Compare commits
605
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2cc31c8cfd | ||
|
|
1f2bde4f57 | ||
|
|
3358f712c9 | ||
|
|
f4c2909353 | ||
|
|
4a30733ae5 | ||
|
|
670b1598d5 | ||
|
|
b090cb95b2 | ||
|
|
d1d88a2895 | ||
|
|
f0feaa3305 | ||
|
|
861f25d930 | ||
|
|
1eeb4c1121 | ||
|
|
30687fcbb3 | ||
|
|
317d9547a9 | ||
|
|
f55a4d3e55 | ||
|
|
dad43a128d | ||
|
|
9597d30186 | ||
|
|
5a1c2b0b59 | ||
|
|
69d30f8974 | ||
|
|
746b3ac88c | ||
|
|
14ca6270d3 | ||
|
|
d043a41499 | ||
|
|
d2d9910da2 | ||
|
|
76bb33fbd5 | ||
|
|
d646aca282 | ||
|
|
4eee6460ff | ||
|
|
9fb812763a | ||
|
|
99d1ec6c4b | ||
|
|
59c486391d | ||
|
|
1c33dbd27d | ||
|
|
bb837db4ee | ||
|
|
e8ba18906b | ||
|
|
0b2d5490cd | ||
|
|
6035980bb1 | ||
|
|
321c93c05d | ||
|
|
cedfebc64a | ||
|
|
99de681480 | ||
|
|
2a9867d512 | ||
|
|
6bf8535542 | ||
|
|
b944bf4120 | ||
|
|
3a9c82f749 | ||
|
|
f088657eb1 | ||
|
|
ebbcf4c34f | ||
|
|
3d05c99abb | ||
|
|
f08277f9fb | ||
|
|
d8473d8152 | ||
|
|
806f457147 | ||
|
|
aa99a554e4 | ||
|
|
058df60ee1 | ||
|
|
6d8495f926 | ||
|
|
f7cf5603d0 | ||
|
|
7f19cbbc90 | ||
|
|
06bf5f21d2 | ||
|
|
73ff8850bf | ||
|
|
cab15392af | ||
|
|
cee8e4bf9b | ||
|
|
ddb46ecff5 | ||
|
|
8ce52b94f4 | ||
|
|
d43ab7059a | ||
|
|
2a3088e18d | ||
|
|
63467cc192 | ||
|
|
e4f775d1b3 | ||
|
|
6c0bf20ed8 | ||
|
|
7cabfd618b | ||
|
|
8e0c402115 | ||
|
|
6cdc4114cb | ||
|
|
848094d6f7 | ||
|
|
84914a0610 | ||
|
|
bf3fffff67 | ||
|
|
0cc5d622f8 | ||
|
|
f981b52793 | ||
|
|
e58d8f2acb | ||
|
|
b6eb31a0e3 | ||
|
|
b9ebde705b | ||
|
|
180f77dd9c | ||
|
|
059a602551 | ||
|
|
aa3a4a72f2 | ||
|
|
d26d4f289f | ||
|
|
f25e38b67e | ||
|
|
71ce8b0a51 | ||
|
|
5867c1b727 | ||
|
|
a671fb34f6 | ||
|
|
8bec4a6bf6 | ||
|
|
a100c1ff7c | ||
|
|
77b2db8246 | ||
|
|
df317184eb | ||
|
|
25609156a5 | ||
|
|
9256026d18 | ||
|
|
b52d46612f | ||
|
|
a7a482c1b1 | ||
|
|
09dccf29b4 | ||
|
|
7e71c4d0cc | ||
|
|
4216c72d13 | ||
|
|
98718b3b4b | ||
|
|
6d94ac9f96 | ||
|
|
ed1e480c53 | ||
|
|
05e08a21d1 | ||
|
|
4d57ef0c49 | ||
|
|
f0ac4c47b0 | ||
|
|
0130ff96d5 | ||
|
|
ef9bd8533a | ||
|
|
5b2b3e589c | ||
|
|
2771a5b64d | ||
|
|
f831e758d1 | ||
|
|
04e9b6060c | ||
|
|
56fbed2f0f | ||
|
|
ed9a4d9d71 | ||
|
|
9ef4d2b583 | ||
|
|
4bbc245e7e | ||
|
|
7868d8145b | ||
|
|
141da70898 | ||
|
|
142c63dda8 | ||
|
|
9217f1e200 | ||
|
|
855f49cfba | ||
|
|
85c6e797aa | ||
|
|
38f8716b1c | ||
|
|
910c6b9cef | ||
|
|
59f04a5d09 | ||
|
|
23a4559b34 | ||
|
|
f106d0ed2b | ||
|
|
b6e885c97f | ||
|
|
840179a247 | ||
|
|
cadd1a0ab3 | ||
|
|
70e58897c7 | ||
|
|
c0995bc380 | ||
|
|
8138a595d9 | ||
|
|
bd9707464c | ||
|
|
438e9b5587 | ||
|
|
7e2f50c369 | ||
|
|
d4eef9e89a | ||
|
|
ae01ec2823 | ||
|
|
635fbc7f93 | ||
|
|
e71e2d06f5 | ||
|
|
30e0fd942b | ||
|
|
0519a5bfe9 | ||
|
|
ae0898e328 | ||
|
|
62a72211aa | ||
|
|
2bc7303af2 | ||
|
|
2707d0eeb7 | ||
|
|
8b4ba366dd | ||
|
|
a94678ff77 | ||
|
|
abb5e9a575 | ||
|
|
a7cd0868a2 | ||
|
|
40971b22e7 | ||
|
|
87c4c24cde | ||
|
|
15ea6f002f | ||
|
|
c17eee034b | ||
|
|
9f7ba679ac | ||
|
|
48b2a5df97 | ||
|
|
17aed2f895 | ||
|
|
fe4cd556b3 | ||
|
|
96030f23a4 | ||
|
|
b84c9b2608 | ||
|
|
b1e966efaa | ||
|
|
5319d8adea | ||
|
|
7dd8ab7336 | ||
|
|
3edf7a9fe7 | ||
|
|
d8cd4460bf | ||
|
|
4477f71868 | ||
|
|
3a5793ece2 | ||
|
|
7d360bd05e | ||
|
|
5b76f0f80e | ||
|
|
bd814b79d4 | ||
|
|
2261c853b5 | ||
|
|
9039aad0f8 | ||
|
|
5abdee9004 | ||
|
|
3dd8af9aa8 | ||
|
|
84c4eb02e7 | ||
|
|
8594cd00bc | ||
|
|
a243860562 | ||
|
|
4f74e1010e | ||
|
|
003e4b00c6 | ||
|
|
2c419b7abc | ||
|
|
199be183fa | ||
|
|
d48d8e1cf0 | ||
|
|
76bcb4d16b | ||
|
|
6e11211ac6 | ||
|
|
ddf051df65 | ||
|
|
bbea0be767 | ||
|
|
3a650d973f | ||
|
|
a0d2c7cdb6 | ||
|
|
29a3e77425 | ||
|
|
bb61a3a90a | ||
|
|
b05a991ad0 | ||
|
|
e9ef3defa4 | ||
|
|
f768c138b4 | ||
|
|
4dceab142d | ||
|
|
7dbc843496 | ||
|
|
40db7dfcc1 | ||
|
|
63532d6d81 | ||
|
|
cfea9a3aec | ||
|
|
7b9318bf72 | ||
|
|
a32ac8790c | ||
|
|
57f0251713 | ||
|
|
89d7059103 | ||
|
|
fd38a4e1bf | ||
|
|
783663db80 | ||
|
|
71cf8fa5ac | ||
|
|
c49a81e27d | ||
|
|
32783d36c2 | ||
|
|
e759fa9847 | ||
|
|
7fd24ded90 | ||
|
|
a5a6362e92 | ||
|
|
f57c51fe05 | ||
|
|
9b84bfb5f4 | ||
|
|
d29e5f197b | ||
|
|
e861224cf4 | ||
|
|
23cb022247 | ||
|
|
fcca62859d | ||
|
|
c38a323082 | ||
|
|
745d9db746 | ||
|
|
132f30b623 | ||
|
|
496c02d32a | ||
|
|
96e9f59637 | ||
|
|
4c3a985a24 | ||
|
|
7939648378 | ||
|
|
1f35977423 | ||
|
|
9de10cd153 | ||
|
|
23195f18bc | ||
|
|
dab22a54df | ||
|
|
81fdc4a822 | ||
|
|
b1eff7586d | ||
|
|
ae508c17bc | ||
|
|
20f0936cf2 | ||
|
|
04d0b70ba2 | ||
|
|
584f0d7a7e | ||
|
|
fe7ce629f4 | ||
|
|
4a44e9dd36 | ||
|
|
80582073a5 | ||
|
|
01fcc07a6b | ||
|
|
d6d107d804 | ||
|
|
8268526294 | ||
|
|
d70daa29f7 | ||
|
|
4761213e80 | ||
|
|
599c1d2a6b | ||
|
|
eeead1cfe7 | ||
|
|
ed22d12f10 | ||
|
|
ced79790b3 | ||
|
|
03697f1bcc | ||
|
|
0fb4fc1897 | ||
|
|
85870ad9ee | ||
|
|
b3a058e7bb | ||
|
|
e8a64d0cbe | ||
|
|
bc203d6082 | ||
|
|
da0d85d748 | ||
|
|
3ec5d2d6ed | ||
|
|
e353700189 | ||
|
|
a962475948 | ||
|
|
e888c62fbd | ||
|
|
99906df09e | ||
|
|
8f6e4dfa15 | ||
|
|
4c008d20e6 | ||
|
|
ff22498849 | ||
|
|
8495edc31d | ||
|
|
5ccb28d6d8 | ||
|
|
cd52953f8a | ||
|
|
e42cb1f198 | ||
|
|
7ba3a06935 | ||
|
|
71dd44339f | ||
|
|
ae7fa0a308 | ||
|
|
9c27a3b0e2 | ||
|
|
9241363f36 | ||
|
|
c9f28777f6 | ||
|
|
dcb6a0c4f8 | ||
|
|
51546e8892 | ||
|
|
f0f3370e14 | ||
|
|
