Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c65f307d57 | ||
|
|
3b8a52264c | ||
|
|
db00eb2fa9 | ||
|
|
8b5aa19ed9 | ||
|
|
a8595262f7 | ||
|
|
c48979e6c5 | ||
|
|
ca52242661 | ||
|
|
3f2de6d39c | ||
|
|
fc834aa4bc | ||
|
|
008b73fb41 | ||
|
|
04ce124279 | ||
|
|
057e9fdb51 | ||
|
|
f1a887a0b9 | ||
|
|
d9e96809ac | ||
|
|
510306c654 | ||
|
|
9d3205e894 | ||
|
|
d98f446d3f | ||
|
|
c8ed70a108 | ||
|
|
ba26c6eb48 | ||
|
|
30610eb9a5 | ||
|
|
3705605e0b | ||
|
|
cd40c9fe61 | ||
|
|
2ebc4776ca | ||
|
|
ddd871bbea | ||
|
|
7b65ea4c11 | ||
|
|
417df8cfbc | ||
|
|
2627287dbc | ||
|
|
33887dd941 | ||
|
|
617696fbfc | ||
|
|
241cf78fee | ||
|
|
5aa375f0d8 | ||
|
|
71325852f1 | ||
|
|
89d5ecb04d | ||
|
|
9fc4be226d | ||
|
|
e1792341ac | ||
|
|
1b9b826518 | ||
|
|
d6a9407908 | ||
|
|
d60557be82 | ||
|
|
4c0b0fa6a5 | ||
|
|
2ceb4b6a98 | ||
|
|
98b460e604 | ||
|
|
1cd3516d54 | ||
|
|
6e48abc503 | ||
|
|
a3af2c57e7 | ||
|
|
48332d4478 | ||
|
|
c9d56a8185 | ||
|
|
403cc1fa12 | ||
|
|
33bddbb5d1 | ||
|
|
ed10608663 | ||
|
|
d7461772bb | ||
|
|
5ed13fe426 | ||
|
|
efa5f7ed54 | ||
|
|
02d95d0b62 | ||
|
|
54de054dd5 | ||
|
|
2c87ab1cca | ||
|
|
f9c07c78bc | ||
|
|
3a19e9ea19 | ||
|
|
0b2b6b2ed1 | ||
|
|
a73350a210 | ||
|
|
a00f1df736 | ||
|
|
1d86b202ad | ||
|
|
6a51b66197 | ||
|
|
053a716ae0 | ||
|
|
d80b6ec879 | ||
|
|
0d20df220e | ||
|
|
4a8b3a8ac0 | ||
|
|
52beeed444 | ||
|
|
443449863b | ||
|
|
44c0cc881f | ||
|
|
cbf32b901b | ||
|
|
22d5355782 | ||
|
|
ab78e350dd | ||
|
|
7fac94f589 | ||
|
|
a5ad6b16c5 | ||
|
|
d3506c9728 | ||
|
|
93ad3eea90 | ||
|
|
edab51b420 | ||
|
|
5d5cf12a85 | ||
|
|
4db3189de2 | ||
|
|
b3cd04b95a | ||
|
|
cd9bbe6dea | ||
|
|
f03aaaa6b5 | ||
|
|
d883aab05f | ||
|
|
48213633ce | ||
|
|
9679c8c20a | ||
|
|
6d50f7d924 | ||
|
|
451113b4a9 | ||
|
|
ac28cc14e1 | ||
|
|
4293a2f4bf | ||
|
|
57a328d67e | ||
|
|
954782d78a | ||
|
|
49c31702bd | ||
|
|
9cfd0ecccf | ||
|
|
9b10cfef56 | ||
|
|
53800281fe | ||
|
|
fefb2d2662 | ||
|
|
37cccbab8d | ||
|
|
4302b4f3c4 | ||
|
|
ae76cd086e | ||
|
|
1d3ba54d6c | ||
|
|
72bd0db6cf | ||
|
|
2b632a232f | ||
|
|
aed7eb0c74 | ||
|
|
d95ae93dd3 | ||
|
|
a7ec7eb6ed | ||
|
|
06d8b1071d | ||
|
|
46919579bb | ||
|
|
d6a60f2905 | ||
|
|
e6de6deec9 | ||
|
|
dd430c3093 | ||
|
|
6d069edb59 | ||
|
|
4b44351e65 | ||
|
|
7c3430a24e | ||
|
|
44381929e2 | ||
|
|
a6dcdc535c | ||
|
|
d502569902 | ||
|
|
b23c8aa5e8 | ||
|
|
e4144fb9cf | ||
|
|
664b8f04f5 | ||
|
|
022649abc3 | ||
|
|
fd00bac736 | ||
|
|
94354d4655 | ||
|
|
ced15edea1 | ||
|
|
90f4c1c5a2 | ||
|
|
36ee99c5ee | ||
|
|
4b5e1da0e3 | ||
|
|
51ec36c826 | ||
|
|
fac23cf939 | ||
|
|
7c210a2b3b | ||
|
|
b791ab542b | ||
|
|
9836d5bc17 | ||
|
|
2a047af31e | ||
|
|
6f8d363514 | ||
|
|
12d9681442 | ||
|
|
91a0cb5da3 | ||
|
|
f30bdd1aac | ||
|
|
326a334b49 | ||
|
|
f4daf6e0e7 | ||
|
|
bb9c1654e2 | ||
|
|
b10d28d1e0 | ||
|
|
266e3ed52a | ||
|
|
ad008f7dbf | ||
|
|
3384455659 | ||
|
|
b5cd146033 | ||
|
|
5381ac0fcc | ||
|
|
59528d0e9d | ||
|
|
03de34194d | ||
|
|
c19ebde14b | ||
|
|
c14dc46319 | ||
|
|
78da483941 | ||
|
|
73e615fcfa | ||
|
|
36bc018275 | ||
|
|
e976db255f | ||
|
|
4b40266a1d | ||
|
|
8751585841 | ||
|
|
b8a96bfa78 | ||
|
|
570d1cf0bb | ||
|
|
e6c13ebb26 | ||
|
|
34ce90565c | ||
|
|
86595ed8cb | ||
|
|
d807ecde24 | ||
|
|
a1871e7f1d | ||
|
|
19eb5d0e83 | ||
|
|
9123da5362 | ||
|
|
f0c6aef542 | ||
|
|
9bdc24a9fd | ||
|
|
601cb4e4cc | ||
|
|
3c1d4298af | ||
|
|
49f244406c | ||
|
|
ae83801e2b | ||
|
|
f63e696967 | ||
|
|
7f828a213c | ||
|
|
3bcd05f081 | ||
|
|
0cd1e5ed28 | ||
|
|
14a4a799c0 | ||
|
|
b558346437 | ||
|
|
14d10521ba | ||
|
|
ca528766d6 | ||
|
|
dd358e6a21 | ||
|
|
bded8af7b8 | ||
|
|
07b4859dec | ||
|
|
2bf44c6cd4 | ||
|
|
673aa9f626 | ||
|
|
839ed7894b | ||
|
|
135519e59a | ||
|
|
c808255682 | ||
|
|
a4f38bec6a | ||
|
|
b786171423 | ||
|
|
b9a1c31df1 | ||
|
|
1eb640049c | ||
|
|
b9dc9b68cd | ||
|
|
59a7f75b7e | ||
|
|
5f71d9c6ac | ||
|
|
fb40bc061f | ||
|
|
a4141fcf98 | ||
|
|
317e36d47e | ||
|
|
0b8632e662 | ||
|
|
779aa2c9d9 | ||
|
|
926f2dedbd | ||
|
|
03b8e7ccb7 | ||
|
|
69e84ab9c1 | ||
|
|
51ec6f6500 | ||
|
|
1711e61549 | ||
|
|
eee6f51d05 | ||
|
|
a912f31398 | ||
|
|
afa81ee4e4 | ||
|
|
4e33942742 | ||
|
|
d1c7b79183 | ||
|
|
4084ba1085 | ||
|
|
257b0456f1 | ||
|
|
00f9ed8f8b | ||
|
|
f3bcd1485f | ||
|
|
9f916b000e | ||
|
|
5b5930dca1 | ||
|
|
dc234e3819 | ||
|
|
7615e86fae | ||
|
|
5efc32ebae | ||
|
|
98eda76eb6 | ||
|
|
2e637325ed | ||
|
|
4b4f33e676 | ||
|
|
895eabd376 | ||
|
|
3cf11418b5 | ||
|
|
111d08a6ad | ||
|
|
fcabb55942 | ||
|
|
db8acb4898 | ||
|
|
dd7bd1c23f | ||
|
|
e56cc07f50 | ||
|
|
81faafd508 | ||
|
|
0471d1c1ce | ||
|
|
c0511688b5 | ||
|
|
f1471bc2e1 | ||
|
|
cbe8034dc8 | ||
|
|
244ac0601f | ||
|
|
81550c67da | ||
|
|
3c30d095c4 | ||
|
|
2a57d0b00c | ||
|
|
38a973a33f | ||
|
|
f3577e4635 | ||
|
|
9da902a201 | ||
|
|
6622c7a70a | ||
|
|
1097a209e1 | ||
|
|
8a128151f9 | ||
|
|
3dece71b91 | ||
|
|
f5d3250d90 | ||
|
|
d108e86cc8 | ||
|
|
757cff6644 | ||
|
|
44e2088449 | ||
|
|
de73904d03 | ||
|
|
fc19182e97 | ||
|
|
92424e23fa | ||
|
|
5aeb99786e | ||
|
|
3fcf98c8d3 | ||
|
|
420f84f3f5 | ||
|
|
b56948743a | ||
|
|
5d49f0ac39 | ||
|
|
c434cc69d7 | ||
|
|
5686c33068 | ||
|
|
8a83592e6a | ||
|
|
5c0cc1ee8b | ||
|
|
5570f6bbdc | ||
|
|
747736d361 | ||
|
|
2f9ae94296 | ||
|
|
a2e89ff0c1 | ||
|
|
1957bcaa99 | ||
|
|
9ba3e3f1b5 | ||
|
|
3781448c89 | ||
|
|
55cca87d8a | ||
|
|
787f2a7e03 | ||
|
|
c01679142a | ||
|
|
77c2a8bcbd | ||
|
|
d1503cbfa2 | ||
|
|
4cacdcc15b | ||
|
|
f56b88f72e | ||
|
|
a2a69725ef | ||
|
|
ab7036488e | ||
|
|
81fcde5953 | ||
|
|
f7f4eef5c5 | ||
|
|
df42771a54 | ||
|
|
590362fa48 | ||
|
|
00807c03af | ||
|
|
b104a9bc50 | ||
|
|
49462cf974 | ||
|
|
7c95192691 | ||
|
|
570f358252 | ||
|
|
99d4339093 | ||
|
|
9c509c2684 | ||
|
|
f55e4c878b | ||
|
|
3128bd96f7 | ||
|
|
6dad6b57c0 | ||
|
|
e957825eee | ||
|
|
4d3e7d0b7d | ||
|
|
646bb64246 | ||
|
|
4ae2713640 | ||
|
|
723433cbc6 | ||
|
|
1fe0c51f9b | ||
|
|
9dd11ee258 | ||
|
|
209b2e53d1 | ||
|
|
1eeda8cd23 | ||
|
|
a5dc24b25a | ||
|
|
4c0e9d0bdf | ||
|
|
7d6eaad1bd | ||
|
|
f895e4aaf2 | ||
|
|
7354207e1b | ||
|
|
3549abe81d | ||
|
|
1dfdedf137 | ||
|
|
0b8790967e | ||
|
|
2890c98d4e | ||
|
|
363e6319b7 | ||
|
|
11aedb1fae | ||
|
|
8854e284fd | ||
|
|
c9945d6148 | ||
|
|
9a1caf99ef | ||
|
|
6399a70cb4 | ||
|
|
6e0b93e5a0 | ||
|
|
fe46d5bc34 | ||
|
|
fea6b5bf10 | ||
|
|
cc1292d694 | ||
|
|
d584223653 | ||
|
|
95a8e42e57 | ||
|
|
f8b3aa97df | ||
|
|
d5c795942f | ||
|
|
ce3907e9fe | ||
|
|
eaba8dd799 | ||
|
|
96f0bbd4d5 | ||
|
|
d02f807a24 | ||
|
|
cdace7cac1 | ||
|
|
e6ef64c385 | ||
|
|
03a6a78b55 | ||
|
|
9a1f0ea873 | ||
|
|
e7684c7b64 | ||
|
|
2c370d93b4 | ||
|
|
c29e344f07 | ||
|
|
e48b3f1a00 | ||
|
|
0b792bd37b | ||
|
|
be492cf28d | ||
|
|
60ce0ed411 | ||
|
|
8ab398a90d | ||
|
|
6cfcc6e8a2 | ||
|
|
42013c43f3 | ||
|
|
f1c236d95d | ||
|
|
97543354d2 | ||
|
|
9fc5e48b14 | ||
|
|
955732d29c | ||
|
|
5d1e7be582 | ||
|
|
32fc6c85f4 | ||
|
|
9badc4dc90 | ||
|
|
e3e6888946 | ||
|
|
0771dd3be8 | ||
|
|
11db639945 | ||
|
|
3a3f40e372 | ||
|
|
6f67546cd6 | ||
|
|
a8750a8805 | ||
|
|
312fa7f65e | ||
|
|
d8cf7aedfa | ||
|
|
e317a675a1 | ||
|
|
134248531c | ||
|
|
2b5615b9d7 | ||
|
|
f77d5599ec | ||
|
|
79eed4e5c6 | ||
|
|
7d499f8fb8 | ||
|
|
42173037ee | ||
|
|
8e05e2e9d5 | ||
|
|
e0dd3757cb | ||
|
|
b62e6418b5 | ||
|
|
41915e88cd | ||
|
|
77db0cb929 | ||
|
|
f6ccd59e8b | ||
|
|
a8dd98fbac | ||
|
|
5aaee26ed0 | ||
|
|
0bdc3df5a0 | ||
|
|
2b1131cb28 | ||
|
|
bc235cf477 | ||
|
|
0f9f1ece14 | ||
|
|
28af0de764 | ||
|
|
5098c95452 | ||
|
|
00b57b0120 | ||
|
|
cbb2edb8d3 | ||
|
|
e21103f2d3 | ||
|
|
9e499ddbf6 | ||
|
|
39344dfb3e | ||
|
|
04961a7e6b | ||
|
|
62fd8827c7 | ||
|
|
ac04d7b348 | ||
|
|
24f23e7fad | ||
|
|
af7b462b30 | ||
|
|
14ea08c759 | ||
|
|
9bb0b30bc2 | ||
|
|
7dfef18b05 | ||
|
|
f1b9bd6f07 | ||
|
|
a78a9d37a8 | ||
|
|
95ecdcd762 | ||
|
|
52f98c5734 | ||
|
|
6a1f24a863 | ||
|
|
6713c6703e | ||
|
|
695c997e6f | ||
|
|
a654756c3e | ||
|
|
5a941fbd88 | ||
|
|
7706f22924 | ||
|
|
42cc7f5456 | ||
|
|
fab67c074a | ||
|
|
ea054d024a | ||
|
|
b2026bd9e8 | ||
|
|
47c8deee52 | ||
|
|
0b7b1161c2 | ||
|
|
fd8adb1282 | ||
|
|
c62a7c88b8 | ||
|
|
24cfee942f | ||
|
|
cd3b656001 | ||
|
|
ce796ac1f4 | ||
|
|
44e6bb8b93 | ||
|
|
3569487875 | ||
|
|
1eb7a9e10b | ||
|
|
3dcf121064 | ||
|
|
5adc0baaca | ||
|
|
68eb9a7c6a | ||
|
|
34db730ee3 | ||
|
|
8136b09fa8 | ||
|
|
90ff5a551a | ||
|
|
db87352742 | ||
|
|
32c86e29e2 | ||
|
|
3663f61e0e | ||
|
|
8975a0830b | ||
|
|
d47c1d5dd0 | ||
|
|
644a2197f4 | ||
|
|
8ceaa19698 | ||
|
|
36dd373ab4 | ||
|
|
0a8c47bae5 | ||
|
|
c6553eb3fc | ||
|
|
fd4e3a650d | ||
|
|
d45f9e413f | ||
|
|
ac3d9b97a3 | ||
|
|
1e2f40d01b | ||
|
|
48f16f223c | ||
|
|
a363455b58 | ||
|
|
3853b3cf6d | ||
|
|
d07053c8f6 | ||
|
|
0ef5b8edb7 | ||
|
|
821f041d8c | ||
|
|
fec032588b | ||
|
|
82f5bce1bb | ||
|
|
a00e54cf0e | ||
|
|
5ab252183b | ||
|
|
977dc54ef6 | ||
|
|
a9dca5831b | ||
|
|
e43925f284 | ||
|
|
e1e800dd40 | ||
|
|
0dd6c2be70 | ||
|
|
bb51694d03 | ||
|
|
9aac7f52f8 | ||
|
|
30a50f9be4 | ||
|
|
56106437b0 | ||
|
|
8973d4bd16 | ||
|
|
9279641496 | ||
|
|
fbd9c5c97f | ||
|
|
56e1b76a88 | ||
|
|
4e97f7dccc | ||
|
|
1bbba52750 | ||
|
|
5d5d751c7f | ||
|
|
ce52ac1178 | ||
|
|
c0e0643fc5 | ||
|
|
14ecd7d79e | ||
|
|
7e05848870 | ||
|
|
2e54b1be29 | ||
|
|
387cc00121 | ||
|
|
85059c2937 | ||
|
|
7ab1fb2a8d | ||
|
|
b675ace6c9 | ||
|
|
d0a73c7da6 | ||
|
|
bae12f569d | ||
|
|
aca283919d | ||
|
|
915af3c950 | ||
|
|
043df1be12 | ||
|
|
62bc30e08f | ||
|
|
9a2c4bf11e | ||
|
|
86f60c0807 | ||
|
|
1a980e8124 | ||
|
|
ab85681c11 | ||
|
|
2846465719 | ||
|
|
af356955e2 | ||
|
|
28323f5ebf | ||
|
|
e56d95847b | ||
|
|
e517c18d98 | ||
|
|
126b3e0bd7 | ||
|
|
6d6e94bee7 | ||
|
|
8783735f89 | ||
|
|
ae52c2117e | ||
|
|
2691e729f0 | ||
|
|
6c6d93b29d | ||
|
|
02bbf1e2b9 | ||
|
|
4501f646ee | ||
|
|
64fbffbbaa | ||
|
|
158ab9afd4 | ||
|
|
22fda5c719 | ||
|
|
a25aa889e1 | ||
|
|
5bc68d16e2 | ||
|
|
4cd01cd7c5 | ||
|
|
6c499a0c08 | ||
|
|
20f2d9b41b | ||
|
|
5da97eeea6 | ||
|
|
4157e6ab73 | ||
|
|
92325d3150 | ||
|
|
61752bf8ac | ||
|
|
ebbedd6c03 | ||
|
|
52a8fb31c7 | ||
|
|
bdde335cca | ||
|
|
9c47bad86a | ||
|
|
4d2d3b49ce | ||
|
|
d54f3f8b8c | ||
|
|
d4596baed4 | ||
|
|
4419d7bf6b | ||
|
|
47b850348c | ||
|
|
bb939a03ff | ||
|
|
56ed1275c6 | ||
|
|
4dea5cb799 | ||
|
|
effd16ab25 | ||
|
|
aaf81ca6ef | ||
|
|
3e7fa15ca3 | ||
|
|
6283c1cc7e | ||
|
|
9491616e5c | ||
|
|
db9cfde1ab | ||
|
|
4c7345bcb6 | ||
|
|
05b7c08a16 | ||
|
|
fa806cc7b3 | ||
|
|
d70bf76d80 | ||
|
|
571f0beee0 | ||
|
|
75815c1581 | ||
|
|
4d498b3dac | ||
|
|
505ec918d7 | ||
|
|
978a37c827 | ||
|
|
8ddc54e200 | ||
|
|
e65d4989a1 | ||
|
|
00ff786384 | ||
|
|
dc9543abb3 | ||
|
|
d5055665ca | ||
|
|
2e7d82443f | ||
|
|
2cbf633192 | ||
|
|
a197df137a | ||
|
|
0efc36c19a | ||
|
|
efff347f96 | ||
|
|
93aa9766e5 | ||
|
|
eb8c9bdd55 | ||
|
|
4d30aee3e2 | ||
|
|
45d76498d9 | ||
|
|
316b399f95 | ||
|
|
94cb73d96c | ||
|
|
1c672367a0 | ||
|
|
e02228125e | ||
|
|
ab389695b0 | ||
|
|
976d62aa23 | ||
|
|
a8e2ca6f7d | ||
|
|
de49b26eb0 | ||
|
|
f546769b8b | ||
|
|
9150e432aa | ||
|
|
2e4986e2c4 | ||
|
|
3ee94d7845 | ||
|
|
7ec9502ec5 | ||
|
|
031bca512d | ||
|
|
25e416fb67 | ||
|
|
07218e08ce | ||
|
|
6e236fbaf1 | ||
|
|
2f17238f94 | ||
|
|
5be7c6f4b3 | ||
|
|
5e80488270 | ||
|
|
7d1a7c46f5 | ||
|
|
55b48700da | ||
|
|
913f246307 | ||
|
|
c8cb612d39 | ||
|
|
f23fa0a3e5 | ||
|
|
ee7cf180b3 | ||
|
|
a157e0ac04 | ||
|
|
793d358cd6 | ||
|
|
8785f6fa34 | ||
|
|
d8f2eb249a | ||
|
|
129b731273 | ||
|
|
796a6c4e4e | ||
|
|
a177b07da1 | ||
|
|
42ed7e43dc | ||
|
|
ce6ecde3f3 | ||
|
|
8ffdf6759e | ||
|
|
8fd8b9fd26 | ||
|
|
1722728c80 | ||
|
|
be5d4cadfc | ||
|
|
cdc4388ac3 | ||
|
|
37e79bd79c | ||
|
|
8a8cd19eb0 | ||
|
|
2163a59d0d | ||
|
|
cfee8b1492 | ||
|
|
bd14aa6d8e | ||
|
|
f4bb54befb | ||
|
|
fb0b8f9bd7 | ||
|
|
d8798098e8 | ||
|
|
6bb57c776e | ||
|
|
ba1d7f3a07 | ||
|
|
d547465af5 | ||
|
|
18c49853e3 | ||
|
|
b958a13c37 | ||
|
|
bdc66eb5d9 | ||
|
|
2483a8c76d | ||
|
|
4886701c03 | ||
|
|
161fec84c7 | ||
|
|
ce5520b695 | ||
|
|
6999bee7ef | ||
|
|
32ba5a0494 | ||
|
|
127333c71f | ||
|
|
cbddd8a0a9 | ||
|
|
d3cd0729c9 | ||
|
|
a33237f070 | ||
|
|
bbae24c140 | ||
|
|
7416045f38 | ||
|
|
f1aaf45085 | ||
|
|
4e5edb35e4 | ||
|
|
8aac8358ec | ||
|
|
4889e06c3a | ||
|
|
f53b9ca88f | ||
|
|
7d05ae8b1d | ||
|
|
cc32080278 | ||
|
|
0fd344e77a | ||
|
|
f3a242d71d | ||
|
|
8965a0ba98 | ||
|
|
b0fd3a2fd1 | ||
|
|
da2c1b74ad | ||
|
|
79357f93c0 | ||
|
|
978a0d2555 | ||
|
|
1766a5d9e0 | ||
|
|
ce8ad08a45 | ||
|
|
4f4c18d643 | ||
|
|
2c85466c67 | ||
|
|
4551c58e30 | ||
|
|
d809ec6c14 | ||
|
|
2f3876d187 | ||
|
|
a0f4a3fa65 | ||
|
|
3c0f8d9146 | ||
|
|
d989a8b38e | ||
|
|
07c3365b0b | ||
|
|
7ef3953085 | ||
|
|
38c29c1b5b | ||
|
|
f3d3703fe3 | ||
|
|
2fbadaeec6 | ||
|
|
9b67f3d34b | ||
|
|
19e4098139 | ||
|
|
eee8084734 | ||
|
|
ea131d2e6a | ||
|
|
11cddb689f | ||
|
|
ffaa5a07dd | ||
|
|
e79dd268b6 | ||
|
|
83473b9758 | ||
|
|
67f0635f3c | ||
|
|
671505feb8 | ||
|
|
7043c6eaf5 | ||
|
|
774b07785c | ||
|
|
f8746cddbc | ||
|
|
1c8e5ea333 | ||
|
|
fd7f2c8f9d | ||
|
|
265554f895 | ||
|
|
3b9d451902 | ||
|
|
bed9ad79ba | ||
|
|
9482d8470b | ||
|
|
e420078c63 | ||
|
|
c9cb567f17 | ||
|
|
4d358c9bce | ||
|
|
7402615697 | ||
|
|
f3e2780dc8 | ||
|
|
da7f683abf | ||
|
|
e47754d7bf | ||
|
|
b6c1cdfffe | ||
|
|
e4280ed9f5 | ||
|
|
761ba4514f | ||
|
|
28f5400d0d | ||
|
|
e048436805 | ||
|
|
c506077da5 | ||
|
|
9fceb376c6 | ||
|
|
e7332343ed | ||
|
|
964749dfdb | ||
|
|
1a9be94f83 | ||
|
|
2e40cc94dc | ||
|
|
9d329a5e74 | ||
|
|
1877139a32 | ||
|
|
abce724ad9 | ||
|
|
4edbb773a1 | ||
|
|
87daa5471d | ||
|
|
591e37a7e2 | ||
|
|
fad7b2a6f8 | ||
|
|
5071e43c19 | ||
|
|
b7e9115793 | ||
|
|
7fff3295f5 | ||
|
|
d134dd9c8c | ||
|
|
e76936fd85 | ||
|
|
a3fd41157d | ||
|
|
3b9dee0baa | ||
|
|
1f578cdb12 | ||
|
|
9b1304be36 | ||
|
|
4b63853aa1 | ||
|
|
8184e5097c | ||
|
|
3cb8c49c73 | ||
|
|
2e83e3255a | ||
|
|
d330986374 | ||
|
|
8bc10bcf59 | ||
|
|
67d75732b6 | ||
|
|
307a1b563b | ||
|
|
b78e128a2f | ||
|
|
e73a5b0ce3 | ||
|
|
b089f43b7a | ||
|
|
1a75a5cee6 | ||
|
|
7941a9554f | ||
|
|
cc5e16e4d3 | ||
|
|
36f30f5731 | ||
|
|
961d256d73 | ||
|
|
dfc485b02e | ||
|
|
195277ca6d | ||
|
|
146202d6a8 | ||
|
|
68851ddb76 | ||
|
|
538da8c80d | ||
|
|
8fd4308bda | ||
|
|
0fb2cf1e44 | ||
|
|
97b7360ce1 | ||
|
|
6eb28eda1e | ||
|
|
b274f3fad7 | ||
|
|
a32a4ed945 | ||
|
|
d712b88048 | ||
|
|
7b0a653858 | ||
|
|
cd68cfffbf | ||
|
|
a6f09b2255 | ||
|
|
43828818a4 | ||
|
|
f78c688c4f | ||
|
|
82d4931440 | ||
|
|
2592e91516 | ||
|
|
629b978fd8 | ||
|
|
698a6f955e | ||
|
|
27d788cff3 | ||
|
|
06021b3529 | ||
|
|
b22a5b6fac | ||
|
|
610d13b456 | ||
|
|
23e6a908df | ||
|
|
b6cce0fb8b | ||
|
|
7e069cb16a | ||
|
|
d11791e24c | ||
|
|
7c960e89ea | ||
|
|
e9771830b8 | ||
|
|
b779342017 | ||
|
|
51a55ddbb7 | ||
|
|
b01ed54bad | ||
|
|
bd670d4a04 | ||
|
|
cd3593c38d | ||
|
|
d089387d7f | ||
|
|
8ccce7e24b | ||
|
|
d0cda3dc83 | ||
|
|
55a7961cf3 | ||
|
|
91dca0f8da | ||
|
|
11c862efff | ||
|
|
e1db1b8dcb | ||
|
|
473987d8d9 | ||
|
|
ffba2eb60d | ||
|
|
c20b89fcf8 | ||
|
|
40a770b932 | ||
|
|
69468e5417 | ||
|
|
a40c60e4c1 | ||
|
|
a17aff7421 | ||
|
|
73afbdc552 | ||
|
|
6847a29b54 | ||
|
|
c6b0384138 | ||
|
|
b9d524ed7e | ||
|
|
5c67d1d120 | ||
|
|
abbdf3d77e | ||
|
|
6e3f812afc | ||
|
|
cde8df8be4 | ||
|
|
2bddb0e2af | ||
|
|
8bbb9ac3e9 | ||
|
|
db2912b099 | ||
|
|
394848b053 | ||
|
|
66e58dc37e | ||
|
|
6b8414db37 | ||
|
|
e3aa835a8f | ||
|
|
8dde994d24 | ||
|
|
4286409d6b | ||
|
|
6abf541f9a | ||
|
|
51b9a8960a | ||
|
|
624bb177c4 | ||
|
|
768ded1102 | ||
|
|
a67dac5d21 | ||
|
|
3b7c849a3f | ||
|
|
b85007e0a6 | ||
|
|
4d1ed1283a | ||
|
|
1d45ad8f39 | ||
|
|
07c35f32f9 | ||
|
|
924fdad0e5 | ||
|
|
dfcf9bb0ed | ||
|
|
8981a07311 | ||
|
|
f86c15f649 | ||
|
|
f2642f4fb8 | ||
|
|
25a689ec7b | ||
|
|
85ea0edf2f | ||
|
|
c787a539d2 | ||
|
|
4afad2a047 | ||
|
|
bd55366bef | ||
|
|
01e7ecfea6 | ||
|
|
ab2d411996 | ||
|
|
0e805b58e8 | ||
|
|
c3fb2c4c77 | ||
|
|
65d63eda34 | ||
|
|
0d37958723 | ||
|
|
1e1c223a0a | ||
|
|
1fbb76ef4d | ||
|
|
89eed3d0b2 | ||
|
|
885a3d208e | ||
|
|
b3ff3bf2e4 | ||
|
|
d069658626 | ||
|
|
fd298a2da8 | ||
|
|
92c9d052a2 | ||
|
|
788f784191 | ||
|
|
71c4fad592 | ||
|
|
e4b4361284 | ||
|
|
15bfe4f2e1 | ||
|
|
ef12cdc653 | ||
|
|
6acc306b10 | ||
|
|
6335043890 | ||
|
|
31df6789d8 | ||
|
|
1eba2c5b06 | ||
|
|
a43d648b95 | ||
|
|
e08e800387 | ||
|
|
d8d04edfba | ||
|
|
d27a061fa2 | ||
|
|
7bf6750330 | ||
|
|
f881c7b4b8 | ||
|
|
719b1d7fdc | ||
|
|
ef978c9279 | ||
|
|
acc3fa04b7 | ||
|
|
48a7efafc2 | ||
|
|
b9a276064b | ||
|
|
62ff4bcc07 | ||
|
|
32f2ae3791 | ||
|
|
ff8bf617e7 | ||
|
|
7ef3bb20cf | ||
|
|
9463a781fb | ||
|
|
aa3da7a232 | ||
|
|
44c8202b0c | ||
|
|
50f6054294 | ||
|
|
56183a3917 | ||
|
|
3365064fb6 | ||
|
|
91e5a99b9b | ||
|
|
985d9d9c84 | ||
|
|
38301052e1 | ||
|
|
faa0de1349 | ||
|
|
e02de04e97 | ||
|
|
5ac5d90620 | ||
|
|
dee1f1a498 | ||
|
|
a85cc41486 | ||
|
|
8baf859063 | ||
|
|
a597bd52a6 | ||
|
|
9a36a1bba3 | ||
|
|
8555fe8b4b | ||
|
|
7cc241ca39 | ||
|
|
e2062879c1 | ||
|
|
a520662ed4 | ||
|
|
76085b7e9c | ||
|
|
7eea756858 | ||
|
|
a6bb44493c | ||
|
|
0eff9a184a | ||
|
|
5caf126267 | ||
|
|
a04a390195 | ||
|
|
1b53e939ed | ||
|
|
d49e9181a0 | ||
|
|
2621db706e | ||
|
|
c2637c8429 | ||
|
|
a96393e837 | ||
|
|
ccfe54f541 | ||
|
|
1b25d8a0ca | ||
|
|
78d0cb0a7d | ||
|
|
0b9f7f8a38 | ||
|
|
15c46a397e | ||
|
|
893c65ce3f | ||
|
|
fd13fef299 | ||
|
|
570f56ab77 | ||
|
|
bf98324956 | ||
|
|
ada6846a10 | ||
|
|
99138abe38 | ||
|
|
0f219714e1 | ||
|
|
f285dd9a08 | ||
|
|
1fc7be36eb | ||
|
|
ce6f3d4bb4 | ||
|
|
7f26cad247 | ||
|
|
3fe7acaa6f | ||
|
|
435ae2f29a | ||
|
|
fced495d47 | ||
|
|
cb32cd98bd | ||
|
|
c37e78539c | ||
|
|
4f60a84e34 | ||
|
|
dad333b644 | ||
|
|
3f2b7e1006 | ||
|
|
a4c60a9f08 | ||
|
|
89234643e1 | ||
|
|
aeed047495 | ||
|
|
d1fa8be611 | ||
|
|
3d512a7e26 | ||
|
|
5bc06a0a11 | ||
|
|
a9c47414b3 | ||
|
|
8b637a1d2f | ||
|
|
57e44efc73 | ||
|
|
ec3d830bc5 | ||
|
|
918fabb65f | ||
|
|
1954f8d2bf | ||
|
|
52d90da41e | ||
|
|
6d24292830 | ||
|
|
b57a38ae43 | ||
|
|
0e67a73bdf | ||
|
|
af4b81f944 | ||
|
|
68ff5f0ebd | ||
|
|
0e64948274 | ||
|
|
06f582f23e | ||
|
|
960ddd5381 | ||
|
|
d2c960cfc2 | ||
|
|
cba155154b | ||
|
|
1a9fc624ca | ||
|
|
d181c28c60 | ||
|
|
c527b7fd5c | ||
|
|
a1c9db1baa | ||
|
|
9a16e0a5ae | ||
|
|
fcade0610f | ||
|
|
db7a7357a6 | ||
|
|
c9dc59eb90 | ||
|
|
648aef129d | ||
|
|
7c6bff3c4e | ||
|
|
ea95d85091 | ||
|
|
cb913177ae | ||
|
|
12a8574aea | ||
|
|
442421906b | ||
|
|
c3dd8bb9f0 | ||
|
|
bbeff24049 | ||
|
|
e410803919 | ||
|
|
c64ed484c8 | ||
|
|
7f6cc1b405 | ||
|
|
5f125df462 | ||
|
|
4988367b53 | ||
|
|
759a7b4ce3 | ||
|
|
03dcdb88a2 | ||
|
|
70ae48e5cb | ||
|
|
ccdeacf45e | ||
|
|
4ad0bc38e9 | ||
|
|
c6939f0bd4 | ||
|
|
3e74c7e5ff | ||
|
|
cdbae0013b | ||
|
|
6602848460 | ||
|
|
d571b33468 | ||
|
|
a077a3ae8a | ||
|
|
a111c8d739 | ||
|
|
e5565808e4 | ||
|
|
6ed14eff25 | ||
|
|
84700f9783 | ||
|
|
ce5476acf0 | ||
|
|
6756280242 | ||
|
|
2e5e429644 | ||
|
|
a490c09121 | ||
|
|
8d392f9093 | ||
|
|
9ecdb292c4 | ||
|
|
f9b50a4019 | ||
|
|
ad785e4f93 | ||
|
|
8758d36a5e | ||
|
|
138268b78a | ||
|
|
efb0d1e83d | ||
|
|
d7b82380ff | ||
|
|
15b18d8a38 | ||
|
|
8514320271 | ||
|
|
821f917db8 | ||
|
|
a9307de85e | ||
|
|
5e7f1a8d67 | ||
|
|
747035dcc5 | ||
|
|
9ae991751c | ||
|
|
fe4810f1f8 | ||
|
|
35025b6e88 | ||
|
|
6f1ac89c1a | ||
|
|
41a851861e | ||
|
|
3022633d79 | ||
|
|
e7c12bffbd | ||
|
|
f09352d20a | ||
|
|
38c2bdba0a | ||
|
|
235a64a5a4 | ||
|
|
91550e21cd | ||
|
|
5893689592 | ||
|
|
3d1bb8038e | ||
|
|
040c23e3d7 |
@@ -53,6 +53,7 @@
|
|||||||
|
|
||||||
(expand-file-name "/usr/local/opt/openssl@1.1/include")
|
(expand-file-name "/usr/local/opt/openssl@1.1/include")
|
||||||
(expand-file-name "/usr/local/opt/libxml2/include/libxml2")
|
(expand-file-name "/usr/local/opt/libxml2/include/libxml2")
|
||||||
|
(expand-file-name "/usr/local/opt/json-c/include/json-c/")
|
||||||
(expand-file-name "/usr/local/include")
|
(expand-file-name "/usr/local/include")
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
@@ -60,5 +61,28 @@
|
|||||||
|
|
||||||
(eval setq flycheck-clang-include-path include-directories)
|
(eval setq flycheck-clang-include-path include-directories)
|
||||||
(eval setq flycheck-cppcheck-include-path include-directories)
|
(eval setq flycheck-cppcheck-include-path include-directories)
|
||||||
|
(eval setq flycheck-gcc-include-path include-directories)
|
||||||
|
(eval setq flycheck-clang-args
|
||||||
|
(list
|
||||||
|
"-include"
|
||||||
|
(expand-file-name
|
||||||
|
(concat directory-of-current-dir-locals-file "config.h"))
|
||||||
|
)
|
||||||
|
)
|
||||||
|
(eval setq flycheck-gcc-args
|
||||||
|
(list
|
||||||
|
"-include"
|
||||||
|
(expand-file-name
|
||||||
|
(concat directory-of-current-dir-locals-file "config.h"))
|
||||||
|
)
|
||||||
|
)
|
||||||
|
(eval setq flycheck-cppcheck-args
|
||||||
|
(list
|
||||||
|
"--enable=all"
|
||||||
|
"--suppress=missingIncludeSystem"
|
||||||
|
(concat "-include=" (expand-file-name
|
||||||
|
(concat directory-of-current-dir-locals-file "config.h")))
|
||||||
|
)
|
||||||
|
)
|
||||||
)
|
)
|
||||||
))
|
))
|
||||||
|
|||||||
+1
-2
@@ -1,3 +1,2 @@
|
|||||||
*.sln.in eol=crlf
|
*.sln.in eol=crlf
|
||||||
*.vcxproj.in eol=crlf
|
*.vcxproj.* eol=crlf
|
||||||
*.vcxproj.filters.in eol=crlf
|
|
||||||
|
|||||||
+51
-29
@@ -1,36 +1,58 @@
|
|||||||
Makefile
|
|
||||||
config.log
|
|
||||||
config.h
|
|
||||||
config.cache
|
|
||||||
config.status
|
|
||||||
libtool
|
|
||||||
/isc-config.sh
|
|
||||||
/configure.lineno
|
|
||||||
autom4te.cache/
|
|
||||||
*.rej
|
|
||||||
*.orig
|
|
||||||
*.o
|
|
||||||
*.lo
|
|
||||||
*.so
|
|
||||||
*.a
|
|
||||||
*.la
|
|
||||||
*.gcno
|
|
||||||
*.gcda
|
|
||||||
*_test
|
|
||||||
*-symtbl.c
|
*-symtbl.c
|
||||||
timestamp
|
*.a
|
||||||
ans.run
|
*.gcda
|
||||||
named.run
|
*.gcno
|
||||||
named.memstats
|
*.la
|
||||||
gen.dSYM/
|
*.lo
|
||||||
|
*.o
|
||||||
|
*.orig
|
||||||
|
*.plist/ # ccc-analyzer store its results in .plist directories
|
||||||
|
*.rej
|
||||||
|
*.so
|
||||||
|
*_test
|
||||||
|
*~
|
||||||
.ccache/
|
.ccache/
|
||||||
|
.cproject
|
||||||
.deps/
|
.deps/
|
||||||
.dirstamp
|
.dirstamp
|
||||||
.libs/
|
.libs/
|
||||||
# ccc-analyzer store its results in .plist directories
|
|
||||||
*.plist/
|
|
||||||
*~
|
|
||||||
.project
|
.project
|
||||||
.cproject
|
|
||||||
.settings
|
.settings
|
||||||
kyua.log
|
/aclocal.m4
|
||||||
|
/ar-lib
|
||||||
|
/autom4te.cache/
|
||||||
|
/bind.keys.h
|
||||||
|
/compile
|
||||||
|
/config.cache
|
||||||
|
/config.guess
|
||||||
|
/config.h
|
||||||
|
/config.h.in
|
||||||
|
/config.log
|
||||||
|
/config.status
|
||||||
|
/config.sub
|
||||||
|
/configure
|
||||||
|
/configure.lineno
|
||||||
|
/depcomp
|
||||||
|
/install-sh
|
||||||
|
/isc-config.sh
|
||||||
|
/libltdl/*
|
||||||
|
/libtool
|
||||||
|
/ltmain.sh
|
||||||
|
/m4/libtool.m4
|
||||||
|
/m4/ltargz.m4
|
||||||
|
/m4/ltdl.m4
|
||||||
|
/m4/ltoptions.m4
|
||||||
|
/m4/ltsugar.m4
|
||||||
|
/m4/ltversion.m4
|
||||||
|
/m4/lt~obsolete.m4
|
||||||
|
/missing
|
||||||
|
/py-compile
|
||||||
|
/stamp-h1
|
||||||
|
/test-driver
|
||||||
|
Makefile
|
||||||
|
ans.run
|
||||||
|
gen.dSYM/
|
||||||
|
kyua.log
|
||||||
|
named.memstats
|
||||||
|
named.run
|
||||||
|
timestamp
|
||||||
|
|||||||
+241
-32
@@ -8,10 +8,18 @@ variables:
|
|||||||
CCACHE_DIR: "/ccache"
|
CCACHE_DIR: "/ccache"
|
||||||
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
||||||
|
|
||||||
|
# VirtualBox driver needs to set build_dir to "/builds" in gitlab-runner.toml
|
||||||
|
KYUA_RESULT: "$CI_PROJECT_DIR/kyua.results"
|
||||||
|
|
||||||
|
BUILD_PARALLEL_JOBS: 6
|
||||||
|
TEST_PARALLEL_JOBS: 6
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- precheck
|
- precheck
|
||||||
- build
|
- build
|
||||||
- test
|
- unit
|
||||||
|
- system
|
||||||
|
- docs
|
||||||
- push
|
- push
|
||||||
|
|
||||||
### Runner Tag Templates
|
### Runner Tag Templates
|
||||||
@@ -28,6 +36,12 @@ stages:
|
|||||||
|
|
||||||
### Docker Image Templates
|
### Docker Image Templates
|
||||||
|
|
||||||
|
# Alpine Linux
|
||||||
|
|
||||||
|
.alpine-3.10-amd64: &alpine_3_10_amd64_image
|
||||||
|
image: "$CI_REGISTRY_IMAGE:alpine-3.10-amd64"
|
||||||
|
<<: *linux_amd64
|
||||||
|
|
||||||
# CentOS
|
# CentOS
|
||||||
|
|
||||||
.centos-centos6-amd64: ¢os_centos6_amd64_image
|
.centos-centos6-amd64: ¢os_centos6_amd64_image
|
||||||
@@ -44,10 +58,6 @@ stages:
|
|||||||
image: "$CI_REGISTRY_IMAGE:debian-jessie-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-jessie-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
|
|
||||||
.debian-jessie-i386: &debian_jessie_i386_image
|
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-jessie-i386"
|
|
||||||
<<: *linux_i386
|
|
||||||
|
|
||||||
.debian-stretch-amd64: &debian_stretch_amd64_image
|
.debian-stretch-amd64: &debian_stretch_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-stretch-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-stretch-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
@@ -56,6 +66,10 @@ stages:
|
|||||||
image: "$CI_REGISTRY_IMAGE:debian-stretch-i386"
|
image: "$CI_REGISTRY_IMAGE:debian-stretch-i386"
|
||||||
<<: *linux_i386
|
<<: *linux_i386
|
||||||
|
|
||||||
|
.debian-buster-amd64: &debian_buster_amd64_image
|
||||||
|
image: "$CI_REGISTRY_IMAGE:debian-buster-amd64"
|
||||||
|
<<: *linux_i386
|
||||||
|
|
||||||
.debian-sid-amd64: &debian_sid_amd64_image
|
.debian-sid-amd64: &debian_sid_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
image: "$CI_REGISTRY_IMAGE:debian-sid-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
@@ -66,8 +80,8 @@ stages:
|
|||||||
|
|
||||||
# Fedora
|
# Fedora
|
||||||
|
|
||||||
.fedora-29-amd64: &fedora_29_amd64_image
|
.fedora-30-amd64: &fedora_30_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:fedora-29-amd64"
|
image: "$CI_REGISTRY_IMAGE:fedora-30-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
|
|
||||||
# Ubuntu
|
# Ubuntu
|
||||||
@@ -101,26 +115,64 @@ stages:
|
|||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
stage: precheck
|
stage: precheck
|
||||||
|
|
||||||
|
.autoconf: &autoconf_job
|
||||||
|
<<: *default_triggering_rules
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: precheck
|
||||||
|
script:
|
||||||
|
- autoreconf -fi
|
||||||
|
artifacts:
|
||||||
|
untracked: true
|
||||||
|
expire_in: "1 hour"
|
||||||
|
|
||||||
|
.configure: &configure |
|
||||||
|
./configure \
|
||||||
|
--disable-maintainer-mode \
|
||||||
|
--enable-developer \
|
||||||
|
--with-libtool \
|
||||||
|
--disable-static \
|
||||||
|
--with-cmocka \
|
||||||
|
--with-libxml2 \
|
||||||
|
--with-json-c \
|
||||||
|
--prefix=$HOME/.local \
|
||||||
|
--without-make-clean \
|
||||||
|
$EXTRA_CONFIGURE \
|
||||||
|
|| cat config.log
|
||||||
|
|
||||||
.build: &build_job
|
.build: &build_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: build
|
stage: build
|
||||||
before_script:
|
before_script:
|
||||||
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
||||||
script:
|
script:
|
||||||
- ./configure --enable-developer --with-libtool --disable-static --with-cmocka --prefix=$HOME/.local --without-make-clean $EXTRA_CONFIGURE || cat config.log
|
- *configure
|
||||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||||
- test -z "${RUN_MAKE_INSTALL}" || make install
|
- test -z "${RUN_MAKE_INSTALL}" || make install
|
||||||
|
dependencies:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
|
needs:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
artifacts:
|
artifacts:
|
||||||
untracked: true
|
untracked: true
|
||||||
expire_in: "1 hour"
|
expire_in: "1 hour"
|
||||||
|
|
||||||
|
.setup_interfaces: &setup_interfaces |
|
||||||
|
if [ "$(id -u)" -eq "0" ]; then
|
||||||
|
sh -x bin/tests/system/ifconfig.sh up;
|
||||||
|
else
|
||||||
|
sudo sh -x bin/tests/system/ifconfig.sh up;
|
||||||
|
fi
|
||||||
|
|
||||||
|
.setup_softhsm: &setup_softhsm |
|
||||||
|
sh -x util/prepare-softhsm2.sh
|
||||||
|
|
||||||
.system_test: &system_test_job
|
.system_test: &system_test_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: test
|
stage: system
|
||||||
retry: 2
|
retry: 2
|
||||||
before_script:
|
before_script:
|
||||||
- bash -x bin/tests/system/ifconfig.sh up
|
- *setup_interfaces
|
||||||
- bash -x util/prepare-softhsm2.sh
|
- *setup_softhsm
|
||||||
script:
|
script:
|
||||||
- ( cd bin/tests && make -j${TEST_PARALLEL_JOBS:-1} -k test V=1 )
|
- ( cd bin/tests && make -j${TEST_PARALLEL_JOBS:-1} -k test V=1 )
|
||||||
- test -s bin/tests/system/systests.output
|
- test -s bin/tests/system/systests.output
|
||||||
@@ -129,16 +181,22 @@ stages:
|
|||||||
expire_in: "1 week"
|
expire_in: "1 week"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
|
.kyua_report: &kyua_report_html |
|
||||||
|
kyua report-html \
|
||||||
|
--force \
|
||||||
|
--results-file "$KYUA_RESULT" \
|
||||||
|
--results-filter "" \
|
||||||
|
--output kyua_html
|
||||||
|
|
||||||
.unit_test: &unit_test_job
|
.unit_test: &unit_test_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: test
|
stage: unit
|
||||||
before_script:
|
before_script:
|
||||||
- export KYUA_RESULT="$CI_PROJECT_DIR/kyua.results"
|
- *setup_softhsm
|
||||||
- bash -x util/prepare-softhsm2.sh
|
|
||||||
script:
|
script:
|
||||||
- make unit
|
- make unit
|
||||||
after_script:
|
after_script:
|
||||||
- kyua report-html --force --results-file kyua.results --results-filter "" --output kyua_html
|
- *kyua_report_html
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- kyua.log
|
- kyua.log
|
||||||
@@ -151,6 +209,9 @@ stages:
|
|||||||
|
|
||||||
# Jobs in the precheck stage
|
# Jobs in the precheck stage
|
||||||
|
|
||||||
|
autoreconf:sid:amd64:
|
||||||
|
<<: *autoconf_job
|
||||||
|
|
||||||
misc:sid:amd64:
|
misc:sid:amd64:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
script:
|
script:
|
||||||
@@ -167,6 +228,7 @@ misc:sid:amd64:
|
|||||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||||
- xmllint --noout --nonet `git ls-files '*.xml' '*.docbook'`
|
- xmllint --noout --nonet `git ls-files '*.xml' '*.docbook'`
|
||||||
- xmllint --noout --nonet --html `git ls-files '*.html'`
|
- xmllint --noout --nonet --html `git ls-files '*.html'`
|
||||||
|
- sh util/check-win32util-configure
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- util/newcopyrights
|
- util/newcopyrights
|
||||||
@@ -176,17 +238,23 @@ misc:sid:amd64:
|
|||||||
|
|
||||||
🐞:sid:amd64:
|
🐞:sid:amd64:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
script: util/check-cocci
|
script:
|
||||||
|
- util/check-cocci
|
||||||
|
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||||
|
|
||||||
# Jobs for doc builds on Debian Sid (amd64)
|
# Jobs for doc builds on Debian Sid (amd64)
|
||||||
|
|
||||||
docs:sid:amd64:
|
docs:sid:amd64:
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
stage: build
|
stage: docs
|
||||||
script:
|
script:
|
||||||
- ./configure || cat config.log
|
- ./configure || cat config.log
|
||||||
- make -C doc/misc docbook
|
- make -C doc/misc docbook
|
||||||
- make -C doc/arm Bv9ARM.html
|
- make -C doc/arm Bv9ARM.html
|
||||||
|
dependencies:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
|
needs:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- doc/arm/
|
- doc/arm/
|
||||||
@@ -208,6 +276,30 @@ push:docs:sid:amd64:
|
|||||||
- master@isc-projects/bind9
|
- master@isc-projects/bind9
|
||||||
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
||||||
|
|
||||||
|
# Jobs for regular GCC builds on Alpine Linux 3.10 (amd64)
|
||||||
|
|
||||||
|
gcc:alpine3.10:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
|
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||||
|
<<: *alpine_3_10_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:gcc:alpine3.10:amd64:
|
||||||
|
<<: *alpine_3_10_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:alpine3.10:amd64
|
||||||
|
needs: ["gcc:alpine3.10:amd64"]
|
||||||
|
|
||||||
|
unit:gcc:alpine3.10:amd64:
|
||||||
|
<<: *alpine_3_10_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:alpine3.10:amd64
|
||||||
|
needs: ["gcc:alpine3.10:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on CentOS 6 (amd64)
|
# Jobs for regular GCC builds on CentOS 6 (amd64)
|
||||||
|
|
||||||
gcc:centos6:amd64:
|
gcc:centos6:amd64:
|
||||||
@@ -223,12 +315,14 @@ system:gcc:centos6:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:centos6:amd64
|
- gcc:centos6:amd64
|
||||||
|
needs: ["gcc:centos6:amd64"]
|
||||||
|
|
||||||
unit:gcc:centos6:amd64:
|
unit:gcc:centos6:amd64:
|
||||||
<<: *centos_centos6_amd64_image
|
<<: *centos_centos6_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:centos6:amd64
|
- gcc:centos6:amd64
|
||||||
|
needs: ["gcc:centos6:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on CentOS 7 (amd64)
|
# Jobs for regular GCC builds on CentOS 7 (amd64)
|
||||||
|
|
||||||
@@ -236,7 +330,7 @@ gcc:centos7:amd64:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
<<: *centos_centos7_amd64_image
|
<<: *centos_centos7_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -245,12 +339,14 @@ system:gcc:centos7:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:centos7:amd64
|
- gcc:centos7:amd64
|
||||||
|
needs: ["gcc:centos7:amd64"]
|
||||||
|
|
||||||
unit:gcc:centos7:amd64:
|
unit:gcc:centos7:amd64:
|
||||||
<<: *centos_centos7_amd64_image
|
<<: *centos_centos7_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:centos7:amd64
|
- gcc:centos7:amd64
|
||||||
|
needs: ["gcc:centos7:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian 8 Jessie (amd64)
|
# Jobs for regular GCC builds on Debian 8 Jessie (amd64)
|
||||||
|
|
||||||
@@ -258,7 +354,7 @@ gcc:jessie:amd64:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
EXTRA_CONFIGURE: "--without-cmocka --with-python"
|
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
||||||
<<: *debian_jessie_amd64_image
|
<<: *debian_jessie_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -267,12 +363,14 @@ system:gcc:jessie:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:jessie:amd64
|
- gcc:jessie:amd64
|
||||||
|
needs: ["gcc:jessie:amd64"]
|
||||||
|
|
||||||
unit:gcc:jessie:amd64:
|
unit:gcc:jessie:amd64:
|
||||||
<<: *debian_jessie_amd64_image
|
<<: *debian_jessie_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:jessie:amd64
|
- gcc:jessie:amd64
|
||||||
|
needs: ["gcc:jessie:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian 9 Stretch (amd64)
|
# Jobs for regular GCC builds on Debian 9 Stretch (amd64)
|
||||||
|
|
||||||
@@ -288,20 +386,45 @@ system:gcc:stretch:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:stretch:amd64
|
- gcc:stretch:amd64
|
||||||
|
needs: ["gcc:stretch:amd64"]
|
||||||
|
|
||||||
unit:gcc:stretch:amd64:
|
unit:gcc:stretch:amd64:
|
||||||
<<: *debian_stretch_amd64_image
|
<<: *debian_stretch_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:stretch:amd64
|
- gcc:stretch:amd64
|
||||||
|
needs: ["gcc:stretch:amd64"]
|
||||||
|
|
||||||
|
# Jobs for regular GCC builds on Debian 10 Buster (amd64)
|
||||||
|
|
||||||
|
gcc:buster:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:gcc:buster:amd64:
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:buster:amd64
|
||||||
|
needs: ["gcc:buster:amd64"]
|
||||||
|
|
||||||
|
unit:gcc:buster:amd64:
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:buster:amd64
|
||||||
|
needs: ["gcc:buster:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian Sid (amd64)
|
# Jobs for regular GCC builds on Debian Sid (amd64)
|
||||||
|
|
||||||
gcc:sid:amd64:
|
gcc:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O3 -g"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
RUN_MAKE_INSTALL: 1
|
RUN_MAKE_INSTALL: 1
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -311,20 +434,22 @@ system:gcc:sid:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:sid:amd64
|
- gcc:sid:amd64
|
||||||
|
needs: ["gcc:sid:amd64"]
|
||||||
|
|
||||||
unit:gcc:sid:amd64:
|
unit:gcc:sid:amd64:
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:sid:amd64
|
- gcc:sid:amd64
|
||||||
|
needs: ["gcc:sid:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian Sid (i386)
|
# Jobs for regular GCC builds on Debian Sid (i386)
|
||||||
|
|
||||||
gcc:sid:i386:
|
gcc:sid:i386:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O3 -g"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --without-python"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
||||||
<<: *debian_sid_i386_image
|
<<: *debian_sid_i386_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -333,34 +458,38 @@ system:gcc:sid:i386:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:sid:i386
|
- gcc:sid:i386
|
||||||
|
needs: ["gcc:sid:i386"]
|
||||||
|
|
||||||
unit:gcc:sid:i386:
|
unit:gcc:sid:i386:
|
||||||
<<: *debian_sid_i386_image
|
<<: *debian_sid_i386_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:sid:i386
|
- gcc:sid:i386
|
||||||
|
needs: ["gcc:sid:i386"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Fedora 29 (amd64)
|
# Jobs for regular GCC builds on Fedora 30 (amd64)
|
||||||
|
|
||||||
gcc:fedora29:amd64:
|
gcc:fedora30:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *fedora_29_amd64_image
|
<<: *fedora_30_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:gcc:fedora29:amd64:
|
system:gcc:fedora30:amd64:
|
||||||
<<: *fedora_29_amd64_image
|
<<: *fedora_30_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:fedora29:amd64
|
- gcc:fedora30:amd64
|
||||||
|
needs: ["gcc:fedora30:amd64"]
|
||||||
|
|
||||||
unit:gcc:fedora29:amd64:
|
unit:gcc:fedora30:amd64:
|
||||||
<<: *fedora_29_amd64_image
|
<<: *fedora_30_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:fedora29:amd64
|
- gcc:fedora30:amd64
|
||||||
|
needs: ["gcc:fedora30:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
|
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
|
||||||
|
|
||||||
@@ -368,6 +497,7 @@ gcc:xenial:amd64:
|
|||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||||
|
EXTRA_CONFIGURE: "--disable-geoip"
|
||||||
<<: *ubuntu_xenial_amd64_image
|
<<: *ubuntu_xenial_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -376,12 +506,14 @@ system:gcc:xenial:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:xenial:amd64
|
- gcc:xenial:amd64
|
||||||
|
needs: ["gcc:xenial:amd64"]
|
||||||
|
|
||||||
unit:gcc:xenial:amd64:
|
unit:gcc:xenial:amd64:
|
||||||
<<: *ubuntu_xenial_amd64_image
|
<<: *ubuntu_xenial_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:xenial:amd64
|
- gcc:xenial:amd64
|
||||||
|
needs: ["gcc:xenial:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Ubuntu 18.04 Bionic Beaver (amd64)
|
# Jobs for regular GCC builds on Ubuntu 18.04 Bionic Beaver (amd64)
|
||||||
|
|
||||||
@@ -398,12 +530,14 @@ system:gcc:bionic:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:bionic:amd64
|
- gcc:bionic:amd64
|
||||||
|
needs: ["gcc:bionic:amd64"]
|
||||||
|
|
||||||
unit:gcc:bionic:amd64:
|
unit:gcc:bionic:amd64:
|
||||||
<<: *ubuntu_bionic_amd64_image
|
<<: *ubuntu_bionic_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:bionic:amd64
|
- gcc:bionic:amd64
|
||||||
|
needs: ["gcc:bionic:amd64"]
|
||||||
|
|
||||||
# Jobs for GCC builds with ASAN enabled on Debian Sid (amd64)
|
# Jobs for GCC builds with ASAN enabled on Debian Sid (amd64)
|
||||||
|
|
||||||
@@ -421,12 +555,60 @@ system:asan:sid:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- asan:sid:amd64
|
- asan:sid:amd64
|
||||||
|
needs: ["asan:sid:amd64"]
|
||||||
|
|
||||||
unit:asan:sid:amd64:
|
unit:asan:sid:amd64:
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- asan:sid:amd64
|
- asan:sid:amd64
|
||||||
|
needs: ["asan:sid:amd64"]
|
||||||
|
|
||||||
|
rwlock:sid:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:rwlock:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- rwlock:sid:amd64
|
||||||
|
needs: ["rwlock:sid:amd64"]
|
||||||
|
|
||||||
|
unit:rwlock:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- rwlock:sid:amd64
|
||||||
|
needs: ["rwlock:sid:amd64"]
|
||||||
|
|
||||||
|
# Jobs for mutex-based atomics on Debian SID (amd64)
|
||||||
|
mutexatomics:sid:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
#system:mutexatomics:sid:amd64:
|
||||||
|
# <<: *debian_sid_amd64_image
|
||||||
|
# <<: *system_test_job
|
||||||
|
# dependencies:
|
||||||
|
# - mutexatomics:sid:amd64
|
||||||
|
# - mutexatomics:sid:amd64
|
||||||
|
# allow_failure: true
|
||||||
|
|
||||||
|
#unit:mutexatomics:sid:amd64:
|
||||||
|
# <<: *debian_sid_amd64_image
|
||||||
|
# <<: *unit_test_job
|
||||||
|
# dependencies:
|
||||||
|
# - mutexatomics:sid:amd64
|
||||||
|
# allow_failure: true
|
||||||
|
|
||||||
# Jobs for Clang builds on Debian Stretch (amd64)
|
# Jobs for Clang builds on Debian Stretch (amd64)
|
||||||
|
|
||||||
@@ -443,6 +625,7 @@ unit:clang:stretch:amd64:
|
|||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- clang:stretch:amd64
|
- clang:stretch:amd64
|
||||||
|
needs: ["clang:stretch:amd64"]
|
||||||
|
|
||||||
# Jobs for Clang builds on Debian Stretch (i386)
|
# Jobs for Clang builds on Debian Stretch (i386)
|
||||||
|
|
||||||
@@ -469,9 +652,35 @@ system:pkcs11:sid:amd64:
|
|||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- pkcs11:sid:amd64
|
- pkcs11:sid:amd64
|
||||||
|
needs: ["pkcs11:sid:amd64"]
|
||||||
|
|
||||||
unit:pkcs11:sid:amd64:
|
unit:pkcs11:sid:amd64:
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- pkcs11:sid:amd64
|
- pkcs11:sid:amd64
|
||||||
|
needs: ["pkcs11:sid:amd64"]
|
||||||
|
|
||||||
|
# Jobs with libtool disabled
|
||||||
|
|
||||||
|
nolibtool:sid:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "-Wall -Wextra -Og -g"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:nolibtool:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- nolibtool:sid:amd64
|
||||||
|
needs: ["nolibtool:sid:amd64"]
|
||||||
|
|
||||||
|
unit:nolibtool:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- nolibtool:sid:amd64
|
||||||
|
needs: ["nolibtool:sid:amd64"]
|
||||||
|
|||||||
@@ -39,6 +39,9 @@
|
|||||||
- [ ] Update tickets in case of waiting support customers.
