Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0e980ca93f | ||
|
|
d31810294b | ||
|
|
18a1bea187 | ||
|
|
10c8c23739 | ||
|
|
08a3dedda1 | ||
|
|
a341252fdd | ||
|
|
4b1eb6a502 | ||
|
|
29d9488d16 | ||
|
|
838a7c6c6b | ||
|
|
a8496f51a8 | ||
|
|
3abcd7cd8a | ||
|
|
5daa633313 | ||
|
|
28c58f39e9 | ||
|
|
8422d43dbc | ||
|
|
b856e695d0 | ||
|
|
5b60d0608a | ||
|
|
2bd2487f51 | ||
|
|
fa644181f5 | ||
|
|
cac4114e9d | ||
|
|
d0c3272eaa | ||
|
|
99ab7127e1 | ||
|
|
560d8b833e | ||
|
|
77c7d1c555 | ||
|
|
9f1e715a64 | ||
|
|
025f606463 | ||
|
|
89b2fc092d | ||
|
|
94f022ec02 | ||
|
|
a9a983781e | ||
|
|
defa292088 | ||
|
|
b2597ce86b | ||
|
|
800fbdfc9c | ||
|
|
0d61fe5dfd | ||
|
|
5de02a075b | ||
|
|
1ca7e01aa7 | ||
|
|
b4c8cab0e2 | ||
|
|
16d6fab2e5 | ||
|
|
9492533d46 | ||
|
|
74f46c45b0 | ||
|
|
23a4f70be0 | ||
|
|
005bdf067b | ||
|
|
5414e48606 | ||
|
|
971503762e | ||
|
|
4c368378fc | ||
|
|
bd08d94f8b | ||
|
|
c89f1bf1b6 | ||
|
|
6cdff94830 | ||
|
|
077f9626c2 | ||
|
|
c0f78692ee | ||
|
|
5df3f839b2 | ||
|
|
2d22725336 | ||
|
|
8c3ee6e6a5 | ||
|
|
42ed778b94 | ||
|
|
cd20cbc9c0 | ||
|
|
7623f92536 | ||
|
|
3b5e75c07a | ||
|
|
2e3b69a800 | ||
|
|
fa512bc524 | ||
|
|
02a669a9a6 | ||
|
|
e09b9e7a91 | ||
|
|
fb5c7e04d3 | ||
|
|
fd140b1261 | ||
|
|
352185e9a8 | ||
|
|
0f91b4097f | ||
|
|
4c6df1653c | ||
|
|
f28498dca1 | ||
|
|
ec0a9c0525 | ||
|
|
6636beb00b | ||
|
|
81198ca4b8 | ||
|
|
995c41e8f0 | ||
|
|
7baa39fc96 | ||
|
|
4101e6d31d | ||
|
|
417218837e | ||
|
|
6bdb69aca4 | ||
|
|
a0c408c90d | ||
|
|
fffbe14289 | ||
|
|
de4d6c4a2d | ||
|
|
2833d094b3 | ||
|
|
b386a826a6 | ||
|
|
6e52e19e3b | ||
|
|
b41c1aacbc | ||
|
|
99e0079380 | ||
|
|
26cde05da4 | ||
|
|
ddcf6c7d2b | ||
|
|
5f55e84a76 | ||
|
|
94f3abed4c | ||
|
|
1e14ea024a | ||
|
|
3f3b51e7af | ||
|
|
c6a63672d1 | ||
|
|
6e51774a60 | ||
|
|
ba37674d03 | ||
|
|
14afc8425b | ||
|
|
d7ee3ed488 | ||
|
|
c370305901 | ||
|
|
abaa9755d2 | ||
|
|
7ac51a8380 | ||
|
|
bdf8fee0e9 | ||
|
|
319aad330d | ||
|
|
653ca094e8 | ||
|
|
9a28f66610 | ||
|
|
34efd9ad93 | ||
|
|
055d310e54 | ||
|
|
4615bc5408 | ||
|
|
d1e823af15 | ||
|
|
e541ee4599 | ||
|
|
396125eefe | ||
|
|
5fcdb09126 | ||
|
|
0bb0890867 | ||
|
|
d227e15567 | ||
|
|
e1c96ad444 | ||
|
|
ca0ae70046 | ||
|
|
0218bd7957 | ||
|
|
a5a60037e5 | ||
|
|
57c04ec865 | ||
|
|
9510de7849 | ||
|
|
b47814be1c | ||
|
|
e515fae2ae | ||
|
|
762dc8b871 | ||
|
|
f29359299a | ||
|
|
a009d03a1a | ||
|
|
7cb14b610e | ||
|
|
c85b467dc0 | ||
|
|
af3f476e77 | ||
|
|
c0f8a8f30a | ||
|
|
a57a6dbe62 | ||
|
|
bf50a60e39 | ||
|
|
3bb6150cae | ||
|
|
5fbc5c9225 | ||
|
|
791aa3e9be | ||
|
|
dc0a792d94 | ||
|
|
83b5464a1f | ||
|
|
24172bd2ee | ||
|
|
86e5d14e82 | ||
|
|
768f6c995f | ||
|
|
f735293431 | ||
|
|
e00fdad191 | ||
|
|
e880197f31 | ||
|
|
6d5608c14d | ||
|
|
d386eb54c6 | ||
|
|
abb8813a33 | ||
|
|
2495de04a5 | ||
|
|
42ee853c23 | ||
|
|
73074e954a | ||
|
|
b4c31c8795 | ||
|
|
f9f3f20d2d | ||
|
|
744061a03b | ||
|
|
08151d7fce | ||
|
|
acc3728c47 | ||
|
|
eb1e4cce6c | ||
|
|
2919a6d34b | ||
|
|
e02abf7ed8 | ||
|
|
fb9712f639 | ||
|
|
6138c5a5e4 | ||
|
|
3148dee766 | ||
|
|
81c9fdd472 | ||
|
|
8200eb4c60 | ||
|
|
83df1994f2 | ||
|
|
2278a14b52 | ||
|
|
af7ded82e0 | ||
|
|
243b3ec486 | ||
|
|
f8c82bbf39 | ||
|
|
e8703033c5 | ||
|
|
d17cf1cade | ||
|
|
cd8e7e8bf8 | ||
|
|
7300f231d6 | ||
|
|
7a2112ff7d | ||
|
|
924d93d4e7 | ||
|
|
0c03a0fb2d | ||
|
|
db22b3ea1f | ||
|
|
ffbe6b9537 | ||
|
|
39a967ff0e | ||
|
|
d12179dd98 | ||
|
|
c750533ce1 | ||
|
|
32bcafc316 | ||
|
|
e2ed24aa4d | ||
|
|
98998f3ddd | ||
|
|
d5707676e4 | ||
|
|
404c9b1c53 | ||
|
|
fb088a00cf | ||
|
|
0e35e567d1 | ||
|
|
cb5bc50c91 | ||
|
|
a9631d156a | ||
|
|
49740fb0f2 | ||
|
|
f665c724e4 | ||
|
|
c2179857de | ||
|
|
0bcb8b0b7c | ||
|
|
c3506e8d75 | ||
|
|
8a98277811 | ||
|
|
c43ed04d37 | ||
|
|
aed87173fd | ||
|
|
6e5ae91479 | ||
|
|
e98d70750c | ||
|
|
0b115f3b55 | ||
|
|
61996344fe | ||
|
|
ad67f0bb42 | ||
|
|
5fc7163211 | ||
|
|
06a8051d24 | ||
|
|
9c829f4f96 | ||
|
|
1b186f7aac | ||
|
|
8bcd080677 | ||
|
|
c0cc899496 | ||
|
|
dc71aa898a | ||
|
|
bdd3edceb9 | ||
|
|
3128cd21e3 | ||
|
|
f54a365aeb | ||
|
|
741fe699dc | ||
|
|
0199666d39 | ||
|
|
364cabf431 | ||
|
|
c59bf663e8 | ||
|
|
bace03316c | ||
|
|
5fb0c09a5e | ||
|
|
cb629cdeda | ||
|
|
bbe9f1dd95 | ||
|
|
077d9d2838 | ||
|
|
9b729a06b0 | ||
|
|
e3bd90ee1b | ||
|
|
33987cb5fd | ||
|
|
603a4815b0 | ||
|
|
21c12d0107 | ||
|
|
54c5723e31 | ||
|
|
e5eca6eebb | ||
|
|
93f7384928 | ||
|
|
188fa6ea68 | ||
|
|
8997fc0a3f | ||
|
|
a2873eabf6 | ||
|
|
bc5e0a6868 | ||
|
|
4c9ba9ded8 | ||
|
|
804ca1d926 | ||
|
|
114f95089c | ||
|
|
e0fc12185d | ||
|
|
06b082c230 | ||
|
|
20502f35dd | ||
|
|
dcbe6a66d7 | ||
|
|
cc24a8725f | ||
|
|
e930487ce7 | ||
|
|
84feab03a9 | ||
|
|
586e65ea5c | ||
|
|
abda73147d | ||
|
|
30973087a0 | ||
|
|
34130ee25a | ||
|
|
1e33899f86 | ||
|
|
7aa2965ab1 | ||
|
|
4a258c3c42 | ||
|
|
25b33bede4 | ||
|
|
88d3c4a228 | ||
|
|
d2d9f1e31e | ||
|
|
7ffd6934ba |
@@ -1,2 +1,3 @@
|
||||
*.sln.in eol=crlf
|
||||
*.vcxproj.in eol=crlf
|
||||
*.vcxproj.filters.in eol=crlf
|
||||
|
||||
@@ -1,3 +1,238 @@
|
||||
--- 9.12.0b1 released ---
|
||||
|
||||
4772. [test] Expanded unit testing framework for libns, using
|
||||
hooks to interrupt query flow and inspect state
|
||||
at specified locations. [RT #46173]
|
||||
|
||||
4771. [bug] When sending RFC 5011 refresh queries, disregard
|
||||
cached DNSKEY rrsets. [RT #46251]
|
||||
|
||||
4770. [bug] Cache additional data from priming queries as glue.
|
||||
Previously they were ignored as unsigned
|
||||
non-answer data from a secure zone, and never
|
||||
actually got added to the cache, causing hints
|
||||
to be used frequently for root-server
|
||||
addresses, which triggered re-priming. [RT #45241]
|
||||
|
||||
4769. [func] The working directory and managed-keys directory has
|
||||
to be writeable (and seekable). [RT #46077]
|
||||
|
||||
4768. [func] By default, memory is no longer filled with tag values
|
||||
when it is allocated or freed; this improves
|
||||
performance but makes debugging of certain memory
|
||||
issues more difficult. "named -M fill" turns memory
|
||||
filling back on. (Building "configure
|
||||
--enable-developer", turns memory fill on by
|
||||
default again; it can then be disabled with
|
||||
"named -M nofill".) [RT #45123]
|
||||
|
||||
4767. [func] Add a new function, isc_buffer_printf(), which can be
|
||||
used to append a formatted string to the used region of
|
||||
a buffer. [RT #46201]
|
||||
|
||||
4766. [cleanup] Addresss Coverity warnings. [RT #46150]
|
||||
|
||||
4765. [bug] Address potential INSIST in dnssec-cds. [RT #46150]
|
||||
|
||||
4764. [bug] Address portability issues in cds system test.
|
||||
[RT #46214]
|
||||
|
||||
4763. [contrib] Improve compatibility when building MySQL DLZ
|
||||
module by using mysql_config if available.
|
||||
[RT #45558]
|
||||
|
||||
4762. [func] "update-policy local" is now restricted to updates
|
||||
from local addresses. (Previously, other addresses
|
||||
were allowed so long as updates were signed by the
|
||||
local session key.) [RT #45492]
|
||||
|
||||
4761. [protocol] Add support for DOA. [RT #45612]
|
||||
|
||||
4760. [func] Add glue cache statistics counters. [RT #46028]
|
||||
|
||||
4759. [func] Add logging channel "trust-anchor-telementry" to
|
||||
record trust-anchor-telementry in incoming requests.
|
||||
Both _ta-XXXX.<anchor>/NULL and EDNS KEY-TAG options
|
||||
are logged. [RT #46124]
|
||||
|
||||
4758. [doc] Remove documentation of unimplemented "topology".
|
||||
[RT #46161]
|
||||
|
||||
4757. [func] New "dnssec-cds" command creates a new parent DS
|
||||
RRset based on CDS or CDNSKEY RRsets found in
|
||||
a child zone, and generates either a dsset file
|
||||
or stream of nsupdate commands to update the
|
||||
parent. Thanks to Tony Finch. [RT #46090]
|
||||
|
||||
4756. [bug] Interrupting dig could lead to an INSIST failure after
|
||||
certain errors were encountered while querying a host
|
||||
whose name resolved to more than one address. Change
|
||||
4537 increased the odds of triggering this issue by
|
||||
causing dig to hang indefinitely when certain error
|
||||
paths were evaluated. dig now also retries TCP queries
|
||||
(once) if the server gracefully closes the connection
|
||||
before sending a response. [RT #42832, #45159]
|
||||
|
||||
4755. [cleanup] Silence unnecessary log message when NZF file doesn't
|
||||
exist. [RT #46186]
|
||||
|
||||
4754. [bug] dns_zone_setview needs a two stage commit to properly
|
||||
handle errors. [RT #45841]
|
||||
|
||||
4753. [contrib] Software obtainable from known upstream locations
|
||||
(i.e., zkt, nslint, query-loc) has been removed.
|
||||
Links to these and other packages can be found at
|
||||
https://www.isc.org/community/tools [RT #46182]
|
||||
|
||||
4752. [test] Add unit test for isc_net_pton. [RT #46171]
|
||||
|
||||
4751. [func] "dnssec-signzone -S" can now automatically add parent
|
||||
synchronization records (CDS and CDNSKEY) according
|
||||
to key metadata set using the -Psync and -Dsync
|
||||
options to dnssec-keygen and dnssec-settime.
|
||||
[RT #46149]
|
||||
|
||||
4750. [func] "rndc managed-keys destroy" shuts down RFC 5011 key
|
||||
maintenance and deletes the managed-keys database.
|
||||
If followed by "rndc reconfig" or a server restart,
|
||||
key maintenance is reinitialized from scratch.
|
||||
This is primarily intended for testing. [RT #32456]
|
||||
|
||||
4749. [func] The ISC DLV service has been shut down, and all
|
||||
DLV records have been removed from dlv.isc.org.
|
||||
- Removed references to ISC DLV in documentation
|
||||
- Removed DLV key from bind.keys
|
||||
- No longer use ISC DLV by default in delv
|
||||
- "dnssec-lookaside auto" and configuration of
|
||||
"dnssec-lookaide" with dlv.isc.org as trust
|
||||
anchor are both now fatal errors.
|
||||
[RT #46155]
|
||||
|
||||
4748. [cleanup] Sprintf to snprintf coversions. [RT #46132]
|
||||
|
||||
4747. [func] Synthesis of responses from DNSSEC-verified records.
|
||||
Stage 3 - synthesize NODATA responses. [RT #40138]
|
||||
|
||||
4746. [cleanup] Add configured prefixes to configure summary
|
||||
output. [RT #46153]
|
||||
|
||||
4745. [test] Add color-coded pass/fail messages to system
|
||||
tests when running on terminals that support them.
|
||||
[RT #45977]
|
||||
|
||||
4744. [bug] Suppress trust-anchor-telementry queries if
|
||||
validation is disabled. [RT #46131]
|
||||
|
||||
4743. [func] Exclude trust-anchor-telementry queries from
|
||||
synth-from-dnssec processing. [RT #46123]
|
||||
|
||||
4742. [func] Synthesis of responses from DNSSEC-verified records.
|
||||
Stage 2 - synthesis of records from wildcard data.
|
||||
If the dns64 or filter-aaaa* is configured then the
|
||||
involved lookups are currently excluded. [RT #40138]
|
||||
|
||||
4741. [bug] Make isc_refcount_current() atomically read the
|
||||
counter value. [RT #46074]
|
||||
|
||||
4740. [cleanup] Avoid triggering format-truncated warnings. [RT #46107]
|
||||
|
||||
4739. [cleanup] Address clang static analysis warnings. [RT #45952]
|
||||
|
||||
4738. [port] win32: strftime mishandles %Z. [RT #46039]
|
||||
|
||||
4737. [cleanup] Address Coverity warnings. [RT #46012]
|
||||
|
||||
4736. [cleanup] (a) Added comments to NSEC3-related functions in
|
||||
lib/dns/zone.c. (b) Refactored NSEC3 salt formatting
|
||||
code. (c) Minor tweaks to lock and result handling.
|
||||
[RT #46053]
|
||||
|
||||
4735. [bug] Add @ISC_OPENSSL_LIBS@ to isc-config. [RT #46078]
|
||||
|
||||
4734. [contrib] Added sample configuration for DNS-over-TLS in
|
||||
contrib/dnspriv.
|
||||
|
||||
4733. [bug] Change #4706 introduced a bug causing TCP clients
|
||||
not be reused correctly, leading to unconstrained
|
||||
memory growth. [RT #46029]
|
||||
|
||||
4732. [func] Change default minimal-responses setting to
|
||||
no-auth-recursive. [RT #46016]
|
||||
|
||||
4731. [bug] Fix use after free when closing an LMDB. [RT #46000]
|
||||
|
||||
4730. [bug] Fix out of bounds access in DHCID totext() method.
|
||||
[RT #46001]
|
||||
|
||||
4729. [bug] Don't use memset() to wipe memory, as it may be
|
||||
removed by compiler optimizations when the
|
||||
memset() occurs on automatic stack allocation
|
||||
just before function return. [RT #45947]
|
||||
|
||||
4728. [func] Use C11's stdatomic.h instead of isc_atomic
|
||||
where available. [RT #40668]
|
||||
|
||||
4727. [bug] Retransferring an inline-signed slave using NSEC3
|
||||
around the time its NSEC3 salt was changed could result
|
||||
in an infinite signing loop. [RT #45080]
|
||||
|
||||
4726. [port] Prevent setsockopt() errors related to TCP_FASTOPEN
|
||||
from being logged on FreeBSD if the kernel does not
|
||||
support it. Notify the user when the kernel does
|
||||
support TCP_FASTOPEN, but it is disabled by sysctl.
|
||||
Add a new configure option, --disable-tcp-fastopen, to
|
||||
disable use of TCP_FASTOPEN altogether. [RT #44754]
|
||||
|
||||
4725. [bug] Nsupdate: "recvsoa" was incorrectly reported for
|
||||
failures in sending the update message. The correct
|
||||
location to be reported is "update_completed".
|
||||
[RT #46014]
|
||||
|
||||
4724. [func] By default, BIND now uses the random number
|
||||
functions provided by the crypto library (i.e.,
|
||||
OpenSSL or a PKCS#11 provider) as a source of
|
||||
randomness rather than /dev/random. This is
|
||||
suitable for virtual machine environments
|
||||
which have limited entropy pools and lack
|
||||
hardware random number generators.
|
||||
|
||||
This can be overridden by specifying another
|
||||
entropy source via the "random-device" option
|
||||
in named.conf, or via the -r command line option;
|
||||
however, for functions requiring full cryptographic
|
||||
strength, such as DNSSEC key generation, this
|
||||
cannot be overridden. In particular, the -r
|
||||
command line option no longer has any effect on
|
||||
dnssec-keygen.
|
||||
|
||||
This can be disabled by building with
|
||||
"configure --disable-crypto-rand".
|
||||
[RT #31459] [RT #46047]
|
||||
|
||||
4723. [bug] Statistics counter DNSTAPdropped was misidentified
|
||||
as DNSSECdropped. [RT #46002]
|
||||
|
||||
4722. [cleanup] Clean up uses of strcpy() and strcat() in favor of
|
||||
strlcpy() and strlcat() for safety. [RT #45981]
|
||||
|
||||
4721. [func] 'dnssec-signzone -x' and 'dnssec-dnskey-kskonly'
|
||||
options now apply to CDNSKEY and DS records as well
|
||||
as DNSKEY. Thanks to Tony Finch. [RT #45689]
|
||||
|
||||
4720. [func] Added a statistics counter to track prefetch
|
||||
queries. [RT #45847]
|
||||
|
||||
4719. [bug] Address PVS static analyzer warnings. [RT #45946]
|
||||
|
||||
4718. [func] Avoid seaching for a owner name compression pointer
|
||||
more than once when writing out a RRset. [RT #45802]
|
||||
|
||||
4717. [bug] Treat replies with QCOUNT=0 as truncated if TC=1,
|
||||
FORMERR if TC=0, and log the error correctly.
|
||||
[RT #45836]
|
||||
|
||||
4716. [placeholder]
|
||||
|
||||
--- 9.12.0a1 released ---
|
||||
|
||||
4715. [bug] TreeMemMax was mis-identified as a second HeapMemMax
|
||||
|
||||
@@ -5,9 +5,9 @@ defined in configure.
|
||||
Some of these settings are:
|
||||
|
||||
Setting Description
|
||||
Don't ovewrite memory when allocating or freeing
|
||||
-DISC_MEM_FILL=0 it; this improves performance but makes
|
||||
debugging more difficult.
|
||||
Overwrite memory with tag values when allocating
|
||||
-DISC_MEM_DEFAULTFILL=1 or freeing it; this impairs performance but
|
||||
makes debugging of memory problems easier.
|
||||
Don't track memory allocations by file and line
|
||||
-DISC_MEM_TRACKLINES=0 number; this improves performance but makes
|
||||
debugging more difficult.
|
||||
@@ -18,5 +18,5 @@ Setting Description
|
||||
-DCHECK_LOCAL=0 Don't check out-of-zone addresses in
|
||||
named-checkzone
|
||||
-DNS_RUN_PID_DIR=0 Create default PID files in ${localstatedir}/run
|
||||
rather than ${localstatedir}/run/{named,lwresd}/
|
||||
rather than ${localstatedir}/run/named/
|
||||
|
||||
|
||||
+2
-2
@@ -13,10 +13,10 @@ Some of these settings are:
|
||||
|
||||
|Setting |Description |
|
||||
|-----------------------------------|----------------------------------------|
|
||||
|`-DISC_MEM_FILL=0`|Don't ovewrite memory when allocating or freeing it; this improves performance but makes debugging more difficult.|
|
||||
|`-DISC_MEM_DEFAULTFILL=1`|Overwrite memory with tag values when allocating or freeing it; this impairs performance but makes debugging of memory problems easier.|
|
||||
|`-DISC_MEM_TRACKLINES=0`|Don't track memory allocations by file and line number; this improves performance but makes debugging more difficult.|
|
||||
|<nobr>`-DISC_FACILITY=LOG_LOCAL0`</nobr>|Change the default syslog facility for `named`|
|
||||
|`-DNS_CLIENT_DROPPORT=0`|Disable dropping queries from particular well-known ports:|
|
||||
|`-DCHECK_SIBLING=0`|Don't check sibling glue in `named-checkzone`|
|
||||
|`-DCHECK_LOCAL=0`|Don't check out-of-zone addresses in `named-checkzone`|
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/{named,lwresd}/`|
|
||||
|`-DNS_RUN_PID_DIR=0`|Create default PID files in `${localstatedir}/run` rather than `${localstatedir}/run/named/`|
|
||||
|
||||
@@ -94,7 +94,7 @@ BIND 9.12.0 is the newest development branch of BIND 9. It includes a
|
||||
number of changes from BIND 9.11 and earlier releases. New features
|
||||
include:
|
||||
|
||||
* named and related libraries have been substantially refactored for for
|
||||
* named and related libraries have been substantially refactored for
|
||||
improved query performance -- particularly on delegation heavy zones
|
||||
-- and for improved readability, maintainability, and testability.
|
||||
* Code implementing the name server query processing logic has been
|
||||
@@ -119,7 +119,6 @@ include:
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
* named-checkconf -l lists the zones found in named.conf.
|
||||
|
||||
Building BIND
|
||||
|
||||
|
||||
@@ -108,7 +108,7 @@ number of changes from BIND 9.11 and earlier releases. New features
|
||||
include:
|
||||
|
||||
* `named` and related libraries have been substantially refactored for
|
||||
for improved query performance -- particularly on delegation heavy zones --
|
||||
improved query performance -- particularly on delegation heavy zones --
|
||||
and for improved readability, maintainability, and testability.
|
||||
* Code implementing the name server query processing logic has been moved
|
||||
into a new `libns` library, for easier testing and use in tools other
|
||||
@@ -132,7 +132,6 @@ include:
|
||||
* Added support for the EDNS Padding and Keepalive options.
|
||||
* 'new-zones-directory' option sets the location where the configuration
|
||||
data for zones added by rndc addzone is stored
|
||||
* `named-checkconf -l` lists the zones found in `named.conf`.
|
||||
|
||||
### <a name="build"/> Building BIND
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ VERSION=@BIND9_VERSION@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
|
||||
CINCLUDES = ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||
CINCLUDES = ${NS_INCLUDES} ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||
${ISC_INCLUDES} @DST_OPENSSL_INC@
|
||||
|
||||
CDEFINES = @CRYPTO@ -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||
@@ -23,11 +23,13 @@ ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||
ISCLIBS = ../../lib/isc/libisc.@A@ @ISC_OPENSSL_LIBS@
|
||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @ISC_OPENSSL_LIBS@
|
||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||
NSLIBS = ../../lib/ns/libns.@A@
|
||||
|
||||
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||
NSDEPENDLIBS = ../../lib/ns/libns.@A@
|
||||
|
||||
LIBS = ${ISCLIBS} @LIBS@
|
||||
NOSYMLIBS = ${ISCNOSYMLIBS} @LIBS@
|
||||
@@ -59,14 +61,15 @@ named-checkzone.@O@: named-checkzone.c
|
||||
-c ${srcdir}/named-checkzone.c
|
||||
|
||||
named-checkconf@EXEEXT@: named-checkconf.@O@ check-tool.@O@ ${ISCDEPLIBS} \
|
||||
${DNSDEPLIBS} ${ISCCFGDEPLIBS} ${BIND9DEPLIBS}
|
||||
${NSDEPENDLIBS} ${DNSDEPLIBS} ${ISCCFGDEPLIBS} ${BIND9DEPLIBS}
|
||||
export BASEOBJS="named-checkconf.@O@ check-tool.@O@"; \
|
||||
export LIBS0="${BIND9LIBS} ${ISCCFGLIBS} ${DNSLIBS}"; \
|
||||
export LIBS0="${NSLIBS} ${BIND9LIBS} ${ISCCFGLIBS} ${DNSLIBS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
named-checkzone@EXEEXT@: named-checkzone.@O@ check-tool.@O@ ${ISCDEPLIBS} ${DNSDEPLIBS}
|
||||
named-checkzone@EXEEXT@: named-checkzone.@O@ check-tool.@O@ ${ISCDEPLIBS} \
|
||||
${NSDEPENDLIBS} ${DNSDEPLIBS}
|
||||
export BASEOBJS="named-checkzone.@O@ check-tool.@O@"; \
|
||||
export LIBS0="${ISCCFGLIBS} ${DNSLIBS}"; \
|
||||
export LIBS0="${NSLIBS} ${ISCCFGLIBS} ${DNSLIBS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
+13
-13
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2000-2002, 2004-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2002, 2004-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -48,6 +48,8 @@
|
||||
|
||||
#include <isccfg/log.h>
|
||||
|
||||
#include <ns/log.h>
|
||||
|
||||
#ifndef CHECK_SIBLING
|
||||
#define CHECK_SIBLING 1
|
||||
#endif
|
||||
@@ -112,13 +114,7 @@ unsigned int zone_options2 = 0;
|
||||
*/
|
||||
static isc_logcategory_t categories[] = {
|
||||
{ "", 0 },
|
||||
{ "client", 0 },
|
||||
{ "network", 0 },
|
||||
{ "update", 0 },
|
||||
{ "queries", 0 },
|
||||
{ "unmatched", 0 },
|
||||
{ "update-security", 0 },
|
||||
{ "query-errors", 0 },
|
||||
{ NULL, 0 }
|
||||
};
|
||||
|
||||
@@ -209,8 +205,9 @@ checkns(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner,
|
||||
/*
|
||||
* Turn off search.
|
||||
*/
|
||||
if (dns_name_countlabels(name) > 1U)
|
||||
strcat(namebuf, ".");
|
||||
if (dns_name_countlabels(name) > 1U) {
|
||||
strlcat(namebuf, ".", sizeof(namebuf));
|
||||
}
|
||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||
|
||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||
@@ -398,8 +395,9 @@ checkmx(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
/*
|
||||
* Turn off search.
|
||||
*/
|
||||
if (dns_name_countlabels(name) > 1U)
|
||||
strcat(namebuf, ".");
|
||||
if (dns_name_countlabels(name) > 1U) {
|
||||
strlcat(namebuf, ".", sizeof(namebuf));
|
||||
}
|
||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||
|
||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||
@@ -483,8 +481,9 @@ checksrv(dns_zone_t *zone, const dns_name_t *name, const dns_name_t *owner) {
|
||||
/*
|
||||
* Turn off search.