9fcc028f5c | ||
|
|
bfa4b9c141 | ||
|
|
612f277877 | ||
|
|
5c271f91e1 | ||
|
|
fe1bbba259 | ||
|
|
c289913e5c | ||
|
|
7e37b5e379 | ||
|
|
5dc3b25d03 | ||
|
|
fd8dd9841d | ||
|
|
01b125ff05 | ||
|
|
13b20ef411 | ||
|
|
7f91f1ecaa | ||
|
|
79b5ccbf34 | ||
|
|
e6ca2a651f | ||
|
|
6437bcc488 | ||
|
|
27850a5ad2 | ||
|
|
c259cecc90 | ||
|
|
514053f244 | ||
|
|
8fbb42c49c | ||
|
|
f4751a91f7 | ||
|
|
bbe1c06a8b | ||
|
|
c752dff3b4 | ||
|
|
f98a6a5308 | ||
|
|
49d2a12e7c | ||
|
|
ad5b0402c9 | ||
|
|
1d4d008fc9 | ||
|
|
420a71df57 | ||
|
|
53a5776025 | ||
|
|
c7085be211 | ||
|
|
7e7a946d44 | ||
|
|
ccc6378355 | ||
|
|
a85df3ff9c | ||
|
|
5f0ee7c303 | ||
|
|
8537878c01 | ||
|
|
ec30944aa4 | ||
|
|
e9f4d00bf0 | ||
|
|
173ad9cf46 | ||
|
|
00392921f0 | ||
|
|
49312d6bb2 | ||
|
|
05c97f2329 | ||
|
|
704ad2907f | ||
|
|
286b57c7f1 | ||
|
|
0a76f186a5 | ||
|
|
96b7f9f9aa | ||
|
|
4e0d576858 | ||
|
|
53ef8835c1 | ||
|
|
342c06c335 | ||
|
|
41a60a0e21 | ||
|
|
b103f516d0 | ||
|
|
524fce77fe | ||
|
|
b0f6fc7f2f | ||
|
|
188684a31d | ||
|
|
53dd4f02c1 | ||
|
|
8ace9e0c62 | ||
|
|
49c804f8b7 | ||
|
|
6ddac2d56d | ||
|
|
a761aa59e3 | ||
|
|
1357d44605 | ||
|
|
178aef5b8c | ||
|
|
785f6d470f | ||
|
|
2d2d87a615 | ||
|
|
315b3c3a1a | ||
|
|
9992f7808c | ||
|
|
2e42414522 | ||
|
|
473d5a8d03 | ||
|
|
ca1da46ac1 | ||
|
|
e532d39146 | ||
|
|
037468f6a4 | ||
|
|
328d11297d | ||
|
|
ec1e8e7001 | ||
|
|
6be83f2eb7 | ||
|
|
1c77f55dc6 | ||
|
|
338df9e1ff | ||
|
|
6bcfa0c4ec | ||
|
|
bfaf88ce7d | ||
|
|
ae73a8d87a | ||
|
|
e369c90369 | ||
|
|
f251d69eba | ||
|
|
0b68596c45 | ||
|
|
d128656d2e | ||
|
|
8fa27365ec | ||
|
|
3db335bca0 | ||
|
|
bbb4cdb92d | ||
|
|
acf5986a7c | ||
|
|
67dbe0ae4d | ||
|
|
8098a58581 | ||
|
|
5d34a14f22 | ||
|
|
b40d1e8467 | ||
|
|
e48af36981 | ||
|
|
d4c2395fff | ||
|
|
9bcf45f4ce | ||
|
|
f23e86b96b | ||
|
|
18efcdc65f | ||
|
|
963f6a2203 | ||
|
|
e229d46a87 | ||
|
|
9d8e8a4fcc | ||
|
|
51147fa567 | ||
|
|
b5a5eed7a0 | ||
|
|
f24b26188d | ||
|
|
d811cca3c6 | ||
|
|
d75b953489 | ||
|
|
6bd025942c | ||
|
|
1bb56bb0fc | ||
|
|
a53ed01d03 | ||
|
|
be34b1c535 | ||
|
|
f3ca90a804 | ||
|
|
488b1a776c | ||
|
|
f3228df622 | ||
|
|
4043fe9090 | ||
|
|
98820aef7e | ||
|
|
284b2ce106 | ||
|
|
6b52160a5b | ||
|
|
60f5f78b8d | ||
|
|
347ce4f590 | ||
|
|
117dac11d1 | ||
|
|
ef0d7177b6 | ||
|
|
600b6abc05 | ||
|
|
4ca74eee49 | ||
|
|
5bcac990dd | ||
|
|
ce8703a79e | ||
|
|
d36938321e | ||
|
|
4c356d2770 | ||
|
|
ed3dd45da8 | ||
|
|
b8b99603f1 | ||
|
|
f6453c1bc7 | ||
|
|
b220fb32bd | ||
|
|
e2636b1de0 | ||
|
|
26f817f574 | ||
|
|
48039fa25e | ||
|
|
bbaade23eb | ||
|
|
5e4580d479 | ||
|
|
0bde07261b | ||
|
|
0e57fc160e | ||
|
|
9422a5da44 | ||
|
|
0069a689a6 | ||
|
|
53e1b41660 | ||
|
|
dc9ba2d3ef | ||
|
|
759ad04eb8 | ||
|
|
7cef148b5a | ||
|
|
5076355822 | ||
|
|
40caf57cf5 | ||
|
|
ecf042991c | ||
|
|
be339b3c83 | ||
|
|
3b2d680c5b | ||
|
|
92cce1da65 | ||
|
|
be5be5aa39 | ||
|
|
e2555a306f | ||
|
|
3268627916 | ||
|
|
713444e51a | ||
|
|
88418c3372 | ||
|
|
e42d5d8875 | ||
|
|
600f9010d2 | ||
|
|
1c462a63ec | ||
|
|
f7482b68b9 | ||
|
|
df0bc2b3b6 | ||
|
|
653db956f0 | ||
|
|
2070dcf99d | ||
|
|
fd5e39cc76 | ||
|
|
39730a503d | ||
|
|
b645e28167 | ||
|
|
d0c2113693 | ||
|
|
f216eb0d64 | ||
|
|
ddd5b0ff89 | ||
|
|
30fda4cb52 | ||
|
|
d01562f22b | ||
|
|
30f4bdb17e | ||
|
|
b215018067 | ||
|
|
2bcf5a5315 | ||
|
|
4f5b4662b6 | ||
|
|
306a3c0803 | ||
|
|
987ad32fac | ||
|
|
8fed1b6461 | ||
|
|
8643bbab84 | ||
|
|
037549c405 | ||
|
|
3c7b04d015 | ||
|
|
63f3ad3e3c | ||
|
|
53bc8905ab | ||
|
|
08c2728ed1 | ||
|
|
4d2f5754af | ||
|
|
d2597e3496 | ||
|
|
c3fd94cd4d | ||
|
|
08026c7ded | ||
|
|
9f1c439335 | ||
|
|
ebfdb50ac7 | ||
|
|
4716c56ebb | ||
|
|
0697288b9d | ||
|
|
1b25b76921 | ||
|
|
b6d40b3c4e | ||
|
|
ae4cd57ed5 | ||
|
|
0c35bda762 | ||
|
|
ee359d6ffa | ||
|
|
a89d9e0fa6 | ||
|
|
b735182ae0 | ||
|
|
408b362169 | ||
|
|
cd3b58622c | ||
|
|
45a73c113f | ||
|
|
92338f2e29 | ||
|
|
04361b0ad5 | ||
|
|
4444b168db | ||
|
|
5fbbc312a7 | ||
|
|
39df399d9f | ||
|
|
f286c845b0 | ||
|
|
1e7d666bf5 | ||
|
|
62bd5cb08c | ||
|
|
8715be1e4b | ||
|
|
62e15bb06d | ||
|
|
f4ae230d41 | ||
|
|
cdce681cf7 | ||
|
|
39004d3b33 | ||
|
|
7365400610 | ||
|
|
5fa60c1ce9 | ||
|
|
48c44fe6d4 | ||
|
|
fcc9ac7bd8 | ||
|
|
f0edf07fbc | ||
|
|
6914a4cda3 | ||
|
|
8058d64dda | ||
|
|
63989e98ac | ||
|
|
7fd61f9403 | ||
|
|
4dbad65bfd | ||
|
|
2774b497a6 | ||
|
|
3c83a9d503 | ||
|
|
bd3b310eae | ||
|
|
f8cb0ac141 | ||
|
|
16dec1ff58 | ||
|
|
f7225db822 | ||
|
|
09d6cf89df | ||
|
|
9437ea08e1 | ||
|
|
2b5b777c07 | ||
|
|
b686b5c161 | ||
|
|
f713984886 | ||
|
|
98961e86b8 | ||
|
|
4abd58aa8f | ||
|
|
f57585a599 | ||
|
|
bb60622250 | ||
|
|
62cf6a77cf | ||
|
|
44aa8ef997 | ||
|
|
b9cb29076f | ||
|
|
47b6e5d038 | ||
|
|
0893b5fb79 | ||
|
|
89935864e9 | ||
|
|
9e70c6887a | ||
|
|
b42681c4e9 | ||
|
|
59c3b17ad0 | ||
|
|
0500345513 | ||
|
|
ecc920682e | ||
|
|
1d8788464e | ||
|
|
927d5ff89c | ||
|
|
3de17e9185 | ||
|
|
40652a8879 | ||
|
|
7845f51178 | ||
|
|
a449709441 | ||
|
|
468cf3cdc2 | ||
|
|
bfe287f4a4 | ||
|
|
11a0b41370 | ||
|
|
c586445894 | ||
|
|
d45f0e1d9e | ||
|
|
f998e7e3c2 | ||
|
|
00ba6967b1 | ||
|
|
01bd7d1024 | ||
|
|
a321b28916 | ||
|
|
2ae84702ad | ||
|
|
858e522b4e | ||
|
|
34a3b35b08 | ||
|
|
e97c35b3bc | ||
|
|
d975e6630f | ||
|
|
f5c66f311a | ||
|
|
a8ac23c73c | ||
|
|
123b57db36 | ||
|
|
6de4dfcc8c | ||
