class="option">+[no]keepalive</code></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Send [or do not send] an EDNS Keepalive option.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
+112
-31
@@ -375,6 +375,46 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
void (*dighost_pre_exit_hook)(void) = NULL;
|
||||||
|
|
||||||
|
#if TARGET_OS_IPHONE
|
||||||
|
void
|
||||||
|
warn(const char *format, ...) {
|
||||||
|
va_list args;
|
||||||
|
|
||||||
|
fflush(stdout);
|
||||||
|
fprintf(stderr, ";; Warning: ");
|
||||||
|
va_start(args, format);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
va_end(args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
}
|
||||||
|
#else
|
||||||
|
void
|
||||||
|
warn(const char *format, ...) {
|
||||||
|
va_list args;
|
||||||
|
|
||||||
|
fflush(stdout);
|
||||||
|
fprintf(stderr, "%s: ", progname);
|
||||||
|
va_start(args, format);
|
||||||
|
vfprintf(stderr, format, args);
|
||||||
|
va_end(args);
|
||||||
|
fprintf(stderr, "\n");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
|
void
|
||||||
|
digexit(void) {
|
||||||
|
if (exitcode < 10)
|
||||||
|
exitcode = 10;
|
||||||
|
if (fatalexit != 0)
|
||||||
|
exitcode = fatalexit;
|
||||||
|
if (dighost_pre_exit_hook != NULL) {
|
||||||
|
dighost_pre_exit_hook();
|
||||||
|
}
|
||||||
|
exit(exitcode);
|
||||||
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
fatal(const char *format, ...) {
|
fatal(const char *format, ...) {
|
||||||
va_list args;
|
va_list args;
|
||||||
@@ -385,11 +425,7 @@ fatal(const char *format, ...) {
|
|||||||
vfprintf(stderr, format, args);
|
vfprintf(stderr, format, args);
|
||||||
va_end(args);
|
va_end(args);
|
||||||
fprintf(stderr, "\n");
|
fprintf(stderr, "\n");
|
||||||
if (exitcode < 10)
|
digexit();
|
||||||
exitcode = 10;
|
|
||||||
if (fatalexit != 0)
|
|
||||||
exitcode = fatalexit;
|
|
||||||
exit(exitcode);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -655,6 +691,41 @@ make_empty_lookup(void) {
|
|||||||
return (looknew);
|
return (looknew);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#define EDNSOPT_OPTIONS 100U
|
||||||
|
|
||||||
|
static void
|
||||||
|
cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
||||||
|
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
||||||
|
size_t i;
|
||||||
|
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
||||||
|
if (looknew->ednsopts == NULL)
|
||||||
|
fatal("out of memory");
|
||||||
|
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||||
|
looknew->ednsopts[i].code = 0;
|
||||||
|
looknew->ednsopts[i].length = 0;
|
||||||
|
looknew->ednsopts[i].value = NULL;
|
||||||
|
}
|
||||||
|
looknew->ednsoptscnt = 0;
|
||||||
|
if (lookold == NULL || lookold->ednsopts == NULL)
|
||||||
|
return;
|
||||||
|
|
||||||
|
for (i = 0; i < lookold->ednsoptscnt; i++) {
|
||||||
|
len = lookold->ednsopts[i].length;
|
||||||
|
if (len != 0) {
|
||||||
|
INSIST(lookold->ednsopts[i].value != NULL);
|
||||||
|
looknew->ednsopts[i].value =
|
||||||
|
isc_mem_allocate(mctx, len);
|
||||||
|
if (looknew->ednsopts[i].value == NULL)
|
||||||
|
fatal("out of memory");
|
||||||
|
memmove(looknew->ednsopts[i].value,
|
||||||
|
lookold->ednsopts[i].value, len);
|
||||||
|
}
|
||||||
|
looknew->ednsopts[i].code = lookold->ednsopts[i].code;
|
||||||
|
looknew->ednsopts[i].length = len;
|
||||||
|
}
|
||||||
|
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||||
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Clone a lookup, perhaps copying the server list. This does not clone
|
* Clone a lookup, perhaps copying the server list. This does not clone
|
||||||
* the query list, since it will be regenerated by the setup_lookup()
|
* the query list, since it will be regenerated by the setup_lookup()
|
||||||
@@ -700,8 +771,12 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
|||||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||||
looknew->badcookie = lookold->badcookie;
|
looknew->badcookie = lookold->badcookie;
|
||||||
looknew->cookie = lookold->cookie;
|
looknew->cookie = lookold->cookie;
|
||||||
looknew->ednsopts = lookold->ednsopts;
|
if (lookold->ednsopts != NULL) {
|
||||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
cloneopts(looknew, lookold);
|
||||||
|
} else {
|
||||||
|
looknew->ednsopts = NULL;
|
||||||
|
looknew->ednsoptscnt = 0;
|
||||||
|
}
|
||||||
looknew->ednsneg = lookold->ednsneg;
|
looknew->ednsneg = lookold->ednsneg;
|
||||||
looknew->padding = lookold->padding;
|
looknew->padding = lookold->padding;
|
||||||
looknew->mapped = lookold->mapped;
|
looknew->mapped = lookold->mapped;
|
||||||
@@ -1317,13 +1392,6 @@ setup_libs(void) {
|
|||||||
check_result(result, "isc_mutex_init");
|
check_result(result, "isc_mutex_init");
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
|
||||||
* Array of up to 100 options configured by +ednsopt
|
|
||||||
*/
|
|
||||||
#define EDNSOPT_OPTIONS 100U
|
|
||||||
static dns_ednsopt_t ednsopts[EDNSOPT_OPTIONS];
|
|
||||||
static unsigned char ednsoptscnt = 0;
|
|
||||||
|
|
||||||
typedef struct dig_ednsoptname {
|
typedef struct dig_ednsoptname {
|
||||||
isc_uint32_t code;
|
isc_uint32_t code;
|
||||||
const char *name;
|
const char *name;
|
||||||
@@ -1350,12 +1418,12 @@ dig_ednsoptname_t optnames[] = {
|
|||||||
void
|
void
|
||||||
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_uint32_t num;
|
isc_uint32_t num = 0;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
isc_boolean_t found = ISC_FALSE;
|
isc_boolean_t found = ISC_FALSE;
|
||||||
unsigned int i;
|
unsigned int i;
|
||||||
|
|
||||||
if (ednsoptscnt == EDNSOPT_OPTIONS)
|
if (lookup->ednsoptscnt >= EDNSOPT_OPTIONS)
|
||||||
fatal("too many ednsopts");
|
fatal("too many ednsopts");
|
||||||
|
|
||||||
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
||||||
@@ -1372,9 +1440,16 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
|||||||
fatal("bad edns code point: %s", code);
|
fatal("bad edns code point: %s", code);
|
||||||
}
|
}
|
||||||
|
|
||||||
ednsopts[ednsoptscnt].code = num;
|
if (lookup->ednsopts == NULL) {
|
||||||
ednsopts[ednsoptscnt].length = 0;
|
cloneopts(lookup, NULL);
|
||||||
ednsopts[ednsoptscnt].value = NULL;
|
}
|
||||||
|
|
||||||
|
if (lookup->ednsopts[lookup->ednsoptscnt].value != NULL)
|
||||||
|
isc_mem_free(mctx, lookup->ednsopts[lookup->ednsoptscnt].value);
|
||||||
|
|
||||||
|
lookup->ednsopts[lookup->ednsoptscnt].code = num;
|
||||||
|
lookup->ednsopts[lookup->ednsoptscnt].length = 0;
|
||||||
|
lookup->ednsopts[lookup->ednsoptscnt].value = NULL;
|
||||||
|
|
||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
char *buf;
|
char *buf;
|
||||||
@@ -1384,14 +1459,13 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
|||||||
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
||||||
result = isc_hex_decodestring(value, &b);
|
result = isc_hex_decodestring(value, &b);
|
||||||
check_result(result, "isc_hex_decodestring");
|
check_result(result, "isc_hex_decodestring");
|
||||||
ednsopts[ednsoptscnt].value = isc_buffer_base(&b);
|
lookup->ednsopts[lookup->ednsoptscnt].value =
|
||||||
ednsopts[ednsoptscnt].length = isc_buffer_usedlength(&b);
|
isc_buffer_base(&b);
|
||||||
|
lookup->ednsopts[lookup->ednsoptscnt].length =
|
||||||
|
isc_buffer_usedlength(&b);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (lookup->ednsoptscnt == 0)
|
|
||||||
lookup->ednsopts = &ednsopts[ednsoptscnt];
|
|
||||||
lookup->ednsoptscnt++;
|
lookup->ednsoptscnt++;
|
||||||
ednsoptscnt++;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -1570,6 +1644,15 @@ destroy_lookup(dig_lookup_t *lookup) {
|
|||||||
if (lookup->ecs_addr != NULL)
|
if (lookup->ecs_addr != NULL)
|
||||||
isc_mem_free(mctx, lookup->ecs_addr);
|
isc_mem_free(mctx, lookup->ecs_addr);
|
||||||
|
|
||||||
|
if (lookup->ednsopts != NULL) {
|
||||||
|
size_t i;
|
||||||
|
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||||
|
if (lookup->ednsopts[i].value != NULL)
|
||||||
|
isc_mem_free(mctx, lookup->ednsopts[i].value);
|
||||||
|
}
|
||||||
|
isc_mem_free(mctx, lookup->ednsopts);
|
||||||
|
}
|
||||||
|
|
||||||
isc_mem_free(mctx, lookup);
|
isc_mem_free(mctx, lookup);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2114,9 +2197,13 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
dns_message_puttempname(lookup->sendmsg,
|
dns_message_puttempname(lookup->sendmsg,
|
||||||
&lookup->name);
|
&lookup->name);
|
||||||
fatal("'%s' is not a legal name "
|
warn("'%s' is not a legal name "
|
||||||
"(%s)", lookup->textname,
|
"(%s)", lookup->textname,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
#if TARGET_OS_IPHONE
|
||||||
|
check_next_lookup(current_lookup);
|
||||||
|
return (ISC_FALSE);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
dns_name_format(lookup->name, store, sizeof(store));
|
dns_name_format(lookup->name, store, sizeof(store));
|
||||||
@@ -4127,12 +4214,6 @@ destroy_libs(void) {
|
|||||||
debug("Removing log context");
|
debug("Removing log context");
|
||||||
isc_log_destroy(&lctx);
|
isc_log_destroy(&lctx);
|
||||||
|
|
||||||
while (ednsoptscnt > 0U) {
|
|
||||||
ednsoptscnt--;
|
|
||||||
if (ednsopts[ednsoptscnt].value != NULL)
|
|
||||||
isc_mem_free(mctx, ednsopts[ednsoptscnt].value);
|
|
||||||
}
|
|
||||||
|
|
||||||
debug("Destroy memory");
|
debug("Destroy memory");
|
||||||
if (memdebugging != 0)
|
if (memdebugging != 0)
|
||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
|
|||||||
@@ -26,6 +26,10 @@
|
|||||||
#include <isc/sockaddr.h>
|
#include <isc/sockaddr.h>
|
||||||
#include <isc/socket.h>
|
#include <isc/socket.h>
|
||||||
|
|
||||||
|
#ifdef __APPLE__
|
||||||
|
#include <TargetConditionals.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#define MXSERV 20
|
#define MXSERV 20
|
||||||
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
||||||
#define MXRD 32
|
#define MXRD 32
|
||||||
@@ -282,6 +286,13 @@ ISC_PLATFORM_NORETURN_PRE void
|
|||||||
fatal(const char *format, ...)
|
fatal(const char *format, ...)
|
||||||
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
|
void
|
||||||
|
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
|
ISC_PLATFORM_NORETURN_PRE void
|
||||||
|
digexit(void)
|
||||||
|
ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
void
|
void
|
||||||
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
@@ -384,6 +395,9 @@ extern void
|
|||||||
extern void
|
extern void
|
||||||
(*dighost_shutdown)(void);
|
(*dighost_shutdown)(void);
|
||||||
|
|
||||||
|
extern void
|
||||||
|
(*dighost_pre_exit_hook)(void);
|
||||||
|
|
||||||
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
||||||
|
|
||||||
void setup_file_key(void);
|
void setup_file_key(void);
|
||||||
|
|||||||
@@ -62,12 +62,15 @@ may be preferable to direct use of
|
|||||||
.RS 4
|
.RS 4
|
||||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||||
\fBalgorithm\fR
|
\fBalgorithm\fR
|
||||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TSIG/TKEY keys, the value must be one of DH (Diffie Hellman), HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512; specifying any of these algorithms will automatically set the
|
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
|
||||||
\fB\-T KEY\fR
|
\fB\-T KEY\fR
|
||||||
option as well\&. (Note:
|
option as well\&.
|
||||||
|
.sp
|
||||||
|
TSIG keys can also be generated by setting the value to one of HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512\&. As with DH, specifying these values will automatically set
|
||||||
|
\fB\-T KEY\fR\&. Note, however, that
|
||||||
\fBtsig\-keygen\fR
|
\fBtsig\-keygen\fR
|
||||||
produces TSIG keys in a more useful format than
|
produces TSIG keys in a more useful format\&. These algorithms have been deprecated in
|
||||||
\fBdnssec\-keygen\fR\&.)
|
\fBdnssec\-keygen\fR, and will be removed in a future release\&.
|
||||||
.sp
|
.sp
|
||||||
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
||||||
\fB\-3\fR
|
\fB\-3\fR
|
||||||
@@ -75,7 +78,7 @@ option, then NSEC3RSASHA1 or NSEC3DSA will be used instead\&.
|
|||||||
.sp
|
.sp
|
||||||
As of BIND 9\&.12\&.0, this option is mandatory except when using the
|
As of BIND 9\&.12\&.0, this option is mandatory except when using the
|
||||||
\fB\-S\fR
|
\fB\-S\fR
|
||||||
option (which copies the algorithm from the predecessor key)\&. Previously, the default for newly generated keys was RSASHA1\&.
|
option, which copies the algorithm from the predecessor key\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-b \fIkeysize\fR
|
\-b \fIkeysize\fR
|
||||||
|
|||||||
@@ -582,6 +582,16 @@ main(int argc, char **argv) {
|
|||||||
INSIST((alg != DNS_KEYALG_RSAMD5) && (alg != DST_ALG_HMACMD5));
|
INSIST((alg != DNS_KEYALG_RSAMD5) && (alg != DST_ALG_HMACMD5));
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
|
||||||
|
if (alg == DST_ALG_HMACMD5 || alg == DST_ALG_HMACSHA1 ||
|
||||||
|
alg == DST_ALG_HMACSHA224 || alg == DST_ALG_HMACSHA256 ||
|
||||||
|
alg == DST_ALG_HMACSHA384 || alg == DST_ALG_HMACSHA512)
|
||||||
|
{
|
||||||
|
fprintf(stderr,
|
||||||
|
"Use of dnssec-keygen for HMAC keys is "
|
||||||
|
"deprecated: use tsig-keygen\n");
|
||||||
|
}
|
||||||
|
|
||||||
if (!dst_algorithm_supported(alg))
|
if (!dst_algorithm_supported(alg))
|
||||||
fatal("unsupported algorithm: %d", alg);
|
fatal("unsupported algorithm: %d", alg);
|
||||||
|
|
||||||
|
|||||||
@@ -122,12 +122,19 @@
|
|||||||
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
||||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
his value will automatically set the <option>-T KEY</option>
|
||||||
or HMAC-SHA512; specifying any of these algorithms will
|
option as well.
|
||||||
automatically set the <option>-T KEY</option> option as well.
|
</para>
|
||||||
(Note: <command>tsig-keygen</command> produces TSIG keys in a
|
<para>
|
||||||
more useful format than <command>dnssec-keygen</command>.)
|
TSIG keys can also be generated by setting the value to
|
||||||
|
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||||
|
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||||
|
values will automatically set <option>-T KEY</option>. Note,
|
||||||
|
however, that <command>tsig-keygen</command> produces TSIG keys
|
||||||
|
in a more useful format. These algorithms have been deprecated
|
||||||
|
in <command>dnssec-keygen</command>, and will be removed in a
|
||||||
|
future release.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
These values are case insensitive. In some cases, abbreviations
|
These values are case insensitive. In some cases, abbreviations
|
||||||
@@ -138,8 +145,8 @@
|
|||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
As of BIND 9.12.0, this option is mandatory except when using
|
As of BIND 9.12.0, this option is mandatory except when using
|
||||||
the <option>-S</option> option (which copies the algorithm from
|
the <option>-S</option> option, which copies the algorithm from
|
||||||
the predecessor key). Previously, the default for newly
|
the predecessor key. Previously, the default for newly
|
||||||
generated keys was RSASHA1.
|
generated keys was RSASHA1.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|||||||
@@ -103,12 +103,19 @@
|
|||||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||||
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
TKEY, the value must be DH (Diffie Hellman); specifying
|
||||||
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
his value will automatically set the <code class="option">-T KEY</code>
|
||||||
or HMAC-SHA512; specifying any of these algorithms will
|
option as well.
|
||||||
automatically set the <code class="option">-T KEY</code> option as well.
|
</p>
|
||||||
(Note: <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys in a
|
<p>
|
||||||
more useful format than <span class="command"><strong>dnssec-keygen</strong></span>.)
|
TSIG keys can also be generated by setting the value to
|
||||||
|
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||||
|
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||||
|
values will automatically set <code class="option">-T KEY</code>. Note,
|
||||||
|
however, that <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys
|
||||||
|
in a more useful format. These algorithms have been deprecated
|
||||||
|
in <span class="command"><strong>dnssec-keygen</strong></span>, and will be removed in a
|
||||||
|
future release.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
These values are case insensitive. In some cases, abbreviations
|
These values are case insensitive. In some cases, abbreviations
|
||||||
@@ -119,8 +126,8 @@
|
|||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
As of BIND 9.12.0, this option is mandatory except when using
|
As of BIND 9.12.0, this option is mandatory except when using
|
||||||
the <code class="option">-S</code> option (which copies the algorithm from
|
the <code class="option">-S</code> option, which copies the algorithm from
|
||||||
the predecessor key). Previously, the default for newly
|
the predecessor key. Previously, the default for newly
|
||||||
generated keys was RSASHA1.
|
generated keys was RSASHA1.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
|||||||
@@ -349,6 +349,14 @@ If the key\*(Aqs revocation date is set and in the past, and the key is publishe
|
|||||||
.RS 4
|
.RS 4
|
||||||
If either of the key\*(Aqs unpublication or deletion dates are set and in the past, the key is NOT published or used to sign the zone, regardless of any other metadata\&.
|
If either of the key\*(Aqs unpublication or deletion dates are set and in the past, the key is NOT published or used to sign the zone, regardless of any other metadata\&.
|
||||||
.RE
|
.RE
|
||||||
|
.PP
|
||||||
|
.RS 4
|
||||||
|
If key\*(Aqs sync publication date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are created\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
.RS 4
|
||||||
|
If key\*(Aqs sync deletion date is set and in the past, synchronization records (type CDS and/or CDNSKEY) are removed\&.
|
||||||
|
.RE
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-T \fIttl\fR
|
\-T \fIttl\fR
|
||||||
|
|||||||
@@ -1958,7 +1958,7 @@ addnsec3(dns_name_t *name, dns_dbnode_t *node,
|
|||||||
* any NSEC3 records which have the same parameters as the chain we
|
* any NSEC3 records which have the same parameters as the chain we
|
||||||
* are building.
|
* are building.
|
||||||
*
|
*
|
||||||
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
* XXXMPA Should we also check that it of the form <hash>.<origin>?
|
||||||
*/
|
*/
|
||||||
static void
|
static void
|
||||||
nsec3clean(dns_name_t *name, dns_dbnode_t *node,
|
nsec3clean(dns_name_t *name, dns_dbnode_t *node,
|
||||||
|
|||||||
@@ -646,6 +646,26 @@
|
|||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
If key's sync publication date is set and in the past,
|
||||||
|
synchronization records (type CDS and/or CDNSKEY) are
|
||||||
|
created.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
If key's sync deletion date is set and in the past,
|
||||||
|
synchronization records (type CDS and/or CDNSKEY) are
|
||||||
|
removed.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
</variablelist>
|
</variablelist>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|||||||
@@ -519,6 +519,22 @@
|
|||||||
zone, regardless of any other metadata.
|
zone, regardless of any other metadata.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
If key's sync publication date is set and in the past,
|
||||||
|
synchronization records (type CDS and/or CDNSKEY) are
|
||||||
|
created.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
If key's sync deletion date is set and in the past,
|
||||||
|
synchronization records (type CDS and/or CDNSKEY) are
|
||||||
|
removed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
</dl></div>
|
</dl></div>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||||
|
|||||||
@@ -8,6 +8,10 @@ srcdir = @srcdir@
|
|||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
# Attempt to disable parallel processing.
|
||||||
|
.NOTPARALLEL:
|
||||||
|
.NO_PARALLEL:
|
||||||
|
|
||||||
VERSION=@BIND9_VERSION@
|
VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@BIND9_PRODUCT@
|
@BIND9_PRODUCT@
|
||||||
@@ -130,7 +134,7 @@ server.@O@: server.c
|
|||||||
-DPRODUCT=\"${PRODUCT}\" \
|
-DPRODUCT=\"${PRODUCT}\" \
|
||||||
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||||
|
|
||||||
named@EXEEXT@: ${OBJS} ${UOBJS} ${DEPLIBS}
|
named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
export MAKE_SYMTABLE="yes"; \
|
export MAKE_SYMTABLE="yes"; \
|
||||||
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|||||||
+1
-1
@@ -9,7 +9,7 @@
|
|||||||
|
|
||||||
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
||||||
<xsl:output method="html" indent="yes" version="4.0"/>
|
<xsl:output method="html" indent="yes" version="4.0"/>
|
||||||
<xsl:template match="statistics[@version="3.10"]">
|
<xsl:template match="statistics[@version="3.11"]">
|
||||||
<html>
|
<html>
|
||||||
<head>
|
<head>
|
||||||
<xsl:if test="system-property('xsl:vendor')!='Transformiix'">
|
<xsl:if test="system-property('xsl:vendor')!='Transformiix'">
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ static char xslmsg[] =
|
|||||||
"\n"
|
"\n"
|
||||||
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
||||||
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
||||||
" <xsl:template match=\"statistics[@version="3.10"]\">\n"
|
" <xsl:template match=\"statistics[@version="3.11"]\">\n"
|
||||||
" <html>\n"
|
" <html>\n"
|
||||||
" <head>\n"
|
" <head>\n"
|
||||||
" <xsl:if test=\"system-property('xsl:vendor')!='Transformiix'\">\n"
|
" <xsl:if test=\"system-property('xsl:vendor')!='Transformiix'\">\n"
|
||||||
|
|||||||
+2
-4
@@ -156,12 +156,10 @@ options {\n\
|
|||||||
# fetch-glue <obsolete>;\n\
|
# fetch-glue <obsolete>;\n\
|
||||||
fetch-quota-params 100 0.1 0.3 0.7;\n\
|
fetch-quota-params 100 0.1 0.3 0.7;\n\
|
||||||
fetches-per-server 0;\n\
|
fetches-per-server 0;\n\
|
||||||
fetches-per-zone 0;\n"
|
fetches-per-zone 0;\n\
|
||||||
#ifdef ALLOW_FILTER_AAAA
|
filter-aaaa-on-v4 no;\n\
|
||||||
" filter-aaaa-on-v4 no;\n\
|
|
||||||
filter-aaaa-on-v6 no;\n\
|
filter-aaaa-on-v6 no;\n\
|
||||||
filter-aaaa { any; };\n"
|
filter-aaaa { any; };\n"
|
||||||
#endif
|
|
||||||
#ifdef HAVE_GEOIP
|
#ifdef HAVE_GEOIP
|
||||||
" geoip-use-ecs yes;\n"
|
" geoip-use-ecs yes;\n"
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -456,9 +456,8 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|||||||
*/
|
*/
|
||||||
if (conn->nonce == 0) {
|
if (conn->nonce == 0) {
|
||||||
while (conn->nonce == 0) {
|
while (conn->nonce == 0) {
|
||||||
isc_uint16_t r1 = isc_rng_random(server->sctx->rngctx);
|
isc_rng_randombytes(server->sctx->rngctx, &conn->nonce,
|
||||||
isc_uint16_t r2 = isc_rng_random(server->sctx->rngctx);
|
sizeof(conn->nonce));
|
||||||
conn->nonce = (r1 << 16) | r2;
|
|
||||||
}
|
}
|
||||||
eresult = ISC_R_SUCCESS;
|
eresult = ISC_R_SUCCESS;
|
||||||
} else
|
} else
|
||||||
|
|||||||
@@ -26,6 +26,8 @@
|
|||||||
int scmp_syscalls[] = {
|
int scmp_syscalls[] = {
|
||||||
SCMP_SYS(access),
|
SCMP_SYS(access),
|
||||||
SCMP_SYS(open),
|
SCMP_SYS(open),
|
||||||
|
SCMP_SYS(openat),
|
||||||
|
SCMP_SYS(lseek),
|
||||||
SCMP_SYS(clock_gettime),
|
SCMP_SYS(clock_gettime),
|
||||||
SCMP_SYS(time),
|
SCMP_SYS(time),
|
||||||
SCMP_SYS(read),
|
SCMP_SYS(read),
|
||||||
@@ -54,6 +56,7 @@ int scmp_syscalls[] = {
|
|||||||
#ifdef HAVE_GETRANDOM
|
#ifdef HAVE_GETRANDOM
|
||||||
SCMP_SYS(getrandom),
|
SCMP_SYS(getrandom),
|
||||||
#endif
|
#endif
|
||||||
|
SCMP_SYS(rename),
|
||||||
SCMP_SYS(unlink),
|
SCMP_SYS(unlink),
|
||||||
SCMP_SYS(socket),
|
SCMP_SYS(socket),
|
||||||
SCMP_SYS(sendto),
|
SCMP_SYS(sendto),
|
||||||
@@ -72,7 +75,6 @@ int scmp_syscalls[] = {
|
|||||||
SCMP_SYS(getsockopt),
|
SCMP_SYS(getsockopt),
|
||||||
SCMP_SYS(getsockname),
|
SCMP_SYS(getsockname),
|
||||||
SCMP_SYS(lstat),
|
SCMP_SYS(lstat),
|
||||||
SCMP_SYS(lseek),
|
|
||||||
SCMP_SYS(getgid),
|
SCMP_SYS(getgid),
|
||||||
SCMP_SYS(getegid),
|
SCMP_SYS(getegid),
|
||||||
SCMP_SYS(getuid),
|
SCMP_SYS(getuid),
|
||||||
@@ -83,9 +85,7 @@ int scmp_syscalls[] = {
|
|||||||
SCMP_SYS(setuid),
|
SCMP_SYS(setuid),
|
||||||
SCMP_SYS(prctl),
|
SCMP_SYS(prctl),
|
||||||
SCMP_SYS(epoll_wait),
|
SCMP_SYS(epoll_wait),
|
||||||
SCMP_SYS(openat),
|
|
||||||
SCMP_SYS(getdents),
|
SCMP_SYS(getdents),
|
||||||
SCMP_SYS(rename),
|
|
||||||
SCMP_SYS(utimes),
|
SCMP_SYS(utimes),
|
||||||
SCMP_SYS(dup),
|
SCMP_SYS(dup),
|
||||||
#endif
|
#endif
|
||||||
@@ -93,6 +93,8 @@ int scmp_syscalls[] = {
|
|||||||
const char *scmp_syscall_names[] = {
|
const char *scmp_syscall_names[] = {
|
||||||
"access",
|
"access",
|
||||||
"open",
|
"open",
|
||||||
|
"openat",
|
||||||
|
"lseek",
|
||||||
"clock_gettime",
|
"clock_gettime",
|
||||||
"time",
|
"time",
|
||||||
"read",
|
"read",
|
||||||
@@ -121,6 +123,7 @@ const char *scmp_syscall_names[] = {
|
|||||||
#ifdef HAVE_GETRANDOM
|
#ifdef HAVE_GETRANDOM
|
||||||
"getrandom",
|
"getrandom",
|
||||||
#endif
|
#endif
|
||||||
|
"rename",
|
||||||
"unlink",
|
"unlink",
|
||||||
"socket",
|
"socket",
|
||||||
"sendto",
|
"sendto",
|
||||||
@@ -139,7 +142,6 @@ const char *scmp_syscall_names[] = {
|
|||||||
"getsockopt",
|
"getsockopt",
|
||||||
"getsockname",
|
"getsockname",
|
||||||
"lstat",
|
"lstat",
|
||||||
"lseek",
|
|
||||||
"getgid",
|
"getgid",
|
||||||
"getegid",
|
"getegid",
|
||||||
"getuid",
|
"getuid",
|
||||||
@@ -150,9 +152,7 @@ const char *scmp_syscall_names[] = {
|
|||||||
"setuid",
|
"setuid",
|
||||||
"prctl",
|
"prctl",
|
||||||
"epoll_wait",
|
"epoll_wait",
|
||||||
"openat",
|
|
||||||
"getdents",
|
"getdents",
|
||||||
"rename",
|
|
||||||
"utimes",
|
"utimes",
|
||||||
"dup",
|
"dup",
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -17,6 +17,7 @@
|
|||||||
#include <isc/stdio.h>
|
#include <isc/stdio.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/syslog.h>
|
#include <isc/syslog.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
#include <isccfg/log.h>
|
#include <isccfg/log.h>
|
||||||
|
|||||||
+299
-209
@@ -154,11 +154,7 @@
|
|||||||
#define EXCLBUFFERS 4096
|
#define EXCLBUFFERS 4096
|
||||||
#endif /* TUNE_LARGE */
|
#endif /* TUNE_LARGE */
|
||||||
|
|
||||||
#ifdef WIN32
|
#define MAX_TCP_TIMEOUT 65535
|
||||||
#define DIR_PERM_OK W_OK
|
|
||||||
#else
|
|
||||||
#define DIR_PERM_OK W_OK|X_OK
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Check an operation for failure. Assumes that the function
|
* Check an operation for failure. Assumes that the function
|
||||||
@@ -803,6 +799,11 @@ dstkey_fromconfig(const cfg_obj_t *vconfig, const cfg_obj_t *key,
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Load keys from configuration into key table. If 'keyname' is specified,
|
||||||
|
* only load keys matching that name. If 'managed' is true, load the key as
|
||||||
|
* an initializing key.