|
||||
*/
|
||||
if (dns_name_countlabels(name) > 1U)
|
||||
strcat(namebuf, ".");
|
||||
if (dns_name_countlabels(name) > 1U) {
|
||||
strlcat(namebuf, ".", sizeof(namebuf));
|
||||
}
|
||||
dns_name_format(owner, ownerbuf, sizeof(ownerbuf));
|
||||
|
||||
result = getaddrinfo(namebuf, NULL, &hints, &ai);
|
||||
@@ -559,6 +558,7 @@ setup_logging(isc_mem_t *mctx, FILE *errout, isc_log_t **logp) {
|
||||
dns_log_init(log);
|
||||
dns_log_setcontext(log);
|
||||
cfg_log_init(log);
|
||||
ns_log_init(log);
|
||||
|
||||
destination.file.stream = errout;
|
||||
destination.file.name = NULL;
|
||||
|
||||
@@ -69,8 +69,8 @@
|
||||
<SubSystem>Console</SubSystem>
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|@PLATFORM@'">
|
||||
@@ -98,8 +98,8 @@
|
||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
||||
<OptimizeReferences>true</OptimizeReferences>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\isccc\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libisccc.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
|
||||
@@ -65,7 +65,7 @@
|
||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<BrowseInformation>true</BrowseInformation>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Lib>
|
||||
@@ -88,7 +88,7 @@
|
||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||
<CompileAs>CompileAsC</CompileAs>
|
||||
</ClCompile>
|
||||
<Lib>
|
||||
|
||||
@@ -69,8 +69,8 @@
|
||||
<SubSystem>Console</SubSystem>
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libbind9.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
</Link>
|
||||
<PostBuildEvent>
|
||||
<Command>cd ..\..\..\Build\$(Configuration)
|
||||
@@ -104,8 +104,8 @@ copy /Y named-checkzone.ilk named-compilezone.ilk
|
||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
||||
<OptimizeReferences>true</OptimizeReferences>
|
||||
<OutputFile>..\..\..\Build\$(Configuration)\$(TargetName)$(TargetExt)</OutputFile>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libbind9.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<AdditionalLibraryDirectories>$(Configuration);..\..\..\lib\isc\win32\$(Configuration);..\..\..\lib\dns\win32\$(Configuration);..\..\..\lib\isccfg\win32\$(Configuration);..\..\..\lib\bind9\win32\$(Configuration);..\..\..\lib\ns\win32\$(Configuration);%(AdditionalLibraryDirectories)</AdditionalLibraryDirectories>
|
||||
<AdditionalDependencies>checktool.lib;libisc.lib;libdns.lib;libisccfg.lib;libbind9.lib;libns.lib;ws2_32.lib;%(AdditionalDependencies)</AdditionalDependencies>
|
||||
<LinkTimeCodeGeneration>Default</LinkTimeCodeGeneration>
|
||||
</Link>
|
||||
<PostBuildEvent>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2009, 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2009, 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -151,6 +151,11 @@ generate_key(isc_mem_t *mctx, const char *randomfile, dns_secalg_t alg,
|
||||
|
||||
DO("create entropy context", isc_entropy_create(mctx, &ectx));
|
||||
|
||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||
if (randomfile == NULL) {
|
||||
isc_entropy_usehook(ectx, ISC_TRUE);
|
||||
}
|
||||
#endif
|
||||
if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||
randomfile = NULL;
|
||||
open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||
|
||||
+8
-8
@@ -55,7 +55,7 @@ is a tool for sending DNS queries and validating the results, using the same int
|
||||
\fBdelv\fR
|
||||
will send to a specified name server all queries needed to fetch and validate the requested data; this includes the original requested query, subsequent queries to follow CNAME or DNAME chains, and queries for DNSKEY, DS and DLV records to establish a chain of trust for DNSSEC validation\&. It does not perform iterative resolution, but simulates the behavior of a name server configured for DNSSEC validating and forwarding\&.
|
||||
.PP
|
||||
By default, responses are validated using built\-in DNSSEC trust anchors for the root zone ("\&.") and for the ISC DNSSEC lookaside validation zone ("dlv\&.isc\&.org")\&. Records returned by
|
||||
By default, responses are validated using built\-in DNSSEC trust anchor for the root zone ("\&.")\&. Records returned by
|
||||
\fBdelv\fR
|
||||
are either fully validated or were not signed\&. If validation fails, an explanation of the failure is included in the output; the validation process can be traced in detail\&. Because
|
||||
\fBdelv\fR
|
||||
@@ -135,13 +135,13 @@ will perform a lookup for an A record\&.
|
||||
Specifies a file from which to read DNSSEC trust anchors\&. The default is
|
||||
/etc/bind\&.keys, which is included with
|
||||
BIND
|
||||
9 and contains trust anchors for the root zone ("\&.") and for the ISC DNSSEC lookaside validation zone ("dlv\&.isc\&.org")\&.
|
||||
9 and contains one or more trust anchors for the root zone ("\&.")\&.
|
||||
.sp
|
||||
Keys that do not match the root or DLV trust\-anchor names are ignored; these key names can be overridden using the
|
||||
\fB+dlv=NAME\fR
|
||||
or
|
||||
Keys that do not match the root zone name are ignored\&. An alternate key name can be specified using the
|
||||
\fB+root=NAME\fR
|
||||
options\&.
|
||||
options\&. DNSSEC Lookaside Validation can also be turned on by using the
|
||||
\fB+dlv=NAME\fR
|
||||
to specify the name of a zone containing DLV records\&.
|
||||
.sp
|
||||
Note: When reading the trust anchor file,
|
||||
\fBdelv\fR
|
||||
@@ -404,9 +404,9 @@ must be used to specify a file containing the key\&.
|
||||
.PP
|
||||
\fB+[no]dlv[=DLV]\fR
|
||||
.RS 4
|
||||
Indicates whether to perform DNSSEC lookaside validation, and if so, specifies the name of the DLV trust anchor\&. The default is to perform lookaside validation using a trust anchor of "dlv\&.isc\&.org", for which there is a built\-in key\&. If specifying a different name, then
|
||||
Indicates whether to perform DNSSEC lookaside validation, and if so, specifies the name of the DLV trust anchor\&. The
|
||||
\fB\-a\fR
|
||||
must be used to specify a file containing the DLV key\&.
|
||||
option must also be used to specify a file containing the DLV key\&.
|
||||
.RE
|
||||
.PP
|
||||
\fB+[no]tcp\fR
|
||||
|
||||
+10
-13
@@ -574,7 +574,7 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||
dns_fixedname_t fkeyname;
|
||||
dns_name_t *keyname;
|
||||
isc_result_t result;
|
||||
isc_boolean_t match_root, match_dlv;
|
||||
isc_boolean_t match_root = ISC_FALSE, match_dlv = ISC_FALSE;
|
||||
|
||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
||||
@@ -582,8 +582,10 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||
if (!root_validation && !dlv_validation)
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
match_root = dns_name_equal(keyname, anchor_name);
|
||||
match_dlv = dns_name_equal(keyname, dlv_name);
|
||||
if (anchor_name)
|
||||
match_root = dns_name_equal(keyname, anchor_name);
|
||||
if (dlv_name)
|
||||
match_dlv = dns_name_equal(keyname, dlv_name);
|
||||
|
||||
if (!match_root && !match_dlv)
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -713,14 +715,10 @@ setup_dnsseckeys(dns_client_t *client) {
|
||||
fatal("out of memory");
|
||||
}
|
||||
|
||||
if (dlv_anchor == NULL) {
|
||||
dlv_anchor = isc_mem_strdup(mctx, "dlv.isc.org");
|
||||
if (dlv_anchor == NULL)
|
||||
fatal("out of memory");
|
||||
}
|
||||
|
||||
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
||||
CHECK(convert_name(&dfn, &dlv_name, dlv_anchor));
|
||||
if (trust_anchor != NULL)
|
||||
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
||||
if (dlv_anchor != NULL)
|
||||
CHECK(convert_name(&dfn, &dlv_name, dlv_anchor));
|
||||
|
||||
CHECK(cfg_parser_create(mctx, dns_lctx, &parser));
|
||||
|
||||
@@ -978,8 +976,7 @@ plus_option(char *option) {
|
||||
char *cmd, *value, *ptr;
|
||||
isc_boolean_t state = ISC_TRUE;
|
||||
|
||||
strncpy(option_store, option, sizeof(option_store));
|
||||
option_store[sizeof(option_store)-1]=0;
|
||||
strlcpy(option_store, option, sizeof(option_store));
|
||||
ptr = option_store;
|
||||
cmd = next_token(&ptr,"=");
|
||||
if (cmd == NULL) {
|
||||
|
||||
+10
-13
@@ -99,8 +99,7 @@
|
||||
</para>
|
||||
<para>
|
||||
By default, responses are validated using built-in DNSSEC trust
|
||||
anchors for the root zone (".") and for the ISC DNSSEC lookaside
|
||||
validation zone ("dlv.isc.org"). Records returned by
|
||||
anchor for the root zone ("."). Records returned by
|
||||
<command>delv</command> are either fully validated or
|
||||
were not signed. If validation fails, an explanation of
|
||||
the failure is included in the output; the validation process
|
||||
@@ -202,14 +201,15 @@
|
||||
Specifies a file from which to read DNSSEC trust anchors.
|
||||
The default is <filename>/etc/bind.keys</filename>, which
|
||||
is included with <acronym>BIND</acronym> 9 and contains
|
||||
trust anchors for the root zone (".") and for the ISC
|
||||
DNSSEC lookaside validation zone ("dlv.isc.org").
|
||||
one or more trust anchors for the root zone (".").
|
||||
</para>
|
||||
<para>
|
||||
Keys that do not match the root or DLV trust-anchor
|
||||
names are ignored; these key names can be overridden
|
||||
using the <option>+dlv=NAME</option> or
|
||||
<option>+root=NAME</option> options.
|
||||
Keys that do not match the root zone name are ignored.
|
||||
An alternate key name can be specified using the
|
||||
<option>+root=NAME</option> options. DNSSEC Lookaside
|
||||
Validation can also be turned on by using the
|
||||
<option>+dlv=NAME</option> to specify the name of a
|
||||
zone containing DLV records.
|
||||
</para>
|
||||
<para>
|
||||
Note: When reading the trust anchor file,
|
||||
@@ -639,11 +639,8 @@
|
||||
<para>
|
||||
Indicates whether to perform DNSSEC lookaside validation,
|
||||
and if so, specifies the name of the DLV trust anchor.
|
||||
The default is to perform lookaside validation using
|
||||
a trust anchor of "dlv.isc.org", for which there is a
|
||||
built-in key. If specifying a different name, then
|
||||
<option>-a</option> must be used to specify a file
|
||||
containing the DLV key.
|
||||
The <option>-a</option> option must also be used to specify
|
||||
a file containing the DLV key.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
+10
-13
@@ -91,8 +91,7 @@
|
||||
</p>
|
||||
<p>
|
||||
By default, responses are validated using built-in DNSSEC trust
|
||||
anchors for the root zone (".") and for the ISC DNSSEC lookaside
|
||||
validation zone ("dlv.isc.org"). Records returned by
|
||||
anchor for the root zone ("."). Records returned by
|
||||
<span class="command"><strong>delv</strong></span> are either fully validated or
|
||||
were not signed. If validation fails, an explanation of
|
||||
the failure is included in the output; the validation process
|
||||
@@ -189,14 +188,15 @@
|
||||
Specifies a file from which to read DNSSEC trust anchors.
|
||||
The default is <code class="filename">/etc/bind.keys</code>, which
|
||||
is included with <acronym class="acronym">BIND</acronym> 9 and contains
|
||||
trust anchors for the root zone (".") and for the ISC
|
||||
DNSSEC lookaside validation zone ("dlv.isc.org").
|
||||
one or more trust anchors for the root zone (".").
|
||||
</p>
|
||||
<p>
|
||||
Keys that do not match the root or DLV trust-anchor
|
||||
names are ignored; these key names can be overridden
|
||||
using the <code class="option">+dlv=NAME</code> or
|
||||
<code class="option">+root=NAME</code> options.
|
||||
Keys that do not match the root zone name are ignored.
|
||||
An alternate key name can be specified using the
|
||||
<code class="option">+root=NAME</code> options. DNSSEC Lookaside
|
||||
Validation can also be turned on by using the
|
||||
<code class="option">+dlv=NAME</code> to specify the name of a
|
||||
zone containing DLV records.
|
||||
</p>
|
||||
<p>
|
||||
Note: When reading the trust anchor file,
|
||||
@@ -538,11 +538,8 @@
|
||||
<p>
|
||||
Indicates whether to perform DNSSEC lookaside validation,
|
||||
and if so, specifies the name of the DLV trust anchor.
|
||||
The default is to perform lookaside validation using
|
||||
a trust anchor of "dlv.isc.org", for which there is a
|
||||
built-in key. If specifying a different name, then
|
||||
<code class="option">-a</code> must be used to specify a file
|
||||
containing the DLV key.
|
||||
The <code class="option">-a</code> option must also be used to specify
|
||||
a file containing the DLV key.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
||||
|
||||
+30
-31
@@ -231,7 +231,11 @@ received(int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||
isc_uint64_t diff;
|
||||
time_t tnow;
|
||||
struct tm tmnow;
|
||||
#ifdef WIN32
|
||||
wchar_t time_str[100];
|
||||
#else
|
||||
char time_str[100];
|
||||
#endif
|
||||
char fromtext[ISC_SOCKADDR_FORMATSIZE];
|
||||
|
||||
isc_sockaddr_format(from, fromtext, sizeof(fromtext));
|
||||
@@ -250,9 +254,19 @@ received(int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||
tmnow = *localtime(&tnow);
|
||||
#endif
|
||||
|
||||
#ifdef WIN32
|
||||
/*
|
||||
* On Windows, time zone name ("%Z") may be a localized
|
||||
* wide-character string, which strftime() handles incorrectly.
|
||||
*/
|
||||
if (wcsftime(time_str, sizeof(time_str)/sizeof(time_str[0]),
|
||||
L"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
||||
printf(";; WHEN: %ls\n", time_str);
|
||||
#else
|
||||
if (strftime(time_str, sizeof(time_str),
|
||||
"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
||||
printf(";; WHEN: %s\n", time_str);
|
||||
#endif
|
||||
if (query->lookup->doing_xfr) {
|
||||
printf(";; XFR size: %u records (messages %u, "
|
||||
"bytes %" ISC_PRINT_QUADFORMAT "u)\n",
|
||||
@@ -669,33 +683,27 @@ cleanup:
|
||||
static void
|
||||
printgreeting(int argc, char **argv, dig_lookup_t *lookup) {
|
||||
int i;
|
||||
size_t remaining;
|
||||
static isc_boolean_t first = ISC_TRUE;
|
||||
char append[MXNAME];
|
||||
|
||||
if (printcmd) {
|
||||
lookup->cmdline[sizeof(lookup->cmdline) - 1] = 0;
|
||||
snprintf(lookup->cmdline, sizeof(lookup->cmdline),
|
||||
"%s; <<>> DiG " VERSION " <<>>",
|
||||
first?"\n":"");
|
||||
i = 1;
|
||||
while (i < argc) {
|
||||
snprintf(append, sizeof(append), " %s", argv[i++]);
|
||||
remaining = sizeof(lookup->cmdline) -
|
||||
strlen(lookup->cmdline) - 1;
|
||||
strncat(lookup->cmdline, append, remaining);
|
||||
strlcat(lookup->cmdline, append,
|
||||
sizeof(lookup->cmdline));
|
||||
}
|
||||
remaining = sizeof(lookup->cmdline) -
|
||||
strlen(lookup->cmdline) - 1;
|
||||
strncat(lookup->cmdline, "\n", remaining);
|
||||
strlcat(lookup->cmdline, "\n", sizeof(lookup->cmdline));
|
||||
if (first && addresscount != 0) {
|
||||
snprintf(append, sizeof(append),
|
||||
"; (%d server%s found)\n",
|
||||
addresscount,
|
||||
addresscount > 1 ? "s" : "");
|
||||
remaining = sizeof(lookup->cmdline) -
|
||||
strlen(lookup->cmdline) - 1;
|
||||
strncat(lookup->cmdline, append, remaining);
|
||||
strlcat(lookup->cmdline, append,
|
||||
sizeof(lookup->cmdline));
|
||||
}
|
||||
if (first) {
|
||||
snprintf(append, sizeof(append),
|
||||
@@ -703,9 +711,8 @@ printgreeting(int argc, char **argv, dig_lookup_t *lookup) {
|
||||
short_form ? " +short" : "",
|
||||
printcmd ? " +cmd" : "");
|
||||
first = ISC_FALSE;
|
||||
remaining = sizeof(lookup->cmdline) -
|
||||
strlen(lookup->cmdline) - 1;
|
||||
strncat(lookup->cmdline, append, remaining);
|
||||
strlcat(lookup->cmdline, append,
|
||||
sizeof(lookup->cmdline));
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -728,8 +735,7 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
isc_boolean_t state = ISC_TRUE;
|
||||
size_t n;
|
||||
|
||||
strncpy(option_store, option, sizeof(option_store));
|
||||
option_store[sizeof(option_store)-1]=0;
|
||||
strlcpy(option_store, option, sizeof(option_store));
|
||||
ptr = option_store;
|
||||
cmd = next_token(&ptr, "=");
|
||||
if (cmd == NULL) {
|
||||
@@ -905,8 +911,7 @@ plus_option(const char *option, isc_boolean_t is_batchfile,
|
||||
goto need_value;
|
||||
if (!state)
|
||||
goto invalid_option;
|
||||
strncpy(domainopt, value, sizeof(domainopt));
|
||||
domainopt[sizeof(domainopt)-1] = '\0';
|
||||
strlcpy(domainopt, value, sizeof(domainopt));
|
||||
break;
|
||||
case 's': /* dscp */
|
||||
FULLCHECK("dscp");
|
||||
@@ -1598,8 +1603,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
batchname = value;
|
||||
return (value_from_next);
|
||||
case 'k':
|
||||
strncpy(keyfile, value, sizeof(keyfile));
|
||||
keyfile[sizeof(keyfile)-1]=0;
|
||||
strlcpy(keyfile, value, sizeof(keyfile));
|
||||
return (value_from_next);
|
||||
case 'p':
|
||||
result = parse_uint(&num, value, MAXPORT, "port number");
|
||||
@@ -1613,9 +1617,8 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
(*lookup) = clone_lookup(default_lookup,
|
||||
ISC_TRUE);
|
||||
*need_clone = ISC_TRUE;
|
||||
strncpy((*lookup)->textname, value,
|
||||
strlcpy((*lookup)->textname, value,
|
||||
sizeof((*lookup)->textname));
|
||||
(*lookup)->textname[sizeof((*lookup)->textname)-1]=0;
|
||||
(*lookup)->trace_root = ISC_TF((*lookup)->trace ||
|
||||
(*lookup)->ns_search_only);
|
||||
(*lookup)->new_search = ISC_TRUE;
|
||||
@@ -1699,10 +1702,8 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
#endif
|
||||
digestbits = 0;
|
||||
}
|
||||
strncpy(keynametext, ptr, sizeof(keynametext));
|
||||
keynametext[sizeof(keynametext)-1]=0;
|
||||
strncpy(keysecret, ptr2, sizeof(keysecret));
|
||||
keysecret[sizeof(keysecret)-1]=0;
|
||||
strlcpy(keynametext, ptr, sizeof(keynametext));
|
||||
strlcpy(keysecret, ptr2, sizeof(keysecret));
|
||||
return (value_from_next);
|
||||
case 'x':
|
||||
if (*need_clone)
|
||||
@@ -1710,9 +1711,8 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
*need_clone = ISC_TRUE;
|
||||
if (get_reverse(textname, sizeof(textname), value,
|
||||
ip6_int, ISC_FALSE) == ISC_R_SUCCESS) {
|
||||
strncpy((*lookup)->textname, textname,
|
||||
strlcpy((*lookup)->textname, textname,
|
||||
sizeof((*lookup)->textname));
|
||||
(*lookup)->textname[sizeof((*lookup)->textname)-1] = 0;
|
||||
debug("looking up %s", (*lookup)->textname);
|
||||
(*lookup)->trace_root = ISC_TF((*lookup)->trace ||
|
||||
(*lookup)->ns_search_only);
|
||||
@@ -2006,9 +2006,8 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
lookup = clone_lookup(default_lookup,
|
||||
ISC_TRUE);
|
||||
need_clone = ISC_TRUE;
|
||||
strncpy(lookup->textname, rv[0],
|
||||
strlcpy(lookup->textname, rv[0],
|
||||
sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1]=0;
|
||||
lookup->trace_root = ISC_TF(lookup->trace ||
|
||||
lookup->ns_search_only);
|
||||
lookup->new_search = ISC_TRUE;
|
||||
@@ -2074,7 +2073,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
lookup->trace_root = ISC_TF(lookup->trace ||
|
||||
lookup->ns_search_only);
|
||||
lookup->new_search = ISC_TRUE;
|
||||
strcpy(lookup->textname, ".");
|
||||
strlcpy(lookup->textname, ".", sizeof(lookup->textname));
|
||||
lookup->rdtype = dns_rdatatype_ns;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
if (firstarg) {
|
||||
|
||||
+33
-12
@@ -646,6 +646,7 @@ make_empty_lookup(void) {
|
||||
looknew->mapped = ISC_TRUE;
|
||||
looknew->dscp = -1;
|
||||
looknew->rrcomments = 0;
|
||||
looknew->eoferr = 0;
|
||||
dns_fixedname_init(&looknew->fdomain);
|
||||
ISC_LINK_INIT(looknew, link);
|
||||
ISC_LIST_INIT(looknew->q);
|
||||
@@ -737,6 +738,7 @@ clone_lookup(dig_lookup_t *lookold, isc_boolean_t servers) {
|
||||
looknew->done_as_is = lookold->done_as_is;
|
||||
looknew->dscp = lookold->dscp;
|
||||
looknew->rrcomments = lookold->rrcomments;
|
||||
looknew->eoferr = lookold->eoferr;
|
||||
|
||||
if (lookold->ecs_addr != NULL) {
|
||||
size_t len = sizeof(isc_sockaddr_t);
|
||||
@@ -899,7 +901,6 @@ parse_netprefix(isc_sockaddr_t **sap, const char *value) {
|
||||
|
||||
if (strcmp(buf, "0") == 0) {
|
||||
sa->type.sa.sa_family = AF_UNSPEC;
|
||||
parsed = ISC_TRUE;
|
||||
prefix_length = 0;
|
||||
goto done;
|
||||
}
|
||||
@@ -1743,7 +1744,8 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
namestr, isc_result_totext(lresult));
|
||||
if (addresses_result == ISC_R_SUCCESS) {
|
||||
addresses_result = lresult;
|
||||
strcpy(bad_namestr, namestr);
|
||||
strlcpy(bad_namestr, namestr,
|
||||
sizeof(bad_namestr));
|
||||
}
|
||||
}
|
||||
numLookups += num;
|
||||
@@ -2775,9 +2777,12 @@ send_udp(dig_query_t *query) {
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
l = query->lookup;
|
||||
clear_query(query);
|
||||
if (next == NULL)
|
||||
if (next == NULL) {
|
||||
printf(";; No acceptable nameservers\n");
|
||||
check_next_lookup(l);
|
||||
check_next_lookup(l);
|
||||
} else {
|
||||
send_udp(next);
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -2909,7 +2914,7 @@ tcp_length_done(isc_task_t *task, isc_event_t *event) {
|
||||
isc_buffer_t *b = NULL;
|
||||
isc_result_t result;
|
||||
dig_query_t *query = NULL;
|
||||
dig_lookup_t *l;
|
||||
dig_lookup_t *l, *n;
|
||||
isc_uint16_t length;
|
||||
|
||||
REQUIRE(event->ev_type == ISC_SOCKEVENT_RECVDONE);
|
||||
@@ -2944,13 +2949,20 @@ tcp_length_done(isc_task_t *task, isc_event_t *event) {
|
||||
sizeof(sockstr));
|
||||
printf(";; communications error to %s: %s\n",
|
||||
sockstr, isc_result_totext(sevent->result));
|
||||
if (keep != NULL)
|
||||
isc_socket_detach(&keep);
|
||||
l = query->lookup;
|
||||
isc_socket_detach(&query->sock);
|
||||
sockcount--;
|
||||
debug("sockcount=%d", sockcount);
|
||||
INSIST(sockcount >= 0);
|
||||
if (sevent->result == ISC_R_EOF && l->eoferr == 0U) {
|
||||
n = requeue_lookup(l, ISC_TRUE);
|
||||
n->eoferr++;
|
||||
}
|
||||
isc_event_free(&event);
|
||||
clear_query(query);
|
||||
cancel_lookup(l);
|
||||
check_next_lookup(l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
@@ -3443,13 +3455,20 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
||||
} else {
|
||||
printf(";; communications error: %s\n",
|
||||
isc_result_totext(sevent->result));
|
||||
if (keep != NULL)
|
||||
isc_socket_detach(&keep);
|
||||
isc_socket_detach(&query->sock);
|
||||
sockcount--;
|
||||
debug("sockcount=%d", sockcount);
|
||||
INSIST(sockcount >= 0);
|
||||
}
|
||||
if (sevent->result == ISC_R_EOF && l->eoferr == 0U) {
|
||||
n = requeue_lookup(l, ISC_TRUE);
|
||||
n->eoferr++;
|
||||
}
|
||||
isc_event_free(&event);
|
||||
clear_query(query);
|
||||
cancel_lookup(l);
|
||||
check_next_lookup(l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
@@ -3511,6 +3530,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
||||
if (fail) {
|
||||
isc_event_free(&event);
|
||||
clear_query(query);
|
||||
cancel_lookup(l);
|
||||
check_next_lookup(l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
@@ -3614,6 +3634,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
||||
if (l->tcp_mode) {
|
||||
isc_event_free(&event);
|
||||
clear_query(query);
|
||||
cancel_lookup(l);
|
||||
check_next_lookup(l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
@@ -3925,7 +3946,7 @@ getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp) {
|
||||
if (resultp == NULL)
|
||||
fatal("couldn't get address for '%s': %s",
|
||||
host, isc_result_totext(result));
|
||||
return 0;
|
||||
return (0);
|
||||
}
|
||||
|
||||
for (i = 0; i < count; i++) {
|
||||
@@ -3935,7 +3956,7 @@ getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp) {
|
||||
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
|
||||
}
|
||||
|
||||
return count;
|
||||
return (count);
|
||||
}
|
||||
|
||||
/*%
|
||||
@@ -4170,7 +4191,7 @@ output_filter(isc_buffer_t *buffer, unsigned int used_org,
|
||||
*/
|
||||
if (idn_decodename(IDN_DECODE_APP, tmp1, tmp2, MAXDLEN) != idn_success)
|
||||
return (ISC_R_SUCCESS);
|
||||
strcpy(tmp1, tmp2);
|
||||
strlcpy(tmp1, tmp2, MAXDLEN);
|
||||
|
||||
/*
|
||||
* Copy the converted contents in 'tmp1' back to 'buffer'.
|
||||
@@ -4197,17 +4218,17 @@ append_textname(char *name, const char *origin, size_t namesize) {
|
||||
|
||||
/* Already absolute? */
|
||||
if (namelen > 0 && name[namelen - 1] == '.')
|
||||
return idn_success;
|
||||
return (idn_success);
|
||||
|
||||
/* Append dot and origin */
|
||||
|
||||
if (namelen + 1 + originlen >= namesize)
|
||||
return idn_buffer_overflow;
|
||||
return (idn_buffer_overflow);
|
||||
|
||||
if (*origin != '.')