|
- [ ] Update tickets in case of waiting support customers.
|
||||||
|
|
||||||
## Marketing
|
## Marketing
|
||||||
- [ ] Post short note to Twitter.
|
- [ ] Update BIND Product page if needed
|
||||||
|
- [ ] Update BIND Significant Features Matrix in KB if needed
|
||||||
|
- [ ] Update BIND -S Edition data sheet if S Edition feature change
|
||||||
|
- [ ] Announce on social media
|
||||||
- [ ] Update [Wikipedia entry for BIND](http://en.wikipedia.org/wiki/BIND).
|
- [ ] Update [Wikipedia entry for BIND](http://en.wikipedia.org/wiki/BIND).
|
||||||
- [ ] Write blog article (if a major release).
|
- [ ] Write blog article (if a major release).
|
||||||
|
|||||||
@@ -1,3 +1,402 @@
|
|||||||
|
5280. [protocol] Add support for displaying EDNS option LLQ. [GL #1201]
|
||||||
|
|
||||||
|
5279. [bug] When loading, reject zones containing CDS or CDNSKEY
|
||||||
|
RRsets at the zone apex if they would cause DNSSEC
|
||||||
|
validation failures if published in the parent zone
|
||||||
|
as the DS RRset. [GL #1187]
|
||||||
|
|
||||||
|
5278. [func] Add YAML output formats for dig, mdig and delv;
|
||||||
|
use the "+yaml" option to enable. [GL #1145]
|
||||||
|
|
||||||
|
--- 9.15.3 released ---
|
||||||
|
|
||||||
|
5277. [bug] Cache DB statistics could underflow when serve-stale
|
||||||
|
was in use, because of a bug in counter maintenance
|
||||||
|
when RRsets become stale.
|
||||||
|
|
||||||
|
Functions for dumping statistics have been updated
|
||||||
|
to dump active, stale, and ancient statistic
|
||||||
|
counters. Ancient RRset counters are prefixed
|
||||||
|
with '~'; stale RRset counters are still prefixed
|
||||||
|
with '#'. [GL #602]
|
||||||
|
|
||||||
|
5276. [func] DNSSEC Lookaside Validation (DLV) is now obsolete;
|
||||||
|
all code enabling its use has been removed from the
|
||||||
|
validator, "delv", and the DNSSEC tools. [GL #7]
|
||||||
|
|
||||||
|
5275. [bug] Mark DS records included in referral messages
|
||||||
|
with trust level "pending" so that they can be
|
||||||
|
validated and cached immediately, with no need to
|
||||||
|
re-query. [GL #964]
|
||||||
|
|
||||||
|
5274. [bug] Address potential use after free race when shutting
|
||||||
|
down rpz. [GL #1175]
|
||||||
|
|
||||||
|
5273. [bug] Check that bits [64..71] of a dns64 prefix are zero.
|
||||||
|
[GL #1159]
|
||||||
|
|
||||||
|
5272. [cleanup] Remove isc-config.sh script as the BIND 9 libraries
|
||||||
|
are now purely internal. [GL #1123]
|
||||||
|
|
||||||
|
5271. [func] The normal (non-debugging) output of dnssec-signzone
|
||||||
|
and dnssec-verify tools now goes to stdout, instead of
|
||||||
|
the combination of stderr and stdout.
|
||||||
|
|
||||||
|
5270. [bug] 'dig +expandaaaa +short' did not work. [GL #1152]
|
||||||
|
|
||||||
|
5269. [port] cygwin: can return ETIMEDOUT on connect() with a
|
||||||
|
non-blocking socket. [GL #1133]
|
||||||
|
|
||||||
|
5268. [placeholder]
|
||||||
|
|
||||||
|
5267. [func] Allow statistics groups display to be toggleable.
|
||||||
|
[GL #1030]
|
||||||
|
|
||||||
|
5266. [bug] named-checkconf failed to report dnstap-output
|
||||||
|
missing from named.conf when dnstap was specified.
|
||||||
|
[GL #1136]
|
||||||
|
|
||||||
|
5265. [bug] DNS64 and RPZ nodata (CNAME *.) rules interacted badly
|
||||||
|
[GL #1106]
|
||||||
|
|
||||||
|
5264. [func] New DNS Cookie algorithm - siphash24 - has been added
|
||||||
|
to BIND 9, and the old HMAC-SHA DNS Cookie algorithms
|
||||||
|
have been removed. [GL #605]
|
||||||
|
|
||||||
|
--- 9.15.2 released ---
|
||||||
|
|
||||||
|
5263. [cleanup] Use atomics and isc_refcount_t wherever possible.
|
||||||
|
[GL #1038]
|
||||||
|
|
||||||
|
5262. [func] Removed support for the legacy GeoIP API. [GL #1112]
|
||||||
|
|
||||||
|
5261. [cleanup] Remove SO_BSDCOMPAT socket option usage.
|
||||||
|
|
||||||
|
5260. [bug] dnstap-read was producing malformed output for large
|
||||||
|
packets. [GL #1093]
|
||||||
|
|
||||||
|
5259. [func] New option '-i' for 'named-checkconf' to ignore
|
||||||
|
warnings about deprecated options. [GL #1101]
|
||||||
|
|
||||||
|
5258. [func] Added support for the GeoIP2 API from MaxMind. This
|
||||||
|
will be compiled in by default if the "libmaxminddb"
|
||||||
|
library is found at compile time, but can be
|
||||||
|
suppressed using "configure --disable-geoip".
|
||||||
|
|
||||||
|
Certain geoip ACL settings that were available with
|
||||||
|
legacy GeoIP are not available when using GeoIP2.
|
||||||
|
[GL #182]
|
||||||
|
|
||||||
|
5257. [bug] Some statistics data was not being displayed.
|
||||||
|
Add shading to the zone tables. [GL #1030]
|
||||||
|
|
||||||
|
5256. [bug] Ensure that glue records are included in root
|
||||||
|
priming responses if "minimal-responses" is not
|
||||||
|
set to "yes". [GL #1092]
|
||||||
|
|
||||||
|
5255. [bug] Errors encountered while reloading inline-signing
|
||||||
|
zones could be ignored, causing the zone content to
|
||||||
|
be left in an incompletely updated state rather than
|
||||||
|
reverted. [GL #1109]
|
||||||
|
|
||||||
|
5254. [func] Collect metrics to report to the statistics-channel
|
||||||
|
DNSSEC signing operations (dnssec-sign) and refresh
|
||||||
|
operations (dnssec-refresh) per zone and per keytag.
|
||||||
|
[GL #513]
|
||||||
|
|
||||||
|
5253. [port] Support platforms that don't define ULLONG_MAX.
|
||||||
|
[GL #1098]
|
||||||
|
|
||||||
|
5252. [func] Report if the last 'rndc reload/reconfig' failed in
|
||||||
|
rndc status. [GL !2040]
|
||||||
|
|
||||||
|
5251. [bug] Statistics were broken in x86 Windows builds.
|
||||||
|
[GL #1081]
|
||||||
|
|
||||||
|
5250. [func] The default size for RSA keys is now 2048 bits,
|
||||||
|
for both ZSKs and KSKs. [GL #1097]
|
||||||
|
|
||||||
|
5249. [bug] Fix a possible underflow in recursion clients
|
||||||
|
statistics when hitting recursive clients
|
||||||
|
soft quota. [GL #1067]
|
||||||
|
|
||||||
|
--- 9.15.1 released ---
|
||||||
|
|
||||||
|
5248. [func] To clarify the configuration of DNSSEC keys,
|
||||||
|
the "managed-keys" and "trusted-keys" options
|
||||||
|
have both been deprecated. The new "dnssec-keys"
|
||||||
|
statement can now be used for all trust anchors,
|
||||||
|
with the keywords "iniital-key" or "static-key"
|
||||||
|
to indicate whether the configured trust anchor
|
||||||
|
should be used for initialization of RFC 5011 key
|
||||||
|
management, or as a permanent trust anchor.
|
||||||
|
|
||||||
|
The "static-key" keyword will generate a warning if
|
||||||
|
used for the root zone.
|
||||||
|
|
||||||
|
Configurations using "trusted-keys" or "managed-keys"
|
||||||
|
will continue to work with no changes, but will
|
||||||
|
generate warnings in the log. In a future release,
|
||||||
|
these options will be marked obsolete. [GL #6]
|
||||||
|
|
||||||
|
5247. [cleanup] The 'cleaning-interval' option has been removed.
|
||||||
|
[GL !1731]
|
||||||
|
|
||||||
|
5246. [func] Log TSIG if appropriate in 'sending notify to' message.
|
||||||
|
[GL #1058]
|
||||||
|
|
||||||
|
5245. [cleanup] Reduce logging level for IXFR up-to-date poll
|
||||||
|
responses. [GL #1009]
|
||||||
|
|
||||||
|
5244. [security] Fixed a race condition in dns_dispatch_getnext()
|
||||||
|
that could cause an assertion failure if a
|
||||||
|
significant number of incoming packets were
|
||||||
|
rejected. (CVE-2019-6471) [GL #942]
|
||||||
|
|
||||||
|
5243. [bug] Fix a possible race between dispatcher and socket
|
||||||
|
code in a high-load cold-cache resolver scenario.
|
||||||
|
[GL #943]
|
||||||
|
|
||||||
|
5242. [bug] In relaxed qname minimizatiom mode, fall back to
|
||||||
|
normal resolution when encountering a lame
|
||||||
|
delegation, and use _.domain/A queries rather
|
||||||
|
than domain/NS. [GL #1055]
|
||||||
|
|
||||||
|
5241. [bug] Fix Ed448 private and public key ASN.1 prefix blobs.
|
||||||
|
[GL #225]
|
||||||
|
|
||||||
|
5240. [bug] Remove key id calculation for RSAMD5. [GL #996]
|
||||||
|
|
||||||
|
5239. [func] Change the json-c detection to pkg-config. [GL #855]
|
||||||
|
|
||||||
|
5238. [bug] Fix a possible deadlock in TCP code. [GL #1046]
|
||||||
|
|
||||||
|
5237. [bug] Recurse to find the root server list with 'dig +trace'.
|
||||||
|
[GL #1028]
|
||||||
|
|
||||||
|
5236. [func] Add SipHash 2-4 implementation in lib/isc/siphash.c
|
||||||
|
and switch isc_hash_function() to use SipHash 2-4.
|
||||||
|
[GL #605]
|
||||||
|
|
||||||
|
5235. [cleanup] Refactor lib/isc/app.c to be thread-safe, unused
|
||||||
|
parts of the API has been removed and the
|
||||||
|
isc_appctx_t data type has been changed to be
|
||||||
|
fully opaque. [GL #1023]
|
||||||
|
|
||||||
|
5234. [port] arm: just use the compiler's default support for
|
||||||
|
yield. [GL #981]
|
||||||
|
|
||||||
|
--- 9.15.0 released ---
|
||||||
|
|
||||||
|
5233. [bug] Negative trust anchors did not work with "forward only;"
|
||||||
|
to validating resolvers. [GL #997]
|
||||||
|
|
||||||
|
5232. [placeholder]
|
||||||
|
|
||||||
|
5231. [protocol] Add support for displaying CLIENT-TAG and SERVER-TAG.
|
||||||
|
[GL #960]
|
||||||
|
|
||||||
|
5230. [protocol] The SHA-1 hash algorithm is no longer used when
|
||||||
|
generating DS and CDS records. [GL #1015]
|
||||||
|
|
||||||
|
5229. [protocol] Enforce known SSHFP fingerprint lengths. [GL #852]
|
||||||
|
|
||||||
|
5228. [func] If trusted-keys and managed-keys were configured
|
||||||
|
simultaneously for the same name, the key could
|
||||||
|
not be be rolled automatically. This is now
|
||||||
|
a fatal configuration error. [GL #868]
|
||||||
|
|
||||||
|
5227. [placeholder]
|
||||||
|
|
||||||
|
5226. [placeholder]
|
||||||
|
|
||||||
|
5225. [func] Allow dig to print out AAAA record fully expanded.
|
||||||
|
with +[no]expandaaaa. [GL #765]
|
||||||
|
|
||||||
|
5224. [bug] Only test provide-ixfr on TCP streams. [GL #991]
|
||||||
|
|
||||||
|
5223. [bug] Fixed a race in the filter-aaaa plugin accessing
|
||||||
|
the hash table. [GL #1005]
|
||||||
|
|
||||||
|
5222. [bug] 'delv -t ANY' could leak memory. [GL #983]
|
||||||
|
|
||||||
|
5221. [test] Enable parallel execution of system tests on
|
||||||
|
Windows. [GL !4101]
|
||||||
|
|
||||||
|
5220. [cleanup] Refactor the isc_stat structure to take advantage
|
||||||
|
of stdatomic. [GL !1493]
|
||||||
|
|
||||||
|
5219. [bug] Fixed a race in the filter-aaaa plugin that could
|
||||||
|
trigger a crash when returning an instance object
|
||||||
|
to the memory pool. [GL #982]
|
||||||
|
|
||||||
|
5218. [bug] Conditionally include <dlfcn.h>. [GL #995]
|
||||||
|
|
||||||
|
5217. [bug] Restore key id calculation for RSAMD5. [GL #996]
|
||||||
|
|
||||||
|
5216. [bug] Fetches-per-zone counter wasn't updated correctly
|
||||||
|
when doing qname minimization. [GL #992]
|
||||||
|
|
||||||
|
5215. [bug] Change #5124 was incomplete; named could still
|
||||||
|
return FORMERR instead of SERVFAIL in some cases.
|
||||||
|
[GL #990]
|
||||||
|
|
||||||
|
5214. [bug] win32: named now removes its lock file upon shutdown.
|
||||||
|
[GL #979]
|
||||||
|
|
||||||
|
5213. [bug] win32: Eliminated a race which allowed named.exe running
|
||||||
|
as a service to be killed prematurely during shutdown.
|
||||||
|
[GL #978]
|
||||||
|
|
||||||
|
5212. [placeholder]
|
||||||
|
|
||||||
|
5211. [bug] Allow out-of-zone additional data to be included
|
||||||
|
in authoritative responses if recursion is allowed
|
||||||
|
and "minimal-responses" is disabled. This behavior
|
||||||
|
was inadvertently removed in change #4605. [GL #817]
|
||||||
|
|
||||||
|
5210. [bug] When dnstap is enabled and recursion is not
|
||||||
|
available, incoming queries are now logged
|
||||||
|
as "auth". Previously, this depended on whether
|
||||||
|
recursion was requested by the client, not on
|
||||||
|
whether recursion was available. [GL #963]
|
||||||
|
|
||||||
|
5209. [bug] When update-check-ksk is true, add_sigs was not
|
||||||
|
considering offline keys, leaving record sets signed
|
||||||
|
with the incorrect type key. [GL #763]
|
||||||
|
|
||||||
|
5208. [test] Run valid rdata wire encodings through totext+fromtext
|
||||||
|
and tofmttext+fromtext methods to check these methods.
|
||||||
|
[GL #899]
|
||||||
|
|
||||||
|
5207. [test] Check delv and dig TTL values. [GL #965]
|
||||||
|
|
||||||
|
5206. [bug] Delv could print out bad TTLs. [GL #965]
|
||||||
|
|
||||||
|
5205. [bug] Enforce that a DS hash exists. [GL #899]
|
||||||
|
|
||||||
|
5204. [test] Check that dns_rdata_fromtext() produces a record that
|
||||||
|
will be accepted by dns_rdata_fromwire(). [GL #852]
|
||||||
|
|
||||||
|
5203. [bug] Enforce whether key rdata exists or not in KEY,
|
||||||
|
DNSKEY, CDNSKEY and RKEY. [GL #899]
|
||||||
|
|
||||||
|
5202. [bug] <dns/ecs.h> was missing ISC_LANG_ENDDECLS. [GL #976]
|
||||||
|
|
||||||
|
5201. [bug] Fix a possible deadlock in RPZ update code. [GL #973]
|
||||||
|
|
||||||
|
5200. [security] tcp-clients settings could be exceeded in some cases,
|
||||||
|
which could lead to exhaustion of file descriptors.
|
||||||
|
(CVE-2018-5743) [GL #615]
|
||||||
|
|
||||||
|
5199. [security] In certain configurations, named could crash
|
||||||
|
if nxdomain-redirect was in use and a redirected
|
||||||
|
query resulted in an NXDOMAIN from the cache.
|
||||||
|
(CVE-2019-6467) [GL #880]
|
||||||
|
|
||||||
|
5198. [bug] If a fetch context was being shut down and, at the same
|
||||||
|
time, we returned from qname minimization, an INSIST
|
||||||
|
could be hit. [GL #966]
|
||||||
|
|
||||||
|
5197. [bug] dig could die in best effort mode on multiple SIG(0)
|
||||||
|
records. Similarly on multiple OPT and multiple TSIG
|
||||||
|
records. [GL #920]
|
||||||
|
|
||||||
|
5196. [bug] make install failed with --with-dlopen=no. [GL #955]
|
||||||
|
|
||||||
|
5195. [bug] "allow-update" and "allow-update-forwarding" were
|
||||||
|
treated as configuration errors if used at the
|
||||||
|
options or view level. [GL #913]
|
||||||
|
|
||||||
|
5194. [bug] Enforce non empty ZOMEMD hash. [GL #899]
|
||||||
|
|
||||||
|
5193. [bug] EID and NIMLOC failed to do multi-line output
|
||||||
|
correctly. [GL #899]
|
||||||
|
|
||||||
|
5192. [placeholder]
|
||||||
|
|
||||||
|
5191. [placeholder]
|
||||||
|
|
||||||
|
5190. [bug] Ignore trust anchors using disabled algorithms.
|
||||||
|
[GL #806]
|
||||||
|
|
||||||
|
5189. [cleanup] Remove revoked root DNSKEY from bind.keys. [GL #945]
|
||||||
|
|
||||||
|
5188. [func] The "dnssec-enable" option is deprecated and no
|
||||||
|
longer has any effect; DNSSEC responses are
|
||||||
|
always enabled. [GL #866]
|
||||||
|
|
||||||
|
5187. [test] Set time zone before running any tests in dnstap_test.
|
||||||
|
[GL #940]
|
||||||
|
|
||||||
|
5186. [cleanup] More dnssec-keygen manual tidying. [GL !1678]
|
||||||
|
|
||||||
|
5185. [placeholder]
|
||||||
|
|
||||||
|
5184. [bug] Missing unlocks in sdlz.c. [GL #936]
|
||||||
|
|
||||||
|
5183. [bug] Reinitialize ECS data before reusing client
|
||||||
|
structures. [GL #881]
|
||||||
|
|
||||||
|
5182. [bug] Fix a high-load race/crash in handling of
|
||||||
|
isc_socket_close() in resolver. [GL #834]
|
||||||
|
|
||||||
|
5181. [func] Add a mechanism for a DLZ module to signal that
|
||||||
|
the view's allow-transfer ACL should be used to
|
||||||
|
determine whether transfers are allowed. [GL #803]
|
||||||
|
|
||||||
|
5180. [bug] delv now honors the operating system's preferred
|
||||||
|
ephemeral port range. [GL #925]
|
||||||
|
|
||||||
|
5179. [cleanup] Replace some vague type declarations with the more
|
||||||
|
specific dns_secalg_t and dns_dsdigest_t.
|
||||||
|
Thanks to Tony Finch. [GL !1498]
|
||||||
|
|
||||||
|
5178. [bug] Handle EDQUOT (disk quota) and ENOSPC (disk full)
|
||||||
|
errors when writing files. [GL #902]
|
||||||
|
|
||||||
|
5177. [func] Add the ability to specify in named.conf whether a
|
||||||
|
response-policy zone's SOA record should be added
|
||||||
|
to the additional section (add-soa yes/no). [GL #865]
|
||||||
|
|
||||||
|
5176. [tests] Remove a dependency on libxml in statschannel system
|
||||||
|
test. [GL #926]
|
||||||
|
|
||||||
|
5175. [bug] Fixed a problem with file input in dnssec-keymgr,
|
||||||
|
dnssec-coverage and dnssec-checkds when using
|
||||||
|
python3. [GL #882]
|
||||||
|
|
||||||
|
5174. [doc] Tidy dnssec-keygen manual. [GL !1557]
|
||||||
|
|
||||||
|
5173. [bug] Fixed a race in socket code that could occur when
|
||||||
|
accept, send, or recv were called from an event
|
||||||
|
loop but the socket had been closed by another
|
||||||
|
thread. [RT #874]
|
||||||
|
|
||||||
|
5172. [bug] nsupdate now honors the operating system's preferred
|
||||||
|
ephemeral port range. [GL #905]
|
||||||
|
|
||||||
|
5171. [func] named plugins are now installed into a separate
|
||||||
|
directory. Supplying a filename (a string without path
|
||||||
|
separators) in a "plugin" configuration stanza now
|
||||||
|
causes named to look for that plugin in that directory.
|
||||||
|
[GL #878]
|
||||||
|
|
||||||
|
5170. [test] Added --with-dlz-filesystem to feature-test. [GL !1587]
|
||||||
|
|
||||||
|
5169. [bug] The presence of certain types in an otherwise
|
||||||
|
empty node could cause a crash while processing a
|
||||||
|
type ANY query. [GL #901]
|
||||||
|
|
||||||
|
5168. [bug] Do not crash on shutdown when RPZ fails to load. Also,
|
||||||
|
keep previous version of the database if RPZ fails to
|
||||||
|
load. [GL #813]
|
||||||
|
|
||||||
|
5167. [bug] nxdomain-redirect could sometimes lookup the wrong
|
||||||
|
redirect name. [GL #892]
|
||||||
|
|
||||||
|
5166. [placeholder]
|
||||||
|
|
||||||
5165. [contrib] Removed SDB drivers from contrib; they're obsolete.
|
5165. [contrib] Removed SDB drivers from contrib; they're obsolete.
|
||||||
[GL #428]
|
[GL #428]
|
||||||
|
|
||||||
@@ -25,8 +424,6 @@
|
|||||||
5157. [bug] Nslookup now errors out if there are extra command
|
5157. [bug] Nslookup now errors out if there are extra command
|
||||||
line arguments. [GL #207]
|
line arguments. [GL #207]
|
||||||
|
|
||||||
--- 9.13.6 released ---
|
|
||||||
|
|
||||||
5156. [doc] Extended and refined the section of the ARM describing
|
5156. [doc] Extended and refined the section of the ARM describing
|
||||||
mirror zones. [GL #774]
|
mirror zones. [GL #774]
|
||||||
|
|
||||||
@@ -48,7 +445,7 @@
|
|||||||
- Zone signing and DNSKEY maintenance events are
|
- Zone signing and DNSKEY maintenance events are
|
||||||
now logged to the "dnssec" category
|
now logged to the "dnssec" category
|
||||||
- Messages are now logged when DNSSEC keys are
|
- Messages are now logged when DNSSEC keys are
|
||||||
pubished, activated, inactivated, deleted,
|
published, activated, inactivated, deleted,
|
||||||
or revoked.
|
or revoked.
|
||||||
[GL #714]
|
[GL #714]
|
||||||
|
|
||||||
@@ -85,7 +482,9 @@
|
|||||||
and "nsdname-enable" both now default to yes,
|
and "nsdname-enable" both now default to yes,
|
||||||
regardless of compile-time settings. [GL #824]
|
regardless of compile-time settings. [GL #824]
|
||||||
|
|
||||||
5141. [placeholder]
|
5141. [security] Zone transfer controls for writable DLZ zones were
|
||||||
|
not effective as the allowzonexfr method was not being
|
||||||
|
called for such zones. (CVE-2019-6465) [GL #790]
|
||||||
|
|
||||||
5140. [bug] Don't immediately mark existing keys as inactive and
|
5140. [bug] Don't immediately mark existing keys as inactive and
|
||||||
deleted when running dnssec-keymgr for the first
|
deleted when running dnssec-keymgr for the first
|
||||||
@@ -157,7 +556,10 @@
|
|||||||
|
|
||||||
5119. [placeholder]
|
5119. [placeholder]
|
||||||
|
|
||||||
5118. [placeholder]
|
5118. [security] Named could crash if it is managing a key with
|
||||||
|
`managed-keys` and the authoritative zone is rolling
|
||||||
|
the key to an unsupported algorithm. (CVE-2018-5745)
|
||||||
|
[GL #780]
|
||||||
|
|
||||||
5117. [placeholder]
|
5117. [placeholder]
|
||||||
|
|
||||||
@@ -179,7 +581,8 @@
|
|||||||
5111. [bug] Occluded DNSKEY records could make it into the
|
5111. [bug] Occluded DNSKEY records could make it into the
|
||||||
delegating NSEC/NSEC3 bitmap. [GL #742]
|
delegating NSEC/NSEC3 bitmap. [GL #742]
|
||||||
|
|
||||||
5110. [placeholder]
|
5110. [security] Named leaked memory if there were multiple Key Tag
|
||||||
|
EDNS options present. (CVE-2018-5744) [GL #772]
|
||||||
|
|
||||||
5109. [cleanup] Remove support for RSAMD5 algorithm. [GL #628]
|
5109. [cleanup] Remove support for RSAMD5 algorithm. [GL #628]
|
||||||
|
|
||||||
@@ -259,8 +662,8 @@
|
|||||||
5091. [func] Two new global and per-view options min-cache-ttl
|
5091. [func] Two new global and per-view options min-cache-ttl
|
||||||
and min-ncache-ttl [GL #613]
|
and min-ncache-ttl [GL #613]
|
||||||
|
|
||||||
5090. [bug] dig and mdig failed to properly preparse dash value
|
5090. [bug] dig and mdig failed to properly pre-parse dash value
|
||||||
pairs when value was a seperate argument and started
|
pairs when value was a separate argument and started
|
||||||
with a dash. [GL #584]
|
with a dash. [GL #584]
|
||||||
|
|
||||||
5089. [bug] Restore localhost fallback in dig and host which is
|
5089. [bug] Restore localhost fallback in dig and host which is
|
||||||
@@ -326,7 +729,7 @@
|
|||||||
5072. [bug] Add unit tests for isc_buffer_copyregion() and fix its
|
5072. [bug] Add unit tests for isc_buffer_copyregion() and fix its
|
||||||
behavior for auto-reallocated buffers. [GL #644]
|
behavior for auto-reallocated buffers. [GL #644]
|
||||||
|
|
||||||
5071. [bug] Comparision of NXT records was broken. [GL #631]
|
5071. [bug] Comparison of NXT records was broken. [GL #631]
|
||||||
|
|
||||||
5070. [bug] Record types which support a empty rdata field were
|
5070. [bug] Record types which support a empty rdata field were
|
||||||
not handling the empty rdata field case. [GL #638]
|
not handling the empty rdata field case. [GL #638]
|
||||||
@@ -345,7 +748,7 @@
|
|||||||
|
|
||||||
5065. [bug] Only set IPV6_USE_MIN_MTU on IPv6. [GL #553]
|
5065. [bug] Only set IPV6_USE_MIN_MTU on IPv6. [GL #553]
|
||||||
|
|
||||||
5064. [test] Initalize TZ environment variable before calling
|
5064. [test] Initialize TZ environment variable before calling
|
||||||
dns_test_begin in dnstap_test. [GL #624]
|
dns_test_begin in dnstap_test. [GL #624]
|
||||||
|
|
||||||
5063. [test] In statschannel test try a few times before failing
|
5063. [test] In statschannel test try a few times before failing
|
||||||
@@ -571,7 +974,7 @@
|
|||||||
5001. [bug] Fix refcount errors on error paths. [GL !563]
|
5001. [bug] Fix refcount errors on error paths. [GL !563]
|
||||||
|
|
||||||
5000. [bug] named_server_servestale() could leave the server in
|
5000. [bug] named_server_servestale() could leave the server in
|
||||||
exclusive mode if an error occured. [GL #441]
|
exclusive mode if an error occurred. [GL #441]
|
||||||
|
|
||||||
4999. [cleanup] Remove custom printf implementation in lib/isc/print.c.
|
4999. [cleanup] Remove custom printf implementation in lib/isc/print.c.
|
||||||
[GL #261]
|
[GL #261]
|
||||||
|
|||||||
@@ -0,0 +1,79 @@
|
|||||||
|
CODE OF CONDUCT
|
||||||
|
|
||||||
|
BIND 9 Code of Conduct
|
||||||
|
|
||||||
|
Like the technical community as a whole, the BIND 9 team and community is
|
||||||
|
made up of a mixture of professionals and volunteers from all over the
|
||||||
|
world, working on every aspect of the mission - including mentorship,
|
||||||
|
teaching, and connecting people.
|
||||||
|
|
||||||
|
Diversity is one of our huge strengths, but it can also lead to
|
||||||
|
communication issues and unhappiness. To that end, we have a few ground
|
||||||
|
rules that we ask people to adhere to. This code applies equally to the
|
||||||
|
core development team, open source contributors and those seeking help and
|
||||||
|
guidance.
|
||||||
|
|
||||||
|
This isn't an exhaustive list of things that you can't do. Rather, take it
|
||||||
|
in the spirit in which it's intended - a guide to make it easier to enrich
|
||||||
|
all of us and the technical communities in which we participate.
|
||||||
|
|
||||||
|
This code of conduct applies to all spaces managed by the BIND 9 project
|
||||||
|
or Internet Systems Consortium. This includes chat, the mailing lists, the
|
||||||
|
issue tracker, and any other fora created by the project team which the
|
||||||
|
community uses for communication. In addition, violations of this code
|
||||||
|
outside these spaces may affect a person's ability to participate within
|
||||||
|
them.
|
||||||
|
|
||||||
|
If you believe someone is violating the code of conduct, we ask that you
|
||||||
|
report it by emailing conduct@isc.org. For more details please see our
|
||||||
|
Reporting Guidelines.
|
||||||
|
|
||||||
|
* Be friendly and patient.
|
||||||
|
* Be welcoming. We strive to be a community that welcomes and supports
|
||||||
|
people of all backgrounds and identities. This includes, but is not
|
||||||
|
limited to members of any race, ethnicity, culture, national origin,
|
||||||
|
colour, immigration status, social and economic class, educational
|
||||||
|
level, sex, sexual orientation, gender identity and expression, age,
|
||||||
|
size, family status, political belief, religion, and mental and
|
||||||
|
physical ability.
|
||||||
|
* Be considerate. Your work will be used by other people, and you in
|
||||||
|
turn will depend on the work of others. Any decision you take will
|
||||||
|
affect users and colleagues, and you should take those consequences
|
||||||
|
into account when making decisions. Remember that we're a world-wide
|
||||||
|
community, so you might not be communicating in someone else's primary
|
||||||
|
language.
|
||||||
|
* Be respectful. Not all of us will agree all the time, but disagreement
|
||||||
|
is no excuse for poor behavior and poor manners. We might all
|
||||||
|
experience some frustration now and then, but we cannot allow that
|
||||||
|
frustration to turn into a personal attack. It's important to remember
|
||||||
|
that a community where people feel uncomfortable or threatened is not
|
||||||
|
a productive one. Members of the BIND 9 community should be respectful
|
||||||
|
when dealing with other members as well as with people outside the
|
||||||
|
BIND 9 community.
|
||||||
|
* Be careful in the words that you choose. We are a community of
|
||||||
|
professionals, and we conduct ourselves professionally. Be kind to
|
||||||
|
others. Do not insult or put down other participants. Harassment and
|
||||||
|
other exclusionary behavior aren't acceptable. This includes, but is
|
||||||
|
not limited to:
|
||||||
|
+ Violent threats or language directed against another person.
|
||||||
|
+ Discriminatory jokes and language.
|
||||||
|
+ Posting sexually explicit or violent material.
|
||||||
|
+ Posting (or threatening to post) other people's personally
|
||||||
|
identifying information ("doxing").
|
||||||
|
+ Personal insults, especially those using racist or sexist terms.
|
||||||
|
+ Unwelcome sexual attention.
|
||||||
|
+ Advocating for, or encouraging, any of the above behavior.
|
||||||
|
+ Repeated harassment of others. In general, if someone asks you to
|
||||||
|
stop, then stop.
|
||||||
|
* When we disagree, try to understand why. Disagreements, both social
|
||||||
|
and technical, happen all the time and BIND 9 is no exception. It is
|
||||||
|
important that we resolve disagreements and differing views
|
||||||
|
constructively. Remember that we're different. The strength of BIND 9
|
||||||
|
comes from its varied community, people from a wide range of
|
||||||
|
backgrounds. Different people have different perspectives on issues.
|
||||||
|
Being unable to understand why someone holds a viewpoint doesn't mean
|
||||||
|
that they're wrong. Don't forget that it is human to err and blaming
|
||||||
|
each other doesn't get us anywhere. Instead, focus on helping to
|
||||||
|
resolve issues and learning from mistakes.
|
||||||
|
|
||||||
|
Original text courtesy of the Django Code of Conduct project.
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
# BIND 9 Code of Conduct
|
||||||
|
|
||||||
|
Like the technical community as a whole, the BIND 9 team and community is made
|
||||||
|
up of a mixture of professionals and volunteers from all over the world, working
|
||||||
|
on every aspect of the mission - including mentorship, teaching, and connecting
|
||||||
|
people.
|
||||||
|
|
||||||
|
Diversity is one of our huge strengths, but it can also lead to communication
|
||||||
|
issues and unhappiness. To that end, we have a few ground rules that we ask
|
||||||
|
people to adhere to. This code applies equally to the core development team, open source contributors and those
|
||||||
|
seeking help and guidance.
|
||||||
|
|
||||||
|
This isn't an exhaustive list of things that you can't do. Rather, take it in
|
||||||
|
the spirit in which it's intended - a guide to make it easier to enrich all of
|
||||||
|
us and the technical communities in which we participate.
|
||||||
|
|
||||||
|
This code of conduct applies to all spaces managed by the BIND 9 project or
|
||||||
|
Internet Systems Consortium. This includes chat, the mailing lists, the issue
|
||||||
|
tracker, and any other fora created by the project team which the
|
||||||
|
community uses for communication. In addition, violations of this code outside
|
||||||
|
these spaces may affect a person's ability to participate within them.
|
||||||
|
|
||||||
|
If you believe someone is violating the code of conduct, we ask that you report
|
||||||
|
it by emailing [conduct@isc.org](conduct@isc.org). For more details please see
|
||||||
|
our [Reporting Guidelines](https://www.isc.org/conductreporting/).
|
||||||
|
|
||||||
|
* **Be friendly and patient.**
|
||||||
|
* **Be welcoming.** We strive to be a community that welcomes and supports
|
||||||
|
people of all backgrounds and identities. This includes, but is not limited to
|
||||||
|
members of any race, ethnicity, culture, national origin, colour, immigration
|
||||||
|
status, social and economic class, educational level, sex, sexual orientation,
|
||||||
|
gender identity and expression, age, size, family status, political belief,
|
||||||
|
religion, and mental and physical ability.
|
||||||
|
* **Be considerate.** Your work will be used by other people, and you in turn
|
||||||
|
will depend on the work of others. Any decision you take will affect users and
|
||||||
|
colleagues, and you should take those consequences into account when making
|
||||||
|
decisions. Remember that we're a world-wide community, so you might not be
|
||||||
|
communicating in someone else's primary language.
|
||||||
|
* **Be respectful.** Not all of us will agree all the time, but disagreement is
|
||||||
|
no excuse for poor behavior and poor manners. We might all experience some
|
||||||
|
frustration now and then, but we cannot allow that frustration to turn into a
|
||||||
|
personal attack. It's important to remember that a community where people feel
|
||||||
|
uncomfortable or threatened is not a productive one. Members of the BIND 9
|
||||||
|
community should be respectful when dealing with other members as well as with
|
||||||
|
people outside the BIND 9 community.
|
||||||
|
* **Be careful in the words that you choose.** We are a community of
|
||||||
|
professionals, and we conduct ourselves professionally. Be kind to others. Do
|
||||||
|
not insult or put down other participants. Harassment and other exclusionary
|
||||||
|
behavior aren't acceptable. This includes, but is not limited to:
|
||||||
|
* Violent threats or language directed against another person.
|
||||||
|
* Discriminatory jokes and language.
|
||||||
|
* Posting sexually explicit or violent material.
|
||||||
|
* Posting (or threatening to post) other people's personally identifying
|
||||||
|
information ("doxing").
|
||||||
|
* Personal insults, especially those using racist or sexist terms.
|
||||||
|
* Unwelcome sexual attention.
|
||||||
|
* Advocating for, or encouraging, any of the above behavior.
|
||||||
|
* Repeated harassment of others. In general, if someone asks you to stop, then
|
||||||
|
stop.
|
||||||
|
* **When we disagree, try to understand why.** Disagreements, both social and
|
||||||
|
technical, happen all the time and BIND 9 is no exception. It is important
|
||||||
|
that we resolve disagreements and differing views constructively. Remember
|
||||||
|
that we're different. The strength of BIND 9 comes from its varied community,
|
||||||
|
people from a wide range of backgrounds. Different people have different
|
||||||
|
perspectives on issues. Being unable to understand why someone holds a
|
||||||
|
viewpoint doesn't mean that they're wrong. Don't forget that it is human to
|
||||||
|
err and blaming each other doesn't get us anywhere. Instead, focus on helping
|
||||||
|
to resolve issues and learning from mistakes.
|
||||||
|
|
||||||
|
Original text courtesy of the [Django Code of Conduct](https://www.djangoproject.com/conduct/)
|
||||||
|
project.