|
||||||
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
||||||
dns_view_t *view, isc_boolean_t managed,
|
dns_view_t *view, isc_boolean_t managed,
|
||||||
@@ -818,12 +819,14 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
|||||||
|
|
||||||
for (elt = cfg_list_first(keys);
|
for (elt = cfg_list_first(keys);
|
||||||
elt != NULL;
|
elt != NULL;
|
||||||
elt = cfg_list_next(elt)) {
|
elt = cfg_list_next(elt))
|
||||||
|
{
|
||||||
keylist = cfg_listelt_value(elt);
|
keylist = cfg_listelt_value(elt);
|
||||||
|
|
||||||
for (elt2 = cfg_list_first(keylist);
|
for (elt2 = cfg_list_first(keylist);
|
||||||
elt2 != NULL;
|
elt2 != NULL;
|
||||||
elt2 = cfg_list_next(elt2)) {
|
elt2 = cfg_list_next(elt2))
|
||||||
|
{
|
||||||
key = cfg_listelt_value(elt2);
|
key = cfg_listelt_value(elt2);
|
||||||
result = dstkey_fromconfig(vconfig, key, managed,
|
result = dstkey_fromconfig(vconfig, key, managed,
|
||||||
&dstkey, mctx);
|
&dstkey, mctx);
|
||||||
@@ -831,8 +834,9 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
|||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* If keyname was specified, we only add that key.
|
* If keyname was specified, we only add that key.
|
||||||
@@ -844,17 +848,27 @@ load_view_keys(const cfg_obj_t *keys, const cfg_obj_t *vconfig,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(dns_keytable_add(secroots, managed, &dstkey));
|
/*
|
||||||
|
* This key is taken from the configuration, so
|
||||||
|
* if it's a managed key then it's an
|
||||||
|
* initializing key; that's why 'managed'
|
||||||
|
* is duplicated below.
|
||||||
|
*/
|
||||||
|
CHECK(dns_keytable_add2(secroots, managed,
|
||||||
|
managed, &dstkey));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (dstkey != NULL)
|
if (dstkey != NULL) {
|
||||||
dst_key_free(&dstkey);
|
dst_key_free(&dstkey);
|
||||||
if (secroots != NULL)
|
}
|
||||||
|
if (secroots != NULL) {
|
||||||
dns_keytable_detach(&secroots);
|
dns_keytable_detach(&secroots);
|
||||||
if (result == DST_R_NOCRYPTO)
|
}
|
||||||
|
if (result == DST_R_NOCRYPTO) {
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1024,7 +1038,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Add key zone for managed-keys.
|
* Add key zone for managed keys.
|
||||||
*/
|
*/
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
(void)named_config_get(maps, "managed-keys-directory", &obj);
|
(void)named_config_get(maps, "managed-keys-directory", &obj);
|
||||||
@@ -1039,7 +1053,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
|
|
||||||
} else if (directory != NULL) {
|
} else if (directory != NULL) {
|
||||||
if (access(directory, DIR_PERM_OK) != 0) {
|
if (!isc_file_isdirwritable(directory)) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"managed-keys-directory '%s' "
|
"managed-keys-directory '%s' "
|
||||||
@@ -1048,6 +1062,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(add_keydata_zone(view, directory, named_g_mctx));
|
CHECK(add_keydata_zone(view, directory, named_g_mctx));
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
@@ -3323,7 +3338,7 @@ create_empty_zone(dns_zone_t *zone, dns_name_t *name, dns_view_t *view,
|
|||||||
viewname = "";
|
viewname = "";
|
||||||
}
|
}
|
||||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_ZONELOAD,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||||
"automatic empty zone%s%s: %s",
|
"automatic empty zone%s%s: %s",
|
||||||
sep, viewname, namebuf);
|
sep, viewname, namebuf);
|
||||||
@@ -4681,20 +4696,19 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|||||||
* "allow-recursion" inherits from "allow-query-cache" if set,
|
* "allow-recursion" inherits from "allow-query-cache" if set,
|
||||||
* otherwise from "allow-query" if set.
|
* otherwise from "allow-query" if set.
|
||||||
*/
|
*/
|
||||||
if (view->cacheacl == NULL && view->recursionacl != NULL)
|
if (view->cacheacl == NULL && view->recursionacl != NULL) {
|
||||||
dns_acl_attach(view->recursionacl, &view->cacheacl);
|
dns_acl_attach(view->recursionacl, &view->cacheacl);
|
||||||
/*
|
}
|
||||||
* XXXEACH: This call to configure_view_acl() is redundant. We
|
|
||||||
* are leaving it as it is because we are making a minimal change
|
if (view->cacheacl == NULL && view->recursion) {
|
||||||
* for a patch release. In the future this should be changed to
|
dns_acl_attach(view->queryacl, &view->cacheacl);
|
||||||
* dns_acl_attach(view->queryacl, &view->cacheacl).
|
}
|
||||||
*/
|
|
||||||
if (view->cacheacl == NULL && view->recursion)
|
|
||||||
CHECK(configure_view_acl(vconfig, config, "allow-query", NULL,
|
|
||||||
actx, named_g_mctx, &view->cacheacl));
|
|
||||||
if (view->recursion &&
|
if (view->recursion &&
|
||||||
view->recursionacl == NULL && view->cacheacl != NULL)
|
view->recursionacl == NULL && view->cacheacl != NULL)
|
||||||
|
{
|
||||||
dns_acl_attach(view->cacheacl, &view->recursionacl);
|
dns_acl_attach(view->cacheacl, &view->recursionacl);
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Set default "allow-recursion", "allow-recursion-on" and
|
* Set default "allow-recursion", "allow-recursion-on" and
|
||||||
@@ -4875,7 +4889,6 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|||||||
dns_quotatype_zone, r);
|
dns_quotatype_zone, r);
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifdef ALLOW_FILTER_AAAA
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "filter-aaaa-on-v4", &obj);
|
result = named_config_get(maps, "filter-aaaa-on-v4", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
@@ -4910,7 +4923,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|||||||
|
|
||||||
CHECK(configure_view_acl(vconfig, config, "filter-aaaa", NULL,
|
CHECK(configure_view_acl(vconfig, config, "filter-aaaa", NULL,
|
||||||
actx, named_g_mctx, &view->aaaa_acl));
|
actx, named_g_mctx, &view->aaaa_acl));
|
||||||
#endif
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
result = named_config_get(maps, "prefetch", &obj);
|
result = named_config_get(maps, "prefetch", &obj);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
@@ -4956,11 +4969,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|||||||
if (!strcasecmp(dom, "no")) {
|
if (!strcasecmp(dom, "no")) {
|
||||||
result = ISC_R_NOTFOUND;
|
result = ISC_R_NOTFOUND;
|
||||||
} else if (!strcasecmp(dom, "auto")) {
|
} else if (!strcasecmp(dom, "auto")) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
/*
|
||||||
"WARNING: the DLV server at "
|
* Warning logged by libbind9.
|
||||||
"'dlv.isc.org' is no longer "
|
*/
|
||||||
"in service; dnssec-lookaside "
|
|
||||||
"ignored");
|
|
||||||
result = ISC_R_NOTFOUND;
|
result = ISC_R_NOTFOUND;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -4986,11 +4997,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist,
|
|||||||
CHECK(dns_name_fromstring(dlv, cfg_obj_asstring(obj),
|
CHECK(dns_name_fromstring(dlv, cfg_obj_asstring(obj),
|
||||||
DNS_NAME_DOWNCASE, NULL));
|
DNS_NAME_DOWNCASE, NULL));
|
||||||
if (dns_name_equal(dlv, iscdlv)) {
|
if (dns_name_equal(dlv, iscdlv)) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
/*
|
||||||
"WARNING: the DLV server at "
|
* Warning logged by libbind9.
|
||||||
"'dlv.isc.org' is no longer "
|
*/
|
||||||
"in service; dnssec-lookaside "
|
|
||||||
"ignored");
|
|
||||||
view->dlv = NULL;
|
view->dlv = NULL;
|
||||||
} else {
|
} else {
|
||||||
view->dlv = dlv;
|
view->dlv = dlv;
|
||||||
@@ -6007,7 +6016,7 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
|||||||
* Add the zone to its view in the new view list.
|
* Add the zone to its view in the new view list.
|
||||||
*/
|
*/
|
||||||
if (!modify)
|
if (!modify)
|
||||||
CHECK(dns_view_addzone(view, zone));
|
CHECK(dns_view_addzone(view, zone));
|
||||||
|
|
||||||
if (zone_is_catz) {
|
if (zone_is_catz) {
|
||||||
/*
|
/*
|
||||||
@@ -6165,7 +6174,7 @@ directory_callback(const char *clausename, const cfg_obj_t *obj, void *arg) {
|
|||||||
"option 'directory' contains relative path '%s'",
|
"option 'directory' contains relative path '%s'",
|
||||||
directory);
|
directory);
|
||||||
|
|
||||||
if (access(directory, DIR_PERM_OK) != 0) {
|
if (!isc_file_isdirwritable(directory)) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"directory '%s' is not writable",
|
"directory '%s' is not writable",
|
||||||
@@ -6443,16 +6452,19 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
|||||||
}
|
}
|
||||||
nextnode = NULL;
|
nextnode = NULL;
|
||||||
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
||||||
if (keynode != firstnode)
|
if (keynode != firstnode) {
|
||||||
dns_keytable_detachkeynode(keytable, &keynode);
|
dns_keytable_detachkeynode(keytable, &keynode);
|
||||||
|
}
|
||||||
keynode = nextnode;
|
keynode = nextnode;
|
||||||
} while (keynode != NULL);
|
} while (keynode != NULL);
|
||||||
|
|
||||||
if (n == 0)
|
if (n == 0) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
if (n > 1)
|
if (n > 1) {
|
||||||
qsort(ids, n, sizeof(ids[0]), cid);
|
qsort(ids, n, sizeof(ids[0]), cid);
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Encoded as "_ta-xxxx\(-xxxx\)*" where xxxx is the hex version of
|
* Encoded as "_ta-xxxx\(-xxxx\)*" where xxxx is the hex version of
|
||||||
@@ -6460,22 +6472,25 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
|||||||
*/
|
*/
|
||||||
label[0] = 0;
|
label[0] = 0;
|
||||||
r.base = label;
|
r.base = label;
|
||||||
r.length = sizeof(label);;
|
r.length = sizeof(label);
|
||||||
m = snprintf(r.base, r.length, "_ta");
|
m = snprintf(r.base, r.length, "_ta");
|
||||||
if (m < 0 || (unsigned)m > r.length)
|
if (m < 0 || (unsigned)m > r.length) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
isc_textregion_consume(&r, m);
|
isc_textregion_consume(&r, m);
|
||||||
for (i = 0; i < n; i++) {
|
for (i = 0; i < n; i++) {
|
||||||
m = snprintf(r.base, r.length, "-%04x", ids[i]);
|
m = snprintf(r.base, r.length, "-%04x", ids[i]);
|
||||||
if (m < 0 || (unsigned)m > r.length)
|
if (m < 0 || (unsigned)m > r.length) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
isc_textregion_consume(&r, m);
|
isc_textregion_consume(&r, m);
|
||||||
}
|
}
|
||||||
dns_fixedname_init(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
tatname = dns_fixedname_name(&fixed);
|
tatname = dns_fixedname_name(&fixed);
|
||||||
result = dns_name_fromstring2(tatname, label, name, 0, NULL);
|
result = dns_name_fromstring2(tatname, label, name, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
dns_name_format(tatname, namebuf, sizeof(namebuf));
|
dns_name_format(tatname, namebuf, sizeof(namebuf));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
@@ -6484,8 +6499,9 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
|||||||
view->name, namebuf);
|
view->name, namebuf);
|
||||||
|
|
||||||
tat = isc_mem_get(dotat_arg->view->mctx, sizeof(*tat));
|
tat = isc_mem_get(dotat_arg->view->mctx, sizeof(*tat));
|
||||||
if (tat == NULL)
|
if (tat == NULL) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
tat->mctx = NULL;
|
tat->mctx = NULL;
|
||||||
tat->task = NULL;
|
tat->task = NULL;
|
||||||
@@ -7053,6 +7069,13 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
|||||||
dir, isc_result_totext(result));
|
dir, isc_result_totext(result));
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
if (!isc_file_isdirwritable(dir)) {
|
||||||
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
|
"new-zones-directory '%s' "
|
||||||
|
"is not writable", dir);
|
||||||
|
return (ISC_R_NOPERM);
|
||||||
|
}
|
||||||
|
|
||||||
dns_view_setnewzonedir(view, dir);
|
dns_view_setnewzonedir(view, dir);
|
||||||
}
|
}
|
||||||
@@ -7310,18 +7333,128 @@ data_to_cfg(dns_view_t *view, MDB_val *key, MDB_val *data,
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Prototype for a callback which can be used with for_all_newzone_cfgs().
|
||||||
|
*/
|
||||||
|
typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||||
|
cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||||
|
isc_mem_t *mctx, dns_view_t *view,
|
||||||
|
cfg_aclconfctx_t *actx);
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* For each zone found in a NZD opened by the caller, create an object
|
||||||
|
* representing its configuration and invoke "callback" with the created
|
||||||
|
* object, "config", "vconfig", "mctx", "view" and "actx" as arguments (all
|
||||||
|
* these are non-global variables required to invoke configure_zone()).
|
||||||
|
* Immediately interrupt processing if an error is encountered while
|
||||||
|
* transforming NZD data into a zone configuration object or if "callback"
|
||||||
|
* returns an error.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||||
|
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||||
|
cfg_aclconfctx_t *actx, MDB_txn *txn, MDB_dbi dbi)
|
||||||
|
{
|
||||||
|
const cfg_obj_t *zconfig, *zlist = NULL;
|
||||||
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
cfg_obj_t *zconfigobj = NULL;
|
||||||
|
isc_buffer_t *text = NULL;
|
||||||
|
MDB_cursor *cursor = NULL;
|
||||||
|
MDB_val data, key;
|
||||||
|
int status;
|
||||||
|
|
||||||
|
status = mdb_cursor_open(txn, dbi, &cursor);
|
||||||
|
if (status != MDB_SUCCESS) {
|
||||||
|
return (ISC_R_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (status = mdb_cursor_get(cursor, &key, &data, MDB_FIRST);
|
||||||
|
status == MDB_SUCCESS;
|
||||||
|
status = mdb_cursor_get(cursor, &key, &data, MDB_NEXT))
|
||||||
|
{
|
||||||
|
/*
|
||||||
|
* Create a configuration object from data fetched from NZD.
|
||||||
|
*/
|
||||||
|
result = data_to_cfg(view, &key, &data, &text, &zconfigobj);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Extract zone configuration from configuration object.
|
||||||
|
*/
|
||||||
|
result = cfg_map_get(zconfigobj, "zone", &zlist);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
break;
|
||||||
|
} else if (!cfg_obj_islist(zlist)) {
|
||||||
|
result = ISC_R_FAILURE;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Invoke callback.
|
||||||
|
*/
|
||||||
|
result = callback(zconfig, config, vconfig, mctx, view, actx);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Destroy the configuration object created in this iteration.
|
||||||
|
*/
|
||||||
|
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (text != NULL) {
|
||||||
|
isc_buffer_free(&text);
|
||||||
|
}
|
||||||
|
if (zconfigobj != NULL) {
|
||||||
|
cfg_obj_destroy(named_g_addparser, &zconfigobj);
|
||||||
|
}
|
||||||
|
mdb_cursor_close(cursor);
|
||||||
|
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Attempt to configure a zone found in NZD and return the result.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||||
|
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||||
|
cfg_aclconfctx_t *actx)
|
||||||
|
{
|
||||||
|
return (configure_zone(config, zconfig, vconfig, mctx, view,
|
||||||
|
&named_g_server->viewlist, actx, ISC_TRUE,
|
||||||
|
ISC_FALSE, ISC_FALSE));
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Revert new view assignment for a zone found in NZD.
|
||||||
|
*/
|
||||||
|
static isc_result_t
|
||||||
|
configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||||
|
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||||
|
cfg_aclconfctx_t *actx)
|
||||||
|
{
|
||||||
|
UNUSED(config);
|
||||||
|
UNUSED(vconfig);
|
||||||
|
UNUSED(mctx);
|
||||||
|
UNUSED(actx);
|
||||||
|
|
||||||
|
configure_zone_setviewcommit(ISC_R_FAILURE, zconfig, view);
|
||||||
|
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx)
|
isc_mem_t *mctx, cfg_aclconfctx_t *actx)
|
||||||
{
|
{
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result;
|
||||||
int status;
|
|
||||||
isc_buffer_t *text = NULL;
|
|
||||||
cfg_obj_t *zoneconf = NULL;
|
|
||||||
MDB_cursor *cursor = NULL;
|
|
||||||
MDB_txn *txn = NULL;
|
MDB_txn *txn = NULL;
|
||||||
MDB_dbi dbi;
|
MDB_dbi dbi;
|
||||||
MDB_val key, data;
|
|
||||||
|
|
||||||
if (view->new_zone_config == NULL) {
|
if (view->new_zone_config == NULL) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
@@ -7338,82 +7471,22 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
|||||||
"for view '%s'",
|
"for view '%s'",
|
||||||
view->new_zone_db, view->name);
|
view->new_zone_db, view->name);
|
||||||
|
|
||||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, mctx,
|
||||||
if (status != 0) {
|
view, actx, txn, dbi);
|
||||||
result = ISC_R_FAILURE;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
|
||||||
const cfg_obj_t *zlist = NULL;
|
|
||||||
const cfg_obj_t *zoneobj = NULL;
|
|
||||||
|
|
||||||
result = data_to_cfg(view, &key, &data, &text, &zoneconf);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
CHECK(cfg_map_get(zoneconf, "zone", &zlist));
|
|
||||||
if (!cfg_obj_islist(zlist)) {
|
|
||||||
CHECK(ISC_R_FAILURE);
|
|
||||||
}
|
|
||||||
|
|
||||||
zoneobj = cfg_listelt_value(cfg_list_first(zlist));
|
|
||||||
CHECK(configure_zone(config, zoneobj, vconfig, mctx,
|
|
||||||
view, &named_g_server->viewlist, actx,
|
|
||||||
ISC_TRUE, ISC_FALSE, ISC_FALSE));
|
|
||||||
|
|
||||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
|
||||||
}
|
|
||||||
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
|
|
||||||
cleanup:
|
|
||||||
if (zoneconf != NULL) {
|
|
||||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
|
||||||
}
|
|
||||||
if (cursor != NULL) {
|
|
||||||
mdb_cursor_close(cursor);
|
|
||||||
cursor = NULL;
|
|
||||||
}
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
status = mdb_cursor_open(txn, dbi, &cursor);
|
/*
|
||||||
if (status != 0) {
|
* An error was encountered while attempting to configure zones
|
||||||
goto cleanup2;
|
* found in NZD. As this error may have been caused by a
|
||||||
}
|
* configure_zone() failure, try restoring a sane configuration
|
||||||
while (mdb_cursor_get(cursor, &key, &data, MDB_NEXT) == 0) {
|
* by reattaching all zones found in NZD to the old view. If
|
||||||
const cfg_obj_t *zlist = NULL;
|
* this also fails, too bad, there is nothing more we can do in
|
||||||
const cfg_obj_t *zconfig = NULL;
|
* terms of trying to make things right.
|
||||||
isc_result_t result2;
|
*/
|
||||||
|
(void) for_all_newzone_cfgs(configure_newzone_revert, config,
|
||||||
result2 = data_to_cfg(view, &key, &data, &text,
|
vconfig, mctx, view, actx, txn,
|
||||||
&zoneconf);
|
dbi);
|
||||||
if (result2 != ISC_R_SUCCESS) {
|
|
||||||
goto cleanup2;
|
|
||||||
}
|
|
||||||
|
|
||||||
result2 = cfg_map_get(zoneconf, "zone", &zlist);
|
|
||||||
if (result2 != ISC_R_SUCCESS) {
|
|
||||||
goto cleanup2;
|
|
||||||
}
|
|
||||||
|
|
||||||
zconfig = cfg_listelt_value(cfg_list_first(zlist));
|
|
||||||
configure_zone_setviewcommit(result, zconfig, view);
|
|
||||||
|
|
||||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup2:
|
|
||||||
if (text != NULL) {
|
|
||||||
isc_buffer_free(&text);
|
|
||||||
}
|
|
||||||
if (zoneconf != NULL) {
|
|
||||||
cfg_obj_destroy(named_g_addparser, &zoneconf);
|
|
||||||
}
|
|
||||||
if (cursor != NULL) {
|
|
||||||
mdb_cursor_close(cursor);
|
|
||||||
}
|
|
||||||
(void) nzd_close(&txn, ISC_FALSE);
|
(void) nzd_close(&txn, ISC_FALSE);
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -7457,8 +7530,9 @@ get_newzone_config(dns_view_t *view, const char *zonename,
|
|||||||
key.mv_size = strlen(zname);
|
key.mv_size = strlen(zname);
|
||||||
|
|
||||||
status = mdb_get(txn, dbi, &key, &data);
|
status = mdb_get(txn, dbi, &key, &data);
|
||||||
if (status != 0)
|
if (status != MDB_SUCCESS) {
|
||||||
CHECK(ISC_R_FAILURE);
|
CHECK(ISC_R_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
CHECK(data_to_cfg(view, &key, &data, &text, &zoneconf));
|
CHECK(data_to_cfg(view, &key, &data, &text, &zoneconf));
|
||||||
|
|
||||||
@@ -7881,11 +7955,11 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
result = named_config_get(maps, "tcp-keepalive-timeout", &obj);
|
result = named_config_get(maps, "tcp-keepalive-timeout", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
keepalive = cfg_obj_asuint32(obj);
|
keepalive = cfg_obj_asuint32(obj);
|
||||||
if (keepalive > 1200) {
|
if (keepalive > MAX_TCP_TIMEOUT) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||||
"tcp-keepalive-timeout value is out of range: "
|
"tcp-keepalive-timeout value is out of range: "
|
||||||
"lowering to 1200");
|
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||||
keepalive = 1200;
|
keepalive = MAX_TCP_TIMEOUT;
|
||||||
} else if (keepalive < 1) {
|
} else if (keepalive < 1) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||||
"tcp-keepalive-timeout value is out of range: "
|
"tcp-keepalive-timeout value is out of range: "
|
||||||
@@ -7897,11 +7971,11 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
result = named_config_get(maps, "tcp-advertised-timeout", &obj);
|
result = named_config_get(maps, "tcp-advertised-timeout", &obj);
|
||||||
INSIST(result == ISC_R_SUCCESS);
|
INSIST(result == ISC_R_SUCCESS);
|
||||||
advertised = cfg_obj_asuint32(obj);
|
advertised = cfg_obj_asuint32(obj);
|
||||||
if (advertised > 1200) {
|
if (advertised > MAX_TCP_TIMEOUT) {
|
||||||
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(obj, named_g_lctx, ISC_LOG_WARNING,
|
||||||
"tcp-advertized-timeout value is out of range: "
|
"tcp-advertized-timeout value is out of range: "
|
||||||
"lowering to 1200");
|
"lowering to %u", MAX_TCP_TIMEOUT);
|
||||||
advertised = 1200;
|
advertised = MAX_TCP_TIMEOUT;
|
||||||
}
|
}
|
||||||
|
|
||||||
ns_server_settimeouts(named_g_server->sctx,
|
ns_server_settimeouts(named_g_server->sctx,
|
||||||
@@ -8487,7 +8561,7 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
/*
|
/*
|
||||||
* Check that the working directory is writable.
|
* Check that the working directory is writable.