|
|
c068c3c771 | ||
|
|
9c02bd1021 | ||
|
|
e8ac7cf6ec | ||
|
|
c2cf69fcc4 | ||
|
|
c3a715123b | ||
|
|
46bd46f253 | ||
|
|
d3fed6f400 | ||
|
|
bba5a1780d | ||
|
|
e42f7d2722 | ||
|
|
79ddedabf8 | ||
|
|
f81debe1c8 | ||
|
|
737e658602 | ||
|
|
3b53680458 | ||
|
|
e97ed8d9b6 | ||
|
|
f6b996f6fc | ||
|
|
8109e924b5 | ||
|
|
9d398572f0 | ||
|
|
986b364fe6 | ||
|
|
d799d7358d | ||
|
|
f386fab2e2 | ||
|
|
f00f521e9c | ||
|
|
bff7dbeef9 | ||
|
|
1e711dcccb | ||
|
|
9c81a45279 | ||
|
|
5d2dd94cf8 | ||
|
|
b983df403a | ||
|
|
67092442d6 | ||
|
|
7ba786dedb | ||
|
|
4c03d814ed | ||
|
|
31988745fc | ||
|
|
a90f4c4ffa | ||
|
|
0af8bbd49b | ||
|
|
8a4f098dee | ||
|
|
eba66665a5 | ||
|
|
221e1bc2a3 | ||
|
|
0725fcad38 | ||
|
|
ad01bca9fd | ||
|
|
3f16408405 | ||
|
|
1d706f328c | ||
|
|
8a2305fe1a | ||
|
|
a938db2170 | ||
|
|
fb87022115 | ||
|
|
65abbca79b | ||
|
|
84878f18d2 | ||
|
|
81d3584116 | ||
|
|
27b709cc75 | ||
|
|
4a6c66288f | ||
|
|
5f9d4b5db4 | ||
|
|
62337d433f | ||
|
|
d7dfa2dc4b | ||
|
|
2fd967136a | ||
|
|
6b937ed5f6 | ||
|
|
3697560f04 | ||
|
|
2941a480cd | ||
|
|
ee3ba3cac9 | ||
|
|
8c82b0f2d0 | ||
|
|
4379e16996 | ||
|
|
b1af79acc7 | ||
|
|
4b1c70de90 | ||
|
|
2c81fa9013 | ||
|
|
933ed9d537 | ||
|
|
5c6b50027a | ||
|
|
3bd4318fcc | ||
|
|
920a2e730b | ||
|
|
f693c9b1a7 | ||
|
|
d2bbd4d81c | ||
|
|
49a32c076c | ||
|
|
3b45759849 | ||
|
|
ccfe682508 | ||
|
|
db82318477 | ||
|
|
8c4d5d5623 |
+55
-20
@@ -7,6 +7,9 @@ variables:
|
||||
CI_REGISTRY_IMAGE: registry.gitlab.isc.org/isc-projects/images/bind9
|
||||
CCACHE_DIR: "/ccache"
|
||||
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
||||
OPENSSL_ENGINES: "/usr/lib/x86_64-linux-gnu/engines-1.1"
|
||||
DEFAULT_OPENSSL_CONF: "/etc/ssl/openssl.cnf"
|
||||
OPENSSL_CONF: "/var/tmp/etc/openssl.cnf"
|
||||
|
||||
GIT_DEPTH: 1
|
||||
BUILD_PARALLEL_JOBS: 6
|
||||
@@ -309,15 +312,10 @@ stages:
|
||||
sudo sh -x bin/tests/system/ifconfig.sh up;
|
||||
fi
|
||||
|
||||
.setup_softhsm: &setup_softhsm
|
||||
- export SLOT=$(sh -x bin/tests/prepare-softhsm2.sh)
|
||||
- test -n "${SLOT}" && test "${SLOT}" -gt 0
|
||||
|
||||
.system_test_common: &system_test_common
|
||||
<<: *default_triggering_rules
|
||||
stage: system
|
||||
before_script:
|
||||
- *setup_softhsm
|
||||
- *retrieve_out_of_tree_workspace
|
||||
- *setup_interfaces
|
||||
script:
|
||||
@@ -325,6 +323,7 @@ stages:
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k check V=1
|
||||
- if git rev-parse > /dev/null 2>&1; then ( ! grep "^I:.*:file.*not removed$" *.log ); fi
|
||||
after_script:
|
||||
- (source bin/tests/system/conf.sh; $PYTHON bin/tests/convert-trs-to-junit.py . > junit.xml)
|
||||
- test -n "${OUT_OF_TREE_WORKSPACE}" && cd "${OUT_OF_TREE_WORKSPACE}"
|
||||
- test -d bind-* && cd bind-*
|
||||
- cat bin/tests/system/test-suite.log
|
||||
@@ -335,7 +334,9 @@ stages:
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 day"
|
||||
when: on_failure
|
||||
when: always
|
||||
reports:
|
||||
junit: junit.xml
|
||||
|
||||
.system_test_gcov: &system_test_gcov_job
|
||||
<<: *system_test_common
|
||||
@@ -349,20 +350,23 @@ stages:
|
||||
after_script:
|
||||
- cat bin/tests/system/test-suite.log
|
||||
- find bin -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
|
||||
- (source bin/tests/system/conf.sh; $PYTHON bin/tests/convert-trs-to-junit.py . > junit.xml)
|
||||
artifacts:
|
||||
expire_in: "1 day"
|
||||
untracked: true
|
||||
when: on_failure
|
||||
when: always
|
||||
reports:
|
||||
junit: junit.xml
|
||||
|
||||
.unit_test_common: &unit_test_common
|
||||
<<: *default_triggering_rules
|
||||
stage: unit
|
||||
before_script:
|
||||
- *setup_softhsm
|
||||
- *retrieve_out_of_tree_workspace
|
||||
script:
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k unit V=1
|
||||
after_script:
|
||||
- (source bin/tests/system/conf.sh; $PYTHON bin/tests/convert-trs-to-junit.py . > junit.xml)
|
||||
- *save_out_of_tree_workspace
|
||||
|
||||
.unit_test: &unit_test_job
|
||||
@@ -370,7 +374,9 @@ stages:
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 day"
|
||||
when: on_failure
|
||||
when: always
|
||||
reports:
|
||||
junit: junit.xml
|
||||
|
||||
.unit_test_gcov: &unit_test_gcov_job
|
||||
<<: *unit_test_common
|
||||
@@ -383,12 +389,16 @@ stages:
|
||||
<<: *unit_test_common
|
||||
after_script:
|
||||
- find lib -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
|
||||
- (source bin/tests/system/conf.sh; $PYTHON bin/tests/convert-trs-to-junit.py . > junit.xml)
|
||||
artifacts:
|
||||
expire_in: "1 day"
|
||||
paths:
|
||||
- lib/*/tests/tsan.*
|
||||
- tsan/
|
||||
when: on_failure
|
||||
- junit.xml
|
||||
when: always
|
||||
reports:
|
||||
junit: junit.xml
|
||||
|
||||
.docs: &docs_job
|
||||
stage: docs
|
||||
@@ -397,9 +407,6 @@ stages:
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k doc V=1
|
||||
- qpdf --check doc/arm/_build/latex/Bv9ARM.pdf
|
||||
- find doc/man/ -maxdepth 1 -name "*.[0-9]" -exec mandoc -T lint "{}" \; | ( ! grep -v -e "skipping paragraph macro. sp after" -e "unknown font, skipping request. ft C" )
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 month"
|
||||
|
||||
### Job Definitions
|
||||
|
||||
@@ -508,16 +515,19 @@ tarball-create:
|
||||
- autoreconf -fi
|
||||
- ./configure --enable-maintainer-mode
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} all V=1