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
CONTRIBUTING
|
||||||
|
|
||||||
BIND Source Access and Contributor Guidelines
|
BIND Source Access and Contributor Guidelines
|
||||||
|
|
||||||
Feb 22, 2018
|
Feb 22, 2018
|
||||||
@@ -32,6 +34,14 @@ access to the source repository was restricted just as commit access was.
|
|||||||
That's now changing, with the opening of a public git mirror to the BIND
|
That's now changing, with the opening of a public git mirror to the BIND
|
||||||
source tree (see below).
|
source tree (see below).
|
||||||
|
|
||||||
|
At Internet Systems Consortium, we're committed to building communities
|
||||||
|
that are welcoming and inclusive; environments where people are encouraged
|
||||||
|
to share ideas, treat each other with respect, and collaborate towards the
|
||||||
|
best solutions. To reinforce our commitment, the Internet Systems
|
||||||
|
Consortium has adopted the Contributor Covenant version 1.4 as our Code of
|
||||||
|
Conduct for BIND 9 project, as well as for the conduct of our developers
|
||||||
|
throughout the industry.
|
||||||
|
|
||||||
Access to source code
|
Access to source code
|
||||||
|
|
||||||
Public BIND releases are always available from the ISC FTP site.
|
Public BIND releases are always available from the ISC FTP site.
|
||||||
|
|||||||
+9
-1
@@ -41,6 +41,14 @@ a release: read access to the source repository was restricted just
|
|||||||
as commit access was. That's now changing, with the opening of a
|
as commit access was. That's now changing, with the opening of a
|
||||||
public git mirror to the BIND source tree (see below).
|
public git mirror to the BIND source tree (see below).
|
||||||
|
|
||||||
|
At [Internet Systems Consortium](https://www.isc.org), we're committed to
|
||||||
|
building communities that are welcoming and inclusive; environments where people
|
||||||
|
are encouraged to share ideas, treat each other with respect, and collaborate
|
||||||
|
towards the best solutions. To reinforce our commitment, the [Internet Systems
|
||||||
|
Consortium](https://www.isc.org) has adopted the Contributor Covenant version
|
||||||
|
1.4 as our Code of Conduct for BIND 9 project, as well as for the conduct of our
|
||||||
|
developers throughout the industry.
|
||||||
|
|
||||||
### <a name="access"></a>Access to source code
|
### <a name="access"></a>Access to source code
|
||||||
|
|
||||||
Public BIND releases are always available from the
|
Public BIND releases are always available from the
|
||||||
@@ -108,7 +116,7 @@ ISC's Security Vulnerability Disclosure Policy is documented at [https://kb.isc.
|
|||||||
If you have a crash, you may want to consult
|
If you have a crash, you may want to consult
|
||||||
[‘What to do if your BIND or DHCP server has crashed.’](https://kb.isc.org/article/AA-00340/89/What-to-do-if-your-BIND-or-DHCP-server-has-crashed.html)
|
[‘What to do if your BIND or DHCP server has crashed.’](https://kb.isc.org/article/AA-00340/89/What-to-do-if-your-BIND-or-DHCP-server-has-crashed.html)
|
||||||
|
|
||||||
### <a name="bugs"></a>Contributing code
|
### <a name="contrib"></a>Contributing code
|
||||||
|
|
||||||
BIND is licensed under the
|
BIND is licensed under the
|
||||||
[Mozilla Public License 2.0](http://www.isc.org/downloads/software-support-policy/isc-license/).
|
[Mozilla Public License 2.0](http://www.isc.org/downloads/software-support-policy/isc-license/).
|
||||||
|
|||||||
@@ -1,5 +1,81 @@
|
|||||||
|
HISTORY
|
||||||
|
|
||||||
Functional enhancements from prior major releases of BIND 9
|
Functional enhancements from prior major releases of BIND 9
|
||||||
|
|
||||||
|
BIND 9.14
|
||||||
|
|
||||||
|
BIND 9.14 (a stable branch based on the 9.13 development branch) includes
|
||||||
|
a number of changes from BIND 9.12 and earlier releases. New features
|
||||||
|
include:
|
||||||
|
|
||||||
|
* A new "plugin" mechanism has been added to allow query functionality
|
||||||
|
to be extended using dynamically loadable libraries. The "filter-aaaa"
|
||||||
|
feature has been removed from named and is now implemented as a
|
||||||
|
plugin.
|
||||||
|
* Socket and task code has been refactored to improve performance.
|
||||||
|
* QNAME minimization, as described in RFC 7816, is now supported.
|
||||||
|
* "Root key sentinel" support, enabling validating resolvers to indicate
|
||||||
|
via a special query which trust anchors are configured for the root
|
||||||
|
zone.
|
||||||
|
* Secondary zones can now be configured as "mirror" zones; their
|
||||||
|
contents are transferred in as with traditional slave zones, but are
|
||||||
|
subject to DNSSEC validation and are not treated as authoritative data
|
||||||
|
when answering. This makes it easier to configure a local copy of the
|
||||||
|
root zone as described in RFC 7706.
|
||||||
|
* The "validate-except" option allows configuration of domains below
|
||||||
|
which DNSSEC validation should not be performed.
|
||||||
|
* The default value of "dnssec-validation" is now "auto".
|
||||||
|
* IDNA2008 is now supported when linking with libidn2.
|
||||||
|
* "named -V" now outputs the default paths for files used by named and
|
||||||
|
other tools.
|
||||||
|
|
||||||
|
In addition, workarounds that were formerly in place to enable resolution
|
||||||
|
of domains whose authoritative servers did not respond to EDNS queries
|
||||||
|
have been removed. See https://dnsflagday.net for more details.
|
||||||
|
|
||||||
|
Cryptographic support has been modernized. BIND now uses the best
|
||||||
|
available pseudo-random number generator for the platform on which it's
|
||||||
|
built. Very old versions of OpenSSL are no longer supported. Cryptography
|
||||||
|
is now mandatory: building BIND without DNSSEC is no longer supported.
|
||||||
|
|
||||||
|
Special code to support certain legacy operating systems has also been
|
||||||
|
removed; see the file PLATFORMS.md for details of supported platforms. In
|
||||||
|
addition to OpenSSL, BIND now requires support for IPv6, threads, and
|
||||||
|
standard atomic operations provided by the C compiler.
|
||||||
|
|
||||||
|
BIND 9.12
|
||||||
|
|
||||||
|
BIND 9.12 includes a number of changes from BIND 9.11 and earlier
|
||||||
|
releases. New features include:
|
||||||
|
|
||||||
|
* named and related libraries have been substantially refactored for
|
||||||
|
improved query performance -- particularly on delegation heavy zones
|
||||||
|
-- and for improved readability, maintainability, and testability.
|
||||||
|
* Code implementing the name server query processing logic has been
|
||||||
|
moved into a new libns library, for easier testing and use in tools
|
||||||
|
other than named.
|
||||||
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
|
NXDOMAIN responses.
|
||||||
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
|
* Setting 'max-journal-size default' now limits the size of journal
|
||||||
|
files to twice the size of the zone.
|
||||||
|
* dnstap-read -x prints a hex dump of the wire format of each logged DNS
|
||||||
|
message.
|
||||||
|
* dnstap output files can now be configured to roll automatically when
|
||||||
|
reaching a given size.
|
||||||
|
* Log file timestamps can now also be formatted in ISO 8601 (local) or
|
||||||
|
ISO 8601 (UTC) formats.
|
||||||
|
* Logging channels and dnstap output files can now be configured to use
|
||||||
|
a timestamp as the suffix when rolling to a new file.
|
||||||
|
* 'named-checkconf -l' lists zones found in named.conf.
|
||||||
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
|
data for zones added by rndc addzone is stored.
|
||||||
|
* The default key algorithm in rndc-confgen is now hmac-sha256.
|
||||||
|
* filter-aaaa-on-v4 and filter-aaaa-on-v6 options are now available by
|
||||||
|
default without a configure option.
|
||||||
|
* The obsolete isc-hmac-fixup command has been removed.
|
||||||
|
|
||||||
BIND 9.11
|
BIND 9.11
|
||||||
|
|
||||||
BIND 9.11.0 includes a number of changes from BIND 9.10 and earlier
|
BIND 9.11.0 includes a number of changes from BIND 9.10 and earlier
|
||||||
@@ -431,11 +507,11 @@ BIND 9.4.0
|
|||||||
* Detect duplicates of UDP queries we are recursing on and drop them.
|
* Detect duplicates of UDP queries we are recursing on and drop them.
|
||||||
New stats category "duplicates".
|
New stats category "duplicates".
|
||||||
* "USE INTERNAL MALLOC" is now runtime selectable.
|
* "USE INTERNAL MALLOC" is now runtime selectable.
|
||||||
* The lame cache is now done on a basis as some servers only appear to
|
* The lame cache is now done on a <qname,qclass,qtype> basis as some
|
||||||
be lame for certain query types.
|
servers only appear to be lame for certain query types.
|
||||||
* Limit the number of recursive clients that can be waiting for a single
|
* Limit the number of recursive clients that can be waiting for a single
|
||||||
query () to resolve. New options clients-per-query and
|
query (<qname,qtype,qclass>) to resolve. New options clients-per-query
|
||||||
max-clients-per-query.
|
and max-clients-per-query.
|
||||||
* dig: report the number of extra bytes still left in the packet after
|
* dig: report the number of extra bytes still left in the packet after
|
||||||
processing all the records.
|
processing all the records.
|
||||||
* Support for IPSECKEY rdata type.
|
* Support for IPSECKEY rdata type.
|
||||||
|
|||||||
+75
@@ -10,6 +10,81 @@
|
|||||||
-->
|
-->
|
||||||
### Functional enhancements from prior major releases of BIND 9
|
### Functional enhancements from prior major releases of BIND 9
|
||||||
|
|
||||||
|
#### BIND 9.14
|
||||||
|
|
||||||
|
BIND 9.14 (a stable branch based on the 9.13 development branch)
|
||||||
|
includes a number of changes from BIND 9.12 and earlier releases.
|
||||||
|
New features include:
|
||||||
|
|
||||||
|
* A new "plugin" mechanism has been added to allow query functionality
|
||||||
|
to be extended using dynamically loadable libraries. The "filter-aaaa"
|
||||||
|
feature has been removed from named and is now implemented as a plugin.
|
||||||
|
* Socket and task code has been refactored to improve performance.
|
||||||
|
* QNAME minimization, as described in RFC 7816, is now supported.
|
||||||
|
* "Root key sentinel" support, enabling validating resolvers to indicate
|
||||||
|
via a special query which trust anchors are configured for the root zone.
|
||||||
|
* Secondary zones can now be configured as "mirror" zones; their contents
|
||||||
|
are transferred in as with traditional slave zones, but are subject to
|
||||||
|
DNSSEC validation and are not treated as authoritative data when
|
||||||
|
answering. This makes it easier to configure a local copy of the root
|
||||||
|
zone as described in RFC 7706.
|
||||||
|
* The "validate-except" option allows configuration of domains below which
|
||||||
|
DNSSEC validation should not be performed.
|
||||||
|
* The default value of "dnssec-validation" is now "auto".
|
||||||
|
* IDNA2008 is now supported when linking with `libidn2`.
|
||||||
|
* "named -V" now outputs the default paths for files used by named
|
||||||
|
and other tools.
|
||||||
|
|
||||||
|
In addition, workarounds that were formerly in place to enable resolution
|
||||||
|
of domains whose authoritative servers did not respond to EDNS queries
|
||||||
|
have been removed. See [https://dnsflagday.net](https://dnsflagday.net)
|
||||||
|
for more details.
|
||||||
|
|
||||||
|
Cryptographic support has been modernized. BIND now uses the
|
||||||
|
best available pseudo-random number generator for the platform on which
|
||||||
|
it's built. Very old versions of OpenSSL are no longer supported.
|
||||||
|
Cryptography is now mandatory: building BIND without DNSSEC is no
|
||||||
|
longer supported.
|
||||||
|
|
||||||
|
Special code to support certain legacy operating systems has also
|
||||||
|
been removed; see the file [PLATFORMS.md](PLATFORMS.md) for details
|
||||||
|
of supported platforms. In addition to OpenSSL, BIND now requires
|
||||||
|
support for IPv6, threads, and standard atomic operations provided
|
||||||
|
by the C compiler.
|
||||||
|
|
||||||
|
#### BIND 9.12
|
||||||
|
|
||||||
|
BIND 9.12 includes a number of changes from BIND 9.11 and earlier releases.
|
||||||
|
New features include:
|
||||||
|
|
||||||
|
* `named` and related libraries have been substantially refactored for
|
||||||
|
improved query performance -- particularly on delegation heavy zones --
|
||||||
|
and for improved readability, maintainability, and testability.
|
||||||
|
* Code implementing the name server query processing logic has been moved
|
||||||
|
into a new `libns` library, for easier testing and use in tools other
|
||||||
|
than `named`.
|
||||||
|
* Cached, validated NSEC and other records can now be used to synthesize
|
||||||
|
NXDOMAIN responses.
|
||||||
|
* The DNS Response Policy Service API (DNSRPS) is now supported.
|
||||||
|
* Setting `'max-journal-size default'` now limits the size of journal files
|
||||||
|
to twice the size of the zone.
|
||||||
|
* `dnstap-read -x` prints a hex dump of the wire format of each logged
|
||||||
|
DNS message.
|
||||||
|
* `dnstap` output files can now be configured to roll automatically when
|
||||||
|
reaching a given size.
|
||||||
|
* Log file timestamps can now also be formatted in ISO 8601 (local) or ISO
|
||||||
|
8601 (UTC) formats.
|
||||||
|
* Logging channels and `dnstap` output files can now be configured to use a
|
||||||
|
timestamp as the suffix when rolling to a new file.
|
||||||
|
* `'named-checkconf -l'` lists zones found in `named.conf`.
|
||||||
|
* Added support for the EDNS Padding and Keepalive options.
|
||||||
|
* 'new-zones-directory' option sets the location where the configuration
|
||||||
|
data for zones added by rndc addzone is stored.
|
||||||
|
* The default key algorithm in `rndc-confgen` is now hmac-sha256.
|
||||||
|
* `filter-aaaa-on-v4` and `filter-aaaa-on-v6` options are now available
|
||||||
|
by default without a configure option.
|
||||||
|
* The obsolete `isc-hmac-fixup` command has been removed.
|
||||||
|
|
||||||
#### BIND 9.11
|
#### BIND 9.11
|
||||||
|
|
||||||
BIND 9.11.0 includes a number of changes from BIND 9.10 and earlier
|
BIND 9.11.0 includes a number of changes from BIND 9.10 and earlier
|
||||||
|
|||||||
+13
-26
@@ -18,11 +18,7 @@ SUBDIRS = make lib fuzz bin doc
|
|||||||
TARGETS =
|
TARGETS =
|
||||||
PREREQS = bind.keys.h
|
PREREQS = bind.keys.h
|
||||||
|
|
||||||
MANPAGES = isc-config.sh.1
|
MANOBJS = README HISTORY OPTIONS CONTRIBUTING PLATFORMS CODE_OF_CONDUCT \
|
||||||
|
|
||||||
HTMLPAGES = isc-config.sh.html
|
|
||||||
|
|
||||||
MANOBJS = README HISTORY OPTIONS CONTRIBUTING PLATFORMS \
|
|
||||||
${MANPAGES} ${HTMLPAGES}
|
${MANPAGES} ${HTMLPAGES}
|
||||||
|
|
||||||
@BIND9_MAKE_RULES@
|
@BIND9_MAKE_RULES@
|
||||||
@@ -35,7 +31,7 @@ bind.keys.h: ${top_srcdir}/bind.keys ${srcdir}/util/bindkeys.pl
|
|||||||
|
|
||||||
distclean::
|
distclean::
|
||||||
rm -f config.cache config.h config.log config.status TAGS
|
rm -f config.cache config.h config.log config.status TAGS
|
||||||
rm -f libtool isc-config.sh configure.lineno
|
rm -f libtool configure.lineno
|
||||||
rm -f util/conf.sh docutil/docbook2man-wrapper.sh
|
rm -f util/conf.sh docutil/docbook2man-wrapper.sh
|
||||||
|
|
||||||
# XXX we should clean libtool stuff too. Only do this after we add rules
|
# XXX we should clean libtool stuff too. Only do this after we add rules
|
||||||
@@ -54,25 +50,11 @@ installdirs:
|
|||||||
${DESTDIR}${localstatedir}/run ${DESTDIR}${sysconfdir}
|
${DESTDIR}${localstatedir}/run ${DESTDIR}${sysconfdir}
|
||||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
install:: isc-config.sh installdirs
|
install:: installdirs
|
||||||
${INSTALL_SCRIPT} isc-config.sh ${DESTDIR}${bindir}
|
|
||||||
rm -f ${DESTDIR}${bindir}/bind9-config
|
|
||||||
@LN@ ${DESTDIR}${bindir}/isc-config.sh ${DESTDIR}${bindir}/bind9-config
|
|
||||||
${INSTALL_DATA} ${top_srcdir}/isc-config.sh.1 ${DESTDIR}${mandir}/man1
|
|
||||||
rm -f ${DESTDIR}${mandir}/man1/bind9-config.1
|
|
||||||
@LN@ ${DESTDIR}${mandir}/man1/isc-config.sh.1 ${DESTDIR}${mandir}/man1/bind9-config.1
|
|
||||||
${INSTALL_DATA} ${top_srcdir}/bind.keys ${DESTDIR}${sysconfdir}
|
${INSTALL_DATA} ${top_srcdir}/bind.keys ${DESTDIR}${sysconfdir}
|
||||||
|
|
||||||
uninstall::
|
uninstall::
|
||||||
rm -f ${DESTDIR}${sysconfdir}/bind.keys
|
rm -f ${DESTDIR}${sysconfdir}/bind.keys
|
||||||
rm -f ${DESTDIR}${mandir}/man1/bind9-config.1
|
|
||||||
rm -f ${DESTDIR}${mandir}/man1/isc-config.sh.1
|
|
||||||
rm -f ${DESTDIR}${bindir}/bind9-config
|
|
||||||
rm -f ${DESTDIR}${bindir}/isc-config.sh
|
|
||||||
|
|
||||||
tags:
|
|
||||||
rm -f TAGS
|
|
||||||
find lib bin -name "*.[ch]" -print | @ETAGS@ -
|
|
||||||
|
|
||||||
test check:
|
test check:
|
||||||
@if test -n "`${PERL} ${top_srcdir}/bin/tests/system/testsock.pl 2>/dev/null || echo fail`"; then \
|
@if test -n "`${PERL} ${top_srcdir}/bin/tests/system/testsock.pl 2>/dev/null || echo fail`"; then \
|
||||||
@@ -97,27 +79,32 @@ test-force:
|
|||||||
exit $$status
|
exit $$status
|
||||||
|
|
||||||
README: README.md
|
README: README.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html README.md | \
|
${PANDOC} --email-obfuscation=none -s --metadata title="README" -f markdown-smart -t html README.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
sed -e '$${/^$$/d;}' > $@
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
HISTORY: HISTORY.md
|
HISTORY: HISTORY.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html HISTORY.md | \
|
${PANDOC} --email-obfuscation=none -s --metadata title="HISTORY" -f markdown-smart -t html HISTORY.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
sed -e '$${/^$$/d;}' > $@
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
OPTIONS: OPTIONS.md
|
OPTIONS: OPTIONS.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html OPTIONS.md | \
|
${PANDOC} --email-obfuscation=none -s --metadata title="OPTIONS" -f markdown-smart -t html OPTIONS.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
sed -e '$${/^$$/d;}' > $@
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
CONTRIBUTING: CONTRIBUTING.md
|
CONTRIBUTING: CONTRIBUTING.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html CONTRIBUTING.md | \
|
${PANDOC} --email-obfuscation=none -s --metadata title="CONTRIBUTING" -f markdown-smart -t html CONTRIBUTING.md | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
sed -e '$${/^$$/d;}' > $@
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
PLATFORMS: PLATFORMS.md
|
PLATFORMS: PLATFORMS.md
|
||||||
${PANDOC} --email-obfuscation=none -s -t html PLATFORMS.md | \
|
${PANDOC} --email-obfuscation=none -s --metadata title="PLATFORMS" -f markdown-smart -t html PLATFORMS.md | \
|
||||||
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
|
CODE_OF_CONDUCT: CODE_OF_CONDUCT.md
|
||||||
|
${PANDOC} --email-obfuscation=none -s --metadata title="CODE OF CONDUCT" -f markdown-smart -t html $< | \
|
||||||
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
${W3M} -dump -cols 75 -O ascii -T text/html | \
|
||||||
sed -e '$${/^$$/d;}' > $@
|
sed -e '$${/^$$/d;}' > $@
|
||||||
|
|
||||||
|
|||||||
@@ -1,10 +1,12 @@
|
|||||||
|
OPTIONS
|
||||||
|
|
||||||
Setting the STD_CDEFINES environment variable before running configure can
|
Setting the STD_CDEFINES environment variable before running configure can
|
||||||
be used to enable certain compile-time options that are not explicitly
|
be used to enable certain compile-time options that are not explicitly
|
||||||
defined in configure.
|
defined in configure.
|
||||||
|
|
||||||
Some of these settings are:
|
Some of these settings are:
|
||||||
|
|
||||||
Setting Description
|
Setting Description
|
||||||
Overwrite memory with tag values when allocating
|
Overwrite memory with tag values when allocating
|
||||||
-DISC_MEM_DEFAULTFILL=1 or freeing it; this impairs performance but
|
-DISC_MEM_DEFAULTFILL=1 or freeing it; this impairs performance but
|
||||||
makes debugging of memory problems easier.
|
makes debugging of memory problems easier.
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
PLATFORMS
|
||||||
|
|
||||||
Supported platforms
|
Supported platforms
|
||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
In general, this version of BIND will build and run on any POSIX-compliant
|
||||||
@@ -13,7 +15,7 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
Regularly tested platforms
|
Regularly tested platforms
|
||||||
|
|
||||||
As of Jan 2019, BIND 9.13 is fully supported and regularly tested on the
|
As of Feb 2019, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 8, 9, 10
|
* Debian 8, 9, 10
|
||||||
@@ -51,7 +53,7 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
|
|
||||||
Unsupported platforms
|
Unsupported platforms
|
||||||
|
|
||||||
These are platforms on which BIND 9.13 is known not to build or run:
|
These are platforms on which BIND 9.15 is known not to build or run:
|
||||||
|
|
||||||
* Platforms without at least OpenSSL 1.0.2
|
* Platforms without at least OpenSSL 1.0.2
|
||||||
* Windows 10 / x86
|
* Windows 10 / x86
|
||||||
@@ -64,27 +66,10 @@ These are platforms on which BIND 9.13 is known not to build or run:
|
|||||||
|
|
||||||
Platform quirks
|
Platform quirks
|
||||||
|
|
||||||
ARM
|
NetBSD 6 i386
|
||||||
|
|
||||||
If the compilation ends with following error:
|
The i386 build of NetBSD requires the libatomic library, available from
|
||||||
|
the gcc5-libs package. Because this library is in a non-standard path, its
|
||||||
|
location must be specified in the configure command line:
|
||||||
|
|
||||||
Error: selected processor does not support `yield' in ARM mode
|
LDFLAGS="-L/usr/pkg/gcc5/i486--netbsdelf/lib/ -Wl,-R/usr/pkg/gcc5/i486--netbsdelf/lib/" ./configure
|
||||||
|
|
||||||
You will need to set -march compiler option to native, so the compiler
|
|
||||||
recognizes yield assembler instruction. The proper way to set -march=
|
|
||||||
native would be to put it into CFLAGS, e.g. run ./configure like this:
|
|
||||||
CFLAGS="-march=native -Os -g" ./configure plus your usual options.
|
|
||||||
|
|
||||||
If that doesn't work, you can enforce the minimum CPU and FPU (taken from
|
|
||||||
Debian armhf documentation):
|
|
||||||
|
|
||||||
* The lowest worthwhile CPU implementation is Armv7-A, therefore the
|
|
||||||
recommended build option is -march=armv7-a.
|
|
||||||
|
|
||||||
* FPU should be set at VFPv3-D16 as they represent the minimum
|
|
||||||
specification of the processors to support here, therefore the
|
|
||||||
recommended build option is -mfpu=vfpv3-d16.
|
|
||||||
|
|
||||||
The configure command should look like this:
|
|
||||||
|
|
||||||
CFLAGS="-march=armv7-a -mfpu=vfpv3-d16 -Os -g" ./configure
|
|
||||||
|
|||||||
+7
-26
@@ -23,7 +23,7 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
### Regularly tested platforms
|
### Regularly tested platforms
|
||||||
|
|
||||||
As of Jan 2019, BIND 9.13 is fully supported and regularly tested on the
|
As of Feb 2019, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 8, 9, 10
|
* Debian 8, 9, 10
|
||||||
@@ -60,7 +60,7 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
|
|
||||||
## Unsupported platforms
|
## Unsupported platforms
|
||||||
|
|
||||||
These are platforms on which BIND 9.13 is known *not* to build or run:
|
These are platforms on which BIND 9.15 is known *not* to build or run:
|
||||||
|
|
||||||
* Platforms without at least OpenSSL 1.0.2
|
* Platforms without at least OpenSSL 1.0.2
|
||||||
* Windows 10 / x86
|
* Windows 10 / x86
|
||||||
@@ -72,31 +72,12 @@ These are platforms on which BIND 9.13 is known *not* to build or run:
|
|||||||
|
|
||||||
## Platform quirks
|
## Platform quirks
|
||||||
|
|
||||||
### ARM
|
### NetBSD 6 i386
|
||||||
|
|
||||||
If the compilation ends with following error:
|
The i386 build of NetBSD requires the `libatomic` library, available from
|
||||||
|
the `gcc5-libs` package. Because this library is in a non-standard path,
|
||||||
|
its location must be specified in the `configure` command line:
|
||||||
|
|
||||||
```
|
```
|
||||||
Error: selected processor does not support `yield' in ARM mode
|
LDFLAGS="-L/usr/pkg/gcc5/i486--netbsdelf/lib/ -Wl,-R/usr/pkg/gcc5/i486--netbsdelf/lib/" ./configure
|
||||||
```
|
|
||||||
|
|
||||||
You will need to set `-march` compiler option to `native`, so the compiler
|
|
||||||
recognizes `yield` assembler instruction. The proper way to set `-march=native`
|
|
||||||
would be to put it into `CFLAGS`, e.g. run `./configure` like this:
|
|
||||||
`CFLAGS="-march=native -Os -g" ./configure` plus your usual options.
|
|
||||||
|
|
||||||
If that doesn't work, you can enforce the minimum CPU and FPU (taken from Debian
|
|
||||||
armhf documentation):
|
|
||||||
|
|
||||||
* The lowest worthwhile CPU implementation is Armv7-A, therefore the recommended
|
|
||||||
build option is `-march=armv7-a`.
|
|
||||||
|
|
||||||
* FPU should be set at VFPv3-D16 as they represent the minimum specification of
|
|
||||||
the processors to support here, therefore the recommended build option is
|
|
||||||
`-mfpu=vfpv3-d16`.
|
|
||||||
|
|
||||||
The configure command should look like this:
|
|
||||||
|
|
||||||
```
|
|
||||||
CFLAGS="-march=armv7-a -mfpu=vfpv3-d16 -Os -g" ./configure
|
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
README
|
||||||
|
|
||||||
BIND 9
|
BIND 9
|
||||||
|
|
||||||
Contents
|
Contents
|
||||||
@@ -5,7 +7,7 @@ Contents
|
|||||||
1. Introduction
|
1. Introduction
|
||||||
2. Reporting bugs and getting help
|
2. Reporting bugs and getting help
|
||||||
3. Contributing to BIND
|
3. Contributing to BIND
|
||||||
4. BIND 9.13 features
|
4. BIND 9.15 features
|
||||||
5. Building BIND
|
5. Building BIND
|
||||||
6. macOS
|
6. macOS
|
||||||
7. Dependencies
|
7. Dependencies
|
||||||
@@ -37,7 +39,7 @@ in versions 4 and 8. Internet Systems Consortium (https://www.isc.org), a
|
|||||||
501(c)(3) public benefit corporation dedicated to providing software and
|
501(c)(3) public benefit corporation dedicated to providing software and
|
||||||
services in support of the Internet infrastructure, developed BIND 9 and
|
services in support of the Internet infrastructure, developed BIND 9 and
|
||||||
is responsible for its ongoing maintenance and improvement. BIND is open
|
is responsible for its ongoing maintenance and improvement. BIND is open
|
||||||
source software licenced under the terms of the Mozilla Public License,
|
source software licensed under the terms of the Mozilla Public License,
|
||||||
version 2.0.
|
version 2.0.
|
||||||
|
|
||||||
For a summary of features introduced in past major releases of BIND, see
|
For a summary of features introduced in past major releases of BIND, see
|
||||||
@@ -85,8 +87,9 @@ ISC maintains a public git repository for BIND; details can be found at
|
|||||||
http://www.isc.org/git/.
|
http://www.isc.org/git/.
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files: -
|
Information for BIND contributors can be found in the following files: -
|
||||||
General information: CONTRIBUTING.md - BIND 9 code style: doc/dev/style.md
|
General information: CONTRIBUTING.md - Code of Conduct: CODE_OF_CONDUCT.md
|
||||||
- BIND architecture and developer guide: doc/dev/dev.md
|
- BIND 9 code style: doc/dev/style.md - BIND architecture and developer
|
||||||
|
guide: doc/dev/dev.md
|
||||||
|
|
||||||
Patches for BIND may be submitted as Merge Requests in the ISC GitLab
|
Patches for BIND may be submitted as Merge Requests in the ISC GitLab
|
||||||
server at at https://gitlab.isc.org/isc-projects/bind9/merge_requests.
|
server at at https://gitlab.isc.org/isc-projects/bind9/merge_requests.
|
||||||
@@ -100,45 +103,13 @@ If you prefer, you may also submit code by opening a GitLab Issue and
|
|||||||
including your patch as an attachment, preferably generated by git
|
including your patch as an attachment, preferably generated by git
|
||||||
format-patch.
|
format-patch.
|
||||||
|
|
||||||
BIND 9.13 features
|
BIND 9.15 features
|
||||||
|
|
||||||
BIND 9.13 is the newest development branch of BIND 9. It includes a number
|
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
||||||
of changes from BIND 9.12 and earlier releases. New features include:
|
of changes from BIND 9.14 and earlier releases. New features include:
|
||||||
|
|
||||||
* A new "plugin" mechanism has been added to allow query functionality
|
* Support for the new GeoIP2 geolocation API
|
||||||
to be extended using dynamically loadable libraries. The "filter-aaaa"
|
* Improved DNSSEC key configuration using dnssec-keys
|
||||||
feature has been removed from named and is now implemented as a
|
|
||||||
plugin.
|
|
||||||
* Socket and task code has been refactored to improve performance.
|
|
||||||
* QNAME minimization, as described in RFC 7816, is now supported.
|
|
||||||
* "Root key sentinel" support, enabling validating resolvers to indicate
|
|
||||||
via a special query which trust anchors are configured for the root
|
|
||||||
zone.
|
|
||||||
* Secondary zones can now be configured as "mirror" zones; their
|
|
||||||
contents are transferred in as with traditional slave zones, but are
|
|
||||||
subject to DNSSEC validation and are not treated as authoritative data
|
|
||||||
when answering. This makes it easier to configure a local copy of the
|
|
||||||
root zone as described in RFC 7706.
|
|
||||||
* The "validate-except" option allows configuration of domains below
|
|
||||||
which DNSSEC validation should not be performed.
|
|
||||||
* The default value of "dnssec-validation" is now "auto".
|
|
||||||
* IDNA2008 is now supported when linking with libidn2.
|
|
||||||
* "named -V" now outputs the default paths for files used by named and
|
|
||||||
other tools.
|
|
||||||
|
|
||||||
In addition, workarounds that were formerly in place to enable resolution
|
|
||||||
of domains whose authoritative servers did not respond to EDNS queries
|
|
||||||
have been removed. See https://dnsflagday.net for more details.
|
|
||||||
|
|
||||||
Cryptographic support has been modernized. BIND now uses the best
|
|
||||||
available pseudo-random number generator for the platform on which it's
|
|
||||||
built. Very old versions of OpenSSL are no longer supported. Cryptography
|
|
||||||
is now mandatory: building BIND without DNSSEC is no longer supported.
|
|
||||||
|
|
||||||
Special code to support certain legacy operating systems has also been
|
|
||||||
removed; see the file PLATFORMS.md for details of supported platforms. In
|
|
||||||
addition to OpenSSL, BIND now requires support for IPv6, threads, and
|
|
||||||
standard atomic operations provided by the C compiler.
|
|
||||||
|
|
||||||
Building BIND
|
Building BIND
|
||||||
|
|
||||||
@@ -169,7 +140,7 @@ make depend. If you're using Emacs, you might find make tags helpful.
|
|||||||
Several environment variables that can be set before running configure
|
Several environment variables that can be set before running configure
|
||||||
will affect compilation:
|
will affect compilation:
|
||||||
|
|
||||||
Variable Description
|
Variable Description
|
||||||
CC The C compiler to use. configure tries to figure out the
|
CC The C compiler to use. configure tries to figure out the
|
||||||
right one for supported systems.
|
right one for supported systems.
|
||||||
C compiler flags. Defaults to include -g and/or -O2 as
|
C compiler flags. Defaults to include -g and/or -O2 as
|
||||||
@@ -222,8 +193,10 @@ operations, specify the path to the PKCS#11 provider library using
|
|||||||
|
|
||||||
To support the HTTP statistics channel, the server must be linked with at
|
To support the HTTP statistics channel, the server must be linked with at
|
||||||
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
least one of the following: libxml2 http://xmlsoft.org or json-c https://
|
||||||
github.com/json-c. If these are installed at a nonstandard location,
|
github.com/json-c. If these are installed at a nonstandard location, then:
|
||||||
specify the prefix using --with-libxml2=/prefix or --with-libjson=/prefix.
|
|
||||||
|
* for libxml2, specify the prefix using --with-libxml2=/prefix,
|
||||||
|
* for json-c, adjust PKG_CONFIG_PATH.
|
||||||
|
|
||||||
To support compression on the HTTP statistics channel, the server must be
|
To support compression on the HTTP statistics channel, the server must be
|
||||||
linked against libzlib. If this is installed in a nonstandard location,
|
linked against libzlib. If this is installed in a nonstandard location,
|
||||||
@@ -233,10 +206,11 @@ To support storing configuration data for runtime-added zones in an LMDB
|
|||||||
database, the server must be linked with liblmdb. If this is installed in
|
database, the server must be linked with liblmdb. If this is installed in
|
||||||
a nonstandard location, specify the prefix using with-lmdb=/prefix.
|
a nonstandard location, specify the prefix using with-lmdb=/prefix.
|
||||||
|
|
||||||
To support GeoIP location-based ACLs, the server must be linked with
|
To support MaxMind GeoIP2 location-based ACLs, the server must be linked
|
||||||
libGeoIP. This is not turned on by default; BIND must be configured with
|
with libmaxminddb. This is turned on by default if the library is found;
|
||||||
--with-geoip. If the library is installed in a nonstandard location,
|
if the library is installed in a nonstandard location, specify the prefix
|
||||||
specify the prefix using --with-geoip=/prefix.
|
using --with-maxminddb=/prefix. GeoIP2 support can be switched off with
|
||||||
|
--disable-geoip.
|
||||||
|
|
||||||
For DNSTAP packet logging, you must have installed libfstrm https://
|
For DNSTAP packet logging, you must have installed libfstrm https://
|
||||||
github.com/farsightsec/fstrm and libprotobuf-c https://
|
github.com/farsightsec/fstrm and libprotobuf-c https://
|
||||||
@@ -274,11 +248,8 @@ default, installation is into /usr/local, but this can be changed with the
|
|||||||
|
|
||||||
You may specify the option --sysconfdir to set the directory where
|
You may specify the option --sysconfdir to set the directory where
|
||||||
configuration files like named.conf go by default, and --localstatedir to
|
configuration files like named.conf go by default, and --localstatedir to
|
||||||
set the default parent directory of run/named.pid. For backwards
|
set the default parent directory of run/named.pid. --sysconfdir defaults
|
||||||
compatibility with BIND 8, --sysconfdir defaults to /etc and
|
to $prefix/etc and --localstatedir defaults to $prefix/var.
|
||||||
--localstatedir defaults to /var if no --prefix option is given. If there
|
|
||||||
is a --prefix option, sysconfdir defaults to $prefix/etc and localstatedir
|
|
||||||
defaults to $prefix/var.
|
|
||||||
|
|
||||||
Automated testing
|
Automated testing
|
||||||
|
|
||||||
@@ -321,7 +292,7 @@ development BIND 9 is included in the file CHANGES, with the most recent
|
|||||||
changes listed first. Change notes include tags indicating the category of
|
changes listed first. Change notes include tags indicating the category of
|
||||||
the change that was made; these categories are:
|
the change that was made; these categories are:
|
||||||
|
|
||||||
Category Description
|
Category Description
|
||||||
[func] New feature
|
[func] New feature
|
||||||
[bug] General bug fix
|
[bug] General bug fix
|
||||||
[security] Fix for a significant security flaw
|
[security] Fix for a significant security flaw
|
||||||
@@ -349,26 +320,46 @@ releases (i.e., those with version numbers ending in zero). Some new
|
|||||||
functionality may be backported to older releases on a case-by-case basis.
|
functionality may be backported to older releases on a case-by-case basis.
|
||||||
All other change types may be applied to all currently-supported releases.
|
All other change types may be applied to all currently-supported releases.
|
||||||
|
|
||||||
|
Bug report identifiers
|
||||||
|
|
||||||
|
Most notes in the CHANGES file include a reference to a bug report or
|
||||||
|
issue number. Prior to 2018, these were usually of the form [RT #NNN] and
|
||||||
|
referred to entries in the "bind9-bugs" RT database, which was not open to
|
||||||
|
the public. More recent entries use the form [GL #NNN] or, less often, [GL
|
||||||
|
!NNN], which, respectively, refer to issues or merge requests in the
|
||||||
|
Gitlab database. Most of these are publicly readable, unless they include
|
||||||
|
information which is confidential or security senstive.
|
||||||
|
|
||||||
|
To look up a Gitlab issue by its number, use the URL https://
|
||||||
|
gitlab.isc.org/isc-projects/bind9/issues/NNN. To look up a merge request,
|
||||||
|
use https://gitlab.isc.org/isc-projects/bind9/merge_requests/NNN.
|
||||||
|
|
||||||
|
In rare cases, an issue or merge request number may be followed with the
|
||||||
|
letter "P". This indicates that the information is in the private ISC
|
||||||
|
Gitlab instance, which is not visible to the public.
|
||||||
|
|
||||||
Acknowledgments
|
Acknowledgments
|
||||||
|
|
||||||
* The original development of BIND 9 was underwritten by the following
|
* The original development of BIND 9 was underwritten by the following
|
||||||
organizations:
|
organizations:
|
||||||
|
|
||||||
Sun Microsystems, Inc.
|
Sun Microsystems, Inc.
|
||||||
Hewlett Packard
|
Hewlett Packard
|
||||||
Compaq Computer Corporation
|
Compaq Computer Corporation
|
||||||
IBM
|
IBM
|
||||||
Process Software Corporation
|
Process Software Corporation
|
||||||
Silicon Graphics, Inc.
|
Silicon Graphics, Inc.
|
||||||
Network Associates, Inc.
|
Network Associates, Inc.
|
||||||
U.S. Defense Information Systems Agency
|
U.S. Defense Information Systems Agency
|
||||||
USENIX Association
|
USENIX Association
|
||||||
Stichting NLnet - NLnet Foundation
|
Stichting NLnet - NLnet Foundation
|
||||||
Nominum, Inc.
|
Nominum, Inc.
|
||||||
|
|
||||||
* This product includes software developed by the OpenSSL Project for
|
* This product includes software developed by the OpenSSL Project for
|
||||||
use in the OpenSSL Toolkit. http://www.OpenSSL.org/
|
use in the OpenSSL Toolkit. http://www.OpenSSL.org/
|
||||||
|
|
||||||
* This product includes cryptographic software written by Eric Young
|
* This product includes cryptographic software written by Eric Young
|
||||||
(eay@cryptsoft.com)
|
(eay@cryptsoft.com)
|
||||||
|
|
||||||
* This product includes software written by Tim Hudson
|
* This product includes software written by Tim Hudson
|
||||||
(tjh@cryptsoft.com)
|
(tjh@cryptsoft.com)
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
1. [Introduction](#intro)
|
1. [Introduction](#intro)
|
||||||
1. [Reporting bugs and getting help](#help)
|
1. [Reporting bugs and getting help](#help)
|
||||||
1. [Contributing to BIND](#contrib)
|
1. [Contributing to BIND](#contrib)
|
||||||
1. [BIND 9.13 features](#features)
|
1. [BIND 9.15 features](#features)
|
||||||
1. [Building BIND](#build)
|
1. [Building BIND](#build)
|
||||||
1. [macOS](#macos)
|
1. [macOS](#macos)
|
||||||
1. [Dependencies](#dependencies)
|
1. [Dependencies](#dependencies)
|
||||||
@@ -48,7 +48,7 @@ used in versions 4 and 8. Internet Systems Consortium
|
|||||||
corporation dedicated to providing software and services in support of the
|
corporation dedicated to providing software and services in support of the
|
||||||
Internet infrastructure, developed BIND 9 and is responsible for its
|
Internet infrastructure, developed BIND 9 and is responsible for its
|
||||||
ongoing maintenance and improvement. BIND is open source software
|
ongoing maintenance and improvement. BIND is open source software
|
||||||
licenced under the terms of the Mozilla Public License, version 2.0.
|
licensed under the terms of the Mozilla Public License, version 2.0.
|
||||||
|
|
||||||
For a summary of features introduced in past major releases of BIND,
|
For a summary of features introduced in past major releases of BIND,
|
||||||
see the file [HISTORY](HISTORY.md).
|
see the file [HISTORY](HISTORY.md).
|
||||||
@@ -98,7 +98,8 @@ ISC maintains a public git repository for BIND; details can be found
|
|||||||
at [http://www.isc.org/git/](http://www.isc.org/git/).
|
at [http://www.isc.org/git/](http://www.isc.org/git/).
|
||||||
|
|
||||||
Information for BIND contributors can be found in the following files:
|
Information for BIND contributors can be found in the following files:
|
||||||
- General information: [CONTRIBUTING.md](CONTRIBUTING)
|
- General information: [CONTRIBUTING.md](CONTRIBUTING.md)
|
||||||
|
- Code of Conduct: [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md)
|
||||||
- BIND 9 code style: [doc/dev/style.md](doc/dev/style.md)
|
- BIND 9 code style: [doc/dev/style.md](doc/dev/style.md)
|
||||||
- BIND architecture and developer guide: [doc/dev/dev.md](doc/dev/dev.md)
|
- BIND architecture and developer guide: [doc/dev/dev.md](doc/dev/dev.md)
|
||||||
|
|
||||||
@@ -117,47 +118,15 @@ If you prefer, you may also submit code by opening a
|
|||||||
including your patch as an attachment, preferably generated by
|
including your patch as an attachment, preferably generated by
|
||||||
`git format-patch`.
|
`git format-patch`.
|
||||||
|
|
||||||
### <a name="features"/> BIND 9.13 features
|
### <a name="features"/> BIND 9.15 features
|
||||||
|
|
||||||
BIND 9.13 is the newest development branch of BIND 9. It includes a
|
BIND 9.15 is the newest development branch of BIND 9. It includes a
|
||||||
number of changes from BIND 9.12 and earlier releases. New features
|
number of changes from BIND 9.14 and earlier releases. New features
|
||||||
include:
|
include:
|
||||||
|
|
||||||
* A new "plugin" mechanism has been added to allow query functionality
|
* Support for the new GeoIP2 geolocation API
|
||||||
to be extended using dynamically loadable libraries. The "filter-aaaa"
|
* Improved DNSSEC key configuration using `dnssec-keys`
|
||||||
feature has been removed from named and is now implemented as a plugin.
|
* YAML output for dig, mdig, and delv.
|
||||||
* Socket and task code has been refactored to improve performance.
|
|
||||||
* QNAME minimization, as described in RFC 7816, is now supported.
|
|
||||||
* "Root key sentinel" support, enabling validating resolvers to indicate
|
|
||||||
via a special query which trust anchors are configured for the root zone.
|
|
||||||
* Secondary zones can now be configured as "mirror" zones; their contents
|
|
||||||
are transferred in as with traditional slave zones, but are subject to
|
|
||||||
DNSSEC validation and are not treated as authoritative data when
|
|
||||||
answering. This makes it easier to configure a local copy of the root
|
|
||||||
zone as described in RFC 7706.
|
|
||||||
* The "validate-except" option allows configuration of domains below which
|
|
||||||
DNSSEC validation should not be performed.
|
|
||||||
* The default value of "dnssec-validation" is now "auto".
|
|
||||||
* IDNA2008 is now supported when linking with `libidn2`.
|
|
||||||
* "named -V" now outputs the default paths for files used by named
|
|
||||||
and other tools.
|
|
||||||
|
|
||||||
In addition, workarounds that were formerly in place to enable resolution
|
|
||||||
of domains whose authoritative servers did not respond to EDNS queries
|
|
||||||
have been removed. See [https://dnsflagday.net](https://dnsflagday.net)
|
|
||||||
for more details.
|
|
||||||
|
|
||||||
Cryptographic support has been modernized. BIND now uses the
|
|
||||||
best available pseudo-random number generator for the platform on which
|
|
||||||
it's built. Very old versions of OpenSSL are no longer supported.
|
|
||||||
Cryptography is now mandatory: building BIND without DNSSEC is no
|
|
||||||
longer supported.
|
|
||||||
|
|
||||||
Special code to support certain legacy operating systems has also
|
|
||||||
been removed; see the file [PLATFORMS.md](PLATFORMS.md) for details
|
|
||||||
of supported platforms. In addition to OpenSSL, BIND now requires
|
|
||||||
support for IPv6, threads, and standard atomic operations provided
|
|
||||||
by the C compiler.
|
|
||||||
|
|
||||||
### <a name="build"/> Building BIND
|
### <a name="build"/> Building BIND
|
||||||
|
|
||||||
@@ -237,8 +206,10 @@ To support the HTTP statistics channel, the server must be linked with at
|
|||||||
least one of the following: libxml2
|
least one of the following: libxml2
|
||||||
[http://xmlsoft.org](http://xmlsoft.org) or json-c
|
[http://xmlsoft.org](http://xmlsoft.org) or json-c
|
||||||
[https://github.com/json-c](https://github.com/json-c). If these are
|
[https://github.com/json-c](https://github.com/json-c). If these are
|
||||||
installed at a nonstandard location, specify the prefix using
|
installed at a nonstandard location, then:
|
||||||
`--with-libxml2=/prefix` or `--with-libjson=/prefix`.
|
|
||||||
|
* for libxml2, specify the prefix using `--with-libxml2=/prefix`,
|
||||||
|
* for json-c, adjust `PKG_CONFIG_PATH`.
|
||||||
|
|
||||||
To support compression on the HTTP statistics channel, the server must be
|
To support compression on the HTTP statistics channel, the server must be
|
||||||
linked against libzlib. If this is installed in a nonstandard location,
|
linked against libzlib. If this is installed in a nonstandard location,
|
||||||
@@ -248,10 +219,11 @@ To support storing configuration data for runtime-added zones in an LMDB
|
|||||||
database, the server must be linked with liblmdb. If this is installed in a
|
database, the server must be linked with liblmdb. If this is installed in a
|
||||||
nonstandard location, specify the prefix using `with-lmdb=/prefix`.
|
nonstandard location, specify the prefix using `with-lmdb=/prefix`.
|
||||||
|
|
||||||
To support GeoIP location-based ACLs, the server must be linked with
|
To support MaxMind GeoIP2 location-based ACLs, the server must be linked
|
||||||
libGeoIP. This is not turned on by default; BIND must be configured with
|
with `libmaxminddb`. This is turned on by default if the library is
|
||||||
`--with-geoip`. If the library is installed in a nonstandard location,
|
found; if the library is installed in a nonstandard location,
|
||||||
specify the prefix using `--with-geoip=/prefix`.
|
specify the prefix using `--with-maxminddb=/prefix`. GeoIP2 support
|
||||||
|
can be switched off with `--disable-geoip`.
|
||||||
|
|
||||||
For DNSTAP packet logging, you must have installed libfstrm
|
For DNSTAP packet logging, you must have installed libfstrm
|
||||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||||
@@ -290,11 +262,8 @@ default, installation is into /usr/local, but this can be changed with the
|
|||||||
|
|
||||||
You may specify the option `--sysconfdir` to set the directory where
|
You may specify the option `--sysconfdir` to set the directory where
|
||||||
configuration files like `named.conf` go by default, and `--localstatedir`
|
configuration files like `named.conf` go by default, and `--localstatedir`
|
||||||
to set the default parent directory of `run/named.pid`. For backwards
|
to set the default parent directory of `run/named.pid`. `--sysconfdir`
|
||||||
compatibility with BIND 8, `--sysconfdir` defaults to `/etc` and
|
defaults to `$prefix/etc` and `--localstatedir` defaults to `$prefix/var`.
|
||||||
`--localstatedir` defaults to `/var` if no `--prefix` option is given. If
|
|
||||||
there is a `--prefix` option, sysconfdir defaults to `$prefix/etc` and
|
|
||||||
localstatedir defaults to `$prefix/var`.
|
|
||||||
|
|
||||||
### <a name="testing"/> Automated testing
|
### <a name="testing"/> Automated testing
|
||||||
|
|
||||||
@@ -360,6 +329,25 @@ releases (i.e., those with version numbers ending in zero). Some new
|
|||||||
functionality may be backported to older releases on a case-by-case basis.
|
functionality may be backported to older releases on a case-by-case basis.
|
||||||
All other change types may be applied to all currently-supported releases.
|
All other change types may be applied to all currently-supported releases.
|
||||||
|
|
||||||
|
#### Bug report identifiers
|
||||||
|
|
||||||
|
Most notes in the CHANGES file include a reference to a bug report or
|
||||||
|
issue number. Prior to 2018, these were usually of the form `[RT #NNN]`
|
||||||
|
and referred to entries in the "bind9-bugs" RT database, which was not open
|
||||||
|
to the public. More recent entries use the form `[GL #NNN]` or, less often,
|
||||||
|
`[GL !NNN]`, which, respectively, refer to issues or merge requests in the
|
||||||
|
Gitlab database. Most of these are publicly readable, unless they include
|
||||||
|
information which is confidential or security senstive.
|
||||||
|
|
||||||
|
To look up a Gitlab issue by its number, use the URL
|
||||||
|
[https://gitlab.isc.org/isc-projects/bind9/issues/NNN](https://gitlab.isc.org/isc-projects/bind9/issues).