|
||||||
*/
|
*/
|
||||||
if (access(".", DIR_PERM_OK) != 0) {
|
if (!isc_file_isdirwritable(".")) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"the working directory is not writable");
|
"the working directory is not writable");
|
||||||
@@ -11739,6 +11813,10 @@ nzf_append(dns_view_t *view, const cfg_obj_t *zconfig) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
||||||
|
const cfg_obj_t *zl = NULL;
|
||||||
|
cfg_list_t *list;
|
||||||
|
const cfg_listelt_t *elt;
|
||||||
|
|
||||||
FILE *fp = NULL;
|
FILE *fp = NULL;
|
||||||
char tmp[1024];
|
char tmp[1024];
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
@@ -11750,9 +11828,24 @@ nzf_writeconf(const cfg_obj_t *config, dns_view_t *view) {
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
return (result);
|
return (result);
|
||||||
|
|
||||||
|
cfg_map_get(config, "zone", &zl);
|
||||||
|
if (!cfg_obj_islist(zl))
|
||||||
|
CHECK(ISC_R_FAILURE);
|
||||||
|
|
||||||
|
DE_CONST(&zl->value.list, list);
|
||||||
|
|
||||||
CHECK(add_comment(fp, view->name)); /* force a comment */
|
CHECK(add_comment(fp, view->name)); /* force a comment */
|
||||||
|
|
||||||
cfg_printx(config, CFG_PRINTER_ONELINE, dumpzone, fp);
|
for (elt = ISC_LIST_HEAD(*list);
|
||||||
|
elt != NULL;
|
||||||
|
elt = ISC_LIST_NEXT(elt, link))
|
||||||
|
{
|
||||||
|
const cfg_obj_t *zconfig = cfg_listelt_value(elt);
|
||||||
|
|
||||||
|
CHECK(isc_stdio_write("zone ", 5, 1, fp, NULL));
|
||||||
|
cfg_printx(zconfig, CFG_PRINTER_ONELINE, dumpzone, fp);
|
||||||
|
CHECK(isc_stdio_write(";\n", 2, 1, fp, NULL));
|
||||||
|
}
|
||||||
|
|
||||||
CHECK(isc_stdio_flush(fp));
|
CHECK(isc_stdio_flush(fp));
|
||||||
result = isc_stdio_close(fp);
|
result = isc_stdio_close(fp);
|
||||||
@@ -11811,7 +11904,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
if (zconfig == NULL) {
|
if (zconfig == NULL) {
|
||||||
/* We're deleting the zone from the database */
|
/* We're deleting the zone from the database */
|
||||||
status = mdb_del(*txnp, dbi, &key, NULL);
|
status = mdb_del(*txnp, dbi, &key, NULL);
|
||||||
if (status != 0 && status != MDB_NOTFOUND) {
|
if (status != MDB_SUCCESS && status != MDB_NOTFOUND) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER,
|
NAMED_LOGMODULE_SERVER,
|
||||||
@@ -11821,8 +11914,9 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
namebuf, mdb_strerror(status));
|
namebuf, mdb_strerror(status));
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
} else if (status != MDB_NOTFOUND)
|
} else if (status != MDB_NOTFOUND) {
|
||||||
commit = ISC_TRUE;
|
commit = ISC_TRUE;
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
/* We're creating or overwriting the zone */
|
/* We're creating or overwriting the zone */
|
||||||
const cfg_obj_t *zoptions;
|
const cfg_obj_t *zoptions;
|
||||||
@@ -11857,7 +11951,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
data.mv_size = isc_buffer_usedlength(text);
|
data.mv_size = isc_buffer_usedlength(text);
|
||||||
|
|
||||||
status = mdb_put(*txnp, dbi, &key, &data, 0);
|
status = mdb_put(*txnp, dbi, &key, &data, 0);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER,
|
NAMED_LOGMODULE_SERVER,
|
||||||
@@ -11875,11 +11969,11 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (!commit || result != ISC_R_SUCCESS)
|
if (!commit || result != ISC_R_SUCCESS) {
|
||||||
(void) mdb_txn_abort(*txnp);
|
(void) mdb_txn_abort(*txnp);
|
||||||
else {
|
} else {
|
||||||
status = mdb_txn_commit(*txnp);
|
status = mdb_txn_commit(*txnp);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER,
|
NAMED_LOGMODULE_SERVER,
|
||||||
@@ -11894,8 +11988,10 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
|
|
||||||
UNLOCK(&view->new_zone_lock);
|
UNLOCK(&view->new_zone_lock);
|
||||||
|
|
||||||
if (text != NULL)
|
if (text != NULL) {
|
||||||
isc_buffer_free(&text);
|
isc_buffer_free(&text);
|
||||||
|
}
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -11909,7 +12005,7 @@ nzd_writable(dns_view_t *view) {
|
|||||||
REQUIRE(view != NULL);
|
REQUIRE(view != NULL);
|
||||||
|
|
||||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0, 0, &txn);
|
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0, 0, &txn);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||||
"mdb_txn_begin: %s",
|
"mdb_txn_begin: %s",
|
||||||
@@ -11918,7 +12014,7 @@ nzd_writable(dns_view_t *view) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
status = mdb_dbi_open(txn, NULL, 0, &dbi);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||||
"mdb_dbi_open: %s",
|
"mdb_dbi_open: %s",
|
||||||
@@ -11941,7 +12037,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
|||||||
|
|
||||||
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0,
|
status = mdb_txn_begin((MDB_env *) view->new_zone_dbenv, 0,
|
||||||
flags, &txn);
|
flags, &txn);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_WARNING, "mdb_txn_begin: %s",
|
ISC_LOG_WARNING, "mdb_txn_begin: %s",
|
||||||
@@ -11950,7 +12046,7 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
status = mdb_dbi_open(txn, NULL, 0, dbi);
|
status = mdb_dbi_open(txn, NULL, 0, dbi);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_WARNING, "mdb_dbi_open: %s",
|
ISC_LOG_WARNING, "mdb_dbi_open: %s",
|
||||||
@@ -11961,9 +12057,10 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
|||||||
*txnp = txn;
|
*txnp = txn;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
if (txn != NULL)
|
if (txn != NULL) {
|
||||||
mdb_txn_abort(txn);
|
mdb_txn_abort(txn);
|
||||||
|
}
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -11977,38 +12074,34 @@ nzd_open(dns_view_t *view, unsigned int flags, MDB_txn **txnp, MDB_dbi *dbi) {
|
|||||||
*/
|
*/
|
||||||
static void
|
static void
|
||||||
nzd_env_close(dns_view_t *view) {
|
nzd_env_close(dns_view_t *view) {
|
||||||
if (view->new_zone_dbenv != NULL) {
|
const char *dbpath = NULL;
|
||||||
const char *dbpath = NULL;
|
char dbpath_copy[PATH_MAX];
|
||||||
isc_boolean_t have_dbpath = ISC_FALSE;
|
char lockpath[PATH_MAX];
|
||||||
char dbpath_copy[PATH_MAX];
|
int status, ret;
|
||||||
char lockpath[PATH_MAX];
|
|
||||||
int ret;
|
|
||||||
|
|
||||||
if (mdb_env_get_path(view->new_zone_dbenv, &dbpath) == 0) {
|
if (view->new_zone_dbenv == NULL) {
|
||||||
have_dbpath = ISC_TRUE;
|
return;
|
||||||
snprintf(lockpath, sizeof(lockpath), "%s-lock",
|
|
||||||
dbpath);
|
|
||||||
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
|
||||||
}
|
|
||||||
|
|
||||||
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
|
||||||
view->new_zone_dbenv = NULL;
|
|
||||||
|
|
||||||
if (have_dbpath) {
|
|
||||||
/*
|
|
||||||
* Database files must be owned by the eventual user, not
|
|
||||||
* by root.
|
|
||||||
*/
|
|
||||||
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
|
||||||
UNUSED(ret);
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Some platforms need the lockfile not to exist when we
|
|
||||||
* reopen the environment.
|
|
||||||
*/
|
|
||||||
(void) isc_file_remove(lockpath);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
status = mdb_env_get_path(view->new_zone_dbenv, &dbpath);
|
||||||
|
INSIST(status == MDB_SUCCESS);
|
||||||
|
snprintf(lockpath, sizeof(lockpath), "%s-lock", dbpath);
|
||||||
|
strlcpy(dbpath_copy, dbpath, sizeof(dbpath_copy));
|
||||||
|
mdb_env_close((MDB_env *) view->new_zone_dbenv);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Database files must be owned by the eventual user, not by root.
|
||||||
|
*/
|
||||||
|
ret = chown(dbpath_copy, ns_os_uid(), -1);
|
||||||
|
UNUSED(ret);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Some platforms need the lockfile not to exist when we reopen the
|
||||||
|
* environment.
|
||||||
|
*/
|
||||||
|
(void) isc_file_remove(lockpath);
|
||||||
|
|
||||||
|
view->new_zone_dbenv = NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
@@ -12024,7 +12117,7 @@ nzd_env_reopen(dns_view_t *view) {
|
|||||||
nzd_env_close(view);
|
nzd_env_close(view);
|
||||||
|
|
||||||
status = mdb_env_create(&env);
|
status = mdb_env_create(&env);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||||
"mdb_env_create failed: %s",
|
"mdb_env_create failed: %s",
|
||||||
@@ -12034,7 +12127,7 @@ nzd_env_reopen(dns_view_t *view) {
|
|||||||
|
|
||||||
if (view->new_zone_mapsize != 0ULL) {
|
if (view->new_zone_mapsize != 0ULL) {
|
||||||
status = mdb_env_set_mapsize(env, view->new_zone_mapsize);
|
status = mdb_env_set_mapsize(env, view->new_zone_mapsize);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||||
"mdb_env_set_mapsize failed: %s",
|
"mdb_env_set_mapsize failed: %s",
|
||||||
@@ -12043,9 +12136,8 @@ nzd_env_reopen(dns_view_t *view) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
status = mdb_env_open(env, view->new_zone_db,
|
status = mdb_env_open(env, view->new_zone_db, DNS_LMDB_FLAGS, 0600);
|
||||||
MDB_NOSUBDIR|MDB_CREATE, 0600);
|
if (status != MDB_SUCCESS) {
|
||||||
if (status != 0) {
|
|
||||||
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_GENERAL,
|
||||||
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
ISC_LOGMODULE_OTHER, ISC_LOG_ERROR,
|
||||||
"mdb_env_open of '%s' failed: %s",
|
"mdb_env_open of '%s' failed: %s",
|
||||||
@@ -12074,10 +12166,12 @@ nzd_close(MDB_txn **txnp, isc_boolean_t commit) {
|
|||||||
if (*txnp != NULL) {
|
if (*txnp != NULL) {
|
||||||
if (commit) {
|
if (commit) {
|
||||||
status = mdb_txn_commit(*txnp);
|
status = mdb_txn_commit(*txnp);
|
||||||
if (status != 0)
|
if (status != MDB_SUCCESS) {
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
} else
|
}
|
||||||
|
} else {
|
||||||
mdb_txn_abort(*txnp);
|
mdb_txn_abort(*txnp);
|
||||||
|
}
|
||||||
*txnp = NULL;
|
*txnp = NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -12095,11 +12189,12 @@ nzd_count(dns_view_t *view, int *countp) {
|
|||||||
REQUIRE(countp != NULL);
|
REQUIRE(countp != NULL);
|
||||||
|
|
||||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
|
}
|
||||||
|
|
||||||
status = mdb_stat(txn, dbi, &statbuf);
|
status = mdb_stat(txn, dbi, &statbuf);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
NAMED_LOGCATEGORY_GENERAL, NAMED_LOGMODULE_SERVER,
|
||||||
ISC_LOG_WARNING, "mdb_stat: %s",
|
ISC_LOG_WARNING, "mdb_stat: %s",
|
||||||
@@ -12172,8 +12267,9 @@ migrate_nzf(dns_view_t *view) {
|
|||||||
|
|
||||||
zonelist = NULL;
|
zonelist = NULL;
|
||||||
CHECK(cfg_map_get(nzf_config, "zone", &zonelist));
|
CHECK(cfg_map_get(nzf_config, "zone", &zonelist));
|
||||||
if (!cfg_obj_islist(zonelist))
|
if (!cfg_obj_islist(zonelist)) {
|
||||||
CHECK(ISC_R_FAILURE);
|
CHECK(ISC_R_FAILURE);
|
||||||
|
}
|
||||||
|
|
||||||
CHECK(nzd_open(view, 0, &txn, &dbi));
|
CHECK(nzd_open(view, 0, &txn, &dbi));
|
||||||
|
|
||||||
@@ -12224,7 +12320,7 @@ migrate_nzf(dns_view_t *view) {
|
|||||||
data.mv_size = isc_buffer_usedlength(text);
|
data.mv_size = isc_buffer_usedlength(text);
|
||||||
|
|
||||||
status = mdb_put(txn, dbi, &key, &data, MDB_NOOVERWRITE);
|
status = mdb_put(txn, dbi, &key, &data, MDB_NOOVERWRITE);
|
||||||
if (status != 0) {
|
if (status != MDB_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx,
|
isc_log_write(named_g_lctx,
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER,
|
NAMED_LOGMODULE_SERVER,
|
||||||
@@ -12253,15 +12349,19 @@ migrate_nzf(dns_view_t *view) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
(void) nzd_close(&txn, ISC_FALSE);
|
(void) nzd_close(&txn, ISC_FALSE);
|
||||||
else
|
} else {
|
||||||
result = nzd_close(&txn, commit);
|
result = nzd_close(&txn, commit);
|
||||||
|
}
|
||||||
|
|
||||||
if (text != NULL)
|
if (text != NULL) {
|
||||||
isc_buffer_free(&text);
|
isc_buffer_free(&text);
|
||||||
if (nzf_config != NULL)
|
}
|
||||||
|
|
||||||
|
if (nzf_config != NULL) {
|
||||||
cfg_obj_destroy(named_g_addparser, &nzf_config);
|
cfg_obj_destroy(named_g_addparser, &nzf_config);
|
||||||
|
}
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -13442,11 +13542,6 @@ newzone_cfgctx_destroy(void **cfgp) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
generate_salt(unsigned char *salt, size_t saltlen) {
|
generate_salt(unsigned char *salt, size_t saltlen) {
|
||||||
size_t i, n;
|
|
||||||
union {
|
|
||||||
unsigned char rnd[256];
|
|
||||||
isc_uint16_t rnd16[128];
|
|
||||||
} rnd;
|
|
||||||
unsigned char text[512 + 1];
|
unsigned char text[512 + 1];
|
||||||
isc_region_t r;
|
isc_region_t r;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
@@ -13455,14 +13550,9 @@ generate_salt(unsigned char *salt, size_t saltlen) {
|
|||||||
if (saltlen > 256U)
|
if (saltlen > 256U)
|
||||||
return (ISC_R_RANGE);
|
return (ISC_R_RANGE);
|
||||||
|
|
||||||
n = (saltlen + sizeof(isc_uint16_t) - 1) / sizeof(isc_uint16_t);
|
isc_rng_randombytes(named_g_server->sctx->rngctx, salt, saltlen);
|
||||||
for (i = 0; i < n; i++) {
|
|
||||||
rnd.rnd16[i] = isc_rng_random(named_g_server->sctx->rngctx);
|
|
||||||
}
|
|
||||||
|
|
||||||
memmove(salt, rnd.rnd, saltlen);
|
r.base = salt;
|
||||||
|
|
||||||
r.base = rnd.rnd;
|
|
||||||
r.length = (unsigned int) saltlen;
|
r.length = (unsigned int) saltlen;
|
||||||
|
|
||||||
isc_buffer_init(&buf, text, sizeof(text));
|
isc_buffer_init(&buf, text, sizeof(text));
|
||||||
@@ -14423,10 +14513,10 @@ mkey_dumpzone(dns_view_t *view, isc_buffer_t **text) {
|
|||||||
else if (revoked)
|
else if (revoked)
|
||||||
snprintf(buf, sizeof(buf),
|
snprintf(buf, sizeof(buf),
|
||||||
"\n\ttrust revoked");
|
"\n\ttrust revoked");
|
||||||
else if (kd.addhd < now)
|
else if (kd.addhd <= now)
|
||||||
snprintf(buf, sizeof(buf),
|
snprintf(buf, sizeof(buf),
|
||||||
"\n\ttrusted since: %s", tbuf);
|
"\n\ttrusted since: %s", tbuf);
|
||||||
else if (kd.addhd >= now)
|
else if (kd.addhd > now)
|
||||||
snprintf(buf, sizeof(buf),
|
snprintf(buf, sizeof(buf),
|
||||||
"\n\ttrust pending: %s", tbuf);
|
"\n\ttrust pending: %s", tbuf);
|
||||||
CHECK(putstr(text, buf));
|
CHECK(putstr(text, buf));
|
||||||
@@ -14695,7 +14785,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
|||||||
if (ptr == NULL)
|
if (ptr == NULL)
|
||||||
return (ISC_R_UNEXPECTEDEND);
|
return (ISC_R_UNEXPECTEDEND);
|
||||||
CHECK(isc_parse_uint32(&keepalive, ptr, 10));
|
CHECK(isc_parse_uint32(&keepalive, ptr, 10));
|
||||||
if (keepalive > 1200)
|
if (keepalive > MAX_TCP_TIMEOUT)
|
||||||
CHECK(ISC_R_RANGE);
|
CHECK(ISC_R_RANGE);
|
||||||
if (keepalive < 1)
|
if (keepalive < 1)
|
||||||
CHECK(ISC_R_RANGE);
|
CHECK(ISC_R_RANGE);
|
||||||
@@ -14704,7 +14794,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
|||||||
if (ptr == NULL)
|
if (ptr == NULL)
|
||||||
return (ISC_R_UNEXPECTEDEND);
|
return (ISC_R_UNEXPECTEDEND);
|
||||||
CHECK(isc_parse_uint32(&advertised, ptr, 10));
|
CHECK(isc_parse_uint32(&advertised, ptr, 10));
|
||||||
if (advertised > 1200)
|
if (advertised > MAX_TCP_TIMEOUT)
|
||||||
CHECK(ISC_R_RANGE);
|
CHECK(ISC_R_RANGE);
|
||||||
|
|
||||||
result = isc_task_beginexclusive(named_g_server->task);
|
result = isc_task_beginexclusive(named_g_server->task);
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
#include <isc/stats.h>
|
#include <isc/stats.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/task.h>
|
#include <isc/task.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/cache.h>
|
#include <dns/cache.h>
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
@@ -394,6 +395,7 @@ init_desc(void) {
|
|||||||
SET_RESSTATDESC(serverquota, "spilled due to server quota",
|
SET_RESSTATDESC(serverquota, "spilled due to server quota",
|
||||||
"ServerQuota");
|
"ServerQuota");
|
||||||
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
SET_RESSTATDESC(nextitem, "waited for next item", "NextItem");
|
||||||
|
SET_RESSTATDESC(priming, "priming queries", "Priming");
|
||||||
|
|
||||||
INSIST(i == dns_resstatscounter_max);
|
INSIST(i == dns_resstatscounter_max);
|
||||||
|
|
||||||
@@ -1614,7 +1616,7 @@ generatexml(named_server_t *server, isc_uint32_t flags,
|
|||||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
||||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
||||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
||||||
ISC_XMLCHAR "3.10"));
|
ISC_XMLCHAR "3.11"));
|
||||||
|
|
||||||
/* Set common fields for statistics dump */
|
/* Set common fields for statistics dump */
|
||||||
dumparg.type = isc_statsformat_xml;
|
dumparg.type = isc_statsformat_xml;
|
||||||
@@ -2410,7 +2412,7 @@ generatejson(named_server_t *server, size_t *msglen,
|
|||||||
/*
|
/*
|
||||||
* These statistics are included no matter which URL we use.
|
* These statistics are included no matter which URL we use.
|
||||||
*/
|
*/
|
||||||
obj = json_object_new_string("1.4");
|
obj = json_object_new_string("1.5");
|
||||||
CHECKMEM(obj);
|
CHECKMEM(obj);
|
||||||
json_object_object_add(bindstats, "json-stats-version", obj);
|
json_object_object_add(bindstats, "json-stats-version", obj);
|
||||||
|
|
||||||
|
|||||||
@@ -16,6 +16,7 @@
|
|||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <isccfg/cfg.h>
|
#include <isccfg/cfg.h>
|
||||||
|
|
||||||
|
|||||||
+16
-7
@@ -150,6 +150,7 @@ static dns_dispatch_t *dispatchv4 = NULL;
|
|||||||
static dns_dispatch_t *dispatchv6 = NULL;
|
static dns_dispatch_t *dispatchv6 = NULL;
|
||||||
static dns_message_t *updatemsg = NULL;
|
static dns_message_t *updatemsg = NULL;
|
||||||
static dns_fixedname_t fuserzone;
|
static dns_fixedname_t fuserzone;
|
||||||
|
static dns_fixedname_t fzname;
|
||||||
static dns_name_t *userzone = NULL;
|
static dns_name_t *userzone = NULL;
|
||||||
static dns_name_t *zname = NULL;
|
static dns_name_t *zname = NULL;
|
||||||
static dns_name_t tmpzonename;
|
static dns_name_t tmpzonename;
|
||||||
@@ -943,16 +944,21 @@ setup_system(void) {
|
|||||||
case AF_INET:
|
case AF_INET:
|
||||||
if (have_ipv4) {
|
if (have_ipv4) {
|
||||||
sa->type.sin.sin_port = htons(dnsport);
|
sa->type.sin.sin_port = htons(dnsport);
|
||||||
|
} else {
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case AF_INET6:
|
case AF_INET6:
|
||||||
if (have_ipv6) {
|
if (have_ipv6) {
|
||||||
sa->type.sin6.sin6_port = htons(dnsport);
|
sa->type.sin6.sin6_port = htons(dnsport);
|
||||||
|
} else {
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
fatal("bad family");
|
fatal("bad family");
|
||||||
}
|
}
|
||||||
|
INSIST(i < ns_alloc);
|
||||||
servers[i++] = *sa;
|
servers[i++] = *sa;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -2390,7 +2396,6 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
|||||||
dns_request_destroy(&request);
|
dns_request_destroy(&request);
|
||||||
dns_message_renderreset(updatemsg);
|
dns_message_renderreset(updatemsg);
|
||||||
dns_message_settsigkey(updatemsg, NULL);
|
dns_message_settsigkey(updatemsg, NULL);
|
||||||
/* XXX MPA fix zonename is freed already */
|
|
||||||
send_update(zname, &master_servers[master_inuse]);
|
send_update(zname, &master_servers[master_inuse]);
|
||||||
isc_event_free(&event);
|
isc_event_free(&event);
|
||||||
return;
|
return;
|
||||||
@@ -2693,13 +2698,17 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
|||||||
dns_name_init(&master, NULL);
|
dns_name_init(&master, NULL);
|
||||||
dns_name_clone(&soa.origin, &master);
|
dns_name_clone(&soa.origin, &master);
|
||||||
|
|
||||||
/*
|
if (userzone != NULL) {
|
||||||
* XXXMPA
|
|
||||||
*/
|
|
||||||
if (userzone != NULL)
|
|
||||||
zname = userzone;
|
zname = userzone;
|
||||||
else
|
} else {
|
||||||
zname = name;
|
/*
|
||||||
|
* Save the zone name in case we need to try a second
|
||||||
|
* address.
|
||||||
|
*/
|
||||||
|
dns_fixedname_init(&fzname);
|
||||||
|
zname = dns_fixedname_name(&fzname);
|
||||||
|
dns_name_copy(name, zname, NULL);
|
||||||
|
}
|
||||||
|
|
||||||
if (debugging) {
|
if (debugging) {
|
||||||
char namestr[DNS_NAME_FORMATSIZE];
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
|
|||||||
@@ -39,9 +39,7 @@
|
|||||||
dnssec-checkds \- DNSSEC delegation consistency checking tool
|
dnssec-checkds \- DNSSEC delegation consistency checking tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-checkds\fR\ 'u
|
.HP \w'\fBdnssec\-checkds\fR\ 'u
|
||||||
\fBdnssec\-checkds\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
\fBdnssec\-checkds\fR [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-s\ \fR\fB\fIfile\fR\fR] {zone}
|
||||||
.HP \w'\fBdnssec\-dsfromkey\fR\ 'u
|
|
||||||
\fBdnssec\-dsfromkey\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-checkds\fR
|
\fBdnssec\-checkds\fR
|
||||||
@@ -60,6 +58,12 @@ is specified, then the zone is read from that file to find the DNSKEY records\&.
|
|||||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&.
|
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-s \fIfile\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies a prepared dsset file, such as would be generated by
|
||||||
|
\fBdnssec\-signzone\fR, to use as a source for the DS RRset instead of querying the parent\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-d \fIdig path\fR
|
\-d \fIdig path\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies a path to a
|
Specifies a path to a
|
||||||
|
|||||||
@@ -42,20 +42,13 @@
|
|||||||
<refsynopsisdiv>
|
<refsynopsisdiv>
|
||||||
<cmdsynopsis sepchar=" ">
|
<cmdsynopsis sepchar=" ">
|
||||||
<command>dnssec-checkds</command>
|
<command>dnssec-checkds</command>
|
||||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">file</replaceable></option></arg>
|
||||||
<arg choice="req" rep="norepeat">zone</arg>
|
<arg choice="req" rep="norepeat">zone</arg>
|
||||||
</cmdsynopsis>
|
</cmdsynopsis>
|
||||||
<cmdsynopsis sepchar=" ">
|
|
||||||
<command>dnssec-dsfromkey</command>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
|
||||||
<arg choice="req" rep="norepeat">zone</arg>
|
|
||||||
</cmdsynopsis>
|
|
||||||
</refsynopsisdiv>
|
</refsynopsisdiv>
|
||||||
|
|
||||||
<refsection><info><title>DESCRIPTION</title></info>
|
<refsection><info><title>DESCRIPTION</title></info>
|
||||||
@@ -92,6 +85,17 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-s <replaceable class="parameter">file</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies a prepared dsset file, such as would be generated
|
||||||
|
by <command>dnssec-signzone</command>, to use as a source for
|
||||||
|
the DS RRset instead of querying the parent.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-d <replaceable class="parameter">dig path</replaceable></term>
|
<term>-d <replaceable class="parameter">dig path</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -33,20 +33,13 @@
|
|||||||
<h2>Synopsis</h2>
|
<h2>Synopsis</h2>
|
||||||
<div class="cmdsynopsis"><p>
|
<div class="cmdsynopsis"><p>
|
||||||
<code class="command">dnssec-checkds</code>
|
<code class="command">dnssec-checkds</code>
|
||||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
|
||||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
|
||||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
||||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
||||||
|
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
||||||
|
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||||
|
[<code class="option">-s <em class="replaceable"><code>file</code></em></code>]
|
||||||
{zone}
|
{zone}
|
||||||
</p></div>
|
</p></div>
|
||||||
<div class="cmdsynopsis"><p>
|
|
||||||
<code class="command">dnssec-dsfromkey</code>
|
|
||||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
|
||||||
[<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
|
|
||||||
[<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
|
|
||||||
[<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
|
|
||||||
{zone}
|
|
||||||
</p></div>
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
@@ -79,6 +72,14 @@
|
|||||||
instead of checking for a DS record in the zone's parent.