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; git diff > diff.patch; exit 1; fi
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} dist V=1
|
||||
artifacts:
|
||||
paths:
|
||||
- diff.patch
|
||||
- bind-*.tar.${TARBALL_EXTENSION}
|
||||
when: always
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
|
||||
# Jobs for doc builds on Debian 11 "bullseye" (amd64)
|
||||
# Long "docs" job artifact retention is needed for bind.isc.org web site
|
||||
|
||||
docs:
|
||||
<<: *release_branch_triggering_rules
|
||||
@@ -528,9 +538,12 @@ docs:
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 month"
|
||||
|
||||
docs:tarball:
|
||||
<<: *schedules_tags_web_triggering_rules
|
||||
<<: *default_triggering_rules
|
||||
<<: *base_image
|
||||
<<: *docs_job
|
||||
before_script:
|
||||
@@ -679,6 +692,7 @@ unit:gcc:buster:amd64:
|
||||
artifacts: true
|
||||
|
||||
# Jobs for regular GCC builds on Debian 11 "bullseye" (amd64)
|
||||
# (The second unit test job also executes unstable unit tests.)
|
||||
|
||||
gcc:bullseye:amd64:
|
||||
variables:
|
||||
@@ -702,6 +716,20 @@ unit:gcc:bullseye:amd64:
|
||||
- job: gcc:bullseye:amd64
|
||||
artifacts: true
|
||||
|
||||
unit:gcc:bullseye:unstable:amd64:
|
||||
<<: *debian_bullseye_amd64_image
|
||||
<<: *unit_test_job
|
||||
variables:
|
||||
CI_ENABLE_ALL_TESTS: 1
|
||||
needs:
|
||||
- job: gcc:bullseye:amd64
|
||||
artifacts: true
|
||||
only:
|
||||
- api
|
||||
- schedules
|
||||
- triggers
|
||||
- web
|
||||
|
||||
# Jobs for cross-compiled GCC builds on Debian 11 "bullseye" (amd64) with
|
||||
# 32-bit libraries
|
||||
|
||||
@@ -930,13 +958,17 @@ unit:gcc:focal:amd64:
|
||||
gcc:asan:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined"
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -Wno-error=stringop-overread"
|
||||
LDFLAGS: "-fsanitize=address,undefined"
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --without-jemalloc"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:asan:
|
||||
variables:
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
LSAN_OPTIONS: "suppressions=$CI_PROJECT_DIR/suppr-lsan.txt"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *system_test_job
|
||||
needs:
|
||||
@@ -980,12 +1012,14 @@ gcc:tsan:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread"
|
||||
LDFLAGS: "-fsanitize=thread"
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:tsan:
|
||||
variables:
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
TSAN_OPTIONS: ${TSAN_OPTIONS_COMMON}
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *system_test_tsan_job
|
||||
@@ -1186,10 +1220,10 @@ release:
|
||||
)
|
||||
- test "$(md5sum cov-analysis-linux64.tgz | awk '{ print $1 }')" = "$(cat cov-analysis-linux64.md5)"
|
||||
- tar --extract --gzip --file=cov-analysis-linux64.tgz
|
||||
- test -d cov-analysis-linux64-2020.09
|
||||
- test -d cov-analysis-linux64-2021.12.1
|
||||
|
||||
.coverity_build: &coverity_build
|
||||
- cov-analysis-linux64-2020.09/bin/cov-build --dir cov-int sh -c 'make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1'
|
||||
- cov-analysis-linux64-2021.12.1/bin/cov-build --dir cov-int sh -c 'make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1'
|
||||
- tar --create --gzip --file=cov-int.tar.gz cov-int/
|
||||
- curl -v https://scan.coverity.com/builds?project=$COVERITY_SCAN_PROJECT_NAME
|
||||
--form token=$COVERITY_SCAN_TOKEN
|
||||
@@ -1225,7 +1259,7 @@ coverity:
|
||||
- $COVERITY_SCAN_PROJECT_NAME
|
||||
- $COVERITY_SCAN_TOKEN
|
||||
cache:
|
||||
key: cov-analysis-linux64-2020.09
|
||||
key: cov-analysis-linux64-2021.12.1
|
||||
paths:
|
||||
- cov-analysis-linux64.md5
|
||||
- cov-analysis-linux64.tgz
|
||||
@@ -1297,7 +1331,6 @@ respdiff-third-party:
|
||||
script:
|
||||
- *configure
|
||||
- *setup_interfaces
|
||||
- *setup_softhsm
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||
- make DESTDIR="${INSTALL_PATH}" install
|
||||
- git clone --depth 1 https://gitlab-ci-token:${CI_JOB_TOKEN}@gitlab.isc.org/isc-private/bind-qa.git
|
||||
@@ -1411,6 +1444,8 @@ gcov:
|
||||
# Help gcovr process the nasty tricks in lib/dns/code.h, where we include C
|
||||
# source files from lib/dns/rdata/*/, using an even nastier trick.
|
||||
- find lib/dns/rdata/* -name "*.c" -execdir cp -f "{}" ../../ \;
|
||||
# Help gcovr process inline function in the isc/hash.h
|
||||
- cp -f lib/isc/include/isc/hash.h lib/dns/hash.h
|
||||
# Generate XML file in the Cobertura XML format suitable for use by GitLab
|
||||
# for the purpose of displaying code coverage information in the diff view
|
||||
# of a given merge request.
|
||||
|
||||
@@ -40,16 +40,11 @@
|
||||
|
||||
### Before the Tagging Deadline
|
||||
|
||||
- [ ] ***(QA)*** Look for outstanding documentation issues (e.g. `CHANGES` mistakes) and address them if any are found.
|
||||
- [ ] ***(QA)*** Ensure release notes are correct, ask Support and Marketing to check them as well.
|
||||
- [ ] ***(QA)*** Update API files for libraries with new version information.
|
||||
- [ ] ***(QA)*** Change software version and library versions in `configure.ac` (new major release only).
|
||||
- [ ] ***(QA)*** Rebuild `configure` using Autoconf on `docs.isc.org`.
|
||||
- [ ] ***(QA)*** Update BIND 9 version in `configure.ac` (9.18+) or `version` (9.16).
|
||||
- [ ] ***(QA)*** Rebuild `configure` using Autoconf on `docs.isc.org` (9.16).