|
||||||
|
To look up a merge request, use
|
||||||
|
[https://gitlab.isc.org/isc-projects/bind9/merge_requests/NNN](https://gitlab.isc.org/isc-projects/bind9/merge_requests).
|
||||||
|
|
||||||
|
In rare cases, an issue or merge request number may be followed with the
|
||||||
|
letter "P". This indicates that the information is in the private ISC
|
||||||
|
Gitlab instance, which is not visible to the public.
|
||||||
|
|
||||||
### <a name="ack"/> Acknowledgments
|
### <a name="ack"/> Acknowledgments
|
||||||
|
|
||||||
* The original development of BIND 9 was underwritten by the
|
* The original development of BIND 9 was underwritten by the
|
||||||
|
|||||||
Vendored
+89
@@ -288,9 +288,98 @@ AS_VAR_COPY([$1], [pkg_cv_][$1])
|
|||||||
AS_VAR_IF([$1], [""], [$5], [$4])dnl
|
AS_VAR_IF([$1], [""], [$5], [$4])dnl
|
||||||
])dnl PKG_CHECK_VAR
|
])dnl PKG_CHECK_VAR
|
||||||
|
|
||||||
|
# AM_CONDITIONAL -*- Autoconf -*-
|
||||||
|
|
||||||
|
# Copyright (C) 1997-2018 Free Software Foundation, Inc.
|
||||||
|
#
|
||||||
|
# This file is free software; the Free Software Foundation
|
||||||
|
# gives unlimited permission to copy and/or distribute it,
|
||||||
|
# with or without modifications, as long as this notice is preserved.
|
||||||
|
|
||||||
|
# AM_CONDITIONAL(NAME, SHELL-CONDITION)
|
||||||
|
# -------------------------------------
|
||||||
|
# Define a conditional.
|
||||||
|
AC_DEFUN([AM_CONDITIONAL],
|
||||||
|
[AC_PREREQ([2.52])dnl
|
||||||
|
m4_if([$1], [TRUE], [AC_FATAL([$0: invalid condition: $1])],
|
||||||
|
[$1], [FALSE], [AC_FATAL([$0: invalid condition: $1])])dnl
|
||||||
|
AC_SUBST([$1_TRUE])dnl
|
||||||
|
AC_SUBST([$1_FALSE])dnl
|
||||||
|
_AM_SUBST_NOTMAKE([$1_TRUE])dnl
|
||||||
|
_AM_SUBST_NOTMAKE([$1_FALSE])dnl
|
||||||
|
m4_define([_AM_COND_VALUE_$1], [$2])dnl
|
||||||
|
if $2; then
|
||||||
|
$1_TRUE=
|
||||||
|
$1_FALSE='#'
|
||||||
|
else
|
||||||
|
$1_TRUE='#'
|
||||||
|
$1_FALSE=
|
||||||
|
fi
|
||||||
|
AC_CONFIG_COMMANDS_PRE(
|
||||||
|
[if test -z "${$1_TRUE}" && test -z "${$1_FALSE}"; then
|
||||||
|
AC_MSG_ERROR([[conditional "$1" was never defined.
|
||||||
|
Usually this means the macro was only invoked conditionally.]])
|
||||||
|
fi])])
|
||||||
|
|
||||||
|
# Add --enable-maintainer-mode option to configure. -*- Autoconf -*-
|
||||||
|
# From Jim Meyering
|
||||||
|
|
||||||
|
# Copyright (C) 1996-2018 Free Software Foundation, Inc.
|
||||||
|
#
|
||||||
|
# This file is free software; the Free Software Foundation
|
||||||
|
# gives unlimited permission to copy and/or distribute it,
|
||||||
|
# with or without modifications, as long as this notice is preserved.
|
||||||
|
|
||||||
|
# AM_MAINTAINER_MODE([DEFAULT-MODE])
|
||||||
|
# ----------------------------------
|
||||||
|
# Control maintainer-specific portions of Makefiles.
|
||||||
|
# Default is to disable them, unless 'enable' is passed literally.
|
||||||
|
# For symmetry, 'disable' may be passed as well. Anyway, the user
|
||||||
|
# can override the default with the --enable/--disable switch.
|
||||||
|
AC_DEFUN([AM_MAINTAINER_MODE],
|
||||||
|
[m4_case(m4_default([$1], [disable]),
|
||||||
|
[enable], [m4_define([am_maintainer_other], [disable])],
|
||||||
|
[disable], [m4_define([am_maintainer_other], [enable])],
|
||||||
|
[m4_define([am_maintainer_other], [enable])
|
||||||
|
m4_warn([syntax], [unexpected argument to AM@&t@_MAINTAINER_MODE: $1])])
|
||||||
|
AC_MSG_CHECKING([whether to enable maintainer-specific portions of Makefiles])
|
||||||
|
dnl maintainer-mode's default is 'disable' unless 'enable' is passed
|
||||||
|
AC_ARG_ENABLE([maintainer-mode],
|
||||||
|
[AS_HELP_STRING([--]am_maintainer_other[-maintainer-mode],
|
||||||
|
am_maintainer_other[ make rules and dependencies not useful
|
||||||
|
(and sometimes confusing) to the casual installer])],
|
||||||
|
[USE_MAINTAINER_MODE=$enableval],
|
||||||
|
[USE_MAINTAINER_MODE=]m4_if(am_maintainer_other, [enable], [no], [yes]))
|
||||||
|
AC_MSG_RESULT([$USE_MAINTAINER_MODE])
|
||||||
|
AM_CONDITIONAL([MAINTAINER_MODE], [test $USE_MAINTAINER_MODE = yes])
|
||||||
|
MAINT=$MAINTAINER_MODE_TRUE
|
||||||
|
AC_SUBST([MAINT])dnl
|
||||||
|
]
|
||||||
|
)
|
||||||
|
|
||||||
|
# Copyright (C) 2006-2018 Free Software Foundation, Inc.
|
||||||
|
#
|
||||||
|
# This file is free software; the Free Software Foundation
|
||||||
|
# gives unlimited permission to copy and/or distribute it,
|
||||||
|
# with or without modifications, as long as this notice is preserved.
|
||||||
|
|
||||||
|
# _AM_SUBST_NOTMAKE(VARIABLE)
|
||||||
|
# ---------------------------
|
||||||
|
# Prevent Automake from outputting VARIABLE = @VARIABLE@ in Makefile.in.
|
||||||
|
# This macro is traced by Automake.
|
||||||
|
AC_DEFUN([_AM_SUBST_NOTMAKE])
|
||||||
|
|
||||||
|
# AM_SUBST_NOTMAKE(VARIABLE)
|
||||||
|
# --------------------------
|
||||||
|
# Public sister of _AM_SUBST_NOTMAKE.
|
||||||
|
AC_DEFUN([AM_SUBST_NOTMAKE], [_AM_SUBST_NOTMAKE($@)])
|
||||||
|
|
||||||
|
m4_include([m4/ax_check_compile_flag.m4])
|
||||||
m4_include([m4/ax_check_openssl.m4])
|
m4_include([m4/ax_check_openssl.m4])
|
||||||
m4_include([m4/ax_posix_shell.m4])
|
m4_include([m4/ax_posix_shell.m4])
|
||||||
m4_include([m4/ax_pthread.m4])
|
m4_include([m4/ax_pthread.m4])
|
||||||
|
m4_include([m4/ax_restore_flags.m4])
|
||||||
|
m4_include([m4/ax_save_flags.m4])
|
||||||
m4_include([m4/libtool.m4])
|
m4_include([m4/libtool.m4])
|
||||||
m4_include([m4/ltoptions.m4])
|
m4_include([m4/ltoptions.m4])
|
||||||
m4_include([m4/ltsugar.m4])
|
m4_include([m4/ltsugar.m4])
|
||||||
|
|||||||
@@ -16,15 +16,16 @@ VERSION=@BIND9_VERSION@
|
|||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
CINCLUDES = ${NS_INCLUDES} ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
CINCLUDES = ${NS_INCLUDES} ${BIND9_INCLUDES} ${DNS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
${ISC_INCLUDES} @OPENSSL_INCLUDES@
|
${ISC_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
CDEFINES = -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
CDEFINES = -DNAMED_CONFFILE=\"${sysconfdir}/named.conf\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @OPENSSL_LIBS@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
NSLIBS = ../../lib/ns/libns.@A@
|
NSLIBS = ../../lib/ns/libns.@A@
|
||||||
|
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
@@ -142,8 +140,6 @@ add(char *key, int value) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
key = isc_mem_strdup(sym_mctx, key);
|
key = isc_mem_strdup(sym_mctx, key);
|
||||||
if (key == NULL)
|
|
||||||
return;
|
|
||||||
|
|
||||||
symvalue.as_pointer = NULL;
|
symvalue.as_pointer = NULL;
|
||||||
result = isc_symtab_define(symtab, key, value, symvalue,
|
result = isc_symtab_define(symtab, key, value, symvalue,
|
||||||
@@ -668,7 +664,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
|||||||
origin = dns_fixedname_initname(&fixorigin);
|
origin = dns_fixedname_initname(&fixorigin);
|
||||||
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
CHECK(dns_name_fromtext(origin, &buffer, dns_rootname, 0, NULL));
|
||||||
CHECK(dns_zone_setorigin(zone, origin));
|
CHECK(dns_zone_setorigin(zone, origin));
|
||||||
CHECK(dns_zone_setdbtype(zone, 1, (const char * const *) dbtype));
|
dns_zone_setdbtype(zone, 1, (const char * const *) dbtype);
|
||||||
CHECK(dns_zone_setfile(zone, filename, fileformat,
|
CHECK(dns_zone_setfile(zone, filename, fileformat,
|
||||||
&dns_master_style_default));
|
&dns_master_style_default));
|
||||||
if (journal != NULL)
|
if (journal != NULL)
|
||||||
|
|||||||
@@ -86,6 +86,11 @@ Check "core" configuration only\&. This suppresses the loading of plugin modules
|
|||||||
statements to be ignored\&.
|
statements to be ignored\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-i
|
||||||
|
.RS 4
|
||||||
|
Ignore warnings on deprecated options\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-p
|
\-p
|
||||||
.RS 4
|
.RS 4
|
||||||
Print out the
|
Print out the
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -30,6 +28,7 @@
|
|||||||
#include <isc/util.h>
|
#include <isc/util.h>
|
||||||
|
|
||||||
#include <isccfg/namedconf.h>
|
#include <isccfg/namedconf.h>
|
||||||
|
#include <isccfg/grammar.h>
|
||||||
|
|
||||||
#include <bind9/check.h>
|
#include <bind9/check.h>
|
||||||
|
|
||||||
@@ -63,7 +62,7 @@ usage(void) ISC_PLATFORM_NORETURN_POST;
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
usage(void) {
|
usage(void) {
|
||||||
fprintf(stderr, "usage: %s [-hjlvz] [-p [-x]] [-t directory] "
|
fprintf(stderr, "usage: %s [-chijlvz] [-p [-x]] [-t directory] "
|
||||||
"[named.conf]\n", program);
|
"[named.conf]\n", program);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
@@ -557,6 +556,7 @@ main(int argc, char **argv) {
|
|||||||
bool load_zones = false;
|
bool load_zones = false;
|
||||||
bool list_zones = false;
|
bool list_zones = false;
|
||||||
bool print = false;
|
bool print = false;
|
||||||
|
bool nodeprecate = false;
|
||||||
unsigned int flags = 0;
|
unsigned int flags = 0;
|
||||||
|
|
||||||
isc_commandline_errprint = false;
|
isc_commandline_errprint = false;
|
||||||
@@ -564,7 +564,7 @@ main(int argc, char **argv) {
|
|||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
*/
|
*/
|
||||||
#define CMDLINE_FLAGS "cdhjlm:t:pvxz"
|
#define CMDLINE_FLAGS "cdhijlm:t:pvxz"
|
||||||
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((c = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (c) {
|
switch (c) {
|
||||||
case 'm':
|
case 'm':
|
||||||
@@ -597,6 +597,10 @@ main(int argc, char **argv) {
|
|||||||
debug++;
|
debug++;
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case 'i':
|
||||||
|
nodeprecate = true;
|
||||||
|
break;
|
||||||
|
|
||||||
case 'j':
|
case 'j':
|
||||||
nomerge = false;
|
nomerge = false;
|
||||||
break;
|
break;
|
||||||
@@ -677,11 +681,16 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
RUNTIME_CHECK(cfg_parser_create(mctx, logc, &parser) == ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
if (nodeprecate) {
|
||||||
|
cfg_parser_setflags(parser, CFG_PCTX_NODEPRECATED, true);
|
||||||
|
}
|
||||||
cfg_parser_setcallback(parser, directory_callback, NULL);
|
cfg_parser_setcallback(parser, directory_callback, NULL);
|
||||||
|
|
||||||
if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
|
if (cfg_parse_file(parser, conffile, &cfg_type_namedconf, &config) !=
|
||||||
ISC_R_SUCCESS)
|
ISC_R_SUCCESS)
|
||||||
|
{
|
||||||
exit(1);
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
result = bind9_check_namedconf(config, loadplugins, logc, mctx);
|
result = bind9_check_namedconf(config, loadplugins, logc, mctx);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
|||||||
@@ -126,6 +126,15 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-i</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Ignore warnings on deprecated options.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-p</term>
|
<term>-p</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -96,6 +96,12 @@
|
|||||||
<span class="command"><strong>plugin</strong></span> statements to be ignored.
|
<span class="command"><strong>plugin</strong></span> statements to be ignored.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-i</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Ignore warnings on deprecated options.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-p</span></dt>
|
<dt><span class="term">-p</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
|
|||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -89,6 +90,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -65,6 +65,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -88,6 +89,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\ns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -95,6 +96,7 @@ copy /Y named-checkzone.ilk named-compilezone.ilk
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -27,9 +27,9 @@ CWARNINGS =
|
|||||||
|
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @OPENSSL_LIBS@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
|||||||
@@ -17,8 +17,6 @@
|
|||||||
* and the corresponding key and update-policy statements in named.conf.
|
* and the corresponding key and update-policy statements in named.conf.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdarg.h>
|
#include <stdarg.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -224,8 +222,6 @@ main(int argc, char **argv) {
|
|||||||
if (suffix != NULL) {
|
if (suffix != NULL) {
|
||||||
len = strlen(keyname) + strlen(suffix) + 2;
|
len = strlen(keyname) + strlen(suffix) + 2;
|
||||||
keybuf = isc_mem_get(mctx, len);
|
keybuf = isc_mem_get(mctx, len);
|
||||||
if (keybuf == NULL)
|
|
||||||
fatal("failed to allocate memory for keyname");
|
|
||||||
snprintf(keybuf, len, "%s.%s", keyname, suffix);
|
snprintf(keybuf, len, "%s.%s", keyname, suffix);
|
||||||
keyname = (const char *) keybuf;
|
keyname = (const char *) keybuf;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <stdarg.h>
|
#include <stdarg.h>
|
||||||
|
|
||||||
|
|||||||
@@ -20,8 +20,6 @@
|
|||||||
* controls statement altogether.
|
* controls statement altogether.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdarg.h>
|
#include <stdarg.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -224,8 +222,6 @@ main(int argc, char **argv) {
|
|||||||
char *buf;
|
char *buf;
|
||||||
len = strlen(chrootdir) + strlen(keyfile) + 2;
|
len = strlen(chrootdir) + strlen(keyfile) + 2;
|
||||||
buf = isc_mem_get(mctx, len);
|
buf = isc_mem_get(mctx, len);
|
||||||
if (buf == NULL)
|
|
||||||
fatal("isc_mem_get(%d) failed\n", len);
|
|
||||||
snprintf(buf, len, "%s%s%s", chrootdir,
|
snprintf(buf, len, "%s%s%s", chrootdir,
|
||||||
(*keyfile != '/') ? "/" : "", keyfile);
|
(*keyfile != '/') ? "/" : "", keyfile);
|
||||||
|
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
#include <confgen/os.h>
|
||||||
|
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
|
|||||||
@@ -12,8 +12,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdarg.h>
|
#include <stdarg.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
|
|||||||
@@ -60,6 +60,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -84,6 +85,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -95,6 +96,7 @@ copy /Y ddns-confgen.ilk tsig-keygen.ilk
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -9,9 +9,6 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <confgen/os.h>
|
#include <confgen/os.h>
|
||||||
|
|
||||||
#include <fcntl.h>
|
#include <fcntl.h>
|
||||||
|
|||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -89,6 +90,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;..\..\..\lib\isccc\include;..\..\..\lib\isccfg\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -16,16 +16,17 @@ VERSION=@BIND9_VERSION@
|
|||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @OPENSSL_INCLUDES@
|
${IRS_INCLUDES} ${ISCCFG_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\" \
|
CDEFINES = -DVERSION=\"${VERSION}\" \
|
||||||
-DSYSCONFDIR=\"${sysconfdir}\"
|
-DSYSCONFDIR=\"${sysconfdir}\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @OPENSSL_LIBS@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
IRSLIBS = ../../lib/irs/libirs.@A@
|
IRSLIBS = ../../lib/irs/libirs.@A@
|
||||||
|
|
||||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
|||||||
+13
-22
@@ -53,7 +53,7 @@ is a tool for sending DNS queries and validating the results, using the same int
|
|||||||
\fBnamed\fR\&.
|
\fBnamed\fR\&.
|
||||||
.PP
|
.PP
|
||||||
\fBdelv\fR
|
\fBdelv\fR
|
||||||
will send to a specified name server all queries needed to fetch and validate the requested data; this includes the original requested query, subsequent queries to follow CNAME or DNAME chains, and queries for DNSKEY, DS and DLV records to establish a chain of trust for DNSSEC validation\&. It does not perform iterative resolution, but simulates the behavior of a name server configured for DNSSEC validating and forwarding\&.
|
will send to a specified name server all queries needed to fetch and validate the requested data; this includes the original requested query, subsequent queries to follow CNAME or DNAME chains, and queries for DNSKEY and DS records to establish a chain of trust for DNSSEC validation\&. It does not perform iterative resolution, but simulates the behavior of a name server configured for DNSSEC validating and forwarding\&.
|
||||||
.PP
|
.PP
|
||||||
By default, responses are validated using built\-in DNSSEC trust anchor for the root zone ("\&.")\&. Records returned by
|
By default, responses are validated using built\-in DNSSEC trust anchor for the root zone ("\&.")\&. Records returned by
|
||||||
\fBdelv\fR
|
\fBdelv\fR
|
||||||
@@ -139,21 +139,21 @@ BIND
|
|||||||
.sp
|
.sp
|
||||||
Keys that do not match the root zone name are ignored\&. An alternate key name can be specified using the
|
Keys that do not match the root zone name are ignored\&. An alternate key name can be specified using the
|
||||||
\fB+root=NAME\fR
|
\fB+root=NAME\fR
|
||||||
options\&. DNSSEC Lookaside Validation can also be turned on by using the
|
options\&.
|
||||||
\fB+dlv=NAME\fR
|
|
||||||
to specify the name of a zone containing DLV records\&.
|
|
||||||
.sp
|
.sp
|
||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
\fBdelv\fR
|
\fBdelv\fR
|
||||||
treats
|
treats
|
||||||
\fBmanaged\-keys\fR
|
\fBdnssec\-keys\fR\fBinitial\-key\fR
|
||||||
statements and
|
and
|
||||||
\fBtrusted\-keys\fR
|
\fBstatic\-key\fR
|
||||||
statements identically\&. That is, for a managed key, it is the
|
entries identically\&. That is, even if a key is configured with
|
||||||
\fIinitial\fR
|
\fBinitial\-key\fR, indicating that it is meant to be used only as an initializing key for RFC 5011 key maintenance, it is still treated by
|
||||||
key that is trusted; RFC 5011 key management is not supported\&.
|
|
||||||
\fBdelv\fR
|
\fBdelv\fR
|
||||||
will not consult the managed\-keys database maintained by
|
as if it had been configured as a
|
||||||
|
\fBstatic\-key\fR\&.
|
||||||
|
\fBdelv\fR
|
||||||
|
does not consult the managed keys database maintained by
|
||||||
\fBnamed\fR\&. This means that if either of the keys in
|
\fBnamed\fR\&. This means that if either of the keys in
|
||||||
/etc/bind\&.keys
|
/etc/bind\&.keys
|
||||||
is revoked and rolled over, it will be necessary to update
|
is revoked and rolled over, it will be necessary to update
|
||||||
@@ -390,25 +390,16 @@ output\&. The default is to do so\&. Note that (unlike in
|
|||||||
control whether to request DNSSEC records or whether to validate them\&. DNSSEC records are always requested, and validation will always occur unless suppressed by the use of
|
control whether to request DNSSEC records or whether to validate them\&. DNSSEC records are always requested, and validation will always occur unless suppressed by the use of
|
||||||
\fB\-i\fR
|
\fB\-i\fR
|
||||||
or
|
or
|
||||||
\fB+noroot\fR
|
\fB+noroot\fR\&.
|
||||||
and
|
|
||||||
\fB+nodlv\fR\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]root[=ROOT]\fR
|
\fB+[no]root[=ROOT]\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Indicates whether to perform conventional (non\-lookaside) DNSSEC validation, and if so, specifies the name of a trust anchor\&. The default is to validate using a trust anchor of "\&." (the root zone), for which there is a built\-in key\&. If specifying a different trust anchor, then
|
Indicates whether to perform conventional DNSSEC validation, and if so, specifies the name of a trust anchor\&. The default is to validate using a trust anchor of "\&." (the root zone), for which there is a built\-in key\&. If specifying a different trust anchor, then
|
||||||
\fB\-a\fR
|
\fB\-a\fR
|
||||||
must be used to specify a file containing the key\&.
|
must be used to specify a file containing the key\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]dlv[=DLV]\fR
|
|
||||||
.RS 4
|
|
||||||
Indicates whether to perform DNSSEC lookaside validation, and if so, specifies the name of the DLV trust anchor\&. The
|
|
||||||
\fB\-a\fR
|
|
||||||
option must also be used to specify a file containing the DLV key\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\fB+[no]tcp\fR
|
\fB+[no]tcp\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Controls whether to use TCP when sending queries\&. The default is to use UDP unless a truncated response has been received\&.
|
Controls whether to use TCP when sending queries\&. The default is to use UDP unless a truncated response has been received\&.
|
||||||
|
|||||||
+168
-133
@@ -9,7 +9,6 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
#include <bind.keys.h>
|
#include <bind.keys.h>
|
||||||
|
|
||||||
#ifndef WIN32
|
#ifndef WIN32
|
||||||
@@ -112,7 +111,8 @@ static bool
|
|||||||
nottl = false,
|
nottl = false,
|
||||||
multiline = false,
|
multiline = false,
|
||||||
short_form = false,
|
short_form = false,
|
||||||
print_unknown_format = false;
|
print_unknown_format = false,
|
||||||
|
yaml = false;
|
||||||
|
|
||||||
static bool
|
static bool
|
||||||
resolve_trace = false,
|
resolve_trace = false,
|
||||||
@@ -126,21 +126,19 @@ static bool
|
|||||||
static bool
|
static bool
|
||||||
cdflag = false,
|
cdflag = false,
|
||||||
no_sigs = false,
|
no_sigs = false,
|
||||||
root_validation = true,
|
root_validation = true;
|
||||||
dlv_validation = true;
|
|
||||||
|
|
||||||
static bool use_tcp = false;
|
static bool use_tcp = false;
|
||||||
|
|
||||||
static char *anchorfile = NULL;
|
static char *anchorfile = NULL;
|
||||||
static char *trust_anchor = NULL;
|
static char *trust_anchor = NULL;
|
||||||
static char *dlv_anchor = NULL;
|
static int num_keys = 0;
|
||||||
static int trusted_keys = 0;
|
|
||||||
|
|
||||||
static dns_fixedname_t afn, dfn;
|
static dns_fixedname_t afn;
|
||||||
static dns_name_t *anchor_name = NULL, *dlv_name = NULL;
|
static dns_name_t *anchor_name = NULL;
|
||||||
|
|
||||||
/* Default bind.keys contents */
|
/* Default bind.keys contents */
|
||||||
static char anchortext[] = MANAGED_KEYS;
|
static char anchortext[] = DNSSEC_KEYS;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Static function prototypes
|
* Static function prototypes
|
||||||
@@ -162,7 +160,7 @@ usage(void) {
|
|||||||
" q-opt is one of:\n"
|
" q-opt is one of:\n"
|
||||||
" -x dot-notation (shortcut for reverse lookups)\n"
|
" -x dot-notation (shortcut for reverse lookups)\n"
|
||||||
" -d level (set debugging level)\n"
|
" -d level (set debugging level)\n"
|
||||||
" -a anchor-file (specify root and dlv trust anchors)\n"
|
" -a anchor-file (specify root trust anchor)\n"
|
||||||
" -b address[#port] (bind to source address/port)\n"
|
" -b address[#port] (bind to source address/port)\n"
|
||||||
" -p port (specify port number)\n"
|
" -p port (specify port number)\n"
|
||||||
" -q name (specify query name)\n"
|
" -q name (specify query name)\n"
|
||||||
@@ -182,7 +180,8 @@ usage(void) {
|
|||||||
" +[no]comments (Control display of comment lines)\n"
|
" +[no]comments (Control display of comment lines)\n"
|
||||||
" +[no]rrcomments (Control display of per-record "
|
" +[no]rrcomments (Control display of per-record "
|
||||||
"comments)\n"
|
"comments)\n"
|
||||||
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" format)\n"
|
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
||||||
|
"\"unknown\" format)\n"
|
||||||
" +[no]short (Short form answer)\n"
|
" +[no]short (Short form answer)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||||
" +[no]tcp (TCP mode)\n"
|
" +[no]tcp (TCP mode)\n"
|
||||||
@@ -191,7 +190,7 @@ usage(void) {
|
|||||||
" +[no]rtrace (Trace resolver fetches)\n"
|
" +[no]rtrace (Trace resolver fetches)\n"
|
||||||
" +[no]mtrace (Trace messages received)\n"
|
" +[no]mtrace (Trace messages received)\n"
|
||||||
" +[no]vtrace (Trace validation process)\n"
|
" +[no]vtrace (Trace validation process)\n"
|
||||||
" +[no]dlv (DNSSEC lookaside validation anchor)\n"
|
" +[no]dlv (Obsolete)\n"
|
||||||
" +[no]root (DNSSEC validation trust anchor)\n"
|
" +[no]root (DNSSEC validation trust anchor)\n"
|
||||||
" +[no]dnssec (Display DNSSEC records)\n"
|
" +[no]dnssec (Display DNSSEC records)\n"
|
||||||
" -h (print help and exit)\n"
|
" -h (print help and exit)\n"
|
||||||
@@ -355,53 +354,80 @@ setup_logging(FILE *errout) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
print_status(dns_rdataset_t *rdataset) {
|
print_status(dns_rdataset_t *rdataset) {
|
||||||
const char *astr = "", *tstr = "";
|
char buf[1024] = { 0 };
|
||||||
|
|
||||||
REQUIRE(rdataset != NULL);
|
REQUIRE(rdataset != NULL);
|
||||||
|
|
||||||
if (!showtrust || !dns_rdataset_isassociated(rdataset))
|
if (!showtrust || !dns_rdataset_isassociated(rdataset)) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0)
|
buf[0] = '\0';
|
||||||
astr = "negative response, ";
|
|
||||||
|
if ((rdataset->attributes & DNS_RDATASETATTR_NEGATIVE) != 0) {
|
||||||
|
strlcat(buf, "negative response", sizeof(buf));
|
||||||
|
strlcat(buf, (yaml ? "_" : ", "), sizeof(buf));
|
||||||
|
}
|
||||||
|
|
||||||
switch (rdataset->trust) {
|
switch (rdataset->trust) {
|
||||||
case dns_trust_none:
|
case dns_trust_none:
|
||||||
tstr = "untrusted";
|
strlcat(buf, "untrusted", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_pending_additional:
|
case dns_trust_pending_additional:
|
||||||
tstr = "signed additional data, pending validation";
|
strlcat(buf, "signed additional data", sizeof(buf));
|
||||||
|
if (!yaml) {
|
||||||
|
strlcat(buf, ", ", sizeof(buf));
|
||||||
|
}
|
||||||
|
strlcat(buf, "pending validation", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_pending_answer:
|
case dns_trust_pending_answer:
|
||||||
tstr = "signed answer, pending validation";
|
strlcat(buf, "signed answer", sizeof(buf));
|
||||||
|
if (!yaml) {
|
||||||
|
strlcat(buf, ", ", sizeof(buf));
|
||||||
|
}
|
||||||
|
strlcat(buf, "pending validation", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_additional:
|
case dns_trust_additional:
|
||||||
tstr = "unsigned additional data";
|
strlcat(buf, "unsigned additional data", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_glue:
|
case dns_trust_glue:
|
||||||
tstr = "glue data";
|
strlcat(buf, "glue data", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_answer:
|
case dns_trust_answer:
|
||||||
if (root_validation || dlv_validation)
|
if (root_validation) {
|
||||||
tstr = "unsigned answer";
|
strlcat(buf, "unsigned answer", sizeof(buf));
|
||||||
else
|
} else {
|
||||||
tstr = "answer not validated";
|
strlcat(buf, "answer not validated", sizeof(buf));
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case dns_trust_authauthority:
|
case dns_trust_authauthority:
|
||||||
tstr = "authority data";
|
strlcat(buf, "authority data", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_authanswer:
|
case dns_trust_authanswer:
|
||||||
tstr = "authoritative";
|
strlcat(buf, "authoritative", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_secure:
|
case dns_trust_secure:
|
||||||
tstr = "fully validated";
|
strlcat(buf, "fully validated", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
case dns_trust_ultimate:
|
case dns_trust_ultimate:
|
||||||
tstr = "ultimate trust";
|
strlcat(buf, "ultimate trust", sizeof(buf));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
printf("; %s%s\n", astr, tstr);
|
if (yaml) {
|
||||||
|
char *p;
|
||||||
|
|
||||||
|
/* Convert spaces to underscores for YAML */
|
||||||
|
for (p = buf; p != NULL && *p != '\0'; p++) {
|
||||||
|
if (*p == ' ') {
|
||||||
|
*p = '_';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
printf(" - %s:\n", buf);
|
||||||
|
} else {
|
||||||
|
printf("; %s\n", buf);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
@@ -428,8 +454,9 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
if (first || rdataset->trust != trust) {
|
if (first || rdataset->trust != trust) {
|
||||||
if (!first && showtrust && !short_form)
|
if (!first && showtrust && !short_form && !yaml) {
|
||||||
putchar('\n');
|
putchar('\n');
|
||||||
|
}
|
||||||
print_status(rdataset);
|
print_status(rdataset);
|
||||||
trust = rdataset->trust;
|
trust = rdataset->trust;
|
||||||
first = false;
|
first = false;
|
||||||
@@ -437,8 +464,6 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
|||||||
|
|
||||||
do {
|
do {
|
||||||
t = isc_mem_get(mctx, len);
|
t = isc_mem_get(mctx, len);
|
||||||
if (t == NULL)
|
|
||||||
return (ISC_R_NOMEMORY);
|
|
||||||
|
|
||||||
isc_buffer_init(&target, t, len);
|
isc_buffer_init(&target, t, len);
|
||||||
if (short_form) {
|
if (short_form) {
|
||||||
@@ -470,9 +495,11 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
|||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if ((rdataset->attributes &
|
if (!yaml && (rdataset->attributes &
|
||||||
DNS_RDATASETATTR_NEGATIVE) != 0)
|
DNS_RDATASETATTR_NEGATIVE) != 0)
|
||||||
|
{
|
||||||
isc_buffer_putstr(&target, "; ");
|
isc_buffer_putstr(&target, "; ");
|
||||||
|
}
|
||||||
|
|
||||||
result = dns_master_rdatasettotext(owner, rdataset,
|
result = dns_master_rdatasettotext(owner, rdataset,
|
||||||
style, &target);
|
style, &target);
|
||||||
@@ -505,38 +532,52 @@ setup_style(dns_master_style_t **stylep) {
|
|||||||
REQUIRE(stylep != NULL || *stylep == NULL);
|
REQUIRE(stylep != NULL || *stylep == NULL);
|
||||||
|
|
||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (showcomments)
|
if (yaml) {
|
||||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
if (print_unknown_format)
|
dns_master_indentstr = " ";
|
||||||
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
dns_master_indent = 2;
|
||||||
if (rrcomments)
|
} else {
|
||||||
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
if (showcomments) {
|
||||||
if (nottl)
|
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||||
styleflags |= DNS_STYLEFLAG_NO_TTL;
|
}
|
||||||
if (noclass)
|
if (print_unknown_format) {
|
||||||
styleflags |= DNS_STYLEFLAG_NO_CLASS;
|
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
||||||
if (nocrypto)
|
}
|
||||||
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
if (rrcomments) {
|
||||||
if (multiline) {
|
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
||||||
styleflags |= DNS_STYLEFLAG_MULTILINE;
|
}
|
||||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
if (nottl) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NO_TTL;
|
||||||
|
}
|
||||||
|
if (noclass) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NO_CLASS;
|
||||||
|
}
|
||||||
|
if (nocrypto) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
||||||
|
}
|
||||||
|
if (multiline) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_MULTILINE;
|
||||||
|
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (multiline || (nottl && noclass))
|
if (multiline || (nottl && noclass)) {
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 24, 24, 32, 80, 8,
|
24, 24, 24, 32, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else if (nottl || noclass)
|
} else if (nottl || noclass) {
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 24, 32, 40, 80, 8,
|
24, 24, 32, 40, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else
|
} else {
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 32, 40, 48, 80, 8,
|
24, 32, 40, 48, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
|
}
|
||||||
|
|
||||||
if (result == ISC_R_SUCCESS)
|
if (result == ISC_R_SUCCESS) {
|
||||||
*stylep = style;
|
*stylep = style;
|
||||||
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -578,30 +619,30 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
dns_fixedname_t fkeyname;
|
dns_fixedname_t fkeyname;
|
||||||
dns_name_t *keyname;
|
dns_name_t *keyname;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool match_root = false, match_dlv = false;
|
bool match_root = false;
|
||||||
|
|
||||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||||
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
||||||
|
|
||||||
if (!root_validation && !dlv_validation)
|
if (!root_validation) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
if (anchor_name)
|
if (anchor_name) {
|
||||||
match_root = dns_name_equal(keyname, anchor_name);
|
match_root = dns_name_equal(keyname, anchor_name);
|
||||||
if (dlv_name)
|
}
|
||||||
match_dlv = dns_name_equal(keyname, dlv_name);
|
|
||||||
|
|
||||||
if (!match_root && !match_dlv)
|
if (!match_root) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
if ((!root_validation && match_root) || (!dlv_validation && match_dlv))
|
}
|
||||||
|
if (!root_validation && match_root) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
if (match_root)
|
if (match_root) {
|
||||||
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s",
|
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s",
|
||||||
trust_anchor);
|
trust_anchor);
|
||||||
if (match_dlv)
|
}
|
||||||
delv_log(ISC_LOG_DEBUG(3), "adding DLV trust anchor %s",
|
|
||||||
dlv_anchor);
|
|
||||||
|
|
||||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
||||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
||||||
@@ -643,7 +684,7 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
|
|
||||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||||
keyname, &rrdatabuf));
|
keyname, &rrdatabuf));
|
||||||
trusted_keys++;
|
num_keys++;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (result == DST_R_NOCRYPTO)
|
if (result == DST_R_NOCRYPTO)
|
||||||
@@ -694,13 +735,15 @@ static isc_result_t
|
|||||||
setup_dnsseckeys(dns_client_t *client) {
|
setup_dnsseckeys(dns_client_t *client) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
const cfg_obj_t *keys = NULL;
|
const cfg_obj_t *trusted_keys = NULL;
|
||||||
const cfg_obj_t *managed_keys = NULL;
|
const cfg_obj_t *managed_keys = NULL;
|
||||||
|
const cfg_obj_t *dnssec_keys = NULL;
|
||||||
cfg_obj_t *bindkeys = NULL;
|
cfg_obj_t *bindkeys = NULL;
|
||||||
const char *filename = anchorfile;
|
const char *filename = anchorfile;
|
||||||
|
|
||||||
if (!root_validation && !dlv_validation)
|
if (!root_validation) {
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
if (filename == NULL) {
|
if (filename == NULL) {
|
||||||
#ifndef WIN32
|
#ifndef WIN32
|
||||||
@@ -715,27 +758,27 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
|
|
||||||
if (trust_anchor == NULL) {
|
if (trust_anchor == NULL) {
|
||||||
trust_anchor = isc_mem_strdup(mctx, ".");
|
trust_anchor = isc_mem_strdup(mctx, ".");
|
||||||
if (trust_anchor == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (trust_anchor != NULL)
|
if (trust_anchor != NULL) {
|
||||||
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
CHECK(convert_name(&afn, &anchor_name, trust_anchor));
|
||||||
if (dlv_anchor != NULL)
|
}
|
||||||
CHECK(convert_name(&dfn, &dlv_name, dlv_anchor));
|
|
||||||
|
|
||||||
CHECK(cfg_parser_create(mctx, dns_lctx, &parser));
|
CHECK(cfg_parser_create(mctx, dns_lctx, &parser));
|
||||||
|
|
||||||
if (access(filename, R_OK) != 0) {
|
if (access(filename, R_OK) != 0) {
|
||||||
if (anchorfile != NULL)
|
if (anchorfile != NULL) {
|
||||||
fatal("Unable to read key file '%s'", anchorfile);
|
fatal("Unable to read key file '%s'", anchorfile);
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
result = cfg_parse_file(parser, filename,
|
result = cfg_parse_file(parser, filename,
|
||||||
&cfg_type_bindkeys, &bindkeys);
|
&cfg_type_bindkeys, &bindkeys);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
if (anchorfile != NULL)
|
if (anchorfile != NULL) {
|
||||||
fatal("Unable to load keys from '%s'",
|
fatal("Unable to load keys from '%s'",
|
||||||
anchorfile);
|
anchorfile);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (bindkeys == NULL) {
|
if (bindkeys == NULL) {
|
||||||
@@ -745,26 +788,30 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
isc_buffer_add(&b, sizeof(anchortext) - 1);
|
isc_buffer_add(&b, sizeof(anchortext) - 1);
|
||||||
result = cfg_parse_buffer(parser, &b, NULL, 0,
|
result = cfg_parse_buffer(parser, &b, NULL, 0,
|
||||||
&cfg_type_bindkeys, 0, &bindkeys);
|
&cfg_type_bindkeys, 0, &bindkeys);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("Unable to parse built-in keys");
|
fatal("Unable to parse built-in keys");
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
INSIST(bindkeys != NULL);
|
INSIST(bindkeys != NULL);
|
||||||
cfg_map_get(bindkeys, "trusted-keys", &keys);
|
cfg_map_get(bindkeys, "trusted-keys", &trusted_keys);
|
||||||
cfg_map_get(bindkeys, "managed-keys", &managed_keys);
|
cfg_map_get(bindkeys, "managed-keys", &managed_keys);
|
||||||
|
cfg_map_get(bindkeys, "dnssec-keys", &dnssec_keys);
|
||||||
|
|
||||||
if (keys != NULL)
|
if (trusted_keys != NULL) {
|
||||||
CHECK(load_keys(keys, client));
|
CHECK(load_keys(trusted_keys, client));
|
||||||
if (managed_keys != NULL)
|
}
|
||||||
|
if (managed_keys != NULL) {
|
||||||
CHECK(load_keys(managed_keys, client));
|
CHECK(load_keys(managed_keys, client));
|
||||||
|
}
|
||||||
|
if (dnssec_keys != NULL) {
|
||||||
|
CHECK(load_keys(dnssec_keys, client));
|
||||||
|
}
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
if (trusted_keys == 0)
|
if (num_keys == 0) {
|
||||||
fatal("No trusted keys were loaded");
|
fatal("No trusted keys were loaded");
|
||||||
|
}
|
||||||
if (dlv_validation)
|
|
||||||
dns_client_setdlv(client, dns_rdataclass_in, dlv_anchor);
|
|
||||||
|
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (bindkeys != NULL) {
|
if (bindkeys != NULL) {
|
||||||
@@ -773,9 +820,10 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
if (parser != NULL) {
|
if (parser != NULL) {
|
||||||
cfg_parser_destroy(&parser);
|
cfg_parser_destroy(&parser);
|
||||||
}
|
}
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
delv_log(ISC_LOG_ERROR, "setup_dnsseckeys: %s",
|
delv_log(ISC_LOG_ERROR, "setup_dnsseckeys: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -802,8 +850,6 @@ addserver(dns_client_t *client) {
|
|||||||
fatal("Use of IPv4 disabled by -6");
|
fatal("Use of IPv4 disabled by -6");
|
||||||
}
|
}
|
||||||
sa = isc_mem_get(mctx, sizeof(*sa));
|
sa = isc_mem_get(mctx, sizeof(*sa));
|
||||||
if (sa == NULL)
|
|
||||||
return (ISC_R_NOMEMORY);
|
|
||||||
ISC_LINK_INIT(sa, link);
|
ISC_LINK_INIT(sa, link);
|
||||||
isc_sockaddr_fromin(sa, &in4, destport);
|
isc_sockaddr_fromin(sa, &in4, destport);
|
||||||
ISC_LIST_APPEND(servers, sa, link);
|
ISC_LIST_APPEND(servers, sa, link);
|
||||||
@@ -812,8 +858,6 @@ addserver(dns_client_t *client) {
|
|||||||
fatal("Use of IPv6 disabled by -4");
|
fatal("Use of IPv6 disabled by -4");
|
||||||
}
|
}
|
||||||
sa = isc_mem_get(mctx, sizeof(*sa));
|
sa = isc_mem_get(mctx, sizeof(*sa));
|
||||||
if (sa == NULL)
|
|
||||||
return (ISC_R_NOMEMORY);
|
|
||||||
ISC_LINK_INIT(sa, link);
|
ISC_LINK_INIT(sa, link);
|
||||||
isc_sockaddr_fromin6(sa, &in6, destport);
|
isc_sockaddr_fromin6(sa, &in6, destport);
|
||||||
ISC_LIST_APPEND(servers, sa, link);
|
ISC_LIST_APPEND(servers, sa, link);
|
||||||
@@ -841,10 +885,6 @@ addserver(dns_client_t *client) {
|
|||||||
cur->ai_family != AF_INET6)
|
cur->ai_family != AF_INET6)
|
||||||
continue;
|
continue;
|
||||||
sa = isc_mem_get(mctx, sizeof(*sa));
|
sa = isc_mem_get(mctx, sizeof(*sa));
|
||||||
if (sa == NULL) {
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
memset(sa, 0, sizeof(*sa));
|
memset(sa, 0, sizeof(*sa));
|
||||||
ISC_LINK_INIT(sa, link);
|
ISC_LINK_INIT(sa, link);
|
||||||
memmove(&sa->type, cur->ai_addr, cur->ai_addrlen);
|
memmove(&sa->type, cur->ai_addr, cur->ai_addrlen);
|
||||||
@@ -917,10 +957,6 @@ findserver(dns_client_t *client) {
|
|||||||
struct in_addr localhost;
|
struct in_addr localhost;
|
||||||
localhost.s_addr = htonl(INADDR_LOOPBACK);
|
localhost.s_addr = htonl(INADDR_LOOPBACK);
|
||||||
sa = isc_mem_get(mctx, sizeof(*sa));
|
sa = isc_mem_get(mctx, sizeof(*sa));
|
||||||
if (sa == NULL) {
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
isc_sockaddr_fromin(sa, &localhost, destport);
|
isc_sockaddr_fromin(sa, &localhost, destport);
|
||||||
|
|
||||||
ISC_LINK_INIT(sa, link);
|
ISC_LINK_INIT(sa, link);
|
||||||
@@ -929,10 +965,6 @@ findserver(dns_client_t *client) {
|
|||||||
|
|
||||||
if (use_ipv6) {
|
if (use_ipv6) {
|
||||||
sa = isc_mem_get(mctx, sizeof(*sa));
|
sa = isc_mem_get(mctx, sizeof(*sa));
|
||||||
if (sa == NULL) {
|
|
||||||
result = ISC_R_NOMEMORY;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
isc_sockaddr_fromin6(sa, &in6addr_loopback, destport);
|
isc_sockaddr_fromin6(sa, &in6addr_loopback, destport);
|
||||||
|
|
||||||
ISC_LINK_INIT(sa, link);
|
ISC_LINK_INIT(sa, link);
|
||||||
@@ -1028,13 +1060,10 @@ plus_option(char *option) {
|
|||||||
switch (cmd[1]) {
|
switch (cmd[1]) {
|
||||||
case 'l': /* dlv */
|
case 'l': /* dlv */
|
||||||
FULLCHECK("dlv");
|
FULLCHECK("dlv");
|
||||||
if (state && no_sigs)
|
if (state) {
|
||||||
break;
|
fprintf(stderr, "Invalid option: "
|
||||||
dlv_validation = state;
|
"+dlv is obsolete\n");
|
||||||
if (value != NULL) {
|
exit(1);
|
||||||
dlv_anchor = isc_mem_strdup(mctx, value);
|
|
||||||
if (dlv_anchor == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case 'n': /* dnssec */
|
case 'n': /* dnssec */
|
||||||
@@ -1069,8 +1098,6 @@ plus_option(char *option) {
|
|||||||
root_validation = state;
|
root_validation = state;
|
||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
trust_anchor = isc_mem_strdup(mctx, value);
|
trust_anchor = isc_mem_strdup(mctx, value);
|
||||||
if (trust_anchor == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case 'r': /* rrcomments */
|
case 'r': /* rrcomments */
|
||||||
@@ -1158,6 +1185,13 @@ plus_option(char *option) {
|
|||||||
if (state)
|
if (state)
|
||||||
resolve_trace = state;
|
resolve_trace = state;
|
||||||
break;
|
break;
|
||||||
|
case 'y': /* yaml */
|
||||||
|
FULLCHECK("yaml");
|
||||||
|
yaml = state;
|
||||||
|
if (state) {
|
||||||
|
rrcomments = false;
|
||||||
|
}
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
invalid_option:
|
invalid_option:
|
||||||
/*
|
/*
|
||||||
@@ -1221,7 +1255,6 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
|||||||
/* NOTREACHED */
|
/* NOTREACHED */
|
||||||
case 'i':
|
case 'i':
|
||||||
no_sigs = true;
|
no_sigs = true;
|
||||||
dlv_validation = false;
|
|
||||||
root_validation = false;
|
root_validation = false;
|
||||||
break;
|
break;
|
||||||
case 'm':
|
case 'm':
|
||||||
@@ -1253,8 +1286,6 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
|||||||
switch (opt) {
|
switch (opt) {
|
||||||
case 'a':
|
case 'a':
|
||||||
anchorfile = isc_mem_strdup(mctx, value);
|
anchorfile = isc_mem_strdup(mctx, value);
|
||||||
if (anchorfile == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
case 'b':
|
case 'b':
|
||||||
hash = strchr(value, '#');
|
hash = strchr(value, '#');
|
||||||
@@ -1318,8 +1349,6 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
|||||||
isc_mem_free(mctx, curqname);
|
isc_mem_free(mctx, curqname);
|
||||||
}
|
}
|
||||||
curqname = isc_mem_strdup(mctx, value);
|
curqname = isc_mem_strdup(mctx, value);
|
||||||
if (curqname == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
case 't':
|
case 't':
|
||||||
*open_type_class = false;
|
*open_type_class = false;
|
||||||
@@ -1347,8 +1376,6 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
|||||||
warn("extra query name");
|
warn("extra query name");
|
||||||
}
|
}
|
||||||
curqname = isc_mem_strdup(mctx, textname);
|
curqname = isc_mem_strdup(mctx, textname);
|
||||||
if (curqname == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
if (typeset)
|
if (typeset)
|
||||||
warn("extra query type");
|
warn("extra query type");
|
||||||
qtype = dns_rdatatype_ptr;
|
qtype = dns_rdatatype_ptr;
|
||||||
@@ -1495,8 +1522,6 @@ parse_args(int argc, char **argv) {
|
|||||||
|
|
||||||
if (curqname == NULL) {
|
if (curqname == NULL) {
|
||||||
curqname = isc_mem_strdup(mctx, argv[0]);
|
curqname = isc_mem_strdup(mctx, argv[0]);
|
||||||
if (curqname == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1510,8 +1535,6 @@ parse_args(int argc, char **argv) {
|
|||||||
|
|
||||||
if (curqname == NULL) {
|
if (curqname == NULL) {
|
||||||
qname = isc_mem_strdup(mctx, ".");
|
qname = isc_mem_strdup(mctx, ".");
|
||||||
if (qname == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
|
|
||||||
if (!typeset)
|
if (!typeset)
|
||||||
qtype = dns_rdatatype_ns;
|
qtype = dns_rdatatype_ns;
|
||||||
@@ -1595,6 +1618,7 @@ main(int argc, char *argv[]) {
|
|||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_fixedname_t qfn;
|
dns_fixedname_t qfn;
|
||||||
dns_name_t *query_name, *response_name;
|
dns_name_t *query_name, *response_name;
|
||||||
|
char namestr[DNS_NAME_FORMATSIZE];
|
||||||
dns_rdataset_t *rdataset;
|
dns_rdataset_t *rdataset;
|
||||||
dns_namelist_t namelist;
|
dns_namelist_t namelist;
|
||||||
unsigned int resopt, clopt;
|
unsigned int resopt, clopt;
|
||||||
@@ -1623,9 +1647,9 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("failed to create mctx");
|
fatal("failed to create mctx");
|
||||||
|
|
||||||
CHECK(isc_appctx_create(mctx, &actx));
|
CHECK(isc_appctx_create(mctx, &actx));
|
||||||
CHECK(isc_taskmgr_createinctx(mctx, actx, 1, 0, &taskmgr));
|
CHECK(isc_taskmgr_createinctx(mctx, 1, 0, &taskmgr));
|
||||||
CHECK(isc_socketmgr_createinctx(mctx, actx, &socketmgr));
|
CHECK(isc_socketmgr_createinctx(mctx, &socketmgr));
|
||||||
CHECK(isc_timermgr_createinctx(mctx, actx, &timermgr));
|
CHECK(isc_timermgr_createinctx(mctx, &timermgr));
|
||||||
|
|
||||||
parse_args(argc, argv);
|
parse_args(argc, argv);
|
||||||
|
|
||||||
@@ -1666,22 +1690,35 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
/* Set up resolution options */
|
/* Set up resolution options */
|
||||||
resopt = DNS_CLIENTRESOPT_ALLOWRUN | DNS_CLIENTRESOPT_NOCDFLAG;
|
resopt = DNS_CLIENTRESOPT_ALLOWRUN | DNS_CLIENTRESOPT_NOCDFLAG;
|
||||||
if (no_sigs)
|
if (no_sigs) {
|
||||||
resopt |= DNS_CLIENTRESOPT_NODNSSEC;
|
resopt |= DNS_CLIENTRESOPT_NODNSSEC;
|
||||||
if (!root_validation && !dlv_validation)
|
}
|
||||||
|
if (!root_validation) {
|
||||||
resopt |= DNS_CLIENTRESOPT_NOVALIDATE;
|
resopt |= DNS_CLIENTRESOPT_NOVALIDATE;
|
||||||
if (cdflag)
|
}
|
||||||
|
if (cdflag) {
|
||||||
resopt &= ~DNS_CLIENTRESOPT_NOCDFLAG;
|
resopt &= ~DNS_CLIENTRESOPT_NOCDFLAG;
|
||||||
if (use_tcp)
|
}
|
||||||
|
if (use_tcp) {
|
||||||
resopt |= DNS_CLIENTRESOPT_TCP;
|
resopt |= DNS_CLIENTRESOPT_TCP;
|
||||||
|
}
|
||||||
|
|
||||||
/* Perform resolution */
|
/* Perform resolution */
|
||||||
ISC_LIST_INIT(namelist);
|
ISC_LIST_INIT(namelist);
|
||||||
result = dns_client_resolve(client, query_name, dns_rdataclass_in,
|
result = dns_client_resolve(client, query_name, dns_rdataclass_in,
|
||||||
qtype, resopt, &namelist);
|
qtype, resopt, &namelist);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS && !yaml) {
|
||||||
delv_log(ISC_LOG_ERROR, "resolution failed: %s",
|
delv_log(ISC_LOG_ERROR, "resolution failed: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (yaml) {
|
||||||
|
printf("type: DELV_RESULT\n");
|
||||||
|
dns_name_format(query_name, namestr, sizeof(namestr));
|
||||||
|
printf("query_name: %s\n", namestr);
|
||||||
|
printf("status: %s\n", isc_result_totext(result));
|
||||||
|
printf("records:\n");
|
||||||
|
}
|
||||||
|
|
||||||
for (response_name = ISC_LIST_HEAD(namelist);
|
for (response_name = ISC_LIST_HEAD(namelist);
|
||||||
response_name != NULL;
|
response_name != NULL;
|
||||||
@@ -1698,8 +1735,6 @@ main(int argc, char *argv[]) {
|
|||||||
dns_client_freeresanswer(client, &namelist);
|
dns_client_freeresanswer(client, &namelist);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (dlv_anchor != NULL)
|
|
||||||
isc_mem_free(mctx, dlv_anchor);
|
|
||||||
if (trust_anchor != NULL)
|
if (trust_anchor != NULL)
|
||||||
isc_mem_free(mctx, trust_anchor);
|
isc_mem_free(mctx, trust_anchor);
|
||||||
if (anchorfile != NULL)
|
if (anchorfile != NULL)
|
||||||
|
|||||||
+25
-28
@@ -96,7 +96,7 @@
|
|||||||
<command>delv</command> will send to a specified name server all
|
<command>delv</command> will send to a specified name server all
|
||||||
queries needed to fetch and validate the requested data; this
|
queries needed to fetch and validate the requested data; this
|
||||||
includes the original requested query, subsequent queries to follow
|
includes the original requested query, subsequent queries to follow
|
||||||
CNAME or DNAME chains, and queries for DNSKEY, DS and DLV records
|
CNAME or DNAME chains, and queries for DNSKEY and DS records
|
||||||
to establish a chain of trust for DNSSEC validation.
