Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
150deb0126 | ||
|
|
894ce6081a | ||
|
|
5cdcb725a9 |
+1
-2
@@ -21,10 +21,9 @@ ans.run
|
|||||||
named.run
|
named.run
|
||||||
named.memstats
|
named.memstats
|
||||||
gen.dSYM/
|
gen.dSYM/
|
||||||
.ccache/
|
.libs/
|
||||||
.deps/
|
.deps/
|
||||||
.dirstamp
|
.dirstamp
|
||||||
.libs/
|
|
||||||
unit/atf-src/atf-c++/atf-c++.pc
|
unit/atf-src/atf-c++/atf-c++.pc
|
||||||
unit/atf-src/atf-c/atf-c.pc
|
unit/atf-src/atf-c/atf-c.pc
|
||||||
unit/atf-src/atf-c/defs.h
|
unit/atf-src/atf-c/defs.h
|
||||||
|
|||||||
-233
@@ -1,233 +0,0 @@
|
|||||||
variables:
|
|
||||||
DEBIAN_FRONTEND: noninteractive
|
|
||||||
LC_ALL: C
|
|
||||||
DOCKER_DRIVER: overlay2
|
|
||||||
CI_REGISTRY_IMAGE: oerdnj/bind9
|
|
||||||
CCACHE_DIR: "/ccache"
|
|
||||||
|
|
||||||
stages:
|
|
||||||
- precheck
|
|
||||||
- build
|
|
||||||
- test
|
|
||||||
|
|
||||||
.debian-jessie-amd64: &debian_jessie_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-jessie-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.debian-jessie-i386: &debian_jessie_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-jessie-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.debian-stretch-amd64: &debian_stretch_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-stretch-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.debian-stretch-i386:: &debian_stretch_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-stretch-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.debian-buster-amd64: &debian_buster_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-buster-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.debian-buster-i386:: &debian_buster_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-buster-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.debian-sid-amd64: &debian_sid_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.debian-sid-i386: &debian_sid_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-sid-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.ubuntu-trusty-amd64: &ubuntu_trusty_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:ubuntu-trusty-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.ubuntu-trusty-i386: &ubuntu_trusty_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:ubuntu-trusty-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.ubuntu-xenial-amd64: &ubuntu_xenial_amd64_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:ubuntu-xenial-amd64"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- amd64
|
|
||||||
|
|
||||||
.ubuntu-xenial-i386: &ubuntu_xenial_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:ubuntu-xenial-i386"
|
|
||||||
tags:
|
|
||||||
- linux
|
|
||||||
- docker
|
|
||||||
- i386
|
|
||||||
|
|
||||||
.build: &build_job
|
|
||||||
stage: build
|
|
||||||
before_script:
|
|
||||||
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
|
||||||
- ./autogen.sh
|
|
||||||
script:
|
|
||||||
- ./configure --enable-developer --with-libtool --disable-static --with-atf=/usr/local --with-libidn2
|
|
||||||
- make -j${PARALLEL_JOBS_BUILD:-1} -k all V=1
|
|
||||||
artifacts:
|
|
||||||
expire_in: '1 hour'
|
|
||||||
untracked: true
|
|
||||||
|
|
||||||
.system_test: &system_test_job
|
|
||||||
stage: test
|
|
||||||
before_script:
|
|
||||||
- rm -rf .ccache
|
|
||||||
- bash -x bin/tests/system/ifconfig.sh up
|
|
||||||
script:
|
|
||||||
- ( cd bin/tests && make -j${TEST_PARALLEL_JOBS:-1} -k test V=1 )
|
|
||||||
- test -s bin/tests/system/systests.output
|
|
||||||
artifacts:
|
|
||||||
untracked: true
|
|
||||||
expire_in: '1 week'
|
|
||||||
when: on_failure
|
|
||||||
|
|
||||||
.unit_test: &unit_test_job
|
|
||||||
stage: test
|
|
||||||
before_script:
|
|
||||||
- export KYUA_RESULT="$CI_PROJECT_DIR/kyua.results"
|
|
||||||
script:
|
|
||||||
- make unit
|
|
||||||
after_script:
|
|
||||||
- kyua report-html --force --results-file kyua.results --results-filter "" --output kyua_html
|
|
||||||
artifacts:
|
|
||||||
paths:
|
|
||||||
- atf.out
|
|
||||||
- kyua.log
|
|
||||||
- kyua.results
|
|
||||||
- kyua_html/
|
|
||||||
expire_in: '1 week'
|
|
||||||
when: on_failure
|
|
||||||
|
|
||||||
precheck:debian:sid:amd64:
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
stage: precheck
|
|
||||||
script:
|
|
||||||
- perl util/check-changes CHANGES
|
|
||||||
- perl -w util/merge_copyrights
|
|
||||||
- diff -urNap util/copyrights util/newcopyrights
|
|
||||||
- rm util/newcopyrights
|
|
||||||
artifacts:
|
|
||||||
paths:
|
|
||||||
- util/newcopyrights
|
|
||||||
expire_in: '1 week'
|
|
||||||
when: on_failure
|
|
||||||
|
|
||||||
#build:debian:jessie:amd64:
|
|
||||||
# <<: *debian_jessie_amd64_image
|
|
||||||
# <<: *build_job
|
|
||||||
#
|
|
||||||
#build:debian:jessie:i386:
|
|
||||||
# <<: *debian_jessie_i386_image
|
|
||||||
# <<: *build_job
|
|
||||||
#
|
|
||||||
#build:debian:stretch:amd64:
|
|
||||||
# <<: *debian_stretch_amd64_image
|
|
||||||
# <<: *build_job
|
|
||||||
#
|
|
||||||
#build:debian:buster:i386:
|
|
||||||
# <<: *debian_buster_i386_image
|
|
||||||
# <<: *build_job
|
|
||||||
#
|
|
||||||
#build:ubuntu:trusty:amd64:
|
|
||||||
# <<: *ubuntu_trusty_amd64_image
|
|
||||||
# <<: *build_job
|
|
||||||
#
|
|
||||||
#build:ubuntu:xenial:i386:
|
|
||||||
# <<: *ubuntu_xenial_i386_image
|
|
||||||
# <<: *build_job
|
|
||||||
|
|
||||||
build:clang:debian:sid:amd64:
|
|
||||||
variables:
|
|
||||||
CC: clang-6.0
|
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
<<: *build_job
|
|
||||||
|
|
||||||
build:debian:sid:amd64:
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
<<: *build_job
|
|
||||||
|
|
||||||
build:clang:debian:sid:i386:
|
|
||||||
variables:
|
|
||||||
CC: clang-6.0
|
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
|
||||||
<<: *debian_sid_i386_image
|
|
||||||
<<: *build_job
|
|
||||||
|
|
||||||
build:debian:sid:i386:
|
|
||||||
variables:
|
|
||||||
CC: gcc
|
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
|
||||||
<<: *debian_sid_i386_image
|
|
||||||
<<: *build_job
|
|
||||||
|
|
||||||
unittest:debian:sid:amd64:
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
<<: *unit_test_job
|
|
||||||
dependencies:
|
|
||||||
- build:debian:sid:amd64
|
|
||||||
|
|
||||||
unittest:clang:debian:sid:amd64:
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
<<: *unit_test_job
|
|
||||||
dependencies:
|
|
||||||
- build:clang:debian:sid:amd64
|
|
||||||
|
|
||||||
unittest:debian:sid:i386:
|
|
||||||
<<: *debian_sid_i386_image
|
|
||||||
<<: *unit_test_job
|
|
||||||
dependencies:
|
|
||||||
- build:debian:sid:i386
|
|
||||||
|
|
||||||
systemtest:debian:sid:amd64:
|
|
||||||
<<: *debian_sid_amd64_image
|
|
||||||
<<: *system_test_job
|
|
||||||
dependencies:
|
|
||||||
- build:debian:sid:amd64
|
|
||||||
|
|
||||||
systemtest:debian:sid:i386:
|
|
||||||
<<: *debian_sid_i386_image
|
|
||||||
<<: *system_test_job
|
|
||||||
dependencies:
|
|
||||||
- build:debian:sid:i386
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
<!--
|
|
||||||
If the bug you are reporting is potentially security-related - for example,
|
|
||||||
if it involves an assertion failure or other crash in `named` that can be
|
|
||||||
triggered repeatedly - then please do *NOT* report it here, but send an
|
|
||||||
email to [security-officer@isc.org](security-officer@isc.org).
|
|
||||||
-->
|
|
||||||
|
|
||||||
### Summary
|
|
||||||
|
|
||||||
(Summarize the bug encountered concisely.)
|
|
||||||
|
|
||||||
### Steps to reproduce
|
|
||||||
|
|
||||||
(How one can reproduce the issue - this is very important.)
|
|
||||||
|
|
||||||
### What is the current *bug* behavior?
|
|
||||||
|
|
||||||
(What actually happens.)
|
|
||||||
|
|
||||||
### What is the expected *correct* behavior?
|
|
||||||
|
|
||||||
(What you should see instead.)
|
|
||||||
|
|
||||||
### Relevant configuration files
|
|
||||||
|
|
||||||
(Paste any relevant configuration files - please use code blocks (```)
|
|
||||||
to format console output. If submitting the contents of your
|
|
||||||
configuration file in a non-confidential Issue, it is advisable to
|
|
||||||
obscure key secrets: this can be done automatically by using
|
|
||||||
`named-checkconf -px`.)
|
|
||||||
|
|
||||||
### Relevant logs and/or screenshots
|
|
||||||
|
|
||||||
(Paste any relevant logs - please use code blocks (```) to format console
|
|
||||||
output, logs, and code, as it's very hard to read otherwise.)
|
|
||||||
|
|
||||||
### Possible fixes
|
|
||||||
|
|
||||||
(If you can, link to the line of code that might be responsible for the
|
|
||||||
problem.)
|
|
||||||
|
|
||||||
/label ~bug
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
### Description
|
|
||||||
|
|
||||||
(Describe the problem, use cases, benefits, and/or goals.)
|
|
||||||
|
|
||||||
### Request
|
|
||||||
|
|
||||||
(Describe the solution you'd like to see.)
|
|
||||||
|
|
||||||
### Links / references
|
|
||||||
|
|
||||||
/label ~"feature request"
|
|
||||||
@@ -1,604 +1,3 @@
|
|||||||
4951. [protocol] Add "HOME.ARPA" to list of built in empty zones as
|
|
||||||
per RFC 8375. [GL #273]
|
|
||||||
--- 9.13.0 released ---
|
|
||||||
|
|
||||||
4950. [bug] ISC_SOCKEVENTATTR_TRUNC was not be set. [GL #238]
|
|
||||||
|
|
||||||
4949. [placeholder]
|
|
||||||
|
|
||||||
4948. [bug] When request-nsid is turned on, EDNS NSID options
|
|
||||||
should be logged at level info. Since change 3741
|
|
||||||
they have been logged at debug(3) by mistake.
|
|
||||||
[GL !290]
|
|
||||||
|
|
||||||
4947. [func] Replace all random functions with isc_random(),
|
|
||||||
isc_random_buf() and isc_random_uniform() API.
|
|
||||||
[GL #221]
|
|
||||||
|
|
||||||
4946. [bug] Additional glue was not being returned by resolver
|
|
||||||
for unsigned zones since change 4596. [GL #209]
|
|
||||||
|
|
||||||
4945. [func] BIND can no longer be built without DNSSEC support.
|
|
||||||
A cryptography provder (i.e., OpenSSL or a hardware
|
|
||||||
service module with PKCS#11 support) must be
|
|
||||||
available. [GL #244]
|
|
||||||
|
|
||||||
4944. [cleanup] Silence cppcheck portability warnings in
|
|
||||||
lib/isc/tests/buffer_test.c. [GL #239]
|
|
||||||
|
|
||||||
4943. [bug] Change 4687 consumed too much memory when running
|
|
||||||
system tests with --with-tuning=large. Reduced the
|
|
||||||
hash table size to 512 entries for 'named -m record'
|
|
||||||
restoring the previous memory footprint. [GL #248]
|
|
||||||
|
|
||||||
4942. [cleanup] Consolidate multiple instances of splitting of
|
|
||||||
batchline in dig into a single function. [GL #196]
|
|
||||||
|
|
||||||
4941. [cleanup] Silence clang static analyzer warnings. [GL #196]
|
|
||||||
|
|
||||||
4940. [cleanup] Extract the loop in dns__zone_updatesigs() into
|
|
||||||
separate functions to improve code readability.
|
|
||||||
[GL #135]
|
|
||||||
|
|
||||||
4939. [test] Add basic unit tests for update_sigs(). [GL #135]
|
|
||||||
|
|
||||||
4938. [placeholder]
|
|
||||||
|
|
||||||
4937. [func] Remove support for OpenSSL < 1.0.0 [GL #191]
|
|
||||||
|
|
||||||
4936. [func] Always use OpenSSL or PKCS#11 random data providers,
|
|
||||||
and remove the --{enable,disable}-crypto-rand configure
|
|
||||||
options. [GL #165]
|
|
||||||
|
|
||||||
4935. [func] Add support for LibreSSL >= 2.7.0 (some OpenSSL 1.1.0
|
|
||||||
call were added). [GL #191]
|
|
||||||
|
|
||||||
4934. [security] The serve-stale feature could cause an assertion failure
|
|
||||||
in rbtdb.c even when stale-answer-enable was false.
|
|
||||||
Simultaneous use of stale cache records and NSEC
|
|
||||||
aggressive negative caching could trigger a recursion
|
|
||||||
loop. (CVE-2018-5737) [GL #185]
|
|
||||||
|
|
||||||
4933. [bug] Not creating signing keys for an inline signed zone
|
|
||||||
prevented changes applied to the raw zone from being
|
|
||||||
reflected in the secure zone until signing keys were
|
|
||||||
made available. [GL #159]
|
|
||||||
|
|
||||||
4932. [bug] Bumped signed serial of an inline signed zone was
|
|
||||||
logged even when an error occurred while updating
|
|
||||||
signatures. [GL #159]
|
|
||||||
|
|
||||||
4931. [func] Removed the "rbtdb64" database implementation.
|
|
||||||
[GL #217]
|
|
||||||
|
|
||||||
4930. [bug] Remove a bogus check in nslookup command line
|
|
||||||
argument processing. [GL #206]
|
|
||||||
|
|
||||||
4929. [func] Add the ability to set RA and TC in queries made by
|
|
||||||
dig (+[no]raflag, +[no]tcflag). [GL #213]
|
|
||||||
|
|
||||||
4928. [func] The "dnskey-sig-validity" option allows
|
|
||||||
"sig-validity-interval" to be overriden for signatures
|
|
||||||
covering DNSKEY RRsets. [GL #145]
|
|
||||||
|
|
||||||
4927. [placeholder]
|
|
||||||
|
|
||||||
4926. [func] Add root key sentinel support. To disable, add
|
|
||||||
'root-key-sentinel no;' to named.conf. [GL #37]
|
|
||||||
|
|
||||||
4925. [func] Several configuration options that define intervals
|
|
||||||
can now take TTL value suffixes (for example, 2h or 1d)
|
|
||||||
in addition to integer parameters. These include
|
|
||||||
max-cache-ttl, max-ncache-ttl, max-policy-ttl,
|
|
||||||
fstrm-set-reopen-interval, interface-interval, and
|
|
||||||
min-update-interval. [GL #203]
|
|
||||||
|
|
||||||
4924. [cleanup] Clean up the isc_string_* namespace and leave
|
|
||||||
only strlcpy and strlcat. [GL #178]
|
|
||||||
|
|
||||||
4923. [cleanup] Refactor socket and socket event options into
|
|
||||||
enum types. [GL !135]
|
|
||||||
|
|
||||||
4922. [bug] dnstap: Log the destination address of client
|
|
||||||
packets rather than the interface address.
|
|
||||||
[GL #197]
|
|
||||||
|
|
||||||
4921. [cleanup] Add dns_fixedname_initname() and refactor the caller
|
|
||||||
code to make usage of the new function, as a part of
|
|
||||||
refactoring dns_fixedname_*() macros were turned into
|
|
||||||
functions. [GL #183]
|
|
||||||
|
|
||||||
4920. [cleanup] Clean up libdns removing most of the backwards
|
|
||||||
compatibility wrappers.
|
|
||||||
|
|
||||||
4919. [cleanup] Clean up the isc_hash_* namespace and leave only
|
|
||||||
the FNV-1a hash implementation. [GL #178]
|
|
||||||
|
|
||||||
4918. [bug] Fix double free after keygen error in dnssec-keygen
|
|
||||||
when OpenSSL >= 1.1.0 is used and RSA_generate_key_ex
|
|
||||||
fails. [GL #109]
|
|
||||||
|
|
||||||
4917. [func] Support 64 RPZ policy zones by default. [GL #123]
|
|
||||||
|
|
||||||
4916. [func] Remove IDNA2003 support and the bundled idnkit-1.0
|
|
||||||
library.
|
|
||||||
|
|
||||||
4915. [func] Implement IDNA2008 support in dig by adding support
|
|
||||||
for libidn2. New dig option +idnin has been added,
|
|
||||||
which allows to process invalid domain names much
|
|
||||||
like dig without IDN support. libidn2 version 2.0
|
|
||||||
or higher is needed for +idnout enabled by default.
|
|
||||||
|
|
||||||
4914. [security] A bug in zone database reference counting could lead to
|
|
||||||
a crash when multiple versions of a slave zone were
|
|
||||||
transferred from a master in close succession.
|
|
||||||
(CVE-2018-5736) [GL #134]
|
|
||||||
|
|
||||||
4913. [test] Re-implemented older unit tests in bin/tests as ATF,
|
|
||||||
removed the lib/tests unit testing library. [GL #115]
|
|
||||||
|
|
||||||
4912. [test] Improved the reliability of the 'cds' system test.
|
|
||||||
[GL #136]
|
|
||||||
|
|
||||||
4911. [test] Improved the reliability of the 'mkeys' system test.
|
|
||||||
[GL #128]
|
|
||||||
|
|
||||||
4910. [func] Update util/check-changes to work on release branches.
|
|
||||||
[GL #113]
|
|
||||||
|
|
||||||
4909. [bug] named-checkconf did not detect in-view zone collisions.
|
|
||||||
[GL #125]
|
|
||||||
|
|
||||||
4908. [test] Eliminated unnecessary waiting in the allow_query
|
|
||||||
system test. Also changed its name to allow-query.
|
|
||||||
[GL #81]
|
|
||||||
|
|
||||||
4907. [test] Improved the reliability of the 'notify' system
|
|
||||||
test. [GL #59]
|
|
||||||
|
|
||||||
4906. [func] Replace getquad() with inet_pton(), completing
|
|
||||||
change #4900. [GL #56]
|
|
||||||
|
|
||||||
4905. [bug] irs_resconf_load() ignored resolv.conf syntax errors
|
|
||||||
when "domain" or "search" options were present in that
|
|
||||||
file. [GL #110]
|
|
||||||
|
|
||||||
4904. [bug] Temporarily revert change #4859. [GL #124]
|
|
||||||
|
|
||||||
4903. [bug] "check-mx fail;" did not prevent MX records containing
|
|
||||||
IP addresses from being added to a zone by a dynamic
|
|
||||||
update. [GL #112]
|
|
||||||
|
|
||||||
4902. [test] Improved the reliability of the 'ixfr' system
|
|
||||||
test. [GL #66]
|
|
||||||
|
|
||||||
4901. [func] "dig +nssearch" now lists the name servers
|
|
||||||
for a domain that time out, as well as the servers
|
|
||||||
that respond. [GL #64]
|
|
||||||
|
|
||||||
4900. [func] Remove all uses of inet_aton(). As a result of this
|
|
||||||
change, IPv4 addresses are now only accepted in
|
|
||||||
dotted-quad format. [GL #13]
|
|
||||||
|
|
||||||
4899. [test] Convert most of the remaining system tests to be able
|
|
||||||
to run in parallel, continuing the work from change
|
|
||||||
#4895. To take advantage of this, use "make -jN check",
|
|
||||||
where N is the number of processors to use. [GL #91]
|
|
||||||
|
|
||||||
4898. [func] Remove libseccomp based system-call filtering. [GL #93]
|
|
||||||
|
|
||||||
4897. [test] Update to rpz system test so that it doesn't recurse.
|
|
||||||
[GL #68]
|
|
||||||
|
|
||||||
4896. [test] cacheclean system test was not robust. [GL #82]
|
|
||||||
|
|
||||||
4895. [test] Allow some system tests to run in parallel.
|
|
||||||
[RT #46602]
|
|
||||||
|
|
||||||
4894. [bug] named could crash while rolling a dnstap output file.
|
|
||||||
[RT #46942]
|
|
||||||
|
|
||||||
4893. [bug] Address various issues reported by cppcheck. [GL #51]
|
|
||||||
|
|
||||||
4892. [bug] named could leak memory when "rndc reload" was invoked
|
|
||||||
before all zone loading actions triggered by a previous
|
|
||||||
"rndc reload" command were completed. [RT #47076]
|
|
||||||
|
|
||||||
4891. [placeholder]
|
|
||||||
|
|
||||||
4890. [func] Remove unused ondestroy callback from libisc.
|
|
||||||
[isc-projects/bind9!3]
|
|
||||||
|
|
||||||
4889. [func] Warn about the use of old root keys without the new
|
|
||||||
root key being present. Warn about dlv.isc.org's
|
|
||||||
key being present. Warn about both managed and
|
|
||||||
trusted root keys being present. [RT #43670]
|
|
||||||
|
|
||||||
4888. [test] Initialize sockets correctly in sample-update so
|
|
||||||
that the nsupdate system test will run on Windows.
|
|
||||||
[RT #47097]
|
|
||||||
|
|
||||||
4887. [test] Enable the rpzrecurse test to run on Windows.
|
|
||||||
[RT #47093]
|
|
||||||
|
|
||||||
4886. [doc] Document dig -u in manpage. [RT #47150]
|
|
||||||
|
|
||||||
4885. [security] update-policy rules that otherwise ignore the name
|
|
||||||
field now require that it be set to "." to ensure
|
|
||||||
that any type list present is properly interpreted.
|
|
||||||
[RT #47126]
|
|
||||||
|
|
||||||
4884. [bug] named could crash on shutdown due to a race between
|
|
||||||
shutdown_server() and ns__client_request(). [RT #47120]
|
|
||||||
|
|
||||||
4883. [cleanup] Improved debugging output from dnssec-cds. [RT #47026]
|
|
||||||
|
|
||||||
4882. [bug] Address potential memory leak in
|
|
||||||
dns_update_signaturesinc. [RT #47084]
|
|
||||||
|
|
||||||
4881. [bug] Only include dst_openssl.h when OpenSSL is required.
|
|
||||||
[RT #47068]
|
|
||||||
|
|
||||||
4880. [bug] Named wasn't returning the target of a cross-zone
|
|
||||||
CNAME between two served zones when recursion was
|
|
||||||
desired and available (RD=1, RA=1). (When this is
|
|
||||||
not the case, the CNAME target is deliberately
|
|
||||||
withheld to prevent accidental cache poisoning.)
|
|
||||||
[RT #47078]
|
|
||||||
|
|
||||||
4879. [bug] dns_rdata_caa:value_len field was too small.
|
|
||||||
[RT #47086]
|
|
||||||
|
|
||||||
4878. [bug] List 'ply' as a requirement for the 'isc' python
|
|
||||||
package. [RT #47065]
|
|
||||||
|
|
||||||
4877. [bug] Address integer overflow when exponentially
|
|
||||||
backing off retry intervals. [RT #47041]
|
|
||||||
|
|
||||||
4876. [bug] Address deadlock with accessing a keytable. [RT #47000]
|
|
||||||
|
|
||||||
4875. [bug] Address compile failures on older systems. [RT #47015]
|
|
||||||
|
|
||||||
4874. [bug] Wrong time display when reporting new keywarntime.
|
|
||||||
[RT #47042]
|
|
||||||
|
|
||||||
4873. [doc] Grammars for named.conf included in the ARM are now
|
|
||||||
automatically generated by the configuration parser
|
|
||||||
itself. As a side effect of the work needed to
|
|
||||||
separate zone type grammars from each other, this
|
|
||||||
also makes checking of zone statements in
|
|
||||||
named-checkconf more correct and consistent.
|
|
||||||
[RT #36957]
|
|
||||||
|
|
||||||
4872. [bug] Don't permit loading meta RR types such as TKEY
|
|
||||||
from master files. [RT #47009]
|
|
||||||
|
|
||||||
4871. [bug] Fix configure glitch in detecting stdatomic.h
|
|
||||||
support on systems with multiple compilers.
|
|
||||||
[RT #46959]
|
|
||||||
|
|
||||||
4870. [test] Update included ATF library to atf-0.21 preserving
|
|
||||||
the ATF tool. [RT #46967]
|
|
||||||
|
|
||||||
4869. [bug] Address some cases where NULL with zero length could
|
|
||||||
be passed to memmove which is undefined behavior and
|
|
||||||
can lead to bad optimization. [RT #46888]
|
|
||||||
|
|
||||||
4868. [func] dnssec-keygen can no longer generate HMAC keys.
|
|
||||||
Use tsig-keygen instead. [RT #46404]
|
|
||||||
|
|
||||||
4867. [cleanup] Normalize rndc on/off commands (validation,
|
|
||||||
querylog, serve-stale) so they all accept the
|
|
||||||
same synonyms for on/off (yes/no, true/false,
|
|
||||||
enable/disable). Thanks to Tony Finch. [RT #47022]
|
|
||||||
|
|
||||||
4866. [port] DST library initialization verifies MD5 (when MD5
|
|
||||||
was not disabled) and SHA-1 hash and HMAC support.
|
|
||||||
[RT #46764]
|
|
||||||
|
|
||||||
4865. [cleanup] Simplify handling isc_socket_sendto2() return values.
|
|
||||||
[RT #46986]
|
|
||||||
|
|
||||||
4864. [bug] named acting as a slave for a catalog zone crashed if
|
|
||||||
the latter contained a master definition without an IP
|
|
||||||
address. [RT #45999]
|
|
||||||
|
|
||||||
4863. [bug] Fix various other bugs reported by Valgrind's
|
|
||||||
memcheck tool. [RT #46978]
|
|
||||||
|
|
||||||
4862. [bug] The rdata flags for RRSIG were not being properly set
|
|
||||||
when constructing a rdataslab. [RT #46978]
|
|
||||||
|
|
||||||
4861. [bug] The isc_crc64 unit test was not endian independent.
|
|
||||||
[RT #46973]
|
|
||||||
|
|
||||||
4860. [bug] isc_int8_t should be signed char. [RT #46973]
|
|
||||||
|
|
||||||
4859. [bug] A loop was possible when attempting to validate
|
|
||||||
unsigned CNAME responses from secure zones;
|
|
||||||
this caused a delay in returning SERVFAIL and
|
|
||||||
also increased the chances of encountering
|
|
||||||
CVE-2017-3145. [RT #46839]
|
|
||||||
|
|
||||||
4858. [security] Addresses could be referenced after being freed
|
|
||||||
in resolver.c, causing an assertion failure.
|
|
||||||
(CVE-2017-3145) [RT #46839]
|
|
||||||
|
|
||||||
4857. [bug] Maintain attach/detach semantics for event->db,
|
|
||||||
event->node, event->rdataset and event->sigrdataset
|
|
||||||
in query.c. [RT #46891]
|
|
||||||
|
|
||||||
4856. [bug] 'rndc zonestatus' reported the wrong underlying type
|
|
||||||
for a inline slave zone. [RT #46875]
|
|
||||||
|
|
||||||
4855. [bug] isc_time_formatshorttimestamp produced incorrect
|
|
||||||
output. [RT #46938]
|
|
||||||
|
|
||||||
4854. [bug] query_synthcnamewildcard should stop generating the
|
|
||||||
response if query_synthwildcard fails. [RT #46939]
|
|
||||||
|
|
||||||
4853. [bug] Add REQUIRE's and INSIST's to isc_time_formatISO8601L
|
|
||||||
and isc_time_formatISO8601Lms. [RT #46916]
|
|
||||||
|
|
||||||
4852. [bug] Handle strftime() failing in isc_time_formatISO8601ms.
|
|
||||||
Add REQUIRE's and INSIST's to isc_time_formattimestamp,
|
|
||||||
isc_time_formathttptimestamp, isc_time_formatISO8601,
|
|
||||||
isc_time_formatISO8601ms. [RT #46892]
|
|
||||||
|
|
||||||
4851. [port] Support using kyua as well as atf-run to run the unit
|
|
||||||
tests. [RT #46853]
|
|
||||||
|
|
||||||
4850. [bug] Named failed to restart with multiple added zones in
|
|
||||||
lmdb database. [RT #46889]
|
|
||||||
|
|
||||||
4849. [bug] Duplicate zones could appear in the .nzf file if
|
|
||||||
addzone failed. [RT #46435]
|
|
||||||
|
|
||||||
4848. [func] Zone types "primary" and "secondary" can now be used
|
|
||||||
as synonyms for "master" and "slave" in named.conf.
|
|
||||||
[RT #46713]
|
|
||||||
|
|
||||||
4847. [bug] dnssec-dnskey-kskonly was not being honored for
|
|
||||||
CDS and CDNSKEY. [RT #46755]
|
|
||||||
|
|
||||||
4846. [test] Adjust timing values in runtime system test. Address
|
|
||||||
named.pid removal races in runtime system test.
|
|
||||||
[RT #46800]
|
|
||||||
|
|
||||||
4845. [bug] Dig (non iOS) should exit on malformed names.
|
|
||||||
[RT #46806]
|
|
||||||
|
|
||||||
4844. [test] Address memory leaks in libatf-c. [RT #46798]
|
|
||||||
|
|
||||||
4843. [bug] dnssec-signzone free hashlist on exit. [RT #46791]
|
|
||||||
|
|
||||||
4842. [bug] Conditionally compile opensslecdsa_link.c to avoid
|
|
||||||
warnings about unused function. [RT #46790]
|
|
||||||
|
|
||||||
--- 9.12.0rc1 released ---
|
|
||||||
|
|
||||||
4841. [bug] Address -fsanitize=undefined warnings. [RT #46786]
|
|
||||||
|
|
||||||
4840. [test] Add tests to cover fallback to using ZSK on inactive
|
|
||||||
KSK. [RT #46787]
|
|
||||||
|
|
||||||
4839. [bug] zone.c:zone_sign was not properly determining
|
|
||||||
if there were active KSK and ZSK keys for
|
|
||||||
a algorithm when update-check-ksk is true
|
|
||||||
(default) leaving records unsigned with one or
|
|
||||||
more DNSKEY algorithms. [RT #46774]
|
|
||||||
|
|
||||||
4838. [bug] zone.c:add_sigs was not properly determining
|
|
||||||
if there were active KSK and ZSK keys for
|
|
||||||
a algorithm when update-check-ksk is true
|
|
||||||
(default) leaving records unsigned with one or
|
|
||||||
more DNSKEY algorithms. [RT #46754]
|
|
||||||
|
|
||||||
4837. [bug] dns_update_signatures{inc} (add_sigs) was not
|
|
||||||
properly determining if there were active KSK and
|
|
||||||
ZSK keys for a algorithm when update-check-ksk is
|
|
||||||
true (default) leaving records unsigned when there
|
|
||||||
were multiple DNSKEY algorithms for the zone.
|
|
||||||
[RT #46743]
|
|
||||||
|
|
||||||
4836. [bug] Zones created using "rndc addzone" could
|
|
||||||
temporarily fail to inherit an "allow-transfer"
|
|
||||||
ACL that had been configured in the options
|
|
||||||
statement. [RT #46603]
|
|
||||||
|
|
||||||
4835. [cleanup] Clean up and refactor LMDB-related code. [RT #46718]
|
|
||||||
|
|
||||||
4834. [port] Fix LMDB support on OpenBSD. [RT #46718]
|
|
||||||
|
|
||||||
4833. [bug] isc_event_free should check that the event is not
|
|
||||||
linked when called. [RT #46725]
|
|
||||||
|
|
||||||
4832. [bug] Events were not being removed from zone->rss_events.
|
|
||||||
[RT #46725]
|
|
||||||
|
|
||||||
4831. [bug] Convert the RRSIG expirytime to 64 bits for
|
|
||||||
comparisions in diff.c:resign. [RT #46710]
|
|
||||||
|
|
||||||
4830. [bug] Failure to configure ATF when requested did not cause
|
|
||||||
an error in top-level configure script. [RT #46655]
|
|
||||||
|
|
||||||
4829. [bug] isc_heap_delete did not zero the index value when
|
|
||||||
the heap was created with a callback to do that.
|
|
||||||
[RT #46709]
|
|
||||||
|
|
||||||
4828. [bug] Do not use thread-local storage for storing LMDB reader
|
|
||||||
locktable slots. [RT #46556]
|
|
||||||
|
|
||||||
4827. [misc] Add a precommit check script util/checklibs.sh
|
|
||||||
[RT #46215]
|
|
||||||
|
|
||||||
4826. [cleanup] Prevent potential build failures in bin/confgen/ and
|
|
||||||
bin/named/ when using parallel make. [RT #46648]
|
|
||||||
|
|
||||||
4825. [bug] Prevent a bogus "error during managed-keys processing
|
|
||||||
(no more)" warning from being logged. [RT #46645]
|
|
||||||
|
|
||||||
4824. [port] Add iOS hooks to dig. [RT #42011]
|
|
||||||
|
|
||||||
4823. [test] Refactor reclimit system test to improve its
|
|
||||||
reliability and speed. [RT #46632]
|
|
||||||
|
|
||||||
4822. [bug] Use resign_sooner in dns_db_setsigningtime. [RT #46473]
|
|
||||||
|
|
||||||
4821. [bug] When resigning ensure that the SOA's expire time is
|
|
||||||
always later that the resigning time of other records.
|
|
||||||
[RT #46473]
|
|
||||||
|
|
||||||
4820. [bug] dns_db_subtractrdataset should transfer the resigning
|
|
||||||
information to the new header. [RT #46473]
|
|
||||||
|
|
||||||
4819. [bug] Fully backout the transaction when adding a RRset
|
|
||||||
to the resigning / removal heaps fails. [RT #46473]
|
|
||||||
|
|
||||||
4818. [test] The logfileconfig system test could intermittently
|
|
||||||
report false negatives on some platforms. [RT #46615]
|
|
||||||
|
|
||||||
4817. [cleanup] Use DNS_NAME_INITABSOLUTE and DNS_NAME_INITNONABSOLUTE.
|
|
||||||
[RT #45433]
|
|
||||||
|
|
||||||
4816. [bug] Don't use a common array for storing EDNS options
|
|
||||||
in DiG as it could fill up. [RT #45611]
|
|
||||||
|
|
||||||
4815. [bug] rbt_test.c:insert_and_delete needed to call
|
|
||||||
dns_rbt_addnode instead of dns_rbt_addname. [RT #46553]
|
|
||||||
|
|
||||||
4814. [cleanup] Use AS_HELP_STRING for consistent help text. [RT #46521]
|
|
||||||
|
|
||||||
4813. [bug] Address potential read after free errors from
|
|
||||||
query_synthnodata, query_synthwildcard and
|
|
||||||
query_synthnxdomain. [RT #46547]
|
|
||||||
|
|
||||||
4812. [bug] Minor improvements to stability and consistency of code
|
|
||||||
handling managed keys. [RT #46468]
|
|
||||||
|
|
||||||
4811. [bug] Revert api changes to use <isc/buffer.h> inline
|
|
||||||
macros. Provide a alternative mechanism to turn
|
|
||||||
on the use of inline macros when building BIND.
|
|
||||||
[RT #46520]
|
|
||||||
|
|
||||||
4810. [test] The chain system test failed if the IPv6 interfaces
|
|
||||||
were not configured. [RT #46508]
|
|
||||||
|
|
||||||
--- 9.12.0b2 released ---
|
|
||||||
|
|
||||||
4809. [port] Check at configure time whether -latomic is needed
|
|
||||||
for stdatomic.h. [RT #46324]
|
|
||||||
|
|
||||||
4808. [bug] Properly test for zlib.h. [RT #46504]
|
|
||||||
|
|
||||||
4807. [cleanup] isc_rng_randombytes() returns a specified number of
|
|
||||||
bytes from the PRNG; this is now used instead of
|
|
||||||
calling isc_rng_random() multiple times. [RT #46230]
|
|
||||||
|
|
||||||
4806. [func] Log messages related to loading of zones are now
|
|
||||||
directed to the "zoneload" logging category.
|
|
||||||
[RT #41640]
|
|
||||||
|
|
||||||
4805. [bug] TCP4Active and TCP6Active weren't being updated
|
|
||||||
correctly. [RT #46454]
|
|
||||||
|
|
||||||
4804. [port] win32: access() does not work on directories as
|
|
||||||
required by POSIX. Supply a alternative in
|
|
||||||
isc_file_isdirwritable. [RT #46394]
|
|
||||||
|
|
||||||
4803. [placeholder]
|
|
||||||
|
|
||||||
4802. [test] Refactor mkeys system test to make it quicker and more
|
|
||||||
reliable. [RT #45293]
|
|
||||||
|
|
||||||
4801. [func] 'dnssec-lookaside auto;' and 'dnssec-lookaside .
|
|
||||||
trust-anchor dlv.isc.org;' now elicit warnings rather
|
|
||||||
than being fatal configuration errors. [RT #46410]
|
|
||||||
|
|
||||||
4800. [bug] When processing delzone, write one zone config per
|
|
||||||
line to the NZF. [RT #46323]
|
|
||||||
|
|
||||||
4799. [cleanup] Improve clarity of keytable unit tests. [RT #46407]
|
|
||||||
|
|
||||||
4798. [func] Keys specified in "managed-keys" statements
|
|
||||||
are tagged as "initializing" until they have been
|
|
||||||
updated by a key refresh query. If initialization
|
|
||||||
fails it will be visible from "rndc secroots".
|
|
||||||
[RT #46267]
|
|
||||||
|
|
||||||
4797. [func] Removed "isc-hmac-fixup", as the versions of BIND that
|
|
||||||
had the bug it worked around are long past end of
|
|
||||||
life. [RT #46411]
|
|
||||||
|
|
||||||
4796. [bug] Increase the maximum configurable TCP keepalive
|
|
||||||
timeout to 65535. [RT #44710]
|
|
||||||
|
|
||||||
4795. [func] A new statistics counter has been added to track
|
|
||||||
priming queries. [RT #46313]
|
|
||||||
|
|
||||||
4794. [func] "dnssec-checkds -s" specifies a file from which
|
|
||||||
to read a DS set rather than querying the parent.
|
|
||||||
[RT #44667]
|
|
||||||
|
|
||||||
4793. [bug] nsupdate -[46] could overflow the array of server
|
|
||||||
addresses. [RT #46402]
|
|
||||||
|
|
||||||
4792. [bug] Fix map file header correctness check. [RT #38418]
|
|
||||||
|
|
||||||
4791. [doc] Fixed outdated documentation about export libraries.
|
|
||||||
[RT #46341]
|
|
||||||
|
|
||||||
4790. [bug] nsupdate could trigger a require when sending a
|
|
||||||
update to the second address of the server.
|
|
||||||
[RT #45731]
|
|
||||||
|
|
||||||
4789. [cleanup] Check writability of new-zones-directory. [RT #46308]
|
|
||||||
|
|
||||||
4788. [cleanup] When using "update-policy local", log a warning
|
|
||||||
when an update matching the session key is received
|
|
||||||
from a remote host. [RT #46213]
|
|
||||||
|
|
||||||
4787. [cleanup] Turn nsec3param_salt_totext() into a public function,
|
|
||||||
dns_nsec3param_salttotext(), and add unit tests for it.
|
|
||||||
[RT #46289]
|
|
||||||
|
|
||||||
4786. [func] The "filter-aaaa-on-v4" and "filter-aaaa-on-v6"
|
|
||||||
options are no longer conditionally compiled.
|
|
||||||
[RT #46340]
|
|
||||||
|
|
||||||
4785. [func] The hmac-md5 algorithm is no longer recommended for
|
|
||||||
use with RNDC keys. The default in rndc-confgen
|
|
||||||
is now hmac-sha256. [RT #42272]
|
|
||||||
|
|
||||||
4784. [func] The use of dnssec-keygen to generate HMAC keys is
|
|
||||||
deprecated in favor of tsig-keygen. dnssec-keygen
|
|
||||||
will print a warning when used for this purpose.
|
|
||||||
All HMAC algorithms will be removed from
|
|
||||||
dnssec-keygen in a future release. [RT #42272]
|
|
||||||
|
|
||||||
4783. [test] dnssec: 'check that NOTIFY is sent at the end of
|
|
||||||
NSEC3 chain generation failed' required more time
|
|
||||||
on some machines for the IXFR to complete. [RT #46388]
|
|
||||||
|
|
||||||
4782. [test] dnssec: 'checking positive and negative validation
|
|
||||||
with negative trust anchors' required more time to
|
|
||||||
complete on some machines. [RT #46386]
|
|
||||||
|
|
||||||
4781. [maint] B.ROOT-SERVERS.NET is now 199.9.14.201. [RT #45889]
|
|
||||||
|
|
||||||
4780. [bug] When answering ANY queries, don't include the NS
|
|
||||||
RRset in the authority section if it was already
|
|
||||||
in the answer section. [RT #44543]
|
|
||||||
|
|
||||||
4779. [bug] Expire NTA at the start of the second. Don't update
|
|
||||||
the expiry value if the record has already expired
|
|
||||||
after a successful check. [RT #46368]
|
|
||||||
|
|
||||||
4778. [test] Improve synth-from-dnssec testing. [RT #46352]
|
|
||||||
|
|
||||||
4777. [cleanup] Removed a redundant call to configure_view_acl().
|
|
||||||
[RT #46369]
|
|
||||||
|
|
||||||
4776. [bug] Improve portability of ht_test. [RT #46333]
|
4776. [bug] Improve portability of ht_test. [RT #46333]
|
||||||
|
|
||||||
4775. [bug] Address Coverity warnings in ht_test.c and mem_test.c
|
4775. [bug] Address Coverity warnings in ht_test.c and mem_test.c
|
||||||
@@ -717,7 +116,7 @@
|
|||||||
- Removed DLV key from bind.keys
|
- Removed DLV key from bind.keys
|
||||||
- No longer use ISC DLV by default in delv
|
- No longer use ISC DLV by default in delv
|
||||||
- "dnssec-lookaside auto" and configuration of
|
- "dnssec-lookaside auto" and configuration of
|
||||||
"dnssec-lookaide" with dlv.isc.org as the trust
|
"dnssec-lookaide" with dlv.isc.org as trust
|
||||||
anchor are both now fatal errors.