|
instead of checking for a DS record in the zone's parent.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-s <em class="replaceable"><code>file</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies a prepared dsset file, such as would be generated
|
||||||
|
by <span class="command"><strong>dnssec-signzone</strong></span>, to use as a source for
|
||||||
|
the DS RRset instead of querying the parent.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
############################################################################
|
############################################################################
|
||||||
# Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -34,7 +34,11 @@ class SECRR:
|
|||||||
if not rrtext:
|
if not rrtext:
|
||||||
raise Exception
|
raise Exception
|
||||||
|
|
||||||
fields = rrtext.decode('ascii').split()
|
# 'str' does not have decode method in python3
|
||||||
|
if type(rrtext) is not str:
|
||||||
|
fields = rrtext.decode('ascii').split()
|
||||||
|
else:
|
||||||
|
fields = rrtext.split()
|
||||||
if len(fields) < 7:
|
if len(fields) < 7:
|
||||||
raise Exception
|
raise Exception
|
||||||
|
|
||||||
@@ -89,35 +93,39 @@ class SECRR:
|
|||||||
# Generate a set of expected DS/DLV records from the DNSKEY RRset,
|
# Generate a set of expected DS/DLV records from the DNSKEY RRset,
|
||||||
# and report on congruency.
|
# and report on congruency.
|
||||||
############################################################################
|
############################################################################
|
||||||
def check(zone, args, masterfile=None, lookaside=None):
|
def check(zone, args):
|
||||||
rrlist = []
|
rrlist = []
|
||||||
cmd = [args.dig, "+noall", "+answer", "-t", "dlv" if lookaside else "ds",
|
if args.dssetfile:
|
||||||
"-q", zone + "." + lookaside if lookaside else zone]
|
fp = open(args.dssetfile).read()
|
||||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
else:
|
||||||
|
cmd = [args.dig, "+noall", "+answer", "-t",
|
||||||
|
"dlv" if args.lookaside else "ds", "-q",
|
||||||
|
zone + "." + args.lookaside if args.lookaside else zone]
|
||||||
|
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||||
|
|
||||||
for line in fp.splitlines():
|
for line in fp.splitlines():
|
||||||
rrlist.append(SECRR(line, lookaside))
|
rrlist.append(SECRR(line, args.lookaside))
|
||||||
rrlist = sorted(rrlist, key=lambda rr: (rr.keyid, rr.keyalg, rr.hashalg))
|
rrlist = sorted(rrlist, key=lambda rr: (rr.keyid, rr.keyalg, rr.hashalg))
|
||||||
|
|
||||||
klist = []
|
klist = []
|
||||||
|
|
||||||
if masterfile:
|
if args.masterfile:
|
||||||
cmd = [args.dsfromkey, "-f", masterfile]
|
cmd = [args.dsfromkey, "-f", args.masterfile]
|
||||||
if lookaside:
|
if args.lookaside:
|
||||||
cmd += ["-l", lookaside]
|
cmd += ["-l", args.lookaside]
|
||||||
cmd.append(zone)
|
cmd.append(zone)
|
||||||
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
fp, _ = Popen(cmd, stdout=PIPE).communicate()
|
||||||
else:
|
else:
|
||||||
intods, _ = Popen([args.dig, "+noall", "+answer", "-t", "dnskey",
|
intods, _ = Popen([args.dig, "+noall", "+answer", "-t", "dnskey",
|
||||||
"-q", zone], stdout=PIPE).communicate()
|
"-q", zone], stdout=PIPE).communicate()
|
||||||
cmd = [args.dsfromkey, "-f", "-"]
|
cmd = [args.dsfromkey, "-f", "-"]
|
||||||
if lookaside:
|
if args.lookaside:
|
||||||
cmd += ["-l", lookaside]
|
cmd += ["-l", args.lookaside]
|
||||||
cmd.append(zone)
|
cmd.append(zone)
|
||||||
fp, _ = Popen(cmd, stdin=PIPE, stdout=PIPE).communicate(intods)
|
fp, _ = Popen(cmd, stdin=PIPE, stdout=PIPE).communicate(intods)
|
||||||
|
|
||||||
for line in fp.splitlines():
|
for line in fp.splitlines():
|
||||||
klist.append(SECRR(line, lookaside))
|
klist.append(SECRR(line, args.lookaside))
|
||||||
|
|
||||||
if len(klist) < 1:
|
if len(klist) < 1:
|
||||||
print("No DNSKEY records found in zone apex")
|
print("No DNSKEY records found in zone apex")
|
||||||
@@ -136,7 +144,8 @@ def check(zone, args, masterfile=None, lookaside=None):
|
|||||||
rr.keyid, SECRR.hashalgs[rr.hashalg]))
|
rr.keyid, SECRR.hashalgs[rr.hashalg]))
|
||||||
|
|
||||||
if not found:
|
if not found:
|
||||||
print("No %s records were found for any DNSKEY" % ("DLV" if lookaside else "DS"))
|
print("No %s records were found for any DNSKEY" %
|
||||||
|
("DLV" if args.lookaside else "DS"))
|
||||||
|
|
||||||
return found
|
return found
|
||||||
|
|
||||||
@@ -151,10 +160,6 @@ def parse_args():
|
|||||||
sbindir = 'bin' if os.name == 'nt' else 'sbin'
|
sbindir = 'bin' if os.name == 'nt' else 'sbin'
|
||||||
|
|
||||||
parser.add_argument('zone', type=str, help='zone to check')
|
parser.add_argument('zone', type=str, help='zone to check')
|
||||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
|
||||||
help='zone master file')
|
|
||||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
|
||||||
help='DLV lookaside zone')
|
|
||||||
parser.add_argument('-d', '--dig', dest='dig',
|
parser.add_argument('-d', '--dig', dest='dig',
|
||||||
default=os.path.join(prefix(bindir), 'dig'),
|
default=os.path.join(prefix(bindir), 'dig'),
|
||||||
type=str, help='path to \'dig\'')
|
type=str, help='path to \'dig\'')
|
||||||
@@ -162,6 +167,12 @@ def parse_args():
|
|||||||
default=os.path.join(prefix(sbindir),
|
default=os.path.join(prefix(sbindir),
|
||||||
'dnssec-dsfromkey'),
|
'dnssec-dsfromkey'),
|
||||||
type=str, help='path to \'dig\'')
|
type=str, help='path to \'dig\'')
|
||||||
|
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||||
|
help='zone master file')
|
||||||
|
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||||
|
help='DLV lookaside zone')
|
||||||
|
parser.add_argument('-s', '--dsset', dest='dssetfile', type=str,
|
||||||
|
help='prepared DSset file')
|
||||||
parser.add_argument('-v', '--version', action='version',
|
parser.add_argument('-v', '--version', action='version',
|
||||||
version=version)
|
version=version)
|
||||||
args = parser.parse_args()
|
args = parser.parse_args()
|
||||||
@@ -178,5 +189,5 @@ def parse_args():
|
|||||||
############################################################################
|
############################################################################
|
||||||
def main():
|
def main():
|
||||||
args = parse_args()
|
args = parse_args()
|
||||||
found = check(args.zone, args, args.masterfile, args.lookaside)
|
found = check(args.zone, args)
|
||||||
exit(0 if found else 1)
|
exit(0 if found else 1)
|
||||||
|
|||||||
+4
-1
@@ -516,7 +516,10 @@ Status will report whether serving of stale answers is currently enabled, disabl
|
|||||||
.PP
|
.PP
|
||||||
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
|
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Dump the server\*(Aqs security roots and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&.
|
Dump the security roots (i\&.e\&., trust anchors configured via
|
||||||
|
\fBtrusted\-keys\fR,
|
||||||
|
\fBmanaged\-keys\fR, or
|
||||||
|
\fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&.
|
||||||
.sp
|
.sp
|
||||||
If the first argument is "\-", then the output is returned via the
|
If the first argument is "\-", then the output is returned via the
|
||||||
\fBrndc\fR
|
\fBrndc\fR
|
||||||
|
|||||||
+15
-9
@@ -774,9 +774,15 @@
|
|||||||
<term><userinput>secroots <optional>-</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
|
<term><userinput>secroots <optional>-</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Dump the server's security roots and negative trust anchors
|
Dump the security roots (i.e., trust anchors
|
||||||
for the specified views. If no view is specified, all views
|
configured via <command>trusted-keys</command>,
|
||||||
are dumped.
|
<command>managed-keys</command>, or
|
||||||
|
<command>dnssec-validation auto</command>) and negative trust
|
||||||
|
anchors for the specified views. If no view is specified, all
|
||||||
|
views are dumped. Security roots will indicate whether
|
||||||
|
they are configured as trusted keys, managed keys, or
|
||||||
|
initializing managed keys (managed keys that have not yet
|
||||||
|
been updated by a successful key refresh query).
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
If the first argument is "-", then the output is
|
If the first argument is "-", then the output is
|
||||||
@@ -963,15 +969,15 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
When called without arguments, display the current
|
When called without arguments, display the current
|
||||||
values of the <command>tcp-initial-timeout</command>,
|
values of the <command>tcp-initial-timeout</command>,
|
||||||
<command>tcp-idle-timeout</command>,
|
<command>tcp-idle-timeout</command>,
|
||||||
<command>tcp-keepalive-timeout</command> and
|
<command>tcp-keepalive-timeout</command> and
|
||||||
<command>tcp-advertised-timeout</command> options.
|
<command>tcp-advertised-timeout</command> options.
|
||||||
When called with arguments, update these values. This
|
When called with arguments, update these values. This
|
||||||
allows an administrator to make rapid adjustments when
|
allows an administrator to make rapid adjustments when
|
||||||
under a denial of service attack. See the descriptions of
|
under a denial of service attack. See the descriptions of
|
||||||
these options in the BIND 9 Administrator Reference Manual
|
these options in the BIND 9 Administrator Reference Manual
|
||||||
for details of their use.
|
for details of their use.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|||||||
+15
-9
@@ -657,9 +657,15 @@
|
|||||||
<dt><span class="term"><strong class="userinput"><code>secroots [<span class="optional">-</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
|
<dt><span class="term"><strong class="userinput"><code>secroots [<span class="optional">-</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Dump the server's security roots and negative trust anchors
|
Dump the security roots (i.e., trust anchors
|
||||||
for the specified views. If no view is specified, all views
|
configured via <span class="command"><strong>trusted-keys</strong></span>,
|
||||||
are dumped.
|
<span class="command"><strong>managed-keys</strong></span>, or
|
||||||
|
<span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust
|
||||||
|
anchors for the specified views. If no view is specified, all
|
||||||
|
views are dumped. Security roots will indicate whether
|
||||||
|
they are configured as trusted keys, managed keys, or
|
||||||
|
initializing managed keys (managed keys that have not yet
|
||||||
|
been updated by a successful key refresh query).
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
If the first argument is "-", then the output is
|
If the first argument is "-", then the output is
|
||||||
@@ -822,15 +828,15 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
When called without arguments, display the current
|
When called without arguments, display the current
|
||||||
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
values of the <span class="command"><strong>tcp-initial-timeout</strong></span>,
|
||||||
<span class="command"><strong>tcp-idle-timeout</strong></span>,
|
<span class="command"><strong>tcp-idle-timeout</strong></span>,
|
||||||
<span class="command"><strong>tcp-keepalive-timeout</strong></span> and
|
<span class="command"><strong>tcp-keepalive-timeout</strong></span> and
|
||||||
<span class="command"><strong>tcp-advertised-timeout</strong></span> options.
|
<span class="command"><strong>tcp-advertised-timeout</strong></span> options.
|
||||||
When called with arguments, update these values. This
|
When called with arguments, update these values. This
|
||||||
allows an administrator to make rapid adjustments when
|
allows an administrator to make rapid adjustments when
|
||||||
under a denial of service attack. See the descriptions of
|
under a denial of service attack. See the descriptions of
|
||||||
these options in the BIND 9 Administrator Reference Manual
|
these options in the BIND 9 Administrator Reference Manual
|
||||||
for details of their use.
|
for details of their use.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><strong class="userinput"><code>thaw [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
|
<dt><span class="term"><strong class="userinput"><code>thaw [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
|
||||||
|
|||||||
@@ -1,19 +1,17 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2013, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
# $Id: clean.sh,v 1.6 2007/09/26 03:22:44 marka Exp $
|
|
||||||
|
|
||||||
#
|
#
|
||||||
# Clean up after tests.
|
# Clean up after tests.
|
||||||
#
|
#
|
||||||
|
|
||||||
rm -f dig.out.*
|
rm -f dig.out.*
|
||||||
rm -f */named.memstats
|
rm -f */named.memstats
|
||||||
rm -f */named.conf
|
rm -f ns1/named.conf
|
||||||
rm -f */named.run
|
rm -f */named.run
|
||||||
rm -f ns*/named.lock
|
rm -f ns*/named.lock
|
||||||
|
|||||||
@@ -0,0 +1,25 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
controls { /* empty */ };
|
||||||
|
|
||||||
|
options {
|
||||||
|
query-source address 10.53.0.3;
|
||||||
|
notify-source 10.53.0.3;
|
||||||
|
transfer-source 10.53.0.3;
|
||||||
|
port 5300;
|
||||||
|
pid-file "named.pid";
|
||||||
|
listen-on { 10.53.0.3; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion yes;
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "root.hint";
|
||||||
|
};
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
;
|
||||||
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
|
. NS ns1.
|
||||||
|
ns1. A 10.53.0.1
|
||||||
@@ -212,7 +212,7 @@ echo "I:testing with 'minimal-responses yes;'"
|
|||||||
minimal=yes
|
minimal=yes
|
||||||
dotests
|
dotests
|
||||||
|
|
||||||
echo "I:reconfiguring server"
|
echo "I:reconfiguring server: minimal-responses no"
|
||||||
cp ns1/named2.conf ns1/named.conf
|
cp ns1/named2.conf ns1/named.conf
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||||
sleep 2
|
sleep 2
|
||||||
@@ -230,7 +230,7 @@ if [ $ret -eq 1 ] ; then
|
|||||||
echo "I: failed"; status=1
|
echo "I: failed"; status=1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "I:reconfiguring server"
|
echo "I:reconfiguring server: minimal-any yes"
|
||||||
cp ns1/named3.conf ns1/named.conf
|
cp ns1/named3.conf ns1/named.conf
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||||
sleep 2
|
sleep 2
|
||||||
@@ -266,7 +266,7 @@ echo "I:testing with 'minimal-responses no-auth;'"
|
|||||||
minimal=no-auth
|
minimal=no-auth
|
||||||
dotests
|
dotests
|
||||||
|
|
||||||
echo "I:reconfiguring server"
|
echo "I:reconfiguring server: minimal-responses no-auth-recursive"
|
||||||
cp ns1/named4.conf ns1/named.conf
|
cp ns1/named4.conf ns1/named.conf
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||||
sleep 2
|
sleep 2
|
||||||
@@ -297,5 +297,30 @@ if [ $ret -eq 1 ] ; then
|
|||||||
echo "I: failed"; status=1
|
echo "I: failed"; status=1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
echo "I:reconfiguring server: minimal-responses no"
|
||||||
|
cp ns1/named2.conf ns1/named.conf
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
||||||
|
sleep 2
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I:testing NS handling in ANY responses (authoritative) ($n)"
|
||||||
|
ret=0
|
||||||
|
$DIG -t ANY rt.example @10.53.0.1 -p 5300 > dig.out.$n || ret=1
|
||||||
|
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||||
|
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||||
|
if [ $ret -eq 1 ] ; then
|
||||||
|
echo "I: failed"; status=1
|
||||||
|
fi
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I:testing NS handling in ANY responses (recursive) ($n)"
|
||||||
|
ret=0
|
||||||
|
$DIG -t ANY rt.example @10.53.0.3 -p 5300 > dig.out.$n || ret=1
|
||||||
|
grep "AUTHORITY: 0" dig.out.$n > /dev/null || ret=1
|
||||||
|
grep "NS[ ]*ns" dig.out.$n > /dev/null || ret=1
|
||||||
|
if [ $ret -eq 1 ] ; then
|
||||||
|
echo "I: failed"; status=1
|
||||||
|
fi
|
||||||
|
|
||||||
echo "I:exit status: $status"
|
echo "I:exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -10,4 +10,4 @@ my $target = shift;
|
|||||||
my $file = shift;
|
my $file = shift;
|
||||||
my $mtime = time - (stat $file)[9];
|
my $mtime = time - (stat $file)[9];
|
||||||
die "bad mtime $mtime"
|
die "bad mtime $mtime"
|
||||||
unless abs($mtime - $target) < 3;
|
unless abs($mtime - $target) < 10;
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ check_stderr() {
|
|||||||
[ -s err.$n ] || return 0
|
[ -s err.$n ] || return 0
|
||||||
fi
|
fi
|
||||||
echo "D:stderr did not match '$err'"
|
echo "D:stderr did not match '$err'"
|
||||||
sed 's/^/D:/' err
|
sed 's/^/D:/' err.$n
|
||||||
fail
|
fail
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -254,7 +254,7 @@ def create_response(msg):
|
|||||||
def sigterm(signum, frame):
|
def sigterm(signum, frame):
|
||||||
print ("Shutting down now...")
|
print ("Shutting down now...")
|
||||||
os.remove('ans.pid')
|
os.remove('ans.pid')
|
||||||
running = 0
|
running = False
|
||||||
sys.exit(0)
|
sys.exit(0)
|
||||||
|
|
||||||
############################################################################
|
############################################################################
|
||||||
@@ -270,8 +270,17 @@ sock = 5300
|
|||||||
|
|
||||||
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
query4_socket = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||||
query4_socket.bind((ip4, sock))
|
query4_socket.bind((ip4, sock))
|
||||||
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
|
||||||
query6_socket.bind((ip6, sock))
|
havev6 = True
|
||||||
|
try:
|
||||||
|
query6_socket = socket.socket(socket.AF_INET6, socket.SOCK_DGRAM)
|
||||||
|
try:
|
||||||
|
query6_socket.bind((ip6, sock))
|
||||||
|
except:
|
||||||
|
query6_socket.close()
|
||||||
|
havev6 = False
|
||||||
|
except:
|
||||||
|
havev6 = False
|
||||||
|
|
||||||
ctrl_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
ctrl_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||||
ctrl_socket.bind((ip4, sock + 1))
|
ctrl_socket.bind((ip4, sock + 1))
|
||||||
@@ -284,14 +293,18 @@ pid = os.getpid()
|
|||||||
print (pid, file=f)
|
print (pid, file=f)
|
||||||
f.close()
|
f.close()
|
||||||
|
|
||||||
running = 1
|
running = True
|
||||||
|
|
||||||
print ("Listening on %s port %d" % (ip4, sock))
|
print ("Listening on %s port %d" % (ip4, sock))
|
||||||
print ("Listening on %s port %d" % (ip6, sock))
|
if havev6:
|
||||||
|
print ("Listening on %s port %d" % (ip6, sock))
|
||||||
print ("Control channel on %s port %d" % (ip4, sock + 1))
|
print ("Control channel on %s port %d" % (ip4, sock + 1))
|
||||||
print ("Ctrl-c to quit")
|
print ("Ctrl-c to quit")
|
||||||
|
|
||||||
input = [query4_socket, query6_socket, ctrl_socket]
|
if havev6:
|
||||||
|
input = [query4_socket, query6_socket, ctrl_socket]
|
||||||
|
else:
|
||||||
|
input = [query4_socket, ctrl_socket]
|
||||||
|
|
||||||
while running:
|
while running:
|
||||||
try:
|
try:
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
options {
|
||||||
|
dnssec-lookaside . trust-anchor dlv.example.com;
|
||||||
|
};
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
# Copyright (C) 2005, 2007, 2010-2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2005, 2007, 2010-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -135,6 +135,7 @@ done
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
echo "I: checking options allowed in inline-signing slaves ($n)"
|
echo "I: checking options allowed in inline-signing slaves ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
l=`$CHECKCONF bad-dnssec.conf 2>&1 | grep "dnssec-dnskey-kskonly.*requires inline" | wc -l`
|
l=`$CHECKCONF bad-dnssec.conf 2>&1 | grep "dnssec-dnskey-kskonly.*requires inline" | wc -l`
|
||||||
@@ -327,5 +328,29 @@ diff good.zonelist checkconf.out$n > diff.out$n || ret=1
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check that 'dnssec-lookaside auto;' generates a warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF warn-dlv-auto.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
|
grep "dnssec-lookaside 'auto' is no longer supported" checkconf.out$n > /dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.isc.org;' generates a warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF warn-dlv-dlv.isc.org.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
|
grep "dlv.isc.org has been shut down" checkconf.out$n > /dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check that 'dnssec-lookaside . trust-anchor dlv.example.com;' doesn't generates a warning ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKCONF good-dlv-dlv.example.com.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||||
|
[ -s checkconf.out$n ] && ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; ret=1; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I:exit status: $status"
|
echo "I:exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -1,12 +1,10 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
# $Id$
|
|
||||||
|
|
||||||
rm -f checkds.*
|
rm -f checkds.*
|
||||||
rm -f ns*/named.lock
|
rm -f ns*/named.lock
|
||||||
|
|||||||
@@ -1,13 +1,11 @@
|
|||||||
#!/usr/bin/perl
|
#!/usr/bin/perl
|
||||||
#
|
#
|
||||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
# $Id$
|
|
||||||
|
|
||||||
my $arg;
|
my $arg;
|
||||||
my $ext;
|
my $ext;
|
||||||
my $file;
|
my $file;
|
||||||
|
|||||||
@@ -1,14 +1,11 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2012, 2013, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2012, 2013, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
# $Id$
|
|
||||||
|
|
||||||
|
|
||||||
while [ "$#" != 0 ]; do
|
while [ "$#" != 0 ]; do
|
||||||
case $1 in
|
case $1 in
|
||||||
+*) shift ;;
|
+*) shift ;;
|
||||||
|
|||||||
@@ -0,0 +1,121 @@
|
|||||||
|
; File written on Thu Oct 5 23:44:34 2017
|
||||||
|
; dnssec_signzone version 9.12.0a1
|
||||||
|
prep.example. 300 IN SOA ns1.prep.example. hostmaster.prep.example. (
|
||||||
|
1 ; serial
|
||||||
|
2000 ; refresh (33 minutes 20 seconds)
|
||||||
|
2000 ; retry (33 minutes 20 seconds)
|
||||||
|
1814400 ; expire (3 weeks)
|
||||||
|
3600 ; minimum (1 hour)
|
||||||
|
)
|
||||||
|
300 RRSIG SOA 8 2 300 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
1fX0z7Swu4gMPews/ZE8bzNg+JXNedFBDGIH
|
||||||
|
PTSfVQtVLIvRWpME+PylX7MdVMZE/PST+x4/
|
||||||
|
mWyveyjetEOo7/7aQL236FfI0y6TxQFy7HwC
|
||||||
|
FMieqoQCUluuKOvToxg4vUp4GOdlUGbqC63h
|
||||||
|
DbX5Z37VptJXLkt4niF4Kl2iD+U9/bk7HAEU
|
||||||
|
4zDiKroYnusGKfVB9xAWddzoHdLxhVuPi7ut
|
||||||
|
328suPdgX0bfs7uB+y4cikhGzAmPpNMlGHju
|
||||||
|
qYG74NcFGQNutLB7ayx/m87t7mTty7jbNKm3
|
||||||
|
QWJSPf5IR8/kmzAi8HMnapY5vUmm+hX8JOfU
|
||||||
|
UtH7i0iEsUqRbEwu5A== )
|
||||||
|
300 NS ns1.prep.example.
|
||||||
|
300 RRSIG NS 8 2 300 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
u5sU2cfqNqIyCLw18ZNnFw28/GyRt0EOiPYS
|
||||||
|
dygmpfMDrvDaxjiiai8zWYjnl/E3qzVH9Zku
|
||||||
|
07lEDORZdVb0uCDe1NynjAyw4AHps85cAwVc
|
||||||
|
8HTSbzdVZsQTELpunYFJffh24PDr9unw7KOY
|
||||||
|
jzTP6qNedJ1uM54TOr177zfmBh7N2fkAoGyV
|
||||||
|
NjvTKrlgDYGNIn8/YMgHb4sNgyfe54MYY00f
|
||||||
|
kehVxfKnRCgDsbJ0Pk6jhBMCQWvOh8jG8WyV
|
||||||
|
ElAa/eMqlxUC1idF8ydWefjsI/7lPcjSalw9
|
||||||
|
qZw4CDCLHHZy0TOSmCYRRZuIeVXzBfDPJyi4
|
||||||
|
2A3iLntKFJ4AOLFMJg== )
|
||||||
|
3600 NSEC ns1.prep.example. NS SOA RRSIG NSEC DNSKEY
|
||||||
|
3600 RRSIG NSEC 8 2 3600 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
Aed99/jdG82YAkKVWjoKOsAGtB3JnyKkCaAq
|
||||||
|
zgMrYkXU41y3KDCAmGzooGPQY7NN+WxX7FJ2
|
||||||
|
1nXkgljma/azgpsbi9ssneFtv7PPFClVmN+u
|
||||||
|
j+mM4MK/ZR7eJOsMqETg4PAO5VAh6c/GVmyA
|
||||||
|
RD/m6EhJVZEjPfLWbDoC4hVAgem7DP/NMjyI
|
||||||
|
GfztpDjMmyLQyv6tL+UEXSJHGp3ZEa5Z5i7X
|
||||||
|
Nl/bRTUlZs7L4rTgoqHv6LEmsXKAf9rZYq4b
|
||||||
|
eP6GF9I1Ry41MfHLc7lPUmtR38ErEsM5uGzw
|
||||||
|
trCQYEFhuRWUBxZ8OSL2EZK9rUBXZX+cwK/8
|
||||||
|
ZP7mIfDfljkXPQcmow== )
|
||||||
|
3600 DNSKEY 256 3 8 (
|
||||||
|
AwEAAfMzj6aZIgZDVcpH1pKOtq998E85+nEY
|
||||||
|
YJa0lLS8+QTCC1Efke8GLwsXT0IPTuwnOuXM
|
||||||
|
RjySirab0NuEr69T8KP/43YxcRdmCg89mjjN
|
||||||
|
szoVPPstC9xBKVOc0pRMDF7sfsTrSye3RY7+
|
||||||
|
Z6uZEH5FOAkz2hNbJJHOn4HpNUhLPJGRauhf
|
||||||
|
0evamwUmQ/mlhkVW5q4WmqPCDMNY3K6XtkEm
|
||||||
|
cvm8n9ZCXC9Z5AX6KpynujzLdKyxpdGqUk6r
|
||||||
|
lavp9ILPpRKoTZDX+2q1pDgP5cDndwtgNSvU
|
||||||
|
DBQZoD0psS2cyB3PHo+dPwwpEyM//ZSKsH9m
|
||||||
|
e85Ti0413TOWFyFd/jUOUA8=
|
||||||
|
) ; ZSK; alg = RSASHA256 ; key id = 19260
|
||||||
|
3600 DNSKEY 257 3 8 (
|
||||||
|
AwEAAbV8X06Qvk350aZ6eZ1d7WbT1H/Y0Sv7
|
||||||
|
qAdbk5fbYIKpMvZ8D9xqoTHgD0z0uCgWWIcm
|
||||||
|
/xyKBfmax76oLwMBpR/kdtuJz0irgFITnJCH
|
||||||
|
pEfR9AJ/Mfm7NyMglq+/39I03E1/LXvpXQLG
|
||||||
|
tg+Mo/2CUE5sbG31jmPNK/2J8RMESkIi87fW
|
||||||
|
azZU/oyUEtECE5PGbdyw+4PacAsXNjnwl30T
|
||||||
|
aatL277wX4pt+IUPdE6EIph3t+dxXJ7OpHgW
|
||||||
|
8g+YSHLlCImLVapdg3oD/cs6ncaBq9z7la5Y
|
||||||
|
dHNw2QAIAvQ11EsonrkonPqO6zNVZAVdT2VB
|
||||||
|
X5YzGAoCFUvbCvlnl2a7SxM=
|
||||||
|
) ; KSK; alg = RSASHA256 ; key id = 65482
|
||||||
|
3600 RRSIG DNSKEY 8 2 3600 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
pPw81pJ3PeF+tqEswTul9N8Qsl9JKgK4v8SV
|
||||||
|
lPfP0pnlMBMbtMFFkx5ZmhQg3Z3U8SdE64Bt
|
||||||
|
C5St3qItyyKdTQ0Rbm9mfV6twxDB8lVry8F7
|
||||||
|
Pv7gJmmcWzBcbLGcrXIrVNSZhigkemQXTElj
|
||||||
|
P8y1j7kaNFWBWbDMn7KesiZ9BiC6sqvuKa3R
|
||||||
|
wSofjwXTESspWZP0NtXr5ymaBIMR9UtNj5Wh
|
||||||
|
jm1+tg6BxNBKxhCHlSC0ltPS/qq9J1ZUmtJz
|
||||||
|
sj/EAFfPVJVuEveebMvi1oDWPTgajO9+EHl4
|
||||||
|
ELrgnQHCgaybMzbpd/A5+Tr1hQkv48I8Mb0/
|
||||||
|
8LJ2/6xrvJm64yRteg== )
|
||||||
|
3600 RRSIG DNSKEY 8 2 3600 (
|
||||||
|
20171105054434 20171006054434 65482 prep.example.
|
||||||
|
WeIWiC9SnBe2+UocVjpap62O8Rz+iljwJiu9
|
||||||
|
VlGUwct3Vydq4/4FVAKdPklXV5cYbBLhO2MB
|
||||||
|
3R4toX8RNU/0Ny8DnugQzLKvVfg0xoyU/UAJ
|
||||||
|
k4aWa/vPivSLGouLQPiNp71bdXN4LB/2xmzu
|
||||||
|
cPYXzS9ePpwCOp/9JLoNjBSMQkfjfWAcaNtj
|
||||||
|
1DKDmHHL1sPMizninxSJLQOAKb+JwUAjAkOM
|
||||||
|
O1JqwkB12/IZuzxN5hly+uNsbFFxPzQkcnJ4
|
||||||
|
5bhzxuh5D/JRXW0nF5aO4aR+9X+lSUpDJQZ1
|
||||||
|
5fOt1cybZCn/ag68RA92zrnisdbrggJGS003
|
||||||
|
wn/VKbLVfFj3eQrfNA== )
|
||||||
|
ns1.prep.example. 300 IN A 1.1.1.1
|
||||||
|
300 RRSIG A 8 3 300 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
QUyDyJVk3JGEq+VTZtY3firzsRqOA0LUm3Tf
|
||||||
|
/fnemQBeOlMda2ErA7DqYVriIGfM8jph416E
|
||||||
|
YX8SKAZXGEAlsEbC9cWBVyc5TYH6tZ43sV51
|
||||||
|
55kGTiUY92NnrH10Q+m2SLAEEaKCA/cgBwOR
|
||||||
|
tN2Wb1meHgiLbGYN2LbANfDQzoEk4AYAgT6r
|
||||||
|
wDKVVg/V9Ed7JnCnBQc9MN9+LQ3h4NBGUiEY
|
||||||
|
mr7HX2w+yzqcGFNLI1aFPe2IwFt120QPLyyl
|
||||||
|
cZgc6FUBX4YCnWoCb0aFyyOT76AQkKF5YBRn
|
||||||
|
gAv6S8q1pZ/0B5w4gjaLEGlts3LG0bxZ1GJd
|
||||||
|
gCQMEhgYgyXUchTtZA== )
|
||||||
|
3600 NSEC prep.example. A RRSIG NSEC
|
||||||
|
3600 RRSIG NSEC 8 3 3600 (
|
||||||
|
20171105054434 20171006054434 19260 prep.example.