|
to establish a chain of trust for DNSSEC validation.
|
||||||
It does not perform iterative resolution, but simulates the
|
It does not perform iterative resolution, but simulates the
|
||||||
behavior of a name server configured for DNSSEC validating and
|
behavior of a name server configured for DNSSEC validating and
|
||||||
@@ -211,21 +211,21 @@
|
|||||||
<para>
|
<para>
|
||||||
Keys that do not match the root zone name are ignored.
|
Keys that do not match the root zone name are ignored.
|
||||||
An alternate key name can be specified using the
|
An alternate key name can be specified using the
|
||||||
<option>+root=NAME</option> options. DNSSEC Lookaside
|
<option>+root=NAME</option> options.
|
||||||
Validation can also be turned on by using the
|
|
||||||
<option>+dlv=NAME</option> to specify the name of a
|
|
||||||
zone containing DLV records.
|
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
<command>delv</command> treats <option>managed-keys</option>
|
<command>delv</command> treats <option>dnssec-keys</option>
|
||||||
statements and <option>trusted-keys</option> statements
|
<option>initial-key</option> and <option>static-key</option>
|
||||||
identically. That is, for a managed key, it is the
|
entries identically. That is, even if a key is configured
|
||||||
<emphasis>initial</emphasis> key that is trusted; RFC 5011
|
with <command>initial-key</command>, indicating that it is
|
||||||
key management is not supported. <command>delv</command>
|
meant to be used only as an initializing key for RFC 5011
|
||||||
will not consult the managed-keys database maintained by
|
key maintenance, it is still treated by <command>delv</command>
|
||||||
<command>named</command>. This means that if either of the
|
as if it had been configured as a <command>static-key</command>.
|
||||||
keys in <filename>/etc/bind.keys</filename> is revoked
|
<command>delv</command> does not consult the managed keys
|
||||||
|
database maintained by <command>named</command>. This means
|
||||||
|
that if either of the keys in
|
||||||
|
<filename>/etc/bind.keys</filename> is revoked
|
||||||
and rolled over, it will be necessary to update
|
and rolled over, it will be necessary to update
|
||||||
<filename>/etc/bind.keys</filename> to use DNSSEC
|
<filename>/etc/bind.keys</filename> to use DNSSEC
|
||||||
validation in <command>delv</command>.
|
validation in <command>delv</command>.
|
||||||
@@ -617,8 +617,7 @@
|
|||||||
request DNSSEC records or whether to validate them.
|
request DNSSEC records or whether to validate them.
|
||||||
DNSSEC records are always requested, and validation
|
DNSSEC records are always requested, and validation
|
||||||
will always occur unless suppressed by the use of
|
will always occur unless suppressed by the use of
|
||||||
<option>-i</option> or <option>+noroot</option> and
|
<option>-i</option> or <option>+noroot</option>.
|
||||||
<option>+nodlv</option>.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -627,7 +626,7 @@
|
|||||||
<term><option>+[no]root[=ROOT]</option></term>
|
<term><option>+[no]root[=ROOT]</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Indicates whether to perform conventional (non-lookaside)
|
Indicates whether to perform conventional
|
||||||
DNSSEC validation, and if so, specifies the
|
DNSSEC validation, and if so, specifies the
|
||||||
name of a trust anchor. The default is to validate using
|
name of a trust anchor. The default is to validate using
|
||||||
a trust anchor of "." (the root zone), for which there is
|
a trust anchor of "." (the root zone), for which there is
|
||||||
@@ -638,18 +637,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term><option>+[no]dlv[=DLV]</option></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Indicates whether to perform DNSSEC lookaside validation,
|
|
||||||
and if so, specifies the name of the DLV trust anchor.
|
|
||||||
The <option>-a</option> option must also be used to specify
|
|
||||||
a file containing the DLV key.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]tcp</option></term>
|
<term><option>+[no]tcp</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -671,6 +658,16 @@
|
|||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term><option>+[no]yaml</option></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print response data in YAML format.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
</variablelist>
|
</variablelist>
|
||||||
|
|
||||||
</para>
|
</para>
|
||||||
|
|||||||
+15
-25
@@ -83,7 +83,7 @@
|
|||||||
<span class="command"><strong>delv</strong></span> will send to a specified name server all
|
<span class="command"><strong>delv</strong></span> will send to a specified name server all
|
||||||
queries needed to fetch and validate the requested data; this
|
queries needed to fetch and validate the requested data; this
|
||||||
includes the original requested query, subsequent queries to follow
|
includes the original requested query, subsequent queries to follow
|
||||||
CNAME or DNAME chains, and queries for DNSKEY, DS and DLV records
|
CNAME or DNAME chains, and queries for DNSKEY and DS records
|
||||||
to establish a chain of trust for DNSSEC validation.
|
to establish a chain of trust for DNSSEC validation.
|
||||||
It does not perform iterative resolution, but simulates the
|
It does not perform iterative resolution, but simulates the
|
||||||
behavior of a name server configured for DNSSEC validating and
|
behavior of a name server configured for DNSSEC validating and
|
||||||
@@ -193,21 +193,21 @@
|
|||||||
<p>
|
<p>
|
||||||
Keys that do not match the root zone name are ignored.
|
Keys that do not match the root zone name are ignored.
|
||||||
An alternate key name can be specified using the
|
An alternate key name can be specified using the
|
||||||
<code class="option">+root=NAME</code> options. DNSSEC Lookaside
|
<code class="option">+root=NAME</code> options.
|
||||||
Validation can also be turned on by using the
|
|
||||||
<code class="option">+dlv=NAME</code> to specify the name of a
|
|
||||||
zone containing DLV records.
|
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
<span class="command"><strong>delv</strong></span> treats <code class="option">managed-keys</code>
|
<span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code>
|
||||||
statements and <code class="option">trusted-keys</code> statements
|
<code class="option">initial-key</code> and <code class="option">static-key</code>
|
||||||
identically. That is, for a managed key, it is the
|
entries identically. That is, even if a key is configured
|
||||||
<span class="emphasis"><em>initial</em></span> key that is trusted; RFC 5011
|
with <span class="command"><strong>initial-key</strong></span>, indicating that it is
|
||||||
key management is not supported. <span class="command"><strong>delv</strong></span>
|
meant to be used only as an initializing key for RFC 5011
|
||||||
will not consult the managed-keys database maintained by
|
key maintenance, it is still treated by <span class="command"><strong>delv</strong></span>
|
||||||
<span class="command"><strong>named</strong></span>. This means that if either of the
|
as if it had been configured as a <span class="command"><strong>static-key</strong></span>.
|
||||||
keys in <code class="filename">/etc/bind.keys</code> is revoked
|
<span class="command"><strong>delv</strong></span> does not consult the managed keys
|
||||||
|
database maintained by <span class="command"><strong>named</strong></span>. This means
|
||||||
|
that if either of the keys in
|
||||||
|
<code class="filename">/etc/bind.keys</code> is revoked
|
||||||
and rolled over, it will be necessary to update
|
and rolled over, it will be necessary to update
|
||||||
<code class="filename">/etc/bind.keys</code> to use DNSSEC
|
<code class="filename">/etc/bind.keys</code> to use DNSSEC
|
||||||
validation in <span class="command"><strong>delv</strong></span>.
|
validation in <span class="command"><strong>delv</strong></span>.
|
||||||
@@ -517,14 +517,13 @@
|
|||||||
request DNSSEC records or whether to validate them.
|
request DNSSEC records or whether to validate them.
|
||||||
DNSSEC records are always requested, and validation
|
DNSSEC records are always requested, and validation
|
||||||
will always occur unless suppressed by the use of
|
will always occur unless suppressed by the use of
|
||||||
<code class="option">-i</code> or <code class="option">+noroot</code> and
|
<code class="option">-i</code> or <code class="option">+noroot</code>.
|
||||||
<code class="option">+nodlv</code>.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]root[=ROOT]</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]root[=ROOT]</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Indicates whether to perform conventional (non-lookaside)
|
Indicates whether to perform conventional
|
||||||
DNSSEC validation, and if so, specifies the
|
DNSSEC validation, and if so, specifies the
|
||||||
name of a trust anchor. The default is to validate using
|
name of a trust anchor. The default is to validate using
|
||||||
a trust anchor of "." (the root zone), for which there is
|
a trust anchor of "." (the root zone), for which there is
|
||||||
@@ -533,15 +532,6 @@
|
|||||||
containing the key.
|
containing the key.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]dlv[=DLV]</code></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Indicates whether to perform DNSSEC lookaside validation,
|
|
||||||
and if so, specifies the name of the DLV trust anchor.
|
|
||||||
The <code class="option">-a</code> option must also be used to specify
|
|
||||||
a file containing the DLV key.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]tcp</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -60,7 +60,8 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
<AdditionalIncludeDirectories>..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@GEOIP_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\win32\include;..\..\..\lib\dns\include;..\..\..\lib\irs\win32\include;..\..\..\lib\irs\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@GEOIP_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\win32\include;..\..\..\lib\dns\include;..\..\..\lib\irs\win32\include;..\..\..\lib\irs\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<Link>
|
<Link>
|
||||||
@@ -87,7 +88,8 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<AdditionalIncludeDirectories>..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@GEOIP_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\win32\include;..\..\..\lib\dns\include;..\..\..\lib\irs\win32\include;..\..\..\lib\irs\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@GEOIP_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\win32\include;..\..\..\lib\dns\include;..\..\..\lib\irs\win32\include;..\..\..\lib\irs\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<Link>
|
<Link>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
+5
-4
@@ -19,16 +19,17 @@ READLINE_LIB = @READLINE_LIB@
|
|||||||
|
|
||||||
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} \
|
CINCLUDES = -I${srcdir}/include ${DNS_INCLUDES} \
|
||||||
${BIND9_INCLUDES} ${ISC_INCLUDES} \
|
${BIND9_INCLUDES} ${ISC_INCLUDES} \
|
||||||
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @LIBIDN2_CFLAGS@ @OPENSSL_INCLUDES@
|
${IRS_INCLUDES} ${ISCCFG_INCLUDES} @LIBIDN2_CFLAGS@ \
|
||||||
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\"
|
CDEFINES = -DVERSION=\"${VERSION}\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @OPENSSL_LIBS@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
IRSLIBS = ../../lib/irs/libirs.@A@
|
IRSLIBS = ../../lib/irs/libirs.@A@
|
||||||
|
|
||||||
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
|||||||
+21
-10
@@ -361,14 +361,20 @@ Display [do not display] the CLASS when printing the record\&.
|
|||||||
.PP
|
.PP
|
||||||
\fB+[no]cmd\fR
|
\fB+[no]cmd\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Toggles the printing of the initial comment in the output identifying the version of
|
Toggles the printing of the initial comment in the output, identifying the version of
|
||||||
\fBdig\fR
|
\fBdig\fR
|
||||||
and the query options that have been applied\&. This comment is printed by default\&.
|
and the query options that have been applied\&. This option always has global effect; it cannot be set globally and then overridden on a per\-lookup basis\&. The default is to print this comment\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]comments\fR
|
\fB+[no]comments\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Toggle the display of comment lines in the output\&. The default is to print comments\&.
|
Toggles the display of some comment lines in the output, containing information about the packet header and OPT pseudosection, and the names of the response section\&. The default is to print these comments\&.
|
||||||
|
.sp
|
||||||
|
Other types of comments in the output are not affected by this option, but can be controlled using other command line switches\&. These include
|
||||||
|
\fB+[no]cmd\fR,
|
||||||
|
\fB+[no]question\fR,
|
||||||
|
\fB+[no]stats\fR, and
|
||||||
|
\fB+[no]rrcomments\fR\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]cookie\fR\fB[=####]\fR
|
\fB+[no]cookie\fR\fB[=####]\fR
|
||||||
@@ -450,6 +456,11 @@ clears the EDNS options to be sent\&.
|
|||||||
Send an EDNS Expire option\&.
|
Send an EDNS Expire option\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\fB+[no]expandaaaa\fR
|
||||||
|
.RS 4
|
||||||
|
When printing AAAA record print all zero nibbles rather than the default RFC 5952 preferred presentation format\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\fB+[no]fail\fR
|
\fB+[no]fail\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Do not try the next server if you receive a SERVFAIL\&. The default is to not try the next server which is the reverse of normal stub resolver behavior\&.
|
Do not try the next server if you receive a SERVFAIL\&. The default is to not try the next server which is the reverse of normal stub resolver behavior\&.
|
||||||
@@ -561,12 +572,12 @@ would cause a 48\-byte query to be padded to 64 bytes\&. The default block size
|
|||||||
.PP
|
.PP
|
||||||
\fB+[no]qr\fR
|
\fB+[no]qr\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Print [do not print] the query as it is sent\&. By default, the query is not printed\&.
|
Toggles the display of the query message as it is sent\&. By default, the query is not printed\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]question\fR
|
\fB+[no]question\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Print [do not print] the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&.
|
Toggles the display of the question section of a query when an answer is returned\&. The default is to print the question section as a comment\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]raflag\fR
|
\fB+[no]raflag\fR
|
||||||
@@ -584,11 +595,11 @@ A synonym for
|
|||||||
.RS 4
|
.RS 4
|
||||||
Toggle the setting of the RD (recursion desired) bit in the query\&. This bit is set by default, which means
|
Toggle the setting of the RD (recursion desired) bit in the query\&. This bit is set by default, which means
|
||||||
\fBdig\fR
|
\fBdig\fR
|
||||||
normally sends recursive queries\&. Recursion is automatically disabled when the
|
normally sends recursive queries\&. Recursion is automatically disabled when using the
|
||||||
\fI+nssearch\fR
|
\fI+nssearch\fR
|
||||||
or
|
option, and when using
|
||||||
\fI+trace\fR
|
\fI+trace\fR
|
||||||
query options are used\&.
|
except for an initial recursive query to get the list of root servers\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+retry=T\fR
|
\fB+retry=T\fR
|
||||||
@@ -619,7 +630,7 @@ determines if the name will be treated as relative or not and hence whether a se
|
|||||||
.PP
|
.PP
|
||||||
\fB+[no]short\fR
|
\fB+[no]short\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Provide a terse answer\&. The default is to print the answer in a verbose form\&.
|
Provide a terse answer\&. The default is to print the answer in a verbose form\&. This option always has global effect; it cannot be set globally and then overridden on a per\-lookup basis\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]showsearch\fR
|
\fB+[no]showsearch\fR
|
||||||
@@ -649,7 +660,7 @@ causes fields not to be split at all\&. The default is 56 characters, or 44 char
|
|||||||
.PP
|
.PP
|
||||||
\fB+[no]stats\fR
|
\fB+[no]stats\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
This query option toggles the printing of statistics: when the query was made, the size of the reply and so on\&. The default behavior is to print the query statistics\&.
|
Toggles the printing of statistics: when the query was made, the size of the reply and so on\&. The default behavior is to print the query statistics as a comment after each lookup\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\fB+[no]subnet=addr[/prefix\-length]\fR
|
\fB+[no]subnet=addr[/prefix\-length]\fR
|
||||||
|
|||||||
+259
-62
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -66,7 +64,8 @@ static char hexcookie[81];
|
|||||||
|
|
||||||
static bool short_form = false, printcmd = true,
|
static bool short_form = false, printcmd = true,
|
||||||
plusquest = false, pluscomm = false,
|
plusquest = false, pluscomm = false,
|
||||||
ipv4only = false, ipv6only = false, digrc = true;
|
ipv4only = false, ipv6only = false, digrc = true,
|
||||||
|
yaml = false;
|
||||||
static uint32_t splitwidth = 0xffffffff;
|
static uint32_t splitwidth = 0xffffffff;
|
||||||
|
|
||||||
/*% opcode text */
|
/*% opcode text */
|
||||||
@@ -175,11 +174,13 @@ help(void) {
|
|||||||
" +bufsize=### (Set EDNS0 Max UDP packet size)\n"
|
" +bufsize=### (Set EDNS0 Max UDP packet size)\n"
|
||||||
" +[no]cdflag (Set checking disabled flag in query)\n"
|
" +[no]cdflag (Set checking disabled flag in query)\n"
|
||||||
" +[no]class (Control display of class in records)\n"
|
" +[no]class (Control display of class in records)\n"
|
||||||
" +[no]cmd (Control display of command line)\n"
|
" +[no]cmd (Control display of command line -\n"
|
||||||
" +[no]comments (Control display of comment lines)\n"
|
" global option)\n"
|
||||||
|
" +[no]comments (Control display of packet header\n"
|
||||||
|
" and section name comments)\n"
|
||||||
" +[no]cookie (Add a COOKIE option to the request)\n"
|
" +[no]cookie (Add a COOKIE option to the request)\n"
|
||||||
" +[no]crypto (Control display of cryptographic "
|
" +[no]crypto (Control display of cryptographic\n"
|
||||||
"fields in records)\n"
|
" fields in records)\n"
|
||||||
" +[no]defname (Use search list (+[no]search))\n"
|
" +[no]defname (Use search list (+[no]search))\n"
|
||||||
" +[no]dnssec (Request DNSSEC records)\n"
|
" +[no]dnssec (Request DNSSEC records)\n"
|
||||||
" +domain=### (Set default domainname)\n"
|
" +domain=### (Set default domainname)\n"
|
||||||
@@ -189,17 +190,20 @@ help(void) {
|
|||||||
" +[no]ednsnegotiation (Set EDNS version negotiation)\n"
|
" +[no]ednsnegotiation (Set EDNS version negotiation)\n"
|
||||||
" +ednsopt=###[:value] (Send specified EDNS option)\n"
|
" +ednsopt=###[:value] (Send specified EDNS option)\n"
|
||||||
" +noednsopt (Clear list of +ednsopt options)\n"
|
" +noednsopt (Clear list of +ednsopt options)\n"
|
||||||
|
" +[no]expandaaaa (Expand AAAA records)\n"
|
||||||
" +[no]expire (Request time to expire)\n"
|
" +[no]expire (Request time to expire)\n"
|
||||||
" +[no]fail (Don't try next server on SERVFAIL)\n"
|
" +[no]fail (Don't try next server on SERVFAIL)\n"
|
||||||
" +[no]header-only (Send query without a question section)\n"
|
" +[no]header-only (Send query without a question section)\n"
|
||||||
" +[no]identify (ID responders in short answers)\n"
|
" +[no]identify (ID responders in short answers)\n"
|
||||||
#ifdef HAVE_LIBIDN2
|
#ifdef HAVE_LIBIDN2
|
||||||
" +[no]idnin (Parse IDN names [default=on on tty])\n"
|
" +[no]idnin (Parse IDN names [default=on on tty])\n"
|
||||||
" +[no]idnout (Convert IDN response [default=on on tty])\n"
|
" +[no]idnout (Convert IDN response "
|
||||||
|
"[default=on on tty])\n"
|
||||||
#endif
|
#endif
|
||||||
" +[no]ignore (Don't revert to TCP for TC responses.)\n"
|
" +[no]ignore (Don't revert to TCP for TC responses.)\n"
|
||||||
" +[no]keepalive (Request EDNS TCP keepalive)\n"
|
" +[no]keepalive (Request EDNS TCP keepalive)\n"
|
||||||
" +[no]keepopen (Keep the TCP socket open between queries)\n"
|
" +[no]keepopen (Keep the TCP socket open between "
|
||||||
|
"queries)\n"
|
||||||
" +[no]mapped (Allow mapped IPv4 over IPv6)\n"
|
" +[no]mapped (Allow mapped IPv4 over IPv6)\n"
|
||||||
" +[no]multiline (Print records in an expanded format)\n"
|
" +[no]multiline (Print records in an expanded format)\n"
|
||||||
" +ndots=### (Set search NDOTS value)\n"
|
" +ndots=### (Set search NDOTS value)\n"
|
||||||
@@ -218,7 +222,7 @@ help(void) {
|
|||||||
"comments)\n"
|
"comments)\n"
|
||||||
" +[no]search (Set whether to use searchlist)\n"
|
" +[no]search (Set whether to use searchlist)\n"
|
||||||
" +[no]short (Display nothing except short\n"
|
" +[no]short (Display nothing except short\n"
|
||||||
" form of answer)\n"
|
" form of answers - global option)\n"
|
||||||
" +[no]showsearch (Search with intermediate results)\n"
|
" +[no]showsearch (Search with intermediate results)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||||
" +[no]stats (Control display of statistics)\n"
|
" +[no]stats (Control display of statistics)\n"
|
||||||
@@ -226,11 +230,13 @@ help(void) {
|
|||||||
" +[no]tcflag (Set TC flag in query (+[no]tcflag))\n"
|
" +[no]tcflag (Set TC flag in query (+[no]tcflag))\n"
|
||||||
" +[no]tcp (TCP mode (+[no]vc))\n"
|
" +[no]tcp (TCP mode (+[no]vc))\n"
|
||||||
" +timeout=### (Set query timeout) [5]\n"
|
" +timeout=### (Set query timeout) [5]\n"
|
||||||
" +[no]trace (Trace delegation down from root [+dnssec])\n"
|
" +[no]trace (Trace delegation down from root "
|
||||||
|
"[+dnssec])\n"
|
||||||
" +tries=### (Set number of UDP attempts) [3]\n"
|
" +tries=### (Set number of UDP attempts) [3]\n"
|
||||||
" +[no]ttlid (Control display of ttls in records)\n"
|
" +[no]ttlid (Control display of ttls in records)\n"
|
||||||
" +[no]ttlunits (Display TTLs in human-readable units)\n"
|
" +[no]ttlunits (Display TTLs in human-readable units)\n"
|
||||||
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" format)\n"
|
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
||||||
|
"format)\n"
|
||||||
" +[no]vc (TCP mode (+[no]tcp))\n"
|
" +[no]vc (TCP mode (+[no]tcp))\n"
|
||||||
" +[no]zflag (Set Z flag in query)\n"
|
" +[no]zflag (Set Z flag in query)\n"
|
||||||
" global d-opts and servers (before host name) affect all queries.\n"
|
" global d-opts and servers (before host name) affect all queries.\n"
|
||||||
@@ -257,7 +263,11 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
|||||||
|
|
||||||
isc_sockaddr_format(from, fromtext, sizeof(fromtext));
|
isc_sockaddr_format(from, fromtext, sizeof(fromtext));
|
||||||
|
|
||||||
if (query->lookup->stats && !short_form) {
|
if (short_form || yaml) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (query->lookup->stats) {
|
||||||
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
||||||
if (query->lookup->use_usec)
|
if (query->lookup->use_usec)
|
||||||
printf(";; Query time: %ld usec\n", (long) diff);
|
printf(";; Query time: %ld usec\n", (long) diff);
|
||||||
@@ -278,11 +288,15 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
|||||||
*/
|
*/
|
||||||
if (wcsftime(time_str, sizeof(time_str)/sizeof(time_str[0]),
|
if (wcsftime(time_str, sizeof(time_str)/sizeof(time_str[0]),
|
||||||
L"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
L"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
||||||
|
{
|
||||||
printf(";; WHEN: %ls\n", time_str);
|
printf(";; WHEN: %ls\n", time_str);
|
||||||
|
}
|
||||||
#else
|
#else
|
||||||
if (strftime(time_str, sizeof(time_str),
|
if (strftime(time_str, sizeof(time_str),
|
||||||
"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
"%a %b %d %H:%M:%S %Z %Y", &tmnow) > 0U)
|
||||||
|
{
|
||||||
printf(";; WHEN: %s\n", time_str);
|
printf(";; WHEN: %s\n", time_str);
|
||||||
|
}
|
||||||
#endif
|
#endif
|
||||||
if (query->lookup->doing_xfr) {
|
if (query->lookup->doing_xfr) {
|
||||||
printf(";; XFR size: %u records (messages %u, "
|
printf(";; XFR size: %u records (messages %u, "
|
||||||
@@ -293,30 +307,32 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
|||||||
printf(";; MSG SIZE rcvd: %u\n", bytes);
|
printf(";; MSG SIZE rcvd: %u\n", bytes);
|
||||||
}
|
}
|
||||||
if (tsigkey != NULL) {
|
if (tsigkey != NULL) {
|
||||||
if (!validated)
|
if (!validated) {
|
||||||
puts(";; WARNING -- Some TSIG could not "
|
puts(";; WARNING -- Some TSIG could not "
|
||||||
"be validated");
|
"be validated");
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if ((tsigkey == NULL) && (keysecret[0] != 0)) {
|
if ((tsigkey == NULL) && (keysecret[0] != 0)) {
|
||||||
puts(";; WARNING -- TSIG key was not used.");
|
puts(";; WARNING -- TSIG key was not used.");
|
||||||
}
|
}
|
||||||
puts("");
|
puts("");
|
||||||
} else if (query->lookup->identify && !short_form) {
|
} else if (query->lookup->identify) {
|
||||||
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
||||||
if (query->lookup->use_usec)
|
if (query->lookup->use_usec) {
|
||||||
printf(";; Received %" PRIu64 " bytes "
|
printf(";; Received %" PRIu64 " bytes "
|
||||||
"from %s(%s) in %ld us\n\n",
|
"from %s(%s) in %ld us\n\n",
|
||||||
query->lookup->doing_xfr
|
query->lookup->doing_xfr
|
||||||
? query->byte_count
|
? query->byte_count
|
||||||
: (uint64_t)bytes,
|
: (uint64_t)bytes,
|
||||||
fromtext, query->userarg, (long) diff);
|
fromtext, query->userarg, (long) diff);
|
||||||
else
|
} else {
|
||||||
printf(";; Received %" PRIu64 " bytes "
|
printf(";; Received %" PRIu64 " bytes "
|
||||||
"from %s(%s) in %ld ms\n\n",
|
"from %s(%s) in %ld ms\n\n",
|
||||||
query->lookup->doing_xfr
|
query->lookup->doing_xfr
|
||||||
? query->byte_count
|
? query->byte_count
|
||||||
: (uint64_t)bytes,
|
: (uint64_t)bytes,
|
||||||
fromtext, query->userarg, (long) diff / 1000);
|
fromtext, query->userarg, (long) diff / 1000);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -355,20 +371,24 @@ say_message(dns_rdata_t *rdata, dig_query_t *query, isc_buffer_t *buf) {
|
|||||||
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
||||||
if (query->lookup->print_unknown_format)
|
if (query->lookup->print_unknown_format)
|
||||||
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
||||||
|
if (query->lookup->expandaaaa)
|
||||||
|
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
||||||
result = dns_rdata_tofmttext(rdata, NULL, styleflags, 0,
|
result = dns_rdata_tofmttext(rdata, NULL, styleflags, 0,
|
||||||
splitwidth, " ", buf);
|
splitwidth, " ", buf);
|
||||||
if (result == ISC_R_NOSPACE)
|
if (result == ISC_R_NOSPACE) {
|
||||||
return (result);
|
return (result);
|
||||||
|
}
|
||||||
check_result(result, "dns_rdata_totext");
|
check_result(result, "dns_rdata_totext");
|
||||||
if (query->lookup->identify) {
|
if (query->lookup->identify) {
|
||||||
|
|
||||||
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
diff = isc_time_microdiff(&query->time_recv, &query->time_sent);
|
||||||
ADD_STRING(buf, " from server ");
|
ADD_STRING(buf, " from server ");
|
||||||
ADD_STRING(buf, query->servname);
|
ADD_STRING(buf, query->servname);
|
||||||
if (query->lookup->use_usec) {
|
if (query->lookup->use_usec) {
|
||||||
snprintf(store, sizeof(store), " in %" PRIu64 " us.", diff);
|
snprintf(store, sizeof(store),
|
||||||
|
" in %" PRIu64 " us.", diff);
|
||||||
} else {
|
} else {
|
||||||
snprintf(store, sizeof(store), " in %" PRIu64 " ms.", diff / 1000);
|
snprintf(store, sizeof(store),
|
||||||
|
" in %" PRIu64 " ms.", diff / 1000);
|
||||||
}
|
}
|
||||||
ADD_STRING(buf, store);
|
ADD_STRING(buf, store);
|
||||||
}
|
}
|
||||||
@@ -408,8 +428,7 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
|
|||||||
loopresult = dns_rdataset_first(rdataset);
|
loopresult = dns_rdataset_first(rdataset);
|
||||||
while (loopresult == ISC_R_SUCCESS) {
|
while (loopresult == ISC_R_SUCCESS) {
|
||||||
dns_rdataset_current(rdataset, &rdata);
|
dns_rdataset_current(rdataset, &rdata);
|
||||||
result = say_message(&rdata, query,
|
result = say_message(&rdata, query, buf);
|
||||||
buf);
|
|
||||||
if (result == ISC_R_NOSPACE)
|
if (result == ISC_R_NOSPACE)
|
||||||
return (result);
|
return (result);
|
||||||
check_result(result, "say_message");
|
check_result(result, "say_message");
|
||||||
@@ -451,60 +470,85 @@ isdotlocal(dns_message_t *msg) {
|
|||||||
* Callback from dighost.c to print the reply from a server
|
* Callback from dighost.c to print the reply from a server
|
||||||
*/
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
printmessage(dig_query_t *query, dns_message_t *msg, bool headers) {
|
printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||||
|
dns_message_t *msg, bool headers)
|
||||||
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dns_messagetextflag_t flags;
|
dns_messagetextflag_t flags;
|
||||||
isc_buffer_t *buf = NULL;
|
isc_buffer_t *buf = NULL;
|
||||||
unsigned int len = OUTPUTBUF;
|
unsigned int len = OUTPUTBUF;
|
||||||
dns_master_style_t *style = NULL;
|
dns_master_style_t *style = NULL;
|
||||||
unsigned int styleflags = 0;
|
unsigned int styleflags = 0;
|
||||||
|
bool isquery = (msg == query->lookup->sendmsg);
|
||||||
|
|
||||||
|
UNUSED(msgbuf);
|
||||||
|
|
||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (query->lookup->comments)
|
if (yaml) {
|
||||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
dns_master_indentstr = " ";
|
||||||
if (query->lookup->print_unknown_format)
|
dns_master_indent = 3;
|
||||||
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
/* Turn on rrcomments if explicitly enabled */
|
} else {
|
||||||
if (query->lookup->rrcomments > 0)
|
if (query->lookup->comments) {
|
||||||
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||||
if (query->lookup->ttlunits)
|
}
|
||||||
styleflags |= DNS_STYLEFLAG_TTL_UNITS;
|
if (query->lookup->print_unknown_format) {
|
||||||
if (query->lookup->nottl)
|
styleflags |= DNS_STYLEFLAG_UNKNOWNFORMAT;
|
||||||
styleflags |= DNS_STYLEFLAG_NO_TTL;
|
}
|
||||||
if (query->lookup->noclass)
|
/* Turn on rrcomments if explicitly enabled */
|
||||||
styleflags |= DNS_STYLEFLAG_NO_CLASS;
|
if (query->lookup->rrcomments > 0) {
|
||||||
if (query->lookup->nocrypto)
|
|
||||||
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
|
||||||
if (query->lookup->multiline) {
|
|
||||||
styleflags |= DNS_STYLEFLAG_OMIT_OWNER;
|
|
||||||
styleflags |= DNS_STYLEFLAG_OMIT_CLASS;
|
|
||||||
styleflags |= DNS_STYLEFLAG_REL_DATA;
|
|
||||||
styleflags |= DNS_STYLEFLAG_OMIT_TTL;
|
|
||||||
styleflags |= DNS_STYLEFLAG_TTL;
|
|
||||||
styleflags |= DNS_STYLEFLAG_MULTILINE;
|
|
||||||
/* Turn on rrcomments unless explicitly disabled */
|
|
||||||
if (query->lookup->rrcomments >= 0)
|
|
||||||
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
||||||
|
}
|
||||||
|
if (query->lookup->ttlunits) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_TTL_UNITS;
|
||||||
|
}
|
||||||
|
if (query->lookup->nottl) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NO_TTL;
|
||||||
|
}
|
||||||
|
if (query->lookup->noclass) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NO_CLASS;
|
||||||
|
}
|
||||||
|
if (query->lookup->nocrypto) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_NOCRYPTO;
|
||||||
|
}
|
||||||
|
if (query->lookup->expandaaaa) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_EXPANDAAAA;
|
||||||
|
}
|
||||||
|
if (query->lookup->multiline) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_OMIT_OWNER;
|
||||||
|
styleflags |= DNS_STYLEFLAG_OMIT_CLASS;
|
||||||
|
styleflags |= DNS_STYLEFLAG_REL_DATA;
|
||||||
|
styleflags |= DNS_STYLEFLAG_OMIT_TTL;
|
||||||
|
styleflags |= DNS_STYLEFLAG_TTL;
|
||||||
|
styleflags |= DNS_STYLEFLAG_MULTILINE;
|
||||||
|
/* Turn on rrcomments unless explicitly disabled */
|
||||||
|
if (query->lookup->rrcomments >= 0) {
|
||||||
|
styleflags |= DNS_STYLEFLAG_RRCOMMENT;
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if (query->lookup->multiline ||
|
if (query->lookup->multiline ||
|
||||||
(query->lookup->nottl && query->lookup->noclass))
|
(query->lookup->nottl && query->lookup->noclass))
|
||||||
|
{
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 24, 24, 32, 80, 8,
|
24, 24, 24, 32, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else if (query->lookup->nottl || query->lookup->noclass)
|
} else if (query->lookup->nottl || query->lookup->noclass) {
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 24, 32, 40, 80, 8,
|
24, 24, 32, 40, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
else
|
} else {
|
||||||
result = dns_master_stylecreate(&style, styleflags,
|
result = dns_master_stylecreate(&style, styleflags,
|
||||||
24, 32, 40, 48, 80, 8,
|
24, 32, 40, 48, 80, 8,
|
||||||
splitwidth, mctx);
|
splitwidth, mctx);
|
||||||
|
}
|
||||||
check_result(result, "dns_master_stylecreate");
|
check_result(result, "dns_master_stylecreate");
|
||||||
|
|
||||||
if (query->lookup->cmdline[0] != 0) {
|
if (query->lookup->cmdline[0] != 0) {
|
||||||
if (!short_form)
|
if (!short_form && printcmd) {
|
||||||
fputs(query->lookup->cmdline, stdout);
|
fputs(query->lookup->cmdline, stdout);
|
||||||
query->lookup->cmdline[0]=0;
|
}
|
||||||
|
query->lookup->cmdline[0] = '\0';
|
||||||
}
|
}
|
||||||
debug("printmessage(%s %s %s)", headers ? "headers" : "noheaders",
|
debug("printmessage(%s %s %s)", headers ? "headers" : "noheaders",
|
||||||
query->lookup->comments ? "comments" : "nocomments",
|
query->lookup->comments ? "comments" : "nocomments",
|
||||||
@@ -525,13 +569,110 @@ printmessage(dig_query_t *query, dns_message_t *msg, bool headers) {
|
|||||||
result = isc_buffer_allocate(mctx, &buf, len);
|
result = isc_buffer_allocate(mctx, &buf, len);
|
||||||
check_result(result, "isc_buffer_allocate");
|
check_result(result, "isc_buffer_allocate");
|
||||||
|
|
||||||
if (query->lookup->comments && !short_form) {
|
if (yaml) {
|
||||||
if (query->lookup->cmdline[0] != 0)
|
enum { Q = 0x1, R = 0x2 }; /* Q:query; R:ecursive */
|
||||||
|
unsigned int tflag = 0;
|
||||||
|
isc_sockaddr_t saddr;
|
||||||
|
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||||
|
uint16_t sport;
|
||||||
|
char *hash;
|
||||||
|
int pf;
|
||||||
|
|
||||||
|
printf("-\n");
|
||||||
|
printf(" type: MESSAGE\n");
|
||||||
|
printf(" message:\n");
|
||||||
|
|
||||||
|
if (isquery) {
|
||||||
|
tflag |= Q;
|
||||||
|
if ((msg->flags & DNS_MESSAGEFLAG_RD) != 0) {
|
||||||
|
tflag |= R;
|
||||||
|
}
|
||||||
|
} else if (((msg->flags & DNS_MESSAGEFLAG_RD) != 0) &&
|
||||||
|
((msg->flags & DNS_MESSAGEFLAG_RA) != 0))
|
||||||
|
{
|
||||||
|
tflag |= R;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (tflag == (Q|R)) {
|
||||||
|
printf(" type: RECURSIVE_QUERY\n");
|
||||||
|
} else if (tflag == Q) {
|
||||||
|
printf(" type: AUTH_QUERY\n");
|
||||||
|
} else if (tflag == R) {
|
||||||
|
printf(" type: RECURSIVE_RESPONSE\n");
|
||||||
|
} else {
|
||||||
|
printf(" type: AUTH_RESPONSE\n");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!isc_time_isepoch(&query->time_sent)) {
|
||||||
|
char tbuf[100];
|
||||||
|
isc_time_formatISO8601ms(&query->time_sent,
|
||||||
|
tbuf, sizeof(tbuf));
|
||||||
|
printf(" query_time: !!timestamp %s\n", tbuf);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!isquery && !isc_time_isepoch(&query->time_recv)) {
|
||||||
|
char tbuf[100];
|
||||||
|
isc_time_formatISO8601ms(&query->time_recv,
|
||||||
|
tbuf, sizeof(tbuf));
|
||||||
|
printf(" response_time: !!timestamp %s\n", tbuf);
|
||||||
|
}
|
||||||
|
|
||||||
|
printf(" message_size: %ub\n",
|
||||||
|
isc_buffer_usedlength(msgbuf));
|
||||||
|
|
||||||
|
pf = isc_sockaddr_pf(&query->sockaddr);
|
||||||
|
if (pf == PF_INET || pf == PF_INET6) {
|
||||||
|
printf(" socket_family: %s\n",
|
||||||
|
pf == PF_INET ? "INET" : "INET6");
|
||||||
|
|
||||||
|
printf(" socket_protocol: %s\n",
|
||||||
|
query->lookup->tcp_mode ? "TCP" : "UDP");
|
||||||
|
|
||||||
|
sport = isc_sockaddr_getport(&query->sockaddr);
|
||||||
|
isc_sockaddr_format(&query->sockaddr,
|
||||||
|
sockstr, sizeof(sockstr));
|
||||||
|
hash = strchr(sockstr, '#');
|
||||||
|
if (hash != NULL) {
|
||||||
|
*hash = '\0';
|
||||||
|
}
|
||||||
|
if (strcmp(sockstr, "::") == 0) {
|
||||||
|
strlcat(sockstr, "0", sizeof(sockstr));
|
||||||
|
}
|
||||||
|
|
||||||
|
printf(" response_address: %s\n", sockstr);
|
||||||
|
printf(" response_port: %u\n", sport);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (query->sock != NULL &&
|
||||||
|
isc_socket_getsockname(query->sock, &saddr)
|
||||||
|
== ISC_R_SUCCESS)
|
||||||
|
{
|
||||||
|
sport = isc_sockaddr_getport(&saddr);
|
||||||
|
isc_sockaddr_format(&saddr, sockstr, sizeof(sockstr));
|
||||||
|
hash = strchr(sockstr, '#');
|
||||||
|
if (hash != NULL) {
|
||||||
|
*hash = '\0';
|
||||||
|
}
|
||||||
|
if (strcmp(sockstr, "::") == 0) {
|
||||||
|
strlcat(sockstr, "0", sizeof(sockstr));
|
||||||
|
}
|
||||||
|
|
||||||
|
printf(" query_address: %s\n", sockstr);
|
||||||
|
printf(" query_port: %u\n", sport);
|
||||||
|
}
|
||||||
|
|
||||||
|
printf(" %s:\n", isquery ? "query_message_data"
|
||||||
|
: "response_message_data");
|
||||||
|
result = dns_message_headertotext(msg, style, flags, buf);
|
||||||
|
} else if (query->lookup->comments && !short_form) {
|
||||||
|
if (query->lookup->cmdline[0] != '\0' && printcmd) {
|
||||||
printf("; %s\n", query->lookup->cmdline);
|
printf("; %s\n", query->lookup->cmdline);
|
||||||
if (msg == query->lookup->sendmsg)
|
}
|
||||||
|
if (msg == query->lookup->sendmsg) {
|
||||||
printf(";; Sending:\n");
|
printf(";; Sending:\n");
|
||||||
else
|
} else {
|
||||||
printf(";; Got answer:\n");
|
printf(";; Got answer:\n");
|
||||||
|
}
|
||||||
|
|
||||||
if (headers) {
|
if (headers) {
|
||||||
if (isdotlocal(msg)) {
|
if (isdotlocal(msg)) {
|
||||||
@@ -676,8 +817,9 @@ buftoosmall:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (headers && query->lookup->comments && !short_form)
|
if (headers && query->lookup->comments && !short_form && !yaml) {
|
||||||
printf("\n");
|
printf("\n");
|
||||||
|
}
|
||||||
|
|
||||||
printf("%.*s", (int)isc_buffer_usedlength(buf),
|
printf("%.*s", (int)isc_buffer_usedlength(buf),
|
||||||
(char *)isc_buffer_base(buf));
|
(char *)isc_buffer_base(buf));
|
||||||
@@ -1036,8 +1178,24 @@ plus_option(char *option, bool is_batchfile,
|
|||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
case 'x':
|
case 'x':
|
||||||
FULLCHECK("expire");
|
switch (cmd[2]) {
|
||||||
lookup->expire = state;
|
case 'p':
|
||||||
|
switch(cmd[3]) {
|
||||||
|
case 'a':
|
||||||
|
FULLCHECK("expandaaaa");
|
||||||
|
lookup->expandaaaa = state;
|
||||||
|
break;
|
||||||
|
case 'i':
|
||||||
|
FULLCHECK("expire");
|
||||||
|
lookup->expire = state;
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
goto invalid_option;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
goto invalid_option;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
goto invalid_option;
|
goto invalid_option;
|
||||||
@@ -1445,7 +1603,7 @@ plus_option(char *option, bool is_batchfile,
|
|||||||
lookup->trace = state;
|
lookup->trace = state;
|
||||||
lookup->trace_root = state;
|
lookup->trace_root = state;
|
||||||
if (state) {
|
if (state) {
|
||||||
lookup->recurse = false;
|
lookup->recurse = true;
|
||||||
lookup->identify = true;
|
lookup->identify = true;
|
||||||
lookup->comments = false;
|
lookup->comments = false;
|
||||||
lookup->rrcomments = 0;
|
lookup->rrcomments = 0;
|
||||||
@@ -1519,6 +1677,15 @@ plus_option(char *option, bool is_batchfile,
|
|||||||
lookup->tcp_mode_set = true;
|
lookup->tcp_mode_set = true;
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
case 'y': /* yaml */
|
||||||
|
FULLCHECK("yaml");
|
||||||
|
yaml = state;
|
||||||
|
if (state) {
|
||||||
|
printcmd = false;
|
||||||
|
lookup->stats = false;
|
||||||
|
lookup->rrcomments = -1;
|
||||||
|
}
|
||||||
|
break;
|
||||||
case 'z': /* zflag */
|
case 'z': /* zflag */
|
||||||
FULLCHECK("zflag");
|
FULLCHECK("zflag");
|
||||||
lookup->zflag = state;
|
lookup->zflag = state;
|
||||||
@@ -2231,8 +2398,37 @@ query_finished(void) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
void dig_setup(int argc, char **argv)
|
static void
|
||||||
{
|
dig_error(const char *format, ...) {
|
||||||
|
va_list args;
|
||||||
|
|
||||||
|
if (yaml) {
|
||||||
|
printf("-\n");
|
||||||
|
printf(" type: DIG_ERROR\n");
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Print an indent before a literal block quote.
|
||||||
|
* Note: this will break if used to print more than
|
||||||
|
* one line of text as only the first line would be
|
||||||
|
* indented.
|
||||||
|
*/
|
||||||
|
printf(" message: |\n");
|
||||||
|
printf(" ");
|
||||||
|
} else {
|
||||||
|
printf(";; ");
|
||||||
|
}
|
||||||
|
|
||||||
|
va_start(args, format);
|
||||||
|
vprintf(format, args);
|
||||||
|
va_end(args);
|
||||||
|
|
||||||
|
if (!yaml) {
|
||||||
|
printf("\n");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
dig_setup(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|
||||||
ISC_LIST_INIT(lookup_list);
|
ISC_LIST_INIT(lookup_list);
|
||||||
@@ -2246,6 +2442,7 @@ void dig_setup(int argc, char **argv)
|
|||||||
dighost_received = received;
|
dighost_received = received;
|
||||||
dighost_trying = trying;
|
dighost_trying = trying;
|
||||||
dighost_shutdown = query_finished;
|
dighost_shutdown = query_finished;
|
||||||
|
dighost_error = dig_error;
|
||||||
|
|
||||||
progname = argv[0];
|
progname = argv[0];
|
||||||
preparse_args(argc, argv);
|
preparse_args(argc, argv);
|
||||||
|
|||||||
+50
-15
@@ -593,9 +593,11 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Toggles the printing of the initial comment in the
|
Toggles the printing of the initial comment in the
|
||||||
output identifying the version of <command>dig</command>
|
output, identifying the version of <command>dig</command>
|
||||||
and the query options that have been applied. This
|
and the query options that have been applied. This option
|
||||||
comment is printed by default.
|
always has global effect; it cannot be set globally
|
||||||
|
and then overridden on a per-lookup basis. The default
|
||||||
|
is to print this comment.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -604,8 +606,18 @@
|
|||||||
<term><option>+[no]comments</option></term>
|
<term><option>+[no]comments</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Toggle the display of comment lines in the output.
|
Toggles the display of some comment lines in the output,
|
||||||
The default is to print comments.
|
containing information about the packet header and
|
||||||
|
OPT pseudosection, and the names of the response
|
||||||
|
section. The default is to print these comments.