|
anchor are both now fatal errors.
|
||||||
[RT #46155]
|
[RT #46155]
|
||||||
|
|
||||||
@@ -857,8 +256,8 @@
|
|||||||
4713. [func] Added support for the DNS Response Policy Service
|
4713. [func] Added support for the DNS Response Policy Service
|
||||||
(DNSRPS) API, which allows named to use an external
|
(DNSRPS) API, which allows named to use an external
|
||||||
response policy daemon when built with
|
response policy daemon when built with
|
||||||
"configure --enable-dnsrps". Thanks to Farsight
|
"configure --enable-dnsrps". Thanks to Vernon
|
||||||
Security. [RT #43376]
|
Schryver and Farsight Security. [RT #43376]
|
||||||
|
|
||||||
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
4712. [bug] "dig +domain" and "dig +search" didn't retain the
|
||||||
search domain when retrying with TCP. [RT #45547]
|
search domain when retrying with TCP. [RT #45547]
|
||||||
|
|||||||
-186
@@ -1,186 +0,0 @@
|
|||||||
BIND Source Access and Contributor Guidelines
|
|
||||||
|
|
||||||
Feb 22, 2018
|
|
||||||
|
|
||||||
Contents
|
|
||||||
|
|
||||||
1. Access to source code
|
|
||||||
2. Reporting bugs
|
|
||||||
3. Contributing code
|
|
||||||
|
|
||||||
Introduction
|
|
||||||
|
|
||||||
Thank you for using BIND!
|
|
||||||
|
|
||||||
BIND is open source software that implements the Domain Name System (DNS)
|
|
||||||
protocols for the Internet. It is a reference implementation of those
|
|
||||||
protocols, but it is also production-grade software, suitable for use in
|
|
||||||
high-volume and high-reliability applications. It is by far the most
|
|
||||||
widely used DNS software, providing a robust and stable platform on top of
|
|
||||||
which organizations can build distributed computing systems with the
|
|
||||||
knowledge that those systems are fully compliant with published DNS
|
|
||||||
standards.
|
|
||||||
|
|
||||||
BIND is and will always remain free and openly available. It can be used
|
|
||||||
and modified in any way by anyone.
|
|
||||||
|
|
||||||
BIND is maintained by the Internet Systems Consortium, a public-benefit
|
|
||||||
501(c)(3) nonprofit, using a "managed open source" approach: anyone can
|
|
||||||
see the source, but only ISC employees have commit access. Until recently,
|
|
||||||
the source could only be seen once ISC had published a release: read
|
|
||||||
access to the source repository was restricted just as commit access was.
|
|
||||||
That's now changing, with the opening of a public git mirror to the BIND
|
|
||||||
source tree (see below).
|
|
||||||
|
|
||||||
Access to source code
|
|
||||||
|
|
||||||
Public BIND releases are always available from the ISC FTP site.
|
|
||||||
|
|
||||||
A public-access GIT repository is also available at https://gitlab.isc.org
|
|
||||||
. This repository is a mirror, updated several times per day, of the
|
|
||||||
source repository maintained by ISC. It contains all the public release
|
|
||||||
branches; upcoming releases can be viewed in their current state at any
|
|
||||||
time. It does not contain development branches or unreviewed work in
|
|
||||||
progress. Commits which address security vulnerablilities are withheld
|
|
||||||
until after public disclosure.
|
|
||||||
|
|
||||||
You can browse the source online via https://gitlab.isc.org/isc-projects/
|
|
||||||
bind9
|
|
||||||
|
|
||||||
To clone the repository, use:
|
|
||||||
|
|
||||||
$ git clone https://gitlab.isc.org/isc-projects/bind9.git
|
|
||||||
|
|
||||||
Release branch names are of the form v9_X, where X represents the second
|
|
||||||
number in the BIND 9 version number. So, to check out the BIND 9.12
|
|
||||||
branch, use:
|
|
||||||
|
|
||||||
$ git checkout v9_12
|
|
||||||
|
|
||||||
Whenever a branch is ready for publication, a tag will be placed of the
|
|
||||||
form v9_X_Y. The 9.12.0 release, for instance, is tagged as v9_12_0.
|
|
||||||
|
|
||||||
The branch in which the next major release is being developed is called
|
|
||||||
master.
|
|
||||||
|
|
||||||
Reporting bugs
|
|
||||||
|
|
||||||
Reports of flaws in the BIND package, including software bugs, errors in
|
|
||||||
the documentation, missing files in the tarball, suggested changes or
|
|
||||||
requests for new features, etc, can be filed using https://gitlab.isc.org/
|
|
||||||
isc-projects/bind9/issues.
|
|
||||||
|
|
||||||
Due to a large ticket backlog, we are sometimes slow to respond,
|
|
||||||
especially if a bug is cosmetic or if a feature request is vague or low in
|
|
||||||
priority, but we will try at least to acknowledge legitimate bug reports
|
|
||||||
within a week.
|
|
||||||
|
|
||||||
ISC's ticketing system is publicly readable; however, you must have an
|
|
||||||
account to file a new issue. You can either register locally or use
|
|
||||||
credentials from an existing account at GitHub, GitLab, Google, Twitter,
|
|
||||||
or Facebook.
|
|
||||||
|
|
||||||
Reporting possible security issues
|
|
||||||
|
|
||||||
If you think you may be seeing a potential security vulnerability in BIND
|
|
||||||
(for example, a crash with REQUIRE, INSIST, or ASSERT failure), please
|
|
||||||
report it immediately by emailing to security-officer@isc.org. Plain-text
|
|
||||||
e-mail is not a secure choice for communications concerning undisclosed
|
|
||||||
security issues so please encrypt your communications to us if possible,
|
|
||||||
using the ISC Security Officer public key.
|
|
||||||
|
|
||||||
Do not discuss undisclosed security vulnerabilites on any public mailing
|
|
||||||
list. ISC has a long history of handling reported vulnerabilities promptly
|
|
||||||
and effectively and we respect and acknowledge responsible reporters.
|
|
||||||
|
|
||||||
ISC's Security Vulnerability Disclosure Policy is documented at https://
|
|
||||||
kb.isc.org/article/AA-00861/0.
|
|
||||||
|
|
||||||
If you have a crash, you may want to consult ?What to do if your BIND or
|
|
||||||
DHCP server has crashed.?
|
|
||||||
|
|
||||||
Contributing code
|
|
||||||
|
|
||||||
BIND is licensed under the Mozilla Public License 2.0. Earier versions
|
|
||||||
(BIND 9.10 and earlier) were licensed under the ISC License
|
|
||||||
|
|
||||||
ISC does not require an explicit copyright assignment for patch
|
|
||||||
contributions. However, by submitting a patch to ISC, you implicitly
|
|
||||||
certify that you are the author of the code, that you intend to reliquish
|
|
||||||
exclusive copyright, and that you grant permission to publish your work
|
|
||||||
under the open source license used for the BIND version(s) to which your
|
|
||||||
patch will be applied.
|
|
||||||
|
|
||||||
BIND code
|
|
||||||
|
|
||||||
Patches for BIND may be submitted directly via merge requests in ISC's
|
|
||||||
Gitlab source repository for BIND.
|
|
||||||
|
|
||||||
Patches can also be submitted as diffs against a specific version of BIND
|
|
||||||
-- preferably the current top of the master branch. Diffs may be generated
|
|
||||||
using either git format-patch or git diff.
|
|
||||||
|
|
||||||
Those wanting to write code for BIND may be interested in the developer
|
|
||||||
information page, which includes information about BIND design and coding
|
|
||||||
practices, including discussion of internal APIs and overall system
|
|
||||||
architecture. (This is a work in progress, and still quite preliminary.)
|
|
||||||
|
|
||||||
Every patch submitted will be reviewed by ISC engineers following our code
|
|
||||||
review process before it is merged.
|
|
||||||
|
|
||||||
It may take considerable time to review patch submissions, especially if
|
|
||||||
they don't meet ISC style and quality guidelines. If a patch is a good
|
|
||||||
idea, we can and will do additional work to bring it up to par, but if
|
|
||||||
we're busy with other work, it may take us a long time to get to it.
|
|
||||||
|
|
||||||
To ensure your patch is acted on as promptly as possible, please:
|
|
||||||
|
|
||||||
* Try to adhere to the BIND 9 coding style.
|
|
||||||
* Run make check to ensure your change hasn't caused any functional
|
|
||||||
regressions.
|
|
||||||
* Document your work, both in the patch itself and in the accompanying
|
|
||||||
email.
|
|
||||||
* In patches that make non-trivial functional changes, include system
|
|
||||||
tests if possible; when introducing or substantially altering a
|
|
||||||
library API, include unit tests. See Testing for more information.
|
|
||||||
|
|
||||||
Changes to configure
|
|
||||||
|
|
||||||
If you need to make changes to configure, you should not edit it directly;
|
|
||||||
instead, edit configure.in, then run autoconf. Similarly, instead of
|
|
||||||
editing config.h.in directly, edit configure.in and run autoheader.
|
|
||||||
|
|
||||||
When submitting a patch as a diff, it's fine to omit the configure diffs
|
|
||||||
to save space. Just send the configure.in diffs and we'll generate the new
|
|
||||||
configure during the review process.
|
|
||||||
|
|
||||||
Documentation
|
|
||||||
|
|
||||||
All functional changes should be documented. There are three types of
|
|
||||||
documentation in the BIND source tree:
|
|
||||||
|
|
||||||
* Man pages are kept alongside the source code for the commands they
|
|
||||||
document, in files ending in .docbook; for example, the named man page
|
|
||||||
is bin/named/named.docbook.
|
|
||||||
* The BIND 9 Administrator Reference Manual is mostly in doc/arm/
|
|
||||||
Bv9ARM-book.xml, plus a few other XML files that are included in it.
|
|
||||||
* API documentation is in the header file describing the API, in
|
|
||||||
Doxygen-formatted comments.
|
|
||||||
|
|
||||||
It is not necessary to edit any documentation files other than these; all
|
|
||||||
PDF, HTML, and nroff-format man page files will be updated automatically
|
|
||||||
from the docbook and XML files after merging.
|
|
||||||
|
|
||||||
Patches to improve existing documentation are also very welcome!
|
|
||||||
|
|
||||||
Tests
|
|
||||||
|
|
||||||
BIND is a large and complex project. We rely heavily on continuous
|
|
||||||
automated testing and cannot merge new code without adequate test
|
|
||||||
coverage. Please see the 'Testing' section of doc/dev/dev.md for more
|
|
||||||
information.
|
|
||||||
|
|
||||||
Thanks
|
|
||||||
|
|
||||||
Thank you for your interest in contributing to the ongoing development of
|
|
||||||
BIND.
|
|
||||||
-201
@@ -1,201 +0,0 @@
|
|||||||
<!--
|
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
-
|
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
|
||||||
## BIND Source Access and Contributor Guidelines
|
|
||||||
*Feb 22, 2018*
|
|
||||||
|
|
||||||
### Contents
|
|
||||||
|
|
||||||
1. [Access to source code](#access)
|
|
||||||
1. [Reporting bugs](#bugs)
|
|
||||||
1. [Contributing code](#contrib)
|
|
||||||
|
|
||||||
### Introduction
|
|
||||||
|
|
||||||
Thank you for using BIND!
|
|
||||||
|
|
||||||
BIND is open source software that implements the Domain Name System (DNS)
|
|
||||||
protocols for the Internet. It is a reference implementation of those
|
|
||||||
protocols, but it is also production-grade software, suitable for use in
|
|
||||||
high-volume and high-reliability applications. It is by far the most
|
|
||||||
widely used DNS software, providing a robust and stable platform on top of
|
|
||||||
which organizations can build distributed computing systems with the
|
|
||||||
knowledge that those systems are fully compliant with published DNS
|
|
||||||
standards.
|
|
||||||
|
|
||||||
BIND is and will always remain free and openly available. It can be
|
|
||||||
used and modified in any way by anyone.
|
|
||||||
|
|
||||||
BIND is maintained by the [Internet Systems Consortium](https://www.isc.org),
|
|
||||||
a public-benefit 501(c)(3) nonprofit, using a "managed open source" approach:
|
|
||||||
anyone can see the source, but only ISC employees have commit access.
|
|
||||||
Until recently, the source could only be seen once ISC had published
|
|
||||||
a release: read access to the source repository was restricted just
|
|
||||||
as commit access was. That's now changing, with the opening of a
|
|
||||||
public git mirror to the BIND source tree (see below).
|
|
||||||
|
|
||||||
### <a name="access"></a>Access to source code
|
|
||||||
|
|
||||||
Public BIND releases are always available from the
|
|
||||||
[ISC FTP site](ftp://ftp.isc.org/isc/bind9).
|
|
||||||
|
|
||||||
A public-access GIT repository is also available at
|
|
||||||
[https://gitlab.isc.org](https://gitlab.isc.org).
|
|
||||||
This repository is a mirror, updated several times per day, of the
|
|
||||||
source repository maintained by ISC. It contains all the public release
|
|
||||||
branches; upcoming releases can be viewed in their current state at any
|
|
||||||
time. It does *not* contain development branches or unreviewed work in
|
|
||||||
progress. Commits which address security vulnerablilities are withheld
|
|
||||||
until after public disclosure.
|
|
||||||
|
|
||||||
You can browse the source online via
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9)
|
|
||||||
|
|
||||||
To clone the repository, use:
|
|
||||||
|
|
||||||
> $ git clone https://gitlab.isc.org/isc-projects/bind9.git
|
|
||||||
|
|
||||||
Release branch names are of the form `v9_X`, where X represents the second
|
|
||||||
number in the BIND 9 version number. So, to check out the BIND 9.12
|
|
||||||
branch, use:
|
|
||||||
|
|
||||||
> $ git checkout v9_12
|
|
||||||
|
|
||||||
Whenever a branch is ready for publication, a tag will be placed of the
|
|
||||||
form `v9_X_Y`. The 9.12.0 release, for instance, is tagged as `v9_12_0`.
|
|
||||||
|
|
||||||
The branch in which the next major release is being developed is called
|
|
||||||
`master`.
|
|
||||||
|
|
||||||
### <a name="bugs"></a>Reporting bugs
|
|
||||||
|
|
||||||
Reports of flaws in the BIND package, including software bugs, errors
|
|
||||||
in the documentation, missing files in the tarball, suggested changes
|
|
||||||
or requests for new features, etc, can be filed using
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9/issues](https://gitlab.isc.org/isc-projects/bind9/issues).
|
|
||||||
|
|
||||||
Due to a large ticket backlog, we are sometimes slow to respond,
|
|
||||||
especially if a bug is cosmetic or if a feature request is vague or
|
|
||||||
low in priority, but we will try at least to acknowledge legitimate
|
|
||||||
bug reports within a week.
|
|
||||||
|
|
||||||
ISC's ticketing system is publicly readable; however, you must have
|
|
||||||
an account to file a new issue. You can either register locally or
|
|
||||||
use credentials from an existing account at GitHub, GitLab, Google,
|
|
||||||
Twitter, or Facebook.
|
|
||||||
|
|
||||||
### Reporting possible security issues
|
|
||||||
If you think you may be seeing a potential security vulnerability in BIND
|
|
||||||
(for example, a crash with REQUIRE, INSIST, or ASSERT failure), please
|
|
||||||
report it immediately by emailing to security-officer@isc.org. Plain-text
|
|
||||||
e-mail is not a secure choice for communications concerning undisclosed
|
|
||||||
security issues so please encrypt your communications to us if possible,
|
|
||||||
using the [ISC Security Officer public key](https://www.isc.org/downloads/software-support-policy/openpgp-key/).
|
|
||||||
|
|
||||||
Do not discuss undisclosed security vulnerabilites on any public mailing list.
|
|
||||||
ISC has a long history of handling reported vulnerabilities promptly and
|
|
||||||
effectively and we respect and acknowledge responsible reporters.
|
|
||||||
|
|
||||||
ISC's Security Vulnerability Disclosure Policy is documented at [https://kb.isc.org/article/AA-00861/0](https://kb.isc.org/article/AA-00861/0).
|
|
||||||
|
|
||||||
If you have a crash, you may want to consult
|
|
||||||
[‘What to do if your BIND or DHCP server has crashed.’](https://kb.isc.org/article/AA-00340/89/What-to-do-if-your-BIND-or-DHCP-server-has-crashed.html)
|
|
||||||
|
|
||||||
### <a name="bugs"></a>Contributing code
|
|
||||||
|
|
||||||
BIND is licensed under the
|
|
||||||
[Mozilla Public License 2.0](http://www.isc.org/downloads/software-support-policy/isc-license/).
|
|
||||||
Earier versions (BIND 9.10 and earlier) were licensed under the [ISC License](http://www.isc.org/downloads/software-support-policy/isc-license/)
|
|
||||||
|
|
||||||
ISC does not require an explicit copyright assignment for patch
|
|
||||||
contributions. However, by submitting a patch to ISC, you implicitly
|
|
||||||
certify that you are the author of the code, that you intend to reliquish
|
|
||||||
exclusive copyright, and that you grant permission to publish your work
|
|
||||||
under the open source license used for the BIND version(s) to which your
|
|
||||||
patch will be applied.
|
|
||||||
|
|
||||||
#### <a name="bind"></a>BIND code
|
|
||||||
|
|
||||||
Patches for BIND may be submitted directly via merge requests in
|
|
||||||
[ISC's Gitlab](https://gitlab.isc.org/isc-projects/bind9/) source
|
|
||||||
repository for BIND.
|
|
||||||
|
|
||||||
Patches can also be submitted as diffs against a specific version of
|
|
||||||
BIND -- preferably the current top of the `master` branch. Diffs may
|
|
||||||
be generated using either `git format-patch` or `git diff`.
|
|
||||||
|
|
||||||
Those wanting to write code for BIND may be interested in the
|
|
||||||
[developer information](doc/dev/dev.md) page, which includes information
|
|
||||||
about BIND design and coding practices, including discussion of internal
|
|
||||||
APIs and overall system architecture. (This is a work in progress, and
|
|
||||||
still quite preliminary.)
|
|
||||||
|
|
||||||
Every patch submitted will be reviewed by ISC engineers following our
|
|
||||||
[code review process](doc/dev/dev.md#reviews) before it is merged.
|
|
||||||
|
|
||||||
It may take considerable time to review patch submissions, especially if
|
|
||||||
they don't meet ISC style and quality guidelines. If a patch is a good
|
|
||||||
idea, we can and will do additional work to bring it up to par, but if
|
|
||||||
we're busy with other work, it may take us a long time to get to it.
|
|
||||||
|
|
||||||
To ensure your patch is acted on as promptly as possible, please:
|
|
||||||
|
|
||||||
* Try to adhere to the [BIND 9 coding style](doc/dev/style.md).
|
|
||||||
* Run `make` `check` to ensure your change hasn't caused any
|
|
||||||
functional regressions.
|
|
||||||
* Document your work, both in the patch itself and in the
|
|
||||||
accompanying email.
|
|
||||||
* In patches that make non-trivial functional changes, include system
|
|
||||||
tests if possible; when introducing or substantially altering a
|
|
||||||
library API, include unit tests. See [Testing](doc/dev/dev.md#testing)
|
|
||||||
for more information.
|
|
||||||
|
|
||||||
##### Changes to `configure`
|
|
||||||
|
|
||||||
If you need to make changes to `configure`, you should not edit it
|
|
||||||
directly; instead, edit `configure.in`, then run `autoconf`. Similarly,
|
|
||||||
instead of editing `config.h.in` directly, edit `configure.in` and run
|
|
||||||
`autoheader`.
|
|
||||||
|
|
||||||
When submitting a patch as a diff, it's fine to omit the `configure`
|
|
||||||
diffs to save space. Just send the `configure.in` diffs and we'll
|
|
||||||
generate the new `configure` during the review process.
|
|
||||||
|
|
||||||
##### Documentation
|
|
||||||
|
|
||||||
All functional changes should be documented. There are three types
|
|
||||||
of documentation in the BIND source tree:
|
|
||||||
|
|
||||||
* Man pages are kept alongside the source code for the commands
|
|
||||||
they document, in files ending in `.docbook`; for example, the
|
|
||||||
`named` man page is `bin/named/named.docbook`.
|
|
||||||
* The *BIND 9 Administrator Reference Manual* is mostly in
|
|
||||||
`doc/arm/Bv9ARM-book.xml`, plus a few other XML files that are included
|
|
||||||
in it.
|
|
||||||
* API documentation is in the header file describing the API, in
|
|
||||||
Doxygen-formatted comments.
|
|
||||||
|
|
||||||
It is not necessary to edit any documentation files other than these;
|
|
||||||
all PDF, HTML, and `nroff`-format man page files will be updated
|
|
||||||
automatically from the `docbook` and `XML` files after merging.
|
|
||||||
|
|
||||||
Patches to improve existing documentation are also very welcome!
|
|
||||||
|
|
||||||
##### Tests
|
|
||||||
|
|
||||||
BIND is a large and complex project. We rely heavily on continuous
|
|
||||||
automated testing and cannot merge new code without adequate test coverage.
|
|
||||||
Please see [the 'Testing' section of doc/dev/dev.md](doc/dev/dev.md#testing)
|
|
||||||
for more information.
|
|
||||||
|
|
||||||
#### Thanks
|
|
||||||
|
|
||||||
Thank you for your interest in contributing to the ongoing development
|
|
||||||
of BIND.
|
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
Copyright (C) 1996-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright (C) 1996-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -522,3 +522,4 @@ BIND 9.2.0
|
|||||||
DNSSEC implementation is still considered experimental. For detailed
|
DNSSEC implementation is still considered experimental. For detailed
|
||||||
information about the state of the DNSSEC implementation, see the file
|
information about the state of the DNSSEC implementation, see the file
|
||||||
doc/misc/dnssec.
|
doc/misc/dnssec.
|
||||||
|
|
||||||
|
|||||||
+1
-4
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
### Functional enhancements from prior major releases of BIND 9
|
### Functional enhancements from prior major releases of BIND 9
|
||||||
|
|
||||||
|
|||||||
+8
-21
@@ -1,16 +1,12 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 1998-2002, 2004-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
top_builddir = @top_builddir@
|
|
||||||
|
|
||||||
VERSION=@BIND9_VERSION@
|
VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@@ -22,7 +18,7 @@ MANPAGES = isc-config.sh.1
|
|||||||
|
|
||||||
HTMLPAGES = isc-config.sh.html
|
HTMLPAGES = isc-config.sh.html
|
||||||
|
|
||||||
MANOBJS = README HISTORY OPTIONS CONTRIBUTING ${MANPAGES} ${HTMLPAGES}
|
MANOBJS = README HISTORY OPTIONS ${MANPAGES} ${HTMLPAGES}
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
@@ -74,7 +70,7 @@ tags:
|
|||||||
find lib bin -name "*.[ch]" -print | @ETAGS@ -
|
find lib bin -name "*.[ch]" -print | @ETAGS@ -
|
||||||
|
|
||||||
test check:
|
test check:
|
||||||
@if test -n "`${PERL} ${top_srcdir}/bin/tests/system/testsock.pl 2>/dev/null || echo fail`"; then \
|
@if test -n "`${PERL} ${top_srcdir}/bin/tests/system/testsock.pl 2>&- || echo fail`"; then \
|
||||||
echo I: NOTE: The tests were not run because they require that; \
|
echo I: NOTE: The tests were not run because they require that; \
|
||||||
echo I: the IP addresses 10.53.0.1 through 10.53.0.8 are configured; \
|
echo I: the IP addresses 10.53.0.1 through 10.53.0.8 are configured; \
|
||||||
echo I: as alias addresses on the loopback interface. Please run; \
|
echo I: as alias addresses on the loopback interface. Please run; \
|
||||||
@@ -90,31 +86,22 @@ force-test: test-force
|
|||||||
test-force:
|
test-force:
|
||||||
status=0; \
|
status=0; \
|
||||||
(cd bin/tests && ${MAKE} ${MAKEDEFS} test) || status=1; \
|
(cd bin/tests && ${MAKE} ${MAKEDEFS} test) || status=1; \
|
||||||
(test -f ${top_builddir}/unit/unittest.sh && \
|
(test -f unit/unittest.sh && $(SHELL) unit/unittest.sh) || status=1; \
|
||||||
$(SHELL) ${top_builddir}/unit/unittest.sh) || status=1; \
|
|
||||||
exit $$status
|
exit $$status
|
||||||
|
|
||||||
README: README.md
|
README: README.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html README.md | \
|
${PANDOC} --email-obfuscation=none -s -t html README.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html > $@
|
||||||
sed -e '$${/^$$/d;}' > $@
|
|
||||||
|
|
||||||
HISTORY: HISTORY.md
|
HISTORY: HISTORY.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html HISTORY.md | \
|
${PANDOC} --email-obfuscation=none -s -t html HISTORY.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html > $@
|
||||||
sed -e '$${/^$$/d;}' > $@
|
|
||||||
|
|
||||||
OPTIONS: OPTIONS.md
|
OPTIONS: OPTIONS.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html OPTIONS.md | \
|
${PANDOC} --email-obfuscation=none -s -t html OPTIONS.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html > $@
|
||||||
sed -e '$${/^$$/d;}' > $@
|
|
||||||
|
|
||||||
CONTRIBUTING: CONTRIBUTING.md
|
|
||||||
${PANDOC} --email-obfuscation=none -s -t html CONTRIBUTING.md | \
|
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
|
||||||
sed -e '$${/^$$/d;}' > $@
|
|
||||||
|
|
||||||
unit::
|
unit::
|
||||||
sh ${top_builddir}/unit/unittest.sh
|
sh ${top_srcdir}/unit/unittest.sh
|
||||||
|
|
||||||
clean::
|
clean::
|
||||||
|
|||||||
@@ -19,8 +19,7 @@ Setting Description
|
|||||||
named-checkzone
|
named-checkzone
|
||||||
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
||||||
rather than ${localstatedir}/run/named/
|
rather than ${localstatedir}/run/named/
|
||||||
Disable the use of inline functions to implement
|
Increase the maximum number of configurable
|
||||||
-DISC_BUFFER_USEINLINE=0 the isc_buffer API: this reduces performance but
|
-DNS_RPZ_MAX_ZONES=64 response policy zones from 32 to 64; this is the
|
||||||
may be useful when debugging
|
highest possible setting
|
||||||
-DISC_HEAP_CHECK Test heap consistency after every heap
|
|
||||||
operation; used when debugging
|
|
||||||
|
|||||||
+2
-6
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
Setting the `STD_CDEFINES` environment variable before running `configure`
|
Setting the `STD_CDEFINES` environment variable before running `configure`
|
||||||
can be used to enable certain compile-time options that are not explicitly
|
can be used to enable certain compile-time options that are not explicitly
|
||||||
@@ -23,5 +20,4 @@ Some of these settings are:
|
|||||||
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
||||||
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
||||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||||
|`-DISC_BUFFER_USEINLINE=0`|Disable the use of inline functions to implement the `isc_buffer` API: this reduces performance but may be useful when debugging |
|
|`-DNS_RPZ_MAX_ZONES=64`|Increase the maximum number of configurable response policy zones from 32 to 64; this is the highest possible setting|
|
||||||
|`-DISC_HEAP_CHECK`|Test heap consistency after every heap operation; used when debugging|
|
|
||||||
|
|||||||
@@ -5,14 +5,13 @@ Contents
|
|||||||
1. Introduction
|
1. Introduction
|
||||||
2. Reporting bugs and getting help
|
2. Reporting bugs and getting help
|
||||||
3. Contributing to BIND
|
3. Contributing to BIND
|
||||||
4. BIND 9.13 features
|
4. BIND 9.12 features
|
||||||
5. Building BIND
|
5. Building BIND
|
||||||
6. macOS
|
6. Compile-time options
|
||||||
7. Compile-time options
|
7. Automated testing
|
||||||
8. Automated testing
|
8. Documentation
|
||||||
9. Documentation
|
9. Change log
|
||||||
10. Change log
|
10. Acknowledgments
|
||||||
11. Acknowledgments
|
|
||||||
|
|
||||||
Introduction
|
Introduction
|
||||||
|
|
||||||
@@ -50,21 +49,19 @@ bind9/releasenotes
|
|||||||
|
|
||||||
Reporting bugs and getting help
|
Reporting bugs and getting help
|
||||||
|
|
||||||
To report non-security-sensitive bugs or request new features, you may
|
Please report assertion failure errors and suspected security issues to
|
||||||
open an Issue in the BIND 9 project on the ISC GitLab server at https://
|
security-officer@isc.org.
|
||||||
gitlab.isc.org/isc-projects/bind9.
|
|
||||||
|
|
||||||
Please note that, unless you explicitly mark the newly created Issue as
|
General bug reports can be sent to bind9-bugs@isc.org.
|
||||||
"confidential", it will be publicly readable. Please do not include any
|
|
||||||
information in bug reports that you consider to be confidential unless the
|
|
||||||
issue has been marked as such. In particular, if submitting the contents
|
|
||||||
of your configuration file in a non-confidential Issue, it is advisable to
|
|
||||||
obscure key secrets: this can be done automatically by using
|
|
||||||
named-checkconf -px.
|
|
||||||
|
|
||||||
If the bug you are reporting is a potential security issue, such as an
|
Feature requests can be sent to bind-suggest@isc.org.
|
||||||
assertion failure or other crash in named, please do NOT use GitLab to
|
|
||||||
report it. Instead, please send mail to security-officer@isc.org.
|
Please note that, while tickets submitted to ISC's ticketing system are
|
||||||
|
not initially publicly readable by default, they can be made publicly
|
||||||
|
acessible afterward. Please do not include information in bug reports that
|
||||||
|
you consider to be confidential. In particular, when sending the contents
|
||||||
|
of your configuration file, it is advisable to obscure key secrets: this
|
||||||
|
can be done automatically by using named-checkconf -px.
|
||||||
|
|
||||||
Professional support and training for BIND are available from ISC at
|
Professional support and training for BIND are available from ISC at
|
||||||
https://www.isc.org/support.
|
https://www.isc.org/support.
|
||||||
@@ -79,31 +76,48 @@ mailman/listinfo/bind-workers.
|
|||||||
Contributing to BIND
|
Contributing to BIND
|
||||||
|
|
||||||
ISC maintains a public git repository for BIND; details can be found at
|
ISC maintains a public git repository for BIND; details can be found at
|
||||||
http://www.isc.org/git/.
|
http://www.isc.org/git/, and also on Github at https://github.com/
|
||||||
|
isc-projects.
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files: -
|
Information for BIND contributors can be found in the following files: -
|
||||||
General information: CONTRIBUTING.md - BIND 9 code style: doc/dev/style.md
|
General information: doc/dev/contrib.md - BIND 9 code style: doc/dev/
|
||||||
- BIND architecture and developer guide: doc/dev/dev.md
|
style.md - BIND architecture and developer guide: doc/dev/dev.md
|
||||||
|
|
||||||
Patches for BIND may be submitted as Merge Requests in the ISC GitLab
|
Patches for BIND may be submitted either as Github pull requests or via
|
||||||
server at at https://gitlab.isc.org/isc-projects/bind9/merge_requests.
|
email. When submitting a patch via email, please prepend the subject
|
||||||
|
header with "[PATCH]" so it will be easier for us to find. If your patch
|
||||||
|
introduces a new feature in BIND, please submit it to bind-suggest@isc.org
|
||||||
|
; if it fixes a bug, please submit it to bind9-bugs@isc.org.
|
||||||
|
|
||||||
By default, external contributors don't have ability to fork BIND in the
|
BIND 9.12 features
|
||||||
GitLab server, but if you wish to contribute code to BIND, you may request
|
|
||||||
permission to do so. Thereafter, you can create git branches and directly
|
|
||||||
submit requests that they be reviewed and merged.
|
|
||||||
|
|
||||||
If you prefer, you may also submit code by opening a GitLab Issue and
|
BIND 9.12.0 is the newest development branch of BIND 9. It includes a
|
||||||
including your patch as an attachment, preferably generated by git
|
number of changes from BIND 9.11 and earlier releases. New features
|
||||||
format-patch.
|
|
||||||
|
|
||||||
BIND 9.13 features
|
|
||||||
|
|
||||||
BIND 9.13.0 is the newest development branch of BIND 9. It includes a
|
|
||||||
number of changes from BIND 9.12 and earlier releases. New features
|
|
||||||
include:
|
include:
|
||||||
|
|
||||||
* TBD
|
* named and related libraries have been substantially refactored for
|
||||||
|
improved query performance -- particularly on delegation heavy zones
|
||||||
|
-- and for improved readability, maintainability, and testability.
|
||||||
|
* Code implementing the name server query processing logic has been
|
||||||
|
moved into a new libns library, for easier testing and use in tools
|
||||||
|
other than named.
|
||||||
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
|
NXDOMAIN responses.
|
||||||
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
|
* Setting 'max-journal-size default' now limits the size of journal
|
||||||
|
files to twice the size of the zone.
|
||||||
|
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
||||||
|
message.
|
||||||
|
* dnstap output files can now be configured to roll automatically when
|
||||||
|
reaching a given size.
|
||||||
|
* Log file timestamps can now also be formatted in ISO 8601 (local) or
|
||||||
|
ISO 8601 (UTC) formats.
|
||||||
|
* Logging channels and dnstap output files can now be configured to use
|
||||||
|
a timestamp as the suffix when rolling to a new file.
|
||||||
|
* 'named-checkconf -l' lists zones found in named.conf.
|
||||||
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
|
data for zones added by rndc addzone is stored
|
||||||
|
|
||||||
Building BIND
|
Building BIND
|
||||||
|
|
||||||
@@ -113,8 +127,8 @@ on many versions of Linux and UNIX, including RedHat, Fedora, Debian,
|
|||||||
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
Ubuntu, SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris,
|
||||||
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
HP-UX, AIX, SCO OpenServer, and OpenWRT.
|
||||||
|
|
||||||
BIND is also available for Windows 2008 and higher. See win32utils/
|
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||||
readme1st.txt for details on building for Windows systems.
|
win32utils/readme1st.txt for details on building for Windows systems.
|
||||||
|
|
||||||
To build on a UNIX or Linux system, use:
|
To build on a UNIX or Linux system, use:
|
||||||
|
|
||||||
@@ -147,14 +161,6 @@ BUILD_CPPFLAGS
|
|||||||
BUILD_LDFLAGS
|
BUILD_LDFLAGS
|
||||||
BUILD_LIBS
|
BUILD_LIBS
|
||||||
|
|
||||||
macOS
|
|
||||||
|
|
||||||
Building on macOS assumes that the "Command Tools for Xcode" is installed.
|
|
||||||
This can be downloaded from https://developer.apple.com/download/more/ or
|
|
||||||
if you have Xcode already installed you can run "xcode-select --install".
|
|
||||||
This will add /usr/include to the system and install the compiler and
|
|
||||||
other tools so that they can be easily found.
|
|
||||||
|
|
||||||
Compile-time options
|
Compile-time options
|
||||||
|
|
||||||
To see a full list of configuration options, run configure --help.
|
To see a full list of configuration options, run configure --help.
|
||||||
@@ -332,3 +338,4 @@ Acknowledgments
|
|||||||
(eay@cryptsoft.com)
|
(eay@cryptsoft.com)
|
||||||
* This product includes software written by Tim Hudson
|
* This product includes software written by Tim Hudson
|
||||||
(tjh@cryptsoft.com)
|
(tjh@cryptsoft.com)
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
# BIND 9
|
# BIND 9
|
||||||
|
|
||||||
@@ -15,9 +12,8 @@
|
|||||||
1. [Introduction](#intro)
|
1. [Introduction](#intro)
|
||||||
1. [Reporting bugs and getting help](#help)
|
1. [Reporting bugs and getting help](#help)
|
||||||
1. [Contributing to BIND](#contrib)
|
1. [Contributing to BIND](#contrib)
|
||||||
1. [BIND 9.13 features](#features)
|
1. [BIND 9.12 features](#features)
|
||||||
1. [Building BIND](#build)
|
1. [Building BIND](#build)
|
||||||
1. [macOS](#macos)
|
|
||||||
1. [Compile-time options](#opts)
|
1. [Compile-time options](#opts)
|
||||||
1. [Automated testing](#testing)
|
1. [Automated testing](#testing)
|
||||||
1. [Documentation](#doc)
|
1. [Documentation](#doc)
|
||||||
@@ -61,24 +57,22 @@ For up-to-date release notes and errata, see
|
|||||||
|
|
||||||
### <a name="help"/> Reporting bugs and getting help
|
### <a name="help"/> Reporting bugs and getting help
|
||||||
|
|
||||||
To report non-security-sensitive bugs or request new features, you may
|
Please report assertion failure errors and suspected security issues to
|
||||||
open an Issue in the BIND 9 project on the
|
|
||||||
[ISC GitLab server](https://gitlab.isc.org) at
|
|
||||||
[https://gitlab.isc.org/isc-projects/bind9](https://gitlab.isc.org/isc-projects/bind9).
|
|
||||||
|
|
||||||
Please note that, unless you explicitly mark the newly created Issue as
|
|
||||||
"confidential", it will be publicly readable. Please do not include any
|
|
||||||
information in bug reports that you consider to be confidential unless
|
|
||||||
the issue has been marked as such. In particular, if submitting the
|
|
||||||
contents of your configuration file in a non-confidential Issue, it is
|
|
||||||
advisable to obscure key secrets: this can be done automatically by
|
|
||||||
using `named-checkconf -px`.
|
|
||||||
|
|
||||||
If the bug you are reporting is a potential security issue, such as an
|
|
||||||
assertion failure or other crash in `named`, please do *NOT* use GitLab to
|
|
||||||
report it. Instead, please send mail to
|
|
||||||
[security-officer@isc.org](mailto:security-officer@isc.org).
|
[security-officer@isc.org](mailto:security-officer@isc.org).
|
||||||
|
|
||||||
|
General bug reports can be sent to
|
||||||
|
[bind9-bugs@isc.org](mailto:bind9-bugs@isc.org).
|
||||||
|
|
||||||
|
Feature requests can be sent to
|
||||||
|
[bind-suggest@isc.org](mailto:bind-suggest@isc.org).
|
||||||
|
|
||||||
|
Please note that, while tickets submitted to ISC's ticketing system
|
||||||
|
are not initially publicly readable by default, they can be made publicly
|
||||||
|
acessible afterward. Please do not include information in bug reports that
|
||||||
|
you consider to be confidential. In particular, when sending the contents of
|
||||||
|
your configuration file, it is advisable to obscure key secrets: this can
|
||||||
|
be done automatically by using `named-checkconf -px`.
|
||||||
|
|
||||||
Professional support and training for BIND are available from
|
Professional support and training for BIND are available from
|
||||||
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
ISC at [https://www.isc.org/support](https://www.isc.org/support).
|
||||||
|
|
||||||
@@ -92,35 +86,50 @@ may also want to join the __BIND Workers__ mailing list, at
|
|||||||
### <a name="contrib"/> Contributing to BIND
|
### <a name="contrib"/> Contributing to BIND
|
||||||
|
|
||||||
ISC maintains a public git repository for BIND; details can be found
|
ISC maintains a public git repository for BIND; details can be found
|
||||||
at [http://www.isc.org/git/](http://www.isc.org/git/).
|
at [http://www.isc.org/git/](http://www.isc.org/git/), and also on Github
|
||||||
|
at [https://github.com/isc-projects](https://github.com/isc-projects).