|
||||||
|
rDWN40u1a3DSzWOrS+4YR2XOxaem0BAQ/glN
|
||||||
|
QkXNDew1WsZo3fe0IHIhDKlJ/5MJAfAHq8Xs
|
||||||
|
A5UGUw2efoNAN/0LuWsI/9IPm4dwQOXiTCly
|
||||||
|
uxugXf5islPYyvn1Z14ay/7/2P3W6HZknXzo
|
||||||
|
lZFpwqfFZQCxz7c/1aH+2ntAMeqx8LHuewSr
|
||||||
|
Rz/sLsSiCcZQ6NMWnZdoC5SGy4CTcIIPPS8z
|
||||||
|
9dQ6QYTC5iq4MKRfyJUyvODyU9be4e6jbo5b
|
||||||
|
mjRcov4ttbImhD5jrLAZIfjO6DSazGNVFf/x
|
||||||
|
6rjxjrc8SISPkt2xYwcOlYch9OZuoH86wcZu
|
||||||
|
3Don6yAnLDYDrZylAA== )
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
prep.example. IN DS 65482 8 1 F3673708FBADDEC3EB55933E2E393ACE85EAC2BB
|
||||||
|
prep.example. IN DS 65482 8 2 51A7C97AAC42803DA515D1CAFEE28031A5018F6345F12F4B6C1B6D20 02B59820
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2012-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -171,6 +171,15 @@ n=`expr $n + 1`
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
echo "I:checking with prepared dsset file ($n)"
|
||||||
|
ret=0
|
||||||
|
$CHECKDS -f prep.example.db -s prep.example.ds.db prep.example > checkds.out.$n || ret=1
|
||||||
|
grep 'SHA-1.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||||
|
grep 'SHA-256.*found' checkds.out.$n > /dev/null 2>&1 || ret=1
|
||||||
|
n=`expr $n + 1`
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
if [ $status = 0 ]; then $SHELL clean.sh; fi
|
if [ $status = 0 ]; then $SHELL clean.sh; fi
|
||||||
echo "I:exit status: $status"
|
echo "I:exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -186,6 +186,19 @@ else
|
|||||||
}
|
}
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
#
|
||||||
|
# Useful functions in test scripts
|
||||||
|
#
|
||||||
|
|
||||||
|
# nextpart: read everything that's been appended to a file since the
|
||||||
|
# last time 'nextpart' was called.
|
||||||
|
nextpart () {
|
||||||
|
[ -f $1.prev ] || echo "0" > $1.prev
|
||||||
|
prev=`cat $1.prev`
|
||||||
|
awk "NR > $prev "'{ print }
|
||||||
|
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||||
|
}
|
||||||
|
|
||||||
#
|
#
|
||||||
# Export command paths
|
# Export command paths
|
||||||
#
|
#
|
||||||
|
|||||||
@@ -58,6 +58,8 @@ MDIG=$TOP/Build/$VSCONF/mdig@EXEEXT@
|
|||||||
NZD2NZF=$TOP/Build/$VSCONF/named-nzd2nzf@EXEEXT@
|
NZD2NZF=$TOP/Build/$VSCONF/named-nzd2nzf@EXEEXT@
|
||||||
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||||
FEATURETEST=$TOP/Build/$VSCONF/feature-test@EXEEXT@
|
FEATURETEST=$TOP/Build/$VSCONF/feature-test@EXEEXT@
|
||||||
|
SAMPLEUPDATE=$TOP/Build/$VSCONF/update@EXEEXT@
|
||||||
|
|
||||||
# to port WIRETEST=$TOP/Build/$VSCONF/wire_test@EXEEXT@
|
# to port WIRETEST=$TOP/Build/$VSCONF/wire_test@EXEEXT@
|
||||||
|
|
||||||
# this is given as argument to native WIN32 executables
|
# this is given as argument to native WIN32 executables
|
||||||
@@ -176,6 +178,19 @@ echoinfo () {
|
|||||||
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#
|
||||||
|
# Useful functions in test scripts
|
||||||
|
#
|
||||||
|
|
||||||
|
# nextpart: read everything that's been appended to a file since the
|
||||||
|
# last time 'nextpart' was called.
|
||||||
|
nextpart () {
|
||||||
|
[ -f $1.prev ] || echo "0" > $1.prev
|
||||||
|
prev=`cat $1.prev`
|
||||||
|
awk "NR > $prev "'{ print }
|
||||||
|
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
||||||
|
}
|
||||||
|
|
||||||
#
|
#
|
||||||
# Export command paths
|
# Export command paths
|
||||||
#
|
#
|
||||||
@@ -211,6 +226,7 @@ export RANDFILE
|
|||||||
export RESOLVE
|
export RESOLVE
|
||||||
export RNDC
|
export RNDC
|
||||||
export RRCHECKER
|
export RRCHECKER
|
||||||
|
export SAMPLEUPDATE
|
||||||
export SIGNER
|
export SIGNER
|
||||||
export SUBDIRS
|
export SUBDIRS
|
||||||
export TESTSOCK6
|
export TESTSOCK6
|
||||||
|
|||||||
@@ -24,8 +24,8 @@ options {
|
|||||||
dnssec-must-be-secure mustbesecure.example yes;
|
dnssec-must-be-secure mustbesecure.example yes;
|
||||||
minimal-responses no;
|
minimal-responses no;
|
||||||
|
|
||||||
nta-lifetime 10s;
|
nta-lifetime 12s;
|
||||||
nta-recheck 7s;
|
nta-recheck 9s;
|
||||||
|
|
||||||
# Note: We only reference the bind.keys file here to confirm that it
|
# Note: We only reference the bind.keys file here to confirm that it
|
||||||
# is *not* being used. It contains the real root key, and we're
|
# is *not* being used. It contains the real root key, and we're
|
||||||
|
|||||||
@@ -1722,7 +1722,7 @@ echo "I: waiting for NTA rechecks/expirations"
|
|||||||
# fakenode.secure.example should both be lifted, but badds.example
|
# fakenode.secure.example should both be lifted, but badds.example
|
||||||
# should still be going.
|
# should still be going.
|
||||||
#
|
#
|
||||||
$PERL -e 'my $delay = '$start' + 8 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
$PERL -e 'my $delay = '$start' + 10 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||||
$DIG $DIGOPTS b.secure.example. a @10.53.0.4 > dig.out.ns4.test$n.8 || ret=1
|
$DIG $DIGOPTS b.secure.example. a @10.53.0.4 > dig.out.ns4.test$n.8 || ret=1
|
||||||
grep "status: SERVFAIL" dig.out.ns4.test$n.8 > /dev/null && ret=1
|
grep "status: SERVFAIL" dig.out.ns4.test$n.8 > /dev/null && ret=1
|
||||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.8 > /dev/null || ret=1
|
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.8 > /dev/null || ret=1
|
||||||
@@ -1742,7 +1742,7 @@ ret=0
|
|||||||
# it should still be NTA'd, but badds.example used the default
|
# it should still be NTA'd, but badds.example used the default
|
||||||
# lifetime of 10s, so it should revert to SERVFAIL now.
|
# lifetime of 10s, so it should revert to SERVFAIL now.
|
||||||
#
|
#
|
||||||
$PERL -e 'my $delay = '$start' + 11 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
$PERL -e 'my $delay = '$start' + 13 - time(); select(undef, undef, undef, $delay) if ($delay > 0);'
|
||||||
# check nta table
|
# check nta table
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 nta -d > rndc.out.ns4.test$n._11
|
$RNDC -c ../common/rndc.conf -s 10.53.0.4 -p 9953 nta -d > rndc.out.ns4.test$n._11
|
||||||
lines=`grep " expiry " rndc.out.ns4.test$n._11 | wc -l`
|
lines=`grep " expiry " rndc.out.ns4.test$n._11 | wc -l`
|
||||||
@@ -2501,9 +2501,15 @@ do
|
|||||||
done;
|
done;
|
||||||
grep "ANSWER: 3," dig.out.ns2.test$n > /dev/null || ret=1
|
grep "ANSWER: 3," dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:nsec3 chain generation not complete"; fi
|
if [ $ret != 0 ]; then echo "I:nsec3 chain generation not complete"; fi
|
||||||
sleep 3
|
|
||||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.2 > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.2 > dig.out.ns2.test$n || ret=1
|
||||||
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
s2=`awk '$4 == "SOA" { print $7}' dig.out.ns2.test$n`
|
||||||
|
for i in 1 2 3 4 5 6 7 8 9 10
|
||||||
|
do
|
||||||
|
$DIG $DIGOPTS +noauth +nodnssec soa nsec3chain-test @10.53.0.3 > dig.out.ns3.test$n || ret=1
|
||||||
|
s3=`awk '$4 == "SOA" { print $7}' dig.out.ns3.test$n`
|
||||||
|
test "$s2" = "$s3" && break
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
$PERL ../digcomp.pl dig.out.ns2.test$n dig.out.ns3.test$n || ret=1
|
$PERL ../digcomp.pl dig.out.ns2.test$n dig.out.ns3.test$n || ret=1
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
#include <config.h>
|
#include <config.h>
|
||||||
|
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
#include <dns/diff.h>
|
#include <dns/diff.h>
|
||||||
|
|||||||
@@ -10,6 +10,7 @@
|
|||||||
#include <isc/eventclass.h>
|
#include <isc/eventclass.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
#include <isc/task.h>
|
#include <isc/task.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/db.h>
|
#include <dns/db.h>
|
||||||
|
|||||||
@@ -36,7 +36,6 @@ usage() {
|
|||||||
fprintf(stderr, "args:\n");
|
fprintf(stderr, "args:\n");
|
||||||
fprintf(stderr, " --edns-version\n");
|
fprintf(stderr, " --edns-version\n");
|
||||||
fprintf(stderr, " --enable-dnsrps\n");
|
fprintf(stderr, " --enable-dnsrps\n");
|
||||||
fprintf(stderr, " --enable-filter-aaaa\n");
|
|
||||||
fprintf(stderr, " --gethostname\n");
|
fprintf(stderr, " --gethostname\n");
|
||||||
fprintf(stderr, " --gssapi\n");
|
fprintf(stderr, " --gssapi\n");
|
||||||
fprintf(stderr, " --have-dlopen\n");
|
fprintf(stderr, " --have-dlopen\n");
|
||||||
@@ -63,14 +62,6 @@ main(int argc, char **argv) {
|
|||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
if (strcmp(argv[1], "--enable-filter-aaaa") == 0) {
|
|
||||||
#ifdef ALLOW_FILTER_AAAA
|
|
||||||
return (0);
|
|
||||||
#else
|
|
||||||
return (1);
|
|
||||||
#endif
|
|
||||||
}
|
|
||||||
|
|
||||||
if (strcmp(argv[1], "--edns-version") == 0) {
|
if (strcmp(argv[1], "--edns-version") == 0) {
|
||||||
#ifdef DNS_EDNS_VERSION
|
#ifdef DNS_EDNS_VERSION
|
||||||
printf("%d\n", DNS_EDNS_VERSION);
|
printf("%d\n", DNS_EDNS_VERSION);
|
||||||
|
|||||||
@@ -1,110 +1,125 @@
|
|||||||
; File written on Thu May 1 12:16:00 2014
|
; File written on Mon Oct 16 09:16:28 2017
|
||||||
; dnssec_signzone version 9.8.5-P1
|
; dnssec_signzone version 9.11.2
|
||||||
signed. 120 IN SOA ns.utld. hostmaster.ns.utld. (
|
signed. 120 IN SOA ns.signed. hostmaster.ns.signed. (
|
||||||
1 ; serial
|
1 ; serial
|
||||||
3600 ; refresh (1 hour)
|
3600 ; refresh (1 hour)
|
||||||
1200 ; retry (20 minutes)
|
1200 ; retry (20 minutes)
|
||||||
604800 ; expire (1 week)
|
604800 ; expire (1 week)
|
||||||
60 ; minimum (1 minute)
|
60 ; minimum (1 minute)
|
||||||
)
|
)
|
||||||
120 RRSIG SOA 3 1 120 20820519023008 (
|
120 RRSIG SOA 3 1 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BEFlElqfz17JeL/ISbgEz7yenWy2QjhgdMUx
|
BJDbUrXS4UzBrTeNUMA0sSGYd+h9M5d8qzsE
|
||||||
VDLBx3+Eiz1nyB1CpWw= )
|
q7RJyDtUNJIwP5vAnSQ= )
|
||||||
120 NS ns.utld.
|
120 NS ns.signed.
|
||||||
120 RRSIG NS 3 1 120 20820519023008 (
|
120 RRSIG NS 3 1 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BC4nYbfEyROe0CZPj/cHRl7BCIc0MbzpDBwz
|
BGoYuOkkcTAYnym27q2BgqkjUgP/0/Tip1yc
|
||||||
an8bPTHrbaHpC8rdX54= )
|
txRS1D0CipTUZhCNrXc= )
|
||||||
120 MX 10 mx.signed.
|
120 MX 10 mx.signed.
|
||||||
120 RRSIG MX 3 1 120 20820519023008 (
|
120 RRSIG MX 3 1 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BEp7iUXEnBCXVtKHcIRfkiK34J83ZbC3g7qQ
|
BOUPCSEEJ8dZ0oWeiYEvGIonjagvM1OS+mEY
|
||||||
XY+wdpJ7TxavEBtZO94= )
|
i5VUmysn7kArWqeFERs= )
|
||||||
60 NSEC a-only.signed. NS SOA MX RRSIG NSEC DNSKEY
|
60 NSEC a-only.signed. NS SOA MX RRSIG NSEC DNSKEY
|
||||||
60 RRSIG NSEC 3 1 60 20820519023008 (
|
60 RRSIG NSEC 3 1 60 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BAjeMFAXkfL9AypyihxU7lvhGCENKAwpoGt6
|
BBzvCsFw4EgfrIsFOu5IjP2gncm8dntwHaMD
|
||||||
WYd6G0kb6zdpZ/AR1GQ= )
|
IeJ6g6s7IOwFT5nyrOU= )
|
||||||
120 DNSKEY 256 3 3 (
|
120 DNSKEY 256 3 3 (
|
||||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
BPXo3mJOeCCuorn7Hc7bxR3QDHrJvq9gUpPS
|
||||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
s8QYF3eiSpB97c8Br7fFzFYHQCJWWnCtpt1E
|
||||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
h7SveJSl1ASNl9W2KE6hDNXfDX+ixDOtFZ/7
|
||||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
PCh/obX36VK86EH+ZBNLxxEy9tHHCGO08zy8
|
||||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
3lWI3E5bk9a1sks2dy6hbQfMmyXWI5QwYS9D
|
||||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
j5Vs5yeUQ5e6SPmIqgqpn6VnDtAIfR2My7/r
|
||||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
/Jgf73gpZugZmn6wDbzNCyGIvtOJCHAY2OEg
|
||||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
ZfACKVdJrXZ42NKcJCgSTd1xY81UyMI9QAMq
|
||||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
64Lx/tENCo1GKBCk/1HMdiO6WKeXCJd1SYzN
|
||||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
VM+n4fRzEkmVT9wfyiSmoq6SxjeqrRebDz8G
|
||||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
42d4lsm2/0bmOlle+fva7LwtGOaS+tBqtD8K
|
||||||
GimMrtxmA5Wf1xoJ
|
kexFaixL5iY+LB0Q
|
||||||
) ; key id = 12955
|
) ; ZSK; alg = DSA ; key id = 17876
|
||||||
120 DNSKEY 257 3 3 (
|
120 DNSKEY 257 3 3 (
|
||||||
BJIozpii3vZYz7LNraaDEOOpLFcdlw091gEG
|
BOOhXnn+YV6RQ+jRPdayrnC2cd9x5P77c1/6
|
||||||
+SHpTEVDdb7atLaYCYoSaodASSYutOQbba1o
|
Ev41qaWl1N7QRDXYh7VDS1UowoPbvQOvgQU0
|
||||||
i6xLiEAZdb4MNoM50vOtQlb4NJDAGElTOShK
|
X7+zKWrB8UQcdsUe96IH/wPab1qkJlKanZni
|
||||||
RE60G1veNVuN87ZpsiPlLU7m307l03aNUkJu
|
uFdB/2sTvQ6yabIC41dItnGeuN9VY1qwCa7T
|
||||||
LNd19kEuq1ItZt1SFVUkLvAHxs8hSLyDpq/u
|
4QFRVYyDPKgxo7MRLq9YoUN8RTcB6lY1BH9Z
|
||||||
4P/6QnPG294dk2eh83m2PuQVChvJLcrFhIbJ
|
QgcHZljAFVgU1Zc/6DZlQeBZyJafwIR+I7Eq
|
||||||
CWxCEsW9fe2eO1YtwoyFmqIIFSlAs84bwy2O
|
Oe+rR44ZeD5JRgI1OwGyw/b1wKUxFhM+4XJi
|
||||||
iA7x0PeoXpKGLhuKCbvre5zVLRaqMFoMDJmr
|
i8mQ1mrvzZ27iQbYP4WEzaskU6P5X+nPrTFi
|
||||||
vpGTxJ+AbOLEzDgO8QkGT+WCEBSMqRXvUkX0
|
tLEaPugt8Oe7+lHLjpHvHzSOJZ5Radfiqgzg
|
||||||
rBcSDAa8GpCTyhVs0j9KIedRbYalV24JzViy
|
GGOzj1qmLfKLdRmp4VuBQ+1kguiz9D3ev89d
|
||||||
m7UrKcZojCcXEjl0rXIJHNlfvQsfy6F3cq4m
|
pzP7dYHuSdCjc9X0fLmPjU1xD6RyLCDEmUm7
|
||||||
GimMrtxmA5Wf1xoJ
|
eeRP55SiTiQCzJFr
|
||||||
) ; key id = 12956
|
) ; KSK; alg = DSA ; key id = 3746
|
||||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
120 RRSIG DNSKEY 3 1 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 3746 signed.
|
||||||
BG/sW/I/ZVcUCjGfAicxv4kYLLYoMZlivDqU
|
BFuLN7ACQrD6/3WaieXRD1JpSXW9s+/xCZ1x
|
||||||
V3GfAXR5Bp69ywKp1OA= )
|
0ihUT1iKNvJS8F4Pafc= )
|
||||||
120 RRSIG DNSKEY 3 1 120 20820519023008 (
|
120 RRSIG DNSKEY 3 1 120 (
|
||||||
20140501011600 12956 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BAoQwXiKVoWwY+IDfzRndz9ndLPTSShDHpxS
|
BN+8hbh1FGTNqHds0In57dPr5fVRU/P28dZa
|
||||||
Z9+uTx+KCPzUsZYQy4k= )
|
zIP19bAwTH/ZvgrqUF0= )
|
||||||
a-only.signed. 120 IN NS 1.0.0.1.signed.
|
a-only.signed. 120 IN NS 1.0.0.1.signed.
|
||||||
60 NSEC aaaa-only.signed. NS RRSIG NSEC
|
60 NSEC aaaa-only.signed. NS RRSIG NSEC
|
||||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
60 RRSIG NSEC 3 2 60 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BBRjTWMwkjpanDw386nblW6fwyliYRUeNNo+
|
BHpGpjMihpoIykHTpK1XmkVn0jqSST3/K6Fx
|
||||||
OHwhqHXXd4bathApttg= )
|
vTaIb24rpkTriaXxChM= )
|
||||||
aaaa-only.signed. 120 IN AAAA 2001:db8::2
|
aaaa-only.signed. 120 IN AAAA 2001:db8::2
|
||||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
120 RRSIG AAAA 3 2 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BDukZxGM62Wmk9JE7F5etkcX4LZyFLK0YS0H
|
BOvYax/3CDnEKTtbc6zoP4hYwhMe5SoXZh0w
|
||||||
CF0lovOlBeK5zLgi/MA= )
|
muzBWw9bEH+Bdt1ZEQ4= )
|
||||||
60 NSEC dual.signed. AAAA RRSIG NSEC
|
60 NSEC dual.signed. AAAA RRSIG NSEC
|
||||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
60 RRSIG NSEC 3 2 60 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BH1TJpK7j1Gu01hb2PimefFISv59NDLfZ9Gr
|
BIqxE79TUnT2DUuocTitGhTNGnLs0+3sLJdz
|
||||||
ojpnjDQNV6bA7HcHeEM= )
|
8haJbyH8pig1h7mqimU= )
|
||||||
dual.signed. 120 IN A 1.0.0.3
|
dual.signed. 120 IN A 1.0.0.3
|
||||||
120 RRSIG A 3 2 120 20820519023008 (
|
120 RRSIG A 3 2 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BBIDPDxbSm3X/Xf5xh/MYIkAvZ9CWpEzSwbM
|
BIGL70eEIGVDW0gcYpEWgCFv4ne14hutQCMh
|
||||||
Pks77CGb4rW8IF8WXxs= )
|
gQ6kcEbl2qszosJA60E= )
|
||||||
120 AAAA 2001:db8::3
|
120 AAAA 2001:db8::3
|
||||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
120 RRSIG AAAA 3 2 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BHKD6egOF6e2DfY7+iPNDPcMS6TdU8/OCm8u
|
BCmwk+ng/x1O7MhheK8MgAXYFVDDbyiZ76RV
|
||||||
OYjmr11t5cI8S0R1Iqk= )
|
iwQrPRm0ThNRtsQU+UY= )
|
||||||
60 NSEC mx.signed. A AAAA RRSIG NSEC
|
60 NSEC mx.signed. A AAAA RRSIG NSEC
|
||||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
60 RRSIG NSEC 3 2 60 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BHeXsjvM4Bmr/Ih4eDgR9VTC7R/UFlz5ns+g
|
BLlLAIHF4SX/eWMCkUvj0XTFmaOp3xnifqkL
|
||||||
7LPl+H9Oe6zGnM5rGOs= )
|
nSWOAqtzJ5fwAdbNBdM= )
|
||||||
mx.signed. 120 IN A 1.0.0.3
|
ns.signed. 120 IN A 10.53.0.1
|
||||||
120 RRSIG A 3 2 120 20820519023008 (
|
120 RRSIG A 3 2 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BAq3t2X4XDI/dIofEkALZsNn1ezNWDYFH0M2
|
BJ+Wll7VfNEjM4EfLY2rlx74oIwKRg9pjcJO
|
||||||
2GI5F0JHr/iZPlAzRbk= )
|
Zxt6GHQIJ2D6EfyMZ00= )
|
||||||
120 AAAA 2001:db8::3
|
120 AAAA fd92:7065:b8e:ffff::1
|
||||||
120 RRSIG AAAA 3 2 120 20820519023008 (
|
120 RRSIG AAAA 3 2 120 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BFts4Mon2FQaLQb6kPOKTEFkHaPIE1xUgrI6
|
BGT/agHn4qcHzLV2hYcGeLJ6Tz1to9sTB8LI
|
||||||
qV8tEaAyFXfhH4su6Y0= )
|
lMwkV/KUu6UO7yvrnYk= )
|
||||||
60 NSEC signed. A AAAA RRSIG NSEC
|
60 NSEC signed. A AAAA RRSIG NSEC
|
||||||
60 RRSIG NSEC 3 2 60 20820519023008 (
|
60 RRSIG NSEC 3 2 60 (
|
||||||
20140501011600 12955 signed.
|
20820519023008 20140501011600 17876 signed.
|
||||||
BCQWnlB8hrID+v5xG/o8t8E+YDb3Fz7Qodmw
|
BNe3XmEGd/xxoh8FN3T3V9G1enCzNQJ7l3G+
|
||||||
kBQ+ZwyIeLOoH2+as5A= )
|
D3QPrp7mYtPAGMxCLlc= )
|
||||||
|
mx.signed. 120 IN A 1.0.0.3
|
||||||
|
120 RRSIG A 3 2 120 (
|
||||||
|
20820519023008 20140501011600 17876 signed.
|
||||||
|
BMlIQp1acUSUvgzV1CWlM0+cS1bGkFsbS6HQ
|
||||||
|
d0S6TbNV+uNw0S1q0Dk= )
|
||||||
|
120 AAAA 2001:db8::3
|
||||||
|
120 RRSIG AAAA 3 2 120 (
|
||||||
|
20820519023008 20140501011600 17876 signed.
|
||||||
|
BGtSuYQF7sRVT5OdVHPJjm0PERzSp4v+d/DP
|
||||||
|
Vp2UD0vSVSr3Vj2Wi4M= )
|
||||||
|
60 NSEC ns.signed. A AAAA RRSIG NSEC
|
||||||
|
60 RRSIG NSEC 3 2 60 (
|
||||||
|
20820519023008 20140501011600 17876 signed.
|
||||||
|
BMzQWws37wYfHvLnqgvjd+j5dkzBb2RYhrQk
|
||||||
|
ykM0GnTAR6ZpmgQO6jc= )
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
#
|
|
||||||
# Copyright (C) 2010, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
#
|
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
SYSTEMTESTTOP=..