|
||||
name[namelen++] = '.';
|
||||
(void)strcpy(name + namelen, origin);
|
||||
return idn_success;
|
||||
(void)strlcpy(name + namelen, origin, namesize - namelen);
|
||||
return (idn_success);
|
||||
}
|
||||
|
||||
static void
|
||||
|
||||
+4
-8
@@ -463,9 +463,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
dns_name_format(name, namestr, sizeof(namestr));
|
||||
lookup = clone_lookup(query->lookup, ISC_FALSE);
|
||||
if (lookup != NULL) {
|
||||
strncpy(lookup->textname, namestr,
|
||||
strlcpy(lookup->textname, namestr,
|
||||
sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1] = 0;
|
||||
lookup->rdtype = dns_rdatatype_aaaa;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
lookup->origin = NULL;
|
||||
@@ -474,9 +473,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
}
|
||||
lookup = clone_lookup(query->lookup, ISC_FALSE);
|
||||
if (lookup != NULL) {
|
||||
strncpy(lookup->textname, namestr,
|
||||
strlcpy(lookup->textname, namestr,
|
||||
sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1] = 0;
|
||||
lookup->rdtype = dns_rdatatype_mx;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
lookup->origin = NULL;
|
||||
@@ -861,14 +859,12 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
||||
lookup->pending = ISC_FALSE;
|
||||
if (get_reverse(store, sizeof(store), hostname,
|
||||
lookup->ip6_int, ISC_TRUE) == ISC_R_SUCCESS) {
|
||||
strncpy(lookup->textname, store, sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1] = 0;
|
||||
strlcpy(lookup->textname, store, sizeof(lookup->textname));
|
||||
lookup->rdtype = dns_rdatatype_ptr;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
default_lookups = ISC_FALSE;
|
||||
} else {
|
||||
strncpy(lookup->textname, hostname, sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1]=0;
|
||||
strlcpy(lookup->textname, hostname, sizeof(lookup->textname));
|
||||
usesearch = ISC_TRUE;
|
||||
}
|
||||
lookup->new_search = ISC_TRUE;
|
||||
|
||||
@@ -168,6 +168,7 @@ struct dig_lookup {
|
||||
unsigned int ednsflags;
|
||||
dns_opcode_t opcode;
|
||||
int rrcomments;
|
||||
unsigned int eoferr;
|
||||
};
|
||||
|
||||
/*% The dig_query structure */
|
||||
|
||||
+22
-18
@@ -479,9 +479,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
dns_name_format(name, namestr, sizeof(namestr));
|
||||
lookup = clone_lookup(query->lookup, ISC_FALSE);
|
||||
if (lookup != NULL) {
|
||||
strncpy(lookup->textname, namestr,
|
||||
strlcpy(lookup->textname, namestr,
|
||||
sizeof(lookup->textname));
|
||||
lookup->textname[sizeof(lookup->textname)-1] = 0;
|
||||
lookup->rdtype = dns_rdatatype_aaaa;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
lookup->origin = NULL;
|
||||
@@ -637,7 +636,12 @@ version(void) {
|
||||
|
||||
static void
|
||||
setoption(char *opt) {
|
||||
if (strncasecmp(opt, "all", 3) == 0) {
|
||||
size_t l = strlen(opt);
|
||||
|
||||
#define CHECKOPT(A, N) \
|
||||
((l >= N) && (l < sizeof(A)) && (strncasecmp(opt, A, l) == 0))
|
||||
|
||||
if (CHECKOPT("all", 3)) {
|
||||
show_settings(ISC_TRUE, ISC_FALSE);
|
||||
} else if (strncasecmp(opt, "class=", 6) == 0) {
|
||||
if (testclass(&opt[6]))
|
||||
@@ -691,43 +695,43 @@ setoption(char *opt) {
|
||||
set_timeout(&opt[8]);
|
||||
} else if (strncasecmp(opt, "t=", 2) == 0) {
|
||||
set_timeout(&opt[2]);
|
||||
} else if (strncasecmp(opt, "rec", 3) == 0) {
|
||||
} else if (CHECKOPT("recurse", 3)) {
|
||||
recurse = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "norec", 5) == 0) {
|
||||
} else if (CHECKOPT("norecurse", 5)) {
|
||||
recurse = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "retry=", 6) == 0) {
|
||||
set_tries(&opt[6]);
|
||||
} else if (strncasecmp(opt, "ret=", 4) == 0) {
|
||||
set_tries(&opt[4]);
|
||||
} else if (strncasecmp(opt, "def", 3) == 0) {
|
||||
} else if (CHECKOPT("defname", 3)) {
|
||||
usesearch = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "nodef", 5) == 0) {
|
||||
} else if (CHECKOPT("nodefname", 5)) {
|
||||
usesearch = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "vc", 3) == 0) {
|
||||
} else if (CHECKOPT("vc", 2) == 0) {
|
||||
tcpmode = ISC_TRUE;
|
||||
tcpmode_set = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "novc", 5) == 0) {
|
||||
} else if (CHECKOPT("novc", 4) == 0) {
|
||||
tcpmode = ISC_FALSE;
|
||||
tcpmode_set = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "deb", 3) == 0) {
|
||||
} else if (CHECKOPT("debug", 3) == 0) {
|
||||
short_form = ISC_FALSE;
|
||||
showsearch = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "nodeb", 5) == 0) {
|
||||
} else if (CHECKOPT("nodebug", 5) == 0) {
|
||||
short_form = ISC_TRUE;
|
||||
showsearch = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "d2", 2) == 0) {
|
||||
} else if (CHECKOPT("d2", 2) == 0) {
|
||||
debugging = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "nod2", 4) == 0) {
|
||||
} else if (CHECKOPT("nod2", 4) == 0) {
|
||||
debugging = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "search", 3) == 0) {
|
||||
} else if (CHECKOPT("search", 3) == 0) {
|
||||
usesearch = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "nosearch", 5) == 0) {
|
||||
} else if (CHECKOPT("nosearch", 5) == 0) {
|
||||
usesearch = ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "sil", 3) == 0) {
|
||||
} else if (CHECKOPT("sil", 3) == 0) {
|
||||
/* deprecation_msg = ISC_FALSE; */
|
||||
} else if (strncasecmp(opt, "fail", 3) == 0) {
|
||||
} else if (CHECKOPT("fail", 3) == 0) {
|
||||
nofail=ISC_FALSE;
|
||||
} else if (strncasecmp(opt, "nofail", 3) == 0) {
|
||||
} else if (CHECKOPT("nofail", 5) == 0) {
|
||||
nofail=ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "ndots=", 6) == 0) {
|
||||
set_ndots(&opt[6]);
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
dnssec-cds
|
||||
dnssec-dsfromkey
|
||||
dnssec-keyfromlabel
|
||||
dnssec-keygen
|
||||
|
||||
+19
-13
@@ -32,30 +32,37 @@ LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
||||
NOSYMLIBS = ${DNSLIBS} ${ISCNOSYMLIBS} @LIBS@
|
||||
|
||||
# Alphabetically
|
||||
TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
||||
dnssec-keyfromlabel@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
||||
dnssec-revoke@EXEEXT@ dnssec-settime@EXEEXT@ \
|
||||
dnssec-verify@EXEEXT@ dnssec-importkey@EXEEXT@
|
||||
TARGETS = dnssec-cds@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
||||
dnssec-importkey@EXEEXT@ dnssec-keyfromlabel@EXEEXT@ \
|
||||
dnssec-keygen@EXEEXT@ dnssec-revoke@EXEEXT@ \
|
||||
dnssec-settime@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
||||
dnssec-verify@EXEEXT@
|
||||
|
||||
OBJS = dnssectool.@O@
|
||||
|
||||
SRCS = dnssec-dsfromkey.c dnssec-keyfromlabel.c dnssec-keygen.c \
|
||||
dnssec-revoke.c dnssec-settime.c dnssec-signzone.c \
|
||||
dnssec-verify.c dnssec-importkey.c dnssectool.c
|
||||
SRCS = dnssec-cds.c dnssec-dsfromkey.c dnssec-importkey.c \
|
||||
dnssec-keyfromlabel.c dnssec-keygen.c dnssec-revoke.c \
|
||||
dnssec-settime.c dnssec-signzone.c dnssec-verify.c \
|
||||
dnssectool.c
|
||||
|
||||
MANPAGES = dnssec-dsfromkey.8 dnssec-keyfromlabel.8 dnssec-keygen.8 \
|
||||
dnssec-revoke.8 dnssec-settime.8 dnssec-signzone.8 \
|
||||
dnssec-verify.8 dnssec-importkey.8
|
||||
MANPAGES = dnssec-cds.8 dnssec-dsfromkey.8 dnssec-importkey.8 \
|
||||
dnssec-keyfromlabel.8 dnssec-keygen.8 dnssec-revoke.8 \
|
||||
dnssec-settime.8 dnssec-signzone.8 dnssec-verify.8
|
||||
|
||||
HTMLPAGES = dnssec-dsfromkey.html dnssec-keyfromlabel.html \
|
||||
HTMLPAGES = dnssec-cds.html dnssec-dsfromkey.html \
|
||||
dnssec-importkey.html dnssec-keyfromlabel.html \
|
||||
dnssec-keygen.html dnssec-revoke.html \
|
||||
dnssec-settime.html dnssec-signzone.html \
|
||||
dnssec-verify.html dnssec-importkey.html
|
||||
dnssec-verify.html
|
||||
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
dnssec-cds@EXEEXT@: dnssec-cds.@O@ ${OBJS} ${DEPLIBS}
|
||||
export BASEOBJS="dnssec-cds.@O@ ${OBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
|
||||
dnssec-dsfromkey@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
||||
export BASEOBJS="dnssec-dsfromkey.@O@ ${OBJS}"; \
|
||||
${FINALBUILDCMD}
|
||||
@@ -115,4 +122,3 @@ uninstall::
|
||||
|
||||
clean distclean::
|
||||
rm -f ${TARGETS}
|
||||
|
||||
|
||||
@@ -0,0 +1,292 @@
|
||||
.\" Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.\" file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
'\" t
|
||||
.\" Title: dnssec-cds
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||
.\" Date: 2017-10-02
|
||||
.\" Manual: BIND9
|
||||
.\" Source: ISC
|
||||
.\" Language: English
|
||||
.\"
|
||||
.TH "DNSSEC\-CDS" "8" "2017\-10\-02" "ISC" "BIND9"
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * Define some portability stuff
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
.\" http://bugs.debian.org/507673
|
||||
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
|
||||
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
.ie \n(.g .ds Aq \(aq
|
||||
.el .ds Aq '
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * set default formatting
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" disable hyphenation
|
||||
.nh
|
||||
.\" disable justification (adjust text to left margin only)
|
||||
.ad l
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * MAIN CONTENT STARTS HERE *
|
||||
.\" -----------------------------------------------------------------
|
||||
.SH "NAME"
|
||||
dnssec-cds \- change DS records for a child zone based on CDS/CDNSKEY
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-cds\fR\ 'u
|
||||
\fBdnssec\-cds\fR [\fB\-a\ \fR\fB\fIalg\fR\fR...] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\fR] {\fB\-d\ \fR\fB\fIdsset\-file\fR\fR} {\fB\-f\ \fR\fB\fIchild\-file\fR\fR} [\fB\-i\fR\ [\fIextension\fR]] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] {domain}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
The
|
||||
\fBdnssec\-cds\fR
|
||||
command changes DS records at a delegation point based on CDS or CDNSKEY records published in the child zone\&. If both CDS and CDNSKEY records are present in the child zone, the CDS is preferred\&.
|
||||
.PP
|
||||
Two input files are required\&. The
|
||||
\fB\-f \fR\fB\fIchild\-file\fR\fR
|
||||
option specifies a file containing the child\*(Aqs CDS and/or CDNSKEY records, plus RRSIG and DNSKEY records so that they can be authenticated\&. The
|
||||
\fB\-d \fR\fB\fIpath\fR\fR
|
||||
option specifies the location of a file containing the current DS records\&. For example, this could be a
|
||||
dsset\-
|
||||
file generated by
|
||||
\fBdnssec\-signzone\fR, or the output of
|
||||
\fBdnssec\-dsfromkey\fR, or the output of a previous run of
|
||||
\fBdnssec\-cds\fR\&.
|
||||
.PP
|
||||
For protection against replay attacks, the signatures on the child records must not be older than they were on a previous run of
|
||||
\fBdnssec\-cds\fR\&. This time is obtained from the modification time of the
|
||||
dsset\-
|
||||
file, or from the
|
||||
\fB\-s\fR
|
||||
option\&.
|
||||
.PP
|
||||
To protect against breaking the delegation,
|
||||
\fBdnssec\-cds\fR
|
||||
ensures that the DNSKEY RRset can be verified by every key algorithm in the new DS RRset, and that the same set of keys are covered by every DS digest type\&.
|
||||
.PP
|
||||
By default, replacement DS records are written to the standard output; with the
|
||||
\fB\-i\fR
|
||||
option the input file is overwritten in place\&. The replacement DS records will be the same as the existing records when no change is required\&. The output can be empty if the CDS / CDNSKEY records specify that the child zone wants to go insecure\&.
|
||||
.PP
|
||||
Warning: Be careful not to delete the DS records when
|
||||
\fBdnssec\-cds\fR
|
||||
fails!
|
||||
.PP
|
||||
Alternatively,
|
||||
\fBdnssec\-cds \-u\fR
|
||||
writes an
|
||||
\fBnsupdate\fR
|
||||
script to the standard output\&. You can use the
|
||||
\fB\-u\fR
|
||||
and
|
||||
\fB\-i\fR
|
||||
options together to maintain a
|
||||
dsset\-
|
||||
file as well as emit an
|
||||
\fBnsupdate\fR
|
||||
script\&.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-a \fIalgorithm\fR
|
||||
.RS 4
|
||||
Specify a digest algorithm to use when converting CDNSKEY records to DS records\&. This option can be repeated, so that multiple DS records are created for each CDNSKEY record\&. This option has no effect when using CDS records\&.
|
||||
.sp
|
||||
The
|
||||
\fIalgorithm\fR
|
||||
must be one of SHA\-1 (SHA1), SHA\-256 (SHA256), GOST, or SHA\-384 (SHA384)\&. These values are case insensitive\&. If no algorithm is specified, the default is SHA\-256\&.
|
||||
.RE
|
||||
.PP
|
||||
\-c \fIclass\fR
|
||||
.RS 4
|
||||
Specifies the DNS class of the zones\&.
|
||||
.RE
|
||||
.PP
|
||||
\-D
|
||||
.RS 4
|
||||
Generate DS records from CDNSKEY records if both CDS and CDNSKEY records are present in the child zone\&. By default CDS records are preferred\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIpath\fR
|
||||
.RS 4
|
||||
Location of the parent DS records\&. The
|
||||
\fIpath\fR
|
||||
can be the name of a file containing the DS records, or if it is a directory,
|
||||
\fBdnssec\-cds\fR
|
||||
looks for a
|
||||
dsset\-
|
||||
file for the
|
||||
\fIdomain\fR
|
||||
inside the directory\&.
|
||||
.sp
|
||||
To protect against replay attacks, child records are rejected if they were signed earlier than the modification time of the
|
||||
dsset\-
|
||||
file\&. This can be adjusted with the
|
||||
\fB\-s\fR
|
||||
option\&.
|
||||
.RE
|
||||
.PP
|
||||
\-f \fIchild\-file\fR
|
||||
.RS 4
|
||||
File containing the child\*(Aqs CDS and/or CDNSKEY records, plus its DNSKEY records and the covering RRSIG records so that they can be authenticated\&.
|
||||
.sp
|
||||
The EXAMPLES below describe how to generate this file\&.
|
||||
.RE
|
||||
.PP
|
||||
\-i [\fIextension\fR]
|
||||
.RS 4
|
||||
Update the
|
||||
dsset\-
|
||||
file in place, instead of writing DS records to the standard output\&.
|
||||
.sp
|
||||
There must be no space between the
|
||||
\fB\-i\fR
|
||||
and the
|
||||
\fIextension\fR\&. If you provide no
|
||||
\fIextension\fR
|
||||
then the old
|
||||
dsset\-
|
||||
is discarded\&. If an
|
||||
\fIextension\fR
|
||||
is present, a backup of the old
|
||||
dsset\-
|
||||
file is kept with the
|
||||
\fIextension\fR
|
||||
appended to its filename\&.
|
||||
.sp
|
||||
To protect against replay attacks, the modification time of the
|
||||
dsset\-
|
||||
file is set to match the signature inception time of the child records, provided that is later than the file\*(Aqs current modification time\&.
|
||||
.RE
|
||||
.PP
|
||||
\-s \fIstart\-time\fR
|
||||
.RS 4
|
||||
Specify the date and time after which RRSIG records become acceptable\&. This can be either an absolute or relative time\&. An absolute start time is indicated by a number in YYYYMMDDHHMMSS notation; 20170827133700 denotes 13:37:00 UTC on August 27th, 2017\&. A time relative to the
|
||||
dsset\-
|
||||
file is indicated with \-N, which is N seconds before the file modification time\&. A time relative to the current time is indicated with now+N\&.
|
||||
.sp
|
||||
If no
|
||||
\fIstart\-time\fR
|
||||
is specified, the modification time of the
|
||||
dsset\-
|
||||
file is used\&.
|
||||
.RE
|
||||
.PP
|
||||
\-T \fIttl\fR
|
||||
.RS 4
|
||||
Specifies a TTL to be used for new DS records\&. If not specified, the default is the TTL of the old DS records\&. If they had no explicit TTL then the new DS records also have no explicit TTL\&.
|
||||
.RE
|
||||
.PP
|
||||
\-u
|
||||
.RS 4
|
||||
Write an
|
||||
\fBnsupdate\fR
|
||||
script to the standard output, instead of printing the new DS reords\&. The output will be empty if no change is needed\&.
|
||||
.sp
|
||||
Note: The TTL of new records needs to be specified, either in the original
|
||||
dsset\-
|
||||
file, or with the
|
||||
\fB\-T\fR
|
||||
option, or using the
|
||||
\fBnsupdate\fR\fBttl\fR
|
||||
command\&.
|
||||
.RE
|
||||
.PP
|
||||
\-V
|
||||
.RS 4
|
||||
Print version information\&.
|
||||
.RE
|
||||
.PP
|
||||
\-v \fIlevel\fR
|
||||
.RS 4
|
||||
Sets the debugging level\&. Level 1 is intended to be usefully verbose for general users; higher levels are intended for developers\&.
|
||||
.RE
|
||||
.PP
|
||||
\fIdomain\fR
|
||||
.RS 4
|
||||
The name of the delegation point / child zone apex\&.
|
||||
.RE
|
||||
.SH "EXIT STATUS"
|
||||
.PP
|
||||
The
|
||||
\fBdnssec\-cds\fR
|
||||
command exits 0 on success, or non\-zero if an error occurred\&.
|
||||
.PP
|
||||
In the success case, the DS records might or might not need to be changed\&.
|
||||
.SH "EXAMPLES"
|
||||
.PP
|
||||
Before running
|
||||
\fBdnssec\-signzone\fR, you can ensure that the delegations are up\-to\-date by running
|
||||
\fBdnssec\-cds\fR
|
||||
on every
|
||||
dsset\-
|
||||
file\&.
|
||||
.PP
|
||||
To fetch the child records required by
|
||||
\fBdnssec\-cds\fR
|
||||
you can invoke
|
||||
\fBdig\fR
|
||||
as in the script below\&. It\*(Aqs okay if the
|
||||
\fBdig\fR
|
||||
fails since
|
||||
\fBdnssec\-cds\fR
|
||||
performs all the necessary checking\&.
|
||||
.sp
|
||||
.if n \{\
|
||||
.RS 4
|
||||
.\}
|
||||
.nf
|
||||
for f in dsset\-*
|
||||
do
|
||||
d=${f#dsset\-}
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec\-cds \-i \-f /dev/stdin \-d $f $d
|
||||
done
|
||||
.fi
|
||||
.if n \{\
|
||||
.RE
|
||||
.\}
|
||||
.PP
|
||||
When the parent zone is automatically signed by
|
||||
\fBnamed\fR, you can use
|
||||
\fBdnssec\-cds\fR
|
||||
with
|
||||
\fBnsupdate\fR
|
||||
to maintain a delegation as follows\&. The
|
||||
dsset\-
|
||||
file allows the script to avoid having to fetch and validate the parent DS records, and it keeps the replay attack protection time\&.
|
||||
.sp
|
||||
.if n \{\
|
||||
.RS 4
|
||||
.\}
|
||||
.nf
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec\-cds \-u \-i \-f /dev/stdin \-d $f $d |
|
||||
nsupdate \-l
|
||||
.fi
|
||||
.if n \{\
|
||||
.RE
|
||||
.\}
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdig\fR(1),
|
||||
\fBdnssec-settime\fR(8),
|
||||
\fBdnssec-signzone\fR(8),
|
||||
\fBnsupdate\fR(1),
|
||||
BIND 9 Administrator Reference Manual,
|
||||
RFC 7344\&.
|
||||
.SH "AUTHORS"
|
||||
.PP
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.PP
|
||||
\fBTony Finch\fR <\&dot@dotat\&.at\&>, <\&fanf2@cam\&.ac\&.uk\&>
|
||||
.br
|
||||
.RS 4
|
||||
.RE
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,373 @@
|
||||
<!--
|
||||
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
-->
|
||||
|
||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-cds">
|
||||
<info>
|
||||
<date>2017-10-02</date>
|
||||
</info>
|
||||
<refentryinfo>
|
||||
<corpname>ISC</corpname>
|
||||
<corpauthor>Internet Systems Consortium, Inc.</corpauthor>
|
||||
<author>
|
||||
<personname>Tony Finch</personname>
|
||||
<email>dot@dotat.at</email>
|
||||
<email>fanf2@cam.ac.uk</email>
|
||||
<affiliation>Cambridge University Information Services</affiliation>
|
||||
<personblurb></personblurb>
|
||||
</author>
|
||||
</refentryinfo>
|
||||
|
||||
<refmeta>
|
||||
<refentrytitle><application>dnssec-cds</application></refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
<refmiscinfo>BIND9</refmiscinfo>
|
||||
</refmeta>
|
||||
|
||||
<refnamediv>
|
||||
<refname><application>dnssec-cds</application></refname>
|
||||
<refpurpose>change DS records for a child zone based on CDS/CDNSKEY</refpurpose>
|
||||
</refnamediv>
|
||||
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2017</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis sepchar=" ">
|
||||
<command>dnssec-cds</command>
|
||||
<arg choice="opt" rep="repeat"><option>-a <replaceable class="parameter">alg</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-D</option></arg>
|
||||
<arg choice="req" rep="norepeat"><option>-d <replaceable class="parameter">dsset-file</replaceable></option></arg>
|
||||
<arg choice="req" rep="norepeat"><option>-f <replaceable class="parameter">child-file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-i</option><arg choice="opt" rep="norepeat"><replaceable class="parameter">extension</replaceable></arg></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-u</option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
||||
<arg choice="req" rep="norepeat">domain</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsection><info><title>DESCRIPTION</title></info>
|
||||
|
||||
<para>
|
||||
The <command>dnssec-cds</command> command changes DS records at
|
||||
a delegation point based on CDS or CDNSKEY records published in
|
||||
the child zone. If both CDS and CDNSKEY records are present in
|
||||
the child zone, the CDS is preferred.
|
||||
</para>
|
||||
<para>
|
||||
Two input files are required. The
|
||||
<option>-f <replaceable class="parameter">child-file</replaceable></option>
|
||||
option specifies a file containing the child's CDS and/or CDNSKEY
|
||||
records, plus RRSIG and DNSKEY records so that they can be
|
||||
authenticated. The
|
||||
<option>-d <replaceable class="parameter">path</replaceable></option>
|
||||
option specifies the location of a file containing the current DS
|
||||
records. For example, this could be a <filename>dsset-</filename>
|
||||
file generated by <command>dnssec-signzone</command>, or the output of
|
||||
<command>dnssec-dsfromkey</command>, or the output of a previous
|
||||
run of <command>dnssec-cds</command>.
|
||||
</para>
|
||||
<para>
|
||||
For protection against replay attacks, the signatures on the
|
||||
child records must not be older than they were on a previous run
|
||||
of <command>dnssec-cds</command>. This time is obtained from the
|
||||
modification time of the <filename>dsset-</filename> file, or
|
||||
from the <option>-s</option> option.
|
||||
</para>
|
||||
<para>
|
||||
To protect against breaking the delegation,
|
||||
<command>dnssec-cds</command> ensures that the DNSKEY RRset can be
|
||||
verified by every key algorithm in the new DS RRset, and that the
|
||||
same set of keys are covered by every DS digest type.
|
||||
</para>
|
||||
<para>
|
||||
By default, replacement DS records are written to the standard
|
||||
output; with the <option>-i</option> option the input file is
|
||||
overwritten in place. The replacement DS records will be the
|
||||
same as the existing records when no change is required. The
|
||||
output can be empty if the CDS / CDNSKEY records specify that
|
||||
the child zone wants to go insecure.
|
||||
</para>
|
||||
<para>
|
||||
Warning: Be careful not to delete the DS records
|
||||
when <command>dnssec-cds</command> fails!
|
||||
</para>
|
||||
<para>
|
||||
Alternatively, <command>dnssec-cds -u</command> writes
|
||||
an <command>nsupdate</command> script to the standard output.
|
||||
You can use the <option>-u</option> and <option>-i</option>
|
||||
options together to maintain a <filename>dsset-</filename> file
|
||||
as well as emit an <command>nsupdate</command> script.
|
||||
</para>
|
||||
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>OPTIONS</title></info>
|
||||
|
||||
<variablelist>
|
||||
|
||||
<varlistentry>
|
||||
<term>-a <replaceable class="parameter">algorithm</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specify a digest algorithm to use when converting CDNSKEY
|
||||
records to DS records. This option can be repeated, so
|
||||
that multiple DS records are created for each CDNSKEY
|
||||
record. This option has no effect when using CDS records.
|
||||
</para>
|
||||
<para>
|
||||
The <replaceable>algorithm</replaceable> must be one of SHA-1
|
||||
(SHA1), SHA-256 (SHA256), GOST, or SHA-384 (SHA384). These
|
||||
values are case insensitive. If no algorithm is specified,
|
||||
the default is SHA-256.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-c <replaceable class="parameter">class</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies the DNS class of the zones.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-D</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Generate DS records from CDNSKEY records if both CDS and
|
||||
CDNSKEY records are present in the child zone. By default
|
||||
CDS records are preferred.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-d <replaceable class="parameter">path</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Location of the parent DS records.
|
||||
The <replaceable>path</replaceable> can be the name of a file
|
||||
containing the DS records, or if it is a
|
||||
directory, <command>dnssec-cds</command> looks for
|
||||
a <filename>dsset-</filename> file for
|
||||
the <replaceable>domain</replaceable> inside the directory.
|
||||
</para>
|
||||
<para>
|
||||
To protect against replay attacks, child records are
|
||||
rejected if they were signed earlier than the modification
|
||||
time of the <filename>dsset-</filename> file. This can be
|
||||
adjusted with the <option>-s</option> option.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-f <replaceable class="parameter">child-file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
File containing the child's CDS and/or CDNSKEY records,
|
||||
plus its DNSKEY records and the covering RRSIG records so
|
||||
that they can be authenticated.
|
||||
</para>
|
||||
<para>
|
||||
The EXAMPLES below describe how to generate this file.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-i<arg choice="opt" rep="norepeat"><replaceable class="parameter">extension</replaceable></arg></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Update the <filename>dsset-</filename> file in place,
|
||||
instead of writing DS records to the standard output.
|
||||
</para>
|
||||
<para>
|
||||
There must be no space between the <option>-i</option> and
|
||||
the <replaceable>extension</replaceable>. If you provide
|
||||
no <replaceable>extension</replaceable> then the
|
||||
old <filename>dsset-</filename> is discarded. If
|
||||
an <replaceable>extension</replaceable> is present, a
|
||||
backup of the old <filename>dsset-</filename> file is kept
|
||||
with the <replaceable>extension</replaceable> appended to
|
||||
its filename.
|
||||
</para>
|
||||
<para>
|
||||
To protect against replay attacks, the modification time
|
||||
of the <filename>dsset-</filename> file is set to match
|
||||
the signature inception time of the child records,
|
||||
provided that is later than the file's current
|
||||
modification time.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-s <replaceable class="parameter">start-time</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specify the date and time after which RRSIG records become
|
||||
acceptable. This can be either an absolute or relative
|
||||
time. An absolute start time is indicated by a number in
|
||||
YYYYMMDDHHMMSS notation; 20170827133700 denotes 13:37:00
|
||||
UTC on August 27th, 2017. A time relative to
|
||||
the <filename>dsset-</filename> file is indicated with -N,
|
||||
which is N seconds before the file modification time. A
|
||||
time relative to the current time is indicated with now+N.
|
||||
</para>
|
||||
<para>
|
||||
If no <replaceable>start-time</replaceable> is specified, the
|
||||
modification time of the <filename>dsset-</filename> file
|
||||
is used.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-T <replaceable class="parameter">ttl</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a TTL to be used for new DS records. If not
|
||||
specified, the default is the TTL of the old DS records.
|
||||
If they had no explicit TTL then the new DS records also
|
||||
have no explicit TTL.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-u</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Write an <command>nsupdate</command> script to the
|
||||
standard output, instead of printing the new DS reords.
|
||||
The output will be empty if no change is needed.
|
||||
</para>
|
||||
<para>
|
||||
Note: The TTL of new records needs to be specified, either
|
||||
in the original <filename>dsset-</filename> file, or with
|
||||
the <option>-T</option> option, or using
|
||||
the <command>nsupdate</command> <command>ttl</command>
|
||||
command.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-V</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Print version information.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-v <replaceable class="parameter">level</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the debugging level. Level 1 is intended to be
|
||||
usefully verbose for general users; higher levels are
|
||||
intended for developers.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><replaceable>domain</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
The name of the delegation point / child zone apex.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
</variablelist>
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>EXIT STATUS</title></info>
|
||||
|
||||
<para>
|
||||
The <command>dnssec-cds</command> command exits 0 on success, or
|
||||
non-zero if an error occurred.
|
||||
</para>
|
||||
<para>
|
||||
In the success case, the DS records might or might not need
|
||||
to be changed.
|
||||
</para>
|
||||
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>EXAMPLES</title></info>
|
||||
|
||||
<para>
|
||||
Before running <command>dnssec-signzone</command>, you can ensure
|
||||
that the delegations are up-to-date by running
|
||||
<command>dnssec-cds</command> on every <filename>dsset-</filename> file.
|
||||
</para>
|
||||
<para>
|
||||
To fetch the child records required by <command>dnssec-cds</command>
|
||||
you can invoke <command>dig</command> as in the script below. It's
|
||||
okay if the <command>dig</command> fails since
|
||||
<command>dnssec-cds</command> performs all the necessary checking.
|
||||
</para>
|
||||
<programlisting>for f in dsset-*
|
||||
do
|
||||
d=${f#dsset-}
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec-cds -i -f /dev/stdin -d $f $d
|
||||
done
|
||||
</programlisting>
|
||||
|
||||
<para>
|
||||
When the parent zone is automatically signed by
|
||||
<command>named</command>, you can use <command>dnssec-cds</command>
|
||||
with <command>nsupdate</command> to maintain a delegation as follows.
|
||||
The <filename>dsset-</filename> file allows the script to avoid
|
||||
having to fetch and validate the parent DS records, and it keeps the
|
||||
replay attack protection time.