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files:
|
Information for BIND contributors can be found in the following files:
|
||||||
- General information: [CONTRIBUTING.md](CONTRIBUTING)
|
- General information: [doc/dev/contrib.md](doc/dev/contrib.md)
|
||||||
- BIND 9 code style: [doc/dev/style.md](doc/dev/style.md)
|
- BIND 9 code style: [doc/dev/style.md](doc/dev/style.md)
|
||||||
- BIND architecture and developer guide: [doc/dev/dev.md](doc/dev/dev.md)
|
- BIND architecture and developer guide: [doc/dev/dev.md](doc/dev/dev.md)
|
||||||
|
|
||||||
Patches for BIND may be submitted as
|
Patches for BIND may be submitted either as Github pull requests
|
||||||
[Merge Requests](https://gitlab.isc.org/isc-projects/bind9/merge_requests)
|
or via email. When submitting a patch via email, please prepend the
|
||||||
in the [ISC GitLab server](https://gitlab.isc.org) at
|
subject header with "`[PATCH]`" so it will be easier for us to find.
|
||||||
at [https://gitlab.isc.org/isc-projects/bind9/merge_requests](https://gitlab.isc.org/isc-projects/bind9/merge_requests).
|
If your patch introduces a new feature in BIND, please submit it to
|
||||||
|
[bind-suggest@isc.org](mailto:bind-suggest@isc.org); if it fixes a bug,
|
||||||
|
please submit it to [bind9-bugs@isc.org](mailto:bind9-bugs@isc.org).
|
||||||
|
|
||||||
By default, external contributors don't have ability to fork BIND in the
|
### <a name="features"/> BIND 9.12 features
|
||||||
GitLab server, but if you wish to contribute code to BIND, you may request
|
|
||||||
permission to do so. Thereafter, you can create git branches and directly
|
|
||||||
submit requests that they be reviewed and merged.
|
|
||||||
|
|
||||||
If you prefer, you may also submit code by opening a
|
BIND 9.12.0 is the newest development branch of BIND 9. It includes a
|
||||||
[GitLab Issue](https://gitlab.isc.org/isc-projects/bind9/issues) and
|
number of changes from BIND 9.11 and earlier releases. New features
|
||||||
including your patch as an attachment, preferably generated by
|
|
||||||
`git format-patch`.
|
|
||||||
|
|
||||||
### <a name="features"/> BIND 9.13 features
|
|
||||||
|
|
||||||
BIND 9.13.0 is the newest development branch of BIND 9. It includes a
|
|
||||||
number of changes from BIND 9.12 and earlier releases. New features
|
|
||||||
include:
|
include:
|
||||||
|
|
||||||
* TBD
|
* `named` and related libraries have been substantially refactored for
|
||||||
|
improved query performance -- particularly on delegation heavy zones --
|
||||||
|
and for improved readability, maintainability, and testability.
|
||||||
|
* Code implementing the name server query processing logic has been moved
|
||||||
|
into a new `libns` library, for easier testing and use in tools other
|
||||||
|
than `named`.
|
||||||
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
|
NXDOMAIN responses.
|
||||||
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
|
* Setting `'max-journal-size default'` now limits the size of journal files
|
||||||
|
to twice the size of the zone.
|
||||||
|
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
||||||
|
DNS message.
|
||||||
|
* `dnstap` output files can now be configured to roll automatically when
|
||||||
|
reaching a given size.
|
||||||
|
* Log file timestamps can now also be formatted in ISO 8601 (local) or ISO
|
||||||
|
8601 (UTC) formats.
|
||||||
|
* Logging channels and `dnstap` output files can now be configured to use a
|
||||||
|
timestamp as the suffix when rolling to a new file.
|
||||||
|
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||||
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
|
data for zones added by rndc addzone is stored
|
||||||
|
|
||||||
### <a name="build"/> Building BIND
|
### <a name="build"/> Building BIND
|
||||||
|
|
||||||
@@ -130,9 +139,8 @@ many versions of Linux and UNIX, including RedHat, Fedora, Debian, Ubuntu,
|
|||||||
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
SuSE, Slackware, FreeBSD, NetBSD, OpenBSD, Mac OS X, Solaris, HP-UX, AIX,
|
||||||
SCO OpenServer, and OpenWRT.
|
SCO OpenServer, and OpenWRT.
|
||||||
|
|
||||||
BIND is also available for Windows 2008 and higher. See
|
BIND is also available for Windows XP, 2003, 2008, and higher. See
|
||||||
`win32utils/readme1st.txt` for details on building for Windows
|
`win32utils/readme1st.txt` for details on building for Windows systems.
|
||||||
systems.
|
|
||||||
|
|
||||||
To build on a UNIX or Linux system, use:
|
To build on a UNIX or Linux system, use:
|
||||||
|
|
||||||
@@ -158,15 +166,6 @@ affect compilation:
|
|||||||
|`BUILD_LDFLAGS`||
|
|`BUILD_LDFLAGS`||
|
||||||
|`BUILD_LIBS`||
|
|`BUILD_LIBS`||
|
||||||
|
|
||||||
#### <a name="macos"> macOS
|
|
||||||
|
|
||||||
Building on macOS assumes that the "Command Tools for Xcode" is installed.
|
|
||||||
This can be downloaded from https://developer.apple.com/download/more/
|
|
||||||
or if you have Xcode already installed you can run "xcode-select --install".
|
|
||||||
This will add /usr/include to the system and install the compiler and other
|
|
||||||
tools so that they can be easily found.
|
|
||||||
|
|
||||||
|
|
||||||
#### <a name="opts"/> Compile-time options
|
#### <a name="opts"/> Compile-time options
|
||||||
|
|
||||||
To see a full list of configuration options, run `configure --help`.
|
To see a full list of configuration options, run `configure --help`.
|
||||||
|
|||||||
+3
-4
@@ -1,14 +1,13 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 1999-2005, 2007, 2008, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: acconfig.h,v 1.53 2008/12/01 23:47:44 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
/***
|
/***
|
||||||
|
|||||||
+1
-4
@@ -1,13 +1,10 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
#
|
#
|
||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
# Run this script after modifying configure.in to generate configure
|
# Run this script after modifying configure.in to generate configure
|
||||||
autoreconf -i
|
autoreconf -i
|
||||||
|
|||||||
+5
-6
@@ -1,18 +1,17 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 1998-2001, 2004, 2007, 2009, 2012-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
# $Id: Makefile.in,v 1.29 2009/10/05 12:07:08 fdupont Exp $
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
SUBDIRS = named rndc dig delv dnssec tools nsupdate check confgen \
|
SUBDIRS = named rndc dig delv dnssec tools tests nsupdate \
|
||||||
@NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@
|
||||||
TARGETS =
|
TARGETS =
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
@BIND9_MAKE_RULES@
|
||||||
|
|||||||
@@ -1,11 +1,8 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2000-2007, 2009, 2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
@@ -18,7 +15,7 @@ VERSION=@BIND9_VERSION@
|
|||||||
CINCLUDES = ${NS_INCLUDES} ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
CINCLUDES = ${NS_INCLUDES} ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
${ISC_INCLUDES} @DST_OPENSSL_INC@
|
${ISC_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
|
||||||
CDEFINES = -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
CDEFINES = @CRYPTO@ -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||||
|
|||||||
+20
-19
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2002, 2004-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: check-tool.c,v 1.44 2011/12/22 07:32:39 each Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
@@ -98,17 +96,18 @@ isc_boolean_t docheckmx = ISC_FALSE;
|
|||||||
isc_boolean_t dochecksrv = ISC_FALSE;
|
isc_boolean_t dochecksrv = ISC_FALSE;
|
||||||
isc_boolean_t docheckns = ISC_FALSE;
|
isc_boolean_t docheckns = ISC_FALSE;
|
||||||
#endif
|
#endif
|
||||||
dns_zoneopt_t zone_options = DNS_ZONEOPT_CHECKNS |
|
unsigned int zone_options = DNS_ZONEOPT_CHECKNS |
|
||||||
DNS_ZONEOPT_CHECKMX |
|
DNS_ZONEOPT_CHECKMX |
|
||||||
DNS_ZONEOPT_MANYERRORS |
|
DNS_ZONEOPT_MANYERRORS |
|
||||||
DNS_ZONEOPT_CHECKNAMES |
|
DNS_ZONEOPT_CHECKNAMES |
|
||||||
DNS_ZONEOPT_CHECKINTEGRITY |
|
DNS_ZONEOPT_CHECKINTEGRITY |
|
||||||
#if CHECK_SIBLING
|
#if CHECK_SIBLING
|
||||||
DNS_ZONEOPT_CHECKSIBLING |
|
DNS_ZONEOPT_CHECKSIBLING |
|
||||||
#endif
|
#endif
|
||||||
DNS_ZONEOPT_CHECKWILDCARD |
|
DNS_ZONEOPT_CHECKWILDCARD |
|
||||||
DNS_ZONEOPT_WARNMXCNAME |
|
DNS_ZONEOPT_WARNMXCNAME |
|
||||||
DNS_ZONEOPT_WARNSRVCNAME;
|
DNS_ZONEOPT_WARNSRVCNAME;
|
||||||
|
unsigned int zone_options2 = 0;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* This needs to match the list in bin/named/log.c.
|
* This needs to match the list in bin/named/log.c.
|
||||||
@@ -588,7 +587,8 @@ check_ttls(dns_zone_t *zone, dns_ttl_t maxttl) {
|
|||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_fixedname_t fname;
|
dns_fixedname_t fname;
|
||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|
||||||
CHECK(dns_zone_getdb(zone, &db));
|
CHECK(dns_zone_getdb(zone, &db));
|
||||||
@@ -683,12 +683,12 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
|
|
||||||
isc_buffer_constinit(&buffer, zonename, strlen(zonename));
|
isc_buffer_constinit(&buffer, zonename, strlen(zonename));
|
||||||
isc_buffer_add(&buffer, strlen(zonename));
|
isc_buffer_add(&buffer, strlen(zonename));
|
||||||
origin = dns_fixedname_initname(&fixorigin);
|
dns_fixedname_init(&fixorigin);
|
||||||
|
origin = dns_fixedname_name(&fixorigin);
|
||||||
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
CHECK(dns_zone_setorigin(zone, origin));
|
||||||
CHECK(dns_zone_setdbtype(zone, 1, (const char * const *) dbtype));
|
CHECK(dns_zone_setdbtype(zone, 1, (const char * const *) dbtype));
|
||||||
CHECK(dns_zone_setfile(zone, filename, fileformat,
|
CHECK(dns_zone_setfile2(zone, filename, fileformat));
|
||||||
&dns_master_style_default));
|
|
||||||
if (journal != NULL)
|
if (journal != NULL)
|
||||||
CHECK(dns_zone_setjournal(zone, journal));
|
CHECK(dns_zone_setjournal(zone, journal));
|
||||||
|
|
||||||
@@ -698,6 +698,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
|
|
||||||
dns_zone_setclass(zone, rdclass);
|
dns_zone_setclass(zone, rdclass);
|
||||||
dns_zone_setoption(zone, zone_options, ISC_TRUE);
|
dns_zone_setoption(zone, zone_options, ISC_TRUE);
|
||||||
|
dns_zone_setoption2(zone, zone_options2, ISC_TRUE);
|
||||||
dns_zone_setoption(zone, DNS_ZONEOPT_NOMERGE, nomerge);
|
dns_zone_setoption(zone, DNS_ZONEOPT_NOMERGE, nomerge);
|
||||||
|
|
||||||
dns_zone_setmaxttl(zone, maxttl);
|
dns_zone_setmaxttl(zone, maxttl);
|
||||||
@@ -760,8 +761,8 @@ dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_zone_dumptostream(zone, output, fileformat, style,
|
result = dns_zone_dumptostream3(zone, output, fileformat, style,
|
||||||
rawversion);
|
rawversion);
|
||||||
if (output != stdout)
|
if (output != stdout)
|
||||||
(void)isc_stdio_close(output);
|
(void)isc_stdio_close(output);
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2002, 2004, 2005, 2007, 2010, 2011, 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: check-tool.h,v 1.18 2011/12/09 23:47:02 tbox Exp $ */
|
||||||
|
|
||||||
#ifndef CHECK_TOOL_H
|
#ifndef CHECK_TOOL_H
|
||||||
#define CHECK_TOOL_H
|
#define CHECK_TOOL_H
|
||||||
@@ -21,7 +19,6 @@
|
|||||||
|
|
||||||
#include <dns/masterdump.h>
|
#include <dns/masterdump.h>
|
||||||
#include <dns/types.h>
|
#include <dns/types.h>
|
||||||
#include <dns/zone.h>
|
|
||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
@@ -49,7 +46,8 @@ extern isc_boolean_t nomerge;
|
|||||||
extern isc_boolean_t docheckmx;
|
extern isc_boolean_t docheckmx;
|
||||||
extern isc_boolean_t docheckns;
|
extern isc_boolean_t docheckns;
|
||||||
extern isc_boolean_t dochecksrv;
|
extern isc_boolean_t dochecksrv;
|
||||||
extern dns_zoneopt_t zone_options;
|
extern unsigned int zone_options;
|
||||||
|
extern unsigned int zone_options2;
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
ISC_LANG_ENDDECLS
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -136,5 +136,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+16
-17
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 1999-2002, 2004-2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: named-checkconf.c,v 1.56 2011/03/12 04:59:46 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
@@ -20,6 +18,7 @@
|
|||||||
|
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -127,13 +126,8 @@ get_checknames(const cfg_obj_t **maps, const cfg_obj_t **obj) {
|
|||||||
element = cfg_list_next(element)) {
|
element = cfg_list_next(element)) {
|
||||||
value = cfg_listelt_value(element);
|
value = cfg_listelt_value(element);
|
||||||
type = cfg_tuple_get(value, "type");
|
type = cfg_tuple_get(value, "type");
|
||||||
if ((strcasecmp(cfg_obj_asstring(type),
|
if (strcasecmp(cfg_obj_asstring(type), "master") != 0)
|
||||||
"primary") != 0) &&
|
|
||||||
(strcasecmp(cfg_obj_asstring(type),
|
|
||||||
"master") != 0))
|
|
||||||
{
|
|
||||||
continue;
|
continue;
|
||||||
}
|
|
||||||
*obj = cfg_tuple_get(value, "mode");
|
*obj = cfg_tuple_get(value, "mode");
|
||||||
return (ISC_TRUE);
|
return (ISC_TRUE);
|
||||||
}
|
}
|
||||||
@@ -249,14 +243,11 @@ configure_zone(const char *vclass, const char *view,
|
|||||||
* Skip loading checks for any type other than
|
* Skip loading checks for any type other than
|
||||||
* master and redirect
|
* master and redirect
|
||||||
*/
|
*/
|
||||||
if (strcasecmp(cfg_obj_asstring(typeobj), "hint") == 0) {
|
if (strcasecmp(cfg_obj_asstring(typeobj), "hint") == 0)
|
||||||
return (configure_hint(zfile, zclass, mctx));
|
return (configure_hint(zfile, zclass, mctx));
|
||||||
} else if ((strcasecmp(cfg_obj_asstring(typeobj), "primary") != 0) &&
|
else if ((strcasecmp(cfg_obj_asstring(typeobj), "master") != 0) &&
|
||||||
(strcasecmp(cfg_obj_asstring(typeobj), "master") != 0) &&
|
(strcasecmp(cfg_obj_asstring(typeobj), "redirect") != 0))
|
||||||
(strcasecmp(cfg_obj_asstring(typeobj), "redirect") != 0))
|
|
||||||
{
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Is the redirect zone configured as a slave?
|
* Is the redirect zone configured as a slave?
|
||||||
@@ -406,7 +397,7 @@ configure_zone(const char *vclass, const char *view,
|
|||||||
obj = NULL;
|
obj = NULL;
|
||||||
if (get_maps(maps, "max-zone-ttl", &obj)) {
|
if (get_maps(maps, "max-zone-ttl", &obj)) {
|
||||||
maxttl = cfg_obj_asuint32(obj);
|
maxttl = cfg_obj_asuint32(obj);
|
||||||
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
zone_options2 |= DNS_ZONEOPT2_CHECKTTL;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = load_zone(mctx, zname, zfile, masterformat,
|
result = load_zone(mctx, zname, zfile, masterformat,
|
||||||
@@ -537,6 +528,7 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
int exit_status = 0;
|
int exit_status = 0;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
isc_boolean_t load_zones = ISC_FALSE;
|
isc_boolean_t load_zones = ISC_FALSE;
|
||||||
isc_boolean_t list_zones = ISC_FALSE;
|
isc_boolean_t list_zones = ISC_FALSE;
|
||||||
isc_boolean_t print = ISC_FALSE;
|
isc_boolean_t print = ISC_FALSE;
|
||||||
@@ -652,6 +644,10 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
|
||||||
|
RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
|
||||||
|
== ISC_R_SUCCESS);
|
||||||
|
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
|
|
||||||
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
||||||
@@ -682,6 +678,9 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_log_destroy(&logc);
|
isc_log_destroy(&logc);
|
||||||
|
|
||||||
|
isc_hash_destroy();
|
||||||
|
isc_entropy_detach(&ectx);
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
|
|||||||
@@ -1,14 +1,11 @@
|
|||||||
<!DOCTYPE book [
|
<!DOCTYPE book [
|
||||||
<!ENTITY mdash "—">]>
|
<!ENTITY mdash "—">]>
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -39,7 +36,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004-2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -325,5 +325,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004-2007, 2009-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004-2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 1999-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: named-checkzone.c,v 1.65.32.2 2012/02/07 02:45:21 each Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
@@ -19,6 +17,7 @@
|
|||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -45,6 +44,7 @@
|
|||||||
|
|
||||||
static int quiet = 0;
|
static int quiet = 0;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
static isc_entropy_t *ectx = NULL;
|
||||||
dns_zone_t *zone = NULL;
|
dns_zone_t *zone = NULL;
|
||||||
dns_zonetype_t zonetype = dns_zone_master;
|
dns_zonetype_t zonetype = dns_zone_master;
|
||||||
static int dumpzone = 0;
|
static int dumpzone = 0;
|
||||||
@@ -257,7 +257,7 @@ main(int argc, char **argv) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'l':
|
case 'l':
|
||||||
zone_options |= DNS_ZONEOPT_CHECKTTL;
|
zone_options2 |= DNS_ZONEOPT2_CHECKTTL;
|
||||||
endp = NULL;
|
endp = NULL;
|
||||||
maxttl = strtol(isc_commandline_argument, &endp, 0);
|
maxttl = strtol(isc_commandline_argument, &endp, 0);
|
||||||
if (*endp != '\0') {
|
if (*endp != '\0') {
|
||||||
@@ -519,6 +519,9 @@ main(int argc, char **argv) {
|
|||||||
if (!quiet)
|
if (!quiet)
|
||||||
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx)
|
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx)
|
||||||
== ISC_R_SUCCESS);
|
== ISC_R_SUCCESS);
|
||||||
|
RUNTIME_CHECK(isc_entropy_create(mctx, &ectx) == ISC_R_SUCCESS);
|
||||||
|
RUNTIME_CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE)
|
||||||
|
== ISC_R_SUCCESS);
|
||||||
|
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
|
|
||||||
@@ -550,6 +553,8 @@ main(int argc, char **argv) {
|
|||||||
destroy();
|
destroy();
|
||||||
if (lctx != NULL)
|
if (lctx != NULL)
|
||||||
isc_log_destroy(&lctx);
|
isc_log_destroy(&lctx);
|
||||||
|
isc_hash_destroy();
|
||||||
|
isc_entropy_detach(&ectx);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
#ifdef _WIN32
|
#ifdef _WIN32
|
||||||
DestroySockets();
|
DestroySockets();
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004-2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -42,7 +39,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004-2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+3
-10
@@ -1,20 +1,13 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2009, 2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
top_srcdir = @top_srcdir@
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
# Attempt to disable parallel processing.
|
|
||||||
.NOTPARALLEL:
|
|
||||||
.NO_PARALLEL:
|
|
||||||
|
|
||||||
VERSION=@BIND9_VERSION@
|
VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
@@ -71,11 +64,11 @@ rndc-confgen.@O@: rndc-confgen.c
|
|||||||
ddns-confgen.@O@: ddns-confgen.c
|
ddns-confgen.@O@: ddns-confgen.c
|
||||||
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c ${srcdir}/ddns-confgen.c
|
||||||
|
|
||||||
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
rndc-confgen@EXEEXT@: rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||||
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
export BASEOBJS="rndc-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${CONFDEPLIBS}
|
ddns-confgen@EXEEXT@: ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS} ${CONFDEPLIBS}
|
||||||
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
export BASEOBJS="ddns-confgen.@O@ util.@O@ keygen.@O@ ${UOBJS}"; \
|
||||||
${FINALBUILDCMD}
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
ddns-confgen \- ddns key generation tool
|
ddns-confgen \- ddns key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBtsig\-keygen\fR\ 'u
|
.HP \w'\fBtsig\-keygen\fR\ 'u
|
||||||
\fBtsig\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-h\fR] [name]
|
\fBtsig\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-h\fR] [\fB\-r\ \fR\fB\fIrandomfile\fR\fR] [name]
|
||||||
.HP \w'\fBddns\-confgen\fR\ 'u
|
.HP \w'\fBddns\-confgen\fR\ 'u
|
||||||
\fBddns\-confgen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-h\fR] [\fB\-k\ \fR\fB\fIkeyname\fR\fR] [\fB\-q\fR] [\fB\-r\ \fR\fB\fIrandomfile\fR\fR] [\-s\ \fIname\fR | \-z\ \fIzone\fR]
|
\fBddns\-confgen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-h\fR] [\fB\-k\ \fR\fB\fIkeyname\fR\fR] [\fB\-q\fR] [\fB\-r\ \fR\fB\fIrandomfile\fR\fR] [\-s\ \fIname\fR | \-z\ \fIzone\fR]
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
@@ -109,6 +109,17 @@ only\&.) Quiet mode: Print only the key, with no explanatory text or usage examp
|
|||||||
\fBtsig\-keygen\fR\&.
|
\fBtsig\-keygen\fR\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-r \fIrandomfile\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies a source of random data for generating the authorization\&. If the operating system does not provide a
|
||||||
|
/dev/random
|
||||||
|
or equivalent device, the default source of randomness is keyboard input\&.
|
||||||
|
randomdev
|
||||||
|
specifies the name of a character device or file containing random data to be used instead of the default\&. The special value
|
||||||
|
keyboard
|
||||||
|
indicates that keyboard input should be used\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-s \fIname\fR
|
\-s \fIname\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
(\fBddns\-confgen\fR
|
(\fBddns\-confgen\fR
|
||||||
@@ -144,5 +155,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+12
-11
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2011, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -26,6 +23,7 @@
|
|||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/keyboard.h>
|
#include <isc/keyboard.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -36,7 +34,7 @@
|
|||||||
#include <isc/time.h>
|
#include <isc/time.h>
|
||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -66,9 +64,10 @@ usage(int status) {
|
|||||||
if (progmode == progmode_confgen) {
|
if (progmode == progmode_confgen) {
|
||||||
fprintf(stderr, "\
|
fprintf(stderr, "\
|
||||||
Usage:\n\
|
Usage:\n\
|
||||||
%s [-a alg] [-k keyname] [-q] [-s name | -z zone]\n\
|
%s [-a alg] [-k keyname] [-r randomfile] [-q] [-s name | -z zone]\n\
|
||||||
-a alg: algorithm (default hmac-sha256)\n\
|
-a alg: algorithm (default hmac-sha256)\n\
|
||||||
-k keyname: name of the key as it will be used in named.conf\n\
|
-k keyname: name of the key as it will be used in named.conf\n\
|
||||||
|
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
||||||
-s name: domain name to be updated using the created key\n\
|
-s name: domain name to be updated using the created key\n\
|
||||||
-z zone: name of the zone as it will be used in named.conf\n\
|
-z zone: name of the zone as it will be used in named.conf\n\
|
||||||
-q: quiet mode: print the key, with no explanatory text\n",
|
-q: quiet mode: print the key, with no explanatory text\n",
|
||||||
@@ -76,8 +75,9 @@ Usage:\n\
|
|||||||
} else {
|
} else {
|
||||||
fprintf(stderr, "\
|
fprintf(stderr, "\
|
||||||
Usage:\n\
|
Usage:\n\
|
||||||
%s [-a alg] [keyname]\n\
|
%s [-a alg] [-r randomfile] [keyname]\n\
|
||||||
-a alg: algorithm (default hmac-sha256)\n\n",
|
-a alg: algorithm (default hmac-sha256)\n\
|
||||||
|
-r randomfile: source of random data (use \"keyboard\" for key timing)\n",
|
||||||
progname);
|
progname);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -92,6 +92,7 @@ main(int argc, char **argv) {
|
|||||||
isc_buffer_t key_txtbuffer;
|
isc_buffer_t key_txtbuffer;
|
||||||
char key_txtsecret[256];
|
char key_txtsecret[256];
|
||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
|
const char *randomfile = NULL;
|
||||||
const char *keyname = NULL;
|
const char *keyname = NULL;
|
||||||
const char *zone = NULL;
|
const char *zone = NULL;
|
||||||
const char *self_domain = NULL;
|
const char *self_domain = NULL;
|
||||||
@@ -102,7 +103,7 @@ main(int argc, char **argv) {
|
|||||||
int len = 0;
|
int len = 0;
|
||||||
int ch;
|
int ch;
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -164,7 +165,7 @@ main(int argc, char **argv) {
|
|||||||
usage(1);
|
usage(1);
|
||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
fatal("The -r option has been deprecated.");
|
randomfile = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
if (progmode == progmode_confgen)
|
if (progmode == progmode_confgen)
|
||||||
@@ -231,7 +232,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
||||||
|
|
||||||
generate_key(mctx, alg, keysize, &key_txtbuffer);
|
generate_key(mctx, randomfile, alg, keysize, &key_txtbuffer);
|
||||||
|
|
||||||
|
|
||||||
if (!quiet)
|
if (!quiet)
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -36,7 +33,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -46,6 +42,7 @@
|
|||||||
<command>tsig-keygen</command>
|
<command>tsig-keygen</command>
|
||||||
<arg choice="opt" rep="norepeat"><option>-a <replaceable class="parameter">algorithm</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-a <replaceable class="parameter">algorithm</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-h</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-h</option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomfile</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat">name</arg>
|
<arg choice="opt" rep="norepeat">name</arg>
|
||||||
</cmdsynopsis>
|
</cmdsynopsis>
|
||||||
<cmdsynopsis sepchar=" ">
|
<cmdsynopsis sepchar=" ">
|
||||||
@@ -156,6 +153,23 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-r <replaceable class="parameter">randomfile</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies a source of random data for generating the
|
||||||
|
authorization. If the operating system does not provide a
|
||||||
|
<filename>/dev/random</filename> or equivalent device, the
|
||||||
|
default source of randomness is keyboard input.
|
||||||
|
<filename>randomdev</filename> specifies the name of a
|
||||||
|
character device or file containing random data to be used
|
||||||
|
instead of the default. The special value
|
||||||
|
<filename>keyboard</filename> indicates that keyboard input
|
||||||
|
should be used.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-s <replaceable class="parameter">name</replaceable></term>
|
<term>-s <replaceable class="parameter">name</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -35,6 +35,7 @@
|
|||||||
<code class="command">tsig-keygen</code>
|
<code class="command">tsig-keygen</code>
|
||||||
[<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
|
[<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
|
||||||
[<code class="option">-h</code>]
|
[<code class="option">-h</code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>]
|
||||||
[name]
|
[name]
|
||||||
</p></div>
|
</p></div>
|
||||||
<div class="cmdsynopsis"><p>
|
<div class="cmdsynopsis"><p>
|
||||||
@@ -135,6 +136,20 @@
|
|||||||
This is essentially identical to <span class="command"><strong>tsig-keygen</strong></span>.
|
This is essentially identical to <span class="command"><strong>tsig-keygen</strong></span>.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-r <em class="replaceable"><code>randomfile</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies a source of random data for generating the
|
||||||
|
authorization. If the operating system does not provide a
|
||||||
|
<code class="filename">/dev/random</code> or equivalent device, the
|
||||||
|
default source of randomness is keyboard input.
|
||||||
|
<code class="filename">randomdev</code> specifies the name of a
|
||||||
|
character device or file containing random data to be used
|
||||||
|
instead of the default. The special value
|
||||||
|
<code class="filename">keyboard</code> indicates that keyboard input
|
||||||
|
should be used.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-s <em class="replaceable"><code>name</code></em></span></dt>
|
<dt><span class="term">-s <em class="replaceable"><code>name</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: os.h,v 1.3 2009/06/11 23:47:55 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
|
|||||||
+42
-11
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: keygen.c,v 1.4 2009/11/12 14:02:38 marka Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
@@ -19,6 +17,7 @@
|
|||||||
|
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/keyboard.h>
|
#include <isc/keyboard.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -112,12 +111,17 @@ alg_bits(dns_secalg_t alg) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Generate a key of size 'keysize' and place it in 'key_txtbuffer'
|
* Generate a key of size 'keysize' using entropy source 'randomfile',
|
||||||
|
* and place it in 'key_txtbuffer'
|
||||||
*/
|
*/
|
||||||
void
|
void
|
||||||
generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
generate_key(isc_mem_t *mctx, const char *randomfile, dns_secalg_t alg,
|
||||||
isc_buffer_t *key_txtbuffer) {
|
int keysize, isc_buffer_t *key_txtbuffer) {
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
isc_entropysource_t *entropy_source = NULL;
|
||||||
|
int open_keyboard = ISC_ENTROPY_KEYBOARDMAYBE;
|
||||||
|
int entropy_flags = 0;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
isc_buffer_t key_rawbuffer;
|
isc_buffer_t key_rawbuffer;
|
||||||
isc_region_t key_rawregion;
|
isc_region_t key_rawregion;
|
||||||
char key_rawsecret[64];
|
char key_rawsecret[64];
|
||||||
@@ -144,12 +148,31 @@ generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|||||||
fatal("unsupported algorithm %d\n", alg);
|
fatal("unsupported algorithm %d\n", alg);
|
||||||
}
|
}
|
||||||
|
|
||||||
DO("initialize dst library", dst_lib_init(mctx, NULL));
|
|
||||||
|
DO("create entropy context", isc_entropy_create(mctx, &ectx));
|
||||||
|
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(ectx, ISC_TRUE);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||||
|
randomfile = NULL;
|
||||||
|
open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||||
|
}
|
||||||
|
DO("start entropy source", isc_entropy_usebestsource(ectx,
|
||||||
|
&entropy_source,
|
||||||
|
randomfile,
|
||||||
|
open_keyboard));
|
||||||
|
|
||||||
|
entropy_flags = ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY;
|
||||||
|
|
||||||
|
DO("initialize dst library", dst_lib_init(mctx, ectx, entropy_flags));
|
||||||
|
|
||||||
DO("generate key", dst_key_generate(dns_rootname, alg,
|
DO("generate key", dst_key_generate(dns_rootname, alg,
|
||||||
keysize, 0, 0, DNS_KEYPROTO_ANY,
|
keysize, 0, 0,
|
||||||
dns_rdataclass_in, mctx, &key,
|
DNS_KEYPROTO_ANY,
|
||||||
NULL));
|
dns_rdataclass_in, mctx, &key));
|
||||||
|
|
||||||
isc_buffer_init(&key_rawbuffer, &key_rawsecret, sizeof(key_rawsecret));
|
isc_buffer_init(&key_rawbuffer, &key_rawsecret, sizeof(key_rawsecret));
|
||||||
|
|
||||||
@@ -160,9 +183,17 @@ generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
|||||||
DO("bsse64 encode secret", isc_base64_totext(&key_rawregion, -1, "",
|
DO("bsse64 encode secret", isc_base64_totext(&key_rawregion, -1, "",
|
||||||
key_txtbuffer));
|
key_txtbuffer));
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Shut down the entropy source now so the "stop typing" message
|
||||||
|
* does not muck with the output.
|
||||||
|
*/
|
||||||
|
if (entropy_source != NULL)
|
||||||
|
isc_entropy_destroysource(&entropy_source);
|
||||||
|
|
||||||
if (key != NULL)
|
if (key != NULL)
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
|
|
||||||
|
isc_entropy_detach(&ectx);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: keygen.h,v 1.3 2009/06/11 23:47:55 tbox Exp $ */
|
||||||
|
|
||||||
#ifndef RNDC_KEYGEN_H
|
#ifndef RNDC_KEYGEN_H
|
||||||
#define RNDC_KEYGEN_H 1
|
#define RNDC_KEYGEN_H 1
|
||||||
@@ -19,8 +17,8 @@
|
|||||||
|
|
||||||
ISC_LANG_BEGINDECLS
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
void generate_key(isc_mem_t *mctx, dns_secalg_t alg, int keysize,
|
void generate_key(isc_mem_t *mctx, const char *randomfile, dns_secalg_t alg,
|
||||||
isc_buffer_t *key_txtbuffer);
|
int keysize, isc_buffer_t *key_txtbuffer);
|
||||||
|
|
||||||
void write_key_file(const char *keyfile, const char *user,
|
void write_key_file(const char *keyfile, const char *user,
|
||||||
const char *keyname, isc_buffer_t *secret,
|
const char *keyname, isc_buffer_t *secret,
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
rndc-confgen \- rndc key generation tool
|
rndc-confgen \- rndc key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBrndc\-confgen\fR\ 'u
|
.HP \w'\fBrndc\-confgen\fR\ 'u
|
||||||
\fBrndc\-confgen\fR [\fB\-a\fR] [\fB\-A\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-c\ \fR\fB\fIkeyfile\fR\fR] [\fB\-h\fR] [\fB\-k\ \fR\fB\fIkeyname\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-s\ \fR\fB\fIaddress\fR\fR] [\fB\-t\ \fR\fB\fIchrootdir\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR]
|
\fBrndc\-confgen\fR [\fB\-a\fR] [\fB\-A\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-c\ \fR\fB\fIkeyfile\fR\fR] [\fB\-h\fR] [\fB\-k\ \fR\fB\fIkeyname\fR\fR] [\fB\-p\ \fR\fB\fIport\fR\fR] [\fB\-r\ \fR\fB\fIrandomfile\fR\fR] [\fB\-s\ \fR\fB\fIaddress\fR\fR] [\fB\-t\ \fR\fB\fIchrootdir\fR\fR] [\fB\-u\ \fR\fB\fIuser\fR\fR]
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBrndc\-confgen\fR
|
\fBrndc\-confgen\fR
|
||||||
@@ -111,7 +111,7 @@ as directed\&.
|
|||||||
.PP
|
.PP
|
||||||
\-A \fIalgorithm\fR
|
\-A \fIalgorithm\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-sha256\&.
|
Specifies the algorithm to use for the TSIG key\&. Available choices are: hmac\-md5, hmac\-sha1, hmac\-sha224, hmac\-sha256, hmac\-sha384 and hmac\-sha512\&. The default is hmac\-md5 or if MD5 was disabled hmac\-sha256\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-b \fIkeysize\fR
|
\-b \fIkeysize\fR
|
||||||
@@ -147,6 +147,17 @@ listens for connections from
|
|||||||
\fBrndc\fR\&. The default is 953\&.
|
\fBrndc\fR\&. The default is 953\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-r \fIrandomfile\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies a source of random data for generating the authorization\&. If the operating system does not provide a
|
||||||
|
/dev/random
|
||||||
|
or equivalent device, the default source of randomness is keyboard input\&.
|
||||||
|
randomdev
|
||||||
|
specifies the name of a character device or file containing random data to be used instead of the default\&. The special value
|
||||||
|
keyboard
|
||||||
|
indicates that keyboard input should be used\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-s \fIaddress\fR
|
\-s \fIaddress\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the IP address where
|
Specifies the IP address where
|
||||||
@@ -206,5 +217,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+44
-10
@@ -1,14 +1,13 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2001, 2003-2005, 2007-2009, 2011, 2013, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: rndc-confgen.c,v 1.7 2011/03/12 04:59:46 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -29,6 +28,7 @@
|
|||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/keyboard.h>
|
#include <isc/keyboard.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -67,9 +67,26 @@ usage(int status) ISC_PLATFORM_NORETURN_POST;
|
|||||||
static void
|
static void
|
||||||
usage(int status) {
|
usage(int status) {
|
||||||
|
|
||||||
|
#ifndef PK11_MD5_DISABLE
|
||||||
fprintf(stderr, "\
|
fprintf(stderr, "\
|
||||||
Usage:\n\
|
Usage:\n\
|
||||||
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] \
|
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||||
|
[-s addr] [-t chrootdir] [-u user]\n\
|
||||||
|
-a: generate just the key clause and write it to keyfile (%s)\n\
|
||||||
|
-A alg: algorithm (default hmac-md5 (deprecated and will change))\n\
|
||||||
|
-b bits: from 1 through 512, default 256; total length of the secret\n\
|
||||||
|
-c keyfile: specify an alternate key file (requires -a)\n\
|
||||||
|
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
||||||
|
-p port: the port named will listen on and rndc will connect to\n\
|
||||||
|
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
||||||
|
-s addr: the address to which rndc should connect\n\
|
||||||
|
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||||
|
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||||
|
progname, keydef);
|
||||||
|
#else
|
||||||
|
fprintf(stderr, "\
|
||||||
|
Usage:\n\
|
||||||
|
%s [-a] [-b bits] [-c keyfile] [-k keyname] [-p port] [-r randomfile] \
|
||||||
[-s addr] [-t chrootdir] [-u user]\n\
|
[-s addr] [-t chrootdir] [-u user]\n\
|
||||||
-a: generate just the key clause and write it to keyfile (%s)\n\
|
-a: generate just the key clause and write it to keyfile (%s)\n\
|
||||||
-A alg: algorithm (default hmac-sha256)\n\
|
-A alg: algorithm (default hmac-sha256)\n\
|
||||||
@@ -77,10 +94,12 @@ Usage:\n\
|
|||||||
-c keyfile: specify an alternate key file (requires -a)\n\
|
-c keyfile: specify an alternate key file (requires -a)\n\
|
||||||
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
-k keyname: the name as it will be used in named.conf and rndc.conf\n\
|
||||||
-p port: the port named will listen on and rndc will connect to\n\
|
-p port: the port named will listen on and rndc will connect to\n\
|
||||||
|
-r randomfile: source of random data (use \"keyboard\" for key timing)\n\
|
||||||
-s addr: the address to which rndc should connect\n\
|
-s addr: the address to which rndc should connect\n\
|
||||||
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
-t chrootdir: write a keyfile in chrootdir as well (requires -a)\n\
|
||||||
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
-u user: set the keyfile owner to \"user\" (requires -a)\n",
|
||||||
progname, keydef);
|
progname, keydef);
|
||||||
|
#endif
|
||||||
|
|
||||||
exit (status);
|
exit (status);
|
||||||
}
|
}
|
||||||
@@ -93,8 +112,10 @@ main(int argc, char **argv) {
|
|||||||
isc_mem_t *mctx = NULL;
|
isc_mem_t *mctx = NULL;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
const char *keyname = NULL;
|
const char *keyname = NULL;
|
||||||
|
const char *randomfile = NULL;
|
||||||
const char *serveraddr = NULL;
|
const char *serveraddr = NULL;
|
||||||
dns_secalg_t alg;
|
dns_secalg_t alg;
|
||||||
|
isc_boolean_t algset = ISC_FALSE;
|
||||||
const char *algname;
|
const char *algname;
|
||||||
char *p;
|
char *p;
|
||||||
int ch;
|
int ch;
|
||||||
@@ -115,7 +136,11 @@ main(int argc, char **argv) {
|
|||||||
progname = program;
|
progname = program;
|
||||||
|
|
||||||
keyname = DEFAULT_KEYNAME;
|
keyname = DEFAULT_KEYNAME;
|
||||||
|
#ifndef PK11_MD5_DISABLE
|
||||||
|
alg = DST_ALG_HMACMD5;
|
||||||
|
#else
|
||||||
alg = DST_ALG_HMACSHA256;
|
alg = DST_ALG_HMACSHA256;
|
||||||
|
#endif
|
||||||
serveraddr = DEFAULT_SERVER;
|
serveraddr = DEFAULT_SERVER;
|
||||||
port = DEFAULT_PORT;
|
port = DEFAULT_PORT;
|
||||||
|
|
||||||
@@ -129,6 +154,7 @@ main(int argc, char **argv) {
|
|||||||
keyonly = ISC_TRUE;
|
keyonly = ISC_TRUE;
|
||||||
break;
|
break;
|
||||||
case 'A':
|
case 'A':
|
||||||
|
algset = ISC_TRUE;
|
||||||
algname = isc_commandline_argument;
|
algname = isc_commandline_argument;
|
||||||
alg = alg_fromtext(algname);
|
alg = alg_fromtext(algname);
|
||||||
if (alg == DST_ALG_UNKNOWN)
|
if (alg == DST_ALG_UNKNOWN)
|
||||||
@@ -162,7 +188,7 @@ main(int argc, char **argv) {
|
|||||||
isc_commandline_argument);
|
isc_commandline_argument);
|
||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
fatal("The -r option has been deprecated.");
|
randomfile = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
serveraddr = isc_commandline_argument;
|
serveraddr = isc_commandline_argument;
|
||||||
@@ -202,9 +228,17 @@ main(int argc, char **argv) {
|
|||||||
usage(1);
|
usage(1);
|
||||||
|
|
||||||
if (alg == DST_ALG_HMACMD5) {
|
if (alg == DST_ALG_HMACMD5) {
|
||||||
fprintf(stderr,
|
if (algset) {
|
||||||
"warning: use of hmac-md5 for RNDC keys "
|
fprintf(stderr,
|
||||||
"is deprecated; hmac-sha256 is now recommended.\n");
|
"warning: use of hmac-md5 for RNDC keys "
|
||||||
|
"is deprecated; hmac-sha256 is now "
|
||||||
|
"recommended.\n");
|
||||||
|
} else {
|
||||||
|
fprintf(stderr,
|
||||||
|
"warning: the default algorithm hmac-md5 "
|
||||||
|
"is deprecated and will be\n"
|
||||||
|
"changed to hmac-sha256 in a future release\n")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (keysize < 0)
|
if (keysize < 0)
|
||||||
@@ -214,7 +248,7 @@ main(int argc, char **argv) {
|
|||||||
DO("create memory context", isc_mem_create(0, 0, &mctx));
|
DO("create memory context", isc_mem_create(0, 0, &mctx));
|
||||||
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
isc_buffer_init(&key_txtbuffer, &key_txtsecret, sizeof(key_txtsecret));
|
||||||
|
|
||||||
generate_key(mctx, alg, keysize, &key_txtbuffer);
|
generate_key(mctx, randomfile, alg, keysize, &key_txtbuffer);
|
||||||
|
|
||||||
if (keyonly) {
|
if (keyonly) {
|
||||||
write_key_file(keyfile, chrootdir == NULL ? user : NULL,
|
write_key_file(keyfile, chrootdir == NULL ? user : NULL,
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -42,8 +39,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -58,6 +53,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-h</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-h</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">keyname</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">keyname</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">port</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">port</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomfile</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">address</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">address</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">chrootdir</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">chrootdir</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-u <replaceable class="parameter">user</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-u <replaceable class="parameter">user</replaceable></option></arg>
|
||||||
@@ -132,7 +128,12 @@
|
|||||||
<para>
|
<para>
|
||||||
Specifies the algorithm to use for the TSIG key. Available
|
Specifies the algorithm to use for the TSIG key. Available
|
||||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
hmac-sha384 and hmac-sha512. The default is hmac-md5, or
|
||||||
|
if MD5 was disabled at compile time, hmac-sha256.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Note: Use of hmac-md5 is no longer recommended, and the default
|
||||||
|
value will be changed to hmac-sha256 in a future release.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -190,6 +191,24 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-r <replaceable class="parameter">randomfile</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies a source of random data for generating the
|
||||||
|
authorization. If the operating
|
||||||
|
system does not provide a <filename>/dev/random</filename>
|
||||||
|
or equivalent device, the default source of randomness
|
||||||
|
is keyboard input. <filename>randomdev</filename>
|
||||||
|
specifies
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used instead of the default. The special value
|
||||||
|
<filename>keyboard</filename> indicates that keyboard
|
||||||
|
input should be used.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-s <replaceable class="parameter">address</replaceable></term>
|
<term>-s <replaceable class="parameter">address</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -40,6 +40,7 @@
|
|||||||
[<code class="option">-h</code>]
|
[<code class="option">-h</code>]
|
||||||
[<code class="option">-k <em class="replaceable"><code>keyname</code></em></code>]
|
[<code class="option">-k <em class="replaceable"><code>keyname</code></em></code>]
|
||||||
[<code class="option">-p <em class="replaceable"><code>port</code></em></code>]
|
[<code class="option">-p <em class="replaceable"><code>port</code></em></code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>address</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>address</code></em></code>]
|
||||||
[<code class="option">-t <em class="replaceable"><code>chrootdir</code></em></code>]
|
[<code class="option">-t <em class="replaceable"><code>chrootdir</code></em></code>]
|
||||||
[<code class="option">-u <em class="replaceable"><code>user</code></em></code>]
|
[<code class="option">-u <em class="replaceable"><code>user</code></em></code>]
|
||||||
@@ -112,7 +113,8 @@
|
|||||||
<p>
|
<p>
|
||||||
Specifies the algorithm to use for the TSIG key. Available
|
Specifies the algorithm to use for the TSIG key. Available
|
||||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
|
||||||
hmac-sha384 and hmac-sha512. The default is hmac-sha256.