|
|
||||||
. $SYSTEMTESTTOP/conf.sh
|
|
||||||
|
|
||||||
$FEATURETEST --enable-filter-aaaa || {
|
|
||||||
echo "I:This test requires --enable-filter-aaaa at compile time." >&2
|
|
||||||
exit 255
|
|
||||||
}
|
|
||||||
exit 0
|
|
||||||
@@ -35,6 +35,19 @@ PIDFILE="${THISDIR}/${CONFDIR}/named.pid"
|
|||||||
myRNDC="$RNDC -c ${THISDIR}/${CONFDIR}/rndc.conf"
|
myRNDC="$RNDC -c ${THISDIR}/${CONFDIR}/rndc.conf"
|
||||||
myNAMED="$NAMED -c ${THISDIR}/${CONFDIR}/named.conf -m record,size,mctx -T clienttest -T nosyslog -d 99 -X named.lock -U 4"
|
myNAMED="$NAMED -c ${THISDIR}/${CONFDIR}/named.conf -m record,size,mctx -T clienttest -T nosyslog -d 99 -X named.lock -U 4"
|
||||||
|
|
||||||
|
# Test given condition. If true, test again after a second. Used for testing
|
||||||
|
# filesystem-dependent conditions in order to prevent false negatives caused by
|
||||||
|
# directory contents not being synchronized immediately after rename() returns.
|
||||||
|
test_with_retry() {
|
||||||
|
if test "$@"; then
|
||||||
|
sleep 1
|
||||||
|
if test "$@"; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
waitforpidfile() {
|
waitforpidfile() {
|
||||||
for _w in 1 2 3 4 5 6 7 8 9 10
|
for _w in 1 2 3 4 5 6 7 8 9 10
|
||||||
do
|
do
|
||||||
@@ -48,9 +61,10 @@ n=0
|
|||||||
|
|
||||||
cd $CONFDIR
|
cd $CONFDIR
|
||||||
|
|
||||||
n=`expr $n + 1`
|
echo "I:testing log file validity (named -g + only plain files allowed)"
|
||||||
echo "I:testing log file validity (named -g + only plain files allowed) ($n)"
|
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: testing plain file (named -g) ($n)"
|
||||||
# First run with a known good config.
|
# First run with a known good config.
|
||||||
echo > $PLAINFILE
|
echo > $PLAINFILE
|
||||||
cp $PLAINCONF named.conf
|
cp $PLAINCONF named.conf
|
||||||
@@ -58,9 +72,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
|||||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing plain file succeeded"
|
echo "I: testing plain file succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing plain file failed (unexpected)"
|
echo "I: testing plain file failed (unexpected)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -79,14 +93,14 @@ then
|
|||||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
else
|
else
|
||||||
echo "I: testing directory as log file failed (expected)"
|
echo "I: testing directory as log file failed (expected)"
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping directory test (unable to create directory)"
|
echo "I: skipping directory test (unable to create directory)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Now try pipe file, expect failure
|
# Now try pipe file, expect failure
|
||||||
@@ -103,14 +117,14 @@ then
|
|||||||
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
grep "checking logging configuration failed: invalid file" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
else
|
else
|
||||||
echo "I: testing pipe file as log file failed (expected)"
|
echo "I: testing pipe file as log file failed (expected)"
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping pipe test (unable to create pipe)"
|
echo "I: skipping pipe test (unable to create pipe)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Now try symlink file to plain file, expect success
|
# Now try symlink file to plain file, expect success
|
||||||
@@ -129,14 +143,14 @@ then
|
|||||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing symlink to plain file succeeded"
|
echo "I: testing symlink to plain file succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing symlink to plain file failed (unexpected)"
|
echo "I: testing symlink to plain file failed (unexpected)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping symlink test (unable to create symlink)"
|
echo "I: skipping symlink test (unable to create symlink)"
|
||||||
fi
|
fi
|
||||||
# Stop the server and run through a series of tests with various config
|
# Stop the server and run through a series of tests with various config
|
||||||
# files while controlling the stop/start of the server.
|
# files while controlling the stop/start of the server.
|
||||||
@@ -155,9 +169,10 @@ fi
|
|||||||
|
|
||||||
status=0
|
status=0
|
||||||
|
|
||||||
n=`expr $n + 1`
|
echo "I:testing log file validity (only plain files allowed)"
|
||||||
echo "I:testing log file validity (only plain files allowed) ($n)"
|
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: testing plain file (named -g) ($n)"
|
||||||
# First run with a known good config.
|
# First run with a known good config.
|
||||||
echo > $PLAINFILE
|
echo > $PLAINFILE
|
||||||
cp $PLAINCONF named.conf
|
cp $PLAINCONF named.conf
|
||||||
@@ -165,9 +180,9 @@ $myRNDC reconfig > rndc.out.test$n 2>&1
|
|||||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing plain file succeeded"
|
echo "I: testing plain file succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing plain file failed (unexpected)"
|
echo "I: testing plain file failed (unexpected)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -186,14 +201,14 @@ then
|
|||||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
echo "I: testing directory as file succeeded (UNEXPECTED)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
else
|
else
|
||||||
echo "I: testing directory as log file failed (expected)"
|
echo "I: testing directory as log file failed (expected)"
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping directory test (unable to create directory)"
|
echo "I: skipping directory test (unable to create directory)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Now try pipe file, expect failure
|
# Now try pipe file, expect failure
|
||||||
@@ -210,14 +225,14 @@ then
|
|||||||
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
grep "configuring logging: invalid file" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
echo "I: testing pipe file as log file succeeded (UNEXPECTED)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
else
|
else
|
||||||
echo "I: testing pipe file as log file failed (expected)"
|
echo "I: testing pipe file as log file failed (expected)"
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping pipe test (unable to create pipe)"
|
echo "I: skipping pipe test (unable to create pipe)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Now try symlink file to plain file, expect success
|
# Now try symlink file to plain file, expect success
|
||||||
@@ -237,18 +252,18 @@ then
|
|||||||
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
grep "reloading configuration failed" named.run > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]
|
if [ $? -ne 0 ]
|
||||||
then
|
then
|
||||||
echo "I: testing symlink to plain file succeeded"
|
echo "I: testing symlink to plain file succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing symlink to plain file failed (unexpected)"
|
echo "I: testing symlink to plain file failed (unexpected)"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I: skipping symlink test (unable to create symlink)"
|
echo "I: skipping symlink test (unable to create symlink)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: testing default logfile using named -L file ($n)"
|
echo "I:testing default logfile using named -L file ($n)"
|
||||||
# Now stop the server again and test the -L option
|
# Now stop the server again and test the -L option
|
||||||
rm -f $DLFILE
|
rm -f $DLFILE
|
||||||
$PERL ../../stop.pl .. ns1
|
$PERL ../../stop.pl .. ns1
|
||||||
@@ -256,7 +271,7 @@ if ! test -f $PIDFILE; then
|
|||||||
cp $PLAINCONF named.conf
|
cp $PLAINCONF named.conf
|
||||||
$myNAMED -L $DLFILE > /dev/null 2>&1
|
$myNAMED -L $DLFILE > /dev/null 2>&1
|
||||||
if [ $? -ne 0 ]; then
|
if [ $? -ne 0 ]; then
|
||||||
echo "I:failed to start $myNAMED"
|
echo "I: failed to start $myNAMED"
|
||||||
echo "I:exit status: $status"
|
echo "I:exit status: $status"
|
||||||
exit $status
|
exit $status
|
||||||
fi
|
fi
|
||||||
@@ -272,7 +287,7 @@ if ! test -f $PIDFILE; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "I:failed to cleanly stop $myNAMED"
|
echo "I: failed to cleanly stop $myNAMED"
|
||||||
echo "I:exit status: 1"
|
echo "I:exit status: 1"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -284,9 +299,9 @@ echo "I: testing iso8601 timestamp ($n)"
|
|||||||
cp $ISOCONF named.conf
|
cp $ISOCONF named.conf
|
||||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||||
if grep '^....-..-..T..:..:..\.... ' $ISOFILE > /dev/null; then
|
if grep '^....-..-..T..:..:..\.... ' $ISOFILE > /dev/null; then
|
||||||
echo "I: testing iso8601 timestamp succeeded"
|
echo "I: testing iso8601 timestamp succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing iso8601 timestamp failed"
|
echo "I: testing iso8601 timestamp failed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -295,14 +310,14 @@ echo "I: testing iso8601-utc timestamp ($n)"
|
|||||||
cp $ISOCONFUTC named.conf
|
cp $ISOCONFUTC named.conf
|
||||||
$myRNDC reconfig > rndc.out.test$n 2>&1
|
$myRNDC reconfig > rndc.out.test$n 2>&1
|
||||||
if grep '^....-..-..T..:..:..\....Z' $ISOUTCFILE > /dev/null; then
|
if grep '^....-..-..T..:..:..\....Z' $ISOUTCFILE > /dev/null; then
|
||||||
echo "I: testing iso8601-utc timestamp succeeded"
|
echo "I: testing iso8601-utc timestamp succeeded"
|
||||||
else
|
else
|
||||||
echo "I: testing iso8601-utc timestamp failed"
|
echo "I: testing iso8601-utc timestamp failed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: testing explict versions ($n)"
|
echo "I: testing explicit versions ($n)"
|
||||||
cp $VERSCONF named.conf
|
cp $VERSCONF named.conf
|
||||||
# a seconds since epoch version number
|
# a seconds since epoch version number
|
||||||
touch $VERSFILE.1480039317
|
touch $VERSFILE.1480039317
|
||||||
@@ -313,27 +328,27 @@ t2=`$PERL -e 'print time()."\n";'`
|
|||||||
t=`expr ${t2:-0} - ${t1:-0}`
|
t=`expr ${t2:-0} - ${t1:-0}`
|
||||||
if test ${t:-1000} -gt 5
|
if test ${t:-1000} -gt 5
|
||||||
then
|
then
|
||||||
echo "I: testing explict versions failed cleanup of old entries took too long ($t secs)"
|
echo "I: testing explicit versions failed: cleanup of old entries took too long ($t secs)"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||||
then
|
then
|
||||||
echo "I: testing explict versions failed DiG lookup failed"
|
echo "I: testing explicit versions failed: DiG lookup failed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test -f $VERSFILE.1480039317
|
if test_with_retry -f $VERSFILE.1480039317
|
||||||
then
|
then
|
||||||
echo "I: testing explict versions failed $VERSFILE.1480039317 not removed"
|
echo "I: testing explicit versions failed: $VERSFILE.1480039317 not removed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test -f $VERSFILE.5
|
if test_with_retry -f $VERSFILE.5
|
||||||
then
|
then
|
||||||
echo "I: testing explict versions failed $VERSFILE.5 exists"
|
echo "I: testing explicit versions failed: $VERSFILE.5 exists"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test ! -f $VERSFILE.4
|
if test_with_retry ! -f $VERSFILE.4
|
||||||
then
|
then
|
||||||
echo "I: testing explict versions failed $VERSFILE.4 does not exist"
|
echo "I: testing explicit versions failed: $VERSFILE.4 does not exist"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -349,17 +364,17 @@ t2=`$PERL -e 'print time()."\n";'`
|
|||||||
t=`expr ${t2:-0} - ${t1:-0}`
|
t=`expr ${t2:-0} - ${t1:-0}`
|
||||||
if test ${t:-1000} -gt 5
|
if test ${t:-1000} -gt 5
|
||||||
then
|
then
|
||||||
echo "I: testing timestamped versions failed cleanup of old entries took too long ($t secs)"
|
echo "I: testing timestamped versions failed: cleanup of old entries took too long ($t secs)"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||||
then
|
then
|
||||||
echo "I: testing timestamped versions failed DiG lookup failed"
|
echo "I: testing timestamped versions failed: DiG lookup failed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test -f $TSFILE.1480039317
|
if test_with_retry -f $TSFILE.1480039317
|
||||||
then
|
then
|
||||||
echo "I: testing timestamped versions failed $TSFILE.1480039317 not removed"
|
echo "I: testing timestamped versions failed: $TSFILE.1480039317 not removed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -375,22 +390,22 @@ t2=`$PERL -e 'print time()."\n";'`
|
|||||||
t=`expr ${t2:-0} - ${t1:-0}`
|
t=`expr ${t2:-0} - ${t1:-0}`
|
||||||
if test ${t:-1000} -gt 5
|
if test ${t:-1000} -gt 5
|
||||||
then
|
then
|
||||||
echo "I: testing unlimited versions failed took too long ($t secs)"
|
echo "I: testing unlimited versions failed: took too long ($t secs)"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
if ! grep "status: NOERROR" dig.out.test$n > /dev/null
|
||||||
then
|
then
|
||||||
echo "I: testing unlimited versions failed DiG lookup failed"
|
echo "I: testing unlimited versions failed: DiG lookup failed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test ! -f $UNLIMITEDFILE.1480039317
|
if test_with_retry ! -f $UNLIMITEDFILE.1480039317
|
||||||
then
|
then
|
||||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.1480039317 removed"
|
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.1480039317 removed"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
if test ! -f $UNLIMITEDFILE.4
|
if test_with_retry ! -f $UNLIMITEDFILE.4
|
||||||
then
|
then
|
||||||
echo "I: testing unlimited versions failed $UNLIMITEDFILE.4 does not"
|
echo "I: testing unlimited versions failed: $UNLIMITEDFILE.4 does not exist"
|
||||||
status=`expr $status + 1`
|
status=`expr $status + 1`
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2005, 2007, 2011-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2005, 2007, 2011-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -238,6 +238,16 @@ done
|
|||||||
[ $ret -eq 0 ] || echo "I:failed"
|
[ $ret -eq 0 ] || echo "I:failed"
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
# stomp on the file header
|
||||||
|
echo "I:checking corrupt map files fail to load (bad file header)"
|
||||||
|
ret=0
|
||||||
|
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
||||||
|
cp map.5 badmap
|
||||||
|
stomp badmap 0 32 99
|
||||||
|
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||||
|
[ $? = 1 ] || ret=1
|
||||||
|
[ $ret -eq 0 ] || echo "I:failed"
|
||||||
|
status=`expr $status + $ret`
|
||||||
# stomp on the file data so it hashes differently.
|
# stomp on the file data so it hashes differently.
|
||||||
# these are small and subtle changes, so that the resulting file
|
# these are small and subtle changes, so that the resulting file
|
||||||
# would appear to be a legitimate map file and would not trigger an
|
# would appear to be a legitimate map file and would not trigger an
|
||||||
@@ -245,7 +255,6 @@ status=`expr $status + $ret`
|
|||||||
# load because of a SHA1 hash mismatch.
|
# load because of a SHA1 hash mismatch.
|
||||||
echo "I:checking corrupt map files fail to load (bad node header)"
|
echo "I:checking corrupt map files fail to load (bad node header)"
|
||||||
ret=0
|
ret=0
|
||||||
./named-compilezone -D -f text -F map -o map.5 example.nil baseline.txt > /dev/null
|
|
||||||
cp map.5 badmap
|
cp map.5 badmap
|
||||||
stomp badmap 2754 2 99
|
stomp badmap 2754 2 99
|
||||||
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
./named-compilezone -D -f map -F text -o text.5 example.nil badmap > /dev/null
|
||||||
|
|||||||
@@ -16,16 +16,8 @@ is used so it will send TAT queries once per second.
|
|||||||
|
|
||||||
ns3 is a validator with a broken key in managed-keys.
|
ns3 is a validator with a broken key in managed-keys.
|
||||||
|
|
||||||
Tests TODO:
|
ns4 is a validator with a deliberately broken managed-keys.bind and
|
||||||
|
managed-keys.jnl, causing RFC 5011 initialization to fail.
|
||||||
|
|
||||||
- initial working KSK
|
ns5 is a validator which is prevented from getting a response from the
|
||||||
|
root server, causing key refresh queries to fail.
|
||||||
TODO: test using delv with new trusted key too
|
|
||||||
|
|
||||||
- introduce a REVOKE bit
|
|
||||||
|
|
||||||
- later remove a signature
|
|
||||||
|
|
||||||
- corrupt a signature
|
|
||||||
|
|
||||||
TODO: also same things with dlv auto updates of trust anchor
|
|
||||||
|
|||||||
@@ -10,8 +10,10 @@ rm -f */K* */*.signed */trusted.conf */*.jnl */*.bk
|
|||||||
rm -f dsset-. ns1/dsset-.
|
rm -f dsset-. ns1/dsset-.
|
||||||
rm -f ns*/named.lock
|
rm -f ns*/named.lock
|
||||||
rm -f */managed-keys.bind* */named.secroots
|
rm -f */managed-keys.bind* */named.secroots
|
||||||
rm -f */managed.conf ns1/managed.key ns1/managed.key.id
|
rm -f */managed*.conf ns1/managed.key ns1/managed.key.id
|
||||||
rm -f */named.memstats */named.run
|
rm -f */named.memstats */named.run */named.run.prev
|
||||||
rm -f dig.out* delv.out* rndc.out* signer.out*
|
rm -f dig.out* delv.out* rndc.out* signer.out*
|
||||||
rm -f ns1/named.secroots ns1/root.db.signed* ns1/root.db.tmp
|
rm -f ns1/named.secroots ns1/root.db.signed* ns1/root.db.tmp
|
||||||
rm -f ns1/named.conf
|
rm -f ns1/named.conf
|
||||||
|
rm -rf ns4/nope
|
||||||
|
rm -f ns5/named.args
|
||||||
|
|||||||
@@ -10,6 +10,11 @@
|
|||||||
|
|
||||||
controls { /* empty */ };
|
controls { /* empty */ };
|
||||||
|
|
||||||
|
acl allowed {
|
||||||
|
! 10.53.0.5;
|
||||||
|
any;
|
||||||
|
};
|
||||||
|
|
||||||
options {
|
options {
|
||||||
query-source address 10.53.0.1;
|
query-source address 10.53.0.1;
|
||||||
notify-source 10.53.0.1;
|
notify-source 10.53.0.1;
|
||||||
@@ -22,6 +27,7 @@ options {
|
|||||||
notify no;
|
notify no;
|
||||||
dnssec-enable yes;
|
dnssec-enable yes;
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
|
allow-query { allowed; };
|
||||||
};
|
};
|
||||||
|
|
||||||
key rndc_key {
|
key rndc_key {
|
||||||
|
|||||||
@@ -10,6 +10,11 @@
|
|||||||
|
|
||||||
controls { /* empty */ };
|
controls { /* empty */ };
|
||||||
|
|
||||||
|
acl allowed {
|
||||||
|
! 10.53.0.5;
|
||||||
|
any;
|
||||||
|
};
|
||||||
|
|
||||||
options {
|
options {
|
||||||
query-source address 10.53.0.1;
|
query-source address 10.53.0.1;
|
||||||
notify-source 10.53.0.1;
|
notify-source 10.53.0.1;
|
||||||
@@ -22,6 +27,7 @@ options {
|
|||||||
notify no;
|
notify no;
|
||||||
dnssec-enable yes;
|
dnssec-enable yes;
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
|
allow-query { allowed; };
|
||||||
};
|
};
|
||||||
|
|
||||||
key rndc_key {
|
key rndc_key {
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// NS1
|
||||||
|
|
||||||
|
controls { /* empty */ };
|
||||||
|
|
||||||
|
options {
|
||||||
|
query-source address 10.53.0.1;
|
||||||
|
notify-source 10.53.0.1;
|
||||||
|
transfer-source 10.53.0.1;
|
||||||
|
port 5300;
|
||||||
|
pid-file "named.pid";
|
||||||
|
listen-on { 10.53.0.1; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion no;
|
||||||
|
notify no;
|
||||||
|
dnssec-enable yes;
|
||||||
|
dnssec-validation yes;
|
||||||
|
};
|
||||||
|
|
||||||
|
key rndc_key {
|
||||||
|
secret "1234abcd8765";
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
};
|
||||||
|
|
||||||
|
controls {
|
||||||
|
inet 10.53.0.1 port 9953 allow { any; } keys { rndc_key; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type master;
|
||||||
|
file "root.db.signed";
|
||||||
|
};
|
||||||
@@ -1,10 +1,10 @@
|
|||||||
; Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
; Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
;
|
;
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
$TTL 2
|
$TTL 20
|
||||||
. IN SOA gson.nominum.com. a.root.servers.nil. (
|
. IN SOA gson.nominum.com. a.root.servers.nil. (
|
||||||
2000042100 ; serial
|
2000042100 ; serial
|
||||||
600 ; refresh
|
600 ; refresh
|
||||||
|
|||||||
@@ -28,6 +28,8 @@ managed-keys {
|
|||||||
EOF
|
EOF
|
||||||
' > managed.conf
|
' > managed.conf
|
||||||
cp managed.conf ../ns2/managed.conf
|
cp managed.conf ../ns2/managed.conf
|
||||||
|
cp managed.conf ../ns4/managed.conf
|
||||||
|
cp managed.conf ../ns5/managed.conf
|
||||||
|
|
||||||
# Configure a trusted key statement (used by delve)
|
# Configure a trusted key statement (used by delve)
|
||||||
cat $keyname.key | grep -v '^; ' | $PERL -n -e '
|
cat $keyname.key | grep -v '^; ' | $PERL -n -e '
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20 -T tat=1
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40 -T tat=1
|
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=5/10/20
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -23,6 +23,7 @@ options {
|
|||||||
dnssec-enable yes;
|
dnssec-enable yes;
|
||||||
dnssec-validation yes;
|
dnssec-validation yes;
|
||||||
bindkeys-file "managed.conf";
|
bindkeys-file "managed.conf";
|
||||||
|
trust-anchor-telemetry no;
|
||||||
};
|
};
|
||||||
|
|
||||||
key rndc_key {
|
key rndc_key {
|
||||||
|
|||||||
@@ -0,0 +1,41 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// NS4
|
||||||
|
|
||||||
|
controls { /* empty */ };
|
||||||
|
|
||||||
|
options {
|
||||||
|
query-source address 10.53.0.4;
|
||||||
|
notify-source 10.53.0.4;
|
||||||
|
transfer-source 10.53.0.4;
|
||||||
|
port 5300;
|
||||||
|
pid-file "named.pid";
|
||||||
|
listen-on { 10.53.0.4; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion yes;
|
||||||
|
notify no;
|
||||||
|
dnssec-enable yes;
|
||||||
|
dnssec-validation auto;
|
||||||
|
bindkeys-file "managed.conf";
|
||||||
|
managed-keys-directory "nope";
|
||||||
|
};
|
||||||
|
|
||||||
|
key rndc_key {
|
||||||
|
secret "1234abcd8765";
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
};
|
||||||
|
|
||||||
|
controls {
|
||||||
|
inet 10.53.0.4 port 9953 allow { any; } keys { rndc_key; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "../../common/root.hint";
|
||||||
|
};
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// NS5
|
||||||
|
|
||||||
|
options {
|
||||||
|
query-source address 10.53.0.5;
|
||||||
|
notify-source 10.53.0.5;
|
||||||
|
transfer-source 10.53.0.5;
|
||||||
|
port 5300;
|
||||||
|
pid-file "named.pid";
|
||||||
|
listen-on { 10.53.0.5; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion yes;
|
||||||
|
notify no;
|
||||||
|
dnssec-enable yes;
|
||||||
|
dnssec-validation auto;
|
||||||
|
bindkeys-file "managed.conf";
|
||||||
|
};
|
||||||
|
|
||||||
|
key rndc_key {
|
||||||
|
secret "1234abcd8765";
|
||||||
|
algorithm hmac-sha256;
|
||||||
|
};
|
||||||
|
|
||||||
|
controls {
|
||||||
|
inet 10.53.0.5 port 9953 allow { any; } keys { rndc_key; };
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "../../common/root.hint";
|
||||||
|
};
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
-m record,size,mctx -T clienttest -c named.conf -d 99 -X named.lock -g -T mkeytimers=2/20/40
|
||||||
@@ -14,5 +14,14 @@ $SHELL clean.sh
|
|||||||
test -r $RANDFILE || $GENRANDOM 800 $RANDFILE
|
test -r $RANDFILE || $GENRANDOM 800 $RANDFILE
|
||||||
|
|
||||||
cp ns1/named1.conf ns1/named.conf
|
cp ns1/named1.conf ns1/named.conf
|
||||||
|
cp ns5/named1.args ns5/named.args
|
||||||
|
|
||||||
cd ns1 && $SHELL sign.sh
|
( cd ns1 && $SHELL sign.sh )
|
||||||
|
|
||||||
|
cp ns2/managed.conf ns2/managed1.conf
|
||||||
|
|
||||||
|
cd ns4
|
||||||
|
mkdir nope
|
||||||
|
touch nope/managed-keys.bind
|
||||||
|
touch nope/managed.keys.bind.jnl
|
||||||
|
chmod 444 nope/*
|
||||||
|
|||||||
+297
-99
@@ -9,6 +9,74 @@
|
|||||||
SYSTEMTESTTOP=..
|
SYSTEMTESTTOP=..
|
||||||
. $SYSTEMTESTTOP/conf.sh
|
. $SYSTEMTESTTOP/conf.sh
|
||||||
|
|
||||||
|
wait_for_log() {
|
||||||
|
msg=$1
|
||||||
|
file=$2
|
||||||
|
for i in 1 2 3 4 5 6 7 8 9 10; do
|
||||||
|
nextpart "$file" | grep "$msg" > /dev/null && return
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
echo "I: exceeded time limit waiting for '$msg' in $file"
|
||||||
|
ret=1
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_reconfig_on() {
|
||||||
|
nsidx=$1
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reconfig . | sed "s/^/I: ns${nsidx} /"
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_reload_on() {
|
||||||
|
nsidx=$1
|
||||||
|
nextpart ns${nsidx}/named.run > /dev/null
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 reload . | sed "s/^/I: ns${nsidx} /"
|
||||||
|
wait_for_log "loaded serial" ns${nsidx}/named.run
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_loadkeys_on() {
|
||||||
|
nsidx=$1
|
||||||
|
nextpart ns${nsidx}/named.run > /dev/null
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 loadkeys . | sed "s/^/I: ns${nsidx} /"
|
||||||
|
wait_for_log "next key event" ns${nsidx}/named.run
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_refresh_on() {
|
||||||
|
nsidx=$1
|
||||||
|
nextpart ns${nsidx}/named.run > /dev/null
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys refresh | sed "s/^/I: ns${nsidx} /"
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns${nsidx}/named.run
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_sync_on() {
|
||||||
|
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||||
|
# returns immediately after the expected log message is written, the
|
||||||
|
# managed-keys zone is already locked and the command below calls
|
||||||
|
# dns_zone_flush(), which also attempts to take that zone's lock
|
||||||
|
nsidx=$1
|
||||||
|
nextpart ns${nsidx}/named.run > /dev/null
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys sync | sed "s/^/I: ns${nsidx} /"
|
||||||
|
wait_for_log "dump_done" ns${nsidx}/named.run
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_status_on() {
|
||||||
|
# No race with mkeys_refresh_on() is possible as even if the latter
|
||||||
|
# returns immediately after the expected log message is written, the
|
||||||
|
# managed-keys zone is already locked and the command below calls
|
||||||
|
# mkey_status(), which in turn calls dns_zone_getrefreshkeytime(),
|
||||||
|
# which also attempts to take that zone's lock
|
||||||
|
nsidx=$1
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 managed-keys status
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_flush_on() {
|
||||||
|
nsidx=$1
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 flush | sed "s/^/I: ns${nsidx} /"
|
||||||
|
}
|
||||||
|
|
||||||
|
mkeys_secroots_on() {
|
||||||
|
nsidx=$1
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.${nsidx} -p 9953 secroots | sed "s/^/I: ns${nsidx} /"
|
||||||
|
}
|
||||||
|
|
||||||
status=0
|
status=0
|
||||||
n=1
|
n=1
|
||||||
|
|
||||||
@@ -58,11 +126,9 @@ n=`expr $n + 1`
|
|||||||
echo "I: check new trust anchor can be added ($n)"
|
echo "I: check new trust anchor can be added ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
standby1=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
standby1=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 5
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# there should be two keys listed now
|
# there should be two keys listed now
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -81,10 +147,8 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check new trust anchor can't be added with bad initial key ($n)"
|
echo "I: check new trust anchor can't be added with bad initial key ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys refresh | sed 's/^/I: ns3 /'
|
mkeys_refresh_on 3
|
||||||
sleep 1
|
mkeys_status_on 3 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys sync | sed 's/^/I: ns3 /'
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# there should be one key listed now
|
# there should be one key listed now
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 1 ] || ret=1
|
[ "$count" -eq 1 ] || ret=1
|
||||||
@@ -100,14 +164,17 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: remove untrusted standby key, check timer restarts ($n)"
|
echo "I: remove untrusted standby key, check timer restarts ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
mkeys_sync_on 2
|
||||||
t1=`grep "trust pending" ns2/managed-keys.bind`
|
t1=`grep "trust pending" ns2/managed-keys.bind`
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||||
sleep 3
|
mkeys_loadkeys_on 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# Less than a second may have passed since the last time ns2 received a
|
||||||
sleep 1
|
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||||
|
# reset to the same timestamp.
|
||||||
sleep 1
|
sleep 1
|
||||||
|
mkeys_refresh_on 2
|
||||||
|
mkeys_sync_on 2
|
||||||
t2=`grep "trust pending" ns2/managed-keys.bind`
|
t2=`grep "trust pending" ns2/managed-keys.bind`
|
||||||
# trust pending date must be different
|
# trust pending date must be different
|
||||||
[ -n "$t2" ] || ret=1
|
[ -n "$t2" ] || ret=1
|
||||||
@@ -121,12 +188,15 @@ echo "I: restore untrusted standby key, revoke original key ($n)"
|
|||||||
t1=$t2
|
t1=$t2
|
||||||
$SETTIME -D none -K ns1 $standby1 > /dev/null
|
$SETTIME -D none -K ns1 $standby1 > /dev/null
|
||||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
# Less than a second may have passed since the last time ns2 received a
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||||
|
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||||
|
# reset to the same timestamp.
|
||||||
sleep 1
|
sleep 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
mkeys_sync_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -153,10 +223,14 @@ n=`expr $n + 1`
|
|||||||
ret=0
|
ret=0
|
||||||
echo "I: refresh managed-keys, ensure same result ($n)"
|
echo "I: refresh managed-keys, ensure same result ($n)"
|
||||||
t1=$t2
|
t1=$t2
|
||||||
sleep 2
|
# Less than a second may have passed since the last time ns2 received a
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
# reset to the same timestamp.
|
||||||
|
sleep 1
|
||||||
|
mkeys_refresh_on 2
|
||||||
|
mkeys_sync_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -184,15 +258,17 @@ ret=0
|
|||||||
echo "I: restore revoked key, ensure same result ($n)"
|
echo "I: restore revoked key, ensure same result ($n)"
|
||||||
t1=$t2
|
t1=$t2
|
||||||
$SETTIME -R none -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -R none -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
|
||||||
$SETTIME -D none -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -D none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