|
||||
</para>
|
||||
<programlisting>
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec-cds -u -i -f /dev/stdin -d $f $d |
|
||||
nsupdate -l
|
||||
</programlisting>
|
||||
</refsection>
|
||||
|
||||
<refsection><info><title>SEE ALSO</title></info>
|
||||
|
||||
<para>
|
||||
<citerefentry>
|
||||
<refentrytitle>dig</refentrytitle><manvolnum>1</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-settime</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>nsupdate</refentrytitle><manvolnum>1</manvolnum>
|
||||
</citerefentry>,
|
||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>,
|
||||
<citetitle>RFC 7344</citetitle>.
|
||||
</para>
|
||||
|
||||
</refsection>
|
||||
|
||||
</refentry>
|
||||
@@ -0,0 +1,332 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
- file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
-->
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>dnssec-cds</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry">
|
||||
<a name="man.dnssec-cds"></a><div class="titlepage"></div>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<div class="refnamediv">
|
||||
<h2>Name</h2>
|
||||
<p>
|
||||
<span class="application">dnssec-cds</span>
|
||||
— change DS records for a child zone based on CDS/CDNSKEY
|
||||
</p>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p>
|
||||
<code class="command">dnssec-cds</code>
|
||||
[<code class="option">-a <em class="replaceable"><code>alg</code></em></code>...]
|
||||
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
||||
[<code class="option">-D</code>]
|
||||
{<code class="option">-d <em class="replaceable"><code>dsset-file</code></em></code>}
|
||||
{<code class="option">-f <em class="replaceable"><code>child-file</code></em></code>}
|
||||
[<code class="option">-i</code> [<em class="replaceable"><code>extension</code></em>]]
|
||||
[<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>]
|
||||
[<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>]
|
||||
[<code class="option">-u</code>]
|
||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||
[<code class="option">-V</code>]
|
||||
{domain}
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.7"></a><h2>DESCRIPTION</h2>
|
||||
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-cds</strong></span> command changes DS records at
|
||||
a delegation point based on CDS or CDNSKEY records published in
|
||||
the child zone. If both CDS and CDNSKEY records are present in
|
||||
the child zone, the CDS is preferred.
|
||||
</p>
|
||||
<p>
|
||||
Two input files are required. The
|
||||
<code class="option">-f <em class="replaceable"><code>child-file</code></em></code>
|
||||
option specifies a file containing the child's CDS and/or CDNSKEY
|
||||
records, plus RRSIG and DNSKEY records so that they can be
|
||||
authenticated. The
|
||||
<code class="option">-d <em class="replaceable"><code>path</code></em></code>
|
||||
option specifies the location of a file containing the current DS
|
||||
records. For example, this could be a <code class="filename">dsset-</code>
|
||||
file generated by <span class="command"><strong>dnssec-signzone</strong></span>, or the output of
|
||||
<span class="command"><strong>dnssec-dsfromkey</strong></span>, or the output of a previous
|
||||
run of <span class="command"><strong>dnssec-cds</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
For protection against replay attacks, the signatures on the
|
||||
child records must not be older than they were on a previous run
|
||||
of <span class="command"><strong>dnssec-cds</strong></span>. This time is obtained from the
|
||||
modification time of the <code class="filename">dsset-</code> file, or
|
||||
from the <code class="option">-s</code> option.
|
||||
</p>
|
||||
<p>
|
||||
To protect against breaking the delegation,
|
||||
<span class="command"><strong>dnssec-cds</strong></span> ensures that the DNSKEY RRset can be
|
||||
verified by every key algorithm in the new DS RRset, and that the
|
||||
same set of keys are covered by every DS digest type.
|
||||
</p>
|
||||
<p>
|
||||
By default, replacement DS records are written to the standard
|
||||
output; with the <code class="option">-i</code> option the input file is
|
||||
overwritten in place. The replacement DS records will be the
|
||||
same as the existing records when no change is required. The
|
||||
output can be empty if the CDS / CDNSKEY records specify that
|
||||
the child zone wants to go insecure.
|
||||
</p>
|
||||
<p>
|
||||
Warning: Be careful not to delete the DS records
|
||||
when <span class="command"><strong>dnssec-cds</strong></span> fails!
|
||||
</p>
|
||||
<p>
|
||||
Alternatively, <span class="command"><strong>dnssec-cds -u</strong></span> writes
|
||||
an <span class="command"><strong>nsupdate</strong></span> script to the standard output.
|
||||
You can use the <code class="option">-u</code> and <code class="option">-i</code>
|
||||
options together to maintain a <code class="filename">dsset-</code> file
|
||||
as well as emit an <span class="command"><strong>nsupdate</strong></span> script.
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.8"></a><h2>OPTIONS</h2>
|
||||
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specify a digest algorithm to use when converting CDNSKEY
|
||||
records to DS records. This option can be repeated, so
|
||||
that multiple DS records are created for each CDNSKEY
|
||||
record. This option has no effect when using CDS records.
|
||||
</p>
|
||||
<p>
|
||||
The <em class="replaceable"><code>algorithm</code></em> must be one of SHA-1
|
||||
(SHA1), SHA-256 (SHA256), GOST, or SHA-384 (SHA384). These
|
||||
values are case insensitive. If no algorithm is specified,
|
||||
the default is SHA-256.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies the DNS class of the zones.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-D</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Generate DS records from CDNSKEY records if both CDS and
|
||||
CDNSKEY records are present in the child zone. By default
|
||||
CDS records are preferred.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>path</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Location of the parent DS records.
|
||||
The <em class="replaceable"><code>path</code></em> can be the name of a file
|
||||
containing the DS records, or if it is a
|
||||
directory, <span class="command"><strong>dnssec-cds</strong></span> looks for
|
||||
a <code class="filename">dsset-</code> file for
|
||||
the <em class="replaceable"><code>domain</code></em> inside the directory.
|
||||
</p>
|
||||
<p>
|
||||
To protect against replay attacks, child records are
|
||||
rejected if they were signed earlier than the modification
|
||||
time of the <code class="filename">dsset-</code> file. This can be
|
||||
adjusted with the <code class="option">-s</code> option.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-f <em class="replaceable"><code>child-file</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
File containing the child's CDS and/or CDNSKEY records,
|
||||
plus its DNSKEY records and the covering RRSIG records so
|
||||
that they can be authenticated.
|
||||
</p>
|
||||
<p>
|
||||
The EXAMPLES below describe how to generate this file.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-i[<em class="replaceable"><code>extension</code></em>]</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Update the <code class="filename">dsset-</code> file in place,
|
||||
instead of writing DS records to the standard output.
|
||||
</p>
|
||||
<p>
|
||||
There must be no space between the <code class="option">-i</code> and
|
||||
the <em class="replaceable"><code>extension</code></em>. If you provide
|
||||
no <em class="replaceable"><code>extension</code></em> then the
|
||||
old <code class="filename">dsset-</code> is discarded. If
|
||||
an <em class="replaceable"><code>extension</code></em> is present, a
|
||||
backup of the old <code class="filename">dsset-</code> file is kept
|
||||
with the <em class="replaceable"><code>extension</code></em> appended to
|
||||
its filename.
|
||||
</p>
|
||||
<p>
|
||||
To protect against replay attacks, the modification time
|
||||
of the <code class="filename">dsset-</code> file is set to match
|
||||
the signature inception time of the child records,
|
||||
provided that is later than the file's current
|
||||
modification time.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specify the date and time after which RRSIG records become
|
||||
acceptable. This can be either an absolute or relative
|
||||
time. An absolute start time is indicated by a number in
|
||||
YYYYMMDDHHMMSS notation; 20170827133700 denotes 13:37:00
|
||||
UTC on August 27th, 2017. A time relative to
|
||||
the <code class="filename">dsset-</code> file is indicated with -N,
|
||||
which is N seconds before the file modification time. A
|
||||
time relative to the current time is indicated with now+N.
|
||||
</p>
|
||||
<p>
|
||||
If no <em class="replaceable"><code>start-time</code></em> is specified, the
|
||||
modification time of the <code class="filename">dsset-</code> file
|
||||
is used.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies a TTL to be used for new DS records. If not
|
||||
specified, the default is the TTL of the old DS records.
|
||||
If they had no explicit TTL then the new DS records also
|
||||
have no explicit TTL.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-u</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Write an <span class="command"><strong>nsupdate</strong></span> script to the
|
||||
standard output, instead of printing the new DS reords.
|
||||
The output will be empty if no change is needed.
|
||||
</p>
|
||||
<p>
|
||||
Note: The TTL of new records needs to be specified, either
|
||||
in the original <code class="filename">dsset-</code> file, or with
|
||||
the <code class="option">-T</code> option, or using
|
||||
the <span class="command"><strong>nsupdate</strong></span> <span class="command"><strong>ttl</strong></span>
|
||||
command.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-V</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Print version information.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the debugging level. Level 1 is intended to be
|
||||
usefully verbose for general users; higher levels are
|
||||
intended for developers.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><em class="replaceable"><code>domain</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The name of the delegation point / child zone apex.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.9"></a><h2>EXIT STATUS</h2>
|
||||
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-cds</strong></span> command exits 0 on success, or
|
||||
non-zero if an error occurred.
|
||||
</p>
|
||||
<p>
|
||||
In the success case, the DS records might or might not need
|
||||
to be changed.
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.10"></a><h2>EXAMPLES</h2>
|
||||
|
||||
<p>
|
||||
Before running <span class="command"><strong>dnssec-signzone</strong></span>, you can ensure
|
||||
that the delegations are up-to-date by running
|
||||
<span class="command"><strong>dnssec-cds</strong></span> on every <code class="filename">dsset-</code> file.
|
||||
</p>
|
||||
<p>
|
||||
To fetch the child records required by <span class="command"><strong>dnssec-cds</strong></span>
|
||||
you can invoke <span class="command"><strong>dig</strong></span> as in the script below. It's
|
||||
okay if the <span class="command"><strong>dig</strong></span> fails since
|
||||
<span class="command"><strong>dnssec-cds</strong></span> performs all the necessary checking.
|
||||
</p>
|
||||
<pre class="programlisting">for f in dsset-*
|
||||
do
|
||||
d=${f#dsset-}
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec-cds -i -f /dev/stdin -d $f $d
|
||||
done
|
||||
</pre>
|
||||
|
||||
<p>
|
||||
When the parent zone is automatically signed by
|
||||
<span class="command"><strong>named</strong></span>, you can use <span class="command"><strong>dnssec-cds</strong></span>
|
||||
with <span class="command"><strong>nsupdate</strong></span> to maintain a delegation as follows.
|
||||
The <code class="filename">dsset-</code> file allows the script to avoid
|
||||
having to fetch and validate the parent DS records, and it keeps the
|
||||
replay attack protection time.
|
||||
</p>
|
||||
<pre class="programlisting">
|
||||
dig +dnssec +noall +answer $d DNSKEY $d CDNSKEY $d CDS |
|
||||
dnssec-cds -u -i -f /dev/stdin -d $f $d |
|
||||
nsupdate -l
|
||||
</pre>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.11"></a><h2>SEE ALSO</h2>
|
||||
|
||||
<p>
|
||||
<span class="citerefentry">
|
||||
<span class="refentrytitle">dig</span>(1)
|
||||
</span>,
|
||||
<span class="citerefentry">
|
||||
<span class="refentrytitle">dnssec-settime</span>(8)
|
||||
</span>,
|
||||
<span class="citerefentry">
|
||||
<span class="refentrytitle">dnssec-signzone</span>(8)
|
||||
</span>,
|
||||
<span class="citerefentry">
|
||||
<span class="refentrytitle">nsupdate</span>(1)
|
||||
</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
<em class="citetitle">RFC 7344</em>.
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
</div></body>
|
||||
</html>
|
||||
@@ -346,7 +346,7 @@ usage(void) {
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
char *algname = NULL, *classname = NULL;
|
||||
char *classname = NULL;
|
||||
char *filename = NULL, *dir = NULL, *namestr;
|
||||
char *lookaside = NULL;
|
||||
char *endp;
|
||||
@@ -393,7 +393,7 @@ main(int argc, char **argv) {
|
||||
showall = ISC_TRUE;
|
||||
break;
|
||||
case 'a':
|
||||
algname = isc_commandline_argument;
|
||||
dtype = strtodsdigest(isc_commandline_argument);
|
||||
both = ISC_FALSE;
|
||||
break;
|
||||
case 'C':
|
||||
@@ -430,7 +430,7 @@ main(int argc, char **argv) {
|
||||
break;
|
||||
case 'T':
|
||||
emitttl = ISC_TRUE;
|
||||
ttl = atol(isc_commandline_argument);
|
||||
ttl = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case 'v':
|
||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||
@@ -460,24 +460,6 @@ main(int argc, char **argv) {
|
||||
}
|
||||
}
|
||||
|
||||
if (algname != NULL) {
|
||||
if (strcasecmp(algname, "SHA1") == 0 ||
|
||||
strcasecmp(algname, "SHA-1") == 0)
|
||||
dtype = DNS_DSDIGEST_SHA1;
|
||||
else if (strcasecmp(algname, "SHA256") == 0 ||
|
||||
strcasecmp(algname, "SHA-256") == 0)
|
||||
dtype = DNS_DSDIGEST_SHA256;
|
||||
#if defined(HAVE_OPENSSL_GOST) || defined(HAVE_PKCS11_GOST)
|
||||
else if (strcasecmp(algname, "GOST") == 0)
|
||||
dtype = DNS_DSDIGEST_GOST;
|
||||
#endif
|
||||
else if (strcasecmp(algname, "SHA384") == 0 ||
|
||||
strcasecmp(algname, "SHA-384") == 0)
|
||||
dtype = DNS_DSDIGEST_SHA384;
|
||||
else
|
||||
fatal("unknown algorithm %s", algname);
|
||||
}
|
||||
|
||||
rdclass = strtoclass(classname);
|
||||
|
||||
if (usekeyset && filename != NULL)
|
||||
@@ -494,14 +476,14 @@ main(int argc, char **argv) {
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize hash");
|
||||
result = dst_lib_init(mctx, ectx,
|
||||
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize hash");
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
setup_logging(mctx, &log);
|
||||
@@ -563,8 +545,8 @@ main(int argc, char **argv) {
|
||||
if (dns_rdataset_isassociated(&rdataset))
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
cleanup_logging(&log);
|
||||
dst_lib_destroy();
|
||||
isc_hash_destroy();
|
||||
dst_lib_destroy();
|
||||
cleanup_entropy(&ectx);
|
||||
dns_name_destroy();
|
||||
if (verbose > 10)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -405,14 +405,14 @@ main(int argc, char **argv) {
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize hash");
|
||||
result = dst_lib_init(mctx, ectx,
|
||||
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize hash");
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
setup_logging(mctx, &log);
|
||||
@@ -456,8 +456,8 @@ main(int argc, char **argv) {
|
||||
if (dns_rdataset_isassociated(&rdataset))
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
cleanup_logging(&log);
|
||||
dst_lib_destroy();
|
||||
isc_hash_destroy();
|
||||
dst_lib_destroy();
|
||||
cleanup_entropy(&ectx);
|
||||
dns_name_destroy();
|
||||
if (verbose > 10)
|
||||
|
||||
@@ -177,13 +177,17 @@ indicating the progress of the key generation\&. A \*(Aq\&.\*(Aq indicates that
|
||||
.PP
|
||||
\-r \fIrandomdev\fR
|
||||
.RS 4
|
||||
Specifies the source of randomness\&. If the operating system does not provide a
|
||||
/dev/random
|
||||
or equivalent device, the default source of randomness is keyboard input\&.
|
||||
Specifies a source of randomness\&. Normally, when generating DNSSEC keys, this option has no effect; the random number generation function provided by the cryptographic library will be used\&.
|
||||
.sp
|
||||
If that behavior is disabled at compile time, however, the specified file will be used as entropy source for key generation\&.
|
||||
randomdev
|
||||
specifies the name of a character device or file containing random data to be used instead of the default\&. The special value
|
||||
is the name of a character device or file containing random data to be used\&. The special value
|
||||
keyboard
|
||||
indicates that keyboard input should be used\&.
|
||||
.sp
|
||||
The default is
|
||||
/dev/random
|
||||
if the operating system provides it or an equivalent device; if not, the default source of randomness is keyboard input\&.
|
||||
.RE
|
||||
.PP
|
||||
\-S \fIkey\fR
|
||||
|
||||
@@ -347,15 +347,23 @@
|
||||
<term>-r <replaceable class="parameter">randomdev</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies the source of randomness. If the operating
|
||||
system does not provide a <filename>/dev/random</filename>
|
||||
or equivalent device, the default source of randomness
|
||||
is keyboard input. <filename>randomdev</filename>
|
||||
specifies
|
||||
Specifies a source of randomness. Normally, when generating
|
||||
DNSSEC keys, this option has no effect; the random number
|
||||
generation function provided by the cryptographic library will
|
||||
be used.
|
||||
</para>
|
||||
<para>
|
||||
If that behavior is disabled at compile time, however,
|
||||
the specified file will be used as entropy source
|
||||
for key generation. <filename>randomdev</filename> is
|
||||
the name of a character device or file containing random
|
||||
data to be used instead of the default. The special value
|
||||
<filename>keyboard</filename> indicates that keyboard
|
||||
input should be used.
|
||||
data to be used. The special value <filename>keyboard</filename>
|
||||
indicates that keyboard input should be used.
|
||||
</para>
|
||||
<para>
|
||||
The default is <filename>/dev/random</filename> if the
|
||||
operating system provides it or an equivalent device;
|
||||
if not, the default source of randomness is keyboard input.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -280,15 +280,23 @@
|
||||
<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies the source of randomness. If the operating
|
||||
system does not provide a <code class="filename">/dev/random</code>
|
||||
or equivalent device, the default source of randomness
|
||||
is keyboard input. <code class="filename">randomdev</code>
|
||||
specifies
|
||||
Specifies a source of randomness. Normally, when generating
|
||||
DNSSEC keys, this option has no effect; the random number
|
||||
generation function provided by the cryptographic library will
|
||||
be used.
|
||||
</p>
|
||||
<p>
|
||||
If that behavior is disabled at compile time, however,
|
||||
the specified file will be used as entropy source
|
||||
for key generation. <code class="filename">randomdev</code> is
|
||||
the name of a character device or file containing random
|
||||
data to be used instead of the default. The special value
|
||||
<code class="filename">keyboard</code> indicates that keyboard
|
||||
input should be used.
|
||||
data to be used. The special value <code class="filename">keyboard</code>
|
||||
indicates that keyboard input should be used.
|
||||
</p>
|
||||
<p>
|
||||
The default is <code class="filename">/dev/random</code> if the
|
||||
operating system provides it or an equivalent device;
|
||||
if not, the default source of randomness is keyboard input.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
|
||||
|
||||
@@ -179,14 +179,14 @@ main(int argc, char **argv) {
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize hash");
|
||||
result = dst_lib_init2(mctx, ectx, engine,
|
||||
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize hash");
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
result = dst_key_fromnamedfile(filename, dir,
|
||||
@@ -268,8 +268,8 @@ main(int argc, char **argv) {
|
||||
|
||||
cleanup:
|
||||
dst_key_free(&key);
|
||||
dst_lib_destroy();
|
||||
isc_hash_destroy();
|
||||
dst_lib_destroy();
|
||||
cleanup_entropy(&ectx);
|
||||
if (verbose > 10)
|
||||
isc_mem_stats(mctx, stdout);
|
||||
|
||||
@@ -377,14 +377,14 @@ main(int argc, char **argv) {
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize hash");
|
||||
result = dst_lib_init2(mctx, ectx, engine,
|
||||
ISC_ENTROPY_BLOCKING | ISC_ENTROPY_GOODONLY);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Could not initialize hash");
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
if (predecessor != NULL) {
|
||||
@@ -669,8 +669,8 @@ main(int argc, char **argv) {
|
||||
if (prevkey != NULL)
|
||||
dst_key_free(&prevkey);
|
||||
dst_key_free(&key);
|
||||
dst_lib_destroy();
|
||||
isc_hash_destroy();
|
||||
dst_lib_destroy();
|
||||
cleanup_entropy(&ectx);
|
||||
if (verbose > 10)
|
||||
isc_mem_stats(mctx, stdout);
|
||||
|
||||
@@ -376,7 +376,7 @@ Sets the debugging level\&.
|
||||
.PP
|
||||
\-x
|
||||
.RS 4
|
||||
Only sign the DNSKEY RRset with key\-signing keys, and omit signatures from zone\-signing keys\&. (This is similar to the
|
||||
Only sign the DNSKEY, CDNSKEY, and CDS RRsets with key\-signing keys, and omit signatures from zone\-signing keys\&. (This is similar to the
|
||||
\fBdnssec\-dnskey\-kskonly yes;\fR
|
||||
zone option in
|
||||
\fBnamed\fR\&.)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Portions Copyright (C) 1999-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 1999-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -659,7 +659,9 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
||||
if (!issigningkey(key))
|
||||
continue;
|
||||
|
||||
if (set->type == dns_rdatatype_dnskey &&
|
||||
if ((set->type == dns_rdatatype_cds ||
|
||||
set->type == dns_rdatatype_cdnskey ||
|
||||
set->type == dns_rdatatype_dnskey) &&
|
||||
dns_name_equal(name, gorigin)) {
|
||||
isc_boolean_t have_ksk;
|
||||
dns_dnsseckey_t *tmpkey;
|
||||
@@ -680,9 +682,7 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
||||
(iszsk(key) && !keyset_kskonly))
|
||||
signwithkey(name, set, key->key, ttl, add,
|
||||
"signing with dnskey");
|
||||
} else if (set->type == dns_rdatatype_cds ||
|
||||
set->type == dns_rdatatype_cdnskey ||
|
||||
iszsk(key)) {
|
||||
} else if (iszsk(key)) {
|
||||
signwithkey(name, set, key->key, ttl, add,
|
||||
"signing with dnskey");
|
||||
}
|
||||
@@ -2591,27 +2591,67 @@ report(const char *format, ...) {
|
||||
putc('\n', stderr);
|
||||
}
|
||||
|
||||
static void
|
||||
clear_keylist(dns_dnsseckeylist_t *list) {
|
||||
dns_dnsseckey_t *key;
|
||||
while (!ISC_LIST_EMPTY(*list)) {
|
||||
key = ISC_LIST_HEAD(*list);
|
||||
ISC_LIST_UNLINK(*list, key, link);
|
||||
dns_dnsseckey_destroy(mctx, &key);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
build_final_keylist(void) {
|
||||
isc_result_t result;
|
||||
dns_dbnode_t *node = NULL;
|
||||
dns_dbversion_t *ver = NULL;
|
||||
dns_diff_t diff;
|
||||
dns_dnsseckeylist_t matchkeys;
|
||||
dns_dnsseckeylist_t rmkeys, matchkeys;
|
||||
char name[DNS_NAME_FORMATSIZE];
|
||||
dns_rdataset_t cdsset, cdnskeyset, soaset;
|
||||
|
||||
ISC_LIST_INIT(rmkeys);
|
||||
ISC_LIST_INIT(matchkeys);
|
||||
|
||||
dns_rdataset_init(&soaset);
|
||||
dns_rdataset_init(&cdsset);
|
||||
dns_rdataset_init(&cdnskeyset);
|
||||
|
||||
/*
|
||||
* Find keys that match this zone in the key repository.
|
||||
*/
|
||||
ISC_LIST_INIT(matchkeys);
|
||||
result = dns_dnssec_findmatchingkeys(gorigin, directory,
|
||||
mctx, &matchkeys);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
result = ISC_R_SUCCESS;
|
||||
}
|
||||
check_result(result, "dns_dnssec_findmatchingkeys");
|
||||
|
||||
result = dns_db_newversion(gdb, &ver);
|
||||
check_result(result, "dns_db_newversion");
|
||||
|
||||
result = dns_db_getoriginnode(gdb, &node);
|
||||
check_result(result, "dns_db_getoriginnode");
|
||||
|
||||
/* Get the CDS rdataset */
|
||||
result = dns_db_findrdataset(gdb, node, ver, dns_rdatatype_cds,
|
||||
dns_rdatatype_none, 0, &cdsset, NULL);
|
||||
if (result != ISC_R_SUCCESS &&
|
||||
dns_rdataset_isassociated(&cdsset))
|
||||
{
|
||||
dns_rdataset_disassociate(&cdsset);
|
||||
}
|
||||
|
||||
/* Get the CDNSKEY rdataset */
|
||||
result = dns_db_findrdataset(gdb, node, ver, dns_rdatatype_cdnskey,
|
||||
dns_rdatatype_none, 0, &cdnskeyset, NULL);
|
||||
if (result != ISC_R_SUCCESS &&
|
||||
dns_rdataset_isassociated(&cdnskeyset))
|
||||
{
|
||||
dns_rdataset_disassociate(&cdnskeyset);
|
||||
}
|
||||
|
||||
dns_diff_init(mctx, &diff);
|
||||
|
||||
/*
|
||||
@@ -2620,16 +2660,34 @@ build_final_keylist(void) {
|
||||
dns_dnssec_updatekeys(&keylist, &matchkeys, NULL, gorigin, keyttl,
|
||||
&diff, ignore_kskflag, mctx, report);
|
||||
|
||||
/*
|
||||
* Update keylist with sync records.
|
||||
*/
|
||||
dns_dnssec_syncupdate(&keylist, &rmkeys, &cdsset, &cdnskeyset,
|
||||
now, keyttl, &diff, mctx);
|
||||
|
||||
dns_name_format(gorigin, name, sizeof(name));
|
||||
|
||||
result = dns_diff_applysilently(&diff, gdb, ver);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("failed to update DNSKEY RRset at node '%s': %s",
|
||||
name, isc_result_totext(result));
|
||||
}
|
||||
|
||||
dns_db_detachnode(gdb, &node);
|
||||
dns_db_closeversion(gdb, &ver, ISC_TRUE);
|
||||
|
||||
dns_diff_clear(&diff);
|
||||
|
||||
if (dns_rdataset_isassociated(&cdsset)) {
|
||||
dns_rdataset_disassociate(&cdsset);
|
||||
}
|
||||
if (dns_rdataset_isassociated(&cdnskeyset)) {
|
||||
dns_rdataset_disassociate(&cdnskeyset);
|
||||
}
|
||||
|
||||
clear_keylist(&rmkeys);
|
||||
clear_keylist(&matchkeys);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -2806,18 +2864,18 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
||||
result = dns_name_tofilenametext(gorigin, ISC_FALSE, &namebuf);
|
||||
check_result(result, "dns_name_tofilenametext");
|
||||
isc_buffer_putuint8(&namebuf, 0);
|
||||
filenamelen = strlen(prefix) + strlen(namestr);
|
||||
filenamelen = strlen(prefix) + strlen(namestr) + 1;
|
||||
if (dsdir != NULL)
|
||||
filenamelen += strlen(dsdir) + 1;
|
||||
filename = isc_mem_get(mctx, filenamelen + 1);
|
||||
filename = isc_mem_get(mctx, filenamelen);
|
||||
if (filename == NULL)
|
||||
fatal("out of memory");
|
||||
if (dsdir != NULL)
|
||||
sprintf(filename, "%s/", dsdir);
|
||||
snprintf(filename, filenamelen, "%s/", dsdir);
|
||||
else
|
||||
filename[0] = 0;
|
||||
strcat(filename, prefix);
|
||||
strcat(filename, namestr);
|
||||
strlcat(filename, prefix, filenamelen);
|
||||
strlcat(filename, namestr, filenamelen);
|
||||
|
||||
dns_diff_init(mctx, &diff);
|
||||
|
||||
@@ -2916,7 +2974,7 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
||||
result = dns_master_dump(mctx, db, dbversion, style, filename);
|
||||
check_result(result, "dns_master_dump");
|
||||
|
||||
isc_mem_put(mctx, filename, filenamelen + 1);
|
||||
isc_mem_put(mctx, filename, filenamelen);
|
||||
|
||||
dns_db_closeversion(db, &dbversion, ISC_FALSE);
|
||||
dns_db_detach(&db);
|
||||
@@ -3431,14 +3489,15 @@ main(int argc, char *argv[]) {
|
||||
if (!pseudorandom)
|
||||
eflags |= ISC_ENTROPY_GOODONLY;
|
||||
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create hash context");
|
||||
|
||||
result = dst_lib_init2(mctx, ectx, engine, eflags);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create hash context");
|
||||
|
||||
isc_stdtime_get(&now);
|
||||
|
||||
if (startstr != NULL) {
|
||||
@@ -3489,12 +3548,13 @@ main(int argc, char *argv[]) {
|
||||
origin = file;
|
||||
|
||||
if (output == NULL) {
|
||||
size_t size;
|
||||
free_output = ISC_TRUE;
|
||||
output = isc_mem_allocate(mctx,
|
||||
strlen(file) + strlen(".signed") + 1);
|
||||
size = strlen(file) + strlen(".signed") + 1;
|
||||
output = isc_mem_allocate(mctx, size);
|
||||
if (output == NULL)
|
||||
fatal("out of memory");
|
||||
sprintf(output, "%s.signed", file);
|
||||
snprintf(output, size, "%s.signed", file);
|
||||
}
|
||||
|
||||
if (inputformatstr != NULL) {
|
||||
@@ -3614,8 +3674,9 @@ main(int argc, char *argv[]) {
|
||||
* do not have private keys associated and were
|
||||
* not specified on the command line.