|
hmac-sha384 and hmac-sha512. The default is hmac-md5 or
|
||||||
|
if MD5 was disabled hmac-sha256.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
||||||
@@ -153,6 +155,21 @@
|
|||||||
The default is 953.
|
The default is 953.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-r <em class="replaceable"><code>randomfile</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies a source of random data for generating the
|
||||||
|
authorization. If the operating
|
||||||
|
system does not provide a <code class="filename">/dev/random</code>
|
||||||
|
or equivalent device, the default source of randomness
|
||||||
|
is keyboard input. <code class="filename">randomdev</code>
|
||||||
|
specifies
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used instead of the default. The special value
|
||||||
|
<code class="filename">keyboard</code> indicates that keyboard
|
||||||
|
input should be used.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-s <em class="replaceable"><code>address</code></em></span></dt>
|
<dt><span class="term">-s <em class="replaceable"><code>address</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2009, 2012, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
# $Id: Makefile.in,v 1.3 2009/06/11 23:47:55 tbox Exp $
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: os.c,v 1.3 2009/06/11 23:47:55 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
|
|||||||
+2
-4
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: util.c,v 1.3 2009/06/11 23:47:55 tbox Exp $ */
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
|
|||||||
+2
-4
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: util.h,v 1.4 2009/09/29 15:06:05 fdupont Exp $ */
|
||||||
|
|
||||||
#ifndef RNDC_UTIL_H
|
#ifndef RNDC_UTIL_H
|
||||||
#define RNDC_UTIL_H 1
|
#define RNDC_UTIL_H 1
|
||||||
|
|||||||
@@ -1,14 +1,12 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
/* $Id: os.c,v 1.3 2009/06/11 23:47:55 tbox Exp $ */
|
||||||
|
|
||||||
#include <config.h>
|
#include <config.h>
|
||||||
|
|
||||||
|
|||||||
@@ -1,11 +1,8 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
@@ -18,7 +15,7 @@ VERSION=@BIND9_VERSION@
|
|||||||
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @DST_OPENSSL_INC@
|
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\" \
|
CDEFINES = @CRYPTO@ -DVERSION=\"${VERSION}\" \
|
||||||
-DSYSCONFDIR=\"${sysconfdir}\"
|
-DSYSCONFDIR=\"${sysconfdir}\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -437,5 +437,5 @@ RFC5155\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+36
-25
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
#include <config.h>
|
||||||
@@ -521,17 +518,17 @@ setup_style(dns_master_style_t **stylep) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (multiline || (nottl && noclass))
|
if (multiline || (nottl && noclass))
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 24, 24, 32, 80, 8,
|
24, 24, 24, 32, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else if (nottl || noclass)
|
else if (nottl || noclass)
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 24, 32, 40, 80, 8,
|
24, 24, 32, 40, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else
|
else
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 32, 40, 48, 80, 8,
|
24, 32, 40, 48, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
|
|
||||||
if (result == ISC_R_SUCCESS)
|
if (result == ISC_R_SUCCESS)
|
||||||
*stylep = style;
|
*stylep = style;
|
||||||
@@ -550,7 +547,8 @@ convert_name(dns_fixedname_t *fn, dns_name_t **name, const char *text) {
|
|||||||
|
|
||||||
isc_buffer_constinit(&b, text, len);
|
isc_buffer_constinit(&b, text, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
n = dns_fixedname_initname(fn);
|
dns_fixedname_init(fn);
|
||||||
|
n = dns_fixedname_name(fn);
|
||||||
|
|
||||||
result = dns_name_fromtext(n, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(n, &b, dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
@@ -943,6 +941,18 @@ cleanup:
|
|||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static char *
|
||||||
|
next_token(char **stringp, const char *delim) {
|
||||||
|
char *res;
|
||||||
|
|
||||||
|
do {
|
||||||
|
res = strsep(stringp, delim);
|
||||||
|
if (res == NULL)
|
||||||
|
break;
|
||||||
|
} while (*res == '\0');
|
||||||
|
return (res);
|
||||||
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
parse_uint(isc_uint32_t *uip, const char *value, isc_uint32_t max,
|
parse_uint(isc_uint32_t *uip, const char *value, isc_uint32_t max,
|
||||||
const char *desc) {
|
const char *desc) {
|
||||||
@@ -962,23 +972,23 @@ parse_uint(isc_uint32_t *uip, const char *value, isc_uint32_t max,
|
|||||||
static void
|
static void
|
||||||
plus_option(char *option) {
|
plus_option(char *option) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
char *cmd, *value, *last = NULL;
|
char option_store[256];
|
||||||
|
char *cmd, *value, *ptr;
|
||||||
isc_boolean_t state = ISC_TRUE;
|
isc_boolean_t state = ISC_TRUE;
|
||||||
|
|
||||||
INSIST(option != NULL);
|
strlcpy(option_store, option, sizeof(option_store));
|
||||||
|
ptr = option_store;
|
||||||
cmd = strtok_r(option, "=", &last);
|
cmd = next_token(&ptr,"=");
|
||||||
if (cmd == NULL) {
|
if (cmd == NULL) {
|
||||||
printf(";; Invalid option %s\n", option);
|
printf(";; Invalid option %s\n", option_store);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
value = ptr;
|
||||||
if (strncasecmp(cmd, "no", 2)==0) {
|
if (strncasecmp(cmd, "no", 2)==0) {
|
||||||
cmd += 2;
|
cmd += 2;
|
||||||
state = ISC_FALSE;
|
state = ISC_FALSE;
|
||||||
}
|
}
|
||||||
|
|
||||||
value = strtok_r(NULL, "\0", &last);
|
|
||||||
|
|
||||||
#define FULLCHECK(A) \
|
#define FULLCHECK(A) \
|
||||||
do { \
|
do { \
|
||||||
size_t _l = strlen(cmd); \
|
size_t _l = strlen(cmd); \
|
||||||
@@ -1525,8 +1535,9 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t strict) {
|
|||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
unsigned int options = 0;
|
unsigned int options = 0;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
result = dns_byaddr_createptrname(&addr, options, name);
|
name = dns_fixedname_name(&fname);
|
||||||
|
result = dns_byaddr_createptrname2(&addr, options, name);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
return (result);
|
return (result);
|
||||||
dns_name_format(name, reverse, (unsigned int)len);
|
dns_name_format(name, reverse, (unsigned int)len);
|
||||||
@@ -1610,8 +1621,8 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
/* Create client */
|
/* Create client */
|
||||||
clopt = DNS_CLIENTCREATEOPT_USECACHE;
|
clopt = DNS_CLIENTCREATEOPT_USECACHE;
|
||||||
result = dns_client_createx(mctx, actx, taskmgr, socketmgr, timermgr,
|
result = dns_client_createx2(mctx, actx, taskmgr, socketmgr, timermgr,
|
||||||
clopt, &client, srcaddr4, srcaddr6);
|
clopt, &client, srcaddr4, srcaddr6);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
delv_log(ISC_LOG_ERROR, "dns_client_create: %s",
|
delv_log(ISC_LOG_ERROR, "dns_client_create: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|||||||
@@ -1,14 +1,11 @@
|
|||||||
<!DOCTYPE book [
|
<!DOCTYPE book [
|
||||||
<!ENTITY mdash "—">]>
|
<!ENTITY mdash "—">]>
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -38,7 +35,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+5
-8
@@ -1,11 +1,8 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
@@ -19,9 +16,9 @@ READLINE_LIB = @READLINE_LIB@
|
|||||||
|
|
||||||
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} \
|
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} \
|
||||||
${BIND9_INCLUDES} ${ISC_INCLUDES} \
|
${BIND9_INCLUDES} ${ISC_INCLUDES} \
|
||||||
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @LIBIDN2_CFLAGS@ @DST_OPENSSL_INC@
|
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\"
|
CDEFINES = -DVERSION=\"${VERSION}\" @CRYPTO@
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
@@ -41,10 +38,10 @@ DEPLIBS = ${DNSDEPLIBS} ${IRSDEPLIBS} ${BIND9DEPLIBS} \
|
|||||||
${ISCDEPLIBS} ${ISCCFGDEPLIBS}
|
${ISCDEPLIBS} ${ISCCFGDEPLIBS}
|
||||||
|
|
||||||
LIBS = ${DNSLIBS} ${IRSLIBS} ${BIND9LIBS} ${ISCCFGLIBS} \
|
LIBS = ${DNSLIBS} ${IRSLIBS} ${BIND9LIBS} ${ISCCFGLIBS} \
|
||||||
${ISCLIBS} @LIBIDN2_LIBS@ @LIBS@
|
${ISCLIBS} @IDNLIBS@ @LIBS@
|
||||||
|
|
||||||
NOSYMLIBS = ${DNSLIBS} ${IRSLIBS} ${BIND9LIBS} ${ISCCFGLIBS} \
|
NOSYMLIBS = ${DNSLIBS} ${IRSLIBS} ${BIND9LIBS} ${ISCCFGLIBS} \
|
||||||
${ISCNOSYMLIBS} @LIBIDN2_LIBS@ @LIBS@
|
${ISCNOSYMLIBS} @IDNLIBS@ @LIBS@
|
||||||
|
|
||||||
SUBDIRS =
|
SUBDIRS =
|
||||||
|
|
||||||
|
|||||||
+11
-37
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2011, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -176,7 +176,7 @@ using the command\-line interface\&.
|
|||||||
.PP
|
.PP
|
||||||
\-i
|
\-i
|
||||||
.RS 4
|
.RS 4
|
||||||
Do reverse IPv6 lookups using the obsolete RFC 1886 IP6\&.INT domain, which is no longer in use\&. Obsolete bit string label queries (RFC 2874) are not attempted\&.
|
Do reverse IPv6 lookups using the obsolete RFC1886 IP6\&.INT domain, which is no longer in use\&. Obsolete bit string label queries (RFC2874) are not attempted\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-k \fIkeyfile\fR
|
\-k \fIkeyfile\fR
|
||||||
@@ -210,20 +210,13 @@ from other arguments\&.
|
|||||||
.PP
|
.PP
|
||||||
\-t \fItype\fR
|
\-t \fItype\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
The resource record type to query\&. It can be any valid query type\&. If it is a resource record type supported in BIND 9, it can be given by the type mnemonic (such as "NS" or "AAAA")\&. The default query type is "A", unless the
|
The resource record type to query\&. It can be any valid query type which is supported in BIND 9\&. The default query type is "A", unless the
|
||||||
\fB\-x\fR
|
\fB\-x\fR
|
||||||
option is supplied to indicate a reverse lookup\&. A zone transfer can be requested by specifying a type of AXFR\&. When an incremental zone transfer (IXFR) is required, set the
|
option is supplied to indicate a reverse lookup\&. A zone transfer can be requested by specifying a type of AXFR\&. When an incremental zone transfer (IXFR) is required, set the
|
||||||
\fItype\fR
|
\fItype\fR
|
||||||
to
|
to
|
||||||
ixfr=N\&. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone\*(Aqs SOA record was
|
ixfr=N\&. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone\*(Aqs SOA record was
|
||||||
\fIN\fR\&.
|
\fIN\fR\&.
|
||||||
.sp
|
|
||||||
All resource record types can be expressed as "TYPEnn", where "nn" is the number of the type\&. If the resource record type is not supported in BIND 9, the result will be displayed as described in RFC 3597\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-u
|
|
||||||
.RS 4
|
|
||||||
Print query times in microseconds instead of milliseconds\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-v
|
\-v
|
||||||
@@ -466,11 +459,6 @@ Show [or do not show] the IP address and port number that supplied the answer wh
|
|||||||
option is enabled\&. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer\&.
|
option is enabled\&. If short form answers are requested, the default is not to show the source address and port number of the server that provided the answer\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]idnin\fR
|
|
||||||
.RS 4
|
|
||||||
Process [do not process] IDN domain names on input\&. This requires IDN SUPPORT to have been enabled at compile time\&. The default is to process IDN input\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\fB+[no]idnout\fR
|
\fB+[no]idnout\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to have been enabled at compile time\&. The default is to convert output\&.
|
Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to have been enabled at compile time\&. The default is to convert output\&.
|
||||||
@@ -481,11 +469,6 @@ Convert [do not convert] puny code on output\&. This requires IDN SUPPORT to hav
|
|||||||
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
Ignore truncation in UDP responses instead of retrying with TCP\&. By default, TCP retries are performed\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]keepalive\fR
|
|
||||||
.RS 4
|
|
||||||
Send [or do not send] an EDNS Keepalive option\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\fB+[no]keepopen\fR
|
\fB+[no]keepopen\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
Keep the TCP socket open between queries and reuse it rather than creating a new TCP socket for each lookup\&. The default is
|
||||||
@@ -532,7 +515,7 @@ Include an EDNS name server ID request when sending a query\&.
|
|||||||
.RS 4
|
.RS 4
|
||||||
When this option is set,
|
When this option is set,
|
||||||
\fBdig\fR
|
\fBdig\fR
|
||||||
attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone\&. Addresses of servers that that did not respond are also printed\&.
|
attempts to find the authoritative name servers for the zone containing the name being looked up and display the SOA record that each name server has for the zone\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]onesoa\fR
|
\fB+[no]onesoa\fR
|
||||||
@@ -564,11 +547,6 @@ Print [do not print] the query as it is sent\&. By default, the query is not pri
|
|||||||
Print [do not print] the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&.
|
Print [do not print] the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]raflag\fR
|
|
||||||
.RS 4
|
|
||||||
Set [do not set] the RA (Recursion Available) bit in the query\&. The default is +noraflag\&. This bit should be ignored by the server for QUERY\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\fB+[no]rdflag\fR
|
\fB+[no]rdflag\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
A synonym for
|
A synonym for
|
||||||
@@ -658,11 +636,6 @@ for short, sends an EDNS CLIENT\-SUBNET option with an empty address and a sourc
|
|||||||
be used when resolving this query\&.
|
be used when resolving this query\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]tcflag\fR
|
|
||||||
.RS 4
|
|
||||||
Set [do not set] the TC (TrunCation) bit in the query\&. The default is +notcflag\&. This bit should be ignored by the server for QUERY\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\fB+[no]tcp\fR
|
\fB+[no]tcp\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Use [do not use] TCP when querying name servers\&. The default behavior is to use UDP unless a type
|
Use [do not use] TCP when querying name servers\&. The default behavior is to use UDP unless a type
|
||||||
@@ -792,10 +765,11 @@ If
|
|||||||
\fBdig\fR
|
\fBdig\fR
|
||||||
has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names\&.
|
has been built with IDN (internationalized domain name) support, it can accept and display non\-ASCII domain names\&.
|
||||||
\fBdig\fR
|
\fBdig\fR
|
||||||
appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server\&. If you\*(Aqd like to turn off the IDN support for some reason, use parameters
|
appropriately converts character encoding of domain name before sending a request to DNS server or displaying a reply from the server\&. If you\*(Aqd like to turn off the IDN support for some reason, defines the
|
||||||
\fI+noidnin\fR
|
\fBIDN_DISABLE\fR
|
||||||
and
|
environment variable\&. The IDN support is disabled if the variable is set when
|
||||||
\fI+noidnout\fR\&.
|
\fBdig\fR
|
||||||
|
runs\&.
|
||||||
.SH "FILES"
|
.SH "FILES"
|
||||||
.PP
|
.PP
|
||||||
/etc/resolv\&.conf
|
/etc/resolv\&.conf
|
||||||
@@ -807,7 +781,7 @@ ${HOME}/\&.digrc
|
|||||||
\fBhost\fR(1),
|
\fBhost\fR(1),
|
||||||
\fBnamed\fR(8),
|
\fBnamed\fR(8),
|
||||||
\fBdnssec-keygen\fR(8),
|
\fBdnssec-keygen\fR(8),
|
||||||
RFC 1035\&.
|
RFC1035\&.
|
||||||
.SH "BUGS"
|
.SH "BUGS"
|
||||||
.PP
|
.PP
|
||||||
There are probably too many query options\&.
|
There are probably too many query options\&.
|
||||||
@@ -816,5 +790,5 @@ There are probably too many query options\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2011, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+128
-183
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -112,11 +109,6 @@ print_usage(FILE *fp) {
|
|||||||
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
" [ host [@local-server] {local-d-opt} [...]]\n", fp);
|
||||||
}
|
}
|
||||||
|
|
||||||
#if TARGET_OS_IPHONE
|
|
||||||
static void usage(void) {
|
|
||||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
|
||||||
}
|
|
||||||
#else
|
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
@@ -127,7 +119,6 @@ usage(void) {
|
|||||||
"for complete list of options\n", stderr);
|
"for complete list of options\n", stderr);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
#endif
|
|
||||||
|
|
||||||
/*% version */
|
/*% version */
|
||||||
static void
|
static void
|
||||||
@@ -190,8 +181,7 @@ help(void) {
|
|||||||
" +[no]fail (Don't try next server on SERVFAIL)\n"
|
" +[no]fail (Don't try next server on SERVFAIL)\n"
|
||||||
" +[no]header-only (Send query without a question section)\n"
|
" +[no]header-only (Send query without a question section)\n"
|
||||||
" +[no]identify (ID responders in short answers)\n"
|
" +[no]identify (ID responders in short answers)\n"
|
||||||
" +[no]idnin (Parse IDN names)\n"
|
" +[no]idnout (convert IDN response)\n"
|
||||||
" +[no]idnout (Convert IDN response)\n"
|
|
||||||
" +[no]ignore (Don't revert to TCP for TC responses.)\n"
|
" +[no]ignore (Don't revert to TCP for TC responses.)\n"
|
||||||
" +[no]keepalive (Request EDNS TCP keepalive)\n"
|
" +[no]keepalive (Request EDNS TCP keepalive)\n"
|
||||||
" +[no]keepopen (Keep the TCP socket open between queries)\n"
|
" +[no]keepopen (Keep the TCP socket open between queries)\n"
|
||||||
@@ -205,7 +195,6 @@ help(void) {
|
|||||||
" +padding=### (Set padding block size [0])\n"
|
" +padding=### (Set padding block size [0])\n"
|
||||||
" +[no]qr (Print question before sending)\n"
|
" +[no]qr (Print question before sending)\n"
|
||||||
" +[no]question (Control display of question section)\n"
|
" +[no]question (Control display of question section)\n"
|
||||||
" +[no]raflag (Set RA flag in query (+[no]raflag))\n"
|
|
||||||
" +[no]rdflag (Recursive mode (+[no]recurse))\n"
|
" +[no]rdflag (Recursive mode (+[no]recurse))\n"
|
||||||
" +[no]recurse (Recursive mode (+[no]rdflag))\n"
|
" +[no]recurse (Recursive mode (+[no]rdflag))\n"
|
||||||
" +retry=### (Set number of UDP retries) [2]\n"
|
" +retry=### (Set number of UDP retries) [2]\n"
|
||||||
@@ -218,7 +207,6 @@ help(void) {
|
|||||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||||
" +[no]stats (Control display of statistics)\n"
|
" +[no]stats (Control display of statistics)\n"
|
||||||
" +subnet=addr (Set edns-client-subnet option)\n"
|
" +subnet=addr (Set edns-client-subnet option)\n"
|
||||||
" +[no]tcflag (Set TC flag in query (+[no]tcflag))\n"
|
|
||||||
" +[no]tcp (TCP mode (+[no]vc))\n"
|
" +[no]tcp (TCP mode (+[no]vc))\n"
|
||||||
" +timeout=### (Set query timeout) [5]\n"
|
" +timeout=### (Set query timeout) [5]\n"
|
||||||
" +[no]trace (Trace delegation down from root [+dnssec])\n"
|
" +[no]trace (Trace delegation down from root [+dnssec])\n"
|
||||||
@@ -239,7 +227,7 @@ help(void) {
|
|||||||
* Callback from dighost.c to print the received message.
|
* Callback from dighost.c to print the received message.
|
||||||
*/
|
*/
|
||||||
static void
|
static void
|
||||||
received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
received(int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||||
isc_uint64_t diff;
|
isc_uint64_t diff;
|
||||||
time_t tnow;
|
time_t tnow;
|
||||||
struct tm tmnow;
|
struct tm tmnow;
|
||||||
@@ -287,12 +275,12 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
|||||||
} else {
|
} else {
|
||||||
printf(";; MSG SIZE rcvd: %u\n", bytes);
|
printf(";; MSG SIZE rcvd: %u\n", bytes);
|
||||||
}
|
}
|
||||||
if (tsigkey != NULL) {
|
if (key != NULL) {
|
||||||
if (!validated)
|
if (!validated)
|
||||||
puts(";; WARNING -- Some TSIG could not "
|
puts(";; WARNING -- Some TSIG could not "
|
||||||
"be validated");
|
"be validated");
|
||||||
}
|
}
|
||||||
if ((tsigkey == NULL) && (keysecret[0] != 0)) {
|
if ((key == NULL) && (keysecret[0] != 0)) {
|
||||||
puts(";; WARNING -- TSIG key was not used.");
|
puts(";; WARNING -- TSIG key was not used.");
|
||||||
}
|
}
|
||||||
puts("");
|
puts("");
|
||||||
@@ -426,8 +414,14 @@ isdotlocal(dns_message_t *msg) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
static unsigned char local_ndata[] = { "\005local\0" };
|
static unsigned char local_ndata[] = { "\005local\0" };
|
||||||
static unsigned char local_offsets[] = { 0, 6 };
|
static unsigned char local_offsets[] = { 0, 6 };
|
||||||
static dns_name_t local =
|
static dns_name_t local = {
|
||||||
DNS_NAME_INITABSOLUTE(local_ndata, local_offsets);
|
DNS_NAME_MAGIC,
|
||||||
|
local_ndata, 7, 2,
|
||||||
|
DNS_NAMEATTR_READONLY | DNS_NAMEATTR_ABSOLUTE,
|
||||||
|
local_offsets, NULL,
|
||||||
|
{(void *)-1, (void *)-1},
|
||||||
|
{NULL, NULL}
|
||||||
|
};
|
||||||
|
|
||||||
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
for (result = dns_message_firstname(msg, DNS_SECTION_QUESTION);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -482,17 +476,17 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
|||||||
}
|
}
|
||||||
if (query->lookup->multiline ||
|
if (query->lookup->multiline ||
|
||||||
(query->lookup->nottl && query->lookup->noclass))
|
(query->lookup->nottl && query->lookup->noclass))
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 24, 24, 32, 80, 8,
|
24, 24, 24, 32, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else if (query->lookup->nottl || query->lookup->noclass)
|
else if (query->lookup->nottl || query->lookup->noclass)
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 24, 32, 40, 80, 8,
|
24, 24, 32, 40, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else
|
else
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
24, 32, 40, 48, 80, 8,
|
24, 32, 40, 48, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
check_result(result, "dns_master_stylecreate");
|
check_result(result, "dns_master_stylecreate");
|
||||||
|
|
||||||
if (query->lookup->cmdline[0] != 0) {
|
if (query->lookup->cmdline[0] != 0) {
|
||||||
@@ -731,27 +725,28 @@ printgreeting(int argc, char **argv, dig_lookup_t *lookup) {
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
static void
|
static void
|
||||||
plus_option(char *option, isc_boolean_t is_batchfile,
|
plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||||
dig_lookup_t *lookup)
|
dig_lookup_t *lookup)
|
||||||
{
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
char *cmd, *value, *last = NULL, *code, *extra;
|
char option_store[256];
|
||||||
|
char *cmd, *value, *ptr, *code;
|
||||||
isc_uint32_t num;
|
isc_uint32_t num;
|
||||||
isc_boolean_t state = ISC_TRUE;
|
isc_boolean_t state = ISC_TRUE;
|
||||||
size_t n;
|
size_t n;
|
||||||
|
|
||||||
INSIST(option != NULL);
|
strlcpy(option_store, option, sizeof(option_store));
|
||||||
|
ptr = option_store;
|
||||||
if ((cmd = strtok_r(option, "=", &last)) == NULL) {
|
cmd = next_token(&ptr, "=");
|
||||||
printf(";; Invalid option %s\n", option);
|
if (cmd == NULL) {
|
||||||
|
printf(";; Invalid option %s\n", option_store);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
value = ptr;
|
||||||
if (strncasecmp(cmd, "no", 2)==0) {
|
if (strncasecmp(cmd, "no", 2)==0) {
|
||||||
cmd += 2;
|
cmd += 2;
|
||||||
state = ISC_FALSE;
|
state = ISC_FALSE;
|
||||||
}
|
}
|
||||||
/* parse the rest of the string */
|
|
||||||
value = strtok_r(NULL, "", &last);
|
|
||||||
|
|
||||||
#define FULLCHECK(A) \
|
#define FULLCHECK(A) \
|
||||||
do { \
|
do { \
|
||||||
@@ -829,10 +824,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&num, value, COMMSIZE,
|
result = parse_uint(&num, value, COMMSIZE,
|
||||||
"buffer size");
|
"buffer size");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse buffer size");
|
fatal("Couldn't parse buffer size");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->udpsize = num;
|
lookup->udpsize = num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -877,10 +870,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
n = strlcpy(hexcookie, value,
|
n = strlcpy(hexcookie, value,
|
||||||
sizeof(hexcookie));
|
sizeof(hexcookie));
|
||||||
if (n >= sizeof(hexcookie)) {
|
if (n >= sizeof(hexcookie))
|
||||||
warn("COOKIE data too large");
|
fatal("COOKIE data too large");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->cookie = hexcookie;
|
lookup->cookie = hexcookie;
|
||||||
} else
|
} else
|
||||||
lookup->cookie = NULL;
|
lookup->cookie = NULL;
|
||||||
@@ -931,10 +922,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value == NULL)
|
if (value == NULL)
|
||||||
goto need_value;
|
goto need_value;
|
||||||
result = parse_uint(&num, value, 0x3f, "DSCP");
|
result = parse_uint(&num, value, 0x3f, "DSCP");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse DSCP value");
|
fatal("Couldn't parse DSCP value");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->dscp = num;
|
lookup->dscp = num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -963,11 +952,9 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
value,
|
value,
|
||||||
255,
|
255,
|
||||||
"edns");
|
"edns");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse "
|
fatal("Couldn't parse "
|
||||||
"edns");
|
"edns");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->edns = num;
|
lookup->edns = num;
|
||||||
break;
|
break;
|
||||||
case 'f':
|
case 'f':
|
||||||
@@ -984,11 +971,9 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
value,
|
value,
|
||||||
0xffff,
|
0xffff,
|
||||||
"ednsflags");
|
"ednsflags");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse "
|
fatal("Couldn't parse "
|
||||||
"ednsflags");
|
"ednsflags");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->ednsflags = num;
|
lookup->ednsflags = num;
|
||||||
break;
|
break;
|
||||||
case 'n':
|
case 'n':
|
||||||
@@ -1001,15 +986,12 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
lookup->ednsoptscnt = 0;
|
lookup->ednsoptscnt = 0;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (value == NULL) {
|
if (value == NULL)
|
||||||
warn("ednsopt no "
|
fatal("ednsopt no "
|
||||||
"code point "
|
"code point "
|
||||||
"specified");
|
"specified");
|
||||||
goto exit_or_usage;
|
code = next_token(&value, ":");
|
||||||
}
|
save_opt(lookup, code, value);
|
||||||
code = strtok_r(value, ":", &last);
|
|
||||||
extra = strtok_r(NULL, "\0", &last);
|
|
||||||
save_opt(lookup, code, extra);
|
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
@@ -1048,29 +1030,13 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
lookup->identify = state;
|
lookup->identify = state;
|
||||||
break;
|
break;
|
||||||
case 'n':
|
case 'n':
|
||||||
switch (cmd[3]) {
|
FULLCHECK("idnout");
|
||||||
case 'i':
|
#ifndef WITH_IDN
|
||||||
FULLCHECK("idnin");
|
fprintf(stderr, ";; IDN support not enabled\n");
|
||||||
#ifndef WITH_IDN_SUPPORT
|
|
||||||
fprintf(stderr, ";; IDN input support"
|
|
||||||
" not enabled\n");
|
|
||||||
#else
|
#else
|
||||||
lookup->idnin = state;
|
lookup->idnout = state;
|
||||||
#endif
|
#endif
|
||||||
break;
|
break;
|
||||||
case 'o':
|
|
||||||
FULLCHECK("idnout");
|
|
||||||
#ifndef WITH_IDN_OUT_SUPPORT
|
|
||||||
fprintf(stderr, ";; IDN output support"
|
|
||||||
" not enabled\n");
|
|
||||||
#else
|
|
||||||
lookup->idnout = state;
|
|
||||||
#endif
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
goto invalid_option;
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
}
|
}
|
||||||
@@ -1138,10 +1104,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
if (!state)
|
if (!state)
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
result = parse_uint(&num, value, MAXNDOTS, "ndots");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse ndots");
|
fatal("Couldn't parse ndots");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
ndots = num;
|
ndots = num;
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
@@ -1203,10 +1167,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
result = parse_uint(&num, value, 15, "opcode");
|
result = parse_uint(&num, value, 15, "opcode");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse opcode");
|
fatal("Couldn't parse opcode");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->opcode = (dns_opcode_t)num;
|
lookup->opcode = (dns_opcode_t)num;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -1220,10 +1182,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
if (value == NULL)
|
if (value == NULL)
|
||||||
goto need_value;
|
goto need_value;
|
||||||
result = parse_uint(&num, value, 512, "padding");
|
result = parse_uint(&num, value, 512, "padding");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse padding");
|
fatal("Couldn't parse padding");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->padding = (isc_uint16_t)num;
|
lookup->padding = (isc_uint16_t)num;
|
||||||
break;
|
break;
|
||||||
case 'q':
|
case 'q':
|
||||||
@@ -1244,10 +1204,6 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
case 'a': /* raflag */
|
|
||||||
FULLCHECK("raflag");
|
|
||||||
lookup->raflag = state;
|
|
||||||
break;
|
|
||||||
case 'd': /* rdflag */
|
case 'd': /* rdflag */
|
||||||
FULLCHECK("rdflag");
|
FULLCHECK("rdflag");
|
||||||
lookup->recurse = state;
|
lookup->recurse = state;
|
||||||
@@ -1266,10 +1222,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&lookup->retries, value,
|
result = parse_uint(&lookup->retries, value,
|
||||||
MAXTRIES - 1, "retries");
|
MAXTRIES - 1, "retries");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse retries");
|
fatal("Couldn't parse retries");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
lookup->retries++;
|
lookup->retries++;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
@@ -1337,11 +1291,11 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
|
|
||||||
result = parse_uint(&splitwidth, value,
|
result = parse_uint(&splitwidth, value,
|
||||||
1023, "split");
|
1023, "split");
|
||||||
if ((splitwidth % 4) != 0U) {
|
if (splitwidth % 4 != 0) {
|
||||||
splitwidth = ((splitwidth + 3) / 4) * 4;
|
splitwidth = ((splitwidth + 3) / 4) * 4;
|
||||||
fprintf(stderr, ";; Warning, split must be "
|
fprintf(stderr, ";; Warning, split must be "
|
||||||
"a multiple of 4; adjusting "
|
"a multiple of 4; adjusting "
|
||||||
"to %u\n", splitwidth);
|
"to %d\n", splitwidth);
|
||||||
}
|
}
|
||||||
/*
|
/*
|
||||||
* There is an adjustment done in the
|
* There is an adjustment done in the
|
||||||
@@ -1352,10 +1306,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
*/
|
*/
|
||||||
if (splitwidth)
|
if (splitwidth)
|
||||||
splitwidth += 3;
|
splitwidth += 3;
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse split");
|
fatal("Couldn't parse split");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case 't': /* stats */
|
case 't': /* stats */
|
||||||
FULLCHECK("stats");
|
FULLCHECK("stats");
|
||||||
@@ -1379,10 +1331,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
lookup->ecs_addr = NULL;
|
lookup->ecs_addr = NULL;
|
||||||
}
|
}
|
||||||
result = parse_netprefix(&lookup->ecs_addr, value);
|
result = parse_netprefix(&lookup->ecs_addr, value);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse client");
|
fatal("Couldn't parse client");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
@@ -1391,20 +1341,10 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
case 't':
|
case 't':
|
||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
case 'c': /* tcp */
|
case 'c': /* tcp */
|
||||||
switch (cmd[2]) {
|
FULLCHECK("tcp");
|
||||||
case 'f':
|
if (!is_batchfile) {
|
||||||
FULLCHECK("tcflag");
|
lookup->tcp_mode = state;
|
||||||
lookup->tcflag = state;
|
lookup->tcp_mode_set = ISC_TRUE;
|
||||||
break;
|
|
||||||
case 'p':
|
|
||||||
FULLCHECK("tcp");
|
|
||||||
if (!is_batchfile) {
|
|
||||||
lookup->tcp_mode = state;
|
|
||||||
lookup->tcp_mode_set = ISC_TRUE;
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
goto invalid_option;
|
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case 'i': /* timeout */
|
case 'i': /* timeout */
|
||||||
@@ -1415,10 +1355,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
result = parse_uint(&timeout, value, MAXTIMEOUT,
|
||||||
"timeout");
|
"timeout");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse timeout");
|
fatal("Couldn't parse timeout");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
if (timeout == 0)
|
if (timeout == 0)
|
||||||
timeout = 1;
|
timeout = 1;
|
||||||
break;
|
break;
|
||||||
@@ -1454,10 +1392,8 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
result = parse_uint(&lookup->retries, value,
|
result = parse_uint(&lookup->retries, value,
|
||||||
MAXTRIES, "tries");
|
MAXTRIES, "tries");
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS)
|
||||||
warn("Couldn't parse tries");
|
fatal("Couldn't parse tries");
|
||||||
goto exit_or_usage;
|
|
||||||
}
|
|
||||||
if (lookup->retries == 0)
|
if (lookup->retries == 0)
|
||||||
lookup->retries = 1;
|
lookup->retries = 1;
|
||||||
break;
|
break;
|
||||||
@@ -1514,19 +1450,11 @@ plus_option(char *option, isc_boolean_t is_batchfile,
|
|||||||
default:
|
default:
|
||||||
invalid_option:
|
invalid_option:
|
||||||
need_value:
|
need_value:
|
||||||
#if TARGET_OS_IPHONE
|
|
||||||
exit_or_usage:
|
|
||||||
#endif
|
|
||||||
fprintf(stderr, "Invalid option: +%s\n",
|
fprintf(stderr, "Invalid option: +%s\n",
|
||||||
option);
|
option);
|
||||||
usage();
|
usage();
|
||||||
}
|
}
|
||||||
return;
|
return;
|
||||||
|
|
||||||
#if ! TARGET_OS_IPHONE
|
|
||||||
exit_or_usage:
|
|
||||||
digexit();
|
|
||||||
#endif
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -1540,7 +1468,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
|||||||
isc_boolean_t config_only, int argc, char **argv,
|
isc_boolean_t config_only, int argc, char **argv,
|
||||||
isc_boolean_t *firstarg)
|
isc_boolean_t *firstarg)
|
||||||
{
|
{
|
||||||
char opt, *value, *ptr, *ptr2, *ptr3, *last;
|
char opt, *value, *ptr, *ptr2, *ptr3;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_boolean_t value_from_next;
|
isc_boolean_t value_from_next;
|
||||||
isc_textregion_t tr;
|
isc_textregion_t tr;
|
||||||
@@ -1754,13 +1682,15 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
|||||||
value);
|
value);
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
case 'y':
|
case 'y':
|
||||||
if ((ptr = strtok_r(value, ":", &last)) == NULL) {
|
ptr = next_token(&value, ":"); /* hmac type or name */
|
||||||
|
if (ptr == NULL) {
|
||||||
usage();
|
usage();
|
||||||
}
|
}
|
||||||
if ((ptr2 = strtok_r(NULL, ":", &last)) == NULL) { /* name or secret */
|
ptr2 = next_token(&value, ":"); /* name or secret */
|
||||||
|
if (ptr2 == NULL)
|
||||||
usage();
|
usage();
|
||||||
}
|
ptr3 = next_token(&value, ":"); /* secret or NULL */
|
||||||
if ((ptr3 = strtok_r(NULL, ":", &last)) != NULL) { /* secret or NULL */
|
if (ptr3 != NULL) {
|
||||||
parse_hmac(ptr);
|
parse_hmac(ptr);
|
||||||
ptr = ptr2;
|
ptr = ptr2;
|
||||||
ptr2 = ptr3;
|
ptr2 = ptr3;
|
||||||
@@ -1772,7 +1702,6 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
|||||||
#endif
|
#endif
|
||||||
digestbits = 0;
|
digestbits = 0;
|
||||||
}
|
}
|
||||||
/* XXXONDREJ: FIXME */
|
|
||||||
strlcpy(keynametext, ptr, sizeof(keynametext));
|
strlcpy(keynametext, ptr, sizeof(keynametext));
|
||||||
strlcpy(keysecret, ptr2, sizeof(keysecret));
|
strlcpy(keysecret, ptr2, sizeof(keysecret));
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
@@ -1856,22 +1785,6 @@ preparse_args(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static int
|
|
||||||
split_batchline(char *batchline, char **bargv, int len, const char *msg) {
|
|
||||||
int bargc;
|
|
||||||
char *last = NULL;
|
|
||||||
|
|
||||||
REQUIRE(batchline != NULL);
|
|
||||||
|
|
||||||
for (bargc = 1, bargv[bargc] = strtok_r(batchline, " \t\r\n", &last);
|
|
||||||
bargc < len && bargv[bargc];
|
|
||||||
bargv[++bargc] = strtok_r(NULL, " \t\r\n", &last))
|
|
||||||
{
|
|
||||||
debug("%s %d: %s", msg, bargc, bargv[bargc]);
|
|
||||||
}
|
|
||||||
return (bargc);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||||
int argc, char **argv)
|
int argc, char **argv)
|
||||||
@@ -1890,8 +1803,10 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
|||||||
char **rv;
|
char **rv;
|
||||||
#ifndef NOPOSIX
|
#ifndef NOPOSIX
|
||||||
char *homedir;
|
char *homedir;
|
||||||
char rcfile[PATH_MAX];
|
char rcfile[256];
|
||||||
#endif
|
#endif
|
||||||
|
char *input;
|
||||||
|
int i;
|
||||||
isc_boolean_t need_clone = ISC_TRUE;
|
isc_boolean_t need_clone = ISC_TRUE;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -1923,21 +1838,31 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
|||||||
unsigned int n;
|
unsigned int n;
|
||||||
n = snprintf(rcfile, sizeof(rcfile), "%s/.digrc",
|
n = snprintf(rcfile, sizeof(rcfile), "%s/.digrc",
|
||||||
homedir);
|
homedir);
|
||||||
if (n < sizeof(rcfile)) {
|
if (n < sizeof(rcfile))
|
||||||
batchfp = fopen(rcfile, "r");
|
batchfp = fopen(rcfile, "r");
|
||||||
}
|
|
||||||
}
|
}
|
||||||
if (batchfp != NULL) {
|
if (batchfp != NULL) {
|
||||||
while (fgets(batchline, sizeof(batchline),
|
while (fgets(batchline, sizeof(batchline),
|
||||||
batchfp) != 0)
|
batchfp) != 0) {
|
||||||
{
|
|
||||||
debug("config line %s", batchline);
|
debug("config line %s", batchline);
|
||||||
bargc = split_batchline(batchline, bargv, 62,
|
bargc = 1;
|
||||||
".digrc argv");
|
input = batchline;
|
||||||
|
bargv[bargc] = next_token(&input, " \t\r\n");
|
||||||
|
while ((bargv[bargc] != NULL) &&
|
||||||
|
(bargc < 62)) {
|
||||||
|
bargc++;
|
||||||
|
bargv[bargc] =
|
||||||
|
next_token(&input, " \t\r\n");
|
||||||
|
}
|
||||||
|
|
||||||
bargv[0] = argv[0];
|
bargv[0] = argv[0];
|
||||||
argv0 = argv[0];
|
argv0 = argv[0];
|
||||||
parse_args(ISC_TRUE, ISC_TRUE,
|
|
||||||
bargc, (char **)bargv);
|
for(i = 0; i < bargc; i++)
|
||||||
|
debug(".digrc argv %d: %s",
|
||||||
|
i, bargv[i]);
|
||||||
|
parse_args(ISC_TRUE, ISC_TRUE, bargc,
|
||||||
|
(char **)bargv);
|
||||||
}
|
}
|
||||||
fclose(batchfp);
|
fclose(batchfp);
|
||||||
}
|
}
|
||||||
@@ -1948,9 +1873,8 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
|||||||
/* Processing '-f batchfile'. */
|
/* Processing '-f batchfile'. */
|
||||||
lookup = clone_lookup(default_lookup, ISC_TRUE);
|
lookup = clone_lookup(default_lookup, ISC_TRUE);
|
||||||
need_clone = ISC_FALSE;
|
need_clone = ISC_FALSE;
|
||||||
} else {
|
} else
|
||||||
lookup = default_lookup;
|
lookup = default_lookup;
|
||||||
}
|
|
||||||
|
|
||||||
rc = argc;
|
rc = argc;
|
||||||
rv = argv;
|
rv = argv;
|
||||||
@@ -2117,14 +2041,23 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
|||||||
/* XXX Remove code dup from shutdown code */
|
/* XXX Remove code dup from shutdown code */
|
||||||
next_line:
|
next_line:
|
||||||
if (fgets(batchline, sizeof(batchline), batchfp) != 0) {
|
if (fgets(batchline, sizeof(batchline), batchfp) != 0) {
|
||||||
|
bargc = 1;
|
||||||
debug("batch line %s", batchline);
|
debug("batch line %s", batchline);
|
||||||
if (batchline[0] == '\r' || batchline[0] == '\n' ||
|
if (batchline[0] == '\r' || batchline[0] == '\n'
|
||||||
batchline[0] == '#' || batchline[0] == ';')
|
|| batchline[0] == '#' || batchline[0] == ';')
|
||||||
goto next_line;
|
goto next_line;
|
||||||
bargc = split_batchline(batchline, bargv, 14,
|
input = batchline;
|
||||||
"batch argv");
|
bargv[bargc] = next_token(&input, " \t\r\n");
|
||||||
|
while ((bargv[bargc] != NULL) && (bargc < 14)) {
|
||||||
|
bargc++;
|
||||||
|
bargv[bargc] = next_token(&input, " \t\r\n");
|
||||||
|
}
|
||||||
|
|
||||||
bargv[0] = argv[0];
|
bargv[0] = argv[0];
|
||||||
argv0 = argv[0];
|
argv0 = argv[0];
|
||||||
|
|
||||||
|
for(i = 0; i < bargc; i++)
|
||||||
|
debug("batch argv %d: %s", i, bargv[i]);
|
||||||
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -2163,6 +2096,8 @@ query_finished(void) {
|
|||||||
char batchline[MXNAME];
|
char batchline[MXNAME];
|
||||||
int bargc;
|
int bargc;
|
||||||
char *bargv[16];
|
char *bargv[16];
|
||||||
|
char *input;
|
||||||
|
int i;
|
||||||
|
|
||||||
if (batchname == NULL) {
|
if (batchname == NULL) {
|
||||||
isc_app_shutdown();
|
isc_app_shutdown();
|
||||||
@@ -2180,8 +2115,18 @@ query_finished(void) {
|
|||||||
|
|
||||||
if (fgets(batchline, sizeof(batchline), batchfp) != 0) {
|
if (fgets(batchline, sizeof(batchline), batchfp) != 0) {
|
||||||
debug("batch line %s", batchline);
|
debug("batch line %s", batchline);
|
||||||
bargc = split_batchline(batchline, bargv, 14, "batch argv");
|
bargc = 1;
|
||||||
|
input = batchline;
|
||||||
|
bargv[bargc] = next_token(&input, " \t\r\n");
|
||||||
|
while ((bargv[bargc] != NULL) && (bargc < 14)) {
|
||||||
|
bargc++;
|
||||||
|
bargv[bargc] = next_token(&input, " \t\r\n");
|
||||||
|
}
|
||||||
|
|
||||||
bargv[0] = argv0;
|
bargv[0] = argv0;
|
||||||
|
|
||||||
|
for(i = 0; i < bargc; i++)
|
||||||
|
debug("batch argv %d: %s", i, bargv[i]);
|
||||||
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
parse_args(ISC_TRUE, ISC_FALSE, bargc, (char **)bargv);
|
||||||
start_lookup();
|
start_lookup();
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
+20
-82
@@ -1,14 +1,11 @@
|
|||||||
<!DOCTYPE book [
|
<!DOCTYPE book [
|
||||||
<!ENTITY mdash "—">]>
|
<!ENTITY mdash "—">]>
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -51,7 +48,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -275,9 +271,9 @@
|
|||||||
<term>-i</term>
|
<term>-i</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Do reverse IPv6 lookups using the obsolete RFC 1886 IP6.INT
|
Do reverse IPv6 lookups using the obsolete RFC1886 IP6.INT
|
||||||
domain, which is no longer in use. Obsolete bit string
|
domain, which is no longer in use. Obsolete bit string
|
||||||
label queries (RFC 2874) are not attempted.