# Less than a second may have passed since the last time ns2 received a
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||||
|
# timestamp to prevent false negatives caused by the acceptance timer getting
|
||||||
|
# reset to the same timestamp.
|
||||||
sleep 1
|
sleep 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
mkeys_sync_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -215,17 +291,44 @@ t2=`grep "trust pending" ns2/managed-keys.bind`
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I: reinitialize trust anchors"
|
echo "I: reinitialize trust anchors, add second key to bind.keys"
|
||||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||||
rm -f ns2/managed-keys.bind*
|
rm -f ns2/managed-keys.bind*
|
||||||
|
cat ns1/$standby1.key | grep -v '^; ' | $PERL -n -e '
|
||||||
|
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
|
||||||
|
local $key = join("", @rest);
|
||||||
|
local $originalkey = `grep initial-key ns2/managed1.conf`;
|
||||||
|
print <<EOF
|
||||||
|
managed-keys {
|
||||||
|
$originalkey
|
||||||
|
"$dn" initial-key $flags $proto $alg "$key";
|
||||||
|
};
|
||||||
|
EOF
|
||||||
|
' > ns2/managed.conf
|
||||||
|
nextpart ns2/named.run > /dev/null
|
||||||
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check that no key from bind.keys is marked as an initializing key ($n)"
|
||||||
|
ret=0
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||||
|
mkeys_secroots_on 2
|
||||||
|
grep '; initializing' ns2/named.secroots > /dev/null 2>&1 && ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
echo "I: reinitialize trust anchors, revert to one key in bind.keys"
|
||||||
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||||
|
rm -f ns2/managed-keys.bind*
|
||||||
|
mv ns2/managed1.conf ns2/managed.conf
|
||||||
|
nextpart ns2/named.run > /dev/null
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check that standby key is now trusted ($n)"
|
echo "I: check that standby key is now trusted ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
sleep 3
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -243,12 +346,9 @@ echo "I: revoke original key, add new standby ($n)"
|
|||||||
ret=0
|
ret=0
|
||||||
standby2=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
standby2=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||||
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -R now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# three keys listed
|
# three keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 3 ] || ret=1
|
[ "$count" -eq 3 ] || ret=1
|
||||||
@@ -277,11 +377,9 @@ n=`expr $n + 1`
|
|||||||
echo "I: revoke standby before it is trusted ($n)"
|
echo "I: revoke standby before it is trusted ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
standby3=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
standby3=`$KEYGEN -a rsasha256 -qfk -r $RANDFILE -K ns1 .`
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.a.$n 2>&1
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.a.$n 2>&1
|
|
||||||
# four keys listed
|
# four keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.a.$n`
|
count=`grep -c "keyid: " rndc.out.a.$n`
|
||||||
[ "$count" -eq 4 ] || { echo "keyid: count ($count) != 4"; ret=1; }
|
[ "$count" -eq 4 ] || { echo "keyid: count ($count) != 4"; ret=1; }
|
||||||
@@ -292,11 +390,9 @@ count=`grep -c "trust revoked" rndc.out.a.$n`
|
|||||||
count=`grep -c "trust pending" rndc.out.a.$n`
|
count=`grep -c "trust pending" rndc.out.a.$n`
|
||||||
[ "$count" -eq 2 ] || { echo "trust pending count ($count) != 2"; ret=1; }
|
[ "$count" -eq 2 ] || { echo "trust pending count ($count) != 2"; ret=1; }
|
||||||
$SETTIME -R now -K ns1 $standby3 > /dev/null
|
$SETTIME -R now -K ns1 $standby3 > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.b.$n 2>&1
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.b.$n 2>&1
|
|
||||||
# now three keys listed
|
# now three keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.b.$n`
|
count=`grep -c "keyid: " rndc.out.b.$n`
|
||||||
[ "$count" -eq 3 ] || { echo "keyid: count ($count) != 3"; ret=1; }
|
[ "$count" -eq 3 ] || { echo "keyid: count ($count) != 3"; ret=1; }
|
||||||
@@ -307,18 +403,16 @@ count=`grep -c "trust revoked" rndc.out.b.$n`
|
|||||||
count=`grep -c "trust pending" rndc.out.b.$n`
|
count=`grep -c "trust pending" rndc.out.b.$n`
|
||||||
[ "$count" -eq 1 ] || { echo "trust pending count ($count) != 1"; ret=1; }
|
[ "$count" -eq 1 ] || { echo "trust pending count ($count) != 1"; ret=1; }
|
||||||
$SETTIME -D now -K ns1 $standby3 > /dev/null
|
$SETTIME -D now -K ns1 $standby3 > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: wait 30 seconds for key add/remove holddowns to expire ($n)"
|
echo "I: wait 20 seconds for key add/remove holddowns to expire ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
sleep 30
|
sleep 20
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_refresh_on 2
|
||||||
sleep 1
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -340,12 +434,9 @@ ret=0
|
|||||||
$SETTIME -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -D now -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$SETTIME -R now -K ns1 $standby1 > /dev/null
|
$SETTIME -R now -K ns1 $standby1 > /dev/null
|
||||||
$SETTIME -R now -K ns1 $standby2 > /dev/null
|
$SETTIME -R now -K ns1 $standby2 > /dev/null
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 loadkeys . | sed 's/^/I: ns1 /'
|
mkeys_loadkeys_on 1
|
||||||
sleep 3
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# two keys listed
|
# two keys listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 2 ] || ret=1
|
[ "$count" -eq 2 ] || ret=1
|
||||||
@@ -367,8 +458,10 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check for insecure response ($n)"
|
echo "I: check for insecure response ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
|
mkeys_refresh_on 2
|
||||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||||
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NOERROR" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
|
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null && ret=1
|
||||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
@@ -380,16 +473,18 @@ $SETTIME -D now -K ns1 $standby2 > /dev/null
|
|||||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||||
cp ns1/named2.conf ns1/named.conf
|
cp ns1/named2.conf ns1/named.conf
|
||||||
rm -f ns1/root.db.signed.jnl
|
rm -f ns1/root.db.signed.jnl
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reconfig
|
mkeys_reconfig_on 1
|
||||||
|
|
||||||
echo "I: reinitialize trust anchors"
|
echo "I: reinitialize trust anchors"
|
||||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns2
|
||||||
rm -f ns2/managed-keys.bind*
|
rm -f ns2/managed-keys.bind*
|
||||||
|
nextpart ns2/named.run > /dev/null
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check positive validation ($n)"
|
echo "I: check positive validation ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns2/named.run
|
||||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
@@ -403,17 +498,25 @@ orig=`cat ns1/managed.key`
|
|||||||
keyid=`cat ns1/managed.key.id`
|
keyid=`cat ns1/managed.key.id`
|
||||||
revoked=`$REVOKE -K ns1 $orig`
|
revoked=`$REVOKE -K ns1 $orig`
|
||||||
rkeyid=`expr $revoked : 'ns1/K\.+00.+0*\([1-9]*[0-9]*[0-9]\)'`
|
rkeyid=`expr $revoked : 'ns1/K\.+00.+0*\([1-9]*[0-9]*[0-9]\)'`
|
||||||
|
rm -f ns1/root.db.signed.jnl
|
||||||
|
# We need to activate at least one valid DNSKEY to prevent dnssec-signzone from
|
||||||
|
# failing. Alternatively, we could use -P to disable post-sign verification,
|
||||||
|
# but we actually do want post-sign verification to happen to ensure the zone
|
||||||
|
# is correct before we break it on purpose.
|
||||||
$SETTIME -R none -D none -K ns1 $standby1 > /dev/null
|
$SETTIME -R none -D none -K ns1 $standby1 > /dev/null
|
||||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -O full -o . -f signer.out.$n ns1/root.db > /dev/null 2>&-
|
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -O full -o . -f signer.out.$n ns1/root.db > /dev/null 2>&-
|
||||||
cp -f ns1/root.db.signed ns1/root.db.tmp
|
cp -f ns1/root.db.signed ns1/root.db.tmp
|
||||||
BADSIG="SVn2tLDzpNX2rxR4xRceiCsiTqcWNKh7NQ0EQfCrVzp9WEmLw60sQ5kP xGk4FS/xSKfh89hO2O/H20Bzp0lMdtr2tKy8IMdU/mBZxQf2PXhUWRkg V2buVBKugTiOPTJSnaqYCN3rSfV1o7NtC1VNHKKK/D5g6bpDehdn5Gaq kpBhN+MSCCh9OZP2IT20luS1ARXxLlvuSVXJ3JYuuhTsQXUbX/SQpNoB Lo6ahCE55szJnmAxZEbb2KOVnSlZRA6ZBHDhdtO0S4OkvcmTutvcVV+7 w53CbKdaXhirvHIh0mZXmYk2PbPLDY7PU9wSH40UiWPOB9f00wwn6hUe uEQ1Qg=="
|
BADSIG="SVn2tLDzpNX2rxR4xRceiCsiTqcWNKh7NQ0EQfCrVzp9WEmLw60sQ5kP xGk4FS/xSKfh89hO2O/H20Bzp0lMdtr2tKy8IMdU/mBZxQf2PXhUWRkg V2buVBKugTiOPTJSnaqYCN3rSfV1o7NtC1VNHKKK/D5g6bpDehdn5Gaq kpBhN+MSCCh9OZP2IT20luS1ARXxLlvuSVXJ3JYuuhTsQXUbX/SQpNoB Lo6ahCE55szJnmAxZEbb2KOVnSlZRA6ZBHDhdtO0S4OkvcmTutvcVV+7 w53CbKdaXhirvHIh0mZXmYk2PbPLDY7PU9wSH40UiWPOB9f00wwn6hUe uEQ1Qg=="
|
||||||
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
# Less than a second may have passed since ns1 was started. If we call
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||||
sleep 3
|
# subsequent "rndc reload ." call on platforms which do not set the
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||||
|
# equal to master file modification time.
|
||||||
sleep 1
|
sleep 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys sync | sed 's/^/I: ns2 /'
|
sed -e "/ $rkeyid \./s, \. .*$, . $BADSIG," signer.out.$n > ns1/root.db.signed
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
mkeys_reload_on 1
|
||||||
|
mkeys_refresh_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
# one key listed
|
# one key listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 1 ] || { echo "'keyid:' count ($count) != 1"; ret=1; }
|
[ "$count" -eq 1 ] || { echo "'keyid:' count ($count) != 1"; ret=1; }
|
||||||
@@ -434,6 +537,7 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check validation fails with bad DNSKEY rrset ($n)"
|
echo "I: check validation fails with bad DNSKEY rrset ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
|
mkeys_flush_on 2
|
||||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||||
grep "status: SERVFAIL" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: SERVFAIL" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
@@ -443,17 +547,18 @@ n=`expr $n + 1`
|
|||||||
echo "I: restore DNSKEY rrset, check validation succeeds again ($n)"
|
echo "I: restore DNSKEY rrset, check validation succeeds again ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
rm -f ${revoked}.key ${revoked}.private
|
rm -f ${revoked}.key ${revoked}.private
|
||||||
|
rm -f ns1/root.db.signed.jnl
|
||||||
$SETTIME -D none -R none -K ns1 `cat ns1/managed.key` > /dev/null
|
$SETTIME -D none -R none -K ns1 `cat ns1/managed.key` > /dev/null
|
||||||
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
$SETTIME -D now -K ns1 $standby1 > /dev/null
|
||||||
$SETTIME -D now -K ns1 $standby2 > /dev/null
|
# Less than a second may have passed since ns1 was started. If we call
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 flush | sed 's/^/I: ns1 /'
|
# dnssec-signzone immediately, ns1/root.db.signed will not be reloaded by the
|
||||||
|
# subsequent "rndc reload ." call on platforms which do not set the
|
||||||
|
# "nanoseconds" field of isc_time_t, due to zone load time being seemingly
|
||||||
|
# equal to master file modification time.
|
||||||
sleep 1
|
sleep 1
|
||||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
mkeys_reload_on 1
|
||||||
sleep 3
|
mkeys_flush_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
@@ -462,15 +567,24 @@ status=`expr $status + $ret`
|
|||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: reset the root server with no keys, check for minimal update ($n)"
|
echo "I: reset the root server with no keys, check for minimal update ($n)"
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
ret=0
|
||||||
|
# Refresh keys first to prevent previous checks from influencing this one.
|
||||||
|
# Note that we might still get occasional false negatives on some really slow
|
||||||
|
# machines, when $t1 equals $t2 due to the time elapsed between "rndc
|
||||||
|
# managed-keys status" calls being equal to the normal active refresh period
|
||||||
|
# (as calculated per rules listed in RFC 5011 section 2.3) minus an "hour" (as
|
||||||
|
# set using -T mkeytimers).
|
||||||
|
mkeys_refresh_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
t1=`grep 'next refresh:' rndc.out.$n`
|
t1=`grep 'next refresh:' rndc.out.$n`
|
||||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||||
|
rm -f ns1/root.db.signed.jnl
|
||||||
cp ns1/root.db ns1/root.db.signed
|
cp ns1/root.db ns1/root.db.signed
|
||||||
|
nextpart ns1/named.run > /dev/null
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||||
sleep 3
|
wait_for_log "loaded serial" ns1/named.run
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_refresh_on 2
|
||||||
sleep 1
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
# one key listed
|
# one key listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 1 ] || ret=1
|
[ "$count" -eq 1 ] || ret=1
|
||||||
@@ -492,14 +606,23 @@ status=`expr $status + $ret`
|
|||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: reset the root server with no signatures, check for minimal update ($n)"
|
echo "I: reset the root server with no signatures, check for minimal update ($n)"
|
||||||
t2=$t1
|
ret=0
|
||||||
|
# Refresh keys first to prevent previous checks from influencing this one
|
||||||
|
mkeys_refresh_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
|
t1=`grep 'next refresh:' rndc.out.$n`
|
||||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns1
|
||||||
|
rm -f ns1/root.db.signed.jnl
|
||||||
cat ns1/K*.key >> ns1/root.db.signed
|
cat ns1/K*.key >> ns1/root.db.signed
|
||||||
|
nextpart ns1/named.run > /dev/null
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||||
sleep 3
|
wait_for_log "loaded serial" ns1/named.run
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
# Less than a second may have passed since the last time ns2 received a
|
||||||
|
# ./DNSKEY response from ns1. Ensure keys are refreshed at a different
|
||||||
|
# timestamp to prevent minimal update from resetting it to the same timestamp.
|
||||||
sleep 1
|
sleep 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
mkeys_refresh_on 2
|
||||||
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
# one key listed
|
# one key listed
|
||||||
count=`grep -c "keyid: " rndc.out.$n`
|
count=`grep -c "keyid: " rndc.out.$n`
|
||||||
[ "$count" -eq 1 ] || ret=1
|
[ "$count" -eq 1 ] || ret=1
|
||||||
@@ -521,13 +644,12 @@ status=`expr $status + $ret`
|
|||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: restore root server, check validation succeeds again ($n)"
|
echo "I: restore root server, check validation succeeds again ($n)"
|
||||||
|
ret=0
|
||||||
rm -f ns1/root.db.signed.jnl
|
rm -f ns1/root.db.signed.jnl
|
||||||
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
$SIGNER -Sg -K ns1 -N unixtime -r $RANDFILE -o . ns1/root.db > /dev/null 2>&-
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 reload . | sed 's/^/I: ns1 /'
|
mkeys_reload_on 1
|
||||||
sleep 3
|
mkeys_refresh_on 2
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys refresh | sed 's/^/I: ns2 /'
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
sleep 1
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
$DIG $DIGOPTS +noauth example. @10.53.0.2 txt > dig.out.ns2.test$n || ret=1
|
||||||
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "flags:.*ad.*QUERY" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "example..*.RRSIG..*TXT" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
@@ -537,14 +659,14 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check that trust-anchor-telemetry queries are logged ($n)"
|
echo "I: check that trust-anchor-telemetry queries are logged ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns3/named.run > /dev/null || ret=1
|
grep "sending trust-anchor-telemetry query '_ta-[0-9a-f]*/NULL" ns2/named.run > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: check that trust-anchor-telemetry queries are received ($n)"
|
echo "I: check that trust-anchor-telemetry queries are received ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
grep "query '_ta-[0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
@@ -552,15 +674,91 @@ n=`expr $n + 1`
|
|||||||
echo "I: check 'rndc-managed-keys destroy' ($n)"
|
echo "I: check 'rndc-managed-keys destroy' ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys destroy | sed 's/^/I: ns2 /'
|
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys destroy | sed 's/^/I: ns2 /'
|
||||||
sleep 1
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
grep "no views with managed keys" rndc.out.$n > /dev/null || ret=1
|
grep "no views with managed keys" rndc.out.$n > /dev/null || ret=1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig | sed 's/^/I: ns2 /'
|
mkeys_reconfig_on 2
|
||||||
sleep 1
|
mkeys_status_on 2 > rndc.out.$n 2>&1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 managed-keys status > rndc.out.$n 2>&1
|
|
||||||
grep "name: \." rndc.out.$n > /dev/null || ret=1
|
grep "name: \." rndc.out.$n > /dev/null || ret=1
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check that trust-anchor-telemetry queries contain the correct key ($n)"
|
||||||
|
ret=0
|
||||||
|
# convert the hexadecimal key from the TAT query into decimal and
|
||||||
|
# compare against the known key.
|
||||||
|
tathex=`grep "query '_ta-[0-9a-f][0-9a-f]*/NULL/IN' approved" ns1/named.run | awk '{print $6; exit 0}' | sed -e 's/(_ta-\([0-9a-f][0-9a-f]*\)):/\1/'`
|
||||||
|
tatkey=`$PERL -e 'printf("%d\n", hex(@ARGV[0]));' $tathex`
|
||||||
|
realkey=`$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 secroots - | sed -n 's#.*SHA256/\([0-9][0-9]*\) ; .*managed.*#\1#p'`
|
||||||
|
[ "$tatkey" -eq "$realkey" ] || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check initialization fails if managed-keys can't be created ($n)"
|
||||||
|
ret=0
|
||||||
|
mkeys_secroots_on 4
|
||||||
|
grep '; initializing managed' ns4/named.secroots > /dev/null 2>&1 || ret=1
|
||||||
|
grep '; managed' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||||
|
grep '; trusted' ns4/named.secroots > /dev/null 2>&1 && ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check failure to contact root servers does not prevent key refreshes after restart ($n)"
|
||||||
|
ret=0
|
||||||
|
# By the time we get here, ns5 should have attempted refreshing its managed
|
||||||
|
# keys. These attempts should fail as ns1 is configured to REFUSE all queries
|
||||||
|
# from ns5. Note that named1.args does not contain "-T mkeytimers"; this is to
|
||||||
|
# ensure key refresh retry will be scheduled to one actual hour after the first
|
||||||
|
# key refresh failure instead of just a few seconds, in order to prevent races
|
||||||
|
# between the next scheduled key refresh time and startup time of restarted ns5.
|
||||||
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||||
|
nextpart ns5/named.run > /dev/null
|
||||||
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||||
|
# ns5/named.run will contain logs from both the old instance and the new
|
||||||
|
# instance. In order for the test to pass, both must attempt a fetch.
|
||||||
|
count=`grep -c "Creating key fetch" ns5/named.run`
|
||||||
|
[ $count -lt 2 ] && ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: check key refreshes are resumed after root servers become available ($n)"
|
||||||
|
ret=0
|
||||||
|
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc . ns5
|
||||||
|
# Prevent previous check from affecting this one
|
||||||
|
rm -f ns5/managed-keys.bind*
|
||||||
|
# named2.args adds "-T mkeytimers=2/20/40" to named1.args as we need to wait for
|
||||||
|
# an "hour" until keys are refreshed again after initial failure
|
||||||
|
cp ns5/named2.args ns5/named.args
|
||||||
|
nextpart ns5/named.run > /dev/null
|
||||||
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns5
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||||
|
mkeys_secroots_on 5
|
||||||
|
grep '; initializing managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||||
|
# ns1 should still REFUSE queries from ns5, so resolving should be impossible
|
||||||
|
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.a.test$n || ret=1
|
||||||
|
grep "flags:.*ad.*QUERY" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||||
|
grep "example..*.RRSIG..*TXT" dig.out.ns5.a.test$n > /dev/null && ret=1
|
||||||
|
grep "status: SERVFAIL" dig.out.ns5.a.test$n > /dev/null || ret=1
|
||||||
|
# Allow queries from ns5 to ns1
|
||||||
|
cp ns1/named3.conf ns1/named.conf
|
||||||
|
rm -f ns1/root.db.signed.jnl
|
||||||
|
mkeys_reconfig_on 1
|
||||||
|
nextpart ns5/named.run > /dev/null
|
||||||
|
wait_for_log "Returned from key fetch in keyfetch_done()" ns5/named.run
|
||||||
|
mkeys_secroots_on 5
|
||||||
|
grep '; managed' ns5/named.secroots > /dev/null 2>&1 || ret=1
|
||||||
|
# ns1 should not longer REFUSE queries from ns5, so managed keys should be
|
||||||
|
# correctly refreshed and resolving should succeed
|
||||||
|
$DIG $DIGOPTS +noauth example. @10.53.0.5 txt > dig.out.ns5.b.test$n || ret=1
|
||||||
|
grep "flags:.*ad.*QUERY" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||||
|
grep "example..*.RRSIG..*TXT" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||||
|
grep "status: NOERROR" dig.out.ns5.b.test$n > /dev/null || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I:exit status: $status"
|
echo "I:exit status: $status"
|
||||||
[ $status -eq 0 ] || exit 1
|
[ $status -eq 0 ] || exit 1
|
||||||
|
|||||||
@@ -53,6 +53,7 @@ view "b" {
|
|||||||
type slave;
|
type slave;
|
||||||
masters { 10.53.0.5 key "a"; };
|
masters { 10.53.0.5 key "a"; };
|
||||||
file "x21.bk-b";
|
file "x21.bk-b";
|
||||||
|
notify no;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -62,5 +63,6 @@ view "c" {
|
|||||||
type slave;
|
type slave;
|
||||||
masters { 10.53.0.5 key "a"; };
|
masters { 10.53.0.5 key "a"; };
|
||||||
file "x21.bk-c";
|
file "x21.bk-c";
|
||||||
|
notify no;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ options {
|
|||||||
listen-on-v6 { none; };
|
listen-on-v6 { none; };
|
||||||
recursion yes;
|
recursion yes;
|
||||||
notify yes;
|
notify yes;
|
||||||
|
serial-query-rate 1; // workaround for KB AA-01213
|
||||||
};
|
};
|
||||||
|
|
||||||
key altkey {
|
key altkey {
|
||||||
|
|||||||
@@ -278,7 +278,7 @@ sleep 10
|
|||||||
if
|
if
|
||||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns1
|
||||||
then
|
then
|
||||||
echo "I:restarted server ns1"
|
echo "I:restarted server ns1"
|
||||||
else
|
else
|
||||||
echo "I:could not restart server ns1"
|
echo "I:could not restart server ns1"
|
||||||
exit 1
|
exit 1
|
||||||
@@ -486,6 +486,7 @@ fi
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
ret=0
|
ret=0
|
||||||
echo "I:check that 'update-policy local' fails from non-localhost address ($n)"
|
echo "I:check that 'update-policy local' fails from non-localhost address ($n)"
|
||||||
|
grep 'match on session key not from localhost' ns5/named.run > /dev/null && ret=1
|
||||||
$NSUPDATE -p 5300 -k ns5/session.key > nsupdate.out.$n 2>&1 << END && ret=1
|
$NSUPDATE -p 5300 -k ns5/session.key > nsupdate.out.$n 2>&1 << END && ret=1
|
||||||
server 10.53.0.5 5300
|
server 10.53.0.5 5300
|
||||||
local 10.53.0.1
|
local 10.53.0.1
|
||||||
@@ -493,6 +494,7 @@ update add nonlocal.local.nil. 600 A 4.3.2.1
|
|||||||
send
|
send
|
||||||
END
|
END
|
||||||
grep REFUSED nsupdate.out.$n > /dev/null 2>&1 || ret=1
|
grep REFUSED nsupdate.out.$n > /dev/null 2>&1 || ret=1
|
||||||
|
grep 'match on session key not from localhost' ns5/named.run > /dev/null || ret=1
|
||||||
$DIG @10.53.0.5 -p 5300 \
|
$DIG @10.53.0.5 -p 5300 \
|
||||||
+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd \
|
+tcp +noadd +nosea +nostat +noquest +nocomm +nocmd \
|
||||||
nonlocal.local.nil. > dig.out.ns5.$n || ret=1
|
nonlocal.local.nil. > dig.out.ns5.$n || ret=1
|
||||||
@@ -707,8 +709,12 @@ size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->siz
|
|||||||
[ "$size" -gt 6000 ] || ret=1
|
[ "$size" -gt 6000 ] || ret=1
|
||||||
sleep 1
|
sleep 1
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 sync maxjournal.test
|
$RNDC -c ../common/rndc.conf -s 10.53.0.1 -p 9953 sync maxjournal.test
|
||||||
sleep 1
|
for i in 1 2 3 4 5 6
|
||||||
|
do
|
||||||
|
sleep 1
|
||||||
|
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||||
|
[ "$size" -lt 5000 ] && break
|
||||||
|
done
|
||||||
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
size=`$PERL -e 'use File::stat; my $sb = stat(@ARGV[0]); printf("%s\n", $sb->size);' ns1/maxjournal.db.jnl`
|
||||||
[ "$size" -lt 5000 ] || ret=1
|
[ "$size" -lt 5000 ] || ret=1
|
||||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||||
@@ -883,75 +889,81 @@ grep "address family not supported" nsupdate.out-$n > /dev/null 2>&1 || ret=1
|
|||||||
#
|
#
|
||||||
# Add client library tests here
|
# Add client library tests here
|
||||||
#
|
#
|
||||||
n=`expr $n + 1`
|
|
||||||
ret=0
|
if test unset != "${SAMPLEUPDATE:-unset}" -a -x "${SAMPLEUPDATE}"
|
||||||
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
then
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
ret=0
|
||||||
|
echo "I:check that dns_client_update handles prerequisite NXDOMAIN failure ($n)"
|
||||||
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||||
add "nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
add "nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxdomain exists.sample" \
|
||||||
add "check-nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
add "check-nxdomain-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||||
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
grep "update failed: YXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
ret=0
|
ret=0
|
||||||
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
echo "I:check that dns_client_update handles prerequisite YXDOMAIN failure ($n)"
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||||
add "yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
add "yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxdomain nxdomain.sample" \
|
||||||
add "check-yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
add "check-yxdomain-nxdomain.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||||
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
$DIG +tcp @10.53.0.1 -p 5300 a nxdomain-exists.sample > dig.out.ns1.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a nxdomain-exists.sample > dig.out.ns2.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a check-nxdomain-exists.sample > check.out.ns2.test$n
|
||||||
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
grep "update failed: NXDOMAIN" update.out.test$n > /dev/null || ret=1
|
||||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
ret=0
|
ret=0
|
||||||
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
echo "I:check that dns_client_update handles prerequisite NXRRSET failure ($n)"
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.1 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||||
add "nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
add "nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "nxrrset exists.sample TXT This RRset exists." \
|
||||||
add "check-nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
add "check-nxrrset-exists.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||||
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
$DIG +tcp @10.53.0.1 -p 5300 a nxrrset-exists.sample > dig.out.ns1.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a nxrrset-exists.sample > dig.out.ns2.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a check-nxrrset-exists.sample > check.out.ns2.test$n
|
||||||
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
grep "update failed: YXRRSET" update.out.test$n > /dev/null || ret=1
|
||||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
ret=0
|
ret=0
|
||||||
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
echo "I:check that dns_client_update handles prerequisite YXRRSET failure ($n)"
|
||||||
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
$SAMPLEUPDATE -s -P 5300 -a 10.53.0.1 -a 10.53.0.2 \
|
||||||
-p "yxrrset no-txt.sample TXT" \
|
-p "yxrrset no-txt.sample TXT" \
|
||||||
add "yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
add "yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.test$n 2>&1
|
||||||
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
$SAMPLEUPDATE -P 5300 -a 10.53.0.2 -p "yxrrset no-txt.sample TXT" \
|
||||||
add "check-yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
add "check-yxrrset-nxrrset.sample 0 in a 1.2.3.4" > update.out.check$n 2>&1
|
||||||
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
$DIG +tcp @10.53.0.1 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns1.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a yxrrset-nxrrset.sample > dig.out.ns2.test$n
|
||||||
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
$DIG +tcp @10.53.0.2 -p 5300 a check-yxrrset-nxrrset.sample > check.out.ns2.test$n
|
||||||
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
grep "update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||||
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
grep "update succeeded" update.out.check$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns1.test$n > /dev/null || ret=1
|
||||||
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NXDOMAIN" dig.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
grep "status: NOERROR" check.out.ns2.test$n > /dev/null || ret=1
|
||||||
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
grep "2nd update failed: NXRRSET" update.out.test$n > /dev/null || ret=1
|
||||||
[ $ret = 0 ] || { echo I:failed; status=1; }
|
[ $ret = 0 ] || { echo I:failed; status=1; }
|
||||||
|
|
||||||
|
fi
|
||||||
|
|
||||||
#
|
#
|
||||||
# End client library tests here
|
# End client library tests here
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -7,8 +7,9 @@ file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|||||||
system test for recursion limits
|
system test for recursion limits
|
||||||
|
|
||||||
ns1 -- root server
|
ns1 -- root server
|
||||||
ans2 -- delegate to ns1.(n+1).example.com for all n, up to
|
ans2 -- for example.org: delegate to ns1.(n+1).example.org for all n, up to the
|
||||||
the value specified in ans.limit (or forever if limit is 0)
|
value specified in ans.limit (or forever if limit is 0)
|
||||||
|
for example.net: delegate every query to 15 more name servers, with
|
||||||
|
"victim" address
|
||||||
ns3 -- resolver under test
|
ns3 -- resolver under test
|
||||||
ans4 -- delegates every query to 16 more name servers, with "victim" address
|
|
||||||
ans7 -- "victim" server
|
ans7 -- "victim" server
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/usr/bin/env perl
|
#!/usr/bin/env perl
|
||||||
#
|
#
|
||||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -10,9 +10,17 @@ use strict;
|
|||||||
use warnings;
|
use warnings;
|
||||||
|
|
||||||
use IO::File;
|
use IO::File;
|
||||||
use Getopt::Long;
|
use IO::Socket;
|
||||||
use Net::DNS::Nameserver;
|
use Net::DNS;
|
||||||
use Time::HiRes qw(usleep nanosleep);
|
|
||||||
|
my $localaddr = "10.53.0.2";
|
||||||
|
my $limit = getlimit();
|
||||||
|
my $no_more_waiting = 0;
|
||||||
|
my @delayed_response;
|
||||||
|
my $timeout;
|
||||||
|
|
||||||
|
my $udpsock = IO::Socket::INET->new(LocalAddr => "$localaddr",
|
||||||
|
LocalPort => 5300, Proto => "udp", Reuse => 1) or die "$!";
|
||||||
|
|
||||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
||||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
print $pidf "$$\n" or die "cannot write pid file: $!";
|
||||||
@@ -39,21 +47,18 @@ sub getlimit {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
my $localaddr = "10.53.0.2";