|
||||
- [ ] ***(QA)*** Update `CHANGES`.
|
||||
- [ ] ***(QA)*** Update `CHANGES.SE` (Subscription Edition only).
|
||||
- [ ] ***(QA)*** Update `README.md`.
|
||||
- [ ] ***(QA)*** Update `version`.
|
||||
- [ ] ***(QA)*** Build documentation on `docs.isc.org`.
|
||||
- [ ] ***(QA)*** Check that the formatting is correct for text, PDF, and HTML versions of release notes.
|
||||
- [ ] ***(QA)*** Check that the formatting of the generated man pages is correct.
|
||||
- [ ] ***(QA)*** Tag the releases in the private repository (`git tag -s -m "BIND 9.x.y" v9_x_y`).
|
||||
@@ -77,17 +72,15 @@
|
||||
- [ ] ***(Support)*** Update tickets in case of waiting support customers.
|
||||
- [ ] ***(QA)*** Build and test any outstanding private packages.
|
||||
- [ ] ***(QA)*** Build public RPMs.
|
||||
- [ ] ***(SwEng) *** Build Debian/Ubuntu packages.
|
||||
- [ ] ***(SwEng) *** Update Docker images.
|
||||
- [ ] ***(SwEng)*** Build Debian/Ubuntu packages.
|
||||
- [ ] ***(SwEng)*** Update Docker images.
|
||||
- [ ] ***(QA)*** Inform Marketing of the release.
|
||||
- [ ] ***(QA)*** Update the internal [BIND release dates wiki page](https://wiki.isc.org/bin/view/Main/BindReleaseDates) when public announcement has been made.
|
||||
- [ ] ***(Marketing)*** Post short note to Twitter.
|
||||
- [ ] ***(Marketing)*** Update [Wikipedia entry for BIND](https://en.wikipedia.org/wiki/BIND).
|
||||
- [ ] ***(Marketing)*** Write blog article (if a major release).
|
||||
- [ ] ***(QA)*** Ensure all new tags are annotated and signed.
|
||||
- [ ] ***(QA)*** Push tags for the published releases to the public repository.
|
||||
- [ ] ***(QA)*** Merge the automatically prepared `prep 9.x.y` commit which updates `version` and documentation on the release branch into the relevant maintenance branch (`v9_x`).
|
||||
- [ ] ***(QA)*** For each maintained branch, update the `BIND_BASELINE_VERSION` variable for the `abi-check` job in `.gitlab-ci.yml` to the latest published BIND version tag for a given branch.
|
||||
- [ ] ***(QA)*** Prepare empty release notes for the next set of releases.
|
||||
- [ ] ***(QA)*** Sanitize confidential issues which are assigned to the current release milestone and do not describe a security vulnerability, then make them public.
|
||||
- [ ] ***(QA)*** Sanitize confidential issues which are assigned to older release milestones and describe security vulnerabilities, then make them public if appropriate[^2].
|
||||
|
||||
+15
-8
@@ -33,6 +33,11 @@ Files: **/*.after*
|
||||
bin/tests/system/checkzone/zones/bad1.db
|
||||
bin/tests/system/checkzone/zones/crashzone.db
|
||||
bin/tests/system/dnstap/large-answer.fstrm
|
||||
bin/tests/system/doth/CA/CA.cfg
|
||||
bin/tests/system/doth/CA/README
|
||||
bin/tests/system/doth/CA/index.txt
|
||||
bin/tests/system/doth/CA/index.txt.attr
|
||||
bin/tests/system/doth/CA/serial
|
||||
bin/tests/system/notify/ns4/named.port.in
|
||||
bin/tests/system/formerr/nametoolong
|
||||
bin/tests/system/formerr/noquestions
|
||||
@@ -42,16 +47,8 @@ Files: **/*.after*
|
||||
bin/tests/system/journal/ns2/managed-keys.bind.in
|
||||
bin/tests/system/journal/ns2/managed-keys.bind.jnl.in
|
||||
bin/tests/system/keepalive/expected
|
||||
bin/tests/system/legacy/ns10/named.ednsrefused
|
||||
bin/tests/system/legacy/ns2/named.dropedns
|
||||
bin/tests/system/legacy/ns3/named.dropedns
|
||||
bin/tests/system/legacy/ns3/named.notcp
|
||||
bin/tests/system/legacy/ns5/named.notcp
|
||||
bin/tests/system/legacy/ns6/edns512.db.signed
|
||||
bin/tests/system/legacy/ns7/edns512-notcp.db.signed
|
||||
bin/tests/system/legacy/ns7/named.notcp
|
||||
bin/tests/system/legacy/ns8/named.ednsformerr
|
||||
bin/tests/system/legacy/ns9/named.ednsnotimp
|
||||
bin/tests/system/nsupdate/commandlist
|
||||
bin/tests/system/nsupdate/verylarge.in
|
||||
bin/tests/system/org.isc.bind.system.plist
|
||||
@@ -134,6 +131,16 @@ Files: **/.clang-format
|
||||
**/.gitattributes
|
||||
**/.gitignore
|
||||
**/named*.args
|
||||
**/named.dropedns
|
||||
**/named.ednsformerr
|
||||
**/named.ednsnotimp
|
||||
**/named.ednsrefused
|
||||
**/named.maxudp1460
|
||||
**/named.maxudp512
|
||||
**/named.noaa
|
||||
**/named.noedns
|
||||
**/named.nosoa
|
||||
**/named.notcp
|
||||
**/startme
|
||||
.clang-format
|
||||
.clang-format.headers
|
||||
|
||||
@@ -1,3 +1,285 @@
|
||||
5865. [func] Make statistics channel and control channel listen
|
||||
on a single network manager thread. [GL !6032]
|
||||
|
||||
5864. [func] The OID embedded at the start of a PRIVATEOID public
|
||||
key in a KEY, DNSKEY, CDNSKEY, or RKEY RR is now
|
||||
checked for validity when reading from wire or from
|
||||
zone files, and the OID is printed when
|
||||
'dig +rrcomments' is used. Similarly, the name
|
||||
embedded at the start of a PRIVATEDNS public key
|
||||
is also checked for validity. [GL #3234]
|
||||
|
||||
5863. [bug] If there was a pending negative cache DS entry,
|
||||
validations depending upon it could fail. [GL #3279]
|
||||
|
||||
5862. [bug] dig returned a 0 exit status on UDP connection failure.
|
||||
[GL #3235]
|
||||
|
||||
5861. [func] Implement support for catalog zones change of ownership
|
||||
(coo) mechanism described in the DNS catalog zones draft
|
||||
version 5 document. [GL #3223]
|
||||
|
||||
5860. [func] Implement support for catalog zones options new syntax
|
||||
based on catalog zones custom properties with "ext"
|
||||
suffix described in the DNS catalog zones draft version
|
||||
5 document. [GL #3222]
|
||||
|
||||
5859. [bug] Fix an assertion failure when using dig with +nssearch
|
||||
and +tcp options by starting the next query in the
|
||||
send_done() callback (like in the UDP mode) instead
|
||||
of doing that recursively in start_tcp(). Also
|
||||
ensure that queries interrupted while connecting
|
||||
are detached properly. [GL #3144]
|
||||
|
||||
5858. [bug] Don't remove CDS/CDNSKEY DELETE records on zone sign
|
||||
when using 'auto-dnssec maintain;'. [GL #2931]
|
||||
|
||||
5857. [bug] Fixed a possible crash during shutdown due to ADB
|
||||
entries being unlinked from the hash table too
|
||||
soon. [GL #3256]
|
||||
|
||||
--- 9.19.0 released ---
|
||||
|
||||
5856. [bug] The "starting maxtime timer" message related to outgoing
|
||||
zone transfers was incorrectly logged at the ERROR level
|
||||
instead of DEBUG(1). [GL #3208]
|
||||
|
||||
5855. [bug] Ensure that zone maintenance queries have a retry limit.
|
||||
[GL #3242]
|
||||
|
||||
5854. [func] Implement reference counting for TLS contexts and
|
||||
allow reloading of TLS certificates on reconfiguration
|
||||
without destroying the underlying TCP listener sockets
|
||||
for TLS-based DNS transports. [GL #3122]
|
||||
|
||||
5853. [bug] When using both the `+qr` and `+y` options `dig` could
|
||||
crash if the connection to the first server was not
|
||||
successful. [GL #3244]
|
||||
|
||||
5852. [func] Add new "reuseport" option to enable/disable load
|
||||
balancing of sockets. [GL #3249]
|
||||
|
||||
5851. [placeholder]
|
||||
|
||||
5850. [func] Run the RPZ update process on the offload threads.