|
label queries (RFC2874) are not attempted.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -338,12 +334,11 @@
|
|||||||
<term>-t <replaceable class="parameter">type</replaceable></term>
|
<term>-t <replaceable class="parameter">type</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
The resource record type to query. It can be any valid query
|
The resource record type to query. It can be any valid query type
|
||||||
type. If it is a resource record type supported in BIND 9, it
|
which is
|
||||||
can be given by the type mnemonic (such as "NS" or "AAAA").
|
supported in BIND 9. The default query type is "A", unless the
|
||||||
The default query type is "A", unless the <option>-x</option>
|
<option>-x</option> option is supplied to indicate a reverse lookup.
|
||||||
option is supplied to indicate a reverse lookup. A zone
|
A zone transfer can be requested by specifying a type of AXFR. When
|
||||||
transfer can be requested by specifying a type of AXFR. When
|
|
||||||
an incremental zone transfer (IXFR) is required, set the
|
an incremental zone transfer (IXFR) is required, set the
|
||||||
<parameter>type</parameter> to <literal>ixfr=N</literal>.
|
<parameter>type</parameter> to <literal>ixfr=N</literal>.
|
||||||
The incremental zone transfer will contain the changes
|
The incremental zone transfer will contain the changes
|
||||||
@@ -351,21 +346,6 @@
|
|||||||
record was
|
record was
|
||||||
<parameter>N</parameter>.
|
<parameter>N</parameter>.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
|
||||||
All resource record types can be expressed as "TYPEnn", where
|
|
||||||
"nn" is the number of the type. If the resource record type is
|
|
||||||
not supported in BIND 9, the result will be displayed as
|
|
||||||
described in RFC 3597.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-u</term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Print query times in microseconds instead of milliseconds.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
@@ -783,17 +763,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term><option>+[no]idnin</option></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Process [do not process] IDN domain names on input.
|
|
||||||
This requires IDN SUPPORT to have been enabled at
|
|
||||||
compile time. The default is to process IDN input.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]idnout</option></term>
|
<term><option>+[no]idnout</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -815,15 +784,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term><option>+[no]keepalive</option></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Send [or do not send] an EDNS Keepalive option.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]keepopen</option></term>
|
<term><option>+[no]keepopen</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -895,8 +855,7 @@
|
|||||||
attempts to find the authoritative name servers for
|
attempts to find the authoritative name servers for
|
||||||
the zone containing the name being looked up and
|
the zone containing the name being looked up and
|
||||||
display the SOA record that each name server has for
|
display the SOA record that each name server has for
|
||||||
the zone. Addresses of servers that that did not
|
the zone.
|
||||||
respond are also printed.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -960,17 +919,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term><option>+[no]raflag</option></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Set [do not set] the RA (Recursion Available) bit in
|
|
||||||
the query. The default is +noraflag. This bit should
|
|
||||||
be ignored by the server for QUERY.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]rdflag</option></term>
|
<term><option>+[no]rdflag</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -1062,7 +1010,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
This feature is now obsolete and has been removed;
|
This feature is now obsolete and has been removed;
|
||||||
use <command>delv</command> instead.
|
use <command>delv</command> instead.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1114,17 +1062,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term><option>+[no]tcflag</option></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Set [do not set] the TC (TrunCation) bit in the query.
|
|
||||||
The default is +notcflag. This bit should be ignored
|
|
||||||
by the server for QUERY.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]tcp</option></term>
|
<term><option>+[no]tcp</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -1158,8 +1095,8 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
This feature is related to <command>dig +sigchase</command>,
|
This feature is related to <command>dig +sigchase</command>,
|
||||||
which is obsolete and has been removed. Use
|
which is obsolete and has been removed. Use
|
||||||
<command>delv</command> instead.
|
<command>delv</command> instead.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1204,9 +1141,9 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Formerly specified trusted keys for use with
|
Formerly specified trusted keys for use with
|
||||||
<command>dig +sigchase</command>. This feature is now
|
<command>dig +sigchase</command>. This feature is now
|
||||||
obsolete and has been removed; use
|
obsolete and has been removed; use
|
||||||
<command>delv</command> instead.
|
<command>delv</command> instead.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1328,9 +1265,10 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
|||||||
<command>dig</command> appropriately converts character encoding of
|
<command>dig</command> appropriately converts character encoding of
|
||||||
domain name before sending a request to DNS server or displaying a
|
domain name before sending a request to DNS server or displaying a
|
||||||
reply from the server.
|
reply from the server.
|
||||||
If you'd like to turn off the IDN support for some reason, use
|
If you'd like to turn off the IDN support for some reason, defines
|
||||||
parameters <parameter>+noidnin</parameter> and
|
the <envar>IDN_DISABLE</envar> environment variable.
|
||||||
<parameter>+noidnout</parameter>.
|
The IDN support is disabled if the variable is set when
|
||||||
|
<command>dig</command> runs.
|
||||||
</para>
|
</para>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
@@ -1356,7 +1294,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
|||||||
<citerefentry>
|
<citerefentry>
|
||||||
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
|
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
|
||||||
</citerefentry>,
|
</citerefentry>,
|
||||||
<citetitle>RFC 1035</citetitle>.
|
<citetitle>RFC1035</citetitle>.
|
||||||
</para>
|
</para>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
|
|||||||
+20
-63
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2011, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -230,9 +230,9 @@
|
|||||||
<dt><span class="term">-i</span></dt>
|
<dt><span class="term">-i</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Do reverse IPv6 lookups using the obsolete RFC 1886 IP6.INT
|
Do reverse IPv6 lookups using the obsolete RFC1886 IP6.INT
|
||||||
domain, which is no longer in use. Obsolete bit string
|
domain, which is no longer in use. Obsolete bit string
|
||||||
label queries (RFC 2874) are not attempted.
|
label queries (RFC2874) are not attempted.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-k <em class="replaceable"><code>keyfile</code></em></span></dt>
|
<dt><span class="term">-k <em class="replaceable"><code>keyfile</code></em></span></dt>
|
||||||
@@ -277,12 +277,11 @@
|
|||||||
<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
|
<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
The resource record type to query. It can be any valid query
|
The resource record type to query. It can be any valid query type
|
||||||
type. If it is a resource record type supported in BIND 9, it
|
which is
|
||||||
can be given by the type mnemonic (such as "NS" or "AAAA").
|
supported in BIND 9. The default query type is "A", unless the
|
||||||
The default query type is "A", unless the <code class="option">-x</code>
|
<code class="option">-x</code> option is supplied to indicate a reverse lookup.
|
||||||
option is supplied to indicate a reverse lookup. A zone
|
A zone transfer can be requested by specifying a type of AXFR. When
|
||||||
transfer can be requested by specifying a type of AXFR. When
|
|
||||||
an incremental zone transfer (IXFR) is required, set the
|
an incremental zone transfer (IXFR) is required, set the
|
||||||
<em class="parameter"><code>type</code></em> to <code class="literal">ixfr=N</code>.
|
<em class="parameter"><code>type</code></em> to <code class="literal">ixfr=N</code>.
|
||||||
The incremental zone transfer will contain the changes
|
The incremental zone transfer will contain the changes
|
||||||
@@ -290,18 +289,6 @@
|
|||||||
record was
|
record was
|
||||||
<em class="parameter"><code>N</code></em>.
|
<em class="parameter"><code>N</code></em>.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
|
||||||
All resource record types can be expressed as "TYPEnn", where
|
|
||||||
"nn" is the number of the type. If the resource record type is
|
|
||||||
not supported in BIND 9, the result will be displayed as
|
|
||||||
described in RFC 3597.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-u</span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Print query times in microseconds instead of milliseconds.
|
|
||||||
</p>
|
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-v</span></dt>
|
<dt><span class="term">-v</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
@@ -626,14 +613,6 @@
|
|||||||
server that provided the answer.
|
server that provided the answer.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]idnin</code></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Process [do not process] IDN domain names on input.
|
|
||||||
This requires IDN SUPPORT to have been enabled at
|
|
||||||
compile time. The default is to process IDN input.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term"><code class="option">+[no]idnout</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]idnout</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -649,12 +628,6 @@
|
|||||||
with TCP. By default, TCP retries are performed.
|
with TCP. By default, TCP retries are performed.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]keepalive</code></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Send [or do not send] an EDNS Keepalive option.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]keepopen</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -710,8 +683,7 @@
|
|||||||
attempts to find the authoritative name servers for
|
attempts to find the authoritative name servers for
|
||||||
the zone containing the name being looked up and
|
the zone containing the name being looked up and
|
||||||
display the SOA record that each name server has for
|
display the SOA record that each name server has for
|
||||||
the zone. Addresses of servers that that did not
|
the zone.
|
||||||
respond are also printed.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]onesoa</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]onesoa</code></span></dt>
|
||||||
@@ -758,14 +730,6 @@
|
|||||||
the question section as a comment.
|
the question section as a comment.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]raflag</code></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Set [do not set] the RA (Recursion Available) bit in
|
|
||||||
the query. The default is +noraflag. This bit should
|
|
||||||
be ignored by the server for QUERY.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term"><code class="option">+[no]rdflag</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]rdflag</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -835,7 +799,7 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
This feature is now obsolete and has been removed;
|
This feature is now obsolete and has been removed;
|
||||||
use <span class="command"><strong>delv</strong></span> instead.
|
use <span class="command"><strong>delv</strong></span> instead.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+split=W</code></span></dt>
|
<dt><span class="term"><code class="option">+split=W</code></span></dt>
|
||||||
@@ -876,14 +840,6 @@
|
|||||||
this query.
|
this query.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]tcflag</code></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Set [do not set] the TC (TrunCation) bit in the query.
|
|
||||||
The default is +notcflag. This bit should be ignored
|
|
||||||
by the server for QUERY.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -910,8 +866,8 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
This feature is related to <span class="command"><strong>dig +sigchase</strong></span>,
|
This feature is related to <span class="command"><strong>dig +sigchase</strong></span>,
|
||||||
which is obsolete and has been removed. Use
|
which is obsolete and has been removed. Use
|
||||||
<span class="command"><strong>delv</strong></span> instead.
|
<span class="command"><strong>delv</strong></span> instead.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]trace</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]trace</code></span></dt>
|
||||||
@@ -947,9 +903,9 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Formerly specified trusted keys for use with
|
Formerly specified trusted keys for use with
|
||||||
<span class="command"><strong>dig +sigchase</strong></span>. This feature is now
|
<span class="command"><strong>dig +sigchase</strong></span>. This feature is now
|
||||||
obsolete and has been removed; use
|
obsolete and has been removed; use
|
||||||
<span class="command"><strong>delv</strong></span> instead.
|
<span class="command"><strong>delv</strong></span> instead.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]ttlid</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]ttlid</code></span></dt>
|
||||||
@@ -1059,9 +1015,10 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
|||||||
<span class="command"><strong>dig</strong></span> appropriately converts character encoding of
|
<span class="command"><strong>dig</strong></span> appropriately converts character encoding of
|
||||||
domain name before sending a request to DNS server or displaying a
|
domain name before sending a request to DNS server or displaying a
|
||||||
reply from the server.
|
reply from the server.
|
||||||
If you'd like to turn off the IDN support for some reason, use
|
If you'd like to turn off the IDN support for some reason, defines
|
||||||
parameters <em class="parameter"><code>+noidnin</code></em> and
|
the <code class="envar">IDN_DISABLE</code> environment variable.
|
||||||
<em class="parameter"><code>+noidnout</code></em>.
|
The IDN support is disabled if the variable is set when
|
||||||
|
<span class="command"><strong>dig</strong></span> runs.
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -1089,7 +1046,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
|||||||
<span class="citerefentry">
|
<span class="citerefentry">
|
||||||
<span class="refentrytitle">dnssec-keygen</span>(8)
|
<span class="refentrytitle">dnssec-keygen</span>(8)
|
||||||
</span>,
|
</span>,
|
||||||
<em class="citetitle">RFC 1035</em>.
|
<em class="citetitle">RFC1035</em>.
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
|||||||
+213
-329
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file
|
/*! \file
|
||||||
@@ -24,18 +21,17 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
#include <limits.h>
|
#include <limits.h>
|
||||||
#include <errno.h>
|
|
||||||
|
|
||||||
#ifdef HAVE_LOCALE_H
|
#ifdef HAVE_LOCALE_H
|
||||||
#include <locale.h>
|
#include <locale.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
#ifdef WITH_IDN
|
||||||
|
#include <idn/result.h>
|
||||||
#ifdef WITH_LIBIDN2
|
#include <idn/log.h>
|
||||||
#include <idn2.h>
|
#include <idn/resconf.h>
|
||||||
|
#include <idn/api.h>
|
||||||
#endif
|
#endif
|
||||||
#endif /* WITH_IDN_SUPPORT */
|
|
||||||
|
|
||||||
#include <dns/byaddr.h>
|
#include <dns/byaddr.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
@@ -57,6 +53,7 @@
|
|||||||
|
|
||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hex.h>
|
#include <isc/hex.h>
|
||||||
#include <isc/lang.h>
|
#include <isc/lang.h>
|
||||||
@@ -86,7 +83,7 @@
|
|||||||
|
|
||||||
#include <dig/dig.h>
|
#include <dig/dig.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -134,23 +131,18 @@ int lookup_counter = 0;
|
|||||||
|
|
||||||
static char servercookie[256];
|
static char servercookie[256];
|
||||||
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
#ifdef WITH_IDN
|
||||||
static void idn_initialize(void);
|
static void initialize_idn(void);
|
||||||
static isc_result_t idn_locale_to_ace(const char *from,
|
static isc_result_t output_filter(isc_buffer_t *buffer,
|
||||||
char *to,
|
unsigned int used_org,
|
||||||
size_t tolen);
|
isc_boolean_t absolute);
|
||||||
#endif /* WITH_IDN_SUPPORT */
|
static idn_result_t append_textname(char *name, const char *origin,
|
||||||
|
size_t namesize);
|
||||||
|
static void idn_check_result(idn_result_t r, const char *msg);
|
||||||
|
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
#define MAXDLEN 256
|
||||||
static isc_result_t idn_ace_to_locale(const char *from,
|
int idnoptions = 0;
|
||||||
char *to,
|
#endif
|
||||||
size_t tolen);
|
|
||||||
static isc_result_t output_filter(isc_buffer_t *buffer,
|
|
||||||
unsigned int used_org,
|
|
||||||
isc_boolean_t absolute);
|
|
||||||
#define MAXDLEN 256
|
|
||||||
|
|
||||||
#endif /* WITH_IDN_OUT_SUPPORT */
|
|
||||||
|
|
||||||
isc_socket_t *keep = NULL;
|
isc_socket_t *keep = NULL;
|
||||||
isc_sockaddr_t keepaddr;
|
isc_sockaddr_t keepaddr;
|
||||||
@@ -175,8 +167,9 @@ unsigned char cookie[8];
|
|||||||
const dns_name_t *hmacname = NULL;
|
const dns_name_t *hmacname = NULL;
|
||||||
unsigned int digestbits = 0;
|
unsigned int digestbits = 0;
|
||||||
isc_buffer_t *namebuf = NULL;
|
isc_buffer_t *namebuf = NULL;
|
||||||
dns_tsigkey_t *tsigkey = NULL;
|
dns_tsigkey_t *key = NULL;
|
||||||
isc_boolean_t validated = ISC_TRUE;
|
isc_boolean_t validated = ISC_TRUE;
|
||||||
|
isc_entropy_t *entp = NULL;
|
||||||
isc_mempool_t *commctx = NULL;
|
isc_mempool_t *commctx = NULL;
|
||||||
isc_boolean_t debugging = ISC_FALSE;
|
isc_boolean_t debugging = ISC_FALSE;
|
||||||
isc_boolean_t debugtiming = ISC_FALSE;
|
isc_boolean_t debugtiming = ISC_FALSE;
|
||||||
@@ -209,7 +202,7 @@ isc_result_t
|
|||||||
isc_boolean_t headers);
|
isc_boolean_t headers);
|
||||||
|
|
||||||
void
|
void
|
||||||
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
(*dighost_received)(int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
||||||
|
|
||||||
void
|
void
|
||||||
(*dighost_trying)(char *frm, dig_lookup_t *lookup);
|
(*dighost_trying)(char *frm, dig_lookup_t *lookup);
|
||||||
@@ -240,6 +233,18 @@ check_next_lookup(dig_lookup_t *lookup);
|
|||||||
static isc_boolean_t
|
static isc_boolean_t
|
||||||
next_origin(dig_lookup_t *oldlookup);
|
next_origin(dig_lookup_t *oldlookup);
|
||||||
|
|
||||||
|
char *
|
||||||
|
next_token(char **stringp, const char *delim) {
|
||||||
|
char *res;
|
||||||
|
|
||||||
|
do {
|
||||||
|
res = strsep(stringp, delim);
|
||||||
|
if (res == NULL)
|
||||||
|
break;
|
||||||
|
} while (*res == '\0');
|
||||||
|
return (res);
|
||||||
|
}
|
||||||
|
|
||||||
static int
|
static int
|
||||||
count_dots(char *string) {
|
count_dots(char *string) {
|
||||||
char *s;
|
char *s;
|
||||||
@@ -261,7 +266,7 @@ hex_dump(isc_buffer_t *b) {
|
|||||||
|
|
||||||
isc_buffer_usedregion(b, &r);
|
isc_buffer_usedregion(b, &r);
|
||||||
|
|
||||||
printf("%u bytes\n", r.length);
|
printf("%d bytes\n", r.length);
|
||||||
for (len = 0; len < r.length; len++) {
|
for (len = 0; len < r.length; len++) {
|
||||||
printf("%02x ", r.base[len]);
|
printf("%02x ", r.base[len]);
|
||||||
if (len % 16 == 15) {
|
if (len % 16 == 15) {
|
||||||
@@ -339,8 +344,9 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
|||||||
|
|
||||||
if (ip6_int)
|
if (ip6_int)
|
||||||
options |= DNS_BYADDROPT_IPV6INT;
|
options |= DNS_BYADDROPT_IPV6INT;
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
result = dns_byaddr_createptrname(&addr, options, name);
|
name = dns_fixedname_name(&fname);
|
||||||
|
result = dns_byaddr_createptrname2(&addr, options, name);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
return (result);
|
return (result);
|
||||||
dns_name_format(name, reverse, (unsigned int)len);
|
dns_name_format(name, reverse, (unsigned int)len);
|
||||||
@@ -369,46 +375,6 @@ get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
void (*dighost_pre_exit_hook)(void) = NULL;
|
|
||||||
|
|
||||||
#if TARGET_OS_IPHONE
|
|
||||||
void
|
|
||||||
warn(const char *format, ...) {
|
|
||||||
va_list args;
|
|
||||||
|
|
||||||
fflush(stdout);
|
|
||||||
fprintf(stderr, ";; Warning: ");
|
|
||||||
va_start(args, format);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
va_end(args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
}
|
|
||||||
#else
|
|
||||||
void
|
|
||||||
warn(const char *format, ...) {
|
|
||||||
va_list args;
|
|
||||||
|
|
||||||
fflush(stdout);
|
|
||||||
fprintf(stderr, "%s: ", progname);
|
|
||||||
va_start(args, format);
|
|
||||||
vfprintf(stderr, format, args);
|
|
||||||
va_end(args);
|
|
||||||
fprintf(stderr, "\n");
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
void
|
|
||||||
digexit(void) {
|
|
||||||
if (exitcode < 10)
|
|
||||||
exitcode = 10;
|
|
||||||
if (fatalexit != 0)
|
|
||||||
exitcode = fatalexit;
|
|
||||||
if (dighost_pre_exit_hook != NULL) {
|
|
||||||
dighost_pre_exit_hook();
|
|
||||||
}
|
|
||||||
exit(exitcode);
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
void
|
||||||
fatal(const char *format, ...) {
|
fatal(const char *format, ...) {
|
||||||
va_list args;
|
va_list args;
|
||||||
@@ -419,7 +385,11 @@ fatal(const char *format, ...) {
|
|||||||
vfprintf(stderr, format, args);
|
vfprintf(stderr, format, args);
|
||||||
va_end(args);
|
va_end(args);
|
||||||
fprintf(stderr, "\n");
|
fprintf(stderr, "\n");
|
||||||
digexit();
|
if (exitcode < 10)
|
||||||
|
exitcode = 10;
|
||||||
|
if (fatalexit != 0)
|
||||||
|
exitcode = fatalexit;
|
||||||
|
exit(exitcode);
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void
|
||||||
@@ -431,7 +401,7 @@ debug(const char *format, ...) {
|
|||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (debugtiming) {
|
if (debugtiming) {
|
||||||
TIME_NOW(&t);
|
TIME_NOW(&t);
|
||||||
fprintf(stderr, "%u.%06u: ", isc_time_seconds(&t),
|
fprintf(stderr, "%d.%06d: ", isc_time_seconds(&t),
|
||||||
isc_time_nanoseconds(&t) / 1000);
|
isc_time_nanoseconds(&t) / 1000);
|
||||||
}
|
}
|
||||||
va_start(args, format);
|
va_start(args, format);
|
||||||
@@ -637,12 +607,7 @@ make_empty_lookup(void) {
|
|||||||
looknew->ttlunits = ISC_FALSE;
|
looknew->ttlunits = ISC_FALSE;
|
||||||
looknew->ttlunits = ISC_FALSE;
|
looknew->ttlunits = ISC_FALSE;
|
||||||
looknew->qr = ISC_FALSE;
|
looknew->qr = ISC_FALSE;
|
||||||
#ifdef WITH_IDN_SUPPORT
|
#ifdef WITH_IDN
|
||||||
looknew->idnin = ISC_TRUE;
|
|
||||||
#else
|
|
||||||
looknew->idnin = ISC_FALSE;
|
|
||||||
#endif
|
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
|
||||||
looknew->idnout = ISC_TRUE;
|
looknew->idnout = ISC_TRUE;
|
||||||
#else
|
#else
|
||||||
looknew->idnout = ISC_FALSE;
|
looknew->idnout = ISC_FALSE;
|
||||||
@@ -653,8 +618,6 @@ make_empty_lookup(void) {
|
|||||||
looknew->aaonly = ISC_FALSE;
|
looknew->aaonly = ISC_FALSE;
|
||||||
looknew->adflag = ISC_FALSE;
|
looknew->adflag = ISC_FALSE;
|
||||||
looknew->cdflag = ISC_FALSE;
|
looknew->cdflag = ISC_FALSE;
|
||||||
looknew->raflag = ISC_FALSE;
|
|
||||||
looknew->tcflag = ISC_FALSE;
|
|
||||||
looknew->print_unknown_format = ISC_FALSE;
|
looknew->print_unknown_format = ISC_FALSE;
|
||||||
looknew->zflag = ISC_FALSE;
|
looknew->zflag = ISC_FALSE;
|
||||||
looknew->ns_search_only = ISC_FALSE;
|
looknew->ns_search_only = ISC_FALSE;
|
||||||
@@ -692,41 +655,6 @@ make_empty_lookup(void) {
|
|||||||
return (looknew);
|
return (looknew);
|
||||||
}
|
}
|
||||||
|
|
||||||
#define EDNSOPT_OPTIONS 100U
|
|
||||||
|
|
||||||
static void
|
|
||||||
cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
|
||||||
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
|
||||||
size_t i;
|
|
||||||
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
|
||||||
if (looknew->ednsopts == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
|
||||||
looknew->ednsopts[i].code = 0;
|
|
||||||
looknew->ednsopts[i].length = 0;
|
|
||||||
looknew->ednsopts[i].value = NULL;
|
|
||||||
}
|
|
||||||
looknew->ednsoptscnt = 0;
|
|
||||||
if (lookold == NULL || lookold->ednsopts == NULL)
|
|
||||||
return;
|
|
||||||
|
|
||||||
for (i = 0; i < lookold->ednsoptscnt; i++) {
|
|
||||||
len = lookold->ednsopts[i].length;
|
|
||||||
if (len != 0) {
|
|
||||||
INSIST(lookold->ednsopts[i].value != NULL);
|
|
||||||
looknew->ednsopts[i].value =
|
|
||||||
isc_mem_allocate(mctx, len);
|
|
||||||
if (looknew->ednsopts[i].value == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
memmove(looknew->ednsopts[i].value,
|
|
||||||
lookold->ednsopts[i].value, len);
|
|
||||||
}
|
|
||||||
looknew->ednsopts[i].code = lookold->ednsopts[i].code;
|
|
||||||
looknew->ednsopts[i].length = len;
|
|
||||||
}
|
|
||||||
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
|
||||||
}
|
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Clone a lookup, perhaps copying the server list. This does not clone
|
* Clone a lookup, perhaps copying the server list. This does not clone
|
||||||
* the query list, since it will be regenerated by the setup_lookup()
|
* the query list, since it will be regenerated by the setup_lookup()
|
||||||
@@ -772,12 +700,8 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
|||||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||||
looknew->badcookie = lookold->badcookie;
|
looknew->badcookie = lookold->badcookie;
|
||||||
looknew->cookie = lookold->cookie;
|
looknew->cookie = lookold->cookie;
|
||||||
if (lookold->ednsopts != NULL) {
|
looknew->ednsopts = lookold->ednsopts;
|
||||||
cloneopts(looknew, lookold);
|
looknew->ednsoptscnt = lookold->ednsoptscnt;
|
||||||
} else {
|
|
||||||
looknew->ednsopts = NULL;
|
|
||||||
looknew->ednsoptscnt = 0;
|
|
||||||
}
|
|
||||||
looknew->ednsneg = lookold->ednsneg;
|
looknew->ednsneg = lookold->ednsneg;
|
||||||
looknew->padding = lookold->padding;
|
looknew->padding = lookold->padding;
|
||||||
looknew->mapped = lookold->mapped;
|
looknew->mapped = lookold->mapped;
|
||||||
@@ -789,7 +713,6 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
|||||||
looknew->nocrypto = lookold->nocrypto;
|
looknew->nocrypto = lookold->nocrypto;
|
||||||
looknew->ttlunits = lookold->ttlunits;
|
looknew->ttlunits = lookold->ttlunits;
|
||||||
looknew->qr = lookold->qr;
|
looknew->qr = lookold->qr;
|
||||||
looknew->idnin = lookold->idnin;
|
|
||||||
looknew->idnout = lookold->idnout;
|
looknew->idnout = lookold->idnout;
|
||||||
looknew->udpsize = lookold->udpsize;
|
looknew->udpsize = lookold->udpsize;
|
||||||
looknew->edns = lookold->edns;
|
looknew->edns = lookold->edns;
|
||||||
@@ -797,8 +720,6 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
|||||||
looknew->aaonly = lookold->aaonly;
|
looknew->aaonly = lookold->aaonly;
|
||||||
looknew->adflag = lookold->adflag;
|
looknew->adflag = lookold->adflag;
|
||||||
looknew->cdflag = lookold->cdflag;
|
looknew->cdflag = lookold->cdflag;
|
||||||
looknew->raflag = lookold->raflag;
|
|
||||||
looknew->tcflag = lookold->tcflag;
|
|
||||||
looknew->print_unknown_format = lookold->print_unknown_format;
|
looknew->print_unknown_format = lookold->print_unknown_format;
|
||||||
looknew->zflag = lookold->zflag;
|
looknew->zflag = lookold->zflag;
|
||||||
looknew->ns_search_only = lookold->ns_search_only;
|
looknew->ns_search_only = lookold->ns_search_only;
|
||||||
@@ -903,13 +824,13 @@ setup_text_key(void) {
|
|||||||
|
|
||||||
result = dns_tsigkey_create(&keyname, hmacname, secretstore,
|
result = dns_tsigkey_create(&keyname, hmacname, secretstore,
|
||||||
(int)secretsize, ISC_FALSE, NULL, 0, 0,
|
(int)secretsize, ISC_FALSE, NULL, 0, 0,
|
||||||
mctx, NULL, &tsigkey);
|
mctx, NULL, &key);
|
||||||
failure:
|
failure:
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
printf(";; Couldn't create key %s: %s\n",
|
printf(";; Couldn't create key %s: %s\n",
|
||||||
keynametext, isc_result_totext(result));
|
keynametext, isc_result_totext(result));
|
||||||
else
|
else
|
||||||
dst_key_setbits(tsigkey->key, digestbits);
|
dst_key_setbits(key->key, digestbits);
|
||||||
|
|
||||||
isc_mem_free(mctx, secretstore);
|
isc_mem_free(mctx, secretstore);
|
||||||
dns_name_invalidate(&keyname);
|
dns_name_invalidate(&keyname);
|
||||||
@@ -1196,7 +1117,7 @@ setup_file_key(void) {
|
|||||||
}
|
}
|
||||||
result = dns_tsigkey_createfromkey(dst_key_name(dstkey), hmacname,
|
result = dns_tsigkey_createfromkey(dst_key_name(dstkey), hmacname,
|
||||||
dstkey, ISC_FALSE, NULL, 0, 0,
|
dstkey, ISC_FALSE, NULL, 0, 0,
|
||||||
mctx, NULL, &tsigkey);
|
mctx, NULL, &key);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
printf(";; Couldn't create key %s: %s\n",
|
printf(";; Couldn't create key %s: %s\n",
|
||||||
keynametext, isc_result_totext(result));
|
keynametext, isc_result_totext(result));
|
||||||
@@ -1295,27 +1216,18 @@ setup_system(isc_boolean_t ipv4only, isc_boolean_t ipv6only) {
|
|||||||
|
|
||||||
irs_resconf_destroy(&resconf);
|
irs_resconf_destroy(&resconf);
|
||||||
|
|
||||||
#ifdef HAVE_SETLOCALE
|
#ifdef WITH_IDN
|
||||||
/* Set locale */
|
initialize_idn();
|
||||||
(void)setlocale(LC_ALL, "");
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
|
||||||
idn_initialize();
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
|
||||||
/* Set domain name -> text post-conversion filter. */
|
|
||||||
result = dns_name_settotextfilter(output_filter);
|
|
||||||
check_result(result, "dns_name_settotextfilter");
|
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (keyfile[0] != 0)
|
if (keyfile[0] != 0)
|
||||||
setup_file_key();
|
setup_file_key();
|
||||||
else if (keysecret[0] != 0)
|
else if (keysecret[0] != 0)
|
||||||
setup_text_key();
|
setup_text_key();
|
||||||
|
result = isc_entropy_getdata(entp, cookie_secret,
|
||||||
isc_random_buf(cookie_secret, sizeof(cookie_secret));
|
sizeof(cookie_secret), NULL, 0);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("unable to generate cookie secret");
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -1340,7 +1252,7 @@ setup_libs(void) {
|
|||||||
|
|
||||||
debug("setup_libs()");
|
debug("setup_libs()");
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -1384,7 +1296,10 @@ setup_libs(void) {
|
|||||||
result = isc_socketmgr_create(mctx, &socketmgr);
|
result = isc_socketmgr_create(mctx, &socketmgr);
|
||||||
check_result(result, "isc_socketmgr_create");
|
check_result(result, "isc_socketmgr_create");
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
result = isc_entropy_create(mctx, &entp);
|
||||||
|
check_result(result, "isc_entropy_create");
|
||||||
|
|
||||||
|
result = dst_lib_init(mctx, entp, 0);
|
||||||
check_result(result, "dst_lib_init");
|
check_result(result, "dst_lib_init");
|
||||||
is_dst_up = ISC_TRUE;
|
is_dst_up = ISC_TRUE;
|
||||||
|
|
||||||
@@ -1402,6 +1317,13 @@ setup_libs(void) {
|
|||||||
check_result(result, "isc_mutex_init");
|
check_result(result, "isc_mutex_init");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Array of up to 100 options configured by +ednsopt
|
||||||
|
*/
|
||||||
|
#define EDNSOPT_OPTIONS 100U
|
||||||
|
static dns_ednsopt_t ednsopts[EDNSOPT_OPTIONS];
|
||||||
|
static unsigned char ednsoptscnt = 0;
|
||||||
|
|
||||||
typedef struct dig_ednsoptname {
|
typedef struct dig_ednsoptname {
|
||||||
isc_uint32_t code;
|
isc_uint32_t code;
|
||||||
const char *name;
|
const char *name;
|
||||||
@@ -1428,12 +1350,12 @@ dig_ednsoptname_t optnames[] = {
|
|||||||
void
|
void
|
||||||
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_uint32_t num = 0;
|
isc_uint32_t num;
|
||||||
isc_buffer_t b;
|
isc_buffer_t b;
|
||||||
isc_boolean_t found = ISC_FALSE;
|
isc_boolean_t found = ISC_FALSE;
|
||||||
unsigned int i;
|
unsigned int i;
|
||||||
|
|
||||||
if (lookup->ednsoptscnt >= EDNSOPT_OPTIONS)
|
if (ednsoptscnt == EDNSOPT_OPTIONS)
|
||||||
fatal("too many ednsopts");
|
fatal("too many ednsopts");
|
||||||
|
|
||||||
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
for (i = 0; i < N_EDNS_OPTNAMES; i++) {
|
||||||
@@ -1450,16 +1372,9 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
|||||||
fatal("bad edns code point: %s", code);
|
fatal("bad edns code point: %s", code);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (lookup->ednsopts == NULL) {
|
ednsopts[ednsoptscnt].code = num;
|
||||||
cloneopts(lookup, NULL);
|
ednsopts[ednsoptscnt].length = 0;
|
||||||
}
|
ednsopts[ednsoptscnt].value = NULL;
|
||||||
|
|
||||||
if (lookup->ednsopts[lookup->ednsoptscnt].value != NULL)
|
|
||||||
isc_mem_free(mctx, lookup->ednsopts[lookup->ednsoptscnt].value);
|
|
||||||
|
|
||||||
lookup->ednsopts[lookup->ednsoptscnt].code = num;
|
|
||||||
lookup->ednsopts[lookup->ednsoptscnt].length = 0;
|
|
||||||
lookup->ednsopts[lookup->ednsoptscnt].value = NULL;
|
|
||||||
|
|
||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
char *buf;
|
char *buf;
|
||||||
@@ -1469,13 +1384,14 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
|||||||
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
||||||
result = isc_hex_decodestring(value, &b);
|
result = isc_hex_decodestring(value, &b);
|
||||||
check_result(result, "isc_hex_decodestring");
|
check_result(result, "isc_hex_decodestring");
|
||||||
lookup->ednsopts[lookup->ednsoptscnt].value =
|
ednsopts[ednsoptscnt].value = isc_buffer_base(&b);
|
||||||
isc_buffer_base(&b);
|
ednsopts[ednsoptscnt].length = isc_buffer_usedlength(&b);
|
||||||
lookup->ednsopts[lookup->ednsoptscnt].length =
|
|
||||||
isc_buffer_usedlength(&b);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (lookup->ednsoptscnt == 0)
|
||||||
|
lookup->ednsopts = &ednsopts[ednsoptscnt];
|
||||||
lookup->ednsoptscnt++;
|
lookup->ednsoptscnt++;
|
||||||
|
ednsoptscnt++;
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -1654,15 +1570,6 @@ destroy_lookup(dig_lookup_t *lookup) {
|
|||||||
if (lookup->ecs_addr != NULL)
|
if (lookup->ecs_addr != NULL)
|
||||||
isc_mem_free(mctx, lookup->ecs_addr);
|
isc_mem_free(mctx, lookup->ecs_addr);
|
||||||
|
|
||||||
if (lookup->ednsopts != NULL) {
|
|
||||||
size_t i;
|
|
||||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
|
||||||
if (lookup->ednsopts[i].value != NULL)
|
|
||||||
isc_mem_free(mctx, lookup->ednsopts[i].value);
|
|
||||||
}
|
|
||||||
isc_mem_free(mctx, lookup->ednsopts);
|
|
||||||
}
|
|
||||||
|
|
||||||
isc_mem_free(mctx, lookup);
|
isc_mem_free(mctx, lookup);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1870,7 +1777,7 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
|||||||
srv != NULL;
|
srv != NULL;
|
||||||
srv = ISC_LIST_HEAD(lookup->my_server_list)) {
|
srv = ISC_LIST_HEAD(lookup->my_server_list)) {
|
||||||
INSIST(i > 0);
|
INSIST(i > 0);
|
||||||
j = isc_random();
|
isc_random_get(&j);
|
||||||
j %= i;
|
j %= i;
|
||||||
next = ISC_LIST_NEXT(srv, link);
|
next = ISC_LIST_NEXT(srv, link);
|
||||||
while (j-- > 0 && next != NULL) {
|
while (j-- > 0 && next != NULL) {
|
||||||
@@ -1917,7 +1824,8 @@ next_origin(dig_lookup_t *oldlookup) {
|
|||||||
/*
|
/*
|
||||||
* Check for a absolute name or ndots being met.
|
* Check for a absolute name or ndots being met.
|
||||||
*/
|
*/
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
result = dns_name_fromstring2(name, oldlookup->textname, NULL,
|
result = dns_name_fromstring2(name, oldlookup->textname, NULL,
|
||||||
0, NULL);
|
0, NULL);
|
||||||
if (result == ISC_R_SUCCESS &&
|
if (result == ISC_R_SUCCESS &&
|
||||||
@@ -2032,13 +1940,12 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
char store[MXNAME];
|
char store[MXNAME];
|
||||||
char ecsbuf[20];
|
char ecsbuf[20];
|
||||||
char cookiebuf[256];
|
char cookiebuf[256];
|
||||||
char *origin = NULL;
|
#ifdef WITH_IDN
|
||||||
char *textname = NULL;
|
idn_result_t mr;
|
||||||
#ifdef WITH_IDN_SUPPORT
|
char utf8_textname[MXNAME], utf8_origin[MXNAME], idn_textname[MXNAME];
|
||||||
char idn_origin[MXNAME], idn_textname[MXNAME];
|
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
#ifdef WITH_IDN
|
||||||
result = dns_name_settotextfilter(lookup->idnout ?
|
result = dns_name_settotextfilter(lookup->idnout ?
|
||||||
output_filter : NULL);
|
output_filter : NULL);
|
||||||
check_result(result, "dns_name_settotextfilter");
|
check_result(result, "dns_name_settotextfilter");
|
||||||
@@ -2071,19 +1978,15 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
isc_buffer_init(&lookup->onamebuf, lookup->oname_space,
|
isc_buffer_init(&lookup->onamebuf, lookup->oname_space,
|
||||||
sizeof(lookup->oname_space));
|
sizeof(lookup->oname_space));
|
||||||
|
|
||||||
|
#ifdef WITH_IDN
|
||||||
/*
|
/*
|
||||||
* We cannot convert `textname' and `origin' separately.
|
* We cannot convert `textname' and `origin' separately.
|
||||||
* `textname' doesn't contain TLD, but local mapping needs
|
* `textname' doesn't contain TLD, but local mapping needs
|
||||||
* TLD.
|
* TLD.
|
||||||
*/
|
*/
|
||||||
textname = lookup->textname;
|
mr = idn_encodename(IDN_LOCALCONV | IDN_DELIMMAP, lookup->textname,
|
||||||
#ifdef WITH_IDN_SUPPORT
|
utf8_textname, sizeof(utf8_textname));
|
||||||
if (lookup->idnin) {
|
idn_check_result(mr, "convert textname to UTF-8");
|
||||||
result = idn_locale_to_ace(textname, idn_textname, sizeof(idn_textname));
|
|
||||||
check_result(result, "convert textname to IDN encoding");
|
|
||||||
debug("idn_textname: %s", idn_textname);
|
|
||||||
textname = idn_textname;
|
|
||||||
}
|
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -2094,8 +1997,8 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
* is TRUE or we got a domain line in the resolv.conf file.
|
* is TRUE or we got a domain line in the resolv.conf file.