|
||||
*/
|
||||
if (argc == 0 || smartsign)
|
||||
if (argc == 0 || smartsign) {
|
||||
loadzonekeys(!smartsign, ISC_FALSE);
|
||||
}
|
||||
loadexplicitkeys(argv, argc, ISC_FALSE);
|
||||
loadexplicitkeys(dskeyfile, ndskeys, ISC_TRUE);
|
||||
loadzonekeys(!smartsign, ISC_TRUE);
|
||||
@@ -3625,8 +3686,9 @@ main(int argc, char *argv[]) {
|
||||
* key files with metadata, and merge them with the keylist
|
||||
* we have now.
|
||||
*/
|
||||
if (smartsign)
|
||||
if (smartsign) {
|
||||
build_final_keylist();
|
||||
}
|
||||
|
||||
/* Now enumerate the key list */
|
||||
for (key = ISC_LIST_HEAD(keylist);
|
||||
@@ -3845,8 +3907,8 @@ main(int argc, char *argv[]) {
|
||||
dns_master_styledestroy(&dsstyle, mctx);
|
||||
|
||||
cleanup_logging(&log);
|
||||
dst_lib_destroy();
|
||||
isc_hash_destroy();
|
||||
dst_lib_destroy();
|
||||
cleanup_entropy(&ectx);
|
||||
dns_name_destroy();
|
||||
if (verbose > 10)
|
||||
|
||||
@@ -705,8 +705,9 @@
|
||||
<term>-x</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Only sign the DNSKEY RRset with key-signing keys, and omit
|
||||
signatures from zone-signing keys. (This is similar to the
|
||||
Only sign the DNSKEY, CDNSKEY, and CDS RRsets with
|
||||
key-signing keys, and omit signatures from zone-signing
|
||||
keys. (This is similar to the
|
||||
<command>dnssec-dnskey-kskonly yes;</command> zone option in
|
||||
<command>named</command>.)
|
||||
</para>
|
||||
|
||||
@@ -563,8 +563,9 @@
|
||||
<dt><span class="term">-x</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Only sign the DNSKEY RRset with key-signing keys, and omit
|
||||
signatures from zone-signing keys. (This is similar to the
|
||||
Only sign the DNSKEY, CDNSKEY, and CDS RRsets with
|
||||
key-signing keys, and omit signatures from zone-signing
|
||||
keys. (This is similar to the
|
||||
<span class="command"><strong>dnssec-dnskey-kskonly yes;</strong></span> zone option in
|
||||
<span class="command"><strong>named</strong></span>.)
|
||||
</p>
|
||||
|
||||
@@ -278,15 +278,15 @@ main(int argc, char *argv[]) {
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create hash context");
|
||||
|
||||
result = dst_lib_init2(mctx, ectx, engine, ISC_ENTROPY_BLOCKING);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not initialize dst: %s",
|
||||
isc_result_totext(result));
|
||||
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create hash context");
|
||||
|
||||
isc_stdtime_get(&now);
|
||||
|
||||
rdclass = strtoclass(classname);
|
||||
|
||||
+33
-3
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2000, 2001, 2003-2005, 2007, 2009-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2003-2005, 2007, 2009-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -29,6 +29,7 @@
|
||||
#include <isc/heap.h>
|
||||
#include <isc/list.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/platform.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/time.h>
|
||||
@@ -228,10 +229,16 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
||||
if (*ectx == NULL) {
|
||||
result = isc_entropy_create(mctx, ectx);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create entropy object");
|
||||
fatal("could not create entropy object: %s",
|
||||
isc_result_totext(result));
|
||||
ISC_LIST_INIT(sources);
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||
if (randomfile == NULL) {
|
||||
isc_entropy_usehook(*ectx, ISC_TRUE);
|
||||
}
|
||||
#endif
|
||||
if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||
usekeyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||
randomfile = NULL;
|
||||
@@ -405,6 +412,29 @@ strtoclass(const char *str) {
|
||||
return (rdclass);
|
||||
}
|
||||
|
||||
unsigned int
|
||||
strtodsdigest(const char *algname) {
|
||||
if (strcasecmp(algname, "SHA1") == 0 ||
|
||||
strcasecmp(algname, "SHA-1") == 0)
|
||||
{
|
||||
return (DNS_DSDIGEST_SHA1);
|
||||
} else if (strcasecmp(algname, "SHA256") == 0 ||
|
||||
strcasecmp(algname, "SHA-256") == 0)
|
||||
{
|
||||
return (DNS_DSDIGEST_SHA256);
|
||||
#if defined(HAVE_OPENSSL_GOST) || defined(HAVE_PKCS11_GOST)
|
||||
} else if (strcasecmp(algname, "GOST") == 0) {
|
||||
return (DNS_DSDIGEST_GOST);
|
||||
#endif
|
||||
} else if (strcasecmp(algname, "SHA384") == 0 ||
|
||||
strcasecmp(algname, "SHA-384") == 0)
|
||||
{
|
||||
return (DNS_DSDIGEST_SHA384);
|
||||
} else {
|
||||
fatal("unknown algorithm %s", algname);
|
||||
}
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
try_dir(const char *dirname) {
|
||||
isc_result_t result;
|
||||
@@ -1835,7 +1865,7 @@ verifyzone(dns_db_t *db, dns_dbversion_t *ver,
|
||||
for (i = 0; i < 256; i++) {
|
||||
if ((ksk_algorithms[i] != 0) ||
|
||||
(standby_ksk[i] != 0) ||
|
||||
(revoked_zsk[i] != 0) ||
|
||||
(revoked_ksk[i] != 0) ||
|
||||
(zsk_algorithms[i] != 0) ||
|
||||
(standby_zsk[i] != 0) ||
|
||||
(revoked_zsk[i] != 0)) {
|
||||
|
||||
@@ -65,6 +65,9 @@ isc_stdtime_t
|
||||
strtotime(const char *str, isc_int64_t now, isc_int64_t base,
|
||||
isc_boolean_t *setp);
|
||||
|
||||
unsigned int
|
||||
strtodsdigest(const char *str);
|
||||
|
||||
dns_rdataclass_t
|
||||
strtoclass(const char *str);
|
||||
|
||||
|
||||
+34
-1
@@ -9,7 +9,7 @@
|
||||
|
||||
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns="http://www.w3.org/1999/xhtml" version="1.0">
|
||||
<xsl:output method="html" indent="yes" version="4.0"/>
|
||||
<xsl:template match="statistics[@version="3.9"]">
|
||||
<xsl:template match="statistics[@version="3.10"]">
|
||||
<html>
|
||||
<head>
|
||||
<xsl:if test="system-property('xsl:vendor')!='Transformiix'">
|
||||
@@ -800,6 +800,39 @@
|
||||
</xsl:for-each>
|
||||
</xsl:for-each>
|
||||
</xsl:if>
|
||||
<xsl:if test="views/view[zones/zone/counters[@type="gluecache"]/counter >0]">
|
||||
<h2>Glue cache statistics</h2>
|
||||
<xsl:for-each select="views/view[zones/zone/counters[@type="gluecache"]/counter >0]">
|
||||
<h3>View <xsl:value-of select="@name"/></h3>
|
||||
<xsl:variable name="thisview2">
|
||||
<xsl:value-of select="@name"/>
|
||||
</xsl:variable>
|
||||
<xsl:for-each select="zones/zone">
|
||||
<xsl:if test="counters[@type="gluecache"]/counter[. > 0]">
|
||||
<h4>Zone <xsl:value-of select="@name"/></h4>
|
||||
<table class="counters">
|
||||
<xsl:for-each select="counters[@type="gluecache"]/counter[. > 0]">
|
||||
<xsl:sort select="."/>
|
||||
<xsl:variable name="css-class11">
|
||||
<xsl:choose>
|
||||
<xsl:when test="position() mod 2 = 0">even</xsl:when>
|
||||
<xsl:otherwise>odd</xsl:otherwise>
|
||||
</xsl:choose>
|
||||
</xsl:variable>
|
||||
<tr class="{$css-class11}">
|
||||
<th>
|
||||
<xsl:value-of select="@name"/>
|
||||
</th>
|
||||
<td>
|
||||
<xsl:value-of select="."/>
|
||||
</td>
|
||||
</tr>
|
||||
</xsl:for-each>
|
||||
</table>
|
||||
</xsl:if>
|
||||
</xsl:for-each>
|
||||
</xsl:for-each>
|
||||
</xsl:if>
|
||||
<xsl:if test="socketmgr/sockets/socket">
|
||||
<h2>Network Status</h2>
|
||||
<table class="netstat">
|
||||
|
||||
+34
-1
@@ -14,7 +14,7 @@ static char xslmsg[] =
|
||||
"\n"
|
||||
"<xsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" xmlns=\"http://www.w3.org/1999/xhtml\" version=\"1.0\">\n"
|
||||
" <xsl:output method=\"html\" indent=\"yes\" version=\"4.0\"/>\n"
|
||||
" <xsl:template match=\"statistics[@version="3.9"]\">\n"
|
||||
" <xsl:template match=\"statistics[@version="3.10"]\">\n"
|
||||
" <html>\n"
|
||||
" <head>\n"
|
||||
" <xsl:if test=\"system-property('xsl:vendor')!='Transformiix'\">\n"
|
||||
@@ -805,6 +805,39 @@ static char xslmsg[] =
|
||||
" </xsl:for-each>\n"
|
||||
" </xsl:for-each>\n"
|
||||
" </xsl:if>\n"
|
||||
" <xsl:if test=\"views/view[zones/zone/counters[@type="gluecache"]/counter >0]\">\n"
|
||||
" <h2>Glue cache statistics</h2>\n"
|
||||
" <xsl:for-each select=\"views/view[zones/zone/counters[@type="gluecache"]/counter >0]\">\n"
|
||||
" <h3>View <xsl:value-of select=\"@name\"/></h3>\n"
|
||||
" <xsl:variable name=\"thisview2\">\n"
|
||||
" <xsl:value-of select=\"@name\"/>\n"
|
||||
" </xsl:variable>\n"
|
||||
" <xsl:for-each select=\"zones/zone\">\n"
|
||||
" <xsl:if test=\"counters[@type="gluecache"]/counter[. > 0]\">\n"
|
||||
" <h4>Zone <xsl:value-of select=\"@name\"/></h4>\n"
|
||||
" <table class=\"counters\">\n"
|
||||
" <xsl:for-each select=\"counters[@type="gluecache"]/counter[. > 0]\">\n"
|
||||
" <xsl:sort select=\".\"/>\n"
|
||||
" <xsl:variable name=\"css-class11\">\n"
|
||||
" <xsl:choose>\n"
|
||||
" <xsl:when test=\"position() mod 2 = 0\">even</xsl:when>\n"
|
||||
" <xsl:otherwise>odd</xsl:otherwise>\n"
|
||||
" </xsl:choose>\n"
|
||||
" </xsl:variable>\n"
|
||||
" <tr class=\"{$css-class11}\">\n"
|
||||
" <th>\n"
|
||||
" <xsl:value-of select=\"@name\"/>\n"
|
||||
" </th>\n"
|
||||
" <td>\n"
|
||||
" <xsl:value-of select=\".\"/>\n"
|
||||
" </td>\n"
|
||||
" </tr>\n"
|
||||
" </xsl:for-each>\n"
|
||||
" </table>\n"
|
||||
" </xsl:if>\n"
|
||||
" </xsl:for-each>\n"
|
||||
" </xsl:for-each>\n"
|
||||
" </xsl:if>\n"
|
||||
" <xsl:if test=\"socketmgr/sockets/socket\">\n"
|
||||
" <h2>Network Status</h2>\n"
|
||||
" <table class=\"netstat\">\n"
|
||||
|
||||
+6
-7
@@ -86,7 +86,9 @@ options {\n\
|
||||
# pid-file \"" NAMED_LOCALSTATEDIR "/run/named/named.pid\"; \n\
|
||||
port 53;\n\
|
||||
prefetch 2 9;\n"
|
||||
#ifdef PATH_RANDOMDEV
|
||||
#if defined(ISC_PLATFORM_CRYPTORANDOM)
|
||||
" random-device none;\n"
|
||||
#elif defined(PATH_RANDOMDEV)
|
||||
" random-device \"" PATH_RANDOMDEV "\";\n"
|
||||
#endif
|
||||
" recursing-file \"named.recursing\";\n\
|
||||
@@ -125,9 +127,6 @@ options {\n\
|
||||
trust-anchor-telemetry yes;\n\
|
||||
# use-id-pool <obsolete>;\n\
|
||||
# use-ixfr <obsolete>;\n\
|
||||
\n\
|
||||
/* DLV */\n\
|
||||
dnssec-lookaside . trust-anchor dlv.isc.org;\n\
|
||||
\n\
|
||||
/* view */\n\
|
||||
allow-new-zones no;\n\
|
||||
@@ -181,7 +180,7 @@ options {\n\
|
||||
message-compression yes;\n\
|
||||
# min-roots <obsolete>;\n\
|
||||
minimal-any false;\n\
|
||||
minimal-responses true;\n\
|
||||
minimal-responses no-auth-recursive;\n\
|
||||
notify-source *;\n\
|
||||
notify-source-v6 *;\n\
|
||||
nsec3-test-zone no;\n\
|
||||
@@ -293,8 +292,8 @@ view \"_bind\" chaos {\n\
|
||||
};\n\
|
||||
"
|
||||
"#\n\
|
||||
# Default trusted key(s) for builtin DLV support\n\
|
||||
# (used if \"dnssec-lookaside auto;\" is set and\n\
|
||||
# Default trusted key(s), used if \n\
|
||||
# \"dnssec-validation auto;\" is set and\n\
|
||||
# sysconfdir/bind.keys doesn't exist).\n\
|
||||
#\n\
|
||||
# BEGIN MANAGED KEYS\n"
|
||||
|
||||
+12
-7
@@ -320,9 +320,10 @@ log_invalid(isccc_ccmsg_t *ccmsg, isc_result_t result) {
|
||||
|
||||
static void
|
||||
control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
controlconnection_t *conn;
|
||||
controllistener_t *listener;
|
||||
controlkey_t *key;
|
||||
controlconnection_t *conn = NULL;
|
||||
controllistener_t *listener = NULL;
|
||||
named_server_t *server = NULL;
|
||||
controlkey_t *key = NULL;
|
||||
isccc_sexpr_t *request = NULL;
|
||||
isccc_sexpr_t *response = NULL;
|
||||
isc_uint32_t algorithm;
|
||||
@@ -333,16 +334,17 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
isc_buffer_t *text;
|
||||
isc_result_t result;
|
||||
isc_result_t eresult;
|
||||
isccc_sexpr_t *_ctrl;
|
||||
isccc_sexpr_t *_ctrl = NULL;
|
||||
isccc_time_t sent;
|
||||
isccc_time_t exp;
|
||||
isc_uint32_t nonce;
|
||||
isccc_sexpr_t *data;
|
||||
isccc_sexpr_t *data = NULL;
|
||||
|
||||
REQUIRE(event->ev_type == ISCCC_EVENT_CCMSG);
|
||||
|
||||
conn = event->ev_arg;
|
||||
listener = conn->listener;
|
||||
server = listener->controls->server;
|
||||
algorithm = DST_ALG_UNKNOWN;
|
||||
secret.rstart = NULL;
|
||||
text = NULL;
|
||||
@@ -453,8 +455,11 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
* Establish nonce.
|
||||
*/
|
||||
if (conn->nonce == 0) {
|
||||
while (conn->nonce == 0)
|
||||
isc_random_get(&conn->nonce);
|
||||
while (conn->nonce == 0) {
|
||||
isc_uint16_t r1 = isc_rng_random(server->sctx->rngctx);
|
||||
isc_uint16_t r2 = isc_rng_random(server->sctx->rngctx);
|
||||
conn->nonce = (r1 << 16) | r2;
|
||||
}
|
||||
eresult = ISC_R_SUCCESS;
|
||||
} else
|
||||
eresult = named_control_docommand(request, listener->readonly,
|
||||
|
||||
+3
-3
@@ -64,7 +64,7 @@ fuzz_thread_client(void *arg) {
|
||||
* Parse named -A argument in the "address:port" syntax. Due to
|
||||
* the syntax used, this only supports IPv4 addresses.
|
||||
*/
|
||||
host = strdup(named_g_fuzz_named_addr);
|
||||
host = strdup(named_g_fuzz_addr);
|
||||
RUNTIME_CHECK(host != NULL);
|
||||
|
||||
port = strchr(host, ':');
|
||||
@@ -292,7 +292,7 @@ fuzz_thread_resolver(void *arg) {
|
||||
* Parse named -A argument in the "qtype:saddress:sport:raddress:rport"
|
||||
* syntax. Due to the syntax used, this only supports IPv4 addresses.
|
||||
*/
|
||||
sqtype = strdup(named_g_fuzz_named_addr);
|
||||
sqtype = strdup(named_g_fuzz_addr);
|
||||
RUNTIME_CHECK(sqtype != NULL);
|
||||
|
||||
shost = strchr(sqtype, ':');
|
||||
@@ -614,7 +614,7 @@ fuzz_thread_tcp(void *arg) {
|
||||
* Parse named -A argument in the "address:port" syntax. Due to
|
||||
* the syntax used, this only supports IPv4 addresses.
|
||||
*/
|
||||
host = strdup(named_g_fuzz_named_addr);
|
||||
host = strdup(named_g_fuzz_addr);
|
||||
RUNTIME_CHECK(host != NULL);
|
||||
|
||||
port = strchr(host, ':');
|
||||
|
||||
+43
-15
@@ -127,6 +127,7 @@ static isc_boolean_t noaa = ISC_FALSE;
|
||||
static unsigned int delay = 0;
|
||||
static isc_boolean_t nonearest = ISC_FALSE;
|
||||
static isc_boolean_t notcp = ISC_FALSE;
|
||||
static isc_boolean_t fixedlocal = ISC_FALSE;
|
||||
|
||||
/*
|
||||
* -4 and -6
|
||||
@@ -389,14 +390,20 @@ parse_int(char *arg, const char *desc) {
|
||||
static struct flag_def {
|
||||
const char *name;
|
||||
unsigned int value;
|
||||
isc_boolean_t negate;
|
||||
} mem_debug_flags[] = {
|
||||
{ "none", 0},
|
||||
{ "trace", ISC_MEM_DEBUGTRACE },
|
||||
{ "record", ISC_MEM_DEBUGRECORD },
|
||||
{ "usage", ISC_MEM_DEBUGUSAGE },
|
||||
{ "size", ISC_MEM_DEBUGSIZE },
|
||||
{ "mctx", ISC_MEM_DEBUGCTX },
|
||||
{ NULL, 0 }
|
||||
{ "none", 0, ISC_FALSE },
|
||||
{ "trace", ISC_MEM_DEBUGTRACE, ISC_FALSE },
|
||||
{ "record", ISC_MEM_DEBUGRECORD, ISC_FALSE },
|
||||
{ "usage", ISC_MEM_DEBUGUSAGE, ISC_FALSE },
|
||||
{ "size", ISC_MEM_DEBUGSIZE, ISC_FALSE },
|
||||
{ "mctx", ISC_MEM_DEBUGCTX, ISC_FALSE },
|
||||
{ NULL, 0, ISC_FALSE }
|
||||
}, mem_context_flags[] = {
|
||||
{ "external", ISC_MEMFLAG_INTERNAL, ISC_TRUE },
|
||||
{ "fill", ISC_MEMFLAG_FILL, ISC_FALSE },
|
||||
{ "nofill", ISC_MEMFLAG_FILL, ISC_TRUE },
|
||||
{ NULL, 0, ISC_FALSE }
|
||||
};
|
||||
|
||||
static void
|
||||
@@ -415,7 +422,10 @@ set_flags(const char *arg, struct flag_def *defs, unsigned int *ret) {
|
||||
memcmp(arg, def->name, arglen) == 0) {
|
||||
if (def->value == 0)
|
||||
clear = ISC_TRUE;
|
||||
*ret |= def->value;
|
||||
if (def->negate)
|
||||
*ret &= ~(def->value);
|
||||
else
|
||||
*ret |= def->value;
|
||||
goto found;
|
||||
}
|
||||
}
|
||||
@@ -518,8 +528,8 @@ parse_command_line(int argc, char *argv[]) {
|
||||
named_g_logfile = isc_commandline_argument;
|
||||
break;
|
||||
case 'M':
|
||||
if (strcmp(isc_commandline_argument, "external") == 0)
|
||||
isc_mem_defaultflags = 0;
|
||||
set_flags(isc_commandline_argument, mem_context_flags,
|
||||
&isc_mem_defaultflags);
|
||||
break;
|
||||
case 'm':
|
||||
set_flags(isc_commandline_argument, mem_debug_flags,
|
||||
@@ -626,14 +636,21 @@ parse_command_line(int argc, char *argv[]) {
|
||||
} else if (!strcmp(isc_commandline_argument, "notcp"))
|
||||
notcp = ISC_TRUE;
|
||||
else if (!strncmp(isc_commandline_argument, "tat=", 4))
|
||||
{
|
||||
named_g_tat_interval =
|
||||
atoi(isc_commandline_argument + 4);
|
||||
else if (!strcmp(isc_commandline_argument,
|
||||
} else if (!strcmp(isc_commandline_argument,
|
||||
"keepstderr"))
|
||||
{
|
||||
named_g_keepstderr = ISC_TRUE;
|
||||
else
|
||||
} else if (!strcmp(isc_commandline_argument,
|
||||
"fixedlocal"))
|
||||
{
|
||||
fixedlocal = ISC_TRUE;
|
||||
} else {
|
||||
fprintf(stderr, "unknown -T flag '%s\n",
|
||||
isc_commandline_argument);
|
||||
}
|
||||
break;
|
||||
case 'U':
|
||||
named_g_udpdisp = parse_int(isc_commandline_argument,
|
||||
@@ -1193,6 +1210,8 @@ setup(void) {
|
||||
ns_server_setoption(sctx, NS_SERVER_NONEAREST, ISC_TRUE);
|
||||
if (notcp)
|
||||
ns_server_setoption(sctx, NS_SERVER_NOTCP, ISC_TRUE);
|
||||
if (fixedlocal)
|
||||
ns_server_setoption(sctx, NS_SERVER_FIXEDLOCAL, ISC_TRUE);
|
||||
if (disable4)
|
||||
ns_server_setoption(sctx, NS_SERVER_DISABLE4, ISC_TRUE);
|
||||
if (disable6)
|
||||
@@ -1258,11 +1277,11 @@ named_main_setmemstats(const char *filename) {
|
||||
free(memstats);
|
||||
memstats = NULL;
|
||||
}
|
||||
|
||||
if (filename == NULL)
|
||||
return;
|
||||
memstats = malloc(strlen(filename) + 1);
|
||||
if (memstats)
|
||||
strcpy(memstats, filename);
|
||||
|
||||
memstats = strdup(filename);
|
||||
}
|
||||
|
||||
#ifdef HAVE_LIBSCF
|
||||
@@ -1372,6 +1391,15 @@ main(int argc, char *argv[]) {
|
||||
pk11_result_register();
|
||||
#endif
|
||||
|
||||
#if !ISC_MEM_DEFAULTFILL
|
||||
/*
|
||||
* Update the default flags to remove ISC_MEMFLAG_FILL
|
||||
* before we parse the command line. If disabled here,
|
||||
* it can be turned back on with -M fill.
|
||||
*/
|
||||
isc_mem_defaultflags &= ~ISC_MEMFLAG_FILL;
|
||||
#endif
|
||||
|
||||
parse_command_line(argc, argv);
|
||||
|
||||
#ifdef ENABLE_AFL
|
||||
|
||||
+6
-2
@@ -125,8 +125,12 @@ by default instead of the system log\&.
|
||||
.PP
|
||||
\-M \fIoption\fR
|
||||
.RS 4
|
||||
Sets the default memory context options\&. Currently the only supported option is
|
||||
\fIexternal\fR, which causes the internal memory manager to be bypassed in favor of system\-provided memory allocation functions\&.
|
||||
Sets the default memory context options\&. If set to
|
||||
\fIexternal\fR, this causes the internal memory manager to be bypassed in favor of system\-provided memory allocation functions\&. If set to
|
||||
\fIfill\fR, blocks of memory will be filled with tag values when allocated or freed, to assist debugging of memory problems\&. (\fInofill\fR
|
||||
disables this behavior, and is the default unless
|
||||
\fBnamed\fR
|
||||
has been compiled with developer options\&.)
|
||||
.RE
|
||||
.PP
|
||||
\-m \fIflag\fR
|
||||
|
||||
@@ -212,11 +212,17 @@
|
||||
<term>-M <replaceable class="parameter">option</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the default memory context options. Currently
|
||||
the only supported option is
|
||||
Sets the default memory context options. If set to
|
||||
<replaceable class="parameter">external</replaceable>,
|
||||
which causes the internal memory manager to be bypassed
|
||||
this causes the internal memory manager to be bypassed
|
||||
in favor of system-provided memory allocation functions.
|
||||
If set to <replaceable class="parameter">fill</replaceable>,
|
||||
blocks of memory will be filled with tag values when allocated
|
||||
or freed, to assist debugging of memory problems.
|
||||
(<replaceable class="parameter">nofill</replaceable>
|
||||
disables this behavior, and is the default unless
|
||||
<command>named</command> has been compiled with developer
|
||||
options.)
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -168,11 +168,17 @@
|
||||
<dt><span class="term">-M <em class="replaceable"><code>option</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the default memory context options. Currently
|
||||
the only supported option is
|
||||
Sets the default memory context options. If set to
|
||||
<em class="replaceable"><code>external</code></em>,
|
||||
which causes the internal memory manager to be bypassed
|
||||
this causes the internal memory manager to be bypassed
|
||||
in favor of system-provided memory allocation functions.
|
||||
If set to <em class="replaceable"><code>fill</code></em>,
|
||||
blocks of memory will be filled with tag values when allocated
|
||||
or freed, to assist debugging of memory problems.
|
||||
(<em class="replaceable"><code>nofill</code></em>
|
||||
disables this behavior, and is the default unless
|
||||
<span class="command"><strong>named</strong></span> has been compiled with developer
|
||||
options.)