|
||||
[GL #3190]
|
||||
|
||||
5849. [cleanup] Remove use of exclusive mode in ns_interfacemgr in
|
||||
favor of rwlocked access to localhost and localnets
|
||||
members of dns_aclenv_t structure. [GL #3229]
|
||||
|
||||
5848. [bug] dig could hang in some cases involving multiple servers
|
||||
in a lookup, when a request fails and the next one
|
||||
refuses to start for some reason, for example if it was
|
||||
an IPv4 mapped IPv6 address. [GL #3248]
|
||||
|
||||
5847. [cleanup] Remove task privileged mode in favor of processing
|
||||
all events in the loadzone task in a single run
|
||||
by setting the quantum to UINT_MAX. [GL #3253]
|
||||
|
||||
5846. [func] In dns_zonemgr, create per-thread task, zonetask, and
|
||||
loadtask and pin the zones to individual threads,
|
||||
instead of having "many", spreading the zones among
|
||||
them and hoping for the best. This also removes any
|
||||
need to dynamically reallocate the pools with memory
|
||||
contexts and tasks. [GL #3226]
|
||||
|
||||
5845. [bug] Refactor the timer to keep track of posted events
|
||||
as to use isc_task_purgeevent() instead of using
|
||||
isc_task_purgerange(). The isc_task_purgeevent()
|
||||
has been refactored to purge a single event instead
|
||||
of walking through the list of posted events.
|
||||
[GL #3252]
|
||||
|
||||
5844. [bug] dig +nssearch was hanging until manually interrupted.
|
||||
[GL #3145]
|
||||
|
||||
5843. [bug] When an UPDATE targets a zone that is not configured,
|
||||
the requested zone name is now logged in the "not
|
||||
authoritative" error message, so that it is easier to
|
||||
track down problematic update clients. [GL #3209]
|
||||
|
||||
5842. [cleanup] Remove the task exclusive mode use in ns_clientmgr.
|
||||
[GL #3230]
|
||||
|
||||
5841. [bug] Refactor the address database:
|
||||
- Use self-resizing hash tables, eliminating the
|
||||
need to go into task-exclusive mode when resizing.
|
||||
- Simplify reference counting of ADB objects
|
||||
and the process for shutting down. [GL #3213]
|
||||
|
||||
5840. [cleanup] Remove multiple application context use in dns_client
|
||||
unit. [GL !6041]
|
||||
|
||||
5839. [func] Add support for remote TLS certificates
|
||||
verification, both to BIND and dig, making it possible
|
||||
to implement Strict and Mutual TLS authentication,
|
||||
as described in RFC 9103, Section 9.3. [GL #3163]
|
||||
|
||||
5838. [cleanup] When modifying a member zone in a catalog zone, and it
|
||||
is detected that the zone exists and was not created by
|
||||
the current catalog zone, distinguish the two cases when
|
||||
the zone was not added by a catalog zone at all, and
|
||||
when the zone was added by a different catalog zone,
|
||||
and log a warning message accordingly. [GL #3221]
|
||||
|
||||
5837. [func] Key timing options for `dnssec-keygen` and
|
||||
`dnssec-settime` now accept times as printed by
|
||||
`dnssec-settime -p`. [GL !2947]
|
||||
|
||||
5836. [bug] Quote the dns64 prefix in error messages that complain
|
||||
about problems with it, to avoid confusion with the
|
||||
following dns64 ACLs. [GL #3210]
|
||||
|
||||
5835. [cleanup] Remove extrahandlesize from the netmgr, the callers
|
||||
now have to allocate the object before calling
|
||||
isc_nm_setdata() and deallocate the memory in the close
|
||||
callback passed to isc_nm_setdata(). [GL #3227]
|
||||
|
||||
5834. [cleanup] C99 variable-length arrays are difficult to use safely,
|
||||
so avoid them except in test code. [GL #3201]
|
||||
|
||||
5833. [bug] When encountering socket error while trying to initiate
|
||||
a TCP connection to a server, dig could hang
|
||||
indefinitely, when there were more servers to try.
|
||||
[GL #3205]
|
||||
|
||||
5832. [bug] When timing-out or having other types of socket errors
|
||||
during a query, dig wasn't trying to perform the lookup
|
||||
using other servers, in case they exist. [GL #3128]
|
||||
|
||||
5831. [bug] When resending a UDP request in the result of a timeout,
|
||||
the recv_done() function in dighost.c was prepending
|
||||
the new query into the loookup's queries list instead
|
||||
of inserting, which could cause an assertion failure
|
||||
when the resent query's result was SERVFAIL. [GL #3020]
|
||||
|
||||
5830. [func] Implement incremental resizing of isc_ht hash tables to
|
||||
perform the rehashing gradually. [GL #3212]
|
||||
|
||||
5829. [func] Refactor and simplify isc_timer API in preparation
|
||||
for further refactoring on top of network manager
|
||||
loops. [GL #3202]
|
||||
|
||||
5828. [bug] Replace single TCP write timer with per-TCP write
|
||||
timers. [GL #3200]
|
||||
|
||||
5827. [cleanup] The command-line utilities printed their version numbers
|
||||
inconsistently; they all now print to stdout. (They are
|
||||
still inconsistent abotut whether you use `-v` or `-V`
|
||||
to request the version). [GL #3189]
|
||||
|
||||
5826. [cleanup] Stop dig from complaining about lack of IDN support when
|
||||
the user asks for no IDN translation. [GL #3188]
|
||||
|
||||
5825. [func] Set the minimum MTU on UDPv6 and TCPv6 sockets and
|
||||
limit TCP maximum segment size (TCP_MAXSEG) to (1220)
|
||||
for both TCPv4 and TCPv6 sockets. [GL #2201]
|
||||
|
||||
5824. [bug] Invalid dnssec-policy definitions were being accepted
|
||||
where the defined keys did not cover both KSK and ZSK
|
||||
roles for a given algorithm. This is now checked for
|
||||
and the dnssec-policy is rejected if both roles are
|
||||
not present for all algorithms in use. [GL #3142]
|
||||
|
||||
5823. [func] Replace hazard pointers based lock-free list with
|
||||
locked-list based queue that's simpler and has no or
|
||||
little performance impact. [GL #3180]
|
||||
|
||||
5822. [bug] When calling dns_dispatch_send(), attach/detach
|
||||
dns_request_t object as the read callback could
|
||||
be called before send callback dereferencing
|
||||
dns_request_t object too early. [GL #3105]
|
||||
|
||||
5821. [bug] Fix query context management issues in the TCP part
|
||||
of dig. [GL #3184]
|
||||
|
||||
5820. [security] An assertion could occur in resume_dslookup() if the
|
||||
fetch had been shut down earlier. (CVE-2022-0667)
|
||||
[GL #3129]
|
||||
|
||||
5819. [security] Lookups involving a DNAME could trigger an INSIST when
|
||||
"synth-from-dnssec" was enabled. (CVE-2022-0635)
|
||||
[GL #3158]
|
||||
|
||||
5818. [security] A synchronous call to closehandle_cb() caused
|
||||
isc__nm_process_sock_buffer() to be called recursively,
|
||||
which in turn left TCP connections hanging in the
|
||||
CLOSE_WAIT state blocking indefinitely when
|
||||
out-of-order processing was disabled. (CVE-2022-0396)
|
||||
[GL #3112]
|
||||
|
||||
5817. [security] The rules for acceptance of records into the cache
|
||||
have been tightened to prevent the possibility of
|
||||
poisoning if forwarders send records outside
|
||||
the configured bailiwick. (CVE-2021-25220) [GL #2950]
|
||||
|
||||
5816. [bug] Make BIND compile with LibreSSL 3.5.0, as it was using
|
||||
not very accurate pre-processor checks for using shims.