|
||||||
*/
|
*/
|
||||||
if (lookup->new_search) {
|
if (lookup->new_search) {
|
||||||
if ((count_dots(textname) >= ndots) || !usesearch)
|
#ifdef WITH_IDN
|
||||||
{
|
if ((count_dots(utf8_textname) >= ndots) || !usesearch) {
|
||||||
lookup->origin = NULL; /* Force abs lookup */
|
lookup->origin = NULL; /* Force abs lookup */
|
||||||
lookup->done_as_is = ISC_TRUE;
|
lookup->done_as_is = ISC_TRUE;
|
||||||
lookup->need_search = usesearch;
|
lookup->need_search = usesearch;
|
||||||
@@ -2103,8 +2006,33 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
lookup->origin = ISC_LIST_HEAD(search_list);
|
lookup->origin = ISC_LIST_HEAD(search_list);
|
||||||
lookup->need_search = ISC_FALSE;
|
lookup->need_search = ISC_FALSE;
|
||||||
}
|
}
|
||||||
|
#else
|
||||||
|
if ((count_dots(lookup->textname) >= ndots) || !usesearch) {
|
||||||
|
lookup->origin = NULL; /* Force abs lookup */
|
||||||
|
lookup->done_as_is = ISC_TRUE;
|
||||||
|
lookup->need_search = usesearch;
|
||||||
|
} else if (lookup->origin == NULL && usesearch) {
|
||||||
|
lookup->origin = ISC_LIST_HEAD(search_list);
|
||||||
|
lookup->need_search = ISC_FALSE;
|
||||||
|
}
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
if (lookup->origin != NULL) {
|
||||||
|
mr = idn_encodename(IDN_LOCALCONV | IDN_DELIMMAP,
|
||||||
|
lookup->origin->origin, utf8_origin,
|
||||||
|
sizeof(utf8_origin));
|
||||||
|
idn_check_result(mr, "convert origin to UTF-8");
|
||||||
|
mr = append_textname(utf8_textname, utf8_origin,
|
||||||
|
sizeof(utf8_textname));
|
||||||
|
idn_check_result(mr, "append origin to textname");
|
||||||
|
}
|
||||||
|
mr = idn_encodename(idnoptions | IDN_LOCALMAP | IDN_NAMEPREP |
|
||||||
|
IDN_IDNCONV | IDN_LENCHECK, utf8_textname,
|
||||||
|
idn_textname, sizeof(idn_textname));
|
||||||
|
idn_check_result(mr, "convert UTF-8 textname to IDN encoding");
|
||||||
|
#else
|
||||||
if (lookup->origin != NULL) {
|
if (lookup->origin != NULL) {
|
||||||
debug("trying origin %s", lookup->origin->origin);
|
debug("trying origin %s", lookup->origin->origin);
|
||||||
result = dns_message_gettempname(lookup->sendmsg,
|
result = dns_message_gettempname(lookup->sendmsg,
|
||||||
@@ -2112,17 +2040,8 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
check_result(result, "dns_message_gettempname");
|
check_result(result, "dns_message_gettempname");
|
||||||
dns_name_init(lookup->oname, NULL);
|
dns_name_init(lookup->oname, NULL);
|
||||||
/* XXX Helper funct to conv char* to name? */
|
/* XXX Helper funct to conv char* to name? */
|
||||||
origin = lookup->origin->origin;
|
len = (unsigned int) strlen(lookup->origin->origin);
|
||||||
#ifdef WITH_IDN_SUPPORT
|
isc_buffer_init(&b, lookup->origin->origin, len);
|
||||||
if (lookup->idnin) {
|
|
||||||
result = idn_locale_to_ace(origin, idn_origin, sizeof(idn_origin));
|
|
||||||
check_result(result, "convert origin to IDN encoding");
|
|
||||||
debug("trying idn origin %s", idn_origin);
|
|
||||||
origin = idn_origin;
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
len = (unsigned int) strlen(origin);
|
|
||||||
isc_buffer_init(&b, origin, len);
|
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(lookup->oname, &b, dns_rootname,
|
result = dns_name_fromtext(lookup->oname, &b, dns_rootname,
|
||||||
0, &lookup->onamebuf);
|
0, &lookup->onamebuf);
|
||||||
@@ -2132,7 +2051,7 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
dns_message_puttempname(lookup->sendmsg,
|
dns_message_puttempname(lookup->sendmsg,
|
||||||
&lookup->oname);
|
&lookup->oname);
|
||||||
fatal("'%s' is not in legal name syntax (%s)",
|
fatal("'%s' is not in legal name syntax (%s)",
|
||||||
origin,
|
lookup->origin->origin,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
if (lookup->trace && lookup->trace_root) {
|
if (lookup->trace && lookup->trace_root) {
|
||||||
@@ -2141,9 +2060,10 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
dns_fixedname_t fixed;
|
dns_fixedname_t fixed;
|
||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
len = (unsigned int) strlen(textname);
|
name = dns_fixedname_name(&fixed);
|
||||||
isc_buffer_init(&b, textname, len);
|
len = (unsigned int) strlen(lookup->textname);
|
||||||
|
isc_buffer_init(&b, lookup->textname, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(name, &b, NULL, 0, NULL);
|
result = dns_name_fromtext(name, &b, NULL, 0, NULL);
|
||||||
if (result == ISC_R_SUCCESS &&
|
if (result == ISC_R_SUCCESS &&
|
||||||
@@ -2168,37 +2088,42 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
dns_message_puttempname(lookup->sendmsg, &lookup->oname);
|
dns_message_puttempname(lookup->sendmsg, &lookup->oname);
|
||||||
} else {
|
} else
|
||||||
|
#endif
|
||||||
|
{
|
||||||
debug("using root origin");
|
debug("using root origin");
|
||||||
if (lookup->trace && lookup->trace_root)
|
if (lookup->trace && lookup->trace_root)
|
||||||
dns_name_clone(dns_rootname, lookup->name);
|
dns_name_clone(dns_rootname, lookup->name);
|
||||||
else {
|
else {
|
||||||
len = (unsigned int) strlen(textname);
|
#ifdef WITH_IDN
|
||||||
isc_buffer_init(&b, textname, len);
|
len = (unsigned int) strlen(idn_textname);
|
||||||
|
isc_buffer_init(&b, idn_textname, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
result = dns_name_fromtext(lookup->name, &b,
|
result = dns_name_fromtext(lookup->name, &b,
|
||||||
dns_rootname, 0,
|
dns_rootname, 0,
|
||||||
&lookup->namebuf);
|
&lookup->namebuf);
|
||||||
|
#else
|
||||||
|
len = (unsigned int) strlen(lookup->textname);
|
||||||
|
isc_buffer_init(&b, lookup->textname, len);
|
||||||
|
isc_buffer_add(&b, len);
|
||||||
|
result = dns_name_fromtext(lookup->name, &b,
|
||||||
|
dns_rootname, 0,
|
||||||
|
&lookup->namebuf);
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
dns_message_puttempname(lookup->sendmsg,
|
dns_message_puttempname(lookup->sendmsg,
|
||||||
&lookup->name);
|
&lookup->name);
|
||||||
warn("'%s' is not a legal name "
|
fatal("'%s' is not a legal name "
|
||||||
"(%s)", lookup->textname,
|
"(%s)", lookup->textname,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
#if TARGET_OS_IPHONE
|
|
||||||
check_next_lookup(current_lookup);
|
|
||||||
return (ISC_FALSE);
|
|
||||||
#else
|
|
||||||
digexit();
|
|
||||||
#endif
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
dns_name_format(lookup->name, store, sizeof(store));
|
dns_name_format(lookup->name, store, sizeof(store));
|
||||||
dighost_trying(store, lookup);
|
dighost_trying(store, lookup);
|
||||||
INSIST(dns_name_isabsolute(lookup->name));
|
INSIST(dns_name_isabsolute(lookup->name));
|
||||||
|
|
||||||
id = isc_random();
|
isc_random_get(&id);
|
||||||
lookup->sendmsg->id = (unsigned short)id & 0xFFFF;
|
lookup->sendmsg->id = (unsigned short)id & 0xFFFF;
|
||||||
lookup->sendmsg->opcode = lookup->opcode;
|
lookup->sendmsg->opcode = lookup->opcode;
|
||||||
lookup->msgcounter = 0;
|
lookup->msgcounter = 0;
|
||||||
@@ -2232,16 +2157,6 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
lookup->sendmsg->flags |= DNS_MESSAGEFLAG_CD;
|
lookup->sendmsg->flags |= DNS_MESSAGEFLAG_CD;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (lookup->raflag) {
|
|
||||||
debug("RA query");
|
|
||||||
lookup->sendmsg->flags |= DNS_MESSAGEFLAG_RA;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (lookup->tcflag) {
|
|
||||||
debug("TC query");
|
|
||||||
lookup->sendmsg->flags |= DNS_MESSAGEFLAG_TC;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (lookup->zflag) {
|
if (lookup->zflag) {
|
||||||
debug("Z query");
|
debug("Z query");
|
||||||
lookup->sendmsg->flags |= 0x0040U;
|
lookup->sendmsg->flags |= 0x0040U;
|
||||||
@@ -2279,9 +2194,9 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
/* XXX Insist this? */
|
/* XXX Insist this? */
|
||||||
lookup->tsigctx = NULL;
|
lookup->tsigctx = NULL;
|
||||||
lookup->querysig = NULL;
|
lookup->querysig = NULL;
|
||||||
if (tsigkey != NULL) {
|
if (key != NULL) {
|
||||||
debug("initializing keys");
|
debug("initializing keys");
|
||||||
result = dns_message_settsigkey(lookup->sendmsg, tsigkey);
|
result = dns_message_settsigkey(lookup->sendmsg, key);
|
||||||
check_result(result, "dns_message_settsigkey");
|
check_result(result, "dns_message_settsigkey");
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2976,15 +2891,7 @@ connect_timeout(isc_task_t *task, isc_event_t *event) {
|
|||||||
check_next_lookup(l);
|
check_next_lookup(l);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if (l->ns_search_only) {
|
if (!l->ns_search_only) {
|
||||||
isc_netaddr_t netaddr;
|
|
||||||
char buf[ISC_NETADDR_FORMATSIZE];
|
|
||||||
|
|
||||||
isc_netaddr_fromsockaddr(&netaddr, &query->sockaddr);
|
|
||||||
isc_netaddr_format(&netaddr, buf, sizeof(buf));
|
|
||||||
|
|
||||||
printf(";; no response from %s\n", buf);
|
|
||||||
} else {
|
|
||||||
fputs(l->cmdline, stdout);
|
fputs(l->cmdline, stdout);
|
||||||
printf(";; connection timed out; no servers could be "
|
printf(";; connection timed out; no servers could be "
|
||||||
"reached\n");
|
"reached\n");
|
||||||
@@ -3646,7 +3553,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
result = dns_message_create(mctx, DNS_MESSAGE_INTENTPARSE, &msg);
|
result = dns_message_create(mctx, DNS_MESSAGE_INTENTPARSE, &msg);
|
||||||
check_result(result, "dns_message_create");
|
check_result(result, "dns_message_create");
|
||||||
|
|
||||||
if (tsigkey != NULL) {
|
if (key != NULL) {
|
||||||
if (l->querysig == NULL) {
|
if (l->querysig == NULL) {
|
||||||
debug("getting initial querysig");
|
debug("getting initial querysig");
|
||||||
result = dns_message_getquerytsig(l->sendmsg, mctx,
|
result = dns_message_getquerytsig(l->sendmsg, mctx,
|
||||||
@@ -3655,7 +3562,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
}
|
}
|
||||||
result = dns_message_setquerytsig(msg, l->querysig);
|
result = dns_message_setquerytsig(msg, l->querysig);
|
||||||
check_result(result, "dns_message_setquerytsig");
|
check_result(result, "dns_message_setquerytsig");
|
||||||
result = dns_message_settsigkey(msg, tsigkey);
|
result = dns_message_settsigkey(msg, key);
|
||||||
check_result(result, "dns_message_settsigkey");
|
check_result(result, "dns_message_settsigkey");
|
||||||
msg->tsigctx = l->tsigctx;
|
msg->tsigctx = l->tsigctx;
|
||||||
l->tsigctx = NULL;
|
l->tsigctx = NULL;
|
||||||
@@ -3742,7 +3649,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
*/
|
*/
|
||||||
if (l->comments)
|
if (l->comments)
|
||||||
printf(";; BADVERS, retrying with EDNS version %u.\n",
|
printf(";; BADVERS, retrying with EDNS version %u.\n",
|
||||||
(unsigned int)newedns);
|
newedns);
|
||||||
l->edns = newedns;
|
l->edns = newedns;
|
||||||
n = requeue_lookup(l, ISC_TRUE);
|
n = requeue_lookup(l, ISC_TRUE);
|
||||||
if (l->trace && l->trace_root)
|
if (l->trace && l->trace_root)
|
||||||
@@ -3831,7 +3738,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (tsigkey != NULL) {
|
if (key != NULL) {
|
||||||
result = dns_tsig_verify(&query->recvbuf, msg, NULL, NULL);
|
result = dns_tsig_verify(&query->recvbuf, msg, NULL, NULL);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
printf(";; Couldn't verify signature: %s\n",
|
printf(";; Couldn't verify signature: %s\n",
|
||||||
@@ -4146,7 +4053,7 @@ cancel_all(void) {
|
|||||||
*/
|
*/
|
||||||
void
|
void
|
||||||
destroy_libs(void) {
|
destroy_libs(void) {
|
||||||
#ifdef WITH_IDN_SUPPORT
|
#ifdef WITH_IDN
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -4180,7 +4087,7 @@ destroy_libs(void) {
|
|||||||
|
|
||||||
clear_searchlist();
|
clear_searchlist();
|
||||||
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
#ifdef WITH_IDN
|
||||||
result = dns_name_settotextfilter(NULL);
|
result = dns_name_settotextfilter(NULL);
|
||||||
check_result(result, "dns_name_settotextfilter");
|
check_result(result, "dns_name_settotextfilter");
|
||||||
#endif
|
#endif
|
||||||
@@ -4198,9 +4105,9 @@ destroy_libs(void) {
|
|||||||
debug("freeing timermgr");
|
debug("freeing timermgr");
|
||||||
isc_timermgr_destroy(&timermgr);
|
isc_timermgr_destroy(&timermgr);
|
||||||
}
|
}
|
||||||
if (tsigkey != NULL) {
|
if (key != NULL) {
|
||||||
debug("freeing key %p", tsigkey);
|
debug("freeing key %p", key);
|
||||||
dns_tsigkey_detach(&tsigkey);
|
dns_tsigkey_detach(&key);
|
||||||
}
|
}
|
||||||
if (namebuf != NULL)
|
if (namebuf != NULL)
|
||||||
isc_buffer_free(&namebuf);
|
isc_buffer_free(&namebuf);
|
||||||
@@ -4210,12 +4117,22 @@ destroy_libs(void) {
|
|||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
is_dst_up = ISC_FALSE;
|
is_dst_up = ISC_FALSE;
|
||||||
}
|
}
|
||||||
|
if (entp != NULL) {
|
||||||
|
debug("detach from entropy");
|
||||||
|
isc_entropy_detach(&entp);
|
||||||
|
}
|
||||||
|
|
||||||
UNLOCK_LOOKUP;
|
UNLOCK_LOOKUP;
|
||||||
DESTROYLOCK(&lookup_lock);
|
DESTROYLOCK(&lookup_lock);
|
||||||
debug("Removing log context");
|
debug("Removing log context");
|
||||||
isc_log_destroy(&lctx);
|
isc_log_destroy(&lctx);
|
||||||
|
|
||||||
|
while (ednsoptscnt > 0U) {
|
||||||
|
ednsoptscnt--;
|
||||||
|
if (ednsopts[ednsoptscnt].value != NULL)
|
||||||
|
isc_mem_free(mctx, ednsopts[ednsoptscnt].value);
|
||||||
|
}
|
||||||
|
|
||||||
debug("Destroy memory");
|
debug("Destroy memory");
|
||||||
if (memdebugging != 0)
|
if (memdebugging != 0)
|
||||||
isc_mem_stats(mctx, stderr);
|
isc_mem_stats(mctx, stderr);
|
||||||
@@ -4223,7 +4140,27 @@ destroy_libs(void) {
|
|||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
#ifdef WITH_IDN
|
||||||
|
static void
|
||||||
|
initialize_idn(void) {
|
||||||
|
idn_result_t r;
|
||||||
|
isc_result_t result;
|
||||||
|
|
||||||
|
#ifdef HAVE_SETLOCALE
|
||||||
|
/* Set locale */
|
||||||
|
(void)setlocale(LC_ALL, "");
|
||||||
|
#endif
|
||||||
|
/* Create configuration context. */
|
||||||
|
r = idn_nameinit(1);
|
||||||
|
if (r != idn_success)
|
||||||
|
fatal("idn api initialization failed: %s",
|
||||||
|
idn_result_tostring(r));
|
||||||
|
|
||||||
|
/* Set domain name -> text post-conversion filter. */
|
||||||
|
result = dns_name_settotextfilter(output_filter);
|
||||||
|
check_result(result, "dns_name_settotextfilter");
|
||||||
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
||||||
isc_boolean_t absolute)
|
isc_boolean_t absolute)
|
||||||
@@ -4231,7 +4168,6 @@ output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
|||||||
char tmp1[MAXDLEN], tmp2[MAXDLEN];
|
char tmp1[MAXDLEN], tmp2[MAXDLEN];
|
||||||
size_t fromlen, tolen;
|
size_t fromlen, tolen;
|
||||||
isc_boolean_t end_with_dot;
|
isc_boolean_t end_with_dot;
|
||||||
isc_result_t result;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Copy contents of 'buffer' to 'tmp1', supply trailing dot
|
* Copy contents of 'buffer' to 'tmp1', supply trailing dot
|
||||||
@@ -4240,7 +4176,6 @@ output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
|||||||
fromlen = isc_buffer_usedlength(buffer) - used_org;
|
fromlen = isc_buffer_usedlength(buffer) - used_org;
|
||||||
if (fromlen >= MAXDLEN)
|
if (fromlen >= MAXDLEN)
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
memmove(tmp1, (char *)isc_buffer_base(buffer) + used_org, fromlen);
|
memmove(tmp1, (char *)isc_buffer_base(buffer) + used_org, fromlen);
|
||||||
end_with_dot = (tmp1[fromlen - 1] == '.') ? ISC_TRUE : ISC_FALSE;
|
end_with_dot = (tmp1[fromlen - 1] == '.') ? ISC_TRUE : ISC_FALSE;
|
||||||
if (absolute && !end_with_dot) {
|
if (absolute && !end_with_dot) {
|
||||||
@@ -4249,109 +4184,58 @@ output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
tmp1[fromlen - 1] = '.';
|
tmp1[fromlen - 1] = '.';
|
||||||
}
|
}
|
||||||
|
|
||||||
tmp1[fromlen] = '\0';
|
tmp1[fromlen] = '\0';
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Convert contents of 'tmp1' to local encoding.
|
* Convert contents of 'tmp1' to local encoding.
|
||||||
*/
|
*/
|
||||||
result = idn_ace_to_locale(tmp1, tmp2, sizeof(tmp2));
|
if (idn_decodename(IDN_DECODE_APP, tmp1, tmp2, MAXDLEN) != idn_success)
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
strlcpy(tmp1, tmp2, MAXDLEN);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Copy the converted contents in 'tmp1' back to 'buffer'.
|
* Copy the converted contents in 'tmp1' back to 'buffer'.
|
||||||
* If we have appended trailing dot, remove it.
|
* If we have appended trailing dot, remove it.
|
||||||
*/
|
*/
|
||||||
tolen = strlen(tmp2);
|
tolen = strlen(tmp1);
|
||||||
if (absolute && !end_with_dot && tmp2[tolen - 1] == '.')
|
if (absolute && !end_with_dot && tmp1[tolen - 1] == '.')
|
||||||
tolen--;
|
tolen--;
|
||||||
|
|
||||||
if (isc_buffer_length(buffer) < used_org + tolen)
|
if (isc_buffer_length(buffer) < used_org + tolen)
|
||||||
return (ISC_R_NOSPACE);
|
return (ISC_R_NOSPACE);
|
||||||
|
|
||||||
isc_buffer_subtract(buffer, isc_buffer_usedlength(buffer) - used_org);
|
isc_buffer_subtract(buffer, isc_buffer_usedlength(buffer) - used_org);
|
||||||
memmove(isc_buffer_used(buffer), tmp2, tolen);
|
memmove(isc_buffer_used(buffer), tmp1, tolen);
|
||||||
isc_buffer_add(buffer, (unsigned int)tolen);
|
isc_buffer_add(buffer, (unsigned int)tolen);
|
||||||
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
#endif
|
|
||||||
|
|
||||||
#ifdef WITH_IDN_SUPPORT
|
static idn_result_t
|
||||||
#ifdef WITH_LIBIDN2
|
append_textname(char *name, const char *origin, size_t namesize) {
|
||||||
|
size_t namelen = strlen(name);
|
||||||
|
size_t originlen = strlen(origin);
|
||||||
|
|
||||||
|
/* Already absolute? */
|
||||||
|
if (namelen > 0 && name[namelen - 1] == '.')
|
||||||
|
return (idn_success);
|
||||||
|
|
||||||
|
/* Append dot and origin */
|
||||||
|
|
||||||
|
if (namelen + 1 + originlen >= namesize)
|
||||||
|
return (idn_buffer_overflow);
|
||||||
|
|
||||||
|
if (*origin != '.')
|
||||||
|
name[namelen++] = '.';
|
||||||
|
(void)strlcpy(name + namelen, origin, namesize - namelen);
|
||||||
|
return (idn_success);
|
||||||
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
idn_initialize(void) {
|
idn_check_result(idn_result_t r, const char *msg) {
|
||||||
}
|
if (r != idn_success) {
|
||||||
|
exitcode = 1;
|
||||||
static isc_result_t
|
fatal("%s: %s", msg, idn_result_tostring(r));
|
||||||
idn_locale_to_ace(const char *from, char *to, size_t tolen) {
|
|
||||||
int res;
|
|
||||||
char *tmp_str = NULL;
|
|
||||||
|
|
||||||
res = idn2_to_ascii_lz(from, &tmp_str, IDN2_NONTRANSITIONAL|IDN2_NFC_INPUT);
|
|
||||||
if (res == IDN2_DISALLOWED) {
|
|
||||||
res = idn2_to_ascii_lz(from, &tmp_str, IDN2_TRANSITIONAL|IDN2_NFC_INPUT);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (res == IDN2_OK) {
|
|
||||||
/*
|
|
||||||
* idn2_to_ascii_lz() normalizes all strings to lowerl case,
|
|
||||||
* but we generally don't want to lowercase all input strings;
|
|
||||||
* make sure to return the original case if the two strings
|
|
||||||
* differ only in case
|
|
||||||
*/
|
|
||||||
if (!strcasecmp(from, tmp_str)) {
|
|
||||||
if (strlen(from) >= tolen) {
|
|
||||||
debug("from string is too long");
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
return ISC_R_NOSPACE;
|
|
||||||
}
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
(void) strlcpy(to, from, tolen);
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
/* check the length */
|
|
||||||
if (strlen(tmp_str) >= tolen) {
|
|
||||||
debug("ACE string is too long");
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
return ISC_R_NOSPACE;
|
|
||||||
}
|
|
||||||
|
|
||||||
(void) strlcpy(to, tmp_str, tolen);
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
fatal("'%s' is not a legal IDN name (%s), use +noidnin", from, idn2_strerror(res));
|
|
||||||
return ISC_R_FAILURE;
|
|
||||||
}
|
}
|
||||||
|
#endif /* WITH_IDN */
|
||||||
#ifdef WITH_IDN_OUT_SUPPORT
|
|
||||||
static isc_result_t
|
|
||||||
idn_ace_to_locale(const char *from, char *to, size_t tolen) {
|
|
||||||
int res;
|
|
||||||
char *tmp_str = NULL;
|
|
||||||
|
|
||||||
res = idn2_to_unicode_8zlz(from, &tmp_str,
|
|
||||||
IDN2_NONTRANSITIONAL|IDN2_NFC_INPUT);
|
|
||||||
|
|
||||||
if (res == IDN2_OK) {
|
|
||||||
/* check the length */
|
|
||||||
if (strlen(tmp_str) >= tolen) {
|
|
||||||
debug("encoded ASC string is too long");
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
return ISC_R_FAILURE;
|
|
||||||
}
|
|
||||||
|
|
||||||
(void) strlcpy(to, tmp_str, tolen);
|
|
||||||
idn2_free(tmp_str);
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
fatal("'%s' is not a legal IDN name (%s), use +noidnout", from, idn2_strerror(res));
|
|
||||||
return ISC_R_FAILURE;
|
|
||||||
}
|
|
||||||
#endif /* WITH_IDN_OUT_SUPPORT */
|
|
||||||
#endif /* WITH_LIBIDN2 */
|
|
||||||
#endif /* WITH_IDN_SUPPORT */
|
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -274,5 +274,5 @@ runs\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+27
-6
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2007, 2009-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -19,6 +16,13 @@
|
|||||||
#include <locale.h>
|
#include <locale.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
#include <idn/result.h>
|
||||||
|
#include <idn/log.h>
|
||||||
|
#include <idn/resconf.h>
|
||||||
|
#include <idn/api.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/netaddr.h>
|
#include <isc/netaddr.h>
|
||||||
@@ -165,7 +169,7 @@ host_shutdown(void) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
received(int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||||
isc_time_t now;
|
isc_time_t now;
|
||||||
int diff;
|
int diff;
|
||||||
|
|
||||||
@@ -452,7 +456,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
|||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
|
|
||||||
/* Add AAAA and MX lookups. */
|
/* Add AAAA and MX lookups. */
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
dns_name_copy(query->lookup->name, name, NULL);
|
dns_name_copy(query->lookup->name, name, NULL);
|
||||||
chase_cnamechain(msg, name);
|
chase_cnamechain(msg, name);
|
||||||
dns_name_format(name, namestr, sizeof(namestr));
|
dns_name_format(name, namestr, sizeof(namestr));
|
||||||
@@ -713,6 +718,9 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
|||||||
lookup->rdtype != dns_rdatatype_axfr)
|
lookup->rdtype != dns_rdatatype_axfr)
|
||||||
lookup->rdtype = rdtype;
|
lookup->rdtype = rdtype;
|
||||||
lookup->rdtypeset = ISC_TRUE;
|
lookup->rdtypeset = ISC_TRUE;
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
idnoptions = 0;
|
||||||
|
#endif
|
||||||
if (rdtype == dns_rdatatype_axfr) {
|
if (rdtype == dns_rdatatype_axfr) {
|
||||||
/* -l -t any -v */
|
/* -l -t any -v */
|
||||||
list_type = dns_rdatatype_any;
|
list_type = dns_rdatatype_any;
|
||||||
@@ -725,6 +733,13 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
|||||||
} else if (rdtype == dns_rdatatype_any) {
|
} else if (rdtype == dns_rdatatype_any) {
|
||||||
if (!lookup->tcp_mode_set)
|
if (!lookup->tcp_mode_set)
|
||||||
lookup->tcp_mode = ISC_TRUE;
|
lookup->tcp_mode = ISC_TRUE;
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
} else if (rdtype == dns_rdatatype_a ||
|
||||||
|
rdtype == dns_rdatatype_aaaa ||
|
||||||
|
rdtype == dns_rdatatype_mx) {
|
||||||
|
idnoptions = IDN_ASCCHECK;
|
||||||
|
list_type = rdtype;
|
||||||
|
#endif
|
||||||
} else
|
} else
|
||||||
list_type = rdtype;
|
list_type = rdtype;
|
||||||
list_addresses = ISC_FALSE;
|
list_addresses = ISC_FALSE;
|
||||||
@@ -753,6 +768,9 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
|||||||
if (!lookup->rdtypeset ||
|
if (!lookup->rdtypeset ||
|
||||||
lookup->rdtype != dns_rdatatype_axfr)
|
lookup->rdtype != dns_rdatatype_axfr)
|
||||||
lookup->rdtype = dns_rdatatype_any;
|
lookup->rdtype = dns_rdatatype_any;
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
idnoptions = 0;
|
||||||
|
#endif
|
||||||
list_type = dns_rdatatype_any;
|
list_type = dns_rdatatype_any;
|
||||||
list_addresses = ISC_FALSE;
|
list_addresses = ISC_FALSE;
|
||||||
lookup->rdtypeset = ISC_TRUE;
|
lookup->rdtypeset = ISC_TRUE;
|
||||||
@@ -864,6 +882,9 @@ main(int argc, char **argv) {
|
|||||||
ISC_LIST_INIT(search_list);
|
ISC_LIST_INIT(search_list);
|
||||||
|
|
||||||
fatalexit = 1;
|
fatalexit = 1;
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
idnoptions = IDN_ASCCHECK;
|
||||||
|
#endif
|
||||||
|
|
||||||
/* setup dighost callbacks */
|
/* setup dighost callbacks */
|
||||||
dighost_printmessage = printmessage;
|
dighost_printmessage = printmessage;
|
||||||
|
|||||||
@@ -1,14 +1,11 @@
|
|||||||
<!DOCTYPE book [
|
<!DOCTYPE book [
|
||||||
<!ENTITY mdash "—">]>
|
<!ENTITY mdash "—">]>
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -46,7 +43,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#ifndef DIG_H
|
#ifndef DIG_H
|
||||||
@@ -29,10 +26,6 @@
|
|||||||
#include <isc/sockaddr.h>
|
#include <isc/sockaddr.h>
|
||||||
#include <isc/socket.h>
|
#include <isc/socket.h>
|
||||||
|
|
||||||
#ifdef __APPLE__
|
|
||||||
#include <TargetConditionals.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#define MXSERV 20
|
#define MXSERV 20
|
||||||
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
#define MXNAME (DNS_NAME_MAXTEXT+1)
|
||||||
#define MXRD 32
|
#define MXRD 32
|
||||||
@@ -94,8 +87,6 @@ struct dig_lookup {
|
|||||||
aaonly,
|
aaonly,
|
||||||
adflag,
|
adflag,
|
||||||
cdflag,
|
cdflag,
|
||||||
raflag,
|
|
||||||
tcflag,
|
|
||||||
zflag,
|
zflag,
|
||||||
trace, /*% dig +trace */
|
trace, /*% dig +trace */
|
||||||
trace_root, /*% initial query for either +trace or +nssearch */
|
trace_root, /*% initial query for either +trace or +nssearch */
|
||||||
@@ -131,7 +122,6 @@ struct dig_lookup {
|
|||||||
use_usec,
|
use_usec,
|
||||||
nocrypto,
|
nocrypto,
|
||||||
ttlunits,
|
ttlunits,
|
||||||
idnin,
|
|
||||||
idnout,
|
idnout,
|
||||||
qr;
|
qr;
|
||||||
char textname[MXNAME]; /*% Name we're going to be looking up */
|
char textname[MXNAME]; /*% Name we're going to be looking up */
|
||||||
@@ -259,7 +249,7 @@ extern char keyfile[MXNAME];
|
|||||||
extern char keysecret[MXNAME];
|
extern char keysecret[MXNAME];
|
||||||
extern const dns_name_t *hmacname;
|
extern const dns_name_t *hmacname;
|
||||||
extern unsigned int digestbits;
|
extern unsigned int digestbits;
|
||||||
extern dns_tsigkey_t *tsigkey;
|
extern dns_tsigkey_t *key;
|
||||||
extern isc_boolean_t validated;
|
extern isc_boolean_t validated;
|
||||||
extern isc_taskmgr_t *taskmgr;
|
extern isc_taskmgr_t *taskmgr;
|
||||||
extern isc_task_t *global_task;
|
extern isc_task_t *global_task;
|
||||||
@@ -271,6 +261,9 @@ extern char *progname;
|
|||||||
extern int tries;
|
extern int tries;
|
||||||
extern int fatalexit;
|
extern int fatalexit;
|
||||||
extern isc_boolean_t verbose;
|
extern isc_boolean_t verbose;
|
||||||
|
#ifdef WITH_IDN
|
||||||
|
extern int idnoptions;
|
||||||
|
#endif
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Routines in dighost.c.
|
* Routines in dighost.c.
|
||||||
@@ -289,13 +282,6 @@ ISC_PLATFORM_NORETURN_PRE void
|
|||||||
fatal(const char *format, ...)
|
fatal(const char *format, ...)
|
||||||
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
ISC_FORMAT_PRINTF(1, 2) ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
void
|
|
||||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE void
|
|
||||||
digexit(void)
|
|
||||||
ISC_PLATFORM_NORETURN_POST;
|
|
||||||
|
|
||||||
void
|
void
|
||||||
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
debug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||||
|
|
||||||
@@ -371,6 +357,9 @@ destroy_libs(void);
|
|||||||
void
|
void
|
||||||
set_search_domain(char *domain);
|
set_search_domain(char *domain);
|
||||||
|
|
||||||
|
char *
|
||||||
|
next_token(char **stringp, const char *delim);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Routines to be defined in dig.c, host.c, and nslookup.c. and
|
* Routines to be defined in dig.c, host.c, and nslookup.c. and
|
||||||
* then assigned to the appropriate function pointer
|
* then assigned to the appropriate function pointer
|
||||||
@@ -382,7 +371,7 @@ extern isc_result_t
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
extern void
|
extern void
|
||||||
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
(*dighost_received)(int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
||||||
/*%<
|
/*%<
|
||||||
* Print a message about where and when the response
|
* Print a message about where and when the response
|
||||||
* was received from, like the final comment in the
|
* was received from, like the final comment in the
|
||||||
@@ -395,9 +384,6 @@ extern void
|
|||||||
extern void
|
extern void
|
||||||
(*dighost_shutdown)(void);
|
(*dighost_shutdown)(void);
|
||||||
|
|
||||||
extern void
|
|
||||||
(*dighost_pre_exit_hook)(void);
|
|
||||||
|
|
||||||
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
void save_opt(dig_lookup_t *lookup, char *code, char *value);
|
||||||
|
|
||||||
void setup_file_key(void);
|
void setup_file_key(void);
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2004-2007, 2010, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2004-2007, 2010, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -290,5 +290,5 @@ returns with an exit status of 1 if any query failed, and 0 otherwise\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2004-2007, 2010, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2004-2007, 2010, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+20
-22
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2000-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
#include <config.h>
|
||||||
@@ -390,7 +387,7 @@ detailsection(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query)
|
received(int bytes, isc_sockaddr_t *from, dig_query_t *query)
|
||||||
{
|
{
|
||||||
UNUSED(bytes);
|
UNUSED(bytes);
|
||||||
UNUSED(from);
|
UNUSED(from);
|
||||||
@@ -475,7 +472,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
|||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
|
|
||||||
/* Add AAAA lookup. */
|
/* Add AAAA lookup. */
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
dns_name_copy(query->lookup->name, name, NULL);
|
dns_name_copy(query->lookup->name, name, NULL);
|
||||||
chase_cnamechain(msg, name);
|
chase_cnamechain(msg, name);
|
||||||
dns_name_format(name, namestr, sizeof(namestr));
|
dns_name_format(name, namestr, sizeof(namestr));
|
||||||
@@ -551,7 +549,7 @@ show_settings(isc_boolean_t full, isc_boolean_t serv_only) {
|
|||||||
printf(" %s\t\t%s\n",
|
printf(" %s\t\t%s\n",
|
||||||
usesearch ? "search" : "nosearch",
|
usesearch ? "search" : "nosearch",
|
||||||
recurse ? "recurse" : "norecurse");
|
recurse ? "recurse" : "norecurse");
|
||||||
printf(" timeout = %u\t\tretry = %d\tport = %u\tndots = %d\n",
|
printf(" timeout = %d\t\tretry = %d\tport = %d\tndots = %d\n",
|
||||||
timeout, tries, port, ndots);
|
timeout, tries, port, ndots);
|
||||||
printf(" querytype = %-8s\tclass = %s\n", deftype, defclass);
|
printf(" querytype = %-8s\tclass = %s\n", deftype, defclass);
|
||||||
printf(" srchlist = ");
|
printf(" srchlist = ");
|
||||||
@@ -709,31 +707,31 @@ setoption(char *opt) {
|
|||||||
usesearch = ISC_TRUE;
|
usesearch = ISC_TRUE;
|
||||||
} else if (CHECKOPT("nodefname", 5)) {
|
} else if (CHECKOPT("nodefname", 5)) {
|
||||||
usesearch = ISC_FALSE;
|
usesearch = ISC_FALSE;
|
||||||
} else if (CHECKOPT("vc", 2)) {
|
} else if (CHECKOPT("vc", 2) == 0) {
|
||||||
tcpmode = ISC_TRUE;
|
tcpmode = ISC_TRUE;
|
||||||
tcpmode_set = ISC_TRUE;
|
tcpmode_set = ISC_TRUE;
|
||||||
} else if (CHECKOPT("novc", 4)) {
|
} else if (CHECKOPT("novc", 4) == 0) {
|
||||||
tcpmode = ISC_FALSE;
|
tcpmode = ISC_FALSE;
|
||||||
tcpmode_set = ISC_TRUE;
|
tcpmode_set = ISC_TRUE;
|
||||||
} else if (CHECKOPT("debug", 3)) {
|
} else if (CHECKOPT("debug", 3) == 0) {
|
||||||
short_form = ISC_FALSE;
|
short_form = ISC_FALSE;
|
||||||
showsearch = ISC_TRUE;
|
showsearch = ISC_TRUE;
|
||||||
} else if (CHECKOPT("nodebug", 5)) {
|
} else if (CHECKOPT("nodebug", 5) == 0) {
|
||||||
short_form = ISC_TRUE;
|
short_form = ISC_TRUE;
|
||||||
showsearch = ISC_FALSE;
|
showsearch = ISC_FALSE;
|
||||||
} else if (CHECKOPT("d2", 2)) {
|
} else if (CHECKOPT("d2", 2) == 0) {
|
||||||
debugging = ISC_TRUE;
|
debugging = ISC_TRUE;
|
||||||
} else if (CHECKOPT("nod2", 4)) {
|
} else if (CHECKOPT("nod2", 4) == 0) {
|
||||||
debugging = ISC_FALSE;
|
debugging = ISC_FALSE;
|
||||||
} else if (CHECKOPT("search", 3)) {
|
} else if (CHECKOPT("search", 3) == 0) {
|
||||||
usesearch = ISC_TRUE;
|
usesearch = ISC_TRUE;
|
||||||
} else if (CHECKOPT("nosearch", 5)) {
|
} else if (CHECKOPT("nosearch", 5) == 0) {
|
||||||
usesearch = ISC_FALSE;
|
usesearch = ISC_FALSE;
|
||||||
} else if (CHECKOPT("sil", 3)) {
|
} else if (CHECKOPT("sil", 3) == 0) {
|
||||||
/* deprecation_msg = ISC_FALSE; */
|
/* deprecation_msg = ISC_FALSE; */
|
||||||
} else if (CHECKOPT("fail", 3)) {
|
} else if (CHECKOPT("fail", 3) == 0) {
|
||||||
nofail=ISC_FALSE;
|
nofail=ISC_FALSE;
|
||||||
} else if (CHECKOPT("nofail", 5)) {
|
} else if (CHECKOPT("nofail", 5) == 0) {
|
||||||
nofail=ISC_TRUE;
|
nofail=ISC_TRUE;
|
||||||
} else if (strncasecmp(opt, "ndots=", 6) == 0) {
|
} else if (strncasecmp(opt, "ndots=", 6) == 0) {
|
||||||
set_ndots(&opt[6]);
|
set_ndots(&opt[6]);
|
||||||
@@ -813,12 +811,12 @@ addlookup(char *opt) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
do_next_command(char *input) {
|
do_next_command(char *input) {
|
||||||
char *ptr, *arg, *last;
|
char *ptr, *arg;
|
||||||
|
|
||||||
if ((ptr = strtok_r(input, " \t\r\n", &last)) == NULL) {
|
ptr = next_token(&input, " \t\r\n");
|
||||||
|
if (ptr == NULL)
|
||||||
return;
|
return;
|
||||||
}
|
arg = next_token(&input, " \t\r\n");
|
||||||
arg = strtok_r(NULL, " \t\r\n", &last);
|
|
||||||
if ((strcasecmp(ptr, "set") == 0) &&
|
if ((strcasecmp(ptr, "set") == 0) &&
|
||||||
(arg != NULL))
|
(arg != NULL))
|
||||||
setoption(arg);
|
setoption(arg);
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2004-2007, 2010, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!--
|
<!--
|
||||||
@@ -70,7 +67,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2004-2007, 2010, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2004-2007, 2010, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,11 +1,8 @@
|
|||||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
# Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
#
|
#
|
||||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
#
|
|
||||||
# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
# information regarding copyright ownership.
|
|
||||||
|
|
||||||
srcdir = @srcdir@
|
srcdir = @srcdir@
|
||||||
VPATH = @srcdir@
|
VPATH = @srcdir@
|
||||||
@@ -18,7 +15,7 @@ VERSION=@BIND9_VERSION@
|
|||||||
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
||||||
-DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
@CRYPTO@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2017, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -44,8 +44,7 @@ dnssec-cds \- change DS records for a child zone based on CDS/CDNSKEY
|
|||||||
.PP
|
.PP
|
||||||
The
|
The
|
||||||
\fBdnssec\-cds\fR
|
\fBdnssec\-cds\fR
|
||||||
command changes DS records at a delegation point based on CDS or CDNSKEY records published in the child zone\&. If both CDS and CDNSKEY records are present in the child zone, the CDS is preferred\&. This enables a child zone to inform its parent of upcoming changes to its key\-signing keys; by polling periodically with
|
command changes DS records at a delegation point based on CDS or CDNSKEY records published in the child zone\&. If both CDS and CDNSKEY records are present in the child zone, the CDS is preferred\&.
|
||||||
\fBdnssec\-cds\fR, the parent can keep the DS records up to date and enable automatic rolling of KSKs\&.
|
|
||||||
.PP
|
.PP
|
||||||
Two input files are required\&. The
|
Two input files are required\&. The
|
||||||
\fB\-f \fR\fB\fIchild\-file\fR\fR
|
\fB\-f \fR\fB\fIchild\-file\fR\fR
|
||||||
@@ -58,10 +57,6 @@ file generated by
|
|||||||
\fBdnssec\-dsfromkey\fR, or the output of a previous run of
|
\fBdnssec\-dsfromkey\fR, or the output of a previous run of
|
||||||
\fBdnssec\-cds\fR\&.
|
\fBdnssec\-cds\fR\&.
|
||||||
.PP
|
.PP
|
||||||
The
|
|
||||||
\fBdnssec\-cds\fR
|
|
||||||
command uses special DNSSEC validation logic specified by RFC 7344\&. It requires that the CDS and/or CDNSKEY records are validly signed by a key represented in the existing DS records\&. This will typicially be the pre\-existing key\-signing key (KSK)\&.