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
|
||||
|
||||
+479
-233
File diff suppressed because it is too large
Load Diff
+205
-73
@@ -126,6 +126,7 @@ static const char *udpoutsizestats_desc[dns_sizecounter_out_max];
|
||||
static const char *tcpinsizestats_desc[dns_sizecounter_in_max];
|
||||
static const char *tcpoutsizestats_desc[dns_sizecounter_out_max];
|
||||
static const char *dnstapstats_desc[dns_dnstapcounter_max];
|
||||
static const char *gluecachestats_desc[dns_gluecachestatscounter_max];
|
||||
#if defined(EXTENDED_STATS)
|
||||
static const char *nsstats_xmldesc[ns_statscounter_max];
|
||||
static const char *resstats_xmldesc[dns_resstatscounter_max];
|
||||
@@ -138,6 +139,7 @@ static const char *udpoutsizestats_xmldesc[dns_sizecounter_out_max];
|
||||
static const char *tcpinsizestats_xmldesc[dns_sizecounter_in_max];
|
||||
static const char *tcpoutsizestats_xmldesc[dns_sizecounter_out_max];
|
||||
static const char *dnstapstats_xmldesc[dns_dnstapcounter_max];
|
||||
static const char *gluecachestats_xmldesc[dns_gluecachestatscounter_max];
|
||||
#else
|
||||
#define nsstats_xmldesc NULL
|
||||
#define resstats_xmldesc NULL
|
||||
@@ -150,6 +152,7 @@ static const char *dnstapstats_xmldesc[dns_dnstapcounter_max];
|
||||
#define tcpinsizestats_xmldesc NULL
|
||||
#define tcpoutsizestats_xmldesc NULL
|
||||
#define dnstapstats_xmldesc NULL
|
||||
#define gluecachestats_xmldesc NULL
|
||||
#endif /* EXTENDED_STATS */
|
||||
|
||||
#define TRY0(a) do { xmlrc = (a); if (xmlrc < 0) goto error; } while(0)
|
||||
@@ -170,6 +173,7 @@ static int udpoutsizestats_index[dns_sizecounter_out_max];
|
||||
static int tcpinsizestats_index[dns_sizecounter_in_max];
|
||||
static int tcpoutsizestats_index[dns_sizecounter_out_max];
|
||||
static int dnstapstats_index[dns_dnstapcounter_max];
|
||||
static int gluecachestats_index[dns_gluecachestatscounter_max];
|
||||
|
||||
static inline void
|
||||
set_desc(int counter, int maxcounter, const char *fdesc, const char **fdescs,
|
||||
@@ -301,6 +305,8 @@ init_desc(void) {
|
||||
SET_NSSTATDESC(usedstale,
|
||||
"successful uses of stale cache data after lookup failure",
|
||||
"QryUsedStale");
|
||||
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
|
||||
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
|
||||
INSIST(i == ns_statscounter_max);
|
||||
|
||||
/* Initialize resolver statistics */
|
||||
@@ -610,9 +616,33 @@ init_desc(void) {
|
||||
} while (0)
|
||||
i = 0;
|
||||
SET_DNSTAPSTATDESC(success, "dnstap messges written", "DNSTAPsuccess");
|
||||
SET_DNSTAPSTATDESC(drop, "dnstap messages dropped", "DNSSECdropped");
|
||||
SET_DNSTAPSTATDESC(drop, "dnstap messages dropped", "DNSTAPdropped");
|
||||
INSIST(i == dns_dnstapcounter_max);
|
||||
|
||||
#define SET_GLUECACHESTATDESC(counterid, desc, xmldesc) \
|
||||
do { \
|
||||
set_desc(dns_gluecachestatscounter_ ## counterid, \
|
||||
dns_gluecachestatscounter_max, \
|
||||
desc, gluecachestats_desc, \
|
||||
xmldesc, gluecachestats_xmldesc); \
|
||||
gluecachestats_index[i++] = \
|
||||
dns_gluecachestatscounter_ ## counterid; \
|
||||
} while (0)
|
||||
i = 0;
|
||||
SET_GLUECACHESTATDESC(hits_present,
|
||||
"Hits for present glue (cached)",
|
||||
"GLUECACHEhitspresent");
|
||||
SET_GLUECACHESTATDESC(hits_absent,
|
||||
"Hits for non-existent glue (cached)",
|
||||
"GLUECACHEhitsabsent");
|
||||
SET_GLUECACHESTATDESC(inserts_present,
|
||||
"Miss-plus-cache-inserts for present glue",
|
||||
"GLUECACHEinsertspresent");
|
||||
SET_GLUECACHESTATDESC(inserts_absent,
|
||||
"Miss-plus-cache-inserts for non-existent glue",
|
||||
"GLUECACHEinsertsabsent");
|
||||
INSIST(i == dns_gluecachestatscounter_max);
|
||||
|
||||
/* Sanity check */
|
||||
for (i = 0; i < ns_statscounter_max; i++)
|
||||
INSIST(nsstats_desc[i] != NULL);
|
||||
@@ -628,6 +658,8 @@ init_desc(void) {
|
||||
INSIST(dnssecstats_desc[i] != NULL);
|
||||
for (i = 0; i < dns_dnstapcounter_max; i++)
|
||||
INSIST(dnstapstats_desc[i] != NULL);
|
||||
for (i = 0; i < dns_gluecachestatscounter_max; i++)
|
||||
INSIST(gluecachestats_desc[i] != NULL);
|
||||
#if defined(EXTENDED_STATS)
|
||||
for (i = 0; i < ns_statscounter_max; i++)
|
||||
INSIST(nsstats_xmldesc[i] != NULL);
|
||||
@@ -643,6 +675,8 @@ init_desc(void) {
|
||||
INSIST(dnssecstats_xmldesc[i] != NULL);
|
||||
for (i = 0; i < dns_dnstapcounter_max; i++)
|
||||
INSIST(dnstapstats_xmldesc[i] != NULL);
|
||||
for (i = 0; i < dns_gluecachestatscounter_max; i++)
|
||||
INSIST(gluecachestats_xmldesc[i] != NULL);
|
||||
#endif
|
||||
|
||||
/* Initialize traffic size statistics */
|
||||
@@ -1269,8 +1303,8 @@ rdatasetstats_dump(dns_rdatastatstype_t type, isc_uint64_t val, void *arg) {
|
||||
case isc_statsformat_json:
|
||||
#ifdef HAVE_JSON
|
||||
zoneobj = (json_object *) dumparg->arg;
|
||||
sprintf(buf, "%s%s%s", stale ? "#" : "",
|
||||
nxrrset ? "!" : "", typestr);
|
||||
snprintf(buf, sizeof(buf), "%s%s%s",
|
||||
stale ? "#" : "", nxrrset ? "!" : "", typestr);
|
||||
obj = json_object_new_int64(val);
|
||||
if (obj == NULL)
|
||||
return;
|
||||
@@ -1423,10 +1457,7 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
dns_rdataclass_t rdclass;
|
||||
isc_uint32_t serial;
|
||||
xmlTextWriterPtr writer = arg;
|
||||
isc_stats_t *zonestats;
|
||||
dns_stats_t *rcvquerystats;
|
||||
dns_zonestat_level_t statlevel;
|
||||
isc_uint64_t nsstat_values[ns_statscounter_max];
|
||||
int xmlrc;
|
||||
stats_dumparg_t dumparg;
|
||||
const char *ztype;
|
||||
@@ -1464,36 +1495,71 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* serial */
|
||||
|
||||
zonestats = dns_zone_getrequeststats(zone);
|
||||
rcvquerystats = dns_zone_getrcvquerystats(zone);
|
||||
if (statlevel == dns_zonestat_full && zonestats != NULL) {
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "rcode"));
|
||||
if (statlevel == dns_zonestat_full) {
|
||||
isc_stats_t *zonestats;
|
||||
isc_stats_t *gluecachestats;
|
||||
dns_stats_t *rcvquerystats;
|
||||
isc_uint64_t nsstat_values[ns_statscounter_max];
|
||||
isc_uint64_t gluecachestats_values[dns_gluecachestatscounter_max];
|
||||
|
||||
result = dump_counters(zonestats, isc_statsformat_xml, writer,
|
||||
NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max, nsstats_index,
|
||||
nsstat_values, ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
/* counters type="rcode"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
zonestats = dns_zone_getrequeststats(zone);
|
||||
if (zonestats != NULL) {
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer,
|
||||
ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "rcode"));
|
||||
|
||||
if (statlevel == dns_zonestat_full && rcvquerystats != NULL) {
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "qtype"));
|
||||
result = dump_counters(zonestats, isc_statsformat_xml,
|
||||
writer, NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
/* counters type="rcode"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
if(dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
gluecachestats = dns_zone_getgluecachestats(zone);
|
||||
if (gluecachestats != NULL) {
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer,
|
||||
ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "gluecache"));
|
||||
|
||||
/* counters type="qtype"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
result = dump_counters(gluecachestats,
|
||||
isc_statsformat_xml,
|
||||
writer, NULL,
|
||||
gluecachestats_xmldesc,
|
||||
dns_gluecachestatscounter_max,
|
||||
gluecachestats_index,
|
||||
gluecachestats_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
/* counters type="rcode"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
|
||||
rcvquerystats = dns_zone_getrcvquerystats(zone);
|
||||
if (rcvquerystats != NULL) {
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR "counters"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer,
|
||||
ISC_XMLCHAR "type",
|
||||
ISC_XMLCHAR "qtype"));
|
||||
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
if(dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
|
||||
/* counters type="qtype"*/
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
}
|
||||
}
|
||||
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* zone */
|
||||
@@ -1548,7 +1614,7 @@ generatexml(named_server_t *server, isc_uint32_t flags,
|
||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "statistics"));
|
||||
TRY0(xmlTextWriterWriteAttribute(writer, ISC_XMLCHAR "version",
|
||||
ISC_XMLCHAR "3.9"));
|
||||
ISC_XMLCHAR "3.10"));
|
||||
|
||||
/* Set common fields for statistics dump */
|
||||
dumparg.type = isc_statsformat_xml;
|
||||
@@ -2185,9 +2251,6 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
char *class_only = NULL;
|
||||
dns_rdataclass_t rdclass;
|
||||
isc_uint32_t serial;
|
||||
isc_uint64_t nsstat_values[ns_statscounter_max];
|
||||
isc_stats_t *zonestats;
|
||||
dns_stats_t *rcvquerystats;
|
||||
json_object *zonearray = (json_object *) arg;
|
||||
json_object *zoneobj = NULL;
|
||||
dns_zonestat_level_t statlevel;
|
||||
@@ -2213,49 +2276,87 @@ zone_jsonrender(dns_zone_t *zone, void *arg) {
|
||||
if (zoneobj == NULL)
|
||||
return (ISC_R_NOMEMORY);
|
||||
|
||||
zonestats = dns_zone_getrequeststats(zone);
|
||||
rcvquerystats = dns_zone_getrcvquerystats(zone);
|
||||
if (statlevel == dns_zonestat_full && zonestats != NULL) {
|
||||
json_object *counters = json_object_new_object();
|
||||
if (counters == NULL) {
|
||||
result = ISC_R_NOMEMORY;
|
||||
goto error;
|
||||
if (statlevel == dns_zonestat_full) {
|
||||
isc_stats_t *zonestats;
|
||||
isc_stats_t *gluecachestats;
|
||||
dns_stats_t *rcvquerystats;
|
||||
isc_uint64_t nsstat_values[ns_statscounter_max];
|
||||
isc_uint64_t gluecachestats_values[dns_gluecachestatscounter_max];
|
||||
|
||||
zonestats = dns_zone_getrequeststats(zone);
|
||||
if (zonestats != NULL) {
|
||||
json_object *counters = json_object_new_object();
|
||||
if (counters == NULL) {
|
||||
result = ISC_R_NOMEMORY;
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = dump_counters(zonestats, isc_statsformat_json,
|
||||
counters, NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max,
|
||||
nsstats_index,
|
||||
nsstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0)
|
||||
json_object_object_add(zoneobj,
|
||||
"rcodes", counters);
|
||||
else
|
||||
json_object_put(counters);
|
||||
}
|
||||
|
||||
result = dump_counters(zonestats, isc_statsformat_json,
|
||||
counters, NULL, nsstats_xmldesc,
|
||||
ns_statscounter_max, nsstats_index,
|
||||
nsstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
gluecachestats = dns_zone_getgluecachestats(zone);
|
||||
if (gluecachestats != NULL) {
|
||||
json_object *counters = json_object_new_object();
|
||||
if (counters == NULL) {
|
||||
result = ISC_R_NOMEMORY;
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = dump_counters(gluecachestats,
|
||||
isc_statsformat_json,
|
||||
counters, NULL,
|
||||
gluecachestats_xmldesc,
|
||||
dns_gluecachestatscounter_max,
|
||||
gluecachestats_index,
|
||||
gluecachestats_values, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0)
|
||||
json_object_object_add(zoneobj,
|
||||
"gluecache", counters);
|
||||
else
|
||||
json_object_put(counters);
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0)
|
||||
json_object_object_add(zoneobj, "rcodes", counters);
|
||||
else
|
||||
json_object_put(counters);
|
||||
}
|
||||
rcvquerystats = dns_zone_getrcvquerystats(zone);
|
||||
if (rcvquerystats != NULL) {
|
||||
stats_dumparg_t dumparg;
|
||||
json_object *counters = json_object_new_object();
|
||||
CHECKMEM(counters);
|
||||
|
||||
if (statlevel == dns_zonestat_full && rcvquerystats != NULL) {
|
||||
stats_dumparg_t dumparg;
|
||||
json_object *counters = json_object_new_object();
|
||||
CHECKMEM(counters);
|
||||
dumparg.type = isc_statsformat_json;
|
||||
dumparg.arg = counters;
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
}
|
||||
|
||||
dumparg.type = isc_statsformat_json;
|
||||
dumparg.arg = counters;
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS) {
|
||||
json_object_put(counters);
|
||||
goto error;
|
||||
if (json_object_get_object(counters)->count != 0)
|
||||
json_object_object_add(zoneobj,
|
||||
"qtypes", counters);
|
||||
else
|
||||
json_object_put(counters);
|
||||
}
|
||||
|
||||
if (json_object_get_object(counters)->count != 0)
|
||||
json_object_object_add(zoneobj, "qtypes", counters);
|
||||
else
|
||||
json_object_put(counters);
|
||||
}
|
||||
|
||||
json_object_array_add(zonearray, zoneobj);
|
||||
@@ -2309,7 +2410,7 @@ generatejson(named_server_t *server, size_t *msglen,
|
||||
/*
|
||||
* These statistics are included no matter which URL we use.
|
||||
*/
|
||||
obj = json_object_new_string("1.3");
|
||||
obj = json_object_new_string("1.4");
|
||||
CHECKMEM(obj);
|
||||
json_object_object_add(bindstats, "json-stats-version", obj);
|
||||
|
||||
@@ -3446,6 +3547,7 @@ named_stats_dump(named_server_t *server, FILE *fp) {
|
||||
isc_uint64_t adbstat_values[dns_adbstats_max];
|
||||
isc_uint64_t zonestat_values[dns_zonestatscounter_max];
|
||||
isc_uint64_t sockstat_values[isc_sockstatscounter_max];
|
||||
isc_uint64_t gluecachestats_values[dns_gluecachestatscounter_max];
|
||||
|
||||
RUNTIME_CHECK(isc_once_do(&once, init_desc) == ISC_R_SUCCESS);
|
||||
|
||||
@@ -3603,6 +3705,36 @@ named_stats_dump(named_server_t *server, FILE *fp) {
|
||||
}
|
||||
}
|
||||
|
||||
fprintf(fp, "++ Per Zone Glue Cache Statistics ++\n");
|
||||
zone = NULL;
|
||||
for (result = dns_zone_first(server->zonemgr, &zone);
|
||||
result == ISC_R_SUCCESS;
|
||||
next = NULL, result = dns_zone_next(zone, &next), zone = next)
|
||||
{
|
||||
isc_stats_t *gluecachestats = dns_zone_getgluecachestats(zone);
|
||||
if (gluecachestats != NULL) {
|
||||
char zonename[DNS_NAME_FORMATSIZE];
|
||||
|
||||
view = dns_zone_getview(zone);
|
||||
if (view == NULL)
|
||||
continue;
|
||||
|
||||
dns_name_format(dns_zone_getorigin(zone),
|
||||
zonename, sizeof(zonename));
|
||||
fprintf(fp, "[%s", zonename);
|
||||
if (strcmp(view->name, "_default") != 0)
|
||||
fprintf(fp, " (view: %s)", view->name);
|
||||
fprintf(fp, "]\n");
|
||||
|
||||
(void) dump_counters(gluecachestats,
|
||||
isc_statsformat_file,
|
||||
fp, NULL, gluecachestats_desc,
|
||||
dns_gluecachestatscounter_max,
|
||||
gluecachestats_index,
|
||||
gluecachestats_values, 0);
|
||||
}
|
||||
}
|
||||
|
||||
fprintf(fp, "--- Statistics Dump --- (%lu)\n", (unsigned long)now);
|
||||
|
||||
return (ISC_R_SUCCESS); /* this function currently always succeeds */
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2011-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2011-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -476,7 +476,7 @@ dlopen_dlz_configure(dns_view_t *view, dns_dlzdb_t *dlzdb,
|
||||
|
||||
|
||||
/*
|
||||
* Check for authority to change a name
|
||||
* Check for authority to change a name.
|
||||
*/
|
||||
static isc_boolean_t
|
||||
dlopen_dlz_ssumatch(const char *signer, const char *name, const char *tcpaddr,
|
||||
@@ -501,7 +501,7 @@ dlopen_dlz_ssumatch(const char *signer, const char *name, const char *tcpaddr,
|
||||
|
||||
|
||||
/*
|
||||
* Add an rdataset
|
||||
* Add an rdataset.
|
||||
*/
|
||||
static isc_result_t
|
||||
dlopen_dlz_addrdataset(const char *name, const char *rdatastr,
|
||||
@@ -523,7 +523,7 @@ dlopen_dlz_addrdataset(const char *name, const char *rdatastr,
|
||||
}
|
||||
|
||||
/*
|
||||
* Subtract an rdataset
|
||||
* Subtract an rdataset.
|
||||
*/
|
||||
static isc_result_t
|
||||
dlopen_dlz_subrdataset(const char *name, const char *rdatastr,
|
||||
@@ -545,7 +545,7 @@ dlopen_dlz_subrdataset(const char *name, const char *rdatastr,
|
||||
}
|
||||
|
||||
/*
|
||||
delete a rdataset
|
||||
* Delete a rdataset.
|
||||
*/
|
||||
static isc_result_t
|
||||
dlopen_dlz_delrdataset(const char *name, const char *type,
|
||||
|
||||
+3
-9
@@ -1013,7 +1013,6 @@ next_token(char **stringp, const char *delim) {
|
||||
void
|
||||
named_os_shutdownmsg(char *command, isc_buffer_t *text) {
|
||||
char *input, *ptr;
|
||||
unsigned int n;
|
||||
pid_t pid;
|
||||
|
||||
input = command;
|
||||
@@ -1036,12 +1035,7 @@ named_os_shutdownmsg(char *command, isc_buffer_t *text) {
|
||||
pid = getpid();
|
||||
#endif
|
||||
|
||||
n = snprintf((char *)isc_buffer_used(text),
|
||||
isc_buffer_availablelength(text),
|
||||
"pid: %ld", (long)pid);
|
||||
/* Only send a message if it is complete. */
|
||||
if (n > 0 && n < isc_buffer_availablelength(text))
|
||||
isc_buffer_add(text, n);
|
||||
(void)isc_buffer_printf(text, "pid: %ld", (long)pid);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -1061,7 +1055,7 @@ getuname(void) {
|
||||
|
||||
memset(&uts, 0, sizeof(uts));
|
||||
if (uname(&uts) < 0) {
|
||||
strcpy(unamebuf, "unknown architecture");
|
||||
snprintf(unamebuf, sizeof(unamebuf), "unknown architecture");
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -1069,7 +1063,7 @@ getuname(void) {
|
||||
"%s %s %s %s",
|
||||
uts.sysname, uts.machine, uts.release, uts.version);
|
||||
#else
|
||||
strcpy(unamebuf, "unknown architecture");
|
||||
snprintf(unamebuf, sizeof(unamebuf), "unknown architecture");
|
||||
#endif
|
||||
unamep = unamebuf;
|
||||
}
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
#include <isc/commandline.h>
|
||||
#include <isc/log.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/string.h>
|
||||
|
||||
#include <named/globals.h>
|
||||
#include <named/ntservice.h>
|
||||
@@ -49,8 +50,8 @@ ntservice_init(void) {
|
||||
}
|
||||
UpdateSCM(SERVICE_RUNNING);
|
||||
} else {
|
||||
strcpy(ConsoleTitle, "BIND Version ");
|
||||
strcat(ConsoleTitle, VERSION);
|
||||
strlcpy(ConsoleTitle, "BIND Version ", sizeof(ConsoleTitle));
|
||||
strlcat(ConsoleTitle, VERSION, sizeof(ConsoleTitle));
|
||||
SetConsoleTitle(ConsoleTitle);
|
||||
}
|
||||
}
|
||||
|
||||
+16
-16
@@ -218,7 +218,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
||||
const char *str;
|
||||
isc_boolean_t grant = ISC_FALSE;
|
||||
isc_boolean_t usezone = ISC_FALSE;
|
||||
unsigned int mtype = DNS_SSUMATCHTYPE_NAME;
|
||||
unsigned int mtype = dns_ssumatchtype_name;
|
||||
dns_fixedname_t fname, fident;
|
||||
isc_buffer_t b;
|
||||
dns_rdatatype_t *types;
|
||||
@@ -234,34 +234,34 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
||||
|
||||
str = cfg_obj_asstring(matchtype);
|
||||
if (strcasecmp(str, "name") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_NAME;
|
||||
mtype = dns_ssumatchtype_name;
|
||||
else if (strcasecmp(str, "subdomain") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAIN;
|
||||
mtype = dns_ssumatchtype_subdomain;
|
||||
else if (strcasecmp(str, "wildcard") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_WILDCARD;
|
||||
mtype = dns_ssumatchtype_wildcard;
|
||||
else if (strcasecmp(str, "self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SELF;
|
||||
mtype = dns_ssumatchtype_self;
|
||||
else if (strcasecmp(str, "selfsub") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SELFSUB;
|
||||
mtype = dns_ssumatchtype_selfsub;
|
||||
else if (strcasecmp(str, "selfwild") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SELFWILD;
|
||||
mtype = dns_ssumatchtype_selfwild;
|
||||
else if (strcasecmp(str, "ms-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SELFMS;
|
||||
mtype = dns_ssumatchtype_selfms;
|
||||
else if (strcasecmp(str, "krb5-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SELFKRB5;
|
||||
mtype = dns_ssumatchtype_selfkrb5;
|
||||
else if (strcasecmp(str, "ms-subdomain") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAINMS;
|
||||
mtype = dns_ssumatchtype_subdomainms;
|
||||
else if (strcasecmp(str, "krb5-subdomain") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAINKRB5;
|
||||
mtype = dns_ssumatchtype_subdomainkrb5;
|
||||
else if (strcasecmp(str, "tcp-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_TCPSELF;
|
||||
mtype = dns_ssumatchtype_tcpself;
|
||||
else if (strcasecmp(str, "6to4-self") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_6TO4SELF;
|
||||
mtype = dns_ssumatchtype_6to4self;
|
||||
else if (strcasecmp(str, "zonesub") == 0) {
|
||||
mtype = DNS_SSUMATCHTYPE_SUBDOMAIN;
|
||||
mtype = dns_ssumatchtype_subdomain;
|
||||
usezone = ISC_TRUE;
|
||||
} else if (strcasecmp(str, "external") == 0)
|
||||
mtype = DNS_SSUMATCHTYPE_EXTERNAL;
|
||||
mtype = dns_ssumatchtype_external;
|
||||
else
|
||||
INSIST(0);
|
||||
|
||||
@@ -373,7 +373,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
||||
|
||||
result = dns_ssutable_addrule(table, ISC_TRUE,
|
||||
named_g_server->session_keyname,
|
||||
DNS_SSUMATCHTYPE_SUBDOMAIN,
|
||||
dns_ssumatchtype_local,
|
||||
dns_zone_getorigin(zone),
|
||||
1, &any);
|
||||
|
||||
|
||||
+26
-17
@@ -29,6 +29,7 @@
|
||||
#include <isc/mem.h>
|
||||
#include <isc/parseint.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/platform.h>
|
||||
#include <isc/random.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/sockaddr.h>
|
||||
@@ -261,7 +262,8 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
||||
if (*ectx == NULL) {
|
||||
result = isc_entropy_create(mctx, ectx);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("could not create entropy object");
|
||||
fatal("could not create entropy object: %s",
|
||||
isc_result_totext(result));
|
||||
ISC_LIST_INIT(sources);
|
||||
}
|
||||
|
||||
@@ -270,6 +272,11 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
||||
randomfile = NULL;
|
||||
}
|
||||
|
||||
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||
if (randomfile == NULL) {
|
||||
isc_entropy_usehook(*ectx, ISC_TRUE);
|
||||
}
|
||||
#endif
|
||||
result = isc_entropy_usebestsource(*ectx, &source, randomfile,
|
||||
usekeyboard);
|
||||
|
||||
@@ -453,8 +460,8 @@ parse_hmac(const dns_name_t **hmac, const char *hmacstr, size_t len,
|
||||
return (ISC_FALSE);
|
||||
}
|
||||
|
||||
strncpy(buf, hmacstr, len);
|
||||
buf[len] = 0;
|
||||
/* Copy len bytes and NUL terminate. */
|
||||
strlcpy(buf, hmacstr, ISC_MIN(len + 1, sizeof(buf)));
|
||||
|
||||
#ifndef PK11_MD5_DISABLE
|
||||
if (strcasecmp(buf, "hmac-md5") == 0) {
|
||||
@@ -894,14 +901,14 @@ setup_system(void) {
|
||||
}
|
||||
} else {
|
||||
isc_sockaddr_t *sa;
|
||||
int i = 0;
|
||||
int i;
|
||||
|
||||
/*
|
||||
* Count the nameservers (skipping any that we can't use
|
||||
* because of address family restrictions) and allocate
|
||||
* the servers array.
|
||||
*/
|
||||
ns_total = ns_alloc = 0;
|
||||
ns_total = 0;
|
||||
for (sa = ISC_LIST_HEAD(*nslist);
|
||||
sa != NULL;
|
||||
sa = ISC_LIST_NEXT(sa, link))
|
||||
@@ -910,13 +917,11 @@ setup_system(void) {
|
||||
case AF_INET:
|
||||
if (have_ipv4) {
|
||||
ns_total++;
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
case AF_INET6:
|
||||
if (have_ipv6) {
|
||||
ns_total++;
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
@@ -929,22 +934,21 @@ setup_system(void) {
|
||||
if (servers == NULL)
|
||||
fatal("out of memory");
|
||||
|
||||
i = 0;
|
||||
for (sa = ISC_LIST_HEAD(*nslist);
|
||||
sa != NULL;
|
||||
sa = ISC_LIST_NEXT(sa, link))
|
||||
{
|
||||
switch (sa->type.sa.sa_family) {
|
||||
case AF_INET:
|
||||
if (!have_ipv4) {
|
||||
continue;
|
||||
if (have_ipv4) {
|
||||
sa->type.sin.sin_port = htons(dnsport);
|
||||
}
|
||||
sa->type.sin.sin_port = htons(dnsport);
|
||||
break;
|
||||
case AF_INET6:
|
||||
if (!have_ipv6) {
|
||||
continue;
|
||||
if (have_ipv6) {
|
||||
sa->type.sin6.sin6_port = htons(dnsport);
|
||||
}
|
||||
sa->type.sin6.sin6_port = htons(dnsport);
|
||||
break;
|
||||
default:
|
||||
fatal("bad family");
|
||||
@@ -955,11 +959,11 @@ setup_system(void) {
|
||||
|
||||
irs_resconf_destroy(&resconf);
|
||||
|
||||
setup_entropy(gmctx, NULL, &entropy);
|
||||
if (entropy == NULL)
|
||||
setup_entropy(gmctx, NULL, &entropy);
|
||||
|
||||
result = isc_hash_create(gmctx, entropy, DNS_NAME_MAXWIRE);
|
||||
check_result(result, "isc_hash_create");
|
||||
isc_hash_init();
|
||||
|
||||
result = dns_dispatchmgr_create(gmctx, entropy, &dispatchmgr);
|
||||
check_result(result, "dns_dispatchmgr_create");
|
||||
@@ -983,6 +987,9 @@ setup_system(void) {
|
||||
check_result(result, "dst_lib_init");
|
||||
is_dst_up = ISC_TRUE;
|
||||
|
||||
/* moved after dst_lib_init() */
|
||||
isc_hash_init();
|
||||
|
||||
attrmask = DNS_DISPATCHATTR_UDP | DNS_DISPATCHATTR_TCP;
|
||||
attrmask |= DNS_DISPATCHATTR_IPV4 | DNS_DISPATCHATTR_IPV6;
|
||||
|
||||
@@ -2371,8 +2378,10 @@ update_completed(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
|
||||
if (reqev->result != ISC_R_SUCCESS) {
|
||||
if (!next_master("recvsoa", &master_servers[master_inuse],
|
||||
reqev->result)) {
|
||||
if (!next_master("update_completed",
|
||||
&master_servers[master_inuse],
|
||||
reqev->result))
|
||||
{
|
||||
seenerror = ISC_TRUE;
|
||||
goto done;
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -57,8 +57,7 @@ is specified, then the zone is read from that file to find the DNSKEY records\&.
|
||||
.PP
|
||||
\-l \fIdomain\fR
|
||||
.RS 4
|
||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&. For example, to check for DLV records for "example\&.com" in ISC\*(Aqs DLV zone, use:
|
||||
\fBdnssec\-checkds \-l dlv\&.isc\&.org example\&.com\fR
|
||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone\*(Aqs parent\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIdig path\fR
|
||||
@@ -84,5 +83,5 @@ binary\&. Used for testing\&.