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
Other types of comments in the output are not affected by
|
||||||
|
this option, but can be controlled using other command
|
||||||
|
line switches. These include <command>+[no]cmd</command>,
|
||||||
|
<command>+[no]question</command>,
|
||||||
|
<command>+[no]stats</command>, and
|
||||||
|
<command>+[no]rrcomments</command>.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -747,6 +759,16 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term><option>+[no]expandaaaa</option></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
When printing AAAA record print all zero nibbles rather
|
||||||
|
than the default RFC 5952 preferred presentation format.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]fail</option></term>
|
<term><option>+[no]fail</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -955,8 +977,8 @@
|
|||||||
<term><option>+[no]qr</option></term>
|
<term><option>+[no]qr</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Print [do not print] the query as it is sent. By
|
Toggles the display of the query message as it is sent.
|
||||||
default, the query is not printed.
|
By default, the query is not printed.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -965,7 +987,7 @@
|
|||||||
<term><option>+[no]question</option></term>
|
<term><option>+[no]question</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Print [do not print] the question section of a query
|
Toggles the display of the question section of a query
|
||||||
when an answer is returned. The default is to print
|
when an answer is returned. The default is to print
|
||||||
the question section as a comment.
|
the question section as a comment.
|
||||||
</para>
|
</para>
|
||||||
@@ -1000,8 +1022,10 @@
|
|||||||
in the query. This bit is set by default, which means
|
in the query. This bit is set by default, which means
|
||||||
<command>dig</command> normally sends recursive
|
<command>dig</command> normally sends recursive
|
||||||
queries. Recursion is automatically disabled when
|
queries. Recursion is automatically disabled when
|
||||||
the <parameter>+nssearch</parameter> or
|
using the <parameter>+nssearch</parameter> option, and
|
||||||
<parameter>+trace</parameter> query options are used.
|
when using <parameter>+trace</parameter> except for
|
||||||
|
an initial recursive query to get the list of root
|
||||||
|
servers.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1054,7 +1078,9 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Provide a terse answer. The default is to print the
|
Provide a terse answer. The default is to print the
|
||||||
answer in a verbose form.
|
answer in a verbose form. This option always has global
|
||||||
|
effect; it cannot be set globally and then overridden on
|
||||||
|
a per-lookup basis.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1099,10 +1125,9 @@
|
|||||||
<term><option>+[no]stats</option></term>
|
<term><option>+[no]stats</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
This query option toggles the printing of statistics:
|
Toggles the printing of statistics: when the query was made,
|
||||||
when the query was made, the size of the reply and
|
the size of the reply and so on. The default behavior is to
|
||||||
so on. The default behavior is to print the query
|
print the query statistics as a comment after each lookup.
|
||||||
statistics.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -1267,6 +1292,16 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term><option>+[no]yaml</option></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Print the responses (and, if <option>+qr</option> is in use,
|
||||||
|
also the outgoing queries) in a detailed YAML format.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><option>+[no]zflag</option></term>
|
<term><option>+[no]zflag</option></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
+37
-15
@@ -481,16 +481,28 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Toggles the printing of the initial comment in the
|
Toggles the printing of the initial comment in the
|
||||||
output identifying the version of <span class="command"><strong>dig</strong></span>
|
output, identifying the version of <span class="command"><strong>dig</strong></span>
|
||||||
and the query options that have been applied. This
|
and the query options that have been applied. This option
|
||||||
comment is printed by default.
|
always has global effect; it cannot be set globally
|
||||||
|
and then overridden on a per-lookup basis. The default
|
||||||
|
is to print this comment.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]comments</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]comments</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Toggle the display of comment lines in the output.
|
Toggles the display of some comment lines in the output,
|
||||||
The default is to print comments.
|
containing information about the packet header and
|
||||||
|
OPT pseudosection, and the names of the response
|
||||||
|
section. The default is to print these comments.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
Other types of comments in the output are not affected by
|
||||||
|
this option, but can be controlled using other command
|
||||||
|
line switches. These include <span class="command"><strong>+[no]cmd</strong></span>,
|
||||||
|
<span class="command"><strong>+[no]question</strong></span>,
|
||||||
|
<span class="command"><strong>+[no]stats</strong></span>, and
|
||||||
|
<span class="command"><strong>+[no]rrcomments</strong></span>.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]cookie[<span class="optional">=####</span>]</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]cookie[<span class="optional">=####</span>]</code></span></dt>
|
||||||
@@ -598,6 +610,13 @@
|
|||||||
Send an EDNS Expire option.
|
Send an EDNS Expire option.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term"><code class="option">+[no]expandaaaa</code></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
When printing AAAA record print all zero nibbles rather
|
||||||
|
than the default RFC 5952 preferred presentation format.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]fail</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]fail</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -757,14 +776,14 @@
|
|||||||
<dt><span class="term"><code class="option">+[no]qr</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]qr</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Print [do not print] the query as it is sent. By
|
Toggles the display of the query message as it is sent.
|
||||||
default, the query is not printed.
|
By default, the query is not printed.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]question</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]question</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Print [do not print] the question section of a query
|
Toggles the display of the question section of a query
|
||||||
when an answer is returned. The default is to print
|
when an answer is returned. The default is to print
|
||||||
the question section as a comment.
|
the question section as a comment.
|
||||||
</p>
|
</p>
|
||||||
@@ -790,8 +809,10 @@
|
|||||||
in the query. This bit is set by default, which means
|
in the query. This bit is set by default, which means
|
||||||
<span class="command"><strong>dig</strong></span> normally sends recursive
|
<span class="command"><strong>dig</strong></span> normally sends recursive
|
||||||
queries. Recursion is automatically disabled when
|
queries. Recursion is automatically disabled when
|
||||||
the <em class="parameter"><code>+nssearch</code></em> or
|
using the <em class="parameter"><code>+nssearch</code></em> option, and
|
||||||
<em class="parameter"><code>+trace</code></em> query options are used.
|
when using <em class="parameter"><code>+trace</code></em> except for
|
||||||
|
an initial recursive query to get the list of root
|
||||||
|
servers.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+retry=T</code></span></dt>
|
<dt><span class="term"><code class="option">+retry=T</code></span></dt>
|
||||||
@@ -832,7 +853,9 @@
|
|||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Provide a terse answer. The default is to print the
|
Provide a terse answer. The default is to print the
|
||||||
answer in a verbose form.
|
answer in a verbose form. This option always has global
|
||||||
|
effect; it cannot be set globally and then overridden on
|
||||||
|
a per-lookup basis.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]showsearch</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]showsearch</code></span></dt>
|
||||||
@@ -865,10 +888,9 @@
|
|||||||
<dt><span class="term"><code class="option">+[no]stats</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]stats</code></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
This query option toggles the printing of statistics:
|
Toggles the printing of statistics: when the query was made,
|
||||||
when the query was made, the size of the reply and
|
the size of the reply and so on. The default behavior is to
|
||||||
so on. The default behavior is to print the query
|
print the query statistics as a comment after each lookup.
|
||||||
statistics.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term"><code class="option">+[no]subnet=addr[/prefix-length]</code></span></dt>
|
<dt><span class="term"><code class="option">+[no]subnet=addr[/prefix-length]</code></span></dt>
|
||||||
|
|||||||
+59
-59
@@ -19,8 +19,6 @@
|
|||||||
* functions in most applications.
|
* functions in most applications.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -195,11 +193,15 @@ dig_lookup_t *current_lookup = NULL;
|
|||||||
/* dynamic callbacks */
|
/* dynamic callbacks */
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
(*dighost_printmessage)(dig_query_t *query, dns_message_t *msg,
|
(*dighost_printmessage)(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||||
bool headers);
|
dns_message_t *msg, bool headers);
|
||||||
|
|
||||||
void
|
void
|
||||||
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
(*dighost_error)(const char *format, ...);
|
||||||
|
|
||||||
|
void
|
||||||
|
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from,
|
||||||
|
dig_query_t *query);
|
||||||
|
|
||||||
void
|
void
|
||||||
(*dighost_trying)(char *frm, dig_lookup_t *lookup);
|
(*dighost_trying)(char *frm, dig_lookup_t *lookup);
|
||||||
@@ -448,9 +450,6 @@ make_server(const char *servname, const char *userarg) {
|
|||||||
|
|
||||||
debug("make_server(%s)", servname);
|
debug("make_server(%s)", servname);
|
||||||
srv = isc_mem_allocate(mctx, sizeof(struct dig_server));
|
srv = isc_mem_allocate(mctx, sizeof(struct dig_server));
|
||||||
if (srv == NULL)
|
|
||||||
fatal("memory allocation failure in %s:%d",
|
|
||||||
__FILE__, __LINE__);
|
|
||||||
strlcpy(srv->servername, servname, MXNAME);
|
strlcpy(srv->servername, servname, MXNAME);
|
||||||
strlcpy(srv->userarg, userarg, MXNAME);
|
strlcpy(srv->userarg, userarg, MXNAME);
|
||||||
ISC_LINK_INIT(srv, link);
|
ISC_LINK_INIT(srv, link);
|
||||||
@@ -578,9 +577,6 @@ make_empty_lookup(void) {
|
|||||||
INSIST(!free_now);
|
INSIST(!free_now);
|
||||||
|
|
||||||
looknew = isc_mem_allocate(mctx, sizeof(struct dig_lookup));
|
looknew = isc_mem_allocate(mctx, sizeof(struct dig_lookup));
|
||||||
if (looknew == NULL)
|
|
||||||
fatal("memory allocation failure in %s:%d",
|
|
||||||
__FILE__, __LINE__);
|
|
||||||
looknew->pending = true;
|
looknew->pending = true;
|
||||||
looknew->textname[0] = 0;
|
looknew->textname[0] = 0;
|
||||||
looknew->cmdline[0] = 0;
|
looknew->cmdline[0] = 0;
|
||||||
@@ -623,6 +619,7 @@ make_empty_lookup(void) {
|
|||||||
looknew->nocrypto = false;
|
looknew->nocrypto = false;
|
||||||
looknew->ttlunits = false;
|
looknew->ttlunits = false;
|
||||||
looknew->ttlunits = false;
|
looknew->ttlunits = false;
|
||||||
|
looknew->expandaaaa = false;
|
||||||
looknew->qr = false;
|
looknew->qr = false;
|
||||||
#ifdef HAVE_LIBIDN2
|
#ifdef HAVE_LIBIDN2
|
||||||
looknew->idnin = isatty(1)?(getenv("IDN_DISABLE") == NULL):false;
|
looknew->idnin = isatty(1)?(getenv("IDN_DISABLE") == NULL):false;
|
||||||
@@ -682,8 +679,6 @@ cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
|||||||
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
size_t len = sizeof(looknew->ednsopts[0]) * EDNSOPT_OPTIONS;
|
||||||
size_t i;
|
size_t i;
|
||||||
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
looknew->ednsopts = isc_mem_allocate(mctx, len);
|
||||||
if (looknew->ednsopts == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
for (i = 0; i < EDNSOPT_OPTIONS; i++) {
|
||||||
looknew->ednsopts[i].code = 0;
|
looknew->ednsopts[i].code = 0;
|
||||||
looknew->ednsopts[i].length = 0;
|
looknew->ednsopts[i].length = 0;
|
||||||
@@ -697,10 +692,8 @@ cloneopts(dig_lookup_t *looknew, dig_lookup_t *lookold) {
|
|||||||
len = lookold->ednsopts[i].length;
|
len = lookold->ednsopts[i].length;
|
||||||
if (len != 0) {
|
if (len != 0) {
|
||||||
INSIST(lookold->ednsopts[i].value != NULL);
|
INSIST(lookold->ednsopts[i].value != NULL);
|
||||||
looknew->ednsopts[i].value =
|
looknew->ednsopts[i].value = isc_mem_allocate(mctx,
|
||||||
isc_mem_allocate(mctx, len);
|
len);
|
||||||
if (looknew->ednsopts[i].value == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
memmove(looknew->ednsopts[i].value,
|
memmove(looknew->ednsopts[i].value,
|
||||||
lookold->ednsopts[i].value, len);
|
lookold->ednsopts[i].value, len);
|
||||||
}
|
}
|
||||||
@@ -771,6 +764,7 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
looknew->use_usec = lookold->use_usec;
|
looknew->use_usec = lookold->use_usec;
|
||||||
looknew->nocrypto = lookold->nocrypto;
|
looknew->nocrypto = lookold->nocrypto;
|
||||||
looknew->ttlunits = lookold->ttlunits;
|
looknew->ttlunits = lookold->ttlunits;
|
||||||
|
looknew->expandaaaa = lookold->expandaaaa;
|
||||||
looknew->qr = lookold->qr;
|
looknew->qr = lookold->qr;
|
||||||
looknew->idnin = lookold->idnin;
|
looknew->idnin = lookold->idnin;
|
||||||
looknew->idnout = lookold->idnout;
|
looknew->idnout = lookold->idnout;
|
||||||
@@ -805,8 +799,6 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
|||||||
if (lookold->ecs_addr != NULL) {
|
if (lookold->ecs_addr != NULL) {
|
||||||
size_t len = sizeof(isc_sockaddr_t);
|
size_t len = sizeof(isc_sockaddr_t);
|
||||||
looknew->ecs_addr = isc_mem_allocate(mctx, len);
|
looknew->ecs_addr = isc_mem_allocate(mctx, len);
|
||||||
if (looknew->ecs_addr == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
memmove(looknew->ecs_addr, lookold->ecs_addr, len);
|
memmove(looknew->ecs_addr, lookold->ecs_addr, len);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -865,9 +857,6 @@ setup_text_key(void) {
|
|||||||
isc_buffer_putstr(namebuf, keynametext);
|
isc_buffer_putstr(namebuf, keynametext);
|
||||||
secretsize = (unsigned int) strlen(keysecret) * 3 / 4;
|
secretsize = (unsigned int) strlen(keysecret) * 3 / 4;
|
||||||
secretstore = isc_mem_allocate(mctx, secretsize);
|
secretstore = isc_mem_allocate(mctx, secretsize);
|
||||||
if (secretstore == NULL)
|
|
||||||
fatal("memory allocation failure in %s:%d",
|
|
||||||
__FILE__, __LINE__);
|
|
||||||
isc_buffer_init(&secretbuf, secretstore, secretsize);
|
isc_buffer_init(&secretbuf, secretstore, secretsize);
|
||||||
result = isc_base64_decodestring(keysecret, &secretbuf);
|
result = isc_base64_decodestring(keysecret, &secretbuf);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
@@ -957,8 +946,6 @@ parse_netprefix(isc_sockaddr_t **sap, const char *value) {
|
|||||||
fatal("invalid prefix '%s'\n", value);
|
fatal("invalid prefix '%s'\n", value);
|
||||||
|
|
||||||
sa = isc_mem_allocate(mctx, sizeof(*sa));
|
sa = isc_mem_allocate(mctx, sizeof(*sa));
|
||||||
if (sa == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
memset(sa, 0, sizeof(*sa));
|
memset(sa, 0, sizeof(*sa));
|
||||||
|
|
||||||
if (strcmp(buf, "0") == 0) {
|
if (strcmp(buf, "0") == 0) {
|
||||||
@@ -1190,9 +1177,6 @@ static dig_searchlist_t *
|
|||||||
make_searchlist_entry(char *domain) {
|
make_searchlist_entry(char *domain) {
|
||||||
dig_searchlist_t *search;
|
dig_searchlist_t *search;
|
||||||
search = isc_mem_allocate(mctx, sizeof(*search));
|
search = isc_mem_allocate(mctx, sizeof(*search));
|
||||||
if (search == NULL)
|
|
||||||
fatal("memory allocation failure in %s:%d",
|
|
||||||
__FILE__, __LINE__);
|
|
||||||
strlcpy(search->origin, domain, MXNAME);
|
strlcpy(search->origin, domain, MXNAME);
|
||||||
search->origin[MXNAME-1] = 0;
|
search->origin[MXNAME-1] = 0;
|
||||||
ISC_LINK_INIT(search, link);
|
ISC_LINK_INIT(search, link);
|
||||||
@@ -1399,6 +1383,7 @@ typedef struct dig_ednsoptname {
|
|||||||
} dig_ednsoptname_t;
|
} dig_ednsoptname_t;
|
||||||
|
|
||||||
dig_ednsoptname_t optnames[] = {
|
dig_ednsoptname_t optnames[] = {
|
||||||
|
{ 1, "LLQ" }, /* draft-sekar-dns-llq */
|
||||||
{ 3, "NSID" }, /* RFC 5001 */
|
{ 3, "NSID" }, /* RFC 5001 */
|
||||||
{ 5, "DAU" }, /* RFC 6975 */
|
{ 5, "DAU" }, /* RFC 6975 */
|
||||||
{ 6, "DHU" }, /* RFC 6975 */
|
{ 6, "DHU" }, /* RFC 6975 */
|
||||||
@@ -1411,6 +1396,8 @@ dig_ednsoptname_t optnames[] = {
|
|||||||
{ 12, "PAD" }, /* shorthand */
|
{ 12, "PAD" }, /* shorthand */
|
||||||
{ 13, "CHAIN" }, /* RFC 7901 */
|
{ 13, "CHAIN" }, /* RFC 7901 */
|
||||||
{ 14, "KEY-TAG" }, /* RFC 8145 */
|
{ 14, "KEY-TAG" }, /* RFC 8145 */
|
||||||
|
{ 16, "CLIENT-TAG" }, /* draft-bellis-dnsop-edns-tags */
|
||||||
|
{ 17, "SERVER-TAG" }, /* draft-bellis-dnsop-edns-tags */
|
||||||
{ 26946, "DEVICEID" }, /* Brian Hartvigsen */
|
{ 26946, "DEVICEID" }, /* Brian Hartvigsen */
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -1454,9 +1441,7 @@ save_opt(dig_lookup_t *lookup, char *code, char *value) {
|
|||||||
|
|
||||||
if (value != NULL) {
|
if (value != NULL) {
|
||||||
char *buf;
|
char *buf;
|
||||||
buf = isc_mem_allocate(mctx, strlen(value)/2 + 1);
|
buf = isc_mem_allocate(mctx, strlen(value) / 2 + 1);
|
||||||
if (buf == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
isc_buffer_init(&b, buf, (unsigned int) strlen(value)/2 + 1);
|
||||||
result = isc_hex_decodestring(value, &b);
|
result = isc_hex_decodestring(value, &b);
|
||||||
check_result(result, "isc_hex_decodestring");
|
check_result(result, "isc_hex_decodestring");
|
||||||
@@ -2189,12 +2174,14 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
lookup->sendmsg->id = (dns_messageid_t)isc_random16();
|
lookup->sendmsg->id = (dns_messageid_t)isc_random16();
|
||||||
lookup->sendmsg->opcode = lookup->opcode;
|
lookup->sendmsg->opcode = lookup->opcode;
|
||||||
lookup->msgcounter = 0;
|
lookup->msgcounter = 0;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* If this is a trace request, completely disallow recursion, since
|
* If this is a trace request, completely disallow recursion after
|
||||||
* it's meaningless for traces.
|
* looking up the root name servers, since it's meaningless for traces.
|
||||||
*/
|
*/
|
||||||
if (lookup->trace || (lookup->ns_search_only && !lookup->trace_root))
|
if ((lookup->trace || lookup->ns_search_only) && !lookup->trace_root) {
|
||||||
lookup->recurse = false;
|
lookup->recurse = false;
|
||||||
|
}
|
||||||
|
|
||||||
if (lookup->recurse &&
|
if (lookup->recurse &&
|
||||||
lookup->rdtype != dns_rdatatype_axfr &&
|
lookup->rdtype != dns_rdatatype_axfr &&
|
||||||
@@ -2485,10 +2472,6 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
serv = ISC_LIST_NEXT(serv, link))
|
serv = ISC_LIST_NEXT(serv, link))
|
||||||
{
|
{
|
||||||
query = isc_mem_allocate(mctx, sizeof(dig_query_t));
|
query = isc_mem_allocate(mctx, sizeof(dig_query_t));
|
||||||
if (query == NULL) {
|
|
||||||
fatal("memory allocation failure in %s:%d",
|
|
||||||
__FILE__, __LINE__);
|
|
||||||
}
|
|
||||||
debug("create query %p linked to lookup %p", query, lookup);
|
debug("create query %p linked to lookup %p", query, lookup);
|
||||||
query->lookup = lookup;
|
query->lookup = lookup;
|
||||||
query->timer = NULL;
|
query->timer = NULL;
|
||||||
@@ -2523,6 +2506,9 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
COMMSIZE);
|
COMMSIZE);
|
||||||
query->sendbuf = lookup->renderbuf;
|
query->sendbuf = lookup->renderbuf;
|
||||||
|
|
||||||
|
isc_time_settoepoch(&query->time_sent);
|
||||||
|
isc_time_settoepoch(&query->time_recv);
|
||||||
|
|
||||||
ISC_LINK_INIT(query, clink);
|
ISC_LINK_INIT(query, clink);
|
||||||
ISC_LINK_INIT(query, link);
|
ISC_LINK_INIT(query, link);
|
||||||
|
|
||||||
@@ -2531,16 +2517,6 @@ setup_lookup(dig_lookup_t *lookup) {
|
|||||||
ISC_LIST_ENQUEUE(lookup->q, query, link);
|
ISC_LIST_ENQUEUE(lookup->q, query, link);
|
||||||
}
|
}
|
||||||
|
|
||||||
/* XXX qrflag, print_query, etc... */
|
|
||||||
if (!ISC_LIST_EMPTY(lookup->q) && lookup->qr) {
|
|
||||||
extrabytes = 0;
|
|
||||||
dighost_printmessage(ISC_LIST_HEAD(lookup->q),
|
|
||||||
lookup->sendmsg, true);
|
|
||||||
if (lookup->stats) {
|
|
||||||
printf(";; QUERY SIZE: %u\n\n",
|
|
||||||
isc_buffer_usedlength(&lookup->renderbuf));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return (true);
|
return (true);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2878,6 +2854,18 @@ send_udp(dig_query_t *query) {
|
|||||||
sevent, ISC_SOCKFLAG_NORETRY);
|
sevent, ISC_SOCKFLAG_NORETRY);
|
||||||
check_result(result, "isc_socket_sendto2");
|
check_result(result, "isc_socket_sendto2");
|
||||||
sendcount++;
|
sendcount++;
|
||||||
|
|
||||||
|
/* XXX qrflag, print_query, etc... */
|
||||||
|
if (!ISC_LIST_EMPTY(query->lookup->q) && query->lookup->qr) {
|
||||||
|
extrabytes = 0;
|
||||||
|
dighost_printmessage(ISC_LIST_HEAD(query->lookup->q),
|
||||||
|
&query->lookup->renderbuf,
|
||||||
|
query->lookup->sendmsg, true);
|
||||||
|
if (query->lookup->stats) {
|
||||||
|
printf(";; QUERY SIZE: %u\n\n",
|
||||||
|
isc_buffer_usedlength(&query->lookup->renderbuf));
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -2977,11 +2965,11 @@ connect_timeout(isc_task_t *task, isc_event_t *event) {
|
|||||||
isc_netaddr_fromsockaddr(&netaddr, &query->sockaddr);
|
isc_netaddr_fromsockaddr(&netaddr, &query->sockaddr);
|
||||||
isc_netaddr_format(&netaddr, buf, sizeof(buf));
|
isc_netaddr_format(&netaddr, buf, sizeof(buf));
|
||||||
|
|
||||||
printf(";; no response from %s\n", buf);
|
dighost_error("no response from %s\n", buf);
|
||||||
} else {
|
} else {
|
||||||
fputs(l->cmdline, stdout);
|
fputs(l->cmdline, stdout);
|
||||||
printf(";; connection timed out; no servers could be "
|
dighost_error("connection timed out; "
|
||||||
"reached\n");
|
"no servers could be reached\n");
|
||||||
}
|
}
|
||||||
cancel_lookup(l);
|
cancel_lookup(l);
|
||||||
check_next_lookup(l);
|
check_next_lookup(l);
|
||||||
@@ -3053,8 +3041,8 @@ tcp_length_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||||
isc_sockaddr_format(&query->sockaddr, sockstr,
|
isc_sockaddr_format(&query->sockaddr, sockstr,
|
||||||
sizeof(sockstr));
|
sizeof(sockstr));
|
||||||
printf(";; communications error to %s: %s\n",
|
dighost_error("communications error to %s: %s\n",
|
||||||
sockstr, isc_result_totext(sevent->result));
|
sockstr, isc_result_totext(sevent->result));
|
||||||
if (keep != NULL)
|
if (keep != NULL)
|
||||||
isc_socket_detach(&keep);
|
isc_socket_detach(&keep);
|
||||||
l = query->lookup;
|
l = query->lookup;
|
||||||
@@ -3153,6 +3141,19 @@ launch_next_query(dig_query_t *query, bool include_question) {
|
|||||||
check_result(result, "isc_socket_send");
|
check_result(result, "isc_socket_send");
|
||||||
sendcount++;
|
sendcount++;
|
||||||
debug("sendcount=%d", sendcount);
|
debug("sendcount=%d", sendcount);
|
||||||
|
|
||||||
|
/* XXX qrflag, print_query, etc... */
|
||||||
|
if (!ISC_LIST_EMPTY(query->lookup->q) && query->lookup->qr) {
|
||||||
|
extrabytes = 0;
|
||||||
|
dighost_printmessage(ISC_LIST_HEAD(query->lookup->q),
|
||||||
|
&query->lookup->renderbuf,
|
||||||
|
query->lookup->sendmsg, true);
|
||||||
|
if (query->lookup->stats) {
|
||||||
|
printf(";; QUERY SIZE: %u\n\n",
|
||||||
|
isc_buffer_usedlength(
|
||||||
|
&query->lookup->renderbuf));
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
query->waiting_connect = false;
|
query->waiting_connect = false;
|
||||||
#if 0
|
#if 0
|
||||||
@@ -3527,7 +3528,6 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
|
|
||||||
query = event->ev_arg;
|
query = event->ev_arg;
|
||||||
TIME_NOW(&query->time_recv);
|
TIME_NOW(&query->time_recv);
|
||||||
debug("lookup=%p, query=%p", query->lookup, query);
|
|
||||||
|
|
||||||
l = query->lookup;
|
l = query->lookup;
|
||||||
|
|
||||||
@@ -3556,8 +3556,8 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
debug("in recv cancel handler");
|
debug("in recv cancel handler");
|
||||||
query->waiting_connect = false;
|
query->waiting_connect = false;
|
||||||
} else {
|
} else {
|
||||||
printf(";; communications error: %s\n",
|
dighost_error("communications error: %s\n",
|
||||||
isc_result_totext(sevent->result));
|
isc_result_totext(sevent->result));
|
||||||
if (keep != NULL)
|
if (keep != NULL)
|
||||||
isc_socket_detach(&keep);
|
isc_socket_detach(&keep);
|
||||||
isc_socket_detach(&query->sock);
|
isc_socket_detach(&query->sock);
|
||||||
@@ -3908,19 +3908,19 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
if (msg->rcode == dns_rcode_nxdomain &&
|
if (msg->rcode == dns_rcode_nxdomain &&
|
||||||
(l->origin != NULL || l->need_search)) {
|
(l->origin != NULL || l->need_search)) {
|
||||||
if (!next_origin(query->lookup) || showsearch) {
|
if (!next_origin(query->lookup) || showsearch) {
|
||||||
dighost_printmessage(query, msg, true);
|
dighost_printmessage(query, &b, msg, true);
|
||||||
dighost_received(isc_buffer_usedlength(&b),
|
dighost_received(isc_buffer_usedlength(&b),
|
||||||
&sevent->address, query);
|
&sevent->address, query);
|
||||||
}
|
}
|
||||||
} else if (!l->trace && !l->ns_search_only) {
|
} else if (!l->trace && !l->ns_search_only) {
|
||||||
dighost_printmessage(query, msg, true);
|
dighost_printmessage(query, &b, msg, true);
|
||||||
} else if (l->trace) {
|
} else if (l->trace) {
|
||||||
int nl = 0;
|
int nl = 0;
|
||||||
int count = msg->counts[DNS_SECTION_ANSWER];
|
int count = msg->counts[DNS_SECTION_ANSWER];
|
||||||
|
|
||||||
debug("in TRACE code");
|
debug("in TRACE code");
|
||||||
if (!l->ns_search_only)
|
if (!l->ns_search_only)
|
||||||
dighost_printmessage(query, msg, true);
|
dighost_printmessage(query, &b, msg, true);
|
||||||
|
|
||||||
l->rdtype = l->qrdtype;
|
l->rdtype = l->qrdtype;
|
||||||
if (l->trace_root || (l->ns_search_only && count > 0)) {
|
if (l->trace_root || (l->ns_search_only && count > 0)) {
|
||||||
@@ -3951,7 +3951,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
|
|||||||
l->trace_root = false;
|
l->trace_root = false;
|
||||||
usesearch = false;
|
usesearch = false;
|
||||||
} else {
|
} else {
|
||||||
dighost_printmessage(query, msg, true);
|
dighost_printmessage(query, &b, msg, true);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+16
-3
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -402,13 +400,16 @@ chase_cnamechain(dns_message_t *msg, dns_name_t *qname) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
printmessage(dig_query_t *query, dns_message_t *msg, bool headers) {
|
printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||||
|
dns_message_t *msg, bool headers)
|
||||||
|
{
|
||||||
bool did_flag = false;
|
bool did_flag = false;
|
||||||
dns_rdataset_t *opt, *tsig = NULL;
|
dns_rdataset_t *opt, *tsig = NULL;
|
||||||
const dns_name_t *tsigname;
|
const dns_name_t *tsigname;
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
isc_result_t result = ISC_R_SUCCESS;
|
||||||
int force_error;
|
int force_error;
|
||||||
|
|
||||||
|
UNUSED(msgbuf);
|
||||||
UNUSED(headers);
|
UNUSED(headers);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -856,6 +857,17 @@ parse_args(bool is_batchfile, int argc, char **argv) {
|
|||||||
ISC_LIST_APPEND(lookup_list, lookup, link);
|
ISC_LIST_APPEND(lookup_list, lookup, link);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
host_error(const char *format, ...) {
|
||||||
|
va_list args;
|
||||||
|
|
||||||
|
printf(";; ");
|
||||||
|
va_start(args, format);
|
||||||
|
vfprintf(stdout, format, args);
|
||||||
|
va_end(args);
|
||||||
|
printf("\n");
|
||||||
|
}
|
||||||
|
|
||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
@@ -873,6 +885,7 @@ main(int argc, char **argv) {
|
|||||||
dighost_received = received;
|
dighost_received = received;
|
||||||
dighost_trying = trying;
|
dighost_trying = trying;
|
||||||
dighost_shutdown = host_shutdown;
|
dighost_shutdown = host_shutdown;
|
||||||
|
dighost_error = host_error;
|
||||||
|
|
||||||
debug("main()");
|
debug("main()");
|
||||||
progname = argv[0];
|
progname = argv[0];
|
||||||
|
|||||||
@@ -140,6 +140,7 @@ struct dig_lookup {
|
|||||||
ttlunits,
|
ttlunits,
|
||||||
idnin,
|
idnin,
|
||||||
idnout,
|
idnout,
|
||||||
|
expandaaaa,
|
||||||
qr;
|
qr;
|
||||||
char textname[MXNAME]; /*% Name we're going to be looking up */
|
char textname[MXNAME]; /*% Name we're going to be looking up */
|
||||||
char cmdline[MXNAME];
|
char cmdline[MXNAME];
|
||||||
@@ -379,13 +380,22 @@ set_search_domain(char *domain);
|
|||||||
* then assigned to the appropriate function pointer
|
* then assigned to the appropriate function pointer
|
||||||
*/
|
*/
|
||||||
extern isc_result_t
|
extern isc_result_t
|
||||||
(*dighost_printmessage)(dig_query_t *query, dns_message_t *msg, bool headers);
|
(*dighost_printmessage)(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||||
|
dns_message_t *msg, bool headers);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Print an error message in the appropriate format.
|
||||||
|
*/
|
||||||
|
extern void
|
||||||
|
(*dighost_error)(const char *format, ...);
|
||||||
|
|
||||||
/*%<
|
/*%<
|
||||||
* Print the final result of the lookup.
|
* Print the final result of the lookup.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
extern void
|
extern void
|
||||||
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query);
|
(*dighost_received)(unsigned int bytes, isc_sockaddr_t *from,
|
||||||
|
dig_query_t *query);
|
||||||
/*%<
|
/*%<
|
||||||
* Print a message about where and when the response
|
* Print a message about where and when the response
|
||||||
* was received from, like the final comment in the
|
* was received from, like the final comment in the
|
||||||
|
|||||||
+19
-6
@@ -9,8 +9,6 @@
|
|||||||
* information regarding copyright ownership.
|
* information regarding copyright ownership.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -431,16 +429,21 @@ chase_cnamechain(dns_message_t *msg, dns_name_t *qname) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
printmessage(dig_query_t *query, dns_message_t *msg, bool headers) {
|
printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||||
|
dns_message_t *msg, bool headers)
|
||||||
|
{
|
||||||
char servtext[ISC_SOCKADDR_FORMATSIZE];
|
char servtext[ISC_SOCKADDR_FORMATSIZE];
|
||||||
|
|
||||||
|
UNUSED(msgbuf);
|
||||||
|
|
||||||
/* I've we've gotten this far, we've reached a server. */
|
/* I've we've gotten this far, we've reached a server. */
|
||||||
query_error = 0;
|
query_error = 0;
|
||||||
|
|
||||||
debug("printmessage()");
|
debug("printmessage()");
|
||||||
|
|
||||||
if(!default_lookups || query->lookup->rdtype == dns_rdatatype_a) {
|
if(!default_lookups || query->lookup->rdtype == dns_rdatatype_a) {
|
||||||
isc_sockaddr_format(&query->sockaddr, servtext, sizeof(servtext));
|
isc_sockaddr_format(&query->sockaddr, servtext,
|
||||||
|
sizeof(servtext));
|
||||||
printf("Server:\t\t%s\n", query->userarg);
|
printf("Server:\t\t%s\n", query->userarg);
|
||||||
printf("Address:\t%s\n", servtext);
|
printf("Address:\t%s\n", servtext);
|
||||||
|
|
||||||
@@ -852,8 +855,6 @@ get_next_command(void) {
|
|||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
buf = isc_mem_allocate(mctx, COMMSIZE);
|
buf = isc_mem_allocate(mctx, COMMSIZE);
|
||||||
if (buf == NULL)
|
|
||||||
fatal("memory allocation failure");
|
|
||||||
isc_app_block();
|
isc_app_block();
|
||||||
if (interactive) {
|
if (interactive) {
|
||||||
#ifdef HAVE_READLINE
|
#ifdef HAVE_READLINE
|
||||||
@@ -982,6 +983,17 @@ getinput(isc_task_t *task, isc_event_t *event) {
|
|||||||
isc_app_shutdown();
|
isc_app_shutdown();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
nsl_error(const char *format, ...) {
|
||||||
|
va_list args;
|
||||||
|
|
||||||
|
printf(";; ");
|
||||||
|
va_start(args, format);
|
||||||
|
vfprintf(stdout, format, args);
|
||||||
|
va_end(args);
|
||||||
|
printf("\n");
|
||||||
|
}
|
||||||
|
|
||||||
int
|
int
|
||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
@@ -999,6 +1011,7 @@ main(int argc, char **argv) {
|
|||||||
dighost_received = received;
|
dighost_received = received;
|
||||||
dighost_trying = trying;
|
dighost_trying = trying;
|
||||||
dighost_shutdown = query_finished;
|
dighost_shutdown = query_finished;
|
||||||
|
dighost_error = nsl_error;
|
||||||
|
|
||||||
result = isc_app_start();
|
result = isc_app_start();
|
||||||
check_result(result, "isc_app_start");
|
check_result(result, "isc_app_start");
|
||||||
|
|||||||
@@ -60,6 +60,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -87,6 +88,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -60,6 +60,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -85,6 +86,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -60,6 +60,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -87,6 +88,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@IDN_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -60,6 +60,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@READLINE_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@READLINE_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -87,6 +88,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@READLINE_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\include;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@@READLINE_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\isccfg\include;..\..\..\lib\irs\include;..\..\..\lib\irs\win32\include;..\..\..\lib\dns\include;..\..\..\lib\bind9\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -15,14 +15,15 @@ VERSION=@BIND9_VERSION@
|
|||||||
|
|
||||||
@BIND9_MAKE_INCLUDES@
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @OPENSSL_INCLUDES@
|
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
${OPENSSL_CFLAGS}
|
||||||
|
|
||||||
CDEFINES = -DVERSION=\"${VERSION}\"
|
CDEFINES = -DVERSION=\"${VERSION}\"
|
||||||
CWARNINGS =
|
CWARNINGS =
|
||||||
|
|
||||||
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
ISCLIBS = ../../lib/isc/libisc.@A@ @OPENSSL_LIBS@
|
ISCLIBS = ../../lib/isc/libisc.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ @OPENSSL_LIBS@
|
ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@ ${OPENSSL_LIBS} ${JSON_C_LIBS} ${LIBXML2_LIBS}
|
||||||
|
|
||||||
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
|||||||
+7
-71
@@ -16,8 +16,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
@@ -61,12 +59,7 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
#ifndef PATH_MAX
|
|
||||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
|
||||||
#endif
|
|
||||||
|
|
||||||
const char *program = "dnssec-cds";
|
const char *program = "dnssec-cds";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Infrastructure
|
* Infrastructure
|
||||||
@@ -82,12 +75,6 @@ static dns_fixedname_t fixed;
|
|||||||
static dns_name_t *name = NULL;
|
static dns_name_t *name = NULL;
|
||||||
static dns_rdataclass_t rdclass = dns_rdataclass_in;
|
static dns_rdataclass_t rdclass = dns_rdataclass_in;
|
||||||
|
|
||||||
/*
|
|
||||||
* List of digest types used by ds_from_cdnskey(), filled in by add_dtype()
|
|
||||||
* from -a arguments. The size of the array is an arbitrary limit.
|
|
||||||
*/
|
|
||||||
static uint8_t dtype[8];
|
|
||||||
|
|
||||||
static const char *startstr = NULL; /* from which we derive notbefore */
|
static const char *startstr = NULL; /* from which we derive notbefore */
|
||||||
static isc_stdtime_t notbefore = 0; /* restrict sig inception times */
|
static isc_stdtime_t notbefore = 0; /* restrict sig inception times */
|
||||||
static dns_rdata_rrsig_t oldestsig; /* for recording inception time */
|
static dns_rdata_rrsig_t oldestsig; /* for recording inception time */
|
||||||
@@ -129,7 +116,7 @@ static int nkey; /* number of child zone DNSKEY records */
|
|||||||
typedef struct keyinfo {
|
typedef struct keyinfo {
|
||||||
dns_rdata_t rdata;
|
dns_rdata_t rdata;
|
||||||
dst_key_t *dst;
|
dst_key_t *dst;
|
||||||
uint8_t algo;
|
dns_secalg_t algo;
|
||||||
dns_keytag_t tag;
|
dns_keytag_t tag;
|
||||||
} keyinfo_t;
|
} keyinfo_t;
|
||||||
|
|
||||||
@@ -543,9 +530,6 @@ match_keyset_dsset(dns_rdataset_t *keyset, dns_rdataset_t *dsset,
|
|||||||
nkey = dns_rdataset_count(keyset);
|
nkey = dns_rdataset_count(keyset);
|
||||||
|
|
||||||
keytable = isc_mem_get(mctx, sizeof(keyinfo_t) * nkey);
|
keytable = isc_mem_get(mctx, sizeof(keyinfo_t) * nkey);
|
||||||
if (keytable == NULL) {
|
|
||||||
fatal("out of memory");
|
|
||||||
}
|
|
||||||
|
|
||||||
for (result = dns_rdataset_first(keyset), i = 0;
|
for (result = dns_rdataset_first(keyset), i = 0;
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -614,19 +598,15 @@ free_keytable(keyinfo_t **keytable_p) {
|
|||||||
* otherwise the key algorithm. This is used by the signature coverage
|
* otherwise the key algorithm. This is used by the signature coverage
|
||||||
* check functions below.
|
* check functions below.
|
||||||
*/
|
*/
|
||||||
static uint8_t *
|
static dns_secalg_t *
|
||||||
matching_sigs(keyinfo_t *keytbl, dns_rdataset_t *rdataset,
|
matching_sigs(keyinfo_t *keytbl, dns_rdataset_t *rdataset,
|
||||||
dns_rdataset_t *sigset)
|
dns_rdataset_t *sigset)
|
||||||
{
|
{
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
uint8_t *algo;
|
dns_secalg_t *algo;
|
||||||
int i;
|
int i;
|
||||||
|
|
||||||
algo = isc_mem_get(mctx, nkey);
|
algo = isc_mem_get(mctx, nkey);
|
||||||
if (algo == NULL) {
|
|
||||||
fatal("allocating RRSIG/DNSKEY match list: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
}
|
|
||||||
memset(algo, 0, nkey);
|
memset(algo, 0, nkey);
|
||||||
|
|
||||||
for (result = dns_rdataset_first(sigset);
|
for (result = dns_rdataset_first(sigset);
|
||||||
@@ -702,7 +682,7 @@ matching_sigs(keyinfo_t *keytbl, dns_rdataset_t *rdataset,
|
|||||||
* fetched from the child zone, any working signature is enough.
|
* fetched from the child zone, any working signature is enough.
|
||||||
*/
|
*/
|
||||||
static bool
|
static bool
|
||||||
signed_loose(uint8_t *algo) {
|
signed_loose(dns_secalg_t *algo) {
|
||||||
bool ok = false;
|
bool ok = false;
|
||||||
int i;
|
int i;
|
||||||
for (i = 0; i < nkey; i++) {
|
for (i = 0; i < nkey; i++) {
|
||||||
@@ -721,7 +701,7 @@ signed_loose(uint8_t *algo) {
|
|||||||
* RRset.
|
* RRset.
|
||||||
*/
|
*/
|
||||||
static bool
|
static bool
|
||||||
signed_strict(dns_rdataset_t *dsset, uint8_t *algo) {
|
signed_strict(dns_rdataset_t *dsset, dns_secalg_t *algo) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool all_ok = true;
|
bool all_ok = true;
|
||||||
|
|
||||||
@@ -760,10 +740,6 @@ rdata_get(void) {
|
|||||||
dns_rdata_t *rdata;
|
dns_rdata_t *rdata;
|
||||||
|
|
||||||
rdata = isc_mem_get(mctx, sizeof(*rdata));
|
rdata = isc_mem_get(mctx, sizeof(*rdata));
|
||||||
if (rdata == NULL) {
|
|
||||||
fatal("allocating DS rdata: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
}
|
|
||||||
dns_rdata_init(rdata);
|
dns_rdata_init(rdata);
|
||||||
|
|
||||||
return (rdata);
|
return (rdata);
|
||||||
@@ -838,34 +814,6 @@ ds_from_cdnskey(dns_rdatalist_t *dslist, isc_buffer_t *buf,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
|
||||||
* For sorting the digest types so that DS records generated
|
|
||||||
* from CDNSKEY records are in canonical order.
|
|
||||||
*/
|
|
||||||
static int
|
|
||||||
cmp_dtype(const void *ap, const void *bp) {
|
|
||||||
int a = *(const uint8_t *)ap;
|
|
||||||
int b = *(const uint8_t *)bp;
|
|
||||||
return (a - b);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
|
||||||
add_dtype(const char *dn) {
|
|
||||||
uint8_t dt;
|
|
||||||
unsigned i, n;
|
|
||||||
|
|
||||||
dt = strtodsdigest(dn);
|
|
||||||
n = sizeof(dtype)/sizeof(dtype[0]);
|
|
||||||
for (i = 0; i < n; i++) {
|
|
||||||
if (dtype[i] == 0 || dtype[i] == dt) {
|
|
||||||
dtype[i] = dt;
|
|
||||||
qsort(dtype, i+1, 1, cmp_dtype);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
fatal("too many -a digest type arguments");
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
static void
|
||||||
make_new_ds_set(ds_maker_func_t *ds_from_rdata,
|
make_new_ds_set(ds_maker_func_t *ds_from_rdata,
|
||||||
uint32_t ttl, dns_rdataset_t *rdset)
|
uint32_t ttl, dns_rdataset_t *rdset)
|
||||||
@@ -876,10 +824,6 @@ make_new_ds_set(ds_maker_func_t *ds_from_rdata,
|
|||||||
dns_rdatalist_t *dslist;
|
dns_rdatalist_t *dslist;
|
||||||
|
|
||||||
dslist = isc_mem_get(mctx, sizeof(*dslist));
|
dslist = isc_mem_get(mctx, sizeof(*dslist));
|
||||||
if (dslist == NULL) {
|
|
||||||
fatal("allocating new DS list: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
}
|
|
||||||
|
|
||||||
dns_rdatalist_init(dslist);
|
dns_rdatalist_init(dslist);
|
||||||
dslist->rdclass = rdclass;
|
dslist->rdclass = rdclass;
|
||||||
@@ -936,7 +880,7 @@ consistent_digests(dns_rdataset_t *dsset) {
|
|||||||
dns_rdata_t *arrdata;
|
dns_rdata_t *arrdata;
|
||||||
dns_rdata_ds_t *ds;
|
dns_rdata_ds_t *ds;
|
||||||
dns_keytag_t key_tag;
|
dns_keytag_t key_tag;
|
||||||
uint8_t algorithm;
|
dns_secalg_t algorithm;
|
||||||
bool match;
|
bool match;
|
||||||
int i, j, n, d;
|
int i, j, n, d;
|
||||||
|
|
||||||
@@ -948,10 +892,6 @@ consistent_digests(dns_rdataset_t *dsset) {
|
|||||||
n = dns_rdataset_count(dsset);
|
n = dns_rdataset_count(dsset);
|
||||||
|
|
||||||
arrdata = isc_mem_get(mctx, n * sizeof(dns_rdata_t));
|
arrdata = isc_mem_get(mctx, n * sizeof(dns_rdata_t));
|
||||||
if (arrdata == NULL) {
|
|
||||||
fatal("allocating DS rdata array: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
}
|
|
||||||
|
|
||||||
for (result = dns_rdataset_first(dsset), i = 0;
|
for (result = dns_rdataset_first(dsset), i = 0;
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -967,10 +907,6 @@ consistent_digests(dns_rdataset_t *dsset) {
|
|||||||
* Convert sorted arrdata to more accessible format
|
* Convert sorted arrdata to more accessible format
|
||||||
*/
|
*/
|
||||||
ds = isc_mem_get(mctx, n * sizeof(dns_rdata_ds_t));
|
ds = isc_mem_get(mctx, n * sizeof(dns_rdata_ds_t));
|
||||||
if (ds == NULL) {
|
|
||||||
fatal("allocating unpacked DS array: %s",
|
|
||||||
isc_result_totext(ISC_R_NOMEMORY));
|
|
||||||
}
|
|
||||||
|
|
||||||
for (i = 0; i < n; i++) {
|
for (i = 0; i < n; i++) {
|
||||||
result = dns_rdata_tostruct(&arrdata[i], &ds[i], NULL);
|
result = dns_rdata_tostruct(&arrdata[i], &ds[i], NULL);
|
||||||
@@ -1154,7 +1090,7 @@ main(int argc, char *argv[]) {
|
|||||||
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case 'a':
|
case 'a':
|
||||||
add_dtype(isc_commandline_argument);
|
add_dtype(strtodsdigest(isc_commandline_argument));
|
||||||
break;
|
break;
|
||||||
case 'c':
|
case 'c':
|
||||||
rdclass = strtoclass(isc_commandline_argument);
|
rdclass = strtoclass(isc_commandline_argument);
|
||||||
|
|||||||
@@ -10,12 +10,12 @@
|
|||||||
.\" Title: dnssec-dsfromkey
|
.\" Title: dnssec-dsfromkey
|
||||||
.\" Author:
|
.\" Author:
|
||||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||||
.\" Date: 2012-05-02
|
.\" Date: 2019-05-08
|
||||||
.\" Manual: BIND9
|
.\" Manual: BIND9
|
||||||
.\" Source: ISC
|
.\" Source: ISC
|
||||||
.\" Language: English
|
.\" Language: English
|
||||||
.\"
|
.\"
|
||||||
.TH "DNSSEC\-DSFROMKEY" "8" "2012\-05\-02" "ISC" "BIND9"
|
.TH "DNSSEC\-DSFROMKEY" "8" "2019\-05\-08" "ISC" "BIND9"
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
.\" * Define some portability stuff
|
.\" * Define some portability stuff
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
@@ -50,11 +50,9 @@ dnssec-dsfromkey \- DNSSEC DS RR generation tool
|
|||||||
.PP
|
.PP
|
||||||
The
|
The
|
||||||
\fBdnssec\-dsfromkey\fR
|
\fBdnssec\-dsfromkey\fR
|
||||||
command outputs DS (Delegation Signer) resource records (RRs) and other similarly\-constructed RRs: with the
|
command outputs DS (Delegation Signer) resource records (RRs), or CDS (Child DS) RRs with the
|
||||||
\fB\-l\fR
|
|
||||||
option it outputs DLV (DNSSEC Lookaside Validation) RRs; or with the
|
|
||||||
\fB\-C\fR
|
\fB\-C\fR
|
||||||
it outputs CDS (Child DS) RRs\&.
|
option\&.
|
||||||
.PP
|
.PP
|
||||||
The input keys can be specified in a number of ways:
|
The input keys can be specified in a number of ways:
|
||||||
.PP
|
.PP
|
||||||
@@ -83,13 +81,13 @@ file, as generated by
|
|||||||
\-1
|
\-1
|
||||||
.RS 4
|
.RS 4
|
||||||
An abbreviation for
|
An abbreviation for
|
||||||
\fB\-a SHA1\fR
|
\fB\-a SHA\-1\fR\&. (Note: The SHA\-1 algorithm is no longer recommended for use when generating new DS and CDS records\&.)
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-2
|
\-2
|
||||||
.RS 4
|
.RS 4
|
||||||
An abbreviation for
|
An abbreviation for
|
||||||
\fB\-a SHA\-256\fR
|
\fB\-a SHA\-256\fR\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-a \fIalgorithm\fR
|
\-a \fIalgorithm\fR
|
||||||
@@ -98,7 +96,7 @@ Specify a digest algorithm to use when converting DNSKEY records to DS records\&
|
|||||||
.sp
|
.sp
|
||||||
The
|
The
|
||||||
\fIalgorithm\fR
|
\fIalgorithm\fR
|
||||||
must be one of SHA\-1, SHA\-256, or SHA\-384\&. These values are case insensitive, and the hyphen may be omitted\&. If no algorithm is specified, the default is SHA\-256\&.
|
must be one of SHA\-1, SHA\-256, or SHA\-384\&. These values are case insensitive, and the hyphen may be omitted\&. If no algorithm is specified, the default is SHA\-256\&. (Note: The SHA\-1 algorithm is no longer recommended for use when generating new DS and CDS records\&.)