|
# If $wait == 0 is returned, returned reply will be sent immediately.
|
||||||
my $localport = 5300;
|
# If $wait == 1 is returned, sending the returned reply might be delayed; see
|
||||||
my $verbose = 0;
|
# comments inside handle_UDP() for details.
|
||||||
my $limit = getlimit();
|
|
||||||
|
|
||||||
sub reply_handler {
|
sub reply_handler {
|
||||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
my ($qname, $qclass, $qtype) = @_;
|
||||||
my ($rcode, @ans, @auth, @add);
|
my ($rcode, @ans, @auth, @add, $wait);
|
||||||
|
|
||||||
print ("request: $qname/$qtype\n");
|
print ("request: $qname/$qtype\n");
|
||||||
STDOUT->flush();
|
STDOUT->flush();
|
||||||
|
|
||||||
|
$wait = 0;
|
||||||
$count += 1;
|
$count += 1;
|
||||||
# Sleep 100ms to make sure that named sends both A and AAAA queries.
|
|
||||||
usleep(100000);
|
|
||||||
|
|
||||||
if ($qname eq "count" ) {
|
if ($qname eq "count" ) {
|
||||||
if ($qtype eq "TXT") {
|
if ($qtype eq "TXT") {
|
||||||
@@ -95,6 +100,7 @@ sub reply_handler {
|
|||||||
$rcode = "NOERROR";
|
$rcode = "NOERROR";
|
||||||
} elsif ($qname =~ /^ns1\.(\d+)\.example\.org$/) {
|
} elsif ($qname =~ /^ns1\.(\d+)\.example\.org$/) {
|
||||||
my $next = $1 + 1;
|
my $next = $1 + 1;
|
||||||
|
$wait = 1;
|
||||||
if ($limit == 0 || (! $send_response && $next <= $limit)) {
|
if ($limit == 0 || (! $send_response && $next <= $limit)) {
|
||||||
my $rr = new Net::DNS::RR("$1.example.org 86400 $qclass NS ns1.$next.example.org");
|
my $rr = new Net::DNS::RR("$1.example.org 86400 $qclass NS ns1.$next.example.org");
|
||||||
push @auth, $rr;
|
push @auth, $rr;
|
||||||
@@ -108,24 +114,114 @@ sub reply_handler {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
$rcode = "NOERROR";
|
$rcode = "NOERROR";
|
||||||
|
} elsif ($qname eq "direct.example.net" ) {
|
||||||
|
if ($qtype eq "A") {
|
||||||
|
my ($ttl, $rdata) = (3600, $localaddr);
|
||||||
|
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
||||||
|
push @ans, $rr;
|
||||||
|
}
|
||||||
|
$rcode = "NOERROR";
|
||||||
|
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
||||||
|
my $next = ($1 + 1) * 16;
|
||||||
|
for (my $i = 1; $i < 16; $i++) {
|
||||||
|
my $s = $next + $i;
|
||||||
|
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
||||||
|
push @auth, $rr;
|
||||||
|
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
||||||
|
push @add, $rr;
|
||||||
|
}
|
||||||
|
$rcode = "NOERROR";
|
||||||
} else {
|
} else {
|
||||||
$rcode = "NXDOMAIN";
|
$rcode = "NXDOMAIN";
|
||||||
}
|
}
|
||||||
|
|
||||||
# mark the answer as authoritive (by setting the 'aa' flag
|
return ($rcode, \@ans, \@auth, \@add, $wait);
|
||||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
|
||||||
}
|
}
|
||||||
|
|
||||||
GetOptions(
|
sub handleUDP {
|
||||||
'port=i' => \$localport,
|
my ($buf, $peer) = @_;
|
||||||
'verbose!' => \$verbose,
|
my ($request, $rcode, $ans, $auth, $add, $wait);
|
||||||
);
|
|
||||||
|
|
||||||
my $ns = Net::DNS::Nameserver->new(
|
$request = new Net::DNS::Packet(\$buf, 0);
|
||||||
LocalAddr => $localaddr,
|
$@ and die $@;
|
||||||
LocalPort => $localport,
|
|
||||||
ReplyHandler => \&reply_handler,
|
|
||||||
Verbose => $verbose,
|
|
||||||
);
|
|
||||||
|
|
||||||
$ns->main_loop;
|
my ($question) = $request->question;
|
||||||
|
my $qname = $question->qname;
|
||||||
|
my $qclass = $question->qclass;
|
||||||
|
my $qtype = $question->qtype;
|
||||||
|
|
||||||
|
($rcode, $ans, $auth, $add, $wait) = reply_handler($qname, $qclass, $qtype);
|
||||||
|
|
||||||
|
my $reply = $request->reply();
|
||||||
|
|
||||||
|
$reply->header->rcode($rcode);
|
||||||
|
$reply->header->aa(@$ans ? 1 : 0);
|
||||||
|
$reply->header->id($request->header->id);
|
||||||
|
$reply->{answer} = $ans if $ans;
|
||||||
|
$reply->{authority} = $auth if $auth;
|
||||||
|
$reply->{additional} = $add if $add;
|
||||||
|
|
||||||
|
if ($wait) {
|
||||||
|
# reply_handler() asked us to delay sending this reply until
|
||||||
|
# another reply with $wait == 1 is generated or a timeout
|
||||||
|
# occurs.
|
||||||
|
if (@delayed_response) {
|
||||||
|
# A delayed reply is already queued, so we can now send
|
||||||
|
# both the delayed reply and the current reply.
|
||||||
|
send_delayed_response();
|
||||||
|
return $reply;
|
||||||
|
} elsif ($no_more_waiting) {
|
||||||
|
# It was determined before that there is no point in
|
||||||
|
# waiting for "accompanying" queries. Thus, send the
|
||||||
|
# current reply immediately.
|
||||||
|
return $reply;
|
||||||
|
} else {
|
||||||
|
# No delayed reply is queued and the client is expected
|
||||||
|
# to send an "accompanying" query shortly. Do not send
|
||||||
|
# the current reply right now, just save it for later
|
||||||
|
# and wait for an "accompanying" query to be received.
|
||||||
|
@delayed_response = ($reply, $peer);
|
||||||
|
$timeout = 0.5;
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
# Send reply immediately.
|
||||||
|
return $reply;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
sub send_delayed_response {
|
||||||
|
my ($reply, $peer) = @delayed_response;
|
||||||
|
# Truncation to 512 bytes is required for triggering "NS explosion" on
|
||||||
|
# builds without IPv6 support
|
||||||
|
$udpsock->send($reply->data(512), 0, $peer);
|
||||||
|
undef @delayed_response;
|
||||||
|
undef $timeout;
|
||||||
|
}
|
||||||
|
|
||||||
|
# Main
|
||||||
|
my $rin;
|
||||||
|
my $rout;
|
||||||
|
for (;;) {
|
||||||
|
$rin = '';
|
||||||
|
vec($rin, fileno($udpsock), 1) = 1;
|
||||||
|
|
||||||
|
select($rout = $rin, undef, undef, $timeout);
|
||||||
|
|
||||||
|
if (vec($rout, fileno($udpsock), 1)) {
|
||||||
|
my ($buf, $peer, $reply);
|
||||||
|
$udpsock->recv($buf, 512);
|
||||||
|
$peer = $udpsock->peername();
|
||||||
|
$reply = handleUDP($buf, $peer);
|
||||||
|
# Truncation to 512 bytes is required for triggering "NS
|
||||||
|
# explosion" on builds without IPv6 support
|
||||||
|
$udpsock->send($reply->data(512), 0, $peer) if $reply;
|
||||||
|
} else {
|
||||||
|
# An "accompanying" query was expected to come in, but did not.
|
||||||
|
# Assume the client never sends "accompanying" queries to
|
||||||
|
# prevent pointlessly waiting for them ever again.
|
||||||
|
$no_more_waiting = 1;
|
||||||
|
# Send the delayed reply to the query which caused us to wait.
|
||||||
|
send_delayed_response();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,89 +0,0 @@
|
|||||||
#!/usr/bin/env perl
|
|
||||||
#
|
|
||||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
#
|
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
use strict;
|
|
||||||
use warnings;
|
|
||||||
|
|
||||||
use IO::File;
|
|
||||||
use Getopt::Long;
|
|
||||||
use Net::DNS::Nameserver;
|
|
||||||
|
|
||||||
my $pidf = new IO::File "ans.pid", "w" or die "cannot open pid file: $!";
|
|
||||||
print $pidf "$$\n" or die "cannot write pid file: $!";
|
|
||||||
$pidf->close or die "cannot close pid file: $!";
|
|
||||||
sub rmpid { unlink "ans.pid"; exit 1; };
|
|
||||||
|
|
||||||
$SIG{INT} = \&rmpid;
|
|
||||||
$SIG{TERM} = \&rmpid;
|
|
||||||
|
|
||||||
my $count = 0;
|
|
||||||
my $send_response = 0;
|
|
||||||
|
|
||||||
my $localaddr = "10.53.0.4";
|
|
||||||
my $localport = 5300;
|
|
||||||
my $verbose = 0;
|
|
||||||
|
|
||||||
sub reply_handler {
|
|
||||||
my ($qname, $qclass, $qtype, $peerhost, $query, $conn) = @_;
|
|
||||||
my ($rcode, @ans, @auth, @add);
|
|
||||||
|
|
||||||
print ("request: $qname/$qtype\n");
|
|
||||||
STDOUT->flush();
|
|
||||||
|
|
||||||
$count += 1;
|
|
||||||
|
|
||||||
if ($qname eq "count" ) {
|
|
||||||
if ($qtype eq "TXT") {
|
|
||||||
my ($ttl, $rdata) = (0, "$count");
|
|
||||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
|
||||||
push @ans, $rr;
|
|
||||||
print ("\tcount: $count\n");
|
|
||||||
}
|
|
||||||
$rcode = "NOERROR";
|
|
||||||
} elsif ($qname eq "reset" ) {
|
|
||||||
$count = 0;
|
|
||||||
$send_response = 0;
|
|
||||||
$rcode = "NOERROR";
|
|
||||||
} elsif ($qname eq "direct.example.net" ) {
|
|
||||||
if ($qtype eq "A") {
|
|
||||||
my ($ttl, $rdata) = (3600, $localaddr);
|
|
||||||
my $rr = new Net::DNS::RR("$qname $ttl $qclass $qtype $rdata");
|
|
||||||
push @ans, $rr;
|
|
||||||
}
|
|
||||||
$rcode = "NOERROR";
|
|
||||||
} elsif( $qname =~ /^ns1\.(\d+)\.example\.net$/ ) {
|
|
||||||
my $next = ($1 + 1) * 16;
|
|
||||||
for (my $i = 1; $i < 16; $i++) {
|
|
||||||
my $s = $next + $i;
|
|
||||||
my $rr = new Net::DNS::RR("$1.example.net 86400 $qclass NS ns1.$s.example.net");
|
|
||||||
push @auth, $rr;
|
|
||||||
$rr = new Net::DNS::RR("ns1.$s.example.net 86400 $qclass A 10.53.0.7");
|
|
||||||
push @add, $rr;
|
|
||||||
}
|
|
||||||
$rcode = "NOERROR";
|
|
||||||
} else {
|
|
||||||
$rcode = "NXDOMAIN";
|
|
||||||
}
|
|
||||||
|
|
||||||
# mark the answer as authoritive (by setting the 'aa' flag
|
|
||||||
return ($rcode, \@ans, \@auth, \@add, { aa => 1 });
|
|
||||||
}
|
|
||||||
|
|
||||||
GetOptions(
|
|
||||||
'port=i' => \$localport,
|
|
||||||
'verbose!' => \$verbose,
|
|
||||||
);
|
|
||||||
|
|
||||||
my $ns = Net::DNS::Nameserver->new(
|
|
||||||
LocalAddr => $localaddr,
|
|
||||||
LocalPort => $localport,
|
|
||||||
ReplyHandler => \&reply_handler,
|
|
||||||
Verbose => $verbose,
|
|
||||||
);
|
|
||||||
|
|
||||||
$ns->main_loop;
|
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
; Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
; Copyright (C) 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
;
|
;
|
||||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -11,4 +11,4 @@ ns.tld1. 60 IN A 10.53.0.1
|
|||||||
example.org. 60 IN NS direct.example.org.
|
example.org. 60 IN NS direct.example.org.
|
||||||
direct.example.org. 60 IN A 10.53.0.2
|
direct.example.org. 60 IN A 10.53.0.2
|
||||||
example.net. 60 IN NS direct.example.net.
|
example.net. 60 IN NS direct.example.net.
|
||||||
direct.example.net. 60 IN A 10.53.0.4
|
direct.example.net. 60 IN A 10.53.0.2
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -9,6 +9,20 @@
|
|||||||
SYSTEMTESTTOP=..
|
SYSTEMTESTTOP=..
|
||||||
. $SYSTEMTESTTOP/conf.sh
|
. $SYSTEMTESTTOP/conf.sh
|
||||||
|
|
||||||
|
if $PERL -e 'use Net::DNS;' 2>/dev/null
|
||||||
|
then
|
||||||
|
if $PERL -e 'use Net::DNS; die if ($Net::DNS::VERSION <= 0.78);' 2>/dev/null
|
||||||
|
then
|
||||||
|
:
|
||||||
|
else
|
||||||
|
echo "I:Net::DNS versions up to 0.78 have a bug that causes this test to fail: please update." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "I:This test requires the Net::DNS library." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
||||||
then
|
then
|
||||||
:
|
:
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -14,101 +14,107 @@ DIGOPTS="-p 5300"
|
|||||||
status=0
|
status=0
|
||||||
n=0
|
n=0
|
||||||
|
|
||||||
|
ns3_reset() {
|
||||||
|
cp $1 ns3/named.conf
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns3 /'
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush | sed 's/^/I: ns3 /'
|
||||||
|
}
|
||||||
|
|
||||||
|
ns3_sends_aaaa_queries() {
|
||||||
|
if grep "started AAAA fetch" ns3/named.run >/dev/null; then
|
||||||
|
return 0
|
||||||
|
else
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Check whether the number of queries ans2 received from ns3 (this value is
|
||||||
|
# read from dig output stored in file $1) is as expected. The expected query
|
||||||
|
# count is variable:
|
||||||
|
# - if ns3 sends AAAA queries, the query count should equal $2,
|
||||||
|
# - if ns3 does not send AAAA queries, the query count should equal $3.
|
||||||
|
check_query_count() {
|
||||||
|
count=`sed 's/[^0-9]//g;' $1`
|
||||||
|
expected_count_with_aaaa=$2
|
||||||
|
expected_count_without_aaaa=$3
|
||||||
|
|
||||||
|
if ns3_sends_aaaa_queries; then
|
||||||
|
expected_count=$expected_count_with_aaaa
|
||||||
|
else
|
||||||
|
expected_count=$expected_count_without_aaaa
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ $count -ne $expected_count ]; then
|
||||||
|
echo "I: count ($count) != $expected_count"
|
||||||
|
ret=1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
echo "I: set max-recursion-depth=12"
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt excessive-depth lookup ($n)"
|
echo "I: attempt excessive-depth lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "1000" > ans2/ans.limit
|
echo "1000" > ans2/ans.limit
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect1.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect1.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
eval count=`cat dig.out.2.test$n`
|
check_query_count dig.out.2.test$n 26 14
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
|
||||||
then
|
|
||||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
|
||||||
else
|
|
||||||
[ $count -eq 14 ] || { ret=1; echo "I: count ($count) != 14"; }
|
|
||||||
fi
|
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt permissible lookup ($n)"
|
echo "I: attempt permissible lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
sleep 2
|
|
||||||
echo "12" > ans2/ans.limit
|
echo "12" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named1.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect2.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect2.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
eval count=`cat dig.out.2.test$n`
|
check_query_count dig.out.2.test$n 49 26
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
|
||||||
then
|
|
||||||
[ $count -eq 49 ] || { ret=1; echo "I: count ($count) != 49"; }
|
|
||||||
else
|
|
||||||
[ $count -eq 26 ] || { ret=1; echo "I: count ($count) != 26"; }
|
|
||||||
fi
|
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I:reset max-recursion-depth"
|
echo "I: set max-recursion-depth=5"
|
||||||
cp ns3/named2.conf ns3/named.conf
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
|
||||||
sleep 2
|
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt excessive-depth lookup ($n)"
|
echo "I: attempt excessive-depth lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "12" > ans2/ans.limit
|
echo "12" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named2.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect3.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect3.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
eval count=`cat dig.out.2.test$n`
|
check_query_count dig.out.2.test$n 12 7
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
|
||||||
then
|
|
||||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
|
||||||
else
|
|
||||||
[ $count -eq 7 ] || { ret=1; echo "I: count ($count) != 7"; }
|
|
||||||
fi
|
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt permissible lookup ($n)"
|
echo "I: attempt permissible lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "5" > ans2/ans.limit
|
echo "5" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named2.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect4.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect4.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
eval count=`cat dig.out.2.test$n`
|
check_query_count dig.out.2.test$n 21 12
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
|
||||||
then
|
|
||||||
[ $count -eq 21 ] || { ret=1; echo "I: count ($count) != 21"; }
|
|
||||||
else
|
|
||||||
[ $count -eq 12 ] || { ret=1; echo "I: count ($count) != 12"; }
|
|
||||||
fi
|
|
||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I:reset max-recursion-depth"
|
echo "I: set max-recursion-depth=100, max-recursion-queries=50"
|
||||||
cp ns3/named3.conf ns3/named.conf
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
|
||||||
sleep 2
|
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt excessive-queries lookup ($n)"
|
echo "I: attempt excessive-queries lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "13" > ans2/ans.limit
|
echo "13" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named3.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect5.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect5.example.org > dig.out.1.test$n || ret=1
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
if ns3_sends_aaaa_queries; then
|
||||||
then
|
|
||||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||||
fi
|
fi
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
@@ -118,10 +124,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
|||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt permissible lookup ($n)"
|
echo "I: attempt permissible lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "12" > ans2/ans.limit
|
echo "12" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named3.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect6.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect6.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||||
@@ -131,20 +137,16 @@ eval count=`cat dig.out.2.test$n`
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
echo "I:reset max-recursion-queries"
|
echo "I: set max-recursion-depth=100, max-recursion-queries=40"
|
||||||
cp ns3/named4.conf ns3/named.conf
|
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig 2>&1 | sed 's/^/I:ns1 /'
|
|
||||||
sleep 2
|
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt excessive-queries lookup ($n)"
|
echo "I: attempt excessive-queries lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "10" > ans2/ans.limit
|
echo "10" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named4.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect7.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect7.example.org > dig.out.1.test$n || ret=1
|
||||||
if [ "$TESTSOCK6" != "false" ]
|
if ns3_sends_aaaa_queries; then
|
||||||
then
|
|
||||||
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: SERVFAIL" dig.out.1.test$n > /dev/null || ret=1
|
||||||
fi
|
fi
|
||||||
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
@@ -154,10 +156,10 @@ if [ $ret != 0 ]; then echo "I:failed"; fi
|
|||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempt permissible lookup ($n)"
|
echo "I: attempt permissible lookup ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
echo "9" > ans2/ans.limit
|
echo "9" > ans2/ans.limit
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named4.conf
|
||||||
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS @10.53.0.3 indirect8.example.org > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS @10.53.0.3 indirect8.example.org > dig.out.1.test$n || ret=1
|
||||||
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
grep "status: NOERROR" dig.out.1.test$n > /dev/null || ret=1
|
||||||
@@ -170,10 +172,10 @@ status=`expr $status + $ret`
|
|||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: attempting NS explosion ($n)"
|
echo "I: attempting NS explosion ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 flush 2>&1 | sed 's/^/I:ns1 /'
|
ns3_reset ns3/named4.conf
|
||||||
|
$DIG $DIGOPTS @10.53.0.2 reset > /dev/null || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.3 ns1.1.example.net > dig.out.1.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.3 ns1.1.example.net > dig.out.1.test$n || ret=1
|
||||||
sleep 2
|
$DIG $DIGOPTS +short @10.53.0.2 count txt > dig.out.2.test$n || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.4 count txt > dig.out.2.test$n || ret=1
|
|
||||||
eval count=`cat dig.out.2.test$n`
|
eval count=`cat dig.out.2.test$n`
|
||||||
[ $count -lt 50 ] || ret=1
|
[ $count -lt 50 ] || ret=1
|
||||||
$DIG $DIGOPTS +short @10.53.0.7 count txt > dig.out.3.test$n || ret=1
|
$DIG $DIGOPTS +short @10.53.0.7 count txt > dig.out.3.test$n || ret=1
|
||||||
|
|||||||
+17
-16
@@ -100,26 +100,27 @@ $PERL stop.pl $test
|
|||||||
status=`expr $status + $?`
|
status=`expr $status + $?`
|
||||||
|
|
||||||
if [ $status != 0 ]; then
|
if [ $status != 0 ]; then
|
||||||
echofail "R:FAIL"
|
echofail "R:FAIL"
|
||||||
# Don't clean up - we need the evidence.
|
# Don't clean up - we need the evidence.
|
||||||
find . -name core -exec chmod 0644 '{}' \;
|
find . -name core -exec chmod 0644 '{}' \;
|
||||||
else
|
else
|
||||||
echopass "R:PASS"
|
echopass "R:PASS"
|
||||||
|
|
||||||
if $clean
|
if $clean
|
||||||
|
then
|
||||||
|
rm -f $SYSTEMTESTTOP/random.data
|
||||||
|
if test -f $test/clean.sh
|
||||||
then
|
then
|
||||||
rm -f $SYSTEMTESTTOP/random.data
|
( cd $test && $SHELL clean.sh "$@" )
|
||||||
if test -f $test/clean.sh
|
|
||||||
then
|
|
||||||
( cd $test && $SHELL clean.sh "$@" )
|
|
||||||
fi
|
|
||||||
if test -d ../../../.git
|
|
||||||
then
|
|
||||||
git status -su $test |
|
|
||||||
sed -n 's/^?? \(.*\)/I:file \1 not removed/p'
|
|
||||||
fi
|
|
||||||
|
|
||||||
fi
|
fi
|
||||||
|
if test -d ../../../.git
|
||||||
|
then
|
||||||
|
git status -su --ignored $test |
|
||||||
|
sed -n -e 's|^?? \(.*\)|I:file \1 not removed|p' \
|
||||||
|
-e 's|^!! \(.*/named.run\)$|I:file \1 not removed|p' \
|
||||||
|
-e 's|^!! \(.*/named.memstats\)$|I:file \1 not removed|p'
|
||||||
|
fi
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echoinfo "E:$test:`date`"
|
echoinfo "E:$test:`date`"
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
*
|
||||||
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
*/
|
||||||
|
|
||||||
|
options {
|
||||||
|
new-zones-directory "./nope";
|
||||||
|
port 5300;
|
||||||
|
pid-file "../named.pid";
|
||||||
|
listen-on { 127.0.0.1; };
|
||||||
|
listen-on-v6 { none; };
|
||||||
|
recursion no;
|
||||||
|
};
|
||||||
@@ -14,4 +14,10 @@ $SHELL clean.sh
|
|||||||
cp ns2/named1.conf ns2/named.conf
|
cp ns2/named1.conf ns2/named.conf
|
||||||
|
|
||||||
mkdir ns2/nope
|
mkdir ns2/nope
|
||||||
chmod 555 ns2/nope
|
|
||||||
|
if [ 1 = "${CYGWIN:-0}" ]
|
||||||
|
then
|
||||||
|
setfacl -s user::r-x,group::r-x,other::r-x ns2/nope
|
||||||
|
else
|
||||||
|
chmod 555 ns2/nope
|
||||||
|
fi
|
||||||
|
|||||||
@@ -73,6 +73,17 @@ grep "managed-keys-directory './nope' is not writable" ns2/named.run > /dev/null
|
|||||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
status=`expr $status + $ret`
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
|
n=`expr $n + 1`
|
||||||
|
echo "I: checking that named refuses to reconfigure if new-zones-directory is not writable ($n)"
|
||||||
|
ret=0
|
||||||
|
cp -f ns2/named-alt6.conf ns2/named.conf
|
||||||
|
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig > rndc.out.$n 2>&1
|
||||||
|
grep "failed: permission denied" rndc.out.$n > /dev/null 2>&1 || ret=1
|
||||||
|
sleep 1
|
||||||
|
grep "new-zones-directory './nope' is not writable" ns2/named.run > /dev/null 2>&1 || ret=1
|
||||||
|
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||||
|
status=`expr $status + $ret`
|
||||||
|
|
||||||
n=`expr $n + 1`
|
n=`expr $n + 1`
|
||||||
echo "I: checking that named refuses to start if working directory is not writable ($n)"
|
echo "I: checking that named refuses to start if working directory is not writable ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
|
|||||||
@@ -16,15 +16,6 @@ rm -f dig.out.*
|
|||||||
|
|
||||||
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd -p 5300"
|
DIGOPTS="+tcp +noadd +nosea +nostat +nocmd -p 5300"
|
||||||
|
|
||||||
# read everything that's been appended to a file since the last time
|
|
||||||
# 'nextpart' was called.
|
|
||||||
nextpart () {
|
|
||||||
[ -f $1.prev ] || echo "0" > $1.prev
|
|
||||||
prev=`cat $1.prev`
|
|
||||||
awk "FNR > $prev "'{ print }
|
|
||||||
END { print NR > "/dev/stderr" }' $1 2> $1.prev
|
|
||||||
}
|
|
||||||
|
|
||||||
echo "I:checking DNSSEC SERVFAIL is cached ($n)"
|
echo "I:checking DNSSEC SERVFAIL is cached ($n)"
|
||||||
ret=0
|
ret=0
|
||||||
$DIG $DIGOPTS +dnssec foo.example. a @10.53.0.5 > dig.out.ns5.test$n || ret=1
|
$DIG $DIGOPTS +dnssec foo.example. a @10.53.0.5 > dig.out.ns5.test$n || ret=1
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user