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -34,6 +34,7 @@
|
||||
<year>2014</year>
|
||||
<year>2015</year>
|
||||
<year>2016</year>
|
||||
<year>2017</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -87,9 +88,6 @@
|
||||
<para>
|
||||
Check for a DLV record in the specified lookaside domain,
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
For example, to check for DLV records for "example.com"
|
||||
in ISC's DLV zone, use:
|
||||
<command>dnssec-checkds -l dlv.isc.org example.com</command>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -77,9 +77,6 @@
|
||||
<p>
|
||||
Check for a DLV record in the specified lookaside domain,
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
For example, to check for DLV records for "example.com"
|
||||
in ISC's DLV zone, use:
|
||||
<span class="command"><strong>dnssec-checkds -l dlv.isc.org example.com</strong></span>
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||
|
||||
+65
-3
@@ -282,11 +282,73 @@ zone option be set to
|
||||
maintain, and also requires the zone to be configured to allow dynamic DNS\&. (See "Dynamic Update Policies" in the Administrator Reference Manual for more details\&.)
|
||||
.RE
|
||||
.PP
|
||||
\fBmanaged\-keys \fR\fB\fI(status | refresh | sync)\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR
|
||||
\fBmanaged\-keys \fR\fB\fI(status | refresh | sync | destroy)\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR
|
||||
.RS 4
|
||||
When run with the "status" keyword, print the current status of the managed\-keys database for the specified view, or for all views if none is specified\&. When run with the "refresh" keyword, force an immediate refresh of all the managed\-keys in the specified view, or all views\&. When run with the "sync" keyword, force an immediate dump of the managed\-keys database to disk (in the file
|
||||
Inspect and control the "managed\-keys" database which handles RFC 5011 DNSSEC trust anchor maintenance\&. If a view is specified, these commands are applied to that view; otherwise they are applied to all views\&.
|
||||
.sp
|
||||
.RS 4
|
||||
.ie n \{\
|
||||
\h'-04'\(bu\h'+03'\c
|
||||
.\}
|
||||
.el \{\
|
||||
.sp -1
|
||||
.IP \(bu 2.3
|
||||
.\}
|
||||
When run with the
|
||||
status
|
||||
keyword, prints the current status of the managed\-keys database\&.
|
||||
.RE
|
||||
.sp
|
||||
.RS 4
|
||||
.ie n \{\
|
||||
\h'-04'\(bu\h'+03'\c
|
||||
.\}
|
||||
.el \{\
|
||||
.sp -1
|
||||
.IP \(bu 2.3
|
||||
.\}
|
||||
When run with the
|
||||
refresh
|
||||
keyword, forces an immediate refresh query to be sent for all the managed keys, updating the managed\-keys database if any new keys are found, without waiting the normal refresh interval\&.
|
||||
.RE
|
||||
.sp
|
||||
.RS 4
|
||||
.ie n \{\
|
||||
\h'-04'\(bu\h'+03'\c
|
||||
.\}
|
||||
.el \{\
|
||||
.sp -1
|
||||
.IP \(bu 2.3
|
||||
.\}
|
||||
When run with the
|
||||
sync
|
||||
keyword, forces an immediate dump of the managed\-keys database to disk (in the file
|
||||
managed\-keys\&.bind
|
||||
or (\fIviewname\fR\&.mkeys)\&.
|
||||
or (\fIviewname\fR\&.mkeys)\&. This synchronizes the database with its journal file, so that the database\*(Aqs current contents can be inspected visually\&.
|
||||
.RE
|
||||
.sp
|
||||
.RS 4
|
||||
.ie n \{\
|
||||
\h'-04'\(bu\h'+03'\c
|
||||
.\}
|
||||
.el \{\
|
||||
.sp -1
|
||||
.IP \(bu 2.3
|
||||
.\}
|
||||
When run with the
|
||||
destroy
|
||||
keyword, the managed\-keys database is shut down and deleted, and all key maintenance is terminated\&. This command should be used only with extreme caution\&.
|
||||
.sp
|
||||
Existing keys that are already trusted are not deleted from memory; DNSSEC validation can continue after this command is used\&. However, key maintenance operations will cease until
|
||||
\fBnamed\fR
|
||||
is restarted or reconfigured, and all existing key maintenance state will be deleted\&.
|
||||
.sp
|
||||
Running
|
||||
\fBrndc reconfig\fR
|
||||
or restarting
|
||||
\fBnamed\fR
|
||||
immediately after this command will cause key maintenance to be reinitialized from scratch, just as if the server were being started for the first time\&. This is primarily intended for testing, but it may also be used, for example, to jumpstart the acquisition of new keys in the event of a trust anchor rollover, or as a brute\-force repair for key maintenance problems\&.
|
||||
.RE
|
||||
.RE
|
||||
.PP
|
||||
\fBmodzone \fR\fB\fIzone\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR\fB \fR\fB\fIconfiguration\fR\fR\fB \fR
|
||||
|
||||
+60
-11
@@ -450,19 +450,68 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term><userinput>managed-keys <replaceable>(status | refresh | sync)</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
|
||||
<term><userinput>managed-keys <replaceable>(status | refresh | sync | destroy)</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
|
||||
<listitem>
|
||||
<para>
|
||||
When run with the "status" keyword, print the current
|
||||
status of the managed-keys database for the specified
|
||||
view, or for all views if none is specified. When run
|
||||
with the "refresh" keyword, force an immediate refresh
|
||||
of all the managed-keys in the specified view, or all
|
||||
views. When run with the "sync" keyword, force an
|
||||
immediate dump of the managed-keys database to disk (in
|
||||
the file <filename>managed-keys.bind</filename> or
|
||||
(<filename><replaceable>viewname</replaceable>.mkeys</filename>).
|
||||
</para>
|
||||
Inspect and control the "managed-keys" database which
|
||||
handles RFC 5011 DNSSEC trust anchor maintenance. If a view
|
||||
is specified, these commands are applied to that view;
|
||||
otherwise they are applied to all views.
|
||||
</para>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
When run with the <literal>status</literal> keyword, prints
|
||||
the current status of the managed-keys database.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
When run with the <literal>refresh</literal> keyword,
|
||||
forces an immediate refresh query to be sent for all
|
||||
the managed keys, updating the managed-keys database
|
||||
if any new keys are found, without waiting the normal
|
||||
refresh interval.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
When run with the <literal>sync</literal> keyword, forces an
|
||||
immediate dump of the managed-keys database to disk
|
||||
(in the file <filename>managed-keys.bind</filename> or
|
||||
(<filename><replaceable>viewname</replaceable>.mkeys</filename>).
|
||||
This synchronizes the database with its journal file, so
|
||||
that the database's current contents can be inspected
|
||||
visually.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
When run with the <literal>destroy</literal> keyword, the
|
||||
managed-keys database is shut down and deleted, and all key
|
||||
maintenance is terminated. This command should be used only
|
||||
with extreme caution.
|
||||
</para>
|
||||
<para>
|
||||
Existing keys that are already trusted are not deleted
|
||||
from memory; DNSSEC validation can continue after this
|
||||
command is used. However, key maintenance operations will
|
||||
cease until <command>named</command> is restarted or
|
||||
reconfigured, and all existing key maintenance state
|
||||
will be deleted.
|
||||
</para>
|
||||
<para>
|
||||
Running <command>rndc reconfig</command> or restarting
|
||||
<command>named</command> immediately after this command
|
||||
will cause key maintenance to be reinitialized from scratch,
|
||||
just as if the server were being started for the first time.
|
||||
This is primarily intended for testing, but it may also be
|
||||
used, for example, to jumpstart the acquisition of new keys
|
||||
in the event of a trust anchor rollover, or as a
|
||||
brute-force repair for key maintenance problems.
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
|
||||
+60
-11
@@ -375,19 +375,68 @@
|
||||
Reference Manual for more details.)
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><strong class="userinput"><code>managed-keys <em class="replaceable"><code>(status | refresh | sync)</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
|
||||
<dt><span class="term"><strong class="userinput"><code>managed-keys <em class="replaceable"><code>(status | refresh | sync | destroy)</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
When run with the "status" keyword, print the current
|
||||
status of the managed-keys database for the specified
|
||||
view, or for all views if none is specified. When run
|
||||
with the "refresh" keyword, force an immediate refresh
|
||||
of all the managed-keys in the specified view, or all
|
||||
views. When run with the "sync" keyword, force an
|
||||
immediate dump of the managed-keys database to disk (in
|
||||
the file <code class="filename">managed-keys.bind</code> or
|
||||
(<code class="filename"><em class="replaceable"><code>viewname</code></em>.mkeys</code>).
|
||||
</p>
|
||||
Inspect and control the "managed-keys" database which
|
||||
handles RFC 5011 DNSSEC trust anchor maintenance. If a view
|
||||
is specified, these commands are applied to that view;
|
||||
otherwise they are applied to all views.
|
||||
</p>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When run with the <code class="literal">status</code> keyword, prints
|
||||
the current status of the managed-keys database.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When run with the <code class="literal">refresh</code> keyword,
|
||||
forces an immediate refresh query to be sent for all
|
||||
the managed keys, updating the managed-keys database
|
||||
if any new keys are found, without waiting the normal
|
||||
refresh interval.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When run with the <code class="literal">sync</code> keyword, forces an
|
||||
immediate dump of the managed-keys database to disk
|
||||
(in the file <code class="filename">managed-keys.bind</code> or
|
||||
(<code class="filename"><em class="replaceable"><code>viewname</code></em>.mkeys</code>).
|
||||
This synchronizes the database with its journal file, so
|
||||
that the database's current contents can be inspected
|
||||
visually.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When run with the <code class="literal">destroy</code> keyword, the
|
||||
managed-keys database is shut down and deleted, and all key
|
||||
maintenance is terminated. This command should be used only
|
||||
with extreme caution.
|
||||
</p>
|
||||
<p>
|
||||
Existing keys that are already trusted are not deleted
|
||||
from memory; DNSSEC validation can continue after this
|
||||
command is used. However, key maintenance operations will
|
||||
cease until <span class="command"><strong>named</strong></span> is restarted or
|
||||
reconfigured, and all existing key maintenance state
|
||||
will be deleted.
|
||||
</p>
|
||||
<p>
|
||||
Running <span class="command"><strong>rndc reconfig</strong></span> or restarting
|
||||
<span class="command"><strong>named</strong></span> immediately after this command
|
||||
will cause key maintenance to be reinitialized from scratch,
|
||||
just as if the server were being started for the first time.
|
||||
This is primarily intended for testing, but it may also be
|
||||
used, for example, to jumpstart the acquisition of new keys
|
||||
in the event of a trust anchor rollover, or as a
|
||||
brute-force repair for key maintenance problems.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</dd>
|
||||
<dt><span class="term"><strong class="userinput"><code>modzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] <em class="replaceable"><code>configuration</code></em> </code></strong></span></dt>
|
||||
<dd>
|
||||
|
||||
+1
-3
@@ -374,9 +374,7 @@ main(int argc, char *argv[]) {
|
||||
RUNTIME_CHECK(dns_dbtable_create(mctx, dns_rdataclass_in, &dbtable) ==
|
||||
ISC_R_SUCCESS);
|
||||
|
||||
|
||||
|
||||
strcpy(dbtype, "rbt");
|
||||
snprintf(dbtype, sizeof(dbtype), "rbt");
|
||||
while ((ch = isc_commandline_parse(argc, argv, "c:d:t:z:P:Q:glpqvT"))
|
||||
!= -1) {
|
||||
switch (ch) {
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1999-2001, 2004, 2005, 2007-2009, 2011-2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2004, 2005, 2007-2009, 2011-2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -26,6 +26,7 @@
|
||||
#include <isc/entropy.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/stdio.h>
|
||||
#include <isc/string.h>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2000, 2001, 2004-2007, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000, 2001, 2004-2007, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -108,7 +108,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacmd5", digest, 4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacmd5_init(&hmacmd5, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacmd5_update(&hmacmd5, buffer, strlen(s));
|
||||
@@ -140,7 +140,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacsha1", digest, ISC_SHA1_DIGESTLENGTH/4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacsha1_init(&hmacsha1, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacsha1_update(&hmacsha1, buffer, strlen(s));
|
||||
@@ -171,7 +171,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacsha224", digest, ISC_SHA224_DIGESTLENGTH/4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacsha224_init(&hmacsha224, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacsha224_update(&hmacsha224, buffer, strlen(s));
|
||||
@@ -202,7 +202,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacsha256", digest, ISC_SHA256_DIGESTLENGTH/4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacsha256_init(&hmacsha256, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacsha256_update(&hmacsha256, buffer, strlen(s));
|
||||
@@ -233,7 +233,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacsha384", digest, ISC_SHA384_DIGESTLENGTH/4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacsha384_init(&hmacsha384, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacsha384_update(&hmacsha384, buffer, strlen(s));
|
||||
@@ -264,7 +264,7 @@ main(int argc, char **argv) {
|
||||
print_digest(s, "hmacsha512", digest, ISC_SHA512_DIGESTLENGTH/4);
|
||||
|
||||
s = "what do ya want for nothing?";
|
||||
strcpy((char *)key, "Jefe");
|
||||
strlcpy((char *)key, "Jefe", sizeof(key));
|
||||
isc_hmacsha512_init(&hmacsha512, key, 4);
|
||||
memmove(buffer, s, strlen(s));
|
||||
isc_hmacsha512_update(&hmacsha512, buffer, strlen(s));
|
||||
|
||||
@@ -98,12 +98,12 @@ main(int argc, char **argv) {
|
||||
CHECK(isc_mem_create(0, 0, &mctx));
|
||||
CHECK(isc_entropy_create(mctx, &ectx));
|
||||
|
||||
CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE));
|
||||
hash_active = ISC_TRUE;
|
||||
|
||||
CHECK(dst_lib_init(mctx, ectx, ISC_ENTROPY_BLOCKING));
|
||||
dst_active = ISC_TRUE;
|
||||
|
||||
CHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE));
|
||||
hash_active = ISC_TRUE;
|
||||
|
||||
CHECK(isc_log_create(mctx, &lctx, &logconfig));
|
||||
isc_log_registercategories(lctx, categories);
|
||||
isc_log_setcontext(lctx);
|
||||
|
||||
+2
-2
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1999-2001, 2003, 2004, 2007-2009, 2011, 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001, 2003, 2004, 2007-2009, 2011, 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -179,7 +179,7 @@ nsecify(char *filename) {
|
||||
len = strlen(filename);
|
||||
if (len + 4 + 1 > sizeof(newfilename))
|
||||
fatal("filename too long");
|
||||
sprintf(newfilename, "%s.new", filename);
|
||||
snprintf(newfilename, sizeof(newfilename), "%s.new", filename);
|
||||
result = dns_db_dump(db, NULL, newfilename);
|
||||
check_result(result, "dns_db_dump");
|
||||
dns_db_detach(&db);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1998-2001, 2004, 2005, 2007, 2013, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001, 2004, 2005, 2007, 2013, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -109,7 +109,7 @@ main(int argc, char *argv[]) {
|
||||
RUNTIME_CHECK(isc_rwlock_init(&lock, 5, 10) == ISC_R_SUCCESS);
|
||||
|
||||
for (i = 0; i < nworkers; i++) {
|
||||
sprintf(name, "%02u", i);
|
||||
snprintf(name, sizeof(name), "%02u", i);
|
||||
dupname = strdup(name);
|
||||
RUNTIME_CHECK(dupname != NULL);
|
||||
if (i != 0 && i % 3 == 0)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1998-2001, 2004, 2007, 2011, 2013, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001, 2004, 2007, 2011, 2013, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <isc/app.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/time.h>
|
||||
#include <isc/timer.h>
|
||||
@@ -136,9 +137,10 @@ new_task(isc_mem_t *mctx, const char *name) {
|
||||
ti->ticks = 0;
|
||||
if (name != NULL) {
|
||||
INSIST(strlen(name) < sizeof(ti->name));
|
||||
strcpy(ti->name, name);
|
||||
} else
|
||||
sprintf(ti->name, "%d", task_count);
|
||||
strlcpy(ti->name, name, sizeof(ti->name));
|
||||
} else {
|
||||
snprintf(ti->name, sizeof(ti->name), "%d", task_count);
|
||||
}
|
||||
RUNTIME_CHECK(isc_task_create(task_manager, 0, &ti->task) ==
|
||||
ISC_R_SUCCESS);
|
||||
RUNTIME_CHECK(isc_task_onshutdown(ti->task, shutdown_action, ti) ==
|
||||
|
||||
+12
-9
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 1998-2001, 2004, 2007, 2008, 2012-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001, 2004, 2007, 2008, 2012-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -16,8 +16,9 @@
|
||||
|
||||
#include <isc/mem.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/socket.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/task.h>
|
||||
#include <isc/timer.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
@@ -101,12 +102,12 @@ my_recv(isc_task_t *task, isc_event_t *event) {
|
||||
*/
|
||||
if (strcmp(event->ev_arg, "so2") != 0) {
|
||||
region = dev->region;
|
||||
sprintf(buf, "\r\nReceived: %.*s\r\n\r\n",
|
||||
(int)dev->n, (char *)region.base);
|
||||
snprintf(buf, sizeof(buf), "\r\nReceived: %.*s\r\n\r\n",
|
||||
(int)dev->n, (char *)region.base);
|
||||
region.base = isc_mem_get(mctx, strlen(buf) + 1);
|
||||
if (region.base != NULL) {
|
||||
region.length = strlen(buf) + 1;
|
||||
strcpy((char *)region.base, buf); /* strcpy is safe */
|
||||
strlcpy((char *)region.base, buf, region.length);
|
||||
} else
|
||||
region.length = 0;
|
||||
isc_socket_send(sock, ®ion, task, my_send, event->ev_arg);
|
||||
@@ -173,14 +174,16 @@ my_connect(isc_task_t *task, isc_event_t *event) {
|
||||
* Send a GET string, and set up to receive (and just display)
|
||||
* the result.
|
||||
*/
|
||||
strcpy(buf, "GET / HTTP/1.1\r\nHost: www.flame.org\r\n"
|
||||
"Connection: Close\r\n\r\n");
|
||||
snprintf(buf, sizeof(buf),
|
||||
"GET / HTTP/1.1\r\nHost: www.flame.org\r\n"
|
||||
"Connection: Close\r\n\r\n");
|
||||
region.base = isc_mem_get(mctx, strlen(buf) + 1);
|
||||
if (region.base != NULL) {
|
||||
region.length = strlen(buf) + 1;
|
||||
strcpy((char *)region.base, buf); /* This strcpy is safe. */
|
||||
} else
|
||||
strlcpy((char *)region.base, buf, region.length);
|
||||
} else {
|
||||
region.length = 0;
|
||||
}
|
||||
|
||||
isc_socket_send(sock, ®ion, task, my_http_get, event->ev_arg);
|
||||
|
||||
|
||||
@@ -6,8 +6,6 @@
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
# $Id: clean.sh,v 1.3 2010/09/15 03:32:34 marka Exp $
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f rndc.out*
|
||||
rm -f showzone.out*
|
||||
@@ -28,8 +26,11 @@ rm -rf ns2/new-zones
|
||||
rm -f ns*/named.lock
|
||||
rm -f ns*/named.run
|
||||
rm -f ns2/nzf-*
|
||||
rm -f ns3/named.conf
|
||||
rm -f ns3/*.nzf ns3/*.nzf~
|
||||
rm -f ns3/*.nzd ns3/*.nzd-lock
|
||||
rm -f ns3/inlineslave.db
|
||||
rm -f ns1/redirect.db
|
||||
rm -f ns2/redirect.db
|
||||
rm -f ns2/redirect.bk
|
||||
rm -f ns3/redirect.db
|
||||
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.3 port 9953 allow { any; } keys { rndc_key; };
|
||||
};
|
||||
|
||||
options {
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.3; };
|
||||
listen-on-v6 { none; };
|
||||
allow-query { any; };
|
||||
recursion no;
|
||||
allow-new-zones yes;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type master;
|
||||
file "redirect.db";
|
||||
};
|
||||
|
||||
masters "testmaster" {
|
||||
192.5.5.241;
|
||||
};
|
||||
@@ -20,10 +20,7 @@ options {
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.3; };
|
||||
listen-on-v6 { none; };
|
||||
allow-query { any; };
|
||||
recursion no;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type master;
|
||||
file "redirect.db";
|
||||
allow-new-zones yes;
|
||||
};
|
||||
@@ -16,4 +16,8 @@ cp -f ns2/redirect.db.1 ns2/redirect.db
|
||||
cp -f ns3/redirect.db.1 ns3/redirect.db
|
||||
cp -f ns2/named1.conf ns2/named.conf
|
||||
cp -f ns2/default.nzf.in ns2/3bf305731dd26307.nzf
|
||||
cp -f ns3/named1.conf ns3/named.conf
|
||||
rm -f ns3/*.nzf ns3/*.nzf~
|
||||
rm -f ns3/*.nzd ns3/*.nzd-lock
|
||||
rm -f ns3/inlineslave.db
|
||||
mkdir ns2/new-zones
|
||||
|
||||
@@ -661,5 +661,16 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:check delzone after reconfig failure ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 addzone 'inlineslave.example. IN { type slave; file "inlineslave.db"; masterfile-format text; masters { testmaster; }; };' > /dev/null 2>&1 || ret=1
|
||||
cp -f ns3/named2.conf ns3/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 reconfig > /dev/null 2>&1 && ret=1
|
||||
sleep 5
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 delzone inlineslave.example > /dev/null 2>&1 || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -7,27 +7,29 @@
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
rm -f */K* */dsset-* */*.signed */tmp* */*.jnl */*.bk
|
||||
rm -f */trusted.conf */private.conf
|
||||
rm -f */core
|
||||
rm -f */example.bk
|
||||
rm -f */named.memstats
|
||||
rm -f */named.run
|
||||
rm -f */trusted.conf */private.conf
|
||||
rm -f activate-now-publish-1day.key
|
||||
rm -f active.key inact.key del.key unpub.key standby.key rev.key
|
||||
rm -f sync.key
|
||||
rm -f delayksk.key delayzsk.key autoksk.key autozsk.key
|
||||
rm -f dig.out.*
|
||||
rm -f digcomp.out.test*
|
||||
rm -f digcomp.out.test*
|
||||
rm -f missingzsk.key inactivezsk.key
|
||||
rm -f nopriv.key vanishing.key del1.key del2.key
|
||||
rm -f ns*/named.lock
|
||||
rm -f ns*/named.lock
|
||||
rm -f ns1/root.db
|
||||
rm -f ns2/example.db
|
||||
rm -f ns2/private.secure.example.db ns2/bar.db
|
||||
rm -f ns3/*.nzd ns3/*.nzd-lock ns3/*.nzf
|
||||
rm -f ns3/*.nzf
|
||||
rm -f ns3/autonsec3.example.db
|
||||
rm -f ns3/sync.example.db
|
||||
rm -f ns3/kg.out ns3/s.out ns3/st.out
|
||||
rm -f ns3/kskonly.example.db
|
||||
rm -f ns3/nozsk.example.db ns3/inaczsk.example.db
|
||||
rm -f ns3/nsec.example.db
|
||||
rm -f ns3/nsec3-to-nsec.example.db
|
||||
@@ -47,10 +49,9 @@ rm -f ns3/secure-to-insecure2.example.db
|
||||
rm -f ns3/secure.example.db
|
||||
rm -f ns3/secure.nsec3.example.db
|
||||
rm -f ns3/secure.optout.example.db
|
||||
rm -f ns3/sync.example.db
|
||||
rm -f ns3/ttl*.db
|
||||
rm -f nsupdate.out
|
||||
rm -f signing.out.*
|
||||
rm -f settime.out.*
|
||||
rm -f ns3/*.nzd ns3/*.nzd-lock ns3/*.nzf
|
||||
rm -f digcomp.out.test*
|
||||
rm -f ns*/named.lock
|
||||
rm -f signing.out.*
|
||||
rm -f sync.key
|
||||
|
||||
@@ -248,7 +248,7 @@ echo $zsk > ../inactivezsk.key
|
||||
$SETTIME -I now $zsk > st.out 2>&1 || dumpit st.out
|
||||
|
||||
#
|
||||
# A zone that is set to 'auto-dnssec maintain' during a recofnig
|
||||
# A zone that is set to 'auto-dnssec maintain' during a reconfig
|
||||
#
|
||||
setup reconf.example
|
||||
cp secure.example.db.in $zonefile
|
||||
@@ -256,7 +256,7 @@ $KEYGEN -q -a RSASHA1 -3 -r $RANDFILE -fk $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA1 -3 -r $RANDFILE $zone > kg.out 2>&1 || dumpit kg.out
|
||||
|
||||
#
|
||||
# A zone which generates a CDS and CDNSEY RRsets automatically
|
||||
# A zone which generates CDS and CDNSEY RRsets automatically
|
||||
#
|
||||
setup sync.example
|
||||
cp $infile $zonefile
|
||||
@@ -264,3 +264,12 @@ ksk=`$KEYGEN -a RSASHA1 -3 -q -r $RANDFILE -fk -P sync now $zone 2> kg.out` || d
|
||||
$KEYGEN -a RSASHA1 -3 -q -r $RANDFILE $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
echo ns3/$ksk > ../sync.key
|
||||
|
||||
#
|
||||
# A zone that generates CDS and CDNSKEY and uses dnssec-dnskey-kskonly
|
||||
#
|
||||
setup kskonly.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a RSASHA1 -3 -q -r $RANDFILE -fk -P sync now $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a RSASHA1 -3 -q -r $RANDFILE $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
; Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2000042407 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
z A 10.0.0.26
|
||||
a.a.a.a.a.a.a.a.a.a.e A 10.0.0.27
|
||||
x CNAME a
|
||||
|
||||
private NS ns.private
|
||||
ns.private A 10.53.0.2
|
||||
|
||||
insecure NS ns.insecure
|
||||
ns.insecure A 10.53.0.2
|
||||
@@ -1,13 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2009-2013, 2015, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2009-2013, 2015-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* $Id: named.conf,v 1.15 2012/02/06 23:46:47 tbox Exp $ */
|
||||
|
||||
// NS3
|
||||
|
||||
controls { /* empty */ };
|
||||
@@ -243,4 +241,12 @@ zone "sync.example" {
|
||||
auto-dnssec maintain;
|
||||
};
|
||||
|
||||
zone "kskonly.example" {
|
||||
type master;
|
||||
file "kskonly.example.db";
|
||||
allow-update { any; };
|
||||
dnssec-dnskey-kskonly yes;
|
||||
auto-dnssec maintain;
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -1166,8 +1166,38 @@ if [ "$lret" != 0 ]; then ret=$lret; fi
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:test 'dnssec-dnskey-kskonly no' affects DNSKEY/CDS/CDNSKEY ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example dnskey > dig.out.ns3.dnskeytest$n
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example cds > dig.out.ns3.cdstest$n
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "DNSKEY" {print}' dig.out.ns3.dnskeytest$n | wc -l`
|
||||
test ${lines:-0} -eq 2 || ret=1
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "CDNSKEY" {print}' dig.out.ns3.cdnskeytest$n | wc -l`
|
||||
test ${lines:-0} -eq 2 || ret=1
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "CDS" {print}' dig.out.ns3.cdstest$n | wc -l`
|
||||
test ${lines:-0} -eq 2 || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:test 'dnssec-dnskey-kskonly yes' affects DNSKEY/CDS/CDNSKEY ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.3 kskonly.example dnskey > dig.out.ns3.dnskeytest$n
|
||||
$DIG $DIGOPTS @10.53.0.3 kskonly.example cdnskey > dig.out.ns3.cdnskeytest$n
|
||||
$DIG $DIGOPTS @10.53.0.3 kskonly.example cds > dig.out.ns3.cdstest$n
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "DNSKEY" {print}' dig.out.ns3.dnskeytest$n | wc -l`
|
||||
test ${lines:-0} -eq 1 || ret=1
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "CDNSKEY" {print}' dig.out.ns3.cdnskeytest$n | wc -l`
|
||||
test ${lines:-0} -eq 1 || ret=1
|
||||
lines=`awk '$4 == "RRSIG" && $5 == "CDS" {print}' dig.out.ns3.cdstest$n | wc -l`
|
||||
test ${lines:-0} -eq 1 || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'"
|
||||
$SETTIME -D sync now+2 `cat sync.key`
|
||||
$SETTIME -D sync now+2 `cat sync.key` > /dev/null
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.3 -p 9953 loadkeys sync.example
|
||||
echo "I:waiting for deletion to occur"
|
||||
sleep 3
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
CDNSKEY*
|
||||
CDS*
|
||||
DS*
|
||||
K*
|
||||
UP*
|
||||
brk.*
|
||||
db.*
|
||||
dsset-*
|
||||
err
|
||||
empty
|
||||
out
|
||||
sig.*
|
||||
vars.sh
|
||||
@@ -0,0 +1,13 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
my $target = shift;
|
||||
my $file = shift;
|
||||
my $mtime = time - (stat $file)[9];
|
||||
die "bad mtime $mtime"
|
||||
unless abs($mtime - $target) < 3;
|
||||
@@ -0,0 +1,18 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
$target = shift;
|
||||
while (<>) {
|
||||
$notbefore = $1 if m{^.* must not be signed before \d+ [(](\d+)[)]$};
|
||||
$inception = $1 if m{^.* inception time \d+ [(](\d+)[)]$};
|
||||
}
|
||||
die "missing notbefore time" unless $notbefore;
|
||||
die "missing inception time" unless $inception;
|
||||
my $delta = $inception - $notbefore;
|
||||
die "bad inception time $delta"
|
||||
unless abs($delta - $target) < 3;
|
||||
@@ -0,0 +1,18 @@
|
||||
#!/bin/sh -e
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
rm -f CDNSKEY* CDS* DS*
|
||||
rm -f K*
|
||||
rm -f UP*
|
||||
rm -f brk.*
|
||||
rm -f db.*
|
||||
rm -f dsset-*
|
||||
rm -f empty
|
||||
rm -f sig.*
|
||||
rm -f vars.sh
|
||||
rm -f err* out* xerr xout
|
||||
@@ -0,0 +1,14 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
my $re = $ARGV[0];
|
||||
shift;
|
||||
while (<>) {
|
||||
s{($re)........}{${1}00000000};
|
||||
print;
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -0,0 +1,128 @@
|
||||
#!/bin/sh -e
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
set -eu
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
$SHELL clean.sh
|
||||
|
||||
test -r $RANDFILE || $GENRANDOM 800 $RANDFILE
|
||||
|
||||
touch empty
|
||||
|
||||
Z=cds.test
|
||||
|
||||
keyz=$($KEYGEN -q -r $RANDFILE -a RSASHA256 $Z)
|
||||
key1=$($KEYGEN -q -r $RANDFILE -a RSASHA256 -f KSK $Z)
|
||||
key2=$($KEYGEN -q -r $RANDFILE -a RSASHA256 -f KSK $Z)
|
||||
|
||||
idz=$(echo $keyz | sed 's/.*+0*//')
|
||||
id1=$(echo $key1 | sed 's/.*+0*//')
|
||||
id2=$(echo $key2 | sed 's/.*+0*//')
|
||||
|
||||
cat <<EOF >vars.sh
|
||||
Z=$Z
|
||||
key1=$key1
|
||||
key2=$key2
|
||||
idz=$idz
|
||||
id1=$id1
|
||||
id2=$id2
|
||||
EOF
|
||||
|
||||
tac() {
|
||||
perl -e 'print reverse <>' "$@"
|
||||
}
|
||||
|
||||
convert() {
|
||||
local key=$1 n=$2
|
||||
$DSFROMKEY $key >DS.$n
|
||||
grep ' 8 1 ' DS.$n >DS.$n-1
|
||||
grep ' 8 2 ' DS.$n >DS.$n-2
|
||||
sed 's/ IN DS / IN CDS /' <DS.$n >>CDS.$n
|
||||
sed 's/ IN DNSKEY / IN CDNSKEY /' <$key.key >CDNSKEY.$n
|
||||
sed 's/ IN DS / 3600 IN DS /' <DS.$n >DS.ttl$n
|
||||
sed 's/ IN DS / 7200 IN DS /' <DS.$n >DS.ttlong$n
|
||||
tac <DS.$n >DS.rev$n
|
||||
}
|
||||
convert $key1 1
|
||||
convert $key2 2
|
||||
|
||||
# consistent order wrt IDs
|
||||
sort DS.1 DS.2 >DS.both
|
||||
|
||||
cp DS.1 DS.inplace
|
||||
$PERL -we 'utime time, time - 7200, "DS.inplace" or die'
|
||||
|
||||
mangle="$PERL mangle.pl"
|
||||
|
||||
$mangle " IN DS $id1 8 1 " <DS.1 >DS.broke1
|
||||
$mangle " IN DS $id1 8 2 " <DS.1 >DS.broke2
|
||||
$mangle " IN DS $id1 8 [12] " <DS.1 >DS.broke12
|
||||
|
||||
sed 's/^/update add /
|
||||
$a\
|
||||
send
|
||||
' <DS.2 >UP.add2
|
||||
|
||||
sed 's/^/update del /
|
||||
$a\
|
||||
send
|
||||
' <DS.1 >UP.del1
|
||||
|
||||
cat UP.add2 UP.del1 | sed 3d >UP.swap
|
||||
|
||||
sed 's/ add \(.*\) IN DS / add \1 3600 IN DS /' <UP.swap >UP.swapttl
|
||||
|
||||
sign() {
|
||||
cat >db.$1
|
||||
$SIGNER >/dev/null 2>&1 -r $RANDFILE \
|
||||
-S -O full -o $Z -f sig.$1 db.$1
|
||||
}
|
||||
|
||||
sign null <<EOF
|
||||
\$TTL 1h
|
||||
@ SOA localhost. root.localhost. (
|
||||
1 ; serial
|
||||
1h ; refresh
|
||||
1h ; retry
|
||||
1w ; expiry
|
||||
1h ; minimum
|
||||
)
|
||||
;
|
||||
NS localhost.