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-A
|
\-A
|
||||||
@@ -119,9 +117,7 @@ zone file mode\&.
|
|||||||
.PP
|
.PP
|
||||||
\-C
|
\-C
|
||||||
.RS 4
|
.RS 4
|
||||||
Generate CDS records rather than DS records\&. This is mutually exclusive with the
|
Generate CDS records rather than DS records\&.
|
||||||
\fB\-l\fR
|
|
||||||
option for generating DLV records\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-f \fIfile\fR
|
\-f \fIfile\fR
|
||||||
@@ -156,15 +152,6 @@ files in
|
|||||||
\fBdirectory\fR\&.
|
\fBdirectory\fR\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-l \fIdomain\fR
|
|
||||||
.RS 4
|
|
||||||
Generate a DLV set instead of a DS set\&. The specified
|
|
||||||
\fIdomain\fR
|
|
||||||
is appended to the name for each record in the set\&. This is mutually exclusive with the
|
|
||||||
\fB\-C\fR
|
|
||||||
option for generating CDS records\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-s
|
\-s
|
||||||
.RS 4
|
.RS 4
|
||||||
Keyset mode:
|
Keyset mode:
|
||||||
@@ -224,8 +211,6 @@ A keyfile error can give a "file not found" even if the file exists\&.
|
|||||||
BIND 9 Administrator Reference Manual,
|
BIND 9 Administrator Reference Manual,
|
||||||
RFC 3658
|
RFC 3658
|
||||||
(DS RRs),
|
(DS RRs),
|
||||||
RFC 4431
|
|
||||||
(DLV RRs),
|
|
||||||
RFC 4509
|
RFC 4509
|
||||||
(SHA\-256 for DS RRs),
|
(SHA\-256 for DS RRs),
|
||||||
RFC 6605
|
RFC 6605
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -49,12 +47,7 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
#ifndef PATH_MAX
|
|
||||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
|
||||||
#endif
|
|
||||||
|
|
||||||
const char *program = "dnssec-dsfromkey";
|
const char *program = "dnssec-dsfromkey";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
static dns_rdataclass_t rdclass;
|
static dns_rdataclass_t rdclass;
|
||||||
static dns_fixedname_t fixed;
|
static dns_fixedname_t fixed;
|
||||||
@@ -215,8 +208,7 @@ loadkey(char *filename, unsigned char *key_buf, unsigned int key_buf_size,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
logkey(dns_rdata_t *rdata)
|
logkey(dns_rdata_t *rdata) {
|
||||||
{
|
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
dst_key_t *key = NULL;
|
dst_key_t *key = NULL;
|
||||||
isc_buffer_t buf;
|
isc_buffer_t buf;
|
||||||
@@ -235,9 +227,7 @@ logkey(dns_rdata_t *rdata)
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
emit(unsigned int dtype, bool showall, char *lookaside,
|
emit(dns_dsdigest_t dt, bool showall, bool cds, dns_rdata_t *rdata) {
|
||||||
bool cds, dns_rdata_t *rdata)
|
|
||||||
{
|
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
unsigned char buf[DNS_DS_BUFFERSIZE];
|
unsigned char buf[DNS_DS_BUFFERSIZE];
|
||||||
char text_buf[DST_KEY_MAXTEXTSIZE];
|
char text_buf[DST_KEY_MAXTEXTSIZE];
|
||||||
@@ -261,7 +251,7 @@ emit(unsigned int dtype, bool showall, char *lookaside,
|
|||||||
if ((dnskey.flags & DNS_KEYFLAG_KSK) == 0 && !showall)
|
if ((dnskey.flags & DNS_KEYFLAG_KSK) == 0 && !showall)
|
||||||
return;
|
return;
|
||||||
|
|
||||||
result = dns_ds_buildrdata(name, rdata, dtype, buf, &ds);
|
result = dns_ds_buildrdata(name, rdata, dt, buf, &ds);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("can't build record");
|
fatal("can't build record");
|
||||||
|
|
||||||
@@ -269,18 +259,6 @@ emit(unsigned int dtype, bool showall, char *lookaside,
|
|||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
fatal("can't print name");
|
fatal("can't print name");
|
||||||
|
|
||||||
/* Add lookaside origin, if set */
|
|
||||||
if (lookaside != NULL) {
|
|
||||||
if (isc_buffer_availablelength(&nameb) < strlen(lookaside))
|
|
||||||
fatal("DLV origin '%s' is too long", lookaside);
|
|
||||||
isc_buffer_putstr(&nameb, lookaside);
|
|
||||||
if (lookaside[strlen(lookaside) - 1] != '.') {
|
|
||||||
if (isc_buffer_availablelength(&nameb) < 1)
|
|
||||||
fatal("DLV origin '%s' is too long", lookaside);
|
|
||||||
isc_buffer_putstr(&nameb, ".");
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
result = dns_rdata_tofmttext(&ds, (dns_name_t *) NULL, 0, 0, 0, "",
|
result = dns_rdata_tofmttext(&ds, (dns_name_t *) NULL, 0, 0, 0, "",
|
||||||
&textb);
|
&textb);
|
||||||
|
|
||||||
@@ -300,18 +278,28 @@ emit(unsigned int dtype, bool showall, char *lookaside,
|
|||||||
isc_buffer_usedregion(&classb, &r);
|
isc_buffer_usedregion(&classb, &r);
|
||||||
printf("%.*s", (int)r.length, r.base);
|
printf("%.*s", (int)r.length, r.base);
|
||||||
|
|
||||||
if (lookaside == NULL) {
|
if (cds) {
|
||||||
if (cds)
|
printf(" CDS ");
|
||||||
printf(" CDS ");
|
} else {
|
||||||
else
|
printf(" DS ");
|
||||||
printf(" DS ");
|
}
|
||||||
} else
|
|
||||||
printf(" DLV ");
|
|
||||||
|
|
||||||
isc_buffer_usedregion(&textb, &r);
|
isc_buffer_usedregion(&textb, &r);
|
||||||
printf("%.*s\n", (int)r.length, r.base);
|
printf("%.*s\n", (int)r.length, r.base);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
emits(bool showall, bool cds, dns_rdata_t *rdata) {
|
||||||
|
unsigned i, n;
|
||||||
|
|
||||||
|
n = sizeof(dtype)/sizeof(dtype[0]);
|
||||||
|
for (i = 0; i < n; i++) {
|
||||||
|
if (dtype[i] != 0) {
|
||||||
|
emit(dtype[i], showall, cds, rdata);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
@@ -333,12 +321,11 @@ usage(void) {
|
|||||||
" -f zonefile: read keys from a zone file\n"
|
" -f zonefile: read keys from a zone file\n"
|
||||||
" -h: print help information\n"
|
" -h: print help information\n"
|
||||||
" -K directory: where to find key or keyset files\n"
|
" -K directory: where to find key or keyset files\n"
|
||||||
" -l zone: print DLV records in the given lookaside zone\n"
|
|
||||||
" -s: read keys from keyset-<dnsname> file\n"
|
" -s: read keys from keyset-<dnsname> file\n"
|
||||||
" -T: TTL of output records (omitted by default)\n"
|
" -T: TTL of output records (omitted by default)\n"
|
||||||
" -v level: verbosity\n"
|
" -v level: verbosity\n"
|
||||||
" -V: print version information\n");
|
" -V: print version information\n");
|
||||||
fprintf(stderr, "Output: DS, DLV, or CDS RRs\n");
|
fprintf(stderr, "Output: DS or CDS RRs\n");
|
||||||
|
|
||||||
exit (-1);
|
exit (-1);
|
||||||
}
|
}
|
||||||
@@ -347,14 +334,11 @@ int
|
|||||||
main(int argc, char **argv) {
|
main(int argc, char **argv) {
|
||||||
char *classname = NULL;
|
char *classname = NULL;
|
||||||
char *filename = NULL, *dir = NULL, *namestr;
|
char *filename = NULL, *dir = NULL, *namestr;
|
||||||
char *lookaside = NULL;
|
|
||||||
char *endp;
|
char *endp;
|
||||||
int ch;
|
int ch;
|
||||||
unsigned int dtype = DNS_DSDIGEST_SHA1;
|
bool cds = false;
|
||||||
bool cds = false;
|
bool usekeyset = false;
|
||||||
bool both = true;
|
bool showall = false;
|
||||||
bool usekeyset = false;
|
|
||||||
bool showall = false;
|
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
isc_log_t *log = NULL;
|
isc_log_t *log = NULL;
|
||||||
dns_rdataset_t rdataset;
|
dns_rdataset_t rdataset;
|
||||||
@@ -362,12 +346,14 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
dns_rdata_init(&rdata);
|
dns_rdata_init(&rdata);
|
||||||
|
|
||||||
if (argc == 1)
|
if (argc == 1) {
|
||||||
usage();
|
usage();
|
||||||
|
}
|
||||||
|
|
||||||
result = isc_mem_create(0, 0, &mctx);
|
result = isc_mem_create(0, 0, &mctx);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("out of memory");
|
fatal("out of memory");
|
||||||
|
}
|
||||||
|
|
||||||
#if USE_PKCS11
|
#if USE_PKCS11
|
||||||
pk11_result_register();
|
pk11_result_register();
|
||||||
@@ -380,24 +366,18 @@ main(int argc, char **argv) {
|
|||||||
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, OPTIONS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case '1':
|
case '1':
|
||||||
dtype = DNS_DSDIGEST_SHA1;
|
add_dtype(DNS_DSDIGEST_SHA1);
|
||||||
both = false;
|
|
||||||
break;
|
break;
|
||||||
case '2':
|
case '2':
|
||||||
dtype = DNS_DSDIGEST_SHA256;
|
add_dtype(DNS_DSDIGEST_SHA256);
|
||||||
both = false;
|
|
||||||
break;
|
break;
|
||||||
case 'A':
|
case 'A':
|
||||||
showall = true;
|
showall = true;
|
||||||
break;
|
break;
|
||||||
case 'a':
|
case 'a':
|
||||||
dtype = strtodsdigest(isc_commandline_argument);
|
add_dtype(strtodsdigest(isc_commandline_argument));
|
||||||
both = false;
|
|
||||||
break;
|
break;
|
||||||
case 'C':
|
case 'C':
|
||||||
if (lookaside != NULL)
|
|
||||||
fatal("lookaside and CDS are mutually"
|
|
||||||
" exclusive");
|
|
||||||
cds = true;
|
cds = true;
|
||||||
break;
|
break;
|
||||||
case 'c':
|
case 'c':
|
||||||
@@ -416,12 +396,7 @@ main(int argc, char **argv) {
|
|||||||
filename = isc_commandline_argument;
|
filename = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 'l':
|
case 'l':
|
||||||
if (cds)
|
fatal("-l option (DLV lookaside) is obsolete");
|
||||||
fatal("lookaside and CDS are mutually"
|
|
||||||
" exclusive");
|
|
||||||
lookaside = isc_commandline_argument;
|
|
||||||
if (strlen(lookaside) == 0U)
|
|
||||||
fatal("lookaside must be a non-empty string");
|
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 's':
|
||||||
usekeyset = true;
|
usekeyset = true;
|
||||||
@@ -460,22 +435,32 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
rdclass = strtoclass(classname);
|
rdclass = strtoclass(classname);
|
||||||
|
|
||||||
if (usekeyset && filename != NULL)
|
if (usekeyset && filename != NULL) {
|
||||||
fatal("cannot use both -s and -f");
|
fatal("cannot use both -s and -f");
|
||||||
|
}
|
||||||
|
|
||||||
/* When not using -f, -A is implicit */
|
/* When not using -f, -A is implicit */
|
||||||
if (filename == NULL)
|
if (filename == NULL) {
|
||||||
showall = true;
|
showall = true;
|
||||||
|
}
|
||||||
|
|
||||||
if (argc < isc_commandline_index + 1 && filename == NULL)
|
/* Default digest type if none specified. */
|
||||||
|
if (dtype[0] == 0) {
|
||||||
|
dtype[0] = DNS_DSDIGEST_SHA256;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (argc < isc_commandline_index + 1 && filename == NULL) {
|
||||||
fatal("the key file name was not specified");
|
fatal("the key file name was not specified");
|
||||||
if (argc > isc_commandline_index + 1)
|
}
|
||||||
|
if (argc > isc_commandline_index + 1) {
|
||||||
fatal("extraneous arguments");
|
fatal("extraneous arguments");
|
||||||
|
}
|
||||||
|
|
||||||
result = dst_lib_init(mctx, NULL);
|
result = dst_lib_init(mctx, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("could not initialize dst: %s",
|
fatal("could not initialize dst: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
|
||||||
setup_logging(mctx, &log);
|
setup_logging(mctx, &log);
|
||||||
|
|
||||||
@@ -485,38 +470,38 @@ main(int argc, char **argv) {
|
|||||||
if (argc < isc_commandline_index + 1 && filename != NULL) {
|
if (argc < isc_commandline_index + 1 && filename != NULL) {
|
||||||
/* using zone name as the zone file name */
|
/* using zone name as the zone file name */
|
||||||
namestr = filename;
|
namestr = filename;
|
||||||
} else
|
} else {
|
||||||
namestr = argv[isc_commandline_index];
|
namestr = argv[isc_commandline_index];
|
||||||
|
}
|
||||||
|
|
||||||
result = initname(namestr);
|
result = initname(namestr);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("could not initialize name %s", namestr);
|
fatal("could not initialize name %s", namestr);
|
||||||
|
}
|
||||||
|
|
||||||
if (usekeyset)
|
if (usekeyset) {
|
||||||
result = loadkeyset(dir, &rdataset);
|
result = loadkeyset(dir, &rdataset);
|
||||||
else
|
} else {
|
||||||
result = loadset(filename, &rdataset);
|
result = loadset(filename, &rdataset);
|
||||||
|
}
|
||||||
|
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS) {
|
||||||
fatal("could not load DNSKEY set: %s\n",
|
fatal("could not load DNSKEY set: %s\n",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
|
||||||
for (result = dns_rdataset_first(&rdataset);
|
for (result = dns_rdataset_first(&rdataset);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
result = dns_rdataset_next(&rdataset)) {
|
result = dns_rdataset_next(&rdataset))
|
||||||
|
{
|
||||||
dns_rdata_init(&rdata);
|
dns_rdata_init(&rdata);
|
||||||
dns_rdataset_current(&rdataset, &rdata);
|
dns_rdataset_current(&rdataset, &rdata);
|
||||||
|
|
||||||
if (verbose > 2)
|
if (verbose > 2) {
|
||||||
logkey(&rdata);
|
logkey(&rdata);
|
||||||
|
}
|
||||||
|
|
||||||
if (both) {
|
emits(showall, cds, &rdata);
|
||||||
emit(DNS_DSDIGEST_SHA1, showall, lookaside,
|
|
||||||
cds, &rdata);
|
|
||||||
emit(DNS_DSDIGEST_SHA256, showall, lookaside,
|
|
||||||
cds, &rdata);
|
|
||||||
} else
|
|
||||||
emit(dtype, showall, lookaside, cds, &rdata);
|
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
unsigned char key_buf[DST_KEY_MAXSIZE];
|
unsigned char key_buf[DST_KEY_MAXSIZE];
|
||||||
@@ -524,28 +509,25 @@ main(int argc, char **argv) {
|
|||||||
loadkey(argv[isc_commandline_index], key_buf,
|
loadkey(argv[isc_commandline_index], key_buf,
|
||||||
DST_KEY_MAXSIZE, &rdata);
|
DST_KEY_MAXSIZE, &rdata);
|
||||||
|
|
||||||
if (both) {
|
emits(showall, cds, &rdata);
|
||||||
emit(DNS_DSDIGEST_SHA1, showall, lookaside, cds,
|
|
||||||
&rdata);
|
|
||||||
emit(DNS_DSDIGEST_SHA256, showall, lookaside, cds,
|
|
||||||
&rdata);
|
|
||||||
} else
|
|
||||||
emit(dtype, showall, lookaside, cds, &rdata);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (dns_rdataset_isassociated(&rdataset))
|
if (dns_rdataset_isassociated(&rdataset)) {
|
||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
|
}
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
dns_name_destroy();
|
||||||
if (verbose > 10)
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
|
}
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (ferror(stdout)) {
|
if (ferror(stdout)) {
|
||||||
fprintf(stderr, "write error\n");
|
fprintf(stderr, "write error\n");
|
||||||
return (1);
|
return (1);
|
||||||
} else
|
} else {
|
||||||
return (0);
|
return (0);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
<!-- Converted by db4-upgrade version 1.0 -->
|
<!-- Converted by db4-upgrade version 1.0 -->
|
||||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-dsfromkey">
|
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-dsfromkey">
|
||||||
<info>
|
<info>
|
||||||
<date>2012-05-02</date>
|
<date>2019-05-08</date>
|
||||||
</info>
|
</info>
|
||||||
<refentryinfo>
|
<refentryinfo>
|
||||||
<corpname>ISC</corpname>
|
<corpname>ISC</corpname>
|
||||||
@@ -112,10 +112,8 @@
|
|||||||
|
|
||||||
<para>
|
<para>
|
||||||
The <command>dnssec-dsfromkey</command> command outputs DS (Delegation
|
The <command>dnssec-dsfromkey</command> command outputs DS (Delegation
|
||||||
Signer) resource records (RRs) and other similarly-constructed RRs:
|
Signer) resource records (RRs), or CDS (Child DS) RRs with the
|
||||||
with the <option>-l</option> option it outputs DLV (DNSSEC Lookaside
|
<option>-C</option> option.
|
||||||
Validation) RRs; or with the <option>-C</option> it outputs CDS (Child
|
|
||||||
DS) RRs.
|
|
||||||
</para>
|
</para>
|
||||||
|
|
||||||
<para>
|
<para>
|
||||||
@@ -150,7 +148,9 @@
|
|||||||
<term>-1</term>
|
<term>-1</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
An abbreviation for <option>-a SHA1</option>
|
An abbreviation for <option>-a SHA-1</option>.
|
||||||
|
(Note: The SHA-1 algorithm is no longer recommended for use
|
||||||
|
when generating new DS and CDS records.)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -159,7 +159,7 @@
|
|||||||
<term>-2</term>
|
<term>-2</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
An abbreviation for <option>-a SHA-256</option>
|
An abbreviation for <option>-a SHA-256</option>.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -178,6 +178,8 @@
|
|||||||
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
|
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
|
||||||
and the hyphen may be omitted. If no algorithm is specified,
|
and the hyphen may be omitted. If no algorithm is specified,
|
||||||
the default is SHA-256.
|
the default is SHA-256.
|
||||||
|
(Note: The SHA-1 algorithm is no longer recommended for use
|
||||||
|
when generating new DS and CDS records.)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -208,9 +210,7 @@
|
|||||||
<term>-C</term>
|
<term>-C</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Generate CDS records rather than DS records. This is mutually
|
Generate CDS records rather than DS records.
|
||||||
exclusive with the <option>-l</option> option for generating DLV
|
|
||||||
records.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -256,19 +256,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-l <replaceable class="parameter">domain</replaceable></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Generate a DLV set instead of a DS set. The specified
|
|
||||||
<replaceable>domain</replaceable> is appended to the name for each
|
|
||||||
record in the set.
|
|
||||||
This is mutually exclusive with the <option>-C</option> option
|
|
||||||
for generating CDS records.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-s</term>
|
<term>-s</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -358,7 +345,6 @@
|
|||||||
</citerefentry>,
|
</citerefentry>,
|
||||||
<citetitle>BIND 9 Administrator Reference Manual</citetitle>,
|
<citetitle>BIND 9 Administrator Reference Manual</citetitle>,
|
||||||
<citetitle>RFC 3658</citetitle> (DS RRs),
|
<citetitle>RFC 3658</citetitle> (DS RRs),
|
||||||
<citetitle>RFC 4431</citetitle> (DLV RRs),
|
|
||||||
<citetitle>RFC 4509</citetitle> (SHA-256 for DS RRs),
|
<citetitle>RFC 4509</citetitle> (SHA-256 for DS RRs),
|
||||||
<citetitle>RFC 6605</citetitle> (SHA-384 for DS RRs),
|
<citetitle>RFC 6605</citetitle> (SHA-384 for DS RRs),
|
||||||
<citetitle>RFC 7344</citetitle> (CDS and CDNSKEY RRs).
|
<citetitle>RFC 7344</citetitle> (CDS and CDNSKEY RRs).
|
||||||
|
|||||||
@@ -97,10 +97,8 @@
|
|||||||
|
|
||||||
<p>
|
<p>
|
||||||
The <span class="command"><strong>dnssec-dsfromkey</strong></span> command outputs DS (Delegation
|
The <span class="command"><strong>dnssec-dsfromkey</strong></span> command outputs DS (Delegation
|
||||||
Signer) resource records (RRs) and other similarly-constructed RRs:
|
Signer) resource records (RRs), or CDS (Child DS) RRs with the
|
||||||
with the <code class="option">-l</code> option it outputs DLV (DNSSEC Lookaside
|
<code class="option">-C</code> option.
|
||||||
Validation) RRs; or with the <code class="option">-C</code> it outputs CDS (Child
|
|
||||||
DS) RRs.
|
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
@@ -135,13 +133,15 @@
|
|||||||
<dt><span class="term">-1</span></dt>
|
<dt><span class="term">-1</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
An abbreviation for <code class="option">-a SHA1</code>
|
An abbreviation for <code class="option">-a SHA-1</code>.
|
||||||
|
(Note: The SHA-1 algorithm is no longer recommended for use
|
||||||
|
when generating new DS and CDS records.)
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-2</span></dt>
|
<dt><span class="term">-2</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
An abbreviation for <code class="option">-a SHA-256</code>
|
An abbreviation for <code class="option">-a SHA-256</code>.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||||
@@ -157,6 +157,8 @@
|
|||||||
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
|
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
|
||||||
and the hyphen may be omitted. If no algorithm is specified,
|
and the hyphen may be omitted. If no algorithm is specified,
|
||||||
the default is SHA-256.
|
the default is SHA-256.
|
||||||
|
(Note: The SHA-1 algorithm is no longer recommended for use
|
||||||
|
when generating new DS and CDS records.)
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-A</span></dt>
|
<dt><span class="term">-A</span></dt>
|
||||||
@@ -178,9 +180,7 @@
|
|||||||
<dt><span class="term">-C</span></dt>
|
<dt><span class="term">-C</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Generate CDS records rather than DS records. This is mutually
|
Generate CDS records rather than DS records.
|
||||||
exclusive with the <code class="option">-l</code> option for generating DLV
|
|
||||||
records.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
|
<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
|
||||||
@@ -215,16 +215,6 @@
|
|||||||
<code class="option">directory</code>.
|
<code class="option">directory</code>.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Generate a DLV set instead of a DS set. The specified
|
|
||||||
<em class="replaceable"><code>domain</code></em> is appended to the name for each
|
|
||||||
record in the set.
|
|
||||||
This is mutually exclusive with the <code class="option">-C</code> option
|
|
||||||
for generating CDS records.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-s</span></dt>
|
<dt><span class="term">-s</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -307,7 +297,6 @@
|
|||||||
</span>,
|
</span>,
|
||||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||||
<em class="citetitle">RFC 3658</em> (DS RRs),
|
<em class="citetitle">RFC 3658</em> (DS RRs),
|
||||||
<em class="citetitle">RFC 4431</em> (DLV RRs),
|
|
||||||
<em class="citetitle">RFC 4509</em> (SHA-256 for DS RRs),
|
<em class="citetitle">RFC 4509</em> (SHA-256 for DS RRs),
|
||||||
<em class="citetitle">RFC 6605</em> (SHA-384 for DS RRs),
|
<em class="citetitle">RFC 6605</em> (SHA-384 for DS RRs),
|
||||||
<em class="citetitle">RFC 7344</em> (CDS and CDNSKEY RRs).
|
<em class="citetitle">RFC 7344</em> (CDS and CDNSKEY RRs).
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
|
|
||||||
@@ -48,12 +46,7 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
#ifndef PATH_MAX
|
|
||||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
|
||||||
#endif
|
|
||||||
|
|
||||||
const char *program = "dnssec-importkey";
|
const char *program = "dnssec-importkey";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
static dns_rdataclass_t rdclass;
|
static dns_rdataclass_t rdclass;
|
||||||
static dns_fixedname_t fixed;
|
static dns_fixedname_t fixed;
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <ctype.h>
|
#include <ctype.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
@@ -48,7 +46,6 @@
|
|||||||
#define MAX_RSA 4096 /* should be long enough... */
|
#define MAX_RSA 4096 /* should be long enough... */
|
||||||
|
|
||||||
const char *program = "dnssec-keyfromlabel";
|
const char *program = "dnssec-keyfromlabel";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||||
@@ -371,8 +368,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
len = strlen(label) + 8;
|
len = strlen(label) + 8;
|
||||||
l = isc_mem_allocate(mctx, len);
|
l = isc_mem_allocate(mctx, len);
|
||||||
if (l == NULL)
|
|
||||||
fatal("cannot allocate memory");
|
|
||||||
snprintf(l, len, "pkcs11:%s", label);
|
snprintf(l, len, "pkcs11:%s", label);
|
||||||
isc_mem_free(mctx, label);
|
isc_mem_free(mctx, label);
|
||||||
label = l;
|
label = l;
|
||||||
|
|||||||
+42
-44
@@ -39,7 +39,7 @@
|
|||||||
dnssec-keygen \- DNSSEC key generation tool
|
dnssec-keygen \- DNSSEC key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
||||||
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
|
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-keygen\fR
|
\fBdnssec\-keygen\fR
|
||||||
@@ -58,6 +58,13 @@ may be preferable to direct use of
|
|||||||
\fBdnssec\-keygen\fR\&.
|
\fBdnssec\-keygen\fR\&.
|
||||||
.SH "OPTIONS"
|
.SH "OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
|
\-3
|
||||||
|
.RS 4
|
||||||
|
Use an NSEC3\-capable algorithm to generate a DNSSEC key\&. If this option is used with an algorithm that has both NSEC and NSEC3 versions, then the NSEC3 version will be used; for example,
|
||||||
|
\fBdnssec\-keygen \-3a RSASHA1\fR
|
||||||
|
specifies the NSEC3RSASHA1 algorithm\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-a \fIalgorithm\fR
|
\-a \fIalgorithm\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
|
||||||
@@ -83,29 +90,14 @@ to generate TSIG keys\&.
|
|||||||
.PP
|
.PP
|
||||||
\-b \fIkeysize\fR
|
\-b \fIkeysize\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the number of bits in the key\&. The choice of key size depends on the algorithm used\&. RSA keys must be between 1024 and 2048 bits\&. Diffie Hellman keys must be between 128 and 4096 bits\&. DSA keys must be between 512 and 1024 bits and an exact multiple of 64\&. HMAC keys must be between 1 and 512 bits\&. Elliptic curve algorithms don\*(Aqt need this parameter\&.
|
Specifies the number of bits in the key\&. The choice of key size depends on the algorithm used\&. RSA keys must be between 1024 and 4096 bits\&. Diffie Hellman keys must be between 128 and 4096 bits\&. Elliptic curve algorithms don\*(Aqt need this parameter\&.
|
||||||
.sp
|
.sp
|
||||||
If the key size is not specified, some algorithms have pre\-defined defaults\&. For example, RSA keys for use as DNSSEC zone signing keys have a default size of 1024 bits; RSA keys for use as key signing keys (KSKs, generated with
|
If the key size is not specified, some algorithms have pre\-defined defaults\&. For instance, RSA keys have a default size of 2048 bits\&.
|
||||||
\fB\-f KSK\fR) default to 2048 bits\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-n \fInametype\fR
|
|
||||||
.RS 4
|
|
||||||
Specifies the owner type of the key\&. The value of
|
|
||||||
\fBnametype\fR
|
|
||||||
must either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with a host (KEY)), USER (for a key associated with a user(KEY)) or OTHER (DNSKEY)\&. These values are case insensitive\&. Defaults to ZONE for DNSKEY generation\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-3
|
|
||||||
.RS 4
|
|
||||||
Use an NSEC3\-capable algorithm to generate a DNSSEC key\&. If this option is used with an algorithm that has both NSEC and NSEC3 versions, then the NSEC3 version will be used; for example,
|
|
||||||
\fBdnssec\-keygen \-3a RSASHA1\fR
|
|
||||||
specifies the NSEC3RSASHA1 algorithm\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-C
|
\-C
|
||||||
.RS 4
|
.RS 4
|
||||||
Compatibility mode: generates an old\-style key, without any metadata\&. By default,
|
Compatibility mode: generates an old\-style key, without any timing metadata\&. By default,
|
||||||
\fBdnssec\-keygen\fR
|
\fBdnssec\-keygen\fR
|
||||||
will include the key\*(Aqs creation date in the metadata stored with the private key, and other dates may be set there as well (publication date, activation date, etc)\&. Keys that include this data may be incompatible with older versions of BIND; the
|
will include the key\*(Aqs creation date in the metadata stored with the private key, and other dates may be set there as well (publication date, activation date, etc)\&. Keys that include this data may be incompatible with older versions of BIND; the
|
||||||
\fB\-C\fR
|
\fB\-C\fR
|
||||||
@@ -150,11 +142,6 @@ Prints a short summary of the options and arguments to
|
|||||||
Sets the directory in which the key files are to be written\&.
|
Sets the directory in which the key files are to be written\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-k
|
|
||||||
.RS 4
|
|
||||||
Deprecated in favor of \-T KEY\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-L \fIttl\fR
|
\-L \fIttl\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
||||||
@@ -164,9 +151,17 @@ none
|
|||||||
is the same as leaving it unset\&.
|
is the same as leaving it unset\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-n \fInametype\fR
|
||||||
|
.RS 4
|
||||||
|
Specifies the owner type of the key\&. The value of
|
||||||
|
\fBnametype\fR
|
||||||
|
must either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with a host (KEY)), USER (for a key associated with a user(KEY)) or OTHER (DNSKEY)\&. These values are case insensitive\&. Defaults to ZONE for DNSKEY generation\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-p \fIprotocol\fR
|
\-p \fIprotocol\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Sets the protocol value for the generated key\&. The protocol is a number between 0 and 255\&. The default is 3 (DNSSEC)\&. Other possible values for this argument are listed in RFC 2535 and its successors\&.
|
Sets the protocol value for the generated key, for use with
|
||||||
|
\fB\-T KEY\fR\&. The protocol is a number between 0 and 255\&. The default is 3 (DNSSEC)\&. Other possible values for this argument are listed in RFC 2535 and its successors\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-q
|
\-q
|
||||||
@@ -193,27 +188,25 @@ Specifies the strength value of the key\&. The strength is a number between 0 an
|
|||||||
Specifies the resource record type to use for the key\&.
|
Specifies the resource record type to use for the key\&.
|
||||||
\fBrrtype\fR
|
\fBrrtype\fR
|
||||||
must be either DNSKEY or KEY\&. The default is DNSKEY when using a DNSSEC algorithm, but it can be overridden to KEY for use with SIG(0)\&.
|
must be either DNSKEY or KEY\&. The default is DNSKEY when using a DNSSEC algorithm, but it can be overridden to KEY for use with SIG(0)\&.
|
||||||
Specifying any TSIG algorithm (HMAC\-* or DH) with
|
|
||||||
\fB\-a\fR
|
|
||||||
forces this option to KEY\&.
|
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-t \fItype\fR
|
\-t \fItype\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Indicates the use of the key\&.
|
Indicates the use of the key, for use with
|
||||||
|
\fB\-T KEY\fR\&.
|
||||||
\fBtype\fR
|
\fBtype\fR
|
||||||
must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF\&. The default is AUTHCONF\&. AUTH refers to the ability to authenticate data, and CONF the ability to encrypt data\&.
|
must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF\&. The default is AUTHCONF\&. AUTH refers to the ability to authenticate data, and CONF the ability to encrypt data\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-v \fIlevel\fR
|
|
||||||
.RS 4
|
|
||||||
Sets the debugging level\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-V
|
\-V
|
||||||
.RS 4
|
.RS 4
|
||||||
Prints version information\&.
|
Prints version information\&.
|
||||||
.RE
|
.RE
|
||||||
|
.PP
|
||||||
|
\-v \fIlevel\fR
|
||||||
|
.RS 4
|
||||||
|
Sets the debugging level\&.
|
||||||
|
.RE
|
||||||
.SH "TIMING OPTIONS"
|
.SH "TIMING OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS\&. If the argument begins with a \*(Aq+\*(Aq or \*(Aq\-\*(Aq, it is interpreted as an offset from the present time\&. For convenience, if such an offset is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the offset is computed in years (defined as 365 24\-hour days, ignoring leap years), months (defined as 30 24\-hour days), weeks, days, hours, or minutes, respectively\&. Without a suffix, the offset is computed in seconds\&. To explicitly prevent a date from being set, use \*(Aqnone\*(Aq or \*(Aqnever\*(Aq\&.
|
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS\&. If the argument begins with a \*(Aq+\*(Aq or \*(Aq\-\*(Aq, it is interpreted as an offset from the present time\&. For convenience, if such an offset is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the offset is computed in years (defined as 365 24\-hour days, ignoring leap years), months (defined as 30 24\-hour days), weeks, days, hours, or minutes, respectively\&. Without a suffix, the offset is computed in seconds\&. To explicitly prevent a date from being set, use \*(Aqnone\*(Aq or \*(Aqnever\*(Aq\&.
|
||||||
@@ -314,23 +307,24 @@ contains the private key\&.
|
|||||||
.PP
|
.PP
|
||||||
The
|
The
|
||||||
\&.key
|
\&.key
|
||||||
file contains a DNS KEY record that can be inserted into a zone file (directly or with a $INCLUDE statement)\&.
|
file contains a DNSKEY or KEY record\&. When a zone is being signed by
|
||||||
|
\fBnamed\fR
|
||||||
|
or
|
||||||
|
\fBdnssec\-signzone\fR\fB\-S\fR, DNSKEY records are included automatically\&. In other cases, the
|
||||||
|
\&.key
|
||||||
|
file can be inserted into a zone file manually or with a
|
||||||
|
\fB$INCLUDE\fR
|
||||||
|
statement\&.
|
||||||
.PP
|
.PP
|
||||||
The
|
The
|
||||||
\&.private
|
\&.private
|
||||||
file contains algorithm\-specific fields\&. For obvious security reasons, this file does not have general read permission\&.
|
file contains algorithm\-specific fields\&. For obvious security reasons, this file does not have general read permission\&.
|
||||||
.PP
|
|
||||||
Both
|
|
||||||
\&.key
|
|
||||||
and
|
|
||||||
\&.private
|
|
||||||
files are generated for symmetric cryptography algorithms such as HMAC\-MD5, even though the public and private key are equivalent\&.
|
|
||||||
.SH "EXAMPLE"
|
.SH "EXAMPLE"
|
||||||
.PP
|
.PP
|
||||||
To generate an ECDSAP256SHA256 key for the domain
|
To generate an ECDSAP256SHA256 zone\-signing key for the zone
|
||||||
\fBexample\&.com\fR, the following command would be issued:
|
\fBexample\&.com\fR, issue the command:
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-keygen \-a ECDSAP256SHA256 \-n ZONE example\&.com\fR
|
\fBdnssec\-keygen \-a ECDSAP256SHA256 example\&.com\fR
|
||||||
.PP
|
.PP
|
||||||
The command would print a string of the form:
|
The command would print a string of the form:
|
||||||
.PP
|
.PP
|
||||||
@@ -342,6 +336,10 @@ creates the files
|
|||||||
Kexample\&.com\&.+013+26160\&.key
|
Kexample\&.com\&.+013+26160\&.key
|
||||||
and
|
and
|
||||||
Kexample\&.com\&.+013+26160\&.private\&.
|
Kexample\&.com\&.+013+26160\&.private\&.
|
||||||
|
.PP
|
||||||
|
To generate a matching key\-signing key, issue the command:
|
||||||
|
.PP
|
||||||
|
\fBdnssec\-keygen \-a ECDSAP256SHA256 \-f KSK example\&.com\fR
|
||||||
.SH "SEE ALSO"
|
.SH "SEE ALSO"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec-signzone\fR(8),
|
\fBdnssec-signzone\fR(8),
|
||||||
|
|||||||
@@ -25,8 +25,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <ctype.h>
|
#include <ctype.h>
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
@@ -63,7 +61,6 @@
|
|||||||
#define MAX_RSA 4096 /* should be long enough... */
|
#define MAX_RSA 4096 /* should be long enough... */
|
||||||
|
|
||||||
const char *program = "dnssec-keygen";
|
const char *program = "dnssec-keygen";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
usage(void) ISC_PLATFORM_NORETURN_POST;
|
usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||||
@@ -221,7 +218,6 @@ main(int argc, char **argv) {
|
|||||||
bool unsetrev = false, unsetinact = false;
|
bool unsetrev = false, unsetinact = false;
|
||||||
bool unsetdel = false;
|
bool unsetdel = false;
|
||||||
bool genonly = false;
|
bool genonly = false;
|
||||||
bool quiet = false;
|
|
||||||
bool show_progress = false;
|
bool show_progress = false;
|
||||||
unsigned char c;
|
unsigned char c;
|
||||||
isc_stdtime_t syncadd = 0, syncdel = 0;
|
isc_stdtime_t syncadd = 0, syncdel = 0;
|
||||||
@@ -241,7 +237,7 @@ main(int argc, char **argv) {
|
|||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
*/
|
*/
|
||||||
#define CMDLINE_FLAGS "3A:a:b:Cc:D:d:E:eFf:Gg:hI:i:K:kL:m:n:P:p:qR:r:S:s:T:t:" \
|
#define CMDLINE_FLAGS "3A:a:b:Cc:D:d:E:eFf:Gg:hI:i:K:L:m:n:P:p:qR:r:S:s:T:t:" \
|
||||||
"v:V"
|
"v:V"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
@@ -322,11 +318,6 @@ main(int argc, char **argv) {
|
|||||||
fatal("cannot open directory %s: %s",
|
fatal("cannot open directory %s: %s",
|
||||||
directory, isc_result_totext(ret));
|
directory, isc_result_totext(ret));
|
||||||
break;
|
break;
|
||||||
case 'k':
|
|
||||||
fatal("The -k option has been deprecated.\n"
|
|
||||||
"To generate a key-signing key, use -f KSK.\n"
|
|
||||||
"To generate a key with TYPE=KEY, use -T KEY.\n");
|
|
||||||
break;
|
|
||||||
case 'L':
|
case 'L':
|
||||||
ttl = strtottl(isc_commandline_argument);
|
ttl = strtottl(isc_commandline_argument);
|
||||||
setttl = true;
|
setttl = true;
|
||||||
@@ -562,11 +553,7 @@ main(int argc, char **argv) {
|
|||||||
case DST_ALG_NSEC3RSASHA1:
|
case DST_ALG_NSEC3RSASHA1:
|
||||||
case DST_ALG_RSASHA256:
|
case DST_ALG_RSASHA256:
|
||||||
case DST_ALG_RSASHA512:
|
case DST_ALG_RSASHA512:
|
||||||
if ((kskflag & DNS_KEYFLAG_KSK) != 0) {
|
size = 2048;
|
||||||
size = 2048;
|
|
||||||
} else {
|
|
||||||
size = 1024;
|
|
||||||
}
|
|
||||||
if (verbose > 0) {
|
if (verbose > 0) {
|
||||||
fprintf(stderr, "key size not "
|
fprintf(stderr, "key size not "
|
||||||
"specified; defaulting"
|
"specified; defaulting"
|
||||||
|
|||||||
@@ -58,11 +58,10 @@
|
|||||||
<refsynopsisdiv>
|
<refsynopsisdiv>
|
||||||
<cmdsynopsis sepchar=" ">
|
<cmdsynopsis sepchar=" ">
|
||||||
<command>dnssec-keygen</command>
|
<command>dnssec-keygen</command>
|
||||||
<arg rep="norepeat"><option>-a <replaceable class="parameter">algorithm</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-b <replaceable class="parameter">keysize</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
|
|
||||||
<arg choice="opt" rep="norepeat"><option>-3</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-3</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-A <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-A <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
|
<arg rep="norepeat"><option>-a <replaceable class="parameter">algorithm</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-b <replaceable class="parameter">keysize</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-C</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-C</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
@@ -77,6 +76,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-k</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-k</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
|
||||||
@@ -87,7 +87,6 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-z</option></arg>
|
|
||||||
<arg choice="req" rep="norepeat">name</arg>
|
<arg choice="req" rep="norepeat">name</arg>
|
||||||
</cmdsynopsis>
|
</cmdsynopsis>
|
||||||
</refsynopsisdiv>
|
</refsynopsisdiv>
|
||||||
@@ -118,6 +117,20 @@
|
|||||||
|
|
||||||
|
|
||||||
<variablelist>
|
<variablelist>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-3</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Use an NSEC3-capable algorithm to generate a DNSSEC key.
|
||||||
|
If this option is used with an algorithm that has both
|
||||||
|
NSEC and NSEC3 versions, then the NSEC3 version will be
|
||||||
|
used; for example, <command>dnssec-keygen -3a RSASHA1</command>
|
||||||
|
specifies the NSEC3RSASHA1 algorithm.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-a <replaceable class="parameter">algorithm</replaceable></term>
|
<term>-a <replaceable class="parameter">algorithm</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -157,45 +170,14 @@
|
|||||||
<para>
|
<para>
|
||||||
Specifies the number of bits in the key. The choice of key
|
Specifies the number of bits in the key. The choice of key
|
||||||
size depends on the algorithm used. RSA keys must be
|
size depends on the algorithm used. RSA keys must be
|
||||||
between 1024 and 2048 bits. Diffie Hellman keys must be between
|
between 1024 and 4096 bits. Diffie Hellman keys must be between
|
||||||
128 and 4096 bits. DSA keys must be between 512 and 1024
|
128 and 4096 bits. Elliptic curve algorithms don't need this
|
||||||
bits and an exact multiple of 64. HMAC keys must be
|
parameter.
|
||||||
between 1 and 512 bits. Elliptic curve algorithms don't need
|
|
||||||
this parameter.
|
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
If the key size is not specified, some algorithms have
|
If the key size is not specified, some algorithms have
|
||||||
pre-defined defaults. For example, RSA keys for use as
|
pre-defined defaults. For instance, RSA keys have a default
|
||||||
DNSSEC zone signing keys have a default size of 1024 bits;
|
size of 2048 bits.
|
||||||
RSA keys for use as key signing keys (KSKs, generated with
|
|
||||||
<option>-f KSK</option>) default to 2048 bits.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-n <replaceable class="parameter">nametype</replaceable></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Specifies the owner type of the key. The value of
|
|
||||||
<option>nametype</option> must either be ZONE (for a DNSSEC
|
|
||||||
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
|
|
||||||
with a host (KEY)), USER (for a key associated with a
|
|
||||||
user(KEY)) or OTHER (DNSKEY). These values are case
|
|
||||||
insensitive. Defaults to ZONE for DNSKEY generation.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-3</term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Use an NSEC3-capable algorithm to generate a DNSSEC key.
|
|
||||||
If this option is used with an algorithm that has both
|
|
||||||
NSEC and NSEC3 versions, then the NSEC3 version will be
|
|
||||||
used; for example, <command>dnssec-keygen -3a RSASHA1</command>
|
|
||||||
specifies the NSEC3RSASHA1 algorithm.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -204,12 +186,12 @@
|
|||||||
<term>-C</term>
|
<term>-C</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Compatibility mode: generates an old-style key, without
|
Compatibility mode: generates an old-style key, without any
|
||||||
any metadata. By default, <command>dnssec-keygen</command>
|
timing metadata. By default, <command>dnssec-keygen</command>
|
||||||
will include the key's creation date in the metadata stored
|
will include the key's creation date in the metadata stored with
|
||||||
with the private key, and other dates may be set there as well
|
the private key, and other dates may be set there as well
|
||||||
(publication date, activation date, etc). Keys that include
|
(publication date, activation date, etc). Keys that include this
|
||||||
this data may be incompatible with older versions of BIND; the
|
data may be incompatible with older versions of BIND; the
|
||||||
<option>-C</option> option suppresses them.
|
<option>-C</option> option suppresses them.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -293,15 +275,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-k</term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Deprecated in favor of -T KEY.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-L <replaceable class="parameter">ttl</replaceable></term>
|
<term>-L <replaceable class="parameter">ttl</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -318,14 +291,28 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-n <replaceable class="parameter">nametype</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Specifies the owner type of the key. The value of
|
||||||
|
<option>nametype</option> must either be ZONE (for a DNSSEC
|
||||||
|
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
|
||||||
|
with a host (KEY)), USER (for a key associated with a
|
||||||
|
user(KEY)) or OTHER (DNSKEY). These values are case
|
||||||
|
insensitive. Defaults to ZONE for DNSKEY generation.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-p <replaceable class="parameter">protocol</replaceable></term>
|
<term>-p <replaceable class="parameter">protocol</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Sets the protocol value for the generated key. The protocol
|
Sets the protocol value for the generated key, for use
|
||||||
is a number between 0 and 255. The default is 3 (DNSSEC).
|
with <option>-T KEY</option>. The protocol is a number between 0
|
||||||
Other possible values for this argument are listed in
|
and 255. The default is 3 (DNSSEC). Other possible values for
|
||||||
RFC 2535 and its successors.
|
this argument are listed in RFC 2535 and its successors.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -383,10 +370,6 @@
|
|||||||
<option>rrtype</option> must be either DNSKEY or KEY. The
|
<option>rrtype</option> must be either DNSKEY or KEY. The
|
||||||
default is DNSKEY when using a DNSSEC algorithm, but it can be
|
default is DNSKEY when using a DNSSEC algorithm, but it can be
|
||||||
overridden to KEY for use with SIG(0).
|
overridden to KEY for use with SIG(0).
|
||||||
<para>
|
|
||||||
</para>
|
|
||||||
Specifying any TSIG algorithm (HMAC-* or DH) with
|
|
||||||
<option>-a</option> forces this option to KEY.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -395,19 +378,11 @@
|
|||||||
<term>-t <replaceable class="parameter">type</replaceable></term>
|
<term>-t <replaceable class="parameter">type</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Indicates the use of the key. <option>type</option> must be
|
Indicates the use of the key, for use with <option>-T
|
||||||
one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
KEY</option>. <option>type</option> must be one of AUTHCONF,
|
||||||
is AUTHCONF. AUTH refers to the ability to authenticate
|
NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH
|
||||||
data, and CONF the ability to encrypt data.
|
refers to the ability to authenticate data, and CONF the ability
|
||||||
</para>
|
to encrypt data.