|
||||
[GL #3172]
|
||||
|
||||
5815. [bug] If an oversized key name of a specific length was used
|
||||
in the text form of an HTTP or SVBC record, an INSIST
|
||||
could be triggered when parsing it. [GL #3175]
|
||||
|
||||
5814. [bug] The RecursClients statistics counter could underflow
|
||||
in certain resolution scenarios. [GL #3147]
|
||||
|
||||
5813. [func] The "keep-response-order" ACL has been declared
|
||||
obsolete, and is now non-operational. [GL #3140]
|
||||
|
||||
5812. [func] Drop the artificial limit on the number of queries
|
||||
processed in a single TCP read callback. [GL #3141]
|
||||
|
||||
5811. [bug] Reimplement the maximum and idle timeouts for outgoing
|
||||
zone tranfers. [GL #1897]
|
||||
|
||||
5810. [func] New option '-J' for dnssec-signzone and dnssec-verify
|
||||
allows loading journal files. [GL #2486]
|
||||
|
||||
5809. [bug] Reset client TCP connection when data received cannot
|
||||
be parsed as a valid DNS request. [GL #3149]
|
||||
|
||||
5808. [bug] Certain TCP failures were not caught and handled
|
||||
correctly by the dispatch manager, causing
|
||||
connections to time out rather than returning
|
||||
SERVFAIL. [GL #3133]
|
||||
|
||||
5807. [bug] Add a TCP "write" timer, and time out writing
|
||||
connections after the "tcp-idle-timeout" period
|
||||
has elapsed. [GL #3132]
|
||||
|
||||
5806. [bug] An error in checking the "blackhole" ACL could cause
|
||||
DNS requests sent by named to fail if the
|
||||
destination address or prefix was specifically
|
||||
excluded from the ACL. [GL #3157]
|
||||
|
||||
5805. [func] The result of each resolver priming attempt is now
|
||||
included in the "resolver priming query complete" log
|
||||
message. [GL #3139]
|
||||
|
||||
5804. [func] Add a debug log message when starting and ending
|
||||
the task exclusive mode. [GL #3137]
|
||||
|
||||
5803. [func] Use compile-time paths in the documentation.
|
||||
[GL #2717]
|
||||
|
||||
5802. [test] Add system test to test engine_pkcs11. [GL !5727]
|
||||
|
||||
5801. [bug] Log "quota reached" message when hard quota
|
||||
is reached when accepting a connection. [GL #3125]
|
||||
|
||||
5800. [func] Add ECS support to the DLZ interface. [GL #3082]
|
||||
|
||||
5799. [bug] Use L1 cache-line size detected at runtime. [GL #3108]
|
||||
|
||||
5798. [test] Add system test to test dnssec-keyfromlabel. [GL #3092]
|
||||
|
||||
5797. [bug] A failed view configuration during a named
|
||||
reconfiguration procedure could cause inconsistencies
|
||||
in BIND internal structures, causing a crash or other
|
||||
unexpected errors. [GL #3060]
|
||||
|
||||
5796. [bug] Ignore the invalid (<= 0) values returned
|
||||
by the sysconf() check for the L1 cache line
|
||||
size. [GL #3108]
|
||||
@@ -19,8 +301,6 @@
|
||||
when receiving NOTIFY query with SOA record in
|
||||
ANSWER section. [GL #3086]
|
||||
|
||||
--- 9.17.22 released ---
|
||||
|
||||
5790. [bug] The control channel was incorrectly looking for
|
||||
ISC_R_CANCELED as a signal that the named is
|
||||
shutting down. In the dispatch refactoring,
|
||||
@@ -29,6 +309,8 @@
|
||||
channel code to use ISC_R_SHUTTINGDOWN result
|
||||
code to detect named being shut down. [GL #3079]
|
||||
|
||||
--- 9.17.22 released ---
|
||||
|
||||
5789. [bug] Allow replacing expired zone signatures with
|
||||
signatures created by the KSK. [GL #3049]
|
||||
|
||||
|
||||
+32
-10
@@ -9,6 +9,16 @@ AM_V_SPHINX_0 = @echo " SPHINX $@";
|
||||
|
||||
SPHINXBUILDDIR = $(builddir)/_build
|
||||
|
||||
LF = \n
|
||||
RNDC_CONF = .. |rndc_conf| replace:: ``$(sysconfdir)/rndc.conf``
|
||||
RNDC_KEY = .. |rndc_key| replace:: ``$(sysconfdir)/rndc.key``
|
||||
NAMED_CONF = .. |named_conf| replace:: ``$(sysconfdir)/named.conf``
|
||||
BIND_KEYS = .. |bind_keys| replace:: ``$(sysconfdir)/bind.keys``
|
||||
NAMED_PID = .. |named_pid| replace:: ``$(runstatedir)/named.pid``
|
||||
SESSION_KEY = .. |session_key| replace:: ``$(runstatedir)/session.key``
|
||||
|
||||
export RST_EPILOG = $(RNDC_CONF)$(LF)$(RNDC_KEY)$(LF)$(NAMED_CONF)$(LF)$(BIND_KEYS)$(LF)$(NAMED_PID)$(LF)$(SESSION_KEY)
|
||||
|
||||
common_SPHINXOPTS = \
|
||||
-W \
|
||||
-c $(srcdir) \
|
||||
@@ -17,18 +27,30 @@ common_SPHINXOPTS = \
|
||||
|
||||
# The "today" variable set below is not directly used in the ARM, but its value
|
||||
# is implicitly inserted on the title page of the PDF file produced by Sphinx.
|
||||
ALLSPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D today="$(RELEASE_DATE)" \
|
||||
$(SPHINXOPTS) \
|
||||
ALLSPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D today="$(RELEASE_DATE)" \
|
||||
-D rst_epilog="$$(printf "$${RST_EPILOG}")" \
|
||||
$(SPHINXOPTS) \
|
||||
$(srcdir)
|
||||
|
||||
man_SPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D version="@""PACKAGE_VERSION@"\
|
||||
-D today="@""RELEASE_DATE@" \
|
||||
-D release="@""PACKAGE_VERSION@"\
|
||||
$(SPHINXOPTS) \
|
||||
_ = @
|
||||
man_RNDC_CONF = .. |rndc_conf| replace:: ``$(_)sysconfdir$(_)/rndc.conf``
|
||||
man_RNDC_KEY = .. |rndc_key| replace:: ``$(_)sysconfdir$(_)/rndc.key``
|
||||
man_NAMED_CONF = .. |named_conf| replace:: ``$(_)sysconfdir$(_)/named.conf``
|
||||
man_BIND_KEYS = .. |bind_keys| replace:: ``$(_)sysconfdir$(_)/bind.keys``
|
||||
man_NAMED_PID = .. |named_pid| replace:: ``$(_)runstatedir$(_)/named.pid``
|
||||
man_SESSION_KEY = .. |session_key| replace:: ``$(_)runstatedir$(_)/session.key``
|
||||
|
||||
export man_RST_EPILOG = $(man_RNDC_CONF)$(LF)$(man_RNDC_KEY)$(LF)$(man_NAMED_CONF)$(LF)$(man_BIND_KEYS)$(LF)$(man_NAMED_PID)$(LF)$(man_SESSION_KEY)
|
||||
|
||||
man_SPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D version="@""PACKAGE_VERSION@" \
|
||||
-D today="@""RELEASE_DATE@" \
|
||||
-D release="@""PACKAGE_VERSION@" \
|
||||
-D rst_epilog="$$(printf "$${man_RST_EPILOG}")" \
|
||||
$(SPHINXOPTS) \
|
||||
$(srcdir)
|
||||
|
||||
AM_V_SED = $(AM_V_SED_@AM_V@)
|
||||
|
||||
@@ -7,6 +7,9 @@ TESTS = $(check_PROGRAMS)
|
||||
|
||||
LOG_COMPILER = $(builddir)/../../unit-test-driver.sh
|
||||
|
||||
AM_CFLAGS += \
|
||||
$(TEST_CFLAGS)
|
||||
|
||||
AM_CPPFLAGS += \
|
||||
$(CMOCKA_CFLAGS) \
|
||||
-DNAMED_PLUGINDIR=\"$(libdir)/named\" \
|
||||
|
||||
-119
@@ -1,119 +0,0 @@
|
||||
<!--
|
||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
|
||||
SPDX-License-Identifier: MPL-2.0
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
|
||||
See the COPYRIGHT file distributed with this work for additional
|
||||
information regarding copyright ownership.
|
||||
-->
|
||||
## Supported platforms
|
||||
|
||||
In general, this version of BIND will build and run on any POSIX-compliant
|
||||
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
||||
IPv6 support, and POSIX-compliant threads, plus the following mandatory
|
||||
libraries:
|
||||
|
||||
- `libuv` for asynchronous I/O operations and event loops
|
||||
- `libssl` and `libcrypto` from OpenSSL for cryptography
|
||||
|
||||
Use of the following libraries is optional:
|
||||
|
||||
- `libjemalloc` for improved memory allocation performance
|
||||
- `libnghttp2` for DNS-over-HTTPS (DoH) support
|
||||
|
||||
The following C11 features are used in BIND 9:
|
||||
|
||||
* Atomic operations support, either in the form of C11 atomics or
|
||||
`__atomic` builtin operations.
|
||||
|
||||
* Thread Local Storage support, either in the form of C11
|
||||
`_Thread_local`/`thread_local`, or the `__thread` GCC extension.