|
||||
;
|
||||
EOF
|
||||
|
||||
cat sig.null CDS.1 >brk.unsigned-cds
|
||||
|
||||
cat db.null CDS.1 | sign cds.1
|
||||
cat db.null CDS.2 | sign cds.2
|
||||
cat db.null CDS.1 CDS.2 | sign cds.both
|
||||
|
||||
tac <sig.cds.1 >sig.cds.rev1
|
||||
|
||||
cat db.null CDNSKEY.2 | sign cdnskey.2
|
||||
cat db.null CDS.2 CDNSKEY.2 | sign cds.cdnskey.2
|
||||
|
||||
$mangle '\s+IN\s+RRSIG\s+CDS .* '$idz' '$Z'\. ' \
|
||||
<sig.cds.1 >brk.rrsig.cds.zsk
|
||||
$mangle '\s+IN\s+RRSIG\s+CDS .* '$id1' '$Z'\. ' \
|
||||
<sig.cds.1 >brk.rrsig.cds.ksk
|
||||
|
||||
$mangle " IN CDS $id1 8 1 " <db.cds.1 |
|
||||
sign cds-mangled
|
||||
|
||||
sed 's/IN CDS '$id1' 8 1 /IN CDS '$((id1 ^ 255))' 8 1 /' <db.cds.1 |
|
||||
sign bad-digests
|
||||
|
||||
sed '/IN CDS '$id1' 8 /p;s//IN CDS '$((id1 ^ 255))' 13 /' <db.cds.1 |
|
||||
sign bad-algos
|
||||
|
||||
rm -f dsset-*
|
||||
@@ -0,0 +1,238 @@
|
||||
#!/bin/sh -e
|
||||
#
|
||||
# Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
fail() {
|
||||
echo "I:failed"
|
||||
status=`expr $status + 1`
|
||||
}
|
||||
|
||||
runcmd() {
|
||||
"$@" 1> out.$n 2> err.$n
|
||||
echo $?
|
||||
}
|
||||
|
||||
testcase() {
|
||||
n=`expr $n + 1`
|
||||
echo "I:$name ($n)"
|
||||
expect=$1
|
||||
shift
|
||||
result=`runcmd "$@"`
|
||||
check_stdout
|
||||
check_stderr
|
||||
if [ "$expect" -ne "$result" ]; then
|
||||
echo "D:exit status does not match $expect"
|
||||
fail
|
||||
fi
|
||||
unset name err out
|
||||
}
|
||||
|
||||
check_stderr() {
|
||||
if [ -n "${err:=}" ]; then
|
||||
egrep "$err" err.$n >/dev/null && return 0
|
||||
else
|
||||
[ -s err.$n ] || return 0
|
||||
fi
|
||||
echo "D:stderr did not match '$err'"
|
||||
sed 's/^/D:/' err
|
||||
fail
|
||||
}
|
||||
|
||||
check_stdout() {
|
||||
cmp out.$n "${out:-empty}" >/dev/null && return
|
||||
echo "D:stdout did not match '$out'"
|
||||
( echo "wanted"
|
||||
cat "$out"
|
||||
echo "got"
|
||||
cat out.$n
|
||||
) | sed 's/^/D:/'
|
||||
fail
|
||||
}
|
||||
|
||||
Z=cds.test
|
||||
|
||||
name='usage'
|
||||
err='Usage'
|
||||
testcase 1 $CDS
|
||||
|
||||
name='need a DS file'
|
||||
err='DS pathname'
|
||||
testcase 1 $CDS $Z
|
||||
|
||||
name='name of dsset in directory'
|
||||
err="./dsset-$Z.: file not found"
|
||||
testcase 1 $CDS -d . $Z
|
||||
|
||||
name='load a file'
|
||||
err='could not find DS records'
|
||||
testcase 1 $CDS -d empty $Z
|
||||
|
||||
name='load DS records'
|
||||
err='path to file containing child data must be specified'
|
||||
testcase 1 $CDS -d DS.1 $Z
|
||||
|
||||
name='missing DNSKEY'
|
||||
err='could not find signed DNSKEY RRset'
|
||||
testcase 1 $CDS -f db.null -d DS.1 $Z
|
||||
|
||||
name='sigs too old'
|
||||
err='could not validate child DNSKEY RRset'
|
||||
testcase 1 $CDS -f sig.null -d DS.1 $Z
|
||||
|
||||
name='sigs too old, verbosely'
|
||||
err='skip RRSIG by key [0-9]+: too old'
|
||||
testcase 1 $CDS -v1 -f sig.null -d DS.1 $Z
|
||||
|
||||
name='old sigs are allowed'
|
||||
err='found RRSIG by key'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -v1 -s -7200 -f sig.null -d DS.1 $Z
|
||||
|
||||
name='no CDS/CDNSKEY records'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -s -7200 -f sig.null -d DS.1 $Z
|
||||
|
||||
name='no child records, verbosely'
|
||||
err='has neither CDS nor CDNSKEY records'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -v1 -s -7200 -f sig.null -d DS.1 $Z
|
||||
|
||||
name='unsigned CDS'
|
||||
err='missing RRSIG CDS records'
|
||||
testcase 1 $CDS -f brk.unsigned-cds -d DS.1 $Z
|
||||
|
||||
name='correct signature inception time'
|
||||
$CDS -v3 -s -7200 -f sig.cds.1 -d DS.1 $Z 1>xout 2>xerr
|
||||
testcase 0 $PERL checktime.pl 3600 xerr
|
||||
|
||||
name='in-place reads modification time'
|
||||
testcase 0 $CDS -f sig.cds.1 -i.bak -d DS.inplace $Z
|
||||
|
||||
name='in-place output correct modification time'
|
||||
testcase 0 $PERL checkmtime.pl 3600 DS.inplace
|
||||
|
||||
name='in-place backup correct modification time'
|
||||
testcase 0 $PERL checkmtime.pl 7200 DS.inplace.bak
|
||||
|
||||
name='in-place correct output'
|
||||
testcase 0 cmp DS.1 DS.inplace
|
||||
|
||||
name='in-place backup unmodified'
|
||||
testcase 0 cmp DS.1 DS.inplace.bak
|
||||
|
||||
name='one mangled DS'
|
||||
err='found RRSIG by key'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -v1 -s -7200 -f sig.cds.1 -d DS.broke1 $Z
|
||||
|
||||
name='other mangled DS'
|
||||
err='found RRSIG by key'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -v1 -s -7200 -f sig.cds.1 -d DS.broke2 $Z
|
||||
|
||||
name='both mangled DS'
|
||||
err='could not validate child DNSKEY RRset'
|
||||
testcase 1 $CDS -v1 -s -7200 -f sig.cds.1 -d DS.broke12 $Z
|
||||
|
||||
name='mangle RRSIG CDS by ZSK'
|
||||
err='found RRSIG by key'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -v1 -s -7200 -f brk.rrsig.cds.zsk -d DS.1 $Z
|
||||
|
||||
name='mangle RRSIG CDS by KSK'
|
||||
err='could not validate child CDS RRset'
|
||||
testcase 1 $CDS -v1 -s -7200 -f brk.rrsig.cds.ksk -d DS.1 $Z
|
||||
|
||||
name='mangle CDS 1'
|
||||
err='could not validate child DNSKEY RRset with new DS records'
|
||||
testcase 1 $CDS -s -7200 -f sig.cds-mangled -d DS.1 $Z
|
||||
|
||||
name='inconsistent digests'
|
||||
err='do not cover each key with the same set of digest types'
|
||||
testcase 1 $CDS -s -7200 -f sig.bad-digests -d DS.1 $Z
|
||||
|
||||
name='inconsistent algorithms'
|
||||
err='missing signature for algorithm'
|
||||
testcase 1 $CDS -s -7200 -f sig.bad-algos -d DS.1 $Z
|
||||
|
||||
name='add DS records'
|
||||
out=DS.both
|
||||
$CDS -s -7200 -f sig.cds.both -d DS.1 $Z >DS.out
|
||||
# sort to allow for numerical vs lexical order of key tags
|
||||
testcase 0 sort DS.out
|
||||
|
||||
name='update add'
|
||||
out=UP.add2
|
||||
testcase 0 $CDS -u -s -7200 -f sig.cds.both -d DS.1 $Z
|
||||
|
||||
name='remove DS records'
|
||||
out=DS.2
|
||||
testcase 0 $CDS -s -7200 -f sig.cds.2 -d DS.both $Z
|
||||
|
||||
name='update del'
|
||||
out=UP.del1
|
||||
testcase 0 $CDS -u -s -7200 -f sig.cds.2 -d DS.both $Z
|
||||
|
||||
name='swap DS records'
|
||||
out=DS.2
|
||||
testcase 0 $CDS -s -7200 -f sig.cds.2 -d DS.1 $Z
|
||||
|
||||
name='update swap'
|
||||
out=UP.swap
|
||||
testcase 0 $CDS -u -s -7200 -f sig.cds.2 -d DS.1 $Z
|
||||
|
||||
name='TTL from -T'
|
||||
out=DS.ttl2
|
||||
testcase 0 $CDS -T 3600 -s -7200 -f sig.cds.2 -d DS.1 $Z
|
||||
|
||||
name='update TTL from -T'
|
||||
out=UP.swapttl
|
||||
testcase 0 $CDS -u -T 3600 -s -7200 -f sig.cds.2 -d DS.1 $Z
|
||||
|
||||
name='update TTL from dsset'
|
||||
out=UP.swapttl
|
||||
testcase 0 $CDS -u -s -7200 -f sig.cds.2 -d DS.ttl1 $Z
|
||||
|
||||
name='TTL from -T overrides dsset'
|
||||
out=DS.ttlong2
|
||||
testcase 0 $CDS -T 7200 -s -7200 -f sig.cds.2 -d DS.ttl1 $Z
|
||||
|
||||
name='stable DS record order (changes)'
|
||||
out=DS.1
|
||||
testcase 0 $CDS -s -7200 -f sig.cds.rev1 -d DS.2 $Z
|
||||
|
||||
name='CDNSKEY default algorithm'
|
||||
out=DS.2-2
|
||||
testcase 0 $CDS -s -7200 -f sig.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
name='CDNSKEY SHA1'
|
||||
out=DS.2-1
|
||||
testcase 0 $CDS -a SHA1 -s -7200 -f sig.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
name='CDNSKEY two algorithms'
|
||||
out=DS.2
|
||||
testcase 0 $CDS -a SHA1 -a SHA256 -s -7200 -f sig.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
name='CDNSKEY two algorithms, reversed'
|
||||
out=DS.2
|
||||
testcase 0 $CDS -a SHA256 -a SHA1 -s -7200 -f sig.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
name='CDNSKEY and CDS'
|
||||
out=DS.2
|
||||
testcase 0 $CDS -s -7200 -f sig.cds.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
name='prefer CDNSKEY'
|
||||
out=DS.2-2
|
||||
testcase 0 $CDS -D -s -7200 -f sig.cds.cdnskey.2 -d DS.1 $Z
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
@@ -38,3 +38,10 @@ else
|
||||
echo "I:This test requires the perl Net::DNS library." >&2
|
||||
exit 1
|
||||
fi
|
||||
if $PERL -e 'use Net::DNS::Nameserver;' 2>/dev/null
|
||||
then
|
||||
:
|
||||
else
|
||||
echo "I:This test requires the Net::DNS::Nameserver library." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
dnssec-lookaside auto;
|
||||
};
|
||||
@@ -0,0 +1,11 @@
|
||||
/*
|
||||
* Copyright (C) 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
options {
|
||||
dnssec-lookaside . trust-anchor dlv.isc.org;
|
||||
};
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2011, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2011, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
@@ -24,7 +24,7 @@ view view2 {
|
||||
|
||||
view view3 {
|
||||
match-clients { none; };
|
||||
dnssec-lookaside auto;
|
||||
dnssec-validation auto;
|
||||
};
|
||||
|
||||
view view4 {
|
||||
|
||||
@@ -80,7 +80,6 @@ view "first" {
|
||||
type master;
|
||||
file "yyy";
|
||||
};
|
||||
dnssec-lookaside auto;
|
||||
dnssec-validation auto;
|
||||
zone-statistics terse;
|
||||
};
|
||||
@@ -111,7 +110,7 @@ view "second" {
|
||||
1.2.3.4;
|
||||
};
|
||||
};
|
||||
dnssec-lookaside "." trust-anchor "dlv.isc.org.";
|
||||
dnssec-lookaside "." trust-anchor "example.org.";
|
||||
dnssec-validation auto;
|
||||
zone-statistics full;
|
||||
};
|
||||
|
||||
+89
-33
@@ -17,42 +17,43 @@ TOP=${SYSTEMTESTTOP:=.}/../../..
|
||||
# Make it absolute so that it continues to work after we cd.
|
||||
TOP=`cd $TOP && pwd`
|
||||
|
||||
NAMED=$TOP/bin/named/named
|
||||
DIG=$TOP/bin/dig/dig
|
||||
DELV=$TOP/bin/delv/delv
|
||||
RNDC=$TOP/bin/rndc/rndc
|
||||
NSUPDATE=$TOP/bin/nsupdate/nsupdate
|
||||
DDNSCONFGEN=$TOP/bin/confgen/ddns-confgen
|
||||
TSIGKEYGEN=$TOP/bin/confgen/tsig-keygen
|
||||
RNDCCONFGEN=$TOP/bin/confgen/rndc-confgen
|
||||
KEYGEN=$TOP/bin/dnssec/dnssec-keygen
|
||||
KEYFRLAB=$TOP/bin/dnssec/dnssec-keyfromlabel
|
||||
SIGNER=$TOP/bin/dnssec/dnssec-signzone
|
||||
REVOKE=$TOP/bin/dnssec/dnssec-revoke
|
||||
SETTIME=$TOP/bin/dnssec/dnssec-settime
|
||||
DSFROMKEY=$TOP/bin/dnssec/dnssec-dsfromkey
|
||||
IMPORTKEY=$TOP/bin/dnssec/dnssec-importkey
|
||||
CHECKDS=$TOP/bin/python/dnssec-checkds
|
||||
COVERAGE=$TOP/bin/python/dnssec-coverage
|
||||
KEYMGR=$TOP/bin/python/dnssec-keymgr
|
||||
CHECKZONE=$TOP/bin/check/named-checkzone
|
||||
CHECKCONF=$TOP/bin/check/named-checkconf
|
||||
PK11GEN="$TOP/bin/pkcs11/pkcs11-keygen -q -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||
PK11LIST="$TOP/bin/pkcs11/pkcs11-list -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||
PK11DEL="$TOP/bin/pkcs11/pkcs11-destroy -s ${SLOT:-0} -p ${HSMPIN:-1234} -w 0"
|
||||
JOURNALPRINT=$TOP/bin/tools/named-journalprint
|
||||
VERIFY=$TOP/bin/dnssec/dnssec-verify
|
||||
ARPANAME=$TOP/bin/tools/arpaname
|
||||
RESOLVE=$TOP/lib/samples/resolve
|
||||
RRCHECKER=$TOP/bin/tools/named-rrchecker
|
||||
CDS=$TOP/bin/dnssec/dnssec-cds
|
||||
CHECKCONF=$TOP/bin/check/named-checkconf
|
||||
CHECKDS=$TOP/bin/python/dnssec-checkds
|
||||
CHECKZONE=$TOP/bin/check/named-checkzone
|
||||
COVERAGE=$TOP/bin/python/dnssec-coverage
|
||||
DDNSCONFGEN=$TOP/bin/confgen/ddns-confgen
|
||||
DELV=$TOP/bin/delv/delv
|
||||
DIG=$TOP/bin/dig/dig
|
||||
DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||
DSFROMKEY=$TOP/bin/dnssec/dnssec-dsfromkey
|
||||
FEATURETEST=$TOP/bin/tests/system/feature-test
|
||||
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||
GENRANDOM=$TOP/bin/tools/genrandom
|
||||
IMPORTKEY=$TOP/bin/dnssec/dnssec-importkey
|
||||
JOURNALPRINT=$TOP/bin/tools/named-journalprint
|
||||
KEYFRLAB=$TOP/bin/dnssec/dnssec-keyfromlabel
|
||||
KEYGEN=$TOP/bin/dnssec/dnssec-keygen
|
||||
KEYMGR=$TOP/bin/python/dnssec-keymgr
|
||||
MDIG=$TOP/bin/tools/mdig
|
||||
NAMED=$TOP/bin/named/named
|
||||
NSEC3HASH=$TOP/bin/tools/nsec3hash
|
||||
NSLOOKUP=$TOP/bin/dig/nslookup
|
||||
DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||
MDIG=$TOP/bin/tools/mdig
|
||||
NSUPDATE=$TOP/bin/nsupdate/nsupdate
|
||||
NZD2NZF=$TOP/bin/tools/named-nzd2nzf
|
||||
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||
FEATURETEST=$TOP/bin/tests/system/feature-test
|
||||
PK11DEL="$TOP/bin/pkcs11/pkcs11-destroy -s ${SLOT:-0} -p ${HSMPIN:-1234} -w 0"
|
||||
PK11GEN="$TOP/bin/pkcs11/pkcs11-keygen -q -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||
PK11LIST="$TOP/bin/pkcs11/pkcs11-list -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||
RESOLVE=$TOP/lib/samples/resolve
|
||||
REVOKE=$TOP/bin/dnssec/dnssec-revoke
|
||||
RNDC=$TOP/bin/rndc/rndc
|
||||
RNDCCONFGEN=$TOP/bin/confgen/rndc-confgen
|
||||
RRCHECKER=$TOP/bin/tools/named-rrchecker
|
||||
SETTIME=$TOP/bin/dnssec/dnssec-settime
|
||||
SIGNER=$TOP/bin/dnssec/dnssec-signzone
|
||||
TSIGKEYGEN=$TOP/bin/confgen/tsig-keygen
|
||||
VERIFY=$TOP/bin/dnssec/dnssec-verify
|
||||
WIRETEST=$TOP/bin/tests/wire_test
|
||||
|
||||
RANDFILE=$TOP/bin/tests/system/random.data
|
||||
@@ -65,13 +66,16 @@ MAKEJOURNAL=$TOP/bin/tests/makejournal
|
||||
PIPEQUERIES=$TOP/bin/tests/system/pipelined/pipequeries
|
||||
SAMPLEUPDATE=$TOP/lib/samples/sample-update
|
||||
|
||||
# we don't want a KRB5_CONFIG setting breaking the tests
|
||||
KRB5_CONFIG=/dev/null
|
||||
|
||||
# The "stress" test is not run by default since it creates enough
|
||||
# load on the machine to make it unusable to other users.
|
||||
# v6synth
|
||||
SUBDIRS="acl additional addzone allow_query autosign builtin
|
||||
cacheclean case catz chain
|
||||
cacheclean case catz cds chain
|
||||
checkconf @CHECKDS@ checknames checkzone cookie @COVERAGE@
|
||||
database digdelv dlv dlvauto dlz dlzexternal
|
||||
database digdelv dlv dlz dlzexternal
|
||||
dns64 dnssec @DNSTAP@ dscp dsdigest dyndb ecdsa eddsa
|
||||
emptyzones fetchlimit filter-aaaa formerr geoip glue gost
|
||||
inline integrity ixfr keepalive @KEYMGR@ legacy limits
|
||||
@@ -135,8 +139,59 @@ NZD=@NZD_TOOLS@
|
||||
|
||||
. ${TOP}/version
|
||||
|
||||
#
|
||||
# Set up color-coded test output
|
||||
#
|
||||
if test -t 1 && type tput > /dev/null 2>&1 ; then
|
||||
COLOR_FAIL=`tput setaf 1` # red
|
||||
COLOR_WARN=`tput setaf 3` # yellow
|
||||
COLOR_PASS=`tput setaf 2` # green
|
||||
COLOR_INFO=`tput bold` # bold
|
||||
COLOR_NONE=`tput sgr0`
|
||||
else
|
||||
# set to empty strings so printf succeeds
|
||||
COLOR_FAIL=''
|
||||
COLOR_WARN=''
|
||||
COLOR_PASS=''
|
||||
COLOR_INFO=''
|
||||
COLOR_NONE=''
|
||||
fi
|
||||
|
||||
if type printf > /dev/null 2>&1
|
||||
then
|
||||
echofail () {
|
||||
printf "${COLOR_FAIL}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
echowarn () {
|
||||
printf "${COLOR_WARN}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
echopass () {
|
||||
printf "${COLOR_PASS}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
echoinfo () {
|
||||
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
else
|
||||
echofail () {
|
||||
echo "$*"
|
||||
}
|
||||
echowarn () {
|
||||
echo "$*"
|
||||
}
|
||||
echopass () {
|
||||
echo "$*"
|
||||
}
|
||||
echoinfo () {
|
||||
echo "$*"
|
||||
}
|
||||
fi
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
export ARPANAME
|
||||
export BIGKEY
|
||||
export CDS
|
||||
export CHECKZONE
|
||||
export DESCRIPTION
|
||||
export DIG
|
||||
@@ -150,6 +205,7 @@ export KEYFRLAB
|
||||
export KEYGEN
|
||||
export KEYSETTOOL
|
||||
export KEYSIGNER
|
||||
export KRB5_CONFIG
|
||||
export MAKEJOURNAL
|
||||
export MDIG
|
||||
export NAMED
|
||||
|
||||
@@ -71,6 +71,9 @@ MAKEJOURNAL=$TOP/Build/$VSCONF/makejournal@EXEEXT@
|
||||
PIPEQUERIES=$TOP/Build/$VSCONF/pipequeries@EXEEXT@
|
||||
# to port SAMPLEUPDATE=$TOP/lib/samples/sample-update
|
||||
|
||||
# we don't want a KRB5_CONFIG setting breaking the tests
|
||||
KRB5_CONFIG=NUL
|
||||
|
||||
# The "stress" test is not run by default since it creates enough
|
||||
# load on the machine to make it unusable to other users.
|
||||
# v6synth
|
||||
@@ -139,6 +142,43 @@ NZD=@NZD_TOOLS@
|
||||
|
||||
. ${TOP}/version
|
||||
|
||||
#
|
||||
# Set up color-coded test output
|
||||
#
|
||||
if test -t 1 && type tput > /dev/null; then
|
||||
COLOR_FAIL=`tput setaf 1` # red
|
||||
COLOR_WARN=`tput setaf 3` # yellow
|
||||
COLOR_PASS=`tput setaf 2` # green
|
||||
COLOR_INFO=`tput bold` # bold
|
||||
COLOR_NONE=`tput sgr0`
|
||||
else
|
||||
# set to empty strings so printf succeeds
|
||||
COLOR_FAIL=''
|
||||
COLOR_WARN=''
|
||||
COLOR_PASS=''
|
||||
COLOR_INFO=''
|
||||
COLOR_NONE=''
|
||||
fi
|
||||
|
||||
echofail () {
|
||||
printf "${COLOR_FAIL}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
echowarn () {
|
||||
printf "${COLOR_WARN}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
echopass () {
|
||||
printf "${COLOR_PASS}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
echoinfo () {
|
||||
printf "${COLOR_INFO}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
|
||||
#
|
||||
# Export command paths
|
||||
#
|
||||
export ARPANAME
|
||||
export BIGKEY
|
||||
export CHECKZONE
|
||||
@@ -154,6 +194,7 @@ export KEYFRLAB
|
||||
export KEYGEN
|
||||
export KEYSETTOOL
|
||||
export KEYSIGNER
|
||||
export KRB5_CONFIG
|
||||
export MAKEJOURNAL
|
||||
export MDIG
|
||||
export NAMED
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
# Copyright (C) 2011, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
rm -f ns1/K*
|
||||
rm -f ns1/*.signed
|
||||
rm -f ns1/*.db
|
||||
rm -f ns1/bind.keys
|
||||
rm -f ns1/*.mkeys.jnl
|
||||
rm -f ns1/*.mkeys
|
||||
rm -f */named.run
|
||||
rm -f */named.memstats
|
||||
rm -f ns1/dsset-*.
|
||||
rm -f ns2/*.mkeys
|
||||
rm -f ns2/*.mkeys.jnl
|
||||
rm -f dig.out.ns?.test*
|
||||
rm -f ns2/named.secroots
|
||||
rm -f ns*/named.lock
|
||||
@@ -1,37 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2011, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*/
|
||||
|
||||
/* $Id: named.conf,v 1.2 2011/03/01 22:44:04 marka Exp $ */
|
||||
|
||||
// NS1
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
transfer-source 10.53.0.1;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify yes;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
};
|
||||
|
||||
zone "." {
|
||||
type master;
|
||||
file "root.db";
|
||||
};
|
||||
|
||||
zone "dlv.isc.org" {
|
||||
type master;
|
||||
file "dlv.isc.org.db.signed";
|
||||
};
|
||||
@@ -1,20 +0,0 @@
|
||||
; Copyright (C) 2011, 2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
; $Id: root.db.in,v 1.2 2011/03/01 22:44:04 marka Exp $
|
||||
|
||||
$TTL 300
|
||||
. IN SOA gson.nominum.com. a.root.servers.nil. (
|
||||
2000042100 ; serial
|
||||
600 ; refresh
|
||||
600 ; retry
|
||||
1200 ; expire
|
||||
600 ; minimum
|
||||
)
|
||||
. NS a.root-servers.nil.
|
||||
a.root-servers.nil. A 10.53.0.1
|
||||
|
||||
dlv.isc.org. NS a.root-servers.nil.
|
||||
@@ -1,44 +0,0 @@
|
||||
#!/bin/sh -e
|
||||
#
|
||||
# Copyright (C) 2011, 2012, 2014, 2016, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
SYSTEMTESTTOP=../..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
zone=dlv.isc.org
|
||||
infile=dlv.isc.org.db.in
|
||||
zonefile=dlv.isc.org.db
|
||||
|
||||
dlvkey=`$KEYGEN -q -r $RANDFILE -a RSAMD5 -b 1024 -n zone $zone`
|
||||
cat $infile $dlvkey.key > $zonefile
|
||||
$SIGNER -P -g -r $RANDFILE -o $zone $zonefile > /dev/null
|
||||
|
||||
zone=.
|
||||
infile=root.db.in
|
||||
zonefile=root.db
|
||||
|
||||
rootkey=`$KEYGEN -q -r $RANDFILE -a RSAMD5 -b 1024 -n zone $zone`
|
||||
cat $infile $rootkey.key > $zonefile
|
||||
$SIGNER -P -g -r $RANDFILE -o $zone $zonefile > /dev/null
|
||||
|
||||
# Create bind.keys file for the use of the resolving server
|
||||
echo "managed-keys {" > bind.keys
|
||||
cat $dlvkey.key | grep -v '^; ' | $PERL -n -e '
|
||||
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
|
||||
local $key = join("", @rest);
|
||||
print <<EOF
|
||||
"$dn" initial-key $flags $proto $alg "$key";
|
||||
EOF
|
||||
' >> bind.keys
|
||||
cat $rootkey.key | grep -v '^; ' | $PERL -n -e '
|
||||
local ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
|
||||
local $key = join("", @rest);
|
||||
print <<EOF
|
||||
"$dn" initial-key $flags $proto $alg "$key";
|
||||
EOF
|
||||
' >> bind.keys
|
||||
echo "};" >> bind.keys
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user