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-v <replaceable class="parameter">level</replaceable></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Sets the debugging level.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -421,6 +396,15 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-v <replaceable class="parameter">level</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Sets the debugging level.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
</variablelist>
|
</variablelist>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
@@ -585,10 +569,12 @@
|
|||||||
key.
|
key.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
The <filename>.key</filename> file contains a DNS KEY record
|
The <filename>.key</filename> file contains a DNSKEY or KEY record.
|
||||||
that
|
When a zone is being signed by <command>named</command>
|
||||||
can be inserted into a zone file (directly or with a $INCLUDE
|
or <command>dnssec-signzone</command> <option>-S</option>, DNSKEY
|
||||||
statement).
|
records are included automatically. In other cases,
|
||||||
|
the <filename>.key</filename> file can be inserted into a zone file
|
||||||
|
manually or with a <userinput>$INCLUDE</userinput> statement.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
The <filename>.private</filename> file contains
|
The <filename>.private</filename> file contains
|
||||||
@@ -596,21 +582,16 @@
|
|||||||
fields. For obvious security reasons, this file does not have
|
fields. For obvious security reasons, this file does not have
|
||||||
general read permission.
|
general read permission.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
|
||||||
Both <filename>.key</filename> and <filename>.private</filename>
|
|
||||||
files are generated for symmetric cryptography algorithms such as
|
|
||||||
HMAC-MD5, even though the public and private key are equivalent.
|
|
||||||
</para>
|
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>EXAMPLE</title></info>
|
<refsection><info><title>EXAMPLE</title></info>
|
||||||
|
|
||||||
<para>
|
<para>
|
||||||
To generate an ECDSAP256SHA256 key for the domain
|
To generate an ECDSAP256SHA256 zone-signing key for the zone
|
||||||
<userinput>example.com</userinput>, the following command would be
|
<userinput>example.com</userinput>, issue the command:
|
||||||
issued:
|
|
||||||
</para>
|
</para>
|
||||||
<para><userinput>dnssec-keygen -a ECDSAP256SHA256 -n ZONE example.com</userinput>
|
<para>
|
||||||
|
<userinput>dnssec-keygen -a ECDSAP256SHA256 example.com</userinput>
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
The command would print a string of the form:
|
The command would print a string of the form:
|
||||||
@@ -623,6 +604,12 @@
|
|||||||
and
|
and
|
||||||
<filename>Kexample.com.+013+26160.private</filename>.
|
<filename>Kexample.com.+013+26160.private</filename>.
|
||||||
</para>
|
</para>
|
||||||
|
<para>
|
||||||
|
To generate a matching key-signing key, issue the command:
|
||||||
|
</para>
|
||||||
|
<para>
|
||||||
|
<userinput>dnssec-keygen -a ECDSAP256SHA256 -f KSK example.com</userinput>
|
||||||
|
</para>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>SEE ALSO</title></info>
|
<refsection><info><title>SEE ALSO</title></info>
|
||||||
|
|||||||
@@ -33,11 +33,10 @@
|
|||||||
<h2>Synopsis</h2>
|
<h2>Synopsis</h2>
|
||||||
<div class="cmdsynopsis"><p>
|
<div class="cmdsynopsis"><p>
|
||||||
<code class="command">dnssec-keygen</code>
|
<code class="command">dnssec-keygen</code>
|
||||||
[<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
|
|
||||||
[<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
|
|
||||||
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
|
||||||
[<code class="option">-3</code>]
|
[<code class="option">-3</code>]
|
||||||
[<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
|
||||||
|
[<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
|
||||||
[<code class="option">-C</code>]
|
[<code class="option">-C</code>]
|
||||||
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
||||||
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
@@ -52,6 +51,7 @@
|
|||||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||||
[<code class="option">-k</code>]
|
[<code class="option">-k</code>]
|
||||||
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
||||||
|
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
||||||
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
|
[<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
|
||||||
@@ -62,7 +62,6 @@
|
|||||||
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
[<code class="option">-z</code>]
|
|
||||||
{name}
|
{name}
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
@@ -95,6 +94,16 @@
|
|||||||
|
|
||||||
|
|
||||||
<div class="variablelist"><dl class="variablelist">
|
<div class="variablelist"><dl class="variablelist">
|
||||||
|
<dt><span class="term">-3</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Use an NSEC3-capable algorithm to generate a DNSSEC key.
|
||||||
|
If this option is used with an algorithm that has both
|
||||||
|
NSEC and NSEC3 versions, then the NSEC3 version will be
|
||||||
|
used; for example, <span class="command"><strong>dnssec-keygen -3a RSASHA1</strong></span>
|
||||||
|
specifies the NSEC3RSASHA1 algorithm.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -130,50 +139,25 @@
|
|||||||
<p>
|
<p>
|
||||||
Specifies the number of bits in the key. The choice of key
|
Specifies the number of bits in the key. The choice of key
|
||||||
size depends on the algorithm used. RSA keys must be
|
size depends on the algorithm used. RSA keys must be
|
||||||
between 1024 and 2048 bits. Diffie Hellman keys must be between
|
between 1024 and 4096 bits. Diffie Hellman keys must be between
|
||||||
128 and 4096 bits. DSA keys must be between 512 and 1024
|
128 and 4096 bits. Elliptic curve algorithms don't need this
|
||||||
bits and an exact multiple of 64. HMAC keys must be
|
parameter.
|
||||||
between 1 and 512 bits. Elliptic curve algorithms don't need
|
|
||||||
this parameter.
|
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
If the key size is not specified, some algorithms have
|
If the key size is not specified, some algorithms have
|
||||||
pre-defined defaults. For example, RSA keys for use as
|
pre-defined defaults. For instance, RSA keys have a default
|
||||||
DNSSEC zone signing keys have a default size of 1024 bits;
|
size of 2048 bits.
|
||||||
RSA keys for use as key signing keys (KSKs, generated with
|
|
||||||
<code class="option">-f KSK</code>) default to 2048 bits.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Specifies the owner type of the key. The value of
|
|
||||||
<code class="option">nametype</code> must either be ZONE (for a DNSSEC
|
|
||||||
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
|
|
||||||
with a host (KEY)), USER (for a key associated with a
|
|
||||||
user(KEY)) or OTHER (DNSKEY). These values are case
|
|
||||||
insensitive. Defaults to ZONE for DNSKEY generation.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-3</span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Use an NSEC3-capable algorithm to generate a DNSSEC key.
|
|
||||||
If this option is used with an algorithm that has both
|
|
||||||
NSEC and NSEC3 versions, then the NSEC3 version will be
|
|
||||||
used; for example, <span class="command"><strong>dnssec-keygen -3a RSASHA1</strong></span>
|
|
||||||
specifies the NSEC3RSASHA1 algorithm.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-C</span></dt>
|
<dt><span class="term">-C</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Compatibility mode: generates an old-style key, without
|
Compatibility mode: generates an old-style key, without any
|
||||||
any metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
|
timing metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
|
||||||
will include the key's creation date in the metadata stored
|
will include the key's creation date in the metadata stored with
|
||||||
with the private key, and other dates may be set there as well
|
the private key, and other dates may be set there as well
|
||||||
(publication date, activation date, etc). Keys that include
|
(publication date, activation date, etc). Keys that include this
|
||||||
this data may be incompatible with older versions of BIND; the
|
data may be incompatible with older versions of BIND; the
|
||||||
<code class="option">-C</code> option suppresses them.
|
<code class="option">-C</code> option suppresses them.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
@@ -234,12 +218,6 @@
|
|||||||
Sets the directory in which the key files are to be written.
|
Sets the directory in which the key files are to be written.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-k</span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Deprecated in favor of -T KEY.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -253,13 +231,24 @@
|
|||||||
or <code class="literal">none</code> is the same as leaving it unset.
|
or <code class="literal">none</code> is the same as leaving it unset.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Specifies the owner type of the key. The value of
|
||||||
|
<code class="option">nametype</code> must either be ZONE (for a DNSSEC
|
||||||
|
zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
|
||||||
|
with a host (KEY)), USER (for a key associated with a
|
||||||
|
user(KEY)) or OTHER (DNSKEY). These values are case
|
||||||
|
insensitive. Defaults to ZONE for DNSKEY generation.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
|
<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Sets the protocol value for the generated key. The protocol
|
Sets the protocol value for the generated key, for use
|
||||||
is a number between 0 and 255. The default is 3 (DNSSEC).
|
with <code class="option">-T KEY</code>. The protocol is a number between 0
|
||||||
Other possible values for this argument are listed in
|
and 255. The default is 3 (DNSSEC). Other possible values for
|
||||||
RFC 2535 and its successors.
|
this argument are listed in RFC 2535 and its successors.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-q</span></dt>
|
<dt><span class="term">-q</span></dt>
|
||||||
@@ -306,26 +295,15 @@
|
|||||||
default is DNSKEY when using a DNSSEC algorithm, but it can be
|
default is DNSKEY when using a DNSSEC algorithm, but it can be
|
||||||
overridden to KEY for use with SIG(0).
|
overridden to KEY for use with SIG(0).
|
||||||
</p>
|
</p>
|
||||||
<p>
|
|
||||||
</p>
|
|
||||||
<p>
|
|
||||||
Specifying any TSIG algorithm (HMAC-* or DH) with
|
|
||||||
<code class="option">-a</code> forces this option to KEY.
|
|
||||||
</p>
|
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
|
<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
Indicates the use of the key. <code class="option">type</code> must be
|
Indicates the use of the key, for use with <code class="option">-T
|
||||||
one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
KEY</code>. <code class="option">type</code> must be one of AUTHCONF,
|
||||||
is AUTHCONF. AUTH refers to the ability to authenticate
|
NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH
|
||||||
data, and CONF the ability to encrypt data.
|
refers to the ability to authenticate data, and CONF the ability
|
||||||
</p>
|
to encrypt data.
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Sets the debugging level.
|
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-V</span></dt>
|
<dt><span class="term">-V</span></dt>
|
||||||
@@ -334,6 +312,12 @@
|
|||||||
Prints version information.
|
Prints version information.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Sets the debugging level.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
</dl></div>
|
</dl></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -476,10 +460,12 @@
|
|||||||
key.
|
key.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
The <code class="filename">.key</code> file contains a DNS KEY record
|
The <code class="filename">.key</code> file contains a DNSKEY or KEY record.
|
||||||
that
|
When a zone is being signed by <span class="command"><strong>named</strong></span>
|
||||||
can be inserted into a zone file (directly or with a $INCLUDE
|
or <span class="command"><strong>dnssec-signzone</strong></span> <code class="option">-S</code>, DNSKEY
|
||||||
statement).
|
records are included automatically. In other cases,
|
||||||
|
the <code class="filename">.key</code> file can be inserted into a zone file
|
||||||
|
manually or with a <strong class="userinput"><code>$INCLUDE</code></strong> statement.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
The <code class="filename">.private</code> file contains
|
The <code class="filename">.private</code> file contains
|
||||||
@@ -487,22 +473,17 @@
|
|||||||
fields. For obvious security reasons, this file does not have
|
fields. For obvious security reasons, this file does not have
|
||||||
general read permission.
|
general read permission.
|
||||||
</p>
|
</p>
|
||||||
<p>
|
|
||||||
Both <code class="filename">.key</code> and <code class="filename">.private</code>
|
|
||||||
files are generated for symmetric cryptography algorithms such as
|
|
||||||
HMAC-MD5, even though the public and private key are equivalent.
|
|
||||||
</p>
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.11"></a><h2>EXAMPLE</h2>
|
<a name="id-1.11"></a><h2>EXAMPLE</h2>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
To generate an ECDSAP256SHA256 key for the domain
|
To generate an ECDSAP256SHA256 zone-signing key for the zone
|
||||||
<strong class="userinput"><code>example.com</code></strong>, the following command would be
|
<strong class="userinput"><code>example.com</code></strong>, issue the command:
|
||||||
issued:
|
|
||||||
</p>
|
</p>
|
||||||
<p><strong class="userinput"><code>dnssec-keygen -a ECDSAP256SHA256 -n ZONE example.com</code></strong>
|
<p>
|
||||||
|
<strong class="userinput"><code>dnssec-keygen -a ECDSAP256SHA256 example.com</code></strong>
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
The command would print a string of the form:
|
The command would print a string of the form:
|
||||||
@@ -515,6 +496,12 @@
|
|||||||
and
|
and
|
||||||
<code class="filename">Kexample.com.+013+26160.private</code>.
|
<code class="filename">Kexample.com.+013+26160.private</code>.
|
||||||
</p>
|
</p>
|
||||||
|
<p>
|
||||||
|
To generate a matching key-signing key, issue the command:
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
<strong class="userinput"><code>dnssec-keygen -a ECDSAP256SHA256 -f KSK example.com</code></strong>
|
||||||
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -39,7 +37,6 @@
|
|||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
const char *program = "dnssec-revoke";
|
const char *program = "dnssec-revoke";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
|
||||||
@@ -116,10 +113,6 @@ main(int argc, char **argv) {
|
|||||||
* simplify cleanup later
|
* simplify cleanup later
|
||||||
*/
|
*/
|
||||||
dir = isc_mem_strdup(mctx, isc_commandline_argument);
|
dir = isc_mem_strdup(mctx, isc_commandline_argument);
|
||||||
if (dir == NULL) {
|
|
||||||
fatal("Failed to allocate memory for "
|
|
||||||
"directory");
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
removefile = true;
|
removefile = true;
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -42,7 +40,6 @@
|
|||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
const char *program = "dnssec-settime";
|
const char *program = "dnssec-settime";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
|
|
||||||
@@ -256,10 +253,6 @@ main(int argc, char **argv) {
|
|||||||
*/
|
*/
|
||||||
directory = isc_mem_strdup(mctx,
|
directory = isc_mem_strdup(mctx,
|
||||||
isc_commandline_argument);
|
isc_commandline_argument);
|
||||||
if (directory == NULL) {
|
|
||||||
fatal("Failed to allocate memory for "
|
|
||||||
"directory");
|
|
||||||
}
|
|
||||||
break;
|
break;
|
||||||
case 'L':
|
case 'L':
|
||||||
ttl = strtottl(isc_commandline_argument);
|
ttl = strtottl(isc_commandline_argument);
|
||||||
|
|||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-signzone \- DNSSEC zone signing tool
|
dnssec-signzone \- DNSSEC zone signing tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-signzone\fR\ 'u
|
.HP \w'\fBdnssec\-signzone\fR\ 'u
|
||||||
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-M\ \fR\fB\fImaxttl\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-Q\fR] [\fB\-R\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-M\ \fR\fB\fImaxttl\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-Q\fR] [\fB\-q\fR] [\fB\-R\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-signzone\fR
|
\fBdnssec\-signzone\fR
|
||||||
@@ -113,11 +113,6 @@ Key repository: Specify a directory to search for DNSSEC keys\&. If not specifie
|
|||||||
Treat specified key as a key signing key ignoring any key flags\&. This option may be specified multiple times\&.
|
Treat specified key as a key signing key ignoring any key flags\&. This option may be specified multiple times\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
\-l \fIdomain\fR
|
|
||||||
.RS 4
|
|
||||||
Generate a DLV set in addition to the key (DNSKEY) and DS sets\&. The domain is appended to the name of the records\&.
|
|
||||||
.RE
|
|
||||||
.PP
|
|
||||||
\-M \fImaxttl\fR
|
\-M \fImaxttl\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Sets the maximum TTL for the signed zone\&. Any TTL higher than
|
Sets the maximum TTL for the signed zone\&. Any TTL higher than
|
||||||
@@ -296,6 +291,13 @@ forces
|
|||||||
to remove signatures from keys that are no longer active\&. This enables ZSK rollover using the procedure described in RFC 4641, section 4\&.2\&.1\&.1 ("Pre\-Publish Key Rollover")\&.
|
to remove signatures from keys that are no longer active\&. This enables ZSK rollover using the procedure described in RFC 4641, section 4\&.2\&.1\&.1 ("Pre\-Publish Key Rollover")\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-q
|
||||||
|
.RS 4
|
||||||
|
Quiet mode: Suppresses unnecessary output\&. Without this option, when
|
||||||
|
\fBdnssec\-signzone\fR
|
||||||
|
is run it will print to standard output the number of keys in use, the algorithms used to verify the zone was signed correctly and other status information, and finally the filename containing the signed zone\&. With it, that output is suppressed, leaving only the filename\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-R
|
\-R
|
||||||
.RS 4
|
.RS 4
|
||||||
Remove signatures from keys that are no longer published\&.
|
Remove signatures from keys that are no longer published\&.
|
||||||
|
|||||||
@@ -25,8 +25,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -34,6 +32,7 @@
|
|||||||
#include <unistd.h>
|
#include <unistd.h>
|
||||||
|
|
||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
|
#include <isc/atomic.h>
|
||||||
#include <isc/base32.h>
|
#include <isc/base32.h>
|
||||||
#include <isc/commandline.h>
|
#include <isc/commandline.h>
|
||||||
#include <isc/event.h>
|
#include <isc/event.h>
|
||||||
@@ -47,8 +46,8 @@
|
|||||||
#include <isc/print.h>
|
#include <isc/print.h>
|
||||||
#include <isc/random.h>
|
#include <isc/random.h>
|
||||||
#include <isc/rwlock.h>
|
#include <isc/rwlock.h>
|
||||||
#include <isc/serial.h>
|
|
||||||
#include <isc/safe.h>
|
#include <isc/safe.h>
|
||||||
|
#include <isc/serial.h>
|
||||||
#include <isc/stdio.h>
|
#include <isc/stdio.h>
|
||||||
#include <isc/string.h>
|
#include <isc/string.h>
|
||||||
#include <isc/task.h>
|
#include <isc/task.h>
|
||||||
@@ -88,12 +87,7 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
#ifndef PATH_MAX
|
|
||||||
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
|
||||||
#endif
|
|
||||||
|
|
||||||
const char *program = "dnssec-signzone";
|
const char *program = "dnssec-signzone";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
typedef struct hashlist hashlist_t;
|
typedef struct hashlist hashlist_t;
|
||||||
|
|
||||||
@@ -162,14 +156,13 @@ static unsigned char *gsalt = saltbuf;
|
|||||||
static size_t salt_length = 0;
|
static size_t salt_length = 0;
|
||||||
static isc_task_t *master = NULL;
|
static isc_task_t *master = NULL;
|
||||||
static unsigned int ntasks = 0;
|
static unsigned int ntasks = 0;
|
||||||
static bool shuttingdown = false, finished = false;
|
static atomic_bool shuttingdown;
|
||||||
|
static atomic_bool finished;
|
||||||
static bool nokeys = false;
|
static bool nokeys = false;
|
||||||
static bool removefile = false;
|
static bool removefile = false;
|
||||||
static bool generateds = false;
|
static bool generateds = false;
|
||||||
static bool ignore_kskflag = false;
|
static bool ignore_kskflag = false;
|
||||||
static bool keyset_kskonly = false;
|
static bool keyset_kskonly = false;
|
||||||
static dns_name_t *dlv = NULL;
|
|
||||||
static dns_fixedname_t dlv_fixed;
|
|
||||||
static dns_master_style_t *dsstyle = NULL;
|
static dns_master_style_t *dsstyle = NULL;
|
||||||
static unsigned int serialformat = SOA_SERIAL_KEEP;
|
static unsigned int serialformat = SOA_SERIAL_KEEP;
|
||||||
static unsigned int hash_length = 0;
|
static unsigned int hash_length = 0;
|
||||||
@@ -994,16 +987,6 @@ loadds(dns_name_t *name, uint32_t ttl, dns_rdataset_t *dsset) {
|
|||||||
dns_rdata_init(&key);
|
dns_rdata_init(&key);
|
||||||
dns_rdata_init(&ds);
|
dns_rdata_init(&ds);
|
||||||
dns_rdataset_current(&keyset, &key);
|
dns_rdataset_current(&keyset, &key);
|
||||||
result = dns_ds_buildrdata(name, &key, DNS_DSDIGEST_SHA1,
|
|
||||||
dsbuf, &ds);
|
|
||||||
check_result(result, "dns_ds_buildrdata");
|
|
||||||
|
|
||||||
result = dns_difftuple_create(mctx, DNS_DIFFOP_ADDRESIGN, name,
|
|
||||||
ttl, &ds, &tuple);
|
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(&diff, &tuple);
|
|
||||||
|
|
||||||
dns_rdata_reset(&ds);
|
|
||||||
result = dns_ds_buildrdata(name, &key, DNS_DSDIGEST_SHA256,
|
result = dns_ds_buildrdata(name, &key, DNS_DSDIGEST_SHA256,
|
||||||
dsbuf, &ds);
|
dsbuf, &ds);
|
||||||
check_result(result, "dns_ds_buildrdata");
|
check_result(result, "dns_ds_buildrdata");
|
||||||
@@ -1471,11 +1454,12 @@ signapex(void) {
|
|||||||
cleannode(gdb, gversion, node);
|
cleannode(gdb, gversion, node);
|
||||||
dns_db_detachnode(gdb, &node);
|
dns_db_detachnode(gdb, &node);
|
||||||
result = dns_dbiterator_first(gdbiter);
|
result = dns_dbiterator_first(gdbiter);
|
||||||
if (result == ISC_R_NOMORE)
|
if (result == ISC_R_NOMORE) {
|
||||||
finished = true;
|
atomic_store(&finished, true);
|
||||||
else if (result != ISC_R_SUCCESS)
|
} else if (result != ISC_R_SUCCESS) {
|
||||||
fatal("failure iterating database: %s",
|
fatal("failure iterating database: %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -1495,11 +1479,12 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|||||||
static dns_fixedname_t fzonecut; /* Protected by namelock. */
|
static dns_fixedname_t fzonecut; /* Protected by namelock. */
|
||||||
static unsigned int ended = 0; /* Protected by namelock. */
|
static unsigned int ended = 0; /* Protected by namelock. */
|
||||||
|
|
||||||
if (shuttingdown)
|
if (atomic_load(&shuttingdown)) {
|
||||||
return;
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
LOCK(&namelock);
|
LOCK(&namelock);
|
||||||
if (finished) {
|
if (atomic_load(&finished)) {
|
||||||
ended++;
|
ended++;
|
||||||
if (ended == ntasks) {
|
if (ended == ntasks) {
|
||||||
isc_task_detach(&task);
|
isc_task_detach(&task);
|
||||||
@@ -1509,8 +1494,6 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fname = isc_mem_get(mctx, sizeof(dns_fixedname_t));
|
fname = isc_mem_get(mctx, sizeof(dns_fixedname_t));
|
||||||
if (fname == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
name = dns_fixedname_initname(fname);
|
name = dns_fixedname_initname(fname);
|
||||||
node = NULL;
|
node = NULL;
|
||||||
found = false;
|
found = false;
|
||||||
@@ -1569,7 +1552,7 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|||||||
next:
|
next:
|
||||||
result = dns_dbiterator_next(gdbiter);
|
result = dns_dbiterator_next(gdbiter);
|
||||||
if (result == ISC_R_NOMORE) {
|
if (result == ISC_R_NOMORE) {
|
||||||
finished = true;
|
atomic_store(&finished, true);
|
||||||
break;
|
break;
|
||||||
} else if (result != ISC_R_SUCCESS)
|
} else if (result != ISC_R_SUCCESS)
|
||||||
fatal("failure iterating database: %s",
|
fatal("failure iterating database: %s",
|
||||||
@@ -2660,11 +2643,13 @@ loadexplicitkeys(char *keyfiles[], int n, bool setksk) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
report(const char *format, ...) {
|
report(const char *format, ...) {
|
||||||
va_list args;
|
if (!quiet) {
|
||||||
va_start(args, format);
|
FILE *out = output_stdout ? stderr : stdout;
|
||||||
vfprintf(stderr, format, args);
|
va_list args;
|
||||||
va_end(args);
|
va_start(args, format);
|
||||||
putc('\n', stderr);
|
vfprintf(out, format, args);
|
||||||
|
va_end(args);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -2919,7 +2904,6 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
dns_dbversion_t *dbversion = NULL;
|
dns_dbversion_t *dbversion = NULL;
|
||||||
dns_diff_t diff;
|
dns_diff_t diff;
|
||||||
dns_difftuple_t *tuple = NULL;
|
dns_difftuple_t *tuple = NULL;
|
||||||
dns_fixedname_t fixed;
|
|
||||||
dns_name_t *name;
|
dns_name_t *name;
|
||||||
dns_rdata_t rdata, ds;
|
dns_rdata_t rdata, ds;
|
||||||
bool have_ksk = false;
|
bool have_ksk = false;
|
||||||
@@ -2943,8 +2927,6 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
if (dsdir != NULL)
|
if (dsdir != NULL)
|
||||||
filenamelen += strlen(dsdir) + 1;
|
filenamelen += strlen(dsdir) + 1;
|
||||||
filename = isc_mem_get(mctx, filenamelen);
|
filename = isc_mem_get(mctx, filenamelen);
|
||||||
if (filename == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
if (dsdir != NULL)
|
if (dsdir != NULL)
|
||||||
snprintf(filename, filenamelen, "%s/", dsdir);
|
snprintf(filename, filenamelen, "%s/", dsdir);
|
||||||
else
|
else
|
||||||
@@ -2954,18 +2936,7 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
|
|
||||||
dns_diff_init(mctx, &diff);
|
dns_diff_init(mctx, &diff);
|
||||||
|
|
||||||
if (type == dns_rdatatype_dlv) {
|
name = gorigin;
|
||||||
dns_name_t tname;
|
|
||||||
unsigned int labels;
|
|
||||||
|
|
||||||
dns_name_init(&tname, NULL);
|
|
||||||
name = dns_fixedname_initname(&fixed);
|
|
||||||
labels = dns_name_countlabels(gorigin);
|
|
||||||
dns_name_getlabelsequence(gorigin, 0, labels - 1, &tname);
|
|
||||||
result = dns_name_concatenate(&tname, dlv, name, NULL);
|
|
||||||
check_result(result, "dns_name_concatenate");
|
|
||||||
} else
|
|
||||||
name = gorigin;
|
|
||||||
|
|
||||||
for (key = ISC_LIST_HEAD(keylist);
|
for (key = ISC_LIST_HEAD(keylist);
|
||||||
key != NULL;
|
key != NULL;
|
||||||
@@ -3002,34 +2973,20 @@ writeset(const char *prefix, dns_rdatatype_t type) {
|
|||||||
isc_buffer_usedregion(&b, &r);
|
isc_buffer_usedregion(&b, &r);
|
||||||
dns_rdata_fromregion(&rdata, gclass, dns_rdatatype_dnskey, &r);
|
dns_rdata_fromregion(&rdata, gclass, dns_rdatatype_dnskey, &r);
|
||||||
if (type != dns_rdatatype_dnskey) {
|
if (type != dns_rdatatype_dnskey) {
|
||||||
result = dns_ds_buildrdata(gorigin, &rdata,
|
|
||||||
DNS_DSDIGEST_SHA1,
|
|
||||||
dsbuf, &ds);
|
|
||||||
check_result(result, "dns_ds_buildrdata");
|
|
||||||
if (type == dns_rdatatype_dlv)
|
|
||||||
ds.type = dns_rdatatype_dlv;
|
|
||||||
result = dns_difftuple_create(mctx,
|
|
||||||
DNS_DIFFOP_ADDRESIGN,
|
|
||||||
name, 0, &ds, &tuple);
|
|
||||||
check_result(result, "dns_difftuple_create");
|
|
||||||
dns_diff_append(&diff, &tuple);
|
|
||||||
|
|
||||||
dns_rdata_reset(&ds);
|
|
||||||
result = dns_ds_buildrdata(gorigin, &rdata,
|
result = dns_ds_buildrdata(gorigin, &rdata,
|
||||||
DNS_DSDIGEST_SHA256,
|
DNS_DSDIGEST_SHA256,
|
||||||
dsbuf, &ds);
|
dsbuf, &ds);
|
||||||
check_result(result, "dns_ds_buildrdata");
|
check_result(result, "dns_ds_buildrdata");
|
||||||
if (type == dns_rdatatype_dlv)
|
|
||||||
ds.type = dns_rdatatype_dlv;
|
|
||||||
result = dns_difftuple_create(mctx,
|
result = dns_difftuple_create(mctx,
|
||||||
DNS_DIFFOP_ADDRESIGN,
|
DNS_DIFFOP_ADDRESIGN,
|
||||||
name, 0, &ds, &tuple);
|
name, 0, &ds, &tuple);
|
||||||
|
|
||||||
} else
|
} else {
|
||||||
result = dns_difftuple_create(mctx,
|
result = dns_difftuple_create(mctx,
|
||||||
DNS_DIFFOP_ADDRESIGN,
|
DNS_DIFFOP_ADDRESIGN,
|
||||||
gorigin, zone_soa_min_ttl,
|
gorigin, zone_soa_min_ttl,
|
||||||
&rdata, &tuple);
|
&rdata, &tuple);
|
||||||
|
}
|
||||||
check_result(result, "dns_difftuple_create");
|
check_result(result, "dns_difftuple_create");
|
||||||
dns_diff_append(&diff, &tuple);
|
dns_diff_append(&diff, &tuple);
|
||||||
}
|
}
|
||||||
@@ -3114,6 +3071,7 @@ usage(void) {
|
|||||||
fprintf(stderr, "\t-j jitter:\n");
|
fprintf(stderr, "\t-j jitter:\n");
|
||||||
fprintf(stderr, "\t\trandomize signature end time up to jitter seconds\n");
|
fprintf(stderr, "\t\trandomize signature end time up to jitter seconds\n");
|
||||||
fprintf(stderr, "\t-v debuglevel (0)\n");
|
fprintf(stderr, "\t-v debuglevel (0)\n");
|
||||||
|
fprintf(stderr, "\t-q quiet\n");
|
||||||
fprintf(stderr, "\t-V:\tprint version information\n");
|
fprintf(stderr, "\t-V:\tprint version information\n");
|
||||||
fprintf(stderr, "\t-o origin:\n");
|
fprintf(stderr, "\t-o origin:\n");
|
||||||
fprintf(stderr, "\t\tzone origin (name of zonefile)\n");
|
fprintf(stderr, "\t\tzone origin (name of zonefile)\n");
|
||||||
@@ -3156,7 +3114,6 @@ usage(void) {
|
|||||||
"\t\twith older versions of dnssec-signzone -g\n");
|
"\t\twith older versions of dnssec-signzone -g\n");
|
||||||
fprintf(stderr, "\t-n ncpus (number of cpus present)\n");
|
fprintf(stderr, "\t-n ncpus (number of cpus present)\n");
|
||||||
fprintf(stderr, "\t-k key_signing_key\n");
|
fprintf(stderr, "\t-k key_signing_key\n");
|
||||||
fprintf(stderr, "\t-l lookasidezone\n");
|
|
||||||
fprintf(stderr, "\t-3 NSEC3 salt\n");
|
fprintf(stderr, "\t-3 NSEC3 salt\n");
|
||||||
fprintf(stderr, "\t-H NSEC3 iterations (10)\n");
|
fprintf(stderr, "\t-H NSEC3 iterations (10)\n");
|
||||||
fprintf(stderr, "\t-A NSEC3 optout\n");
|
fprintf(stderr, "\t-A NSEC3 optout\n");
|
||||||
@@ -3232,8 +3189,6 @@ main(int argc, char *argv[]) {
|
|||||||
int tempfilelen = 0;
|
int tempfilelen = 0;
|
||||||
dns_rdataclass_t rdclass;
|
dns_rdataclass_t rdclass;
|
||||||
isc_task_t **tasks = NULL;
|
isc_task_t **tasks = NULL;
|
||||||
isc_buffer_t b;
|
|
||||||
int len;
|
|
||||||
hashlist_t hashlist;
|
hashlist_t hashlist;
|
||||||
bool make_keyset = false;
|
bool make_keyset = false;
|
||||||
bool set_salt = false;
|
bool set_salt = false;
|
||||||
@@ -3241,9 +3196,12 @@ main(int argc, char *argv[]) {
|
|||||||
bool set_iter = false;
|
bool set_iter = false;
|
||||||
bool nonsecify = false;
|
bool nonsecify = false;
|
||||||
|
|
||||||
|
atomic_init(&shuttingdown, false);
|
||||||
|
atomic_init(&finished, false);
|
||||||
|
|
||||||
/* Unused letters: Bb G J q Yy (and F is reserved). */
|
/* Unused letters: Bb G J q Yy (and F is reserved). */
|
||||||
#define CMDLINE_FLAGS \
|
#define CMDLINE_FLAGS \
|
||||||
"3:AaCc:Dd:E:e:f:FghH:i:I:j:K:k:L:l:m:M:n:N:o:O:PpQRr:s:ST:tuUv:VX:xzZ:"
|
"3:AaCc:Dd:E:e:f:FghH:i:I:j:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:VX:xzZ:"
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
@@ -3408,14 +3366,7 @@ main(int argc, char *argv[]) {
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 'l':
|
case 'l':
|
||||||
len = strlen(isc_commandline_argument);
|
fatal("-l option (DLV lookaside) is obsolete");
|
||||||
isc_buffer_init(&b, isc_commandline_argument, len);
|
|
||||||
isc_buffer_add(&b, len);
|
|
||||||
|
|
||||||
dlv = dns_fixedname_initname(&dlv_fixed);
|
|
||||||
result = dns_name_fromtext(dlv, &b, dns_rootname, 0,
|
|
||||||
NULL);
|
|
||||||
check_result(result, "dns_name_fromtext(dlv)");
|
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case 'M':
|
case 'M':
|
||||||
@@ -3504,6 +3455,10 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("verbose level must be numeric");
|
fatal("verbose level must be numeric");
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case 'q':
|
||||||
|
quiet = true;
|
||||||
|
break;
|
||||||
|
|
||||||
case 'X':
|
case 'X':
|
||||||
dnskey_endstr = isc_commandline_argument;
|
dnskey_endstr = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
@@ -3603,8 +3558,6 @@ main(int argc, char *argv[]) {
|
|||||||
free_output = true;
|
free_output = true;
|
||||||
size = strlen(file) + strlen(".signed") + 1;
|
size = strlen(file) + strlen(".signed") + 1;
|
||||||
output = isc_mem_allocate(mctx, size);
|
output = isc_mem_allocate(mctx, size);
|
||||||
if (output == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
snprintf(output, size, "%s.signed", file);
|
snprintf(output, size, "%s.signed", file);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -3819,10 +3772,8 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
if (!nokeys) {
|
if (!nokeys) {
|
||||||
writeset("dsset-", dns_rdatatype_ds);
|
writeset("dsset-", dns_rdatatype_ds);
|
||||||
if (make_keyset)
|
if (make_keyset) {
|
||||||
writeset("keyset-", dns_rdatatype_dnskey);
|
writeset("keyset-", dns_rdatatype_dnskey);
|
||||||
if (dlv != NULL) {
|
|
||||||
writeset("dlvset-", dns_rdatatype_dlv);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -3833,8 +3784,6 @@ main(int argc, char *argv[]) {
|
|||||||
} else {
|
} else {
|
||||||
tempfilelen = strlen(output) + 20;
|
tempfilelen = strlen(output) + 20;
|
||||||
tempfile = isc_mem_get(mctx, tempfilelen);
|
tempfile = isc_mem_get(mctx, tempfilelen);
|
||||||
if (tempfile == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
|
|
||||||
result = isc_file_mktemplate(output, tempfile, tempfilelen);
|
result = isc_file_mktemplate(output, tempfile, tempfilelen);
|
||||||
check_result(result, "isc_file_mktemplate");
|
check_result(result, "isc_file_mktemplate");
|
||||||
@@ -3864,8 +3813,6 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("failed to create task: %s", isc_result_totext(result));
|
fatal("failed to create task: %s", isc_result_totext(result));
|
||||||
|
|
||||||
tasks = isc_mem_get(mctx, ntasks * sizeof(isc_task_t *));
|
tasks = isc_mem_get(mctx, ntasks * sizeof(isc_task_t *));
|
||||||
if (tasks == NULL)
|
|
||||||
fatal("out of memory");
|
|
||||||
for (i = 0; i < (int)ntasks; i++) {
|
for (i = 0; i < (int)ntasks; i++) {
|
||||||
tasks[i] = NULL;
|
tasks[i] = NULL;
|
||||||
result = isc_task_create(taskmgr, 0, &tasks[i]);
|
result = isc_task_create(taskmgr, 0, &tasks[i]);
|
||||||
@@ -3883,7 +3830,7 @@ main(int argc, char *argv[]) {
|
|||||||
presign();
|
presign();
|
||||||
TIME_NOW(&sign_start);
|
TIME_NOW(&sign_start);
|
||||||
signapex();
|
signapex();
|
||||||
if (!finished) {
|
if (!atomic_load(&finished)) {
|
||||||
/*
|
/*
|
||||||
* There is more work to do. Spread it out over multiple
|
* There is more work to do. Spread it out over multiple
|
||||||
* processors if possible.
|
* processors if possible.
|
||||||
@@ -3896,11 +3843,12 @@ main(int argc, char *argv[]) {
|
|||||||
isc_result_totext(result));
|
isc_result_totext(result));
|
||||||
}
|
}
|
||||||
(void)isc_app_run();
|
(void)isc_app_run();
|
||||||
if (!finished)
|
if (!atomic_load(&finished)) {
|
||||||
fatal("process aborted by user");
|
fatal("process aborted by user");
|
||||||
|
}
|
||||||
} else
|
} else
|
||||||
isc_task_detach(&master);
|
isc_task_detach(&master);
|
||||||
shuttingdown = true;
|
atomic_store(&shuttingdown, true);;
|
||||||
for (i = 0; i < (int)ntasks; i++)
|
for (i = 0; i < (int)ntasks; i++)
|
||||||
isc_task_detach(&tasks[i]);
|
isc_task_detach(&tasks[i]);
|
||||||
isc_taskmgr_destroy(&taskmgr);
|
isc_taskmgr_destroy(&taskmgr);
|
||||||
@@ -3913,7 +3861,7 @@ main(int argc, char *argv[]) {
|
|||||||
} else {
|
} else {
|
||||||
vresult = dns_zoneverify_dnssec(NULL, gdb, gversion, gorigin,
|
vresult = dns_zoneverify_dnssec(NULL, gdb, gversion, gorigin,
|
||||||
NULL, mctx, ignore_kskflag,
|
NULL, mctx, ignore_kskflag,
|
||||||
keyset_kskonly);
|
keyset_kskonly, report);
|
||||||
if (vresult != ISC_R_SUCCESS) {
|
if (vresult != ISC_R_SUCCESS) {
|
||||||
fprintf(output_stdout ? stderr : stdout,
|
fprintf(output_stdout ? stderr : stdout,
|
||||||
"Zone verification failed (%s)\n",
|
"Zone verification failed (%s)\n",
|
||||||
|
|||||||
@@ -80,6 +80,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-P</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-P</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-Q</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-Q</option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-q</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-R</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-R</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-S</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-S</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
|
||||||
@@ -223,16 +224,6 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
|
||||||
<term>-l <replaceable class="parameter">domain</replaceable></term>
|
|
||||||
<listitem>
|
|
||||||
<para>
|
|
||||||
Generate a DLV set in addition to the key (DNSKEY) and DS sets.
|
|
||||||
The domain is appended to the name of the records.
|
|
||||||
</para>
|
|
||||||
</listitem>
|
|
||||||
</varlistentry>
|
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-M <replaceable class="parameter">maxttl</replaceable></term>
|
<term>-M <replaceable class="parameter">maxttl</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
@@ -543,6 +534,22 @@
|
|||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-q</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Quiet mode: Suppresses unnecessary output. Without this
|
||||||
|
option, when <command>dnssec-signzone</command> is run it
|
||||||
|
will print to standard output the number of keys in use,
|
||||||
|
the algorithms used to verify the zone was signed correctly
|
||||||
|
and other status information, and finally the filename
|
||||||
|
containing the signed zone. With it, that output is
|
||||||
|
suppressed, leaving only the filename.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-R</term>
|
<term>-R</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -55,6 +55,7 @@
|
|||||||
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
||||||
[<code class="option">-P</code>]
|
[<code class="option">-P</code>]
|
||||||
[<code class="option">-Q</code>]
|
[<code class="option">-Q</code>]
|
||||||
|
[<code class="option">-q</code>]
|
||||||
[<code class="option">-R</code>]
|
[<code class="option">-R</code>]
|
||||||
[<code class="option">-S</code>]
|
[<code class="option">-S</code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>]
|
||||||
@@ -173,13 +174,6 @@
|
|||||||
key flags. This option may be specified multiple times.
|
key flags. This option may be specified multiple times.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
|
|
||||||
<dd>
|
|
||||||
<p>
|
|
||||||
Generate a DLV set in addition to the key (DNSKEY) and DS sets.
|
|
||||||
The domain is appended to the name of the records.
|
|
||||||
</p>
|
|
||||||
</dd>
|
|
||||||
<dt><span class="term">-M <em class="replaceable"><code>maxttl</code></em></span></dt>
|
<dt><span class="term">-M <em class="replaceable"><code>maxttl</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -429,6 +423,18 @@
|
|||||||
RFC 4641, section 4.2.1.1 ("Pre-Publish Key Rollover").
|
RFC 4641, section 4.2.1.1 ("Pre-Publish Key Rollover").
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-q</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Quiet mode: Suppresses unnecessary output. Without this
|
||||||
|
option, when <span class="command"><strong>dnssec-signzone</strong></span> is run it
|
||||||
|
will print to standard output the number of keys in use,
|
||||||
|
the algorithms used to verify the zone was signed correctly
|
||||||
|
and other status information, and finally the filename
|
||||||
|
containing the signed zone. With it, that output is
|
||||||
|
suppressed, leaving only the filename.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-R</span></dt>
|
<dt><span class="term">-R</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-verify \- DNSSEC zone verification tool
|
dnssec-verify \- DNSSEC zone verification tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-verify\fR\ 'u
|
.HP \w'\fBdnssec\-verify\fR\ 'u
|
||||||
\fBdnssec\-verify\fR [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-x\fR] [\fB\-z\fR] {zonefile}
|
\fBdnssec\-verify\fR [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-q\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-x\fR] [\fB\-z\fR] {zonefile}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-verify\fR
|
\fBdnssec\-verify\fR
|
||||||
@@ -81,6 +81,13 @@ Sets the debugging level\&.
|
|||||||
Prints version information\&.
|
Prints version information\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-q
|
||||||
|
.RS 4
|
||||||
|
Quiet mode: Suppresses output\&. Without this option, when
|
||||||
|
\fBdnssec\-verify\fR
|
||||||
|
is run it will print to standard output the number of keys in use, the algorithms used to verify the zone was signed correctly and other status information\&. With it, all non\-error output is suppressed, and only the exit code will indicate success\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-x
|
\-x
|
||||||
.RS 4
|
.RS 4
|
||||||
Only verify that the DNSKEY RRset is signed with key\-signing keys\&. Without this flag, it is assumed that the DNSKEY RRset will be signed by all active keys\&. When this flag is set, it will not be an error if the DNSKEY RRset is not signed by zone\-signing keys\&. This corresponds to the
|
Only verify that the DNSKEY RRset is signed with key\-signing keys\&. Without this flag, it is assumed that the DNSKEY RRset will be signed by all active keys\&. When this flag is set, it will not be an error if the DNSKEY RRset is not signed by zone\-signing keys\&. This corresponds to the
|
||||||
|
|||||||
@@ -11,8 +11,6 @@
|
|||||||
|
|
||||||
/*! \file */
|
/*! \file */
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <time.h>
|
#include <time.h>
|
||||||
@@ -69,7 +67,6 @@
|
|||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
const char *program = "dnssec-verify";
|
const char *program = "dnssec-verify";
|
||||||
int verbose;
|
|
||||||
|
|
||||||
static isc_stdtime_t now;
|
static isc_stdtime_t now;
|
||||||
static isc_mem_t *mctx = NULL;
|
static isc_mem_t *mctx = NULL;
|
||||||
@@ -81,6 +78,16 @@ static dns_name_t *gorigin; /* The database origin */
|
|||||||
static bool ignore_kskflag = false;
|
static bool ignore_kskflag = false;
|
||||||
static bool keyset_kskonly = false;
|
static bool keyset_kskonly = false;
|
||||||
|
|
||||||
|
static void
|
||||||
|
report(const char *format, ...) {
|
||||||
|
if (!quiet) {
|
||||||
|
va_list args;
|
||||||
|
va_start(args, format);
|
||||||
|
vfprintf(stdout, format, args);
|
||||||
|
va_end(args);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
* Load the zone file from disk
|
* Load the zone file from disk
|
||||||
*/
|
*/
|
||||||
@@ -143,6 +150,7 @@ usage(void) {
|
|||||||
|
|
||||||
fprintf(stderr, "Options: (default value in parenthesis) \n");
|
fprintf(stderr, "Options: (default value in parenthesis) \n");
|
||||||
fprintf(stderr, "\t-v debuglevel (0)\n");
|
fprintf(stderr, "\t-v debuglevel (0)\n");
|
||||||
|
fprintf(stderr, "\t-q quiet\n");
|
||||||
fprintf(stderr, "\t-V:\tprint version information\n");
|
fprintf(stderr, "\t-V:\tprint version information\n");
|
||||||
fprintf(stderr, "\t-o origin:\n");
|
fprintf(stderr, "\t-o origin:\n");
|
||||||
fprintf(stderr, "\t\tzone origin (name of zonefile)\n");
|
fprintf(stderr, "\t\tzone origin (name of zonefile)\n");
|
||||||
@@ -175,7 +183,7 @@ main(int argc, char *argv[]) {
|
|||||||
int ch;
|
int ch;
|
||||||
|
|
||||||
#define CMDLINE_FLAGS \
|
#define CMDLINE_FLAGS \
|
||||||
"hm:o:I:c:E:v:Vxz"
|
"c:E:hm:o:I:qv:Vxz"
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Process memory debugging argument first.
|
* Process memory debugging argument first.
|
||||||
@@ -240,6 +248,10 @@ main(int argc, char *argv[]) {
|
|||||||
fatal("verbose level must be numeric");
|
fatal("verbose level must be numeric");
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case 'q':
|
||||||
|
quiet = true;
|
||||||
|
break;
|
||||||
|
|
||||||
case 'x':
|
case 'x':
|
||||||
keyset_kskonly = true;
|
keyset_kskonly = true;
|
||||||
break;
|
break;
|
||||||
@@ -307,7 +319,7 @@ main(int argc, char *argv[]) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
gdb = NULL;
|
gdb = NULL;
|
||||||
fprintf(stderr, "Loading zone '%s' from file '%s'\n", origin, file);
|
report("Loading zone '%s' from file '%s'\n", origin, file);
|
||||||
loadzone(file, origin, rdclass, &gdb);
|
loadzone(file, origin, rdclass, &gdb);
|
||||||
gorigin = dns_db_origin(gdb);
|
gorigin = dns_db_origin(gdb);
|
||||||
gclass = dns_db_class(gdb);
|
gclass = dns_db_class(gdb);
|
||||||
@@ -317,7 +329,8 @@ main(int argc, char *argv[]) {
|
|||||||
check_result(result, "dns_db_newversion()");
|
check_result(result, "dns_db_newversion()");
|
||||||
|
|
||||||
result = dns_zoneverify_dnssec(NULL, gdb, gversion, gorigin, NULL,
|
result = dns_zoneverify_dnssec(NULL, gdb, gversion, gorigin, NULL,
|
||||||
mctx, ignore_kskflag, keyset_kskonly);
|
mctx, ignore_kskflag, keyset_kskonly,
|
||||||
|
report);
|
||||||
|
|
||||||
dns_db_closeversion(gdb, &gversion, false);
|
dns_db_closeversion(gdb, &gversion, false);
|
||||||
dns_db_detach(&gdb);
|
dns_db_detach(&gdb);
|
||||||
|
|||||||
@@ -49,6 +49,7 @@
|
|||||||
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
|
||||||
|
<arg choice="opt" rep="norepeat"><option>-q</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
<arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-V</option></arg>
|
||||||
<arg choice="opt" rep="norepeat"><option>-x</option></arg>
|
<arg choice="opt" rep="norepeat"><option>-x</option></arg>
|
||||||
@@ -140,6 +141,20 @@
|
|||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
|
<varlistentry>
|
||||||
|
<term>-q</term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
Quiet mode: Suppresses output. Without this option, when
|
||||||
|
<command>dnssec-verify</command> is run it will print to
|
||||||
|
standard output the number of keys in use, the algorithms
|
||||||
|
used to verify the zone was signed correctly and other
|
||||||
|
status information. With it, all non-error output is
|
||||||
|
suppressed, and only the exit code will indicate success.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
|
||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term>-x</term>
|
<term>-x</term>
|
||||||
<listitem>
|
<listitem>
|
||||||
|
|||||||
@@ -37,6 +37,7 @@
|
|||||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||||
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
||||||
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
||||||
|
[<code class="option">-q</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-x</code>]
|
[<code class="option">-x</code>]
|
||||||
@@ -112,6 +113,17 @@
|
|||||||
Prints version information.
|
Prints version information.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-q</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Quiet mode: Suppresses output. Without this option, when
|
||||||
|
<span class="command"><strong>dnssec-verify</strong></span> is run it will print to
|
||||||
|
standard output the number of keys in use, the algorithms
|
||||||
|
used to verify the zone was signed correctly and other
|
||||||
|
status information. With it, all non-error output is
|
||||||
|
suppressed, and only the exit code will indicate success.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-x</span></dt>
|
<dt><span class="term">-x</span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
+29
-4
@@ -15,8 +15,6 @@
|
|||||||
* DNSSEC Support Routines.
|
* DNSSEC Support Routines.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
#include <config.h>
|
|
||||||
|
|
||||||
#include <inttypes.h>
|
#include <inttypes.h>
|
||||||
#include <stdbool.h>
|
#include <stdbool.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -59,8 +57,9 @@
|
|||||||
|
|
||||||
#include "dnssectool.h"
|
#include "dnssectool.h"
|
||||||
|
|
||||||
extern int verbose;
|
int verbose = 0;
|
||||||
extern const char *program;
|
bool quiet = false;
|
||||||
|
uint8_t dtype[8];
|
||||||
|
|
||||||
static fatalcallback_t *fatalcallback = NULL;
|
static fatalcallback_t *fatalcallback = NULL;
|
||||||
|
|
||||||
@@ -346,6 +345,32 @@ strtodsdigest(const char *algname) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static int
|
||||||
|
cmp_dtype(const void *ap, const void *bp) {
|
||||||
|
int a = *(const uint8_t *)ap;
|
||||||
|
int b = *(const uint8_t *)bp;
|
||||||
|
return (a - b);
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
add_dtype(unsigned int dt) {
|
||||||
|
unsigned i, n;
|
||||||
|
|
||||||
|
/* ensure there is space for a zero terminator */
|
||||||
|
n = sizeof(dtype)/sizeof(dtype[0]) - 1;
|
||||||
|
for (i = 0; i < n; i++) {
|
||||||
|
if (dtype[i] == dt) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (dtype[i] == 0) {
|
||||||
|
dtype[i] = dt;
|
||||||
|
qsort(dtype, i+1, 1, cmp_dtype);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fatal("too many -a digest type arguments");
|
||||||
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
try_dir(const char *dirname) {
|
try_dir(const char *dirname) {
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
|
|||||||
+25
-2
@@ -21,6 +21,26 @@
|
|||||||
#include <dns/rdatastruct.h>
|
#include <dns/rdatastruct.h>
|
||||||
#include <dst/dst.h>
|
#include <dst/dst.h>
|
||||||
|
|
||||||
|
#ifndef PATH_MAX
|
||||||
|
#define PATH_MAX 1024 /* WIN32, and others don't define this. */
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/*! verbosity: set by -v and -q option in each program, defined in dnssectool.c */
|
||||||
|
extern int verbose;
|
||||||
|
extern bool quiet;
|
||||||
|
|
||||||
|
/*! program name, statically initialized in each program */
|
||||||
|
extern const char *program;
|
||||||
|
|
||||||
|
/*!
|
||||||
|
* List of DS digest types used by dnssec-cds and dnssec-dsfromkey,
|
||||||
|
* defined in dnssectool.c. Filled in by add_dtype() from -a
|
||||||
|
* arguments, sorted (so that DS records are in a canonical order) and
|
||||||
|
* terminated by a zero. The size of the array is an arbitrary limit
|
||||||
|
* which should be greater than the number of known digest types.
|
||||||
|
*/
|
||||||
|
extern uint8_t dtype[8];
|
||||||
|
|
||||||
typedef void (fatalcallback_t)(void);
|
typedef void (fatalcallback_t)(void);
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE void
|
ISC_PLATFORM_NORETURN_PRE void
|
||||||
@@ -55,11 +75,14 @@ isc_stdtime_t
|
|||||||
strtotime(const char *str, int64_t now, int64_t base,
|
strtotime(const char *str, int64_t now, int64_t base,
|
||||||
bool *setp);
|
bool *setp);
|
||||||
|
|
||||||
|
dns_rdataclass_t
|
||||||
|
strtoclass(const char *str);
|
||||||
|
|
||||||
unsigned int
|
unsigned int
|
||||||
strtodsdigest(const char *str);
|
strtodsdigest(const char *str);
|
||||||
|
|
||||||
dns_rdataclass_t
|
void
|
||||||
strtoclass(const char *str);
|
add_dtype(unsigned int dt);
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
try_dir(const char *dirname);
|
try_dir(const char *dirname);
|
||||||
|
|||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -89,6 +90,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -68,6 +68,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -92,6 +93,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\include;..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -102,6 +103,7 @@ set PYTHONPATH=.
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<?xml version="1.0" encoding="utf-8"?>
|
<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||||
</Project>
|
</Project>
|
||||||
@@ -62,6 +62,7 @@
|
|||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
<BrowseInformation>true</BrowseInformation>
|
<BrowseInformation>true</BrowseInformation>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
@@ -89,6 +90,7 @@
|
|||||||
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
<AssemblerListingLocation>.\$(Configuration)\</AssemblerListingLocation>
|
||||||
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
<ObjectFileName>.\$(Configuration)\</ObjectFileName>
|
||||||
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
<ProgramDataBaseFileName>$(OutDir)$(TargetName).pdb</ProgramDataBaseFileName>
|
||||||
|
<ForcedIncludeFiles>..\..\..\config.h</ForcedIncludeFiles>
|
||||||
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
<AdditionalIncludeDirectories>.\;..\..\..\;@LIBXML2_INC@@OPENSSL_INC@..\..\..\lib\isc\win32;..\..\..\lib\isc\win32\include;..\..\..\lib\isc\include;..\..\..\lib\dns\include;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
|
||||||
<CompileAs>CompileAsC</CompileAs>
|
<CompileAs>CompileAsC</CompileAs>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user