|
|
||||||
.PP
|
|
||||||
For protection against replay attacks, the signatures on the child records must not be older than they were on a previous run of
|
For protection against replay attacks, the signatures on the child records must not be older than they were on a previous run of
|
||||||
\fBdnssec\-cds\fR\&. This time is obtained from the modification time of the
|
\fBdnssec\-cds\fR\&. This time is obtained from the modification time of the
|
||||||
dsset\-
|
dsset\-
|
||||||
@@ -293,5 +288,5 @@ RFC 7344\&.
|
|||||||
.RE
|
.RE
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2017, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+29
-36
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -23,6 +20,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -53,7 +51,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -71,6 +69,7 @@ int verbose;
|
|||||||
*/
|
*/
|
||||||
static isc_log_t *lctx = NULL;
|
static isc_log_t *lctx = NULL;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
static isc_entropy_t *ectx = NULL;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* The domain we are working on
|
* The domain we are working on
|
||||||
@@ -86,7 +85,7 @@ static dns_rdataclass_t rdclass = dns_rdataclass_in;
|
|||||||
*/
|
*/
|
||||||
static isc_uint8_t dtype[8];
|
static isc_uint8_t dtype[8];
|
||||||
|
|
||||||
static const char *startstr = NULL; /* from which we derive notbefore */
|
static const char *startstr = NULL; /* from which we derive notbefore */
|
||||||
static isc_stdtime_t notbefore = 0; /* restrict sig inception times */
|
static isc_stdtime_t notbefore = 0; /* restrict sig inception times */
|
||||||
static dns_rdata_rrsig_t oldestsig; /* for recording inception time */
|
static dns_rdata_rrsig_t oldestsig; /* for recording inception time */
|
||||||
|
|
||||||
@@ -171,7 +170,8 @@ initname(char *setname) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
namestr = setname;
|
namestr = setname;
|
||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
@@ -251,8 +251,8 @@ load_db(const char *filename, dns_db_t **dbp, dns_dbnode_t **nodep) {
|
|||||||
rdclass, 0, NULL, dbp);
|
rdclass, 0, NULL, dbp);
|
||||||
check_result(result, "dns_db_create()");
|
check_result(result, "dns_db_create()");
|
||||||
|
|
||||||
result = dns_db_load(*dbp, filename,
|
result = dns_db_load3(*dbp, filename,
|
||||||
dns_masterformat_text, DNS_MASTER_HINT);
|
dns_masterformat_text, DNS_MASTER_HINT);
|
||||||
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE) {
|
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE) {
|
||||||
fatal("can't load %s: %s", filename,
|
fatal("can't load %s: %s", filename,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -376,9 +376,9 @@ formatset(dns_rdataset_t *rdataset) {
|
|||||||
* which just separates fields with spaces. The huge tab stop width
|
* which just separates fields with spaces. The huge tab stop width
|
||||||
* eliminates any tab characters.
|
* eliminates any tab characters.
|
||||||
*/
|
*/
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate2(&style, styleflags,
|
||||||
0, 0, 0, 0, 0, 1000000, 0,
|
0, 0, 0, 0, 0, 1000000, 0,
|
||||||
mctx);
|
mctx);
|
||||||
check_result(result, "dns_master_stylecreate2 failed");
|
check_result(result, "dns_master_stylecreate2 failed");
|
||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
||||||
@@ -521,13 +521,6 @@ match_key_dsset(keyinfo_t *ki, dns_rdataset_t *dsset, strictness_t strictness)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
vbprintf(1, "no matching %s for %s %d %d\n",
|
|
||||||
dsset->type == dns_rdatatype_cds
|
|
||||||
? "CDS" : "DS",
|
|
||||||
ki->rdata.type == dns_rdatatype_cdnskey
|
|
||||||
? "CDNSKEY" : "DNSKEY",
|
|
||||||
ki->tag, ki->algo);
|
|
||||||
|
|
||||||
return (ISC_FALSE);
|
return (ISC_FALSE);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -654,28 +647,17 @@ matching_sigs(keyinfo_t *keytbl, dns_rdataset_t *rdataset,
|
|||||||
|
|
||||||
for (i = 0; i < nkey; i++) {
|
for (i = 0; i < nkey; i++) {
|
||||||
keyinfo_t *ki = &keytbl[i];
|
keyinfo_t *ki = &keytbl[i];
|
||||||
if (sig.keyid != ki->tag ||
|
if (ki->dst == NULL ||
|
||||||
|
sig.keyid != ki->tag ||
|
||||||
sig.algorithm != ki->algo ||
|
sig.algorithm != ki->algo ||
|
||||||
!dns_name_equal(&sig.signer, name))
|
!dns_name_equal(&sig.signer, name))
|
||||||
{
|
{
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
if (ki->dst == NULL) {
|
|
||||||
vbprintf(1, "skip RRSIG by key %d:"
|
|
||||||
" no matching (C)DS\n",
|
|
||||||
sig.keyid);
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
result = dns_dnssec_verify(name, rdataset, ki->dst,
|
result = dns_dnssec_verify(name, rdataset, ki->dst,
|
||||||
ISC_FALSE, 0, mctx,
|
ISC_FALSE, mctx, &sigrdata);
|
||||||
&sigrdata, NULL);
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS &&
|
|
||||||
result != DNS_R_FROMWILDCARD) {
|
|
||||||
vbprintf(1, "skip RRSIG by key %d:"
|
|
||||||
" verification failed: %s\n",
|
|
||||||
sig.keyid, isc_result_totext(result));
|
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1147,7 +1129,7 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
}
|
}
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -1231,11 +1213,20 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
setup_logging(mctx, &lctx);
|
setup_logging(mctx, &lctx);
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
if (ectx == NULL) {
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
}
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fatal("could not initialize hash");
|
||||||
|
}
|
||||||
|
result = dst_lib_init(mctx, ectx,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
if (ds_path == NULL) {
|
if (ds_path == NULL) {
|
||||||
fatal("missing -d DS pathname");
|
fatal("missing -d DS pathname");
|
||||||
@@ -1385,6 +1376,8 @@ main(int argc, char *argv[]) {
|
|||||||
free_all_sets();
|
free_all_sets();
|
||||||
cleanup_logging(&lctx);
|
cleanup_logging(&lctx);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
isc_hash_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-cds">
|
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-cds">
|
||||||
@@ -39,7 +36,6 @@
|
|||||||
<docinfo>
|
<docinfo>
|
||||||
<copyright>
|
<copyright>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -68,11 +64,7 @@
|
|||||||
The <command>dnssec-cds</command> command changes DS records at
|
The <command>dnssec-cds</command> command changes DS records at
|
||||||
a delegation point based on CDS or CDNSKEY records published in
|
a delegation point based on CDS or CDNSKEY records published in
|
||||||
the child zone. If both CDS and CDNSKEY records are present in
|
the child zone. If both CDS and CDNSKEY records are present in
|
||||||
the child zone, the CDS is preferred. This enables a child zone
|
the child zone, the CDS is preferred.
|
||||||
to inform its parent of upcoming changes to its key-signing keys;
|
|
||||||
by polling periodically with <command>dnssec-cds</command>, the
|
|
||||||
parent can keep the DS records up to date and enable automatic
|
|
||||||
rolling of KSKs.
|
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
Two input files are required. The
|
Two input files are required. The
|
||||||
@@ -87,13 +79,6 @@
|
|||||||
<command>dnssec-dsfromkey</command>, or the output of a previous
|
<command>dnssec-dsfromkey</command>, or the output of a previous
|
||||||
run of <command>dnssec-cds</command>.
|
run of <command>dnssec-cds</command>.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
|
||||||
The <command>dnssec-cds</command> command uses special DNSSEC
|
|
||||||
validation logic specified by RFC 7344. It requires that the CDS
|
|
||||||
and/or CDNSKEY records are validly signed by a key represented in the
|
|
||||||
existing DS records. This will typicially be the pre-existing
|
|
||||||
key-signing key (KSK).
|
|
||||||
</para>
|
|
||||||
<para>
|
<para>
|
||||||
For protection against replay attacks, the signatures on the
|
For protection against replay attacks, the signatures on the
|
||||||
child records must not be older than they were on a previous run
|
child records must not be older than they were on a previous run
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2017, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -55,11 +55,7 @@
|
|||||||
The <span class="command"><strong>dnssec-cds</strong></span> command changes DS records at
|
The <span class="command"><strong>dnssec-cds</strong></span> command changes DS records at
|
||||||
a delegation point based on CDS or CDNSKEY records published in
|
a delegation point based on CDS or CDNSKEY records published in
|
||||||
the child zone. If both CDS and CDNSKEY records are present in
|
the child zone. If both CDS and CDNSKEY records are present in
|
||||||
the child zone, the CDS is preferred. This enables a child zone
|
the child zone, the CDS is preferred.
|
||||||
to inform its parent of upcoming changes to its key-signing keys;
|
|
||||||
by polling periodically with <span class="command"><strong>dnssec-cds</strong></span>, the
|
|
||||||
parent can keep the DS records up to date and enable automatic
|
|
||||||
rolling of KSKs.
|
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
Two input files are required. The
|
Two input files are required. The
|
||||||
@@ -74,13 +70,6 @@
|
|||||||
<span class="command"><strong>dnssec-dsfromkey</strong></span>, or the output of a previous
|
<span class="command"><strong>dnssec-dsfromkey</strong></span>, or the output of a previous
|
||||||
run of <span class="command"><strong>dnssec-cds</strong></span>.
|
run of <span class="command"><strong>dnssec-cds</strong></span>.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
|
||||||
The <span class="command"><strong>dnssec-cds</strong></span> command uses special DNSSEC
|
|
||||||
validation logic specified by RFC 7344. It requires that the CDS
|
|
||||||
and/or CDNSKEY records are validly signed by a key represented in the
|
|
||||||
existing DS records. This will typicially be the pre-existing
|
|
||||||
key-signing key (KSK).
|
|
||||||
</p>
|
|
||||||
<p>
|
<p>
|
||||||
For protection against replay attacks, the signatures on the
|
For protection against replay attacks, the signatures on the
|
||||||
child records must not be older than they were on a previous run
|
child records must not be older than they were on a previous run
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2008-2012, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2008-2012, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -178,5 +178,5 @@ RFC 4509\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2008-2012, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2008-2012, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2008-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -17,6 +14,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
@@ -41,7 +39,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -66,7 +64,8 @@ initname(char *setname) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
isc_buffer_add(&buf, strlen(setname));
|
isc_buffer_add(&buf, strlen(setname));
|
||||||
@@ -112,7 +111,7 @@ loadset(const char *filename, dns_rdataset_t *rdataset) {
|
|||||||
db_load_from_stream(db, stdin);
|
db_load_from_stream(db, stdin);
|
||||||
filename = "input";
|
filename = "input";
|
||||||
} else {
|
} else {
|
||||||
result = dns_db_load(db, filename, dns_masterformat_text, 0);
|
result = dns_db_load(db, filename);
|
||||||
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
||||||
fatal("can't load %s: %s", filename,
|
fatal("can't load %s: %s", filename,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -204,7 +203,8 @@ loadkey(char *filename, unsigned char *key_buf, unsigned int key_buf_size,
|
|||||||
|
|
||||||
rdclass = dst_key_class(key);
|
rdclass = dst_key_class(key);
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
result = dns_name_copy(dst_key_name(key), name, NULL);
|
result = dns_name_copy(dst_key_name(key), name, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("can't copy name");
|
fatal("can't copy name");
|
||||||
@@ -358,6 +358,7 @@ main(int argc, char **argv) {
|
|||||||
isc_boolean_t showall = ISC_FALSE;
|
isc_boolean_t showall = ISC_FALSE;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_rdata_t rdata;
|
dns_rdata_t rdata;
|
||||||
|
|
||||||
@@ -370,7 +371,7 @@ main(int argc, char **argv) {
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -473,10 +474,17 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
result = dst_lib_init(mctx, ectx,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("could not initialize hash");
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging(mctx, &log);
|
||||||
|
|
||||||
@@ -537,7 +545,9 @@ main(int argc, char **argv) {
|
|||||||
if (dns_rdataset_isassociated(&rdataset))
|
if (dns_rdataset_isassociated(&rdataset))
|
||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
isc_hash_destroy();
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -40,7 +37,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2008-2012, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2013-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -134,5 +134,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2013-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -17,6 +14,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
@@ -41,7 +39,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -71,7 +69,8 @@ initname(char *setname) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
|
|
||||||
isc_buffer_init(&buf, setname, strlen(setname));
|
isc_buffer_init(&buf, setname, strlen(setname));
|
||||||
isc_buffer_add(&buf, strlen(setname));
|
isc_buffer_add(&buf, strlen(setname));
|
||||||
@@ -117,8 +116,8 @@ loadset(const char *filename, dns_rdataset_t *rdataset) {
|
|||||||
db_load_from_stream(db, stdin);
|
db_load_from_stream(db, stdin);
|
||||||
filename = "input";
|
filename = "input";
|
||||||
} else {
|
} else {
|
||||||
result = dns_db_load(db, filename, dns_masterformat_text,
|
result = dns_db_load3(db, filename, dns_masterformat_text,
|
||||||
DNS_MASTER_NOTTL);
|
DNS_MASTER_NOTTL);
|
||||||
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
||||||
fatal("can't load %s: %s", filename,
|
fatal("can't load %s: %s", filename,
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
@@ -179,7 +178,8 @@ loadkey(char *filename, unsigned char *key_buf, unsigned int key_buf_size,
|
|||||||
|
|
||||||
rdclass = dst_key_class(key);
|
rdclass = dst_key_class(key);
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
result = dns_name_copy(dst_key_name(key), name, NULL);
|
result = dns_name_copy(dst_key_name(key), name, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("can't copy name");
|
fatal("can't copy name");
|
||||||
@@ -296,6 +296,7 @@ main(int argc, char **argv) {
|
|||||||
int ch;
|
int ch;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
dns_rdata_t rdata;
|
dns_rdata_t rdata;
|
||||||
isc_stdtime_t now;
|
isc_stdtime_t now;
|
||||||
@@ -310,7 +311,7 @@ main(int argc, char **argv) {
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -402,10 +403,17 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
result = dst_lib_init(mctx, ectx,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("could not initialize hash");
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging(mctx, &log);
|
||||||
|
|
||||||
@@ -448,7 +456,9 @@ main(int argc, char **argv) {
|
|||||||
if (dns_rdataset_isassociated(&rdataset))
|
if (dns_rdataset_isassociated(&rdataset))
|
||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
isc_hash_destroy();
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -37,7 +34,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2013-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2008-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2008-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -307,5 +307,5 @@ The PKCS#11 URI Scheme (draft\-pechanec\-pkcs11uri\-13)\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2008-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2008-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2007-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -18,6 +15,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
@@ -37,7 +35,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -69,7 +67,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||||
fprintf(stderr, " -c class (default: IN)\n");
|
fprintf(stderr, " -c class (default: IN)\n");
|
||||||
fprintf(stderr, " -E <engine>:\n");
|
fprintf(stderr, " -E <engine>:\n");
|
||||||
#if HAVE_PKCS11
|
#if defined(PKCS11CRYPTO)
|
||||||
fprintf(stderr, " path to PKCS#11 provider library "
|
fprintf(stderr, " path to PKCS#11 provider library "
|
||||||
"(default is %s)\n", PK11_LIB_LOCATION);
|
"(default is %s)\n", PK11_LIB_LOCATION);
|
||||||
#elif defined(USE_PKCS11)
|
#elif defined(USE_PKCS11)
|
||||||
@@ -145,6 +143,7 @@ main(int argc, char **argv) {
|
|||||||
char filename[255];
|
char filename[255];
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
int options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC;
|
int options = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC;
|
||||||
char *label = NULL;
|
char *label = NULL;
|
||||||
@@ -173,7 +172,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -345,7 +344,10 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = dst_lib_init(mctx, engine);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
ret = dst_lib_init2(mctx, ectx, engine,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (ret != ISC_R_SUCCESS)
|
if (ret != ISC_R_SUCCESS)
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(ret));
|
isc_result_totext(ret));
|
||||||
@@ -360,7 +362,8 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||||
strlen(argv[isc_commandline_index]));
|
strlen(argv[isc_commandline_index]));
|
||||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||||
@@ -606,13 +609,9 @@ main(int argc, char **argv) {
|
|||||||
isc_buffer_init(&buf, filename, sizeof(filename) - 1);
|
isc_buffer_init(&buf, filename, sizeof(filename) - 1);
|
||||||
|
|
||||||
/* associate the key */
|
/* associate the key */
|
||||||
ret = dst_key_fromlabel(name, alg, flags, protocol, rdclass,
|
ret = dst_key_fromlabel(name, alg, flags, protocol,
|
||||||
#if HAVE_PKCS11
|
rdclass, "pkcs11", label, NULL, mctx, &key);
|
||||||
"pkcs11",
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
#else
|
|
||||||
engine,
|
|
||||||
#endif
|
|
||||||
label, NULL, mctx, &key);
|
|
||||||
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
char namestr[DNS_NAME_FORMATSIZE];
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
@@ -731,6 +730,7 @@ main(int argc, char **argv) {
|
|||||||
dst_key_free(&prevkey);
|
dst_key_free(&prevkey);
|
||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -42,7 +39,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2008-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+25
-13
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2005, 2007-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2005, 2007-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-keygen \- DNSSEC key generation tool
|
dnssec-keygen \- DNSSEC key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
||||||
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
|
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-keygen\fR
|
\fBdnssec\-keygen\fR
|
||||||
@@ -62,23 +62,20 @@ may be preferable to direct use of
|
|||||||
.RS 4
|
.RS 4
|
||||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||||
\fBalgorithm\fR
|
\fBalgorithm\fR
|
||||||
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
|
must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TSIG/TKEY keys, the value must be one of DH (Diffie Hellman), HMAC\-MD5, HMAC\-SHA1, HMAC\-SHA224, HMAC\-SHA256, HMAC\-SHA384, or HMAC\-SHA512; specifying any of these algorithms will automatically set the
|
||||||
\fB\-T KEY\fR
|
\fB\-T KEY\fR
|
||||||
option as well\&.
|
option as well\&. (Note:
|
||||||
|
\fBtsig\-keygen\fR
|
||||||
|
produces TSIG keys in a more useful format than
|
||||||
|
\fBdnssec\-keygen\fR\&.)
|
||||||
.sp
|
.sp
|
||||||
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
These values are case insensitive\&. In some cases, abbreviations are supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for ECDSAP384SHA384\&. If RSASHA1 or DSA is specified along with the
|
||||||
\fB\-3\fR
|
\fB\-3\fR
|
||||||
option, then NSEC3RSASHA1 or NSEC3DSA will be used instead\&.
|
option, then NSEC3RSASHA1 or NSEC3DSA will be used instead\&.
|
||||||
.sp
|
.sp
|
||||||
This parameter
|
As of BIND 9\&.12\&.0, this option is mandatory except when using the
|
||||||
\fImust\fR
|
|
||||||
be specified except when using the
|
|
||||||
\fB\-S\fR
|
\fB\-S\fR
|
||||||
option, which copies the algorithm from the predecessor key\&.
|
option (which copies the algorithm from the predecessor key)\&. Previously, the default for newly generated keys was RSASHA1\&.
|
||||||
.sp
|
|
||||||
In prior releases, HMAC algorithms could be generated for use as TSIG keys, but that feature has been removed as of BIND 9\&.13\&.0\&. Use
|
|
||||||
\fBtsig\-keygen\fR
|
|
||||||
to generate TSIG keys\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-b \fIkeysize\fR
|
\-b \fIkeysize\fR
|
||||||
@@ -178,6 +175,21 @@ stderr
|
|||||||
indicating the progress of the key generation\&. A \*(Aq\&.\*(Aq indicates that a random number has been found which passed an initial sieve test; \*(Aq+\*(Aq means a number has passed a single round of the Miller\-Rabin primality test; a space means that the number has passed all the tests and is a satisfactory key\&.
|
indicating the progress of the key generation\&. A \*(Aq\&.\*(Aq indicates that a random number has been found which passed an initial sieve test; \*(Aq+\*(Aq means a number has passed a single round of the Miller\-Rabin primality test; a space means that the number has passed all the tests and is a satisfactory key\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-r \fIrandomdev\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies a source of randomness\&. Normally, when generating DNSSEC keys, this option has no effect; the random number generation function provided by the cryptographic library will be used\&.
|
||||||
|
.sp
|
||||||
|
If that behavior is disabled at compile time, however, the specified file will be used as entropy source for key generation\&.
|
||||||
|
randomdev
|
||||||
|
is the name of a character device or file containing random data to be used\&. The special value
|
||||||
|
keyboard
|
||||||
|
indicates that keyboard input should be used\&.
|
||||||
|
.sp
|
||||||
|
The default is
|
||||||
|
/dev/random
|
||||||
|
if the operating system provides it or an equivalent device; if not, the default source of randomness is keyboard input\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-S \fIkey\fR
|
\-S \fIkey\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Create a new key which is an explicit successor to an existing key\&. The name, algorithm, size, and type of the key will be set to match the existing key\&. The activation date of the new key will be set to the inactivation date of the existing one\&. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days\&.
|
Create a new key which is an explicit successor to an existing key\&. The name, algorithm, size, and type of the key will be set to match the existing key\&. The activation date of the new key will be set to the inactivation date of the existing one\&. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days\&.
|
||||||
@@ -354,5 +366,5 @@ RFC 4034\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2005, 2007-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2005, 2007-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+148
-40
@@ -1,14 +1,11 @@
|
|||||||
/*
|
/*
|
||||||
* Portions Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Portions Copyright (C) 1999-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* Portions Copyright (C) 1995-2000 by Network Associates, Inc.
|
||||||
* information regarding copyright ownership.
|
|
||||||
*
|
|
||||||
* Portions Copyright (C) Network Associates, Inc.
|
|
||||||
*
|
*
|
||||||
* Permission to use, copy, modify, and/or distribute this software for any
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* purpose with or without fee is hereby granted, provided that the above
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
@@ -33,6 +30,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
#include <isc/region.h>
|
#include <isc/region.h>
|
||||||
@@ -52,7 +50,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -81,7 +79,10 @@ usage(void) {
|
|||||||
" | NSEC3DSA |\n");
|
" | NSEC3DSA |\n");
|
||||||
fprintf(stderr, " RSASHA256 | RSASHA512 | ECCGOST |\n");
|
fprintf(stderr, " RSASHA256 | RSASHA512 | ECCGOST |\n");
|
||||||
fprintf(stderr, " ECDSAP256SHA256 | ECDSAP384SHA384 |\n");
|
fprintf(stderr, " ECDSAP256SHA256 | ECDSAP384SHA384 |\n");
|
||||||
fprintf(stderr, " ED25519 | ED448 | DH\n");
|
fprintf(stderr, " ED25519 | ED448 | DH |\n");
|
||||||
|
fprintf(stderr, " HMAC-MD5 | HMAC-SHA1 | HMAC-SHA224 | "
|
||||||
|
"HMAC-SHA256 | \n");
|
||||||
|
fprintf(stderr, " HMAC-SHA384 | HMAC-SHA512\n");
|
||||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||||
fprintf(stderr, " -b <key size in bits>:\n");
|
fprintf(stderr, " -b <key size in bits>:\n");
|
||||||
fprintf(stderr, " RSAMD5:\t[1024..%d]\n", MAX_RSA);
|
fprintf(stderr, " RSAMD5:\t[1024..%d]\n", MAX_RSA);
|
||||||
@@ -98,6 +99,12 @@ usage(void) {
|
|||||||
fprintf(stderr, " ECDSAP384SHA384:\tignored\n");
|
fprintf(stderr, " ECDSAP384SHA384:\tignored\n");
|
||||||
fprintf(stderr, " ED25519:\tignored\n");
|
fprintf(stderr, " ED25519:\tignored\n");
|
||||||
fprintf(stderr, " ED448:\tignored\n");
|
fprintf(stderr, " ED448:\tignored\n");
|
||||||
|
fprintf(stderr, " HMAC-MD5:\t[1..512]\n");
|
||||||
|
fprintf(stderr, " HMAC-SHA1:\t[1..160]\n");
|
||||||
|
fprintf(stderr, " HMAC-SHA224:\t[1..224]\n");
|
||||||
|
fprintf(stderr, " HMAC-SHA256:\t[1..256]\n");
|
||||||
|
fprintf(stderr, " HMAC-SHA384:\t[1..384]\n");
|
||||||
|
fprintf(stderr, " HMAC-SHA512:\t[1..512]\n");
|
||||||
fprintf(stderr, " (key size defaults are set according to\n"
|
fprintf(stderr, " (key size defaults are set according to\n"
|
||||||
" algorithm and usage (ZSK or KSK)\n");
|
" algorithm and usage (ZSK or KSK)\n");
|
||||||
fprintf(stderr, " -n <nametype>: ZONE | HOST | ENTITY | "
|
fprintf(stderr, " -n <nametype>: ZONE | HOST | ENTITY | "
|
||||||
@@ -106,7 +113,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " -c <class>: (default: IN)\n");
|
fprintf(stderr, " -c <class>: (default: IN)\n");
|
||||||
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
|
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
|
||||||
fprintf(stderr, " -E <engine>:\n");
|
fprintf(stderr, " -E <engine>:\n");
|
||||||
#if HAVE_PKCS11
|
#if defined(PKCS11CRYPTO)
|
||||||
fprintf(stderr, " path to PKCS#11 provider library "
|
fprintf(stderr, " path to PKCS#11 provider library "
|
||||||
"(default is %s)\n", PK11_LIB_LOCATION);
|
"(default is %s)\n", PK11_LIB_LOCATION);
|
||||||
#elif defined(USE_PKCS11)
|
#elif defined(USE_PKCS11)
|
||||||
@@ -120,6 +127,7 @@ usage(void) {
|
|||||||
"(DH only)\n");
|
"(DH only)\n");
|
||||||
fprintf(stderr, " -L <ttl>: default key TTL\n");
|
fprintf(stderr, " -L <ttl>: default key TTL\n");
|
||||||
fprintf(stderr, " -p <protocol>: (default: 3 [dnssec])\n");
|
fprintf(stderr, " -p <protocol>: (default: 3 [dnssec])\n");
|
||||||
|
fprintf(stderr, " -r <randomdev>: a file containing random data\n");
|
||||||
fprintf(stderr, " -s <strength>: strength value this key signs DNS "
|
fprintf(stderr, " -s <strength>: strength value this key signs DNS "
|
||||||
"records with (default: 0)\n");
|
"records with (default: 0)\n");
|
||||||
fprintf(stderr, " -T <rrtype>: DNSKEY | KEY (default: DNSKEY; "
|
fprintf(stderr, " -T <rrtype>: DNSKEY | KEY (default: DNSKEY; "
|
||||||
@@ -216,6 +224,7 @@ main(int argc, char **argv) {
|
|||||||
dst_key_t *prevkey = NULL;
|
dst_key_t *prevkey = NULL;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
#ifdef USE_PKCS11
|
#ifdef USE_PKCS11
|
||||||
const char *engine = PKCS11_ENGINE;
|
const char *engine = PKCS11_ENGINE;
|
||||||
#else
|
#else
|
||||||
@@ -247,7 +256,7 @@ main(int argc, char **argv) {
|
|||||||
if (argc == 1)
|
if (argc == 1)
|
||||||
usage();
|
usage();
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -362,8 +371,7 @@ main(int argc, char **argv) {
|
|||||||
quiet = ISC_TRUE;
|
quiet = ISC_TRUE;
|
||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
fatal("The -r option has been deprecated.\n"
|
setup_entropy(mctx, isc_commandline_argument, &ectx);
|
||||||
"System random data is always used.\n");
|
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
signatory = strtol(isc_commandline_argument,
|
signatory = strtol(isc_commandline_argument,
|
||||||
@@ -492,7 +500,10 @@ main(int argc, char **argv) {
|
|||||||
if (!isatty(0))
|
if (!isatty(0))
|
||||||
quiet = ISC_TRUE;
|
quiet = ISC_TRUE;
|
||||||
|
|
||||||
ret = dst_lib_init(mctx, engine);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
ret = dst_lib_init2(mctx, ectx, engine,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (ret != ISC_R_SUCCESS)
|
if (ret != ISC_R_SUCCESS)
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(ret));
|
isc_result_totext(ret));
|
||||||
@@ -508,7 +519,8 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||||
strlen(argv[isc_commandline_index]));
|
strlen(argv[isc_commandline_index]));
|
||||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||||
@@ -530,6 +542,8 @@ main(int argc, char **argv) {
|
|||||||
"\"-a RSAMD5\"\n");
|
"\"-a RSAMD5\"\n");
|
||||||
INSIST(freeit == NULL);
|
INSIST(freeit == NULL);
|
||||||
return (1);
|
return (1);
|
||||||
|
} else if (strcasecmp(algname, "HMAC-MD5") == 0) {
|
||||||
|
alg = DST_ALG_HMACMD5;
|
||||||
#else
|
#else
|
||||||
fprintf(stderr,
|
fprintf(stderr,
|
||||||
"The use of RSA (RSAMD5) was disabled\n");
|
"The use of RSA (RSAMD5) was disabled\n");
|
||||||
@@ -539,27 +553,48 @@ main(int argc, char **argv) {
|
|||||||
fprintf(stderr, "The use of RSAMD5 was disabled\n");
|
fprintf(stderr, "The use of RSAMD5 was disabled\n");
|
||||||
INSIST(freeit == NULL);
|
INSIST(freeit == NULL);
|
||||||
return (1);
|
return (1);
|
||||||
|
} else if (strcasecmp(algname, "HMAC-MD5") == 0) {
|
||||||
|
fprintf(stderr,
|
||||||
|
"The use of HMAC-MD5 was disabled\n");
|
||||||
|
return (1);
|
||||||
#endif
|
#endif
|
||||||
} else {
|
} else if (strcasecmp(algname, "HMAC-SHA1") == 0)
|
||||||
|
alg = DST_ALG_HMACSHA1;
|
||||||
|
else if (strcasecmp(algname, "HMAC-SHA224") == 0)
|
||||||
|
alg = DST_ALG_HMACSHA224;
|
||||||
|
else if (strcasecmp(algname, "HMAC-SHA256") == 0)
|
||||||
|
alg = DST_ALG_HMACSHA256;
|
||||||
|
else if (strcasecmp(algname, "HMAC-SHA384") == 0)
|
||||||
|
alg = DST_ALG_HMACSHA384;
|
||||||
|
else if (strcasecmp(algname, "HMAC-SHA512") == 0)
|
||||||
|
alg = DST_ALG_HMACSHA512;
|
||||||
|
else {
|
||||||
r.base = algname;
|
r.base = algname;
|
||||||
r.length = strlen(algname);
|
r.length = strlen(algname);
|
||||||
ret = dns_secalg_fromtext(&alg, &r);
|
ret = dns_secalg_fromtext(&alg, &r);
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS)
|
||||||
fatal("unknown algorithm %s", algname);
|
fatal("unknown algorithm %s", algname);
|
||||||
}
|
if (alg == DST_ALG_DH)
|
||||||
if (alg == DST_ALG_DH) {
|
|
||||||
options |= DST_TYPE_KEY;
|
options |= DST_TYPE_KEY;
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifdef PK11_MD5_DISABLE
|
#ifdef PK11_MD5_DISABLE
|
||||||
INSIST((alg != DNS_KEYALG_RSAMD5));
|
INSIST((alg != DNS_KEYALG_RSAMD5) && (alg != DST_ALG_HMACMD5));
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (!dst_algorithm_supported(alg)) {
|
|
||||||
fatal("unsupported algorithm: %d", alg);
|
if (alg == DST_ALG_HMACMD5 || alg == DST_ALG_HMACSHA1 ||
|
||||||
|
alg == DST_ALG_HMACSHA224 || alg == DST_ALG_HMACSHA256 ||
|
||||||
|
alg == DST_ALG_HMACSHA384 || alg == DST_ALG_HMACSHA512)
|
||||||
|
{
|
||||||
|
fprintf(stderr,
|
||||||
|
"Use of dnssec-keygen for HMAC keys is "
|
||||||
|
"deprecated: use tsig-keygen\n");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!dst_algorithm_supported(alg))
|
||||||
|
fatal("unsupported algorithm: %d", alg);
|
||||||
|
|
||||||
if (use_nsec3) {
|
if (use_nsec3) {
|
||||||
switch (alg) {
|
switch (alg) {
|
||||||
case DST_ALG_DSA:
|
case DST_ALG_DSA:
|
||||||
@@ -585,20 +620,20 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
|
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
|
||||||
if (strcasecmp(type, "NOAUTH") == 0) {
|
if (strcasecmp(type, "NOAUTH") == 0)
|
||||||
flags |= DNS_KEYTYPE_NOAUTH;
|
flags |= DNS_KEYTYPE_NOAUTH;
|
||||||
} else if (strcasecmp(type, "NOCONF") == 0) {
|
else if (strcasecmp(type, "NOCONF") == 0)
|
||||||
flags |= DNS_KEYTYPE_NOCONF;
|
flags |= DNS_KEYTYPE_NOCONF;
|
||||||
} else if (strcasecmp(type, "NOAUTHCONF") == 0) {
|
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
|
||||||
flags |= (DNS_KEYTYPE_NOAUTH |
|
flags |= (DNS_KEYTYPE_NOAUTH |
|
||||||
DNS_KEYTYPE_NOCONF);
|
DNS_KEYTYPE_NOCONF);
|
||||||
if (size < 0)
|
if (size < 0)
|
||||||
size = 0;
|
size = 0;
|
||||||
} else if (strcasecmp(type, "AUTHCONF") == 0) {
|
|
||||||
/* nothing */;
|
|
||||||
} else {
|
|
||||||
fatal("invalid type %s", type);
|
|
||||||
}
|
}
|
||||||
|
else if (strcasecmp(type, "AUTHCONF") == 0)
|
||||||
|
/* nothing */;
|
||||||
|
else
|
||||||
|
fatal("invalid type %s", type);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (size < 0) {
|
if (size < 0) {
|
||||||
@@ -768,18 +803,78 @@ main(int argc, char **argv) {
|
|||||||
case DST_ALG_ED448:
|
case DST_ALG_ED448:
|
||||||
size = 456;
|
size = 456;
|
||||||
break;
|
break;
|
||||||
|
case DST_ALG_HMACMD5:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 512)
|
||||||
|
fatal("HMAC-MD5 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 80 || dbits > 128))
|
||||||
|
fatal("HMAC-MD5 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-MD5 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
|
case DST_ALG_HMACSHA1:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 160)
|
||||||
|
fatal("HMAC-SHA1 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 80 || dbits > 160))
|
||||||
|
fatal("HMAC-SHA1 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-SHA1 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
|
case DST_ALG_HMACSHA224:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 224)
|
||||||
|
fatal("HMAC-SHA224 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 112 || dbits > 224))
|
||||||
|
fatal("HMAC-SHA224 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-SHA224 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
|
case DST_ALG_HMACSHA256:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 256)
|
||||||
|
fatal("HMAC-SHA256 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 128 || dbits > 256))
|
||||||
|
fatal("HMAC-SHA256 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-SHA256 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
|
case DST_ALG_HMACSHA384:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 384)
|
||||||
|
fatal("HMAC-384 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 192 || dbits > 384))
|
||||||
|
fatal("HMAC-SHA384 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-SHA384 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
|
case DST_ALG_HMACSHA512:
|
||||||
|
options |= DST_TYPE_KEY;
|
||||||
|
if (size < 1 || size > 512)
|
||||||
|
fatal("HMAC-SHA512 key size %d out of range", size);
|
||||||
|
if (dbits != 0 && (dbits < 256 || dbits > 512))
|
||||||
|
fatal("HMAC-SHA512 digest bits %d out of range", dbits);
|
||||||
|
if ((dbits % 8) != 0)
|
||||||
|
fatal("HMAC-SHA512 digest bits %d not divisible by 8",
|
||||||
|
dbits);
|
||||||
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (alg != DNS_KEYALG_DH && generator != 0)
|
if (alg != DNS_KEYALG_DH && generator != 0)
|
||||||
fatal("specified DH generator for a non-DH key");
|
fatal("specified DH generator for a non-DH key");
|
||||||
|
|
||||||
if (nametype == NULL) {
|
if (nametype == NULL) {
|
||||||
if ((options & DST_TYPE_KEY) != 0) /* KEY */
|
if ((options & DST_TYPE_KEY) != 0) /* KEY / HMAC */
|
||||||
fatal("no nametype specified");
|
fatal("no nametype specified");
|
||||||
flags |= DNS_KEYOWNER_ZONE; /* DNSKEY */
|
flags |= DNS_KEYOWNER_ZONE; /* DNSKEY */
|
||||||
} else if (strcasecmp(nametype, "zone") == 0)
|
} else if (strcasecmp(nametype, "zone") == 0)
|
||||||
flags |= DNS_KEYOWNER_ZONE;
|
flags |= DNS_KEYOWNER_ZONE;
|
||||||
else if ((options & DST_TYPE_KEY) != 0) { /* KEY */
|
else if ((options & DST_TYPE_KEY) != 0) { /* KEY / HMAC */
|
||||||
if (strcasecmp(nametype, "host") == 0 ||
|
if (strcasecmp(nametype, "host") == 0 ||
|
||||||
strcasecmp(nametype, "entity") == 0)
|
strcasecmp(nametype, "entity") == 0)
|
||||||
flags |= DNS_KEYOWNER_ENTITY;
|
flags |= DNS_KEYOWNER_ENTITY;
|
||||||
@@ -795,7 +890,7 @@ main(int argc, char **argv) {
|
|||||||
if (directory == NULL)
|
if (directory == NULL)
|
||||||
directory = ".";
|
directory = ".";
|
||||||
|
|
||||||
if ((options & DST_TYPE_KEY) != 0) /* KEY */
|
if ((options & DST_TYPE_KEY) != 0) /* KEY / HMAC */
|
||||||
flags |= signatory;
|
flags |= signatory;
|
||||||
else if ((flags & DNS_KEYOWNER_ZONE) != 0) { /* DNSKEY */
|
else if ((flags & DNS_KEYOWNER_ZONE) != 0) { /* DNSKEY */
|
||||||
flags |= kskflag;
|
flags |= kskflag;
|
||||||
@@ -816,11 +911,12 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if ((flags & DNS_KEYFLAG_OWNERMASK) == DNS_KEYOWNER_ZONE &&
|
if ((flags & DNS_KEYFLAG_OWNERMASK) == DNS_KEYOWNER_ZONE &&
|
||||||
alg == DNS_KEYALG_DH)
|
(alg == DNS_KEYALG_DH || alg == DST_ALG_HMACMD5 ||
|
||||||
{
|
alg == DST_ALG_HMACSHA1 || alg == DST_ALG_HMACSHA224 ||
|
||||||
|
alg == DST_ALG_HMACSHA256 || alg == DST_ALG_HMACSHA384 ||
|
||||||
|
alg == DST_ALG_HMACSHA512))
|
||||||
fatal("a key with algorithm '%s' cannot be a zone key",
|
fatal("a key with algorithm '%s' cannot be a zone key",
|
||||||
algname);
|
algname);
|
||||||
}
|
|
||||||
|
|
||||||
switch(alg) {
|
switch(alg) {
|
||||||
case DNS_KEYALG_RSAMD5:
|
case DNS_KEYALG_RSAMD5:
|
||||||
@@ -843,6 +939,15 @@ main(int argc, char **argv) {
|
|||||||
case DST_ALG_ED25519:
|
case DST_ALG_ED25519:
|
||||||
case DST_ALG_ED448:
|
case DST_ALG_ED448:
|
||||||
show_progress = ISC_TRUE;
|
show_progress = ISC_TRUE;
|
||||||
|
/* fall through */
|
||||||
|
|
||||||
|
case DST_ALG_HMACMD5:
|
||||||
|
case DST_ALG_HMACSHA1:
|
||||||
|
case DST_ALG_HMACSHA224:
|
||||||
|
case DST_ALG_HMACSHA256:
|
||||||
|
case DST_ALG_HMACSHA384:
|
||||||
|
case DST_ALG_HMACSHA512:
|
||||||
|
param = 0;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -856,17 +961,19 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
if (!quiet && show_progress) {
|
if (!quiet && show_progress) {
|
||||||
fprintf(stderr, "Generating key pair.");
|
fprintf(stderr, "Generating key pair.");
|
||||||
ret = dst_key_generate(name, alg, size, param, flags,
|
ret = dst_key_generate2(name, alg, size, param, flags,
|
||||||
protocol, rdclass, mctx, &key,
|
protocol, rdclass, mctx, &key,
|
||||||
&progress);
|
&progress);
|
||||||
putc('\n', stderr);
|
putc('\n', stderr);
|
||||||
fflush(stderr);
|
fflush(stderr);
|
||||||
} else {
|
} else {
|
||||||
ret = dst_key_generate(name, alg, size, param, flags,
|
ret = dst_key_generate2(name, alg, size, param, flags,
|
||||||
protocol, rdclass, mctx, &key,
|
protocol, rdclass, mctx, &key,
|
||||||
NULL);
|
NULL);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
if (ret != ISC_R_SUCCESS) {
|
if (ret != ISC_R_SUCCESS) {
|
||||||
char namestr[DNS_NAME_FORMATSIZE];
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
char algstr[DNS_SECALG_FORMATSIZE];
|
char algstr[DNS_SECALG_FORMATSIZE];
|
||||||
@@ -1019,6 +1126,7 @@ main(int argc, char **argv) {
|
|||||||
dst_key_free(&prevkey);
|
dst_key_free(&prevkey);
|
||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2005, 2007-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -49,7 +46,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -81,6 +77,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-q</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-q</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
||||||
@@ -125,9 +122,19 @@
|
|||||||
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
of <option>algorithm</option> must be one of RSAMD5, RSASHA1,
|
||||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
TKEY and SIG(0) keys, the value must be DH (Diffie Hellman);
|
||||||
his value will automatically set the <option>-T KEY</option>
|
specifying this value will automatically set the
|
||||||
option as well.
|
<option>-T KEY</option> option as well.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
TSIG keys can also by generated by setting the value to
|
||||||
|
one of HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256,
|
||||||
|
HMAC-SHA384, or HMAC-SHA512. As with DH, specifying these
|
||||||
|
values will automatically set <option>-T KEY</option>. Note,
|
||||||
|
however, that <command>tsig-keygen</command> produces TSIG keys
|
||||||
|
in a more useful format. These algorithms have been deprecated
|
||||||
|
in <command>dnssec-keygen</command>, and will be removed in a
|
||||||
|
future release.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
These values are case insensitive. In some cases, abbreviations
|
These values are case insensitive. In some cases, abbreviations
|
||||||
@@ -137,15 +144,10 @@
|
|||||||
or NSEC3DSA will be used instead.
|
or NSEC3DSA will be used instead.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
This parameter <emphasis>must</emphasis> be specified except
|
As of BIND 9.12.0, this option is mandatory except when using
|
||||||
when using the <option>-S</option> option, which copies the
|
the <option>-S</option> option, which copies the algorithm from
|
||||||
algorithm from the predecessor key.
|
the predecessor key. Previously, the default for newly
|
||||||
</para>
|
generated keys was RSASHA1.
|
||||||
<para>
|
|
||||||
In prior releases, HMAC algorithms could be generated for
|
|
||||||
use as TSIG keys, but that feature has been removed as of
|
|
||||||
BIND 9.13.0. Use <command>tsig-keygen</command> to generate
|
|
||||||
TSIG keys.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -348,6 +350,31 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-r <replaceable class="parameter">randomdev</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies a source of randomness. Normally, when generating
|
||||||
|
DNSSEC keys, this option has no effect; the random number
|
||||||
|
generation function provided by the cryptographic library will
|
||||||
|
be used.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
If that behavior is disabled at compile time, however,
|
||||||
|
the specified file will be used as entropy source
|
||||||
|
for key generation. <filename>randomdev</filename> is
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used. The special value <filename>keyboard</filename>
|
||||||
|
indicates that keyboard input should be used.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
The default is <filename>/dev/random</filename> if the
|
||||||
|
operating system provides it or an equivalent device;
|
||||||
|
if not, the default source of randomness is keyboard input.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-S <replaceable class="parameter">key</replaceable></term>
|
<term>-S <replaceable class="parameter">key</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2005, 2007-2012, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2005, 2007-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -57,6 +57,7 @@
|
|||||||
[<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
|
[<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
|
||||||
[<code class="option">-q</code>]
|
[<code class="option">-q</code>]
|
||||||
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>]
|
||||||
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
||||||
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
||||||
@@ -102,9 +103,12 @@
|
|||||||
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
|
||||||
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
|
||||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448. For
|
||||||
TKEY, the value must be DH (Diffie Hellman); specifying
|
TSIG/TKEY keys, the value must be one of DH (Diffie Hellman),
|
||||||
his value will automatically set the <code class="option">-T KEY</code>
|
HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384,
|
||||||
option as well.
|
or HMAC-SHA512; specifying any of these algorithms will
|
||||||
|
automatically set the <code class="option">-T KEY</code> option as well.
|
||||||
|
(Note: <span class="command"><strong>tsig-keygen</strong></span> produces TSIG keys in a
|
||||||
|
more useful format than <span class="command"><strong>dnssec-keygen</strong></span>.)