|
||||
|
||||
The C11 variants are preferred.
|
||||
|
||||
BIND 9.17 requires a fairly recent version of `libuv` (at least 1.x). For
|
||||
some of the older systems listed below, you will have to install an updated
|
||||
`libuv` package from sources such as EPEL, PPA, or other native sources for
|
||||
updated packages. The other option is to build and install `libuv` from
|
||||
source.
|
||||
|
||||
Certain optional BIND features have additional library dependencies.
|
||||
These include:
|
||||
|
||||
* `libfstrm` and `libprotobuf-c` for DNSTAP
|
||||
* `libidn2` for display of internationalized domain names in `dig`
|
||||
* `libjson-c` for JSON statistics
|
||||
* `libmaxminddb` for geolocation
|
||||
* `libnghttp2` for DNS over HTTPS
|
||||
* `libxml2` for XML statistics
|
||||
* `libz` for compression of the HTTP statistics channel
|
||||
* `readline` for line editing in `nsupdate` and `nslookup`
|
||||
|
||||
ISC regularly tests BIND on many operating systems and architectures, but
|
||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||
offer support on a "best effort" basis for some.
|
||||
|
||||
### Regularly tested platforms
|
||||
|
||||
As of Dec 2021, BIND 9.17 is fully supported and regularly tested on the
|
||||
following systems:
|
||||
|
||||
* Debian 9, 10, 11
|
||||
* Ubuntu LTS 18.04, 20.04
|
||||
* Fedora 35
|
||||
* Red Hat Enterprise Linux / CentOS / Oracle Linux 7, 8
|
||||
* FreeBSD 12.3, 13.0
|
||||
* OpenBSD 7.0
|
||||
* Alpine Linux 3.15
|
||||
|
||||
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
||||
|
||||
### Best effort
|
||||
|
||||
The following are platforms on which BIND is known to build and run.
|
||||
ISC makes every effort to fix bugs on these platforms, but may be unable
|
||||
to do so quickly due to lack of hardware, less familiarity on the part
|
||||
of engineering staff, and other constraints. None of these are tested
|
||||
regularly by ISC.
|
||||
|
||||
* macOS 10.12+
|
||||
* Solaris 11
|
||||
* NetBSD
|
||||
* Other Linux distributions still supported by their vendors, such as:
|
||||
* Ubuntu 20.10+
|
||||
* Gentoo
|
||||
* Arch Linux
|
||||
* OpenWRT/LEDE 17.01+
|
||||
* Other CPU architectures (mips, mipsel, sparc, ...)
|
||||
|
||||
### Community maintained
|
||||
|
||||
These systems may not all have the required dependencies for building BIND
|
||||
easily available, although it will be possible in many cases to compile
|
||||
those directly from source. The community and interested parties may wish
|
||||
to help with maintenance, and we welcome patch contributions, although we
|
||||
cannot guarantee that we will accept them. All contributions will be
|
||||
assessed against the risk of adverse effect on officially supported
|
||||
platforms.
|
||||
|
||||
* Platforms past or close to their respective EOL dates, such as:
|
||||
* Ubuntu 14.04, 16.04 (Ubuntu ESM releases are not supported)
|
||||
* CentOS 6
|
||||
* Debian Jessie
|
||||
* FreeBSD 10.x, 11.x
|
||||
|
||||
## Unsupported platforms
|
||||
|
||||
These are platforms on which BIND 9.17 is known *not* to build or run:
|
||||
|
||||
* Platforms without at least OpenSSL 1.0.2
|
||||
* Windows
|
||||
* Solaris 10 and older
|
||||
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
||||
* Platforms that don't support atomic operations (via compiler or library)
|
||||
* Linux without NPTL (Native POSIX Thread Library)
|
||||
* Platforms on which `libuv` cannot be compiled
|
||||
@@ -18,9 +18,6 @@ information regarding copyright ownership.
|
||||
1. [Reporting bugs and getting help](#help)
|
||||
1. [Contributing to BIND](#contrib)
|
||||
1. [Building BIND](#build)
|
||||
1. [macOS](#macos)
|
||||
1. [Dependencies](#dependencies)
|
||||
1. [Compile-time options](#opts)
|
||||
1. [Automated testing](#testing)
|
||||
1. [Documentation](#doc)
|
||||
1. [Change log](#changes)
|
||||
@@ -58,7 +55,9 @@ CHANGES file format.
|
||||
For up-to-date versions and release notes, see
|
||||
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||
|
||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
||||
For information about supported platforms, see the
|
||||
["Supported Platforms"](doc/arm/platforms.rst) section in the BIND 9
|
||||
Administrator Reference Manual.
|
||||
|
||||
### <a name="help"/> Reporting bugs and getting help
|
||||
|
||||
@@ -125,142 +124,9 @@ including your patch as an attachment, preferably generated by
|
||||
|
||||
### <a name="build"/> Building BIND 9
|
||||
|
||||
At a minimum, BIND requires a Unix or Linux system with an ANSI C compiler,
|
||||
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||
`libuv` asynchronous I/O library, the `nghttp2` HTTP/2 library, the
|
||||
`jemalloc` memory allocation library, and the OpenSSL cryptography
|
||||
library. On Linux, BIND requires the `libcap` library to set process
|
||||
privileges, though this requirement can be overridden by disabling
|
||||
capability support at compile time. See [Compile-time options](#opts)
|
||||
below for details on other libraries that may be required to support
|
||||
optional features.
|
||||
|
||||
Successful builds have been observed on many versions of Linux and Unix,
|
||||
including RHEL/CentOS/Oracle Linux, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
||||
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana,
|
||||
OmniOS CE, HP-UX, and OpenWRT.
|
||||
|
||||
To build on a Unix or Linux system, use:
|
||||
|
||||
$ autoreconf -fi (if you are building in the git repository)
|
||||
$ ./configure
|
||||
$ make
|
||||
|
||||
If you're using Emacs, you might find `make tags` helpful.
|
||||
|
||||
Several environment variables, which can be set before running `configure`,
|
||||
affect compilation. Significant ones are:
|
||||
|
||||
|Variable|Description |
|
||||
|--------------------|-----------------------------------------------|
|
||||
|`CC`|The C compiler to use. `configure` tries to figure out the right one for supported systems.|
|
||||
|`CFLAGS`|C compiler flags. Defaults to include -g and/or -O2 as supported by the compiler. Please include '-g' if you need to set `CFLAGS`. |
|
||||
|`LDFLAGS`|Linker flags. Defaults to empty string.|
|
||||
|
||||
Additional environment variables affecting the build are listed at the
|
||||
end of the `configure` help text, which can be obtained by running the
|
||||
command:
|
||||
|
||||
$ ./configure --help
|
||||
|
||||
#### <a name="macos"> macOS
|
||||
|
||||
Building on macOS assumes that the "Command Tools for Xcode" are installed.
|
||||
These can be downloaded from
|
||||
[https://developer.apple.com/download/more/](https://developer.apple.com/download/more/)
|
||||
or, if you have Xcode already installed, you can run `xcode-select --install`.
|
||||
(Note that an Apple ID may be required to access the download page.)
|
||||
|
||||
#### <a name="dependencies"> Dependencies
|
||||
|
||||
To build BIND you need to have the following packages installed:
|
||||
|
||||
libuv
|
||||
pkg-config / pkgconfig / pkgconf
|
||||
|
||||
To build BIND from the git repository, you need the following tools
|
||||
installed:
|
||||
|
||||
autoconf (includes autoreconf)
|
||||
automake
|
||||
libtool
|
||||
|
||||
#### <a name="opts"/> Compile-time options
|
||||
|
||||
To see a full list of configuration options, run `configure --help`.
|
||||
|
||||
For the server to support DNSSEC, you need to build it with crypto support.
|
||||
To use OpenSSL, you must have OpenSSL 1.0.2e or newer installed. If the
|
||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||
using `--with-openssl=<PREFIX>` on the configure command line. To use a
|
||||
PKCS#11 hardware service module for cryptographic operations, it will
|
||||
be necessary to compile and use engine_pkcs11 from the OpenSC project.
|
||||
|
||||
To support DNS over HTTPS, the server must be linked with `libnghttp2`.
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
least one of the following libraries: `libxml2`
|
||||
[http://xmlsoft.org](http://xmlsoft.org) or `json-c`
|
||||
[https://github.com/json-c/json-c](https://github.com/json-c/json-c).
|
||||
If these are installed at a nonstandard location, then:
|
||||
|
||||
* for `libxml2`, specify the prefix using `--with-libxml2=/prefix`.
|
||||
* for `json-c`, adjust `PKG_CONFIG_PATH`.