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
These values are case insensitive. In some cases, abbreviations
|
These values are case insensitive. In some cases, abbreviations
|
||||||
@@ -114,15 +118,10 @@
|
|||||||
or NSEC3DSA will be used instead.
|
or NSEC3DSA will be used instead.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
This parameter <span class="emphasis"><em>must</em></span> be specified except
|
As of BIND 9.12.0, this option is mandatory except when using
|
||||||
when using the <code class="option">-S</code> option, which copies the
|
the <code class="option">-S</code> option (which copies the algorithm from
|
||||||
algorithm from the predecessor key.
|
the predecessor key). Previously, the default for newly
|
||||||
</p>
|
generated keys was RSASHA1.
|
||||||
<p>
|
|
||||||
In prior releases, HMAC algorithms could be generated for
|
|
||||||
use as TSIG keys, but that feature has been removed as of
|
|
||||||
BIND 9.13.0. Use <span class="command"><strong>tsig-keygen</strong></span> to generate
|
|
||||||
TSIG keys.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
|
||||||
@@ -278,6 +277,28 @@
|
|||||||
a satisfactory key.
|
a satisfactory key.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies a source of randomness. Normally, when generating
|
||||||
|
DNSSEC keys, this option has no effect; the random number
|
||||||
|
generation function provided by the cryptographic library will
|
||||||
|
be used.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
If that behavior is disabled at compile time, however,
|
||||||
|
the specified file will be used as entropy source
|
||||||
|
for key generation. <code class="filename">randomdev</code> is
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used. The special value <code class="filename">keyboard</code>
|
||||||
|
indicates that keyboard input should be used.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
The default is <code class="filename">/dev/random</code> if the
|
||||||
|
operating system provides it or an equivalent device;
|
||||||
|
if not, the default source of randomness is keyboard input.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
|
<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2011, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2011, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -99,5 +99,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2011, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2011, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009-2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -18,6 +15,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -30,7 +28,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -49,7 +47,7 @@ usage(void) {
|
|||||||
fprintf(stderr, "Usage:\n");
|
fprintf(stderr, "Usage:\n");
|
||||||
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
||||||
fprintf(stderr, "Version: %s\n", VERSION);
|
fprintf(stderr, "Version: %s\n", VERSION);
|
||||||
#if HAVE_PKCS11
|
#if defined(PKCS11CRYPTO)
|
||||||
fprintf(stderr, " -E engine: specify PKCS#11 provider "
|
fprintf(stderr, " -E engine: specify PKCS#11 provider "
|
||||||
"(default: %s)\n", PK11_LIB_LOCATION);
|
"(default: %s)\n", PK11_LIB_LOCATION);
|
||||||
#elif defined(USE_PKCS11)
|
#elif defined(USE_PKCS11)
|
||||||
@@ -86,6 +84,7 @@ main(int argc, char **argv) {
|
|||||||
char keystr[DST_KEY_FORMATSIZE];
|
char keystr[DST_KEY_FORMATSIZE];
|
||||||
char *endp;
|
char *endp;
|
||||||
int ch;
|
int ch;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
dst_key_t *key = NULL;
|
dst_key_t *key = NULL;
|
||||||
isc_uint32_t flags;
|
isc_uint32_t flags;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
@@ -100,7 +99,7 @@ main(int argc, char **argv) {
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Out of memory");
|
fatal("Out of memory");
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -178,10 +177,17 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
result = dst_lib_init2(mctx, ectx, engine,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Could not initialize dst: %s",
|
fatal("Could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("Could not initialize hash");
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
result = dst_key_fromnamedfile(filename, dir,
|
result = dst_key_fromnamedfile(filename, dir,
|
||||||
DST_TYPE_PUBLIC|DST_TYPE_PRIVATE,
|
DST_TYPE_PUBLIC|DST_TYPE_PRIVATE,
|
||||||
@@ -262,7 +268,9 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
|
isc_hash_destroy();
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
if (dir != NULL)
|
if (dir != NULL)
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2011, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -37,7 +34,6 @@
|
|||||||
<year>2014</year>
|
<year>2014</year>
|
||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009, 2011, 2014-2016, 2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2011, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009-2011, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009-2011, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -200,5 +200,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009-2011, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009-2011, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Copyright (C) 2009-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
|
||||||
* information regarding copyright ownership.
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
@@ -20,6 +17,7 @@
|
|||||||
|
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
@@ -33,7 +31,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -53,7 +51,7 @@ usage(void) {
|
|||||||
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
fprintf(stderr, " %s [options] keyfile\n\n", program);
|
||||||
fprintf(stderr, "Version: %s\n", VERSION);
|
fprintf(stderr, "Version: %s\n", VERSION);
|
||||||
fprintf(stderr, "General options:\n");
|
fprintf(stderr, "General options:\n");
|
||||||
#if HAVE_PKCS11
|
#if defined(PKCS11CRYPTO)
|
||||||
fprintf(stderr, " -E engine: specify PKCS#11 provider "
|
fprintf(stderr, " -E engine: specify PKCS#11 provider "
|
||||||
"(default: %s)\n", PK11_LIB_LOCATION);
|
"(default: %s)\n", PK11_LIB_LOCATION);
|
||||||
#elif defined(USE_PKCS11)
|
#elif defined(USE_PKCS11)
|
||||||
@@ -138,6 +136,7 @@ main(int argc, char **argv) {
|
|||||||
char keystr[DST_KEY_FORMATSIZE];
|
char keystr[DST_KEY_FORMATSIZE];
|
||||||
char *endp, *p;
|
char *endp, *p;
|
||||||
int ch;
|
int ch;
|
||||||
|
isc_entropy_t *ectx = NULL;
|
||||||
const char *predecessor = NULL;
|
const char *predecessor = NULL;
|
||||||
dst_key_t *prevkey = NULL;
|
dst_key_t *prevkey = NULL;
|
||||||
dst_key_t *key = NULL;
|
dst_key_t *key = NULL;
|
||||||
@@ -178,7 +177,7 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging(mctx, &log);
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -376,10 +375,17 @@ main(int argc, char **argv) {
|
|||||||
if (argc > isc_commandline_index + 1)
|
if (argc > isc_commandline_index + 1)
|
||||||
fatal("Extraneous arguments");
|
fatal("Extraneous arguments");
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
result = dst_lib_init2(mctx, ectx, engine,
|
||||||
|
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("Could not initialize dst: %s",
|
fatal("Could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("Could not initialize hash");
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
|
|
||||||
if (predecessor != NULL) {
|
if (predecessor != NULL) {
|
||||||
int major, minor;
|
int major, minor;
|
||||||
@@ -663,7 +669,9 @@ main(int argc, char **argv) {
|
|||||||
if (prevkey != NULL)
|
if (prevkey != NULL)
|
||||||
dst_key_free(&prevkey);
|
dst_key_free(&prevkey);
|
||||||
dst_key_free(&key);
|
dst_key_free(&key);
|
||||||
|
isc_hash_destroy();
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009-2011, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -39,7 +36,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009-2011, 2014-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009-2011, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2009, 2011-2018 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-signzone \- DNSSEC zone signing tool
|
dnssec-signzone \- DNSSEC zone signing tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-signzone\fR\ 'u
|
.HP \w'\fBdnssec\-signzone\fR\ 'u
|
||||||
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-M\ \fR\fB\fImaxttl\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-Q\fR] [\fB\-R\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-M\ \fR\fB\fImaxttl\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-p\fR] [\fB\-Q\fR] [\fB\-R\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-signzone\fR
|
\fBdnssec\-signzone\fR
|
||||||
@@ -278,6 +278,11 @@ specifies the format version of the raw zone file: if N is 0, the raw file can b
|
|||||||
\fBnamed\fR; if N is 1, the file can be read by release 9\&.9\&.0 or higher; the default is 1\&.
|
\fBnamed\fR; if N is 1, the file can be read by release 9\&.9\&.0 or higher; the default is 1\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-p
|
||||||
|
.RS 4
|
||||||
|
Use pseudo\-random data when signing the zone\&. This is faster, but less secure, than using real random data\&. This option may be useful when signing large zones or when the entropy source is limited\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-P
|
\-P
|
||||||
.RS 4
|
.RS 4
|
||||||
Disable post sign verification tests\&.
|
Disable post sign verification tests\&.
|
||||||
@@ -306,6 +311,17 @@ This option is similar to
|
|||||||
to signatures from keys that are no longer published\&. This enables ZSK rollover using the procedure described in RFC 4641, section 4\&.2\&.1\&.2 ("Double Signature Zone Signing Key Rollover")\&.
|
to signatures from keys that are no longer published\&. This enables ZSK rollover using the procedure described in RFC 4641, section 4\&.2\&.1\&.2 ("Double Signature Zone Signing Key Rollover")\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-r \fIrandomdev\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies the source of randomness\&. If the operating system does not provide a
|
||||||
|
/dev/random
|
||||||
|
or equivalent device, the default source of randomness is keyboard input\&.
|
||||||
|
randomdev
|
||||||
|
specifies the name of a character device or file containing random data to be used instead of the default\&. The special value
|
||||||
|
keyboard
|
||||||
|
indicates that keyboard input should be used\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-S
|
\-S
|
||||||
.RS 4
|
.RS 4
|
||||||
Smart signing: Instructs
|
Smart signing: Instructs
|
||||||
@@ -468,5 +484,5 @@ RFC 4641\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2009, 2011-2018 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1,14 +1,11 @@
|
|||||||
/*
|
/*
|
||||||
* Portions Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
* Portions Copyright (C) 1999-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
*
|
*
|
||||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
*
|
*
|
||||||
* See the COPYRIGHT file distributed with this work for additional
|
* Portions Copyright (C) 1995-2000 by Network Associates, Inc.
|
||||||
* information regarding copyright ownership.
|
|
||||||
*
|
|
||||||
* Portions Copyright (C) Network Associates, Inc.
|
|
||||||
*
|
*
|
||||||
* Permission to use, copy, modify, and/or distribute this software for any
|
* Permission to use, copy, modify, and/or distribute this software for any
|
||||||
* purpose with or without fee is hereby granted, provided that the above
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
@@ -34,6 +31,7 @@
|
|||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/base32.h>
|
#include <isc/base32.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
|
#include <isc/entropy.h>
|
||||||
#include <isc/event.h>
|
#include <isc/event.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
@@ -79,7 +77,7 @@
|
|||||||
|
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
#include <pk11/result.h>
|
#include <pk11/result.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -129,6 +127,7 @@ static int jitter = 0;
|
|||||||
static isc_boolean_t tryverify = ISC_FALSE;
|
static isc_boolean_t tryverify = ISC_FALSE;
|
||||||
static isc_boolean_t printstats = ISC_FALSE;
|
static isc_boolean_t printstats = ISC_FALSE;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
static isc_entropy_t *ectx = NULL;
|
||||||
static dns_ttl_t zone_soa_min_ttl;
|
static dns_ttl_t zone_soa_min_ttl;
|
||||||
static dns_ttl_t soa_ttl;
|
static dns_ttl_t soa_ttl;
|
||||||
static FILE *outfp = NULL;
|
static FILE *outfp = NULL;
|
||||||
@@ -280,10 +279,11 @@ signwithkey(dns_name_t *name, dns_rdataset_t *rdataset, dst_key_t *key,
|
|||||||
else
|
else
|
||||||
expiry = endtime;
|
expiry = endtime;
|
||||||
|
|
||||||
jendtime = (jitter != 0) ? expiry - isc_random_uniform(jitter) : expiry;
|
jendtime = (jitter != 0) ? isc_random_jitter(expiry, jitter) : expiry;
|
||||||
isc_buffer_init(&b, array, sizeof(array));
|
isc_buffer_init(&b, array, sizeof(array));
|
||||||
result = dns_dnssec_sign(name, rdataset, key, &starttime, &jendtime,
|
result = dns_dnssec_sign(name, rdataset, key, &starttime, &jendtime,
|
||||||
mctx, &b, &trdata);
|
mctx, &b, &trdata);
|
||||||
|
isc_entropy_stopcallbacksources(ectx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("dnskey '%s' failed to sign data: %s",
|
fatal("dnskey '%s' failed to sign data: %s",
|
||||||
keystr, isc_result_totext(result));
|
keystr, isc_result_totext(result));
|
||||||
@@ -292,8 +292,8 @@ signwithkey(dns_name_t *name, dns_rdataset_t *rdataset, dst_key_t *key,
|
|||||||
|
|
||||||
if (tryverify) {
|
if (tryverify) {
|
||||||
result = dns_dnssec_verify(name, rdataset, key,
|
result = dns_dnssec_verify(name, rdataset, key,
|
||||||
ISC_TRUE, 0, mctx, &trdata, NULL);
|
ISC_TRUE, mctx, &trdata);
|
||||||
if (result == ISC_R_SUCCESS || result == DNS_R_FROMWILDCARD) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
vbprintf(3, "\tsignature verified\n");
|
vbprintf(3, "\tsignature verified\n");
|
||||||
INCSTAT(nverified);
|
INCSTAT(nverified);
|
||||||
} else {
|
} else {
|
||||||
@@ -453,9 +453,8 @@ setverifies(dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|||||||
dns_rdata_t *rrsig)
|
dns_rdata_t *rrsig)
|
||||||
{
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
result = dns_dnssec_verify(name, set, key, ISC_FALSE, 0, mctx, rrsig,
|
result = dns_dnssec_verify(name, set, key, ISC_FALSE, mctx, rrsig);
|
||||||
NULL);
|
if (result == ISC_R_SUCCESS) {
|
||||||
if (result == ISC_R_SUCCESS || result == DNS_R_FROMWILDCARD) {
|
|
||||||
INCSTAT(nverified);
|
INCSTAT(nverified);
|
||||||
return (ISC_TRUE);
|
return (ISC_TRUE);
|
||||||
} else {
|
} else {
|
||||||
@@ -717,17 +716,6 @@ hashlist_init(hashlist_t *l, unsigned int nodes, unsigned int length) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
|
||||||
hashlist_free(hashlist_t *l) {
|
|
||||||
if (l->hashbuf) {
|
|
||||||
free(l->hashbuf);
|
|
||||||
l->hashbuf = NULL;
|
|
||||||
l->entries = 0;
|
|
||||||
l->length = 0;
|
|
||||||
l->size = 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
hashlist_add(hashlist_t *l, const unsigned char *hash, size_t len)
|
hashlist_add(hashlist_t *l, const unsigned char *hash, size_t len)
|
||||||
{
|
{
|
||||||
@@ -847,7 +835,8 @@ addnowildcardhash(hashlist_t *l, /*const*/ dns_name_t *name,
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
char namestr[DNS_NAME_FORMATSIZE];
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
|
|
||||||
wild = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
wild = dns_fixedname_name(&fixed);
|
||||||
|
|
||||||
result = dns_name_concatenate(dns_wildcardname, name, wild, NULL);
|
result = dns_name_concatenate(dns_wildcardname, name, wild, NULL);
|
||||||
if (result == ISC_R_NOSPACE)
|
if (result == ISC_R_NOSPACE)
|
||||||
@@ -902,7 +891,7 @@ opendb(const char *prefix, dns_name_t *name, dns_rdataclass_t rdclass,
|
|||||||
rdclass, 0, NULL, dbp);
|
rdclass, 0, NULL, dbp);
|
||||||
check_result(result, "dns_db_create()");
|
check_result(result, "dns_db_create()");
|
||||||
|
|
||||||
result = dns_db_load(*dbp, filename, inputformat, DNS_MASTER_HINT);
|
result = dns_db_load3(*dbp, filename, inputformat, DNS_MASTER_HINT);
|
||||||
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
||||||
dns_db_detach(dbp);
|
dns_db_detach(dbp);
|
||||||
}
|
}
|
||||||
@@ -1233,7 +1222,8 @@ get_soa_ttls(void) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
dns_rdataset_init(&soaset);
|
dns_rdataset_init(&soaset);
|
||||||
result = dns_db_find(gdb, gorigin, gversion, dns_rdatatype_soa,
|
result = dns_db_find(gdb, gorigin, gversion, dns_rdatatype_soa,
|
||||||
0, 0, NULL, name, &soaset, NULL);
|
0, 0, NULL, name, &soaset, NULL);
|
||||||
@@ -1402,7 +1392,8 @@ signapex(void) {
|
|||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
result = dns_dbiterator_seek(gdbiter, gorigin);
|
result = dns_dbiterator_seek(gdbiter, gorigin);
|
||||||
check_result(result, "dns_dbiterator_seek()");
|
check_result(result, "dns_dbiterator_seek()");
|
||||||
result = dns_dbiterator_current(gdbiter, &node, name);
|
result = dns_dbiterator_current(gdbiter, &node, name);
|
||||||
@@ -1452,7 +1443,8 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|||||||
fname = isc_mem_get(mctx, sizeof(dns_fixedname_t));
|
fname = isc_mem_get(mctx, sizeof(dns_fixedname_t));
|
||||||
if (fname == NULL)
|
if (fname == NULL)
|
||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
name = dns_fixedname_initname(fname);
|
dns_fixedname_init(fname);
|
||||||
|
name = dns_fixedname_name(fname);
|
||||||
node = NULL;
|
node = NULL;
|
||||||
found = ISC_FALSE;
|
found = ISC_FALSE;
|
||||||
while (!found) {
|
while (!found) {
|
||||||
@@ -1486,7 +1478,8 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|||||||
(zonecut == NULL ||
|
(zonecut == NULL ||
|
||||||
!dns_name_issubdomain(name, zonecut))) {
|
!dns_name_issubdomain(name, zonecut))) {
|
||||||
if (is_delegation(gdb, gversion, gorigin, name, node, NULL)) {
|
if (is_delegation(gdb, gversion, gorigin, name, node, NULL)) {
|
||||||
zonecut = dns_fixedname_initname(&fzonecut);
|
dns_fixedname_init(&fzonecut);
|
||||||
|
zonecut = dns_fixedname_name(&fzonecut);
|
||||||
dns_name_copy(name, zonecut, NULL);
|
dns_name_copy(name, zonecut, NULL);
|
||||||
if (!OPTOUT(nsec3flags) ||
|
if (!OPTOUT(nsec3flags) ||
|
||||||
secure(name, node))
|
secure(name, node))
|
||||||
@@ -1729,8 +1722,10 @@ nsecify(void) {
|
|||||||
isc_uint32_t nsttl = 0;
|
isc_uint32_t nsttl = 0;
|
||||||
|
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
nextname = dns_fixedname_initname(&fnextname);
|
name = dns_fixedname_name(&fname);
|
||||||
|
dns_fixedname_init(&fnextname);
|
||||||
|
nextname = dns_fixedname_name(&fnextname);
|
||||||
dns_fixedname_init(&fzonecut);
|
dns_fixedname_init(&fzonecut);
|
||||||
zonecut = NULL;
|
zonecut = NULL;
|
||||||
|
|
||||||
@@ -2142,7 +2137,8 @@ cleanup_zone(void) {
|
|||||||
|
|
||||||
dns_diff_init(mctx, &add);
|
dns_diff_init(mctx, &add);
|
||||||
dns_diff_init(mctx, &del);
|
dns_diff_init(mctx, &del);
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
|
|
||||||
result = dns_db_createiterator(gdb, 0, &dbiter);
|
result = dns_db_createiterator(gdb, 0, &dbiter);
|
||||||
@@ -2202,8 +2198,10 @@ nsec3ify(unsigned int hashalg, dns_iterations_t iterations,
|
|||||||
unsigned int count, nlabels;
|
unsigned int count, nlabels;
|
||||||
|
|
||||||
dns_rdataset_init(&rdataset);
|
dns_rdataset_init(&rdataset);
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
nextname = dns_fixedname_initname(&fnextname);
|
name = dns_fixedname_name(&fname);
|
||||||
|
dns_fixedname_init(&fnextname);
|
||||||
|
nextname = dns_fixedname_name(&fnextname);
|
||||||
dns_fixedname_init(&fzonecut);
|
dns_fixedname_init(&fzonecut);
|
||||||
zonecut = NULL;
|
zonecut = NULL;
|
||||||
|
|
||||||
@@ -2447,7 +2445,8 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
|||||||
isc_buffer_init(&b, origin, len);
|
isc_buffer_init(&b, origin, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
|
|
||||||
name = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
name = dns_fixedname_name(&fname);
|
||||||
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
result = dns_name_fromtext(name, &b, dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("failed converting name '%s' to dns format: %s",
|
fatal("failed converting name '%s' to dns format: %s",
|
||||||
@@ -2457,7 +2456,7 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
|||||||
rdclass, 0, NULL, db);
|
rdclass, 0, NULL, db);
|
||||||
check_result(result, "dns_db_create()");
|
check_result(result, "dns_db_create()");
|
||||||
|
|
||||||
result = dns_db_load(*db, file, inputformat, 0);
|
result = dns_db_load2(*db, file, inputformat);
|
||||||
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
if (result != ISC_R_SUCCESS && result != DNS_R_SEENINCLUDE)
|
||||||
fatal("failed loading zone from '%s': %s",
|
fatal("failed loading zone from '%s': %s",
|
||||||
file, isc_result_totext(result));
|
file, isc_result_totext(result));
|
||||||
@@ -2503,11 +2502,11 @@ loadzonekeys(isc_boolean_t preserve_keys, isc_boolean_t load_public) {
|
|||||||
goto cleanup;
|
goto cleanup;
|
||||||
|
|
||||||
if (set_keyttl && keyttl != rdataset.ttl) {
|
if (set_keyttl && keyttl != rdataset.ttl) {
|
||||||
fprintf(stderr, "User-specified TTL %u conflicts "
|
fprintf(stderr, "User-specified TTL %d conflicts "
|
||||||
"with existing DNSKEY RRset TTL.\n",
|
"with existing DNSKEY RRset TTL.\n",
|
||||||
keyttl);
|
keyttl);
|
||||||
fprintf(stderr, "Imported keys will use the RRSet "
|
fprintf(stderr, "Imported keys will use the RRSet "
|
||||||
"TTL %u instead.\n",
|
"TTL %d instead.\n",
|
||||||
rdataset.ttl);
|
rdataset.ttl);
|
||||||
}
|
}
|
||||||
keyttl = rdataset.ttl;
|
keyttl = rdataset.ttl;
|
||||||
@@ -2623,7 +2622,7 @@ build_final_keylist(void) {
|
|||||||
* Find keys that match this zone in the key repository.
|
* Find keys that match this zone in the key repository.
|
||||||
*/
|
*/
|
||||||
result = dns_dnssec_findmatchingkeys(gorigin, directory,
|
result = dns_dnssec_findmatchingkeys(gorigin, directory,
|
||||||
now, mctx, &matchkeys);
|
mctx, &matchkeys);
|
||||||
if (result == ISC_R_NOTFOUND) {
|
if (result == ISC_R_NOTFOUND) {
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
}
|
}
|
||||||
@@ -2795,7 +2794,8 @@ set_nsec3params(isc_boolean_t update, isc_boolean_t set_salt,
|
|||||||
* (This assumes all NSEC3 records agree.)
|
* (This assumes all NSEC3 records agree.)
|
||||||
*/
|
*/
|
||||||
|
|
||||||
hashname = dns_fixedname_initname(&fname);
|
dns_fixedname_init(&fname);
|
||||||
|
hashname = dns_fixedname_name(&fname);
|
||||||
result = dns_nsec3_hashname(&fname, NULL, NULL,
|
result = dns_nsec3_hashname(&fname, NULL, NULL,
|
||||||
gorigin, gorigin, dns_hash_sha1,
|
gorigin, gorigin, dns_hash_sha1,
|
||||||
orig_iter, orig_salt, orig_saltlen);
|
orig_iter, orig_salt, orig_saltlen);
|
||||||
@@ -2884,7 +2884,8 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
unsigned int labels;
|
unsigned int labels;
|
||||||
|
|
||||||
dns_name_init(&tname, NULL);
|
dns_name_init(&tname, NULL);
|
||||||
name = dns_fixedname_initname(&fixed);
|
dns_fixedname_init(&fixed);
|
||||||
|
name = dns_fixedname_name(&fixed);
|
||||||
labels = dns_name_countlabels(gorigin);
|
labels = dns_name_countlabels(gorigin);
|
||||||
dns_name_getlabelsequence(gorigin, 0, labels - 1, &tname);
|
dns_name_getlabelsequence(gorigin, 0, labels - 1, &tname);
|
||||||
result = dns_name_concatenate(&tname, dlv, name, NULL);
|
result = dns_name_concatenate(&tname, dlv, name, NULL);
|
||||||
@@ -2970,8 +2971,7 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
check_result(result, "dns_diff_apply");
|
check_result(result, "dns_diff_apply");
|
||||||
dns_diff_clear(&diff);
|
dns_diff_clear(&diff);
|
||||||
|
|
||||||
result = dns_master_dump(mctx, db, dbversion, style, filename,
|
result = dns_master_dump(mctx, db, dbversion, style, filename);
|
||||||
dns_masterformat_text, NULL);
|
|
||||||
check_result(result, "dns_master_dump");
|
check_result(result, "dns_master_dump");
|
||||||
|
|
||||||
isc_mem_put(mctx, filename, filenamelen);
|
isc_mem_put(mctx, filename, filenamelen);
|
||||||
@@ -3053,11 +3053,13 @@ usage(void) {
|
|||||||
fprintf(stderr, "\t\tsoa serial format of signed zone file (keep)\n");
|
fprintf(stderr, "\t\tsoa serial format of signed zone file (keep)\n");
|
||||||
fprintf(stderr, "\t-D:\n");
|
fprintf(stderr, "\t-D:\n");
|
||||||
fprintf(stderr, "\t\toutput only DNSSEC-related records\n");
|
fprintf(stderr, "\t\toutput only DNSSEC-related records\n");
|
||||||
|
fprintf(stderr, "\t-r randomdev:\n");
|
||||||
|
fprintf(stderr, "\t\ta file containing random data\n");
|
||||||
fprintf(stderr, "\t-a:\t");
|
fprintf(stderr, "\t-a:\t");
|
||||||
fprintf(stderr, "verify generated signatures\n");
|
fprintf(stderr, "verify generated signatures\n");
|
||||||
fprintf(stderr, "\t-c class (IN)\n");
|
fprintf(stderr, "\t-c class (IN)\n");
|
||||||
fprintf(stderr, "\t-E engine:\n");
|
fprintf(stderr, "\t-E engine:\n");
|
||||||
#if HAVE_PKCS11
|
#if defined(PKCS11CRYPTO)
|
||||||
fprintf(stderr, "\t\tpath to PKCS#11 provider library "
|
fprintf(stderr, "\t\tpath to PKCS#11 provider library "
|
||||||
"(default is %s)\n", PK11_LIB_LOCATION);
|
"(default is %s)\n", PK11_LIB_LOCATION);
|
||||||
#elif defined(USE_PKCS11)
|
#elif defined(USE_PKCS11)
|
||||||
@@ -3066,6 +3068,8 @@ usage(void) {
|
|||||||
#else
|
#else
|
||||||
fprintf(stderr, "\t\tname of an OpenSSL engine to use\n");
|
fprintf(stderr, "\t\tname of an OpenSSL engine to use\n");
|
||||||
#endif
|
#endif
|
||||||
|
fprintf(stderr, "\t-p:\t");
|
||||||
|
fprintf(stderr, "use pseudorandom data (faster but less secure)\n");
|
||||||
fprintf(stderr, "\t-P:\t");
|
fprintf(stderr, "\t-P:\t");
|
||||||
fprintf(stderr, "disable post-sign verification\n");
|
fprintf(stderr, "disable post-sign verification\n");
|
||||||
fprintf(stderr, "\t-Q:\t");
|
fprintf(stderr, "\t-Q:\t");
|
||||||
@@ -3113,12 +3117,12 @@ print_stats(isc_time_t *timer_start, isc_time_t *timer_finish,
|
|||||||
isc_uint64_t sig_ms; /* Signatures per millisecond */
|
isc_uint64_t sig_ms; /* Signatures per millisecond */
|
||||||
FILE *out = output_stdout ? stderr : stdout;
|
FILE *out = output_stdout ? stderr : stdout;
|
||||||
|
|
||||||
fprintf(out, "Signatures generated: %10u\n", nsigned);
|
fprintf(out, "Signatures generated: %10d\n", nsigned);
|
||||||
fprintf(out, "Signatures retained: %10u\n", nretained);
|
fprintf(out, "Signatures retained: %10d\n", nretained);
|
||||||
fprintf(out, "Signatures dropped: %10u\n", ndropped);
|
fprintf(out, "Signatures dropped: %10d\n", ndropped);
|
||||||
fprintf(out, "Signatures successfully verified: %10u\n", nverified);
|
fprintf(out, "Signatures successfully verified: %10d\n", nverified);
|
||||||
fprintf(out, "Signatures unsuccessfully "
|
fprintf(out, "Signatures unsuccessfully "
|
||||||
"verified: %10u\n", nverifyfailed);
|
"verified: %10d\n", nverifyfailed);
|
||||||
|
|
||||||
time_us = isc_time_microdiff(sign_finish, sign_start);
|
time_us = isc_time_microdiff(sign_finish, sign_start);
|
||||||
time_ms = time_us / 1000;
|
time_ms = time_us / 1000;
|
||||||
@@ -3155,11 +3159,13 @@ main(int argc, char *argv[]) {
|
|||||||
dns_dnsseckey_t *key;
|
dns_dnsseckey_t *key;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
|
isc_boolean_t pseudorandom = ISC_FALSE;
|
||||||
#ifdef USE_PKCS11
|
#ifdef USE_PKCS11
|
||||||
const char *engine = PKCS11_ENGINE;
|
const char *engine = PKCS11_ENGINE;
|
||||||
#else
|
#else
|
||||||
const char *engine = NULL;
|
const char *engine = NULL;
|
||||||
#endif
|
#endif
|
||||||
|
unsigned int eflags;
|
||||||
isc_boolean_t free_output = ISC_FALSE;
|
isc_boolean_t free_output = ISC_FALSE;
|
||||||
int tempfilelen = 0;
|
int tempfilelen = 0;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
@@ -3212,7 +3218,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
|
|
||||||
#if HAVE_PKCS11
|
#ifdef PKCS11CRYPTO
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
#endif
|
#endif
|
||||||
dns_result_register();
|
dns_result_register();
|
||||||
@@ -3344,7 +3350,8 @@ main(int argc, char *argv[]) {
|
|||||||
isc_buffer_init(&b, isc_commandline_argument, len);
|
isc_buffer_init(&b, isc_commandline_argument, len);
|
||||||
isc_buffer_add(&b, len);
|
isc_buffer_add(&b, len);
|
||||||
|
|
||||||
dlv = dns_fixedname_initname(&dlv_fixed);
|
dns_fixedname_init(&dlv_fixed);
|
||||||
|
dlv = dns_fixedname_name(&dlv_fixed);
|
||||||
result = dns_name_fromtext(dlv, &b, dns_rootname, 0,
|
result = dns_name_fromtext(dlv, &b, dns_rootname, 0,
|
||||||
NULL);
|
NULL);
|
||||||
check_result(result, "dns_name_fromtext(dlv)");
|
check_result(result, "dns_name_fromtext(dlv)");
|
||||||
@@ -3388,7 +3395,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'p':
|
case 'p':
|
||||||
fatal("The -p option has been deprecated.\n");
|
pseudorandom = ISC_TRUE;
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'Q':
|
case 'Q':
|
||||||
@@ -3400,7 +3407,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'r':
|
case 'r':
|
||||||
fatal("The -r options has been deprecated.\n");
|
setup_entropy(mctx, isc_commandline_argument, &ectx);
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'S':
|
case 'S':
|
||||||
@@ -3476,11 +3483,21 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, engine);
|
if (ectx == NULL)
|
||||||
|
setup_entropy(mctx, NULL, &ectx);
|
||||||
|
eflags = ISC_ENTROPY_BLOCKING;
|
||||||
|
if (!pseudorandom)
|
||||||
|
eflags |= ISC_ENTROPY_GOODONLY;
|
||||||
|
|
||||||
|
result = dst_lib_init2(mctx, ectx, engine, eflags);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
|
||||||
|
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
fatal("could not create hash context");
|
||||||
|
|
||||||
isc_stdtime_get(&now);
|
isc_stdtime_get(&now);
|
||||||
|
|
||||||
if (startstr != NULL) {
|
if (startstr != NULL) {
|
||||||
@@ -3606,8 +3623,8 @@ main(int argc, char *argv[]) {
|
|||||||
if (output_dnssec_only && set_maxttl)
|
if (output_dnssec_only && set_maxttl)
|
||||||
fatal("option -D cannot be used with -M");
|
fatal("option -D cannot be used with -M");
|
||||||
|
|
||||||
result = dns_master_stylecreate(&dsstyle, DNS_STYLEFLAG_NO_TTL,
|
result = dns_master_stylecreate(&dsstyle, DNS_STYLEFLAG_NO_TTL,
|
||||||
0, 24, 0, 0, 0, 8, 0xffffffff, mctx);
|
0, 24, 0, 0, 0, 8, mctx);
|
||||||
check_result(result, "dns_master_stylecreate");
|
check_result(result, "dns_master_stylecreate");
|
||||||
|
|
||||||
gdb = NULL;
|
gdb = NULL;
|
||||||
@@ -3618,8 +3635,8 @@ main(int argc, char *argv[]) {
|
|||||||
get_soa_ttls();
|
get_soa_ttls();
|
||||||
|
|
||||||
if (set_maxttl && set_keyttl && keyttl > maxttl) {
|
if (set_maxttl && set_keyttl && keyttl > maxttl) {
|
||||||
fprintf(stderr, "%s: warning: Specified key TTL %u "
|
fprintf(stderr, "%s: warning: Specified key TTL %d "
|
||||||
"exceeds maximum zone TTL; reducing to %u\n",
|
"exceeds maximum zone TTL; reducing to %d\n",
|
||||||
program, keyttl, maxttl);
|
program, keyttl, maxttl);
|
||||||
keyttl = maxttl;
|
keyttl = maxttl;
|
||||||
}
|
}
|
||||||
@@ -3714,8 +3731,6 @@ main(int argc, char *argv[]) {
|
|||||||
if (nsec3iter > max)
|
if (nsec3iter > max)
|
||||||
fatal("NSEC3 iterations too big for weakest DNSKEY "
|
fatal("NSEC3 iterations too big for weakest DNSKEY "
|
||||||
"strength. Maximum iterations allowed %u.", max);
|
"strength. Maximum iterations allowed %u.", max);
|
||||||
} else {
|
|
||||||
hashlist_init(&hashlist, 0, 0); /* silence clang */
|
|
||||||
}
|
}
|
||||||
|
|
||||||
gversion = NULL;
|
gversion = NULL;
|
||||||
@@ -3851,9 +3866,9 @@ main(int argc, char *argv[]) {
|
|||||||
header.flags = DNS_MASTERRAW_SOURCESERIALSET;
|
header.flags = DNS_MASTERRAW_SOURCESERIALSET;
|
||||||
header.sourceserial = serialnum;
|
header.sourceserial = serialnum;
|
||||||
}
|
}
|
||||||
result = dns_master_dumptostream(mctx, gdb, gversion,
|
result = dns_master_dumptostream3(mctx, gdb, gversion,
|
||||||
masterstyle, outputformat,
|
masterstyle, outputformat,
|
||||||
&header, outfp);
|
&header, outfp);
|
||||||
check_result(result, "dns_master_dumptostream3");
|
check_result(result, "dns_master_dumptostream3");
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -3877,8 +3892,6 @@ main(int argc, char *argv[]) {
|
|||||||
dns_db_closeversion(gdb, &gversion, ISC_FALSE);
|
dns_db_closeversion(gdb, &gversion, ISC_FALSE);
|
||||||
dns_db_detach(&gdb);
|
dns_db_detach(&gdb);
|
||||||
|
|
||||||
hashlist_free(&hashlist);
|
|
||||||
|
|
||||||
while (!ISC_LIST_EMPTY(keylist)) {
|
while (!ISC_LIST_EMPTY(keylist)) {
|
||||||
key = ISC_LIST_HEAD(keylist);
|
key = ISC_LIST_HEAD(keylist);
|
||||||
ISC_LIST_UNLINK(keylist, key, link);
|
ISC_LIST_UNLINK(keylist, key, link);
|
||||||
@@ -3894,7 +3907,9 @@ main(int argc, char *argv[]) {
|
|||||||
dns_master_styledestroy(&dsstyle, mctx);
|
dns_master_styledestroy(&dsstyle, mctx);
|
||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
|
isc_hash_destroy();
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
|
cleanup_entropy(&ectx);
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
|
|||||||
@@ -1,12 +1,9 @@
|
|||||||
<!--
|
<!--
|
||||||
- Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
-
|
|
||||||
- See the COPYRIGHT file distributed with this work for additional
|
|
||||||
- information regarding copyright ownership.
|
|
||||||
-->
|
-->
|
||||||
|
|
||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
@@ -49,7 +46,6 @@
|
|||||||
<year>2015</year>
|
<year>2015</year>
|
||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -78,8 +74,10 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P</option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-p</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-Q</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-Q</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-R</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-R</option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-S</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-S</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
|
||||||
@@ -506,6 +504,18 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-p</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Use pseudo-random data when signing the zone. This is faster,
|
||||||
|
but less secure, than using real random data. This option
|
||||||
|
may be useful when signing large zones or when the entropy
|
||||||
|
source is limited.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-P</term>
|
<term>-P</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -557,6 +567,23 @@
|
|||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
<varlistentry>
|
||||||
|
<term>-r <replaceable class="parameter">randomdev</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies the source of randomness. If the operating
|
||||||
|
system does not provide a <filename>/dev/random</filename>
|
||||||
|
or equivalent device, the default source of randomness
|
||||||
|
is keyboard input. <filename>randomdev</filename>
|
||||||
|
specifies
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used instead of the default. The special value
|
||||||
|
<filename>keyboard</filename> indicates that keyboard
|
||||||
|
input should be used.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-S</term>
|
<term>-S</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2009, 2011-2018 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -54,8 +54,10 @@
|
|||||||
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
||||||
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
||||||
[<code class="option">-P</code>]
|
[<code class="option">-P</code>]
|
||||||
|
[<code class="option">-p</code>]
|
||||||
[<code class="option">-Q</code>]
|
[<code class="option">-Q</code>]
|
||||||
[<code class="option">-R</code>]
|
[<code class="option">-R</code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>]
|
||||||
[<code class="option">-S</code>]
|
[<code class="option">-S</code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>]
|
||||||
[<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>]
|
[<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>]
|
||||||
@@ -398,6 +400,15 @@
|
|||||||
can be read by release 9.9.0 or higher; the default is 1.
|
can be read by release 9.9.0 or higher; the default is 1.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-p</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Use pseudo-random data when signing the zone. This is faster,
|
||||||
|
but less secure, than using real random data. This option
|
||||||
|
may be useful when signing large zones or when the entropy
|
||||||
|
source is limited.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-P</span></dt>
|
<dt><span class="term">-P</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -442,6 +453,20 @@
|
|||||||
("Double Signature Zone Signing Key Rollover").
|
("Double Signature Zone Signing Key Rollover").
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies the source of randomness. If the operating
|
||||||
|
system does not provide a <code class="filename">/dev/random</code>
|
||||||
|
or equivalent device, the default source of randomness
|
||||||
|
is keyboard input. <code class="filename">randomdev</code>
|
||||||
|
specifies
|
||||||
|
the name of a character device or file containing random
|
||||||
|
data to be used instead of the default. The special value
|
||||||
|
<code class="filename">keyboard</code> indicates that keyboard
|
||||||
|
input should be used.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-S</span></dt>
|
<dt><span class="term">-S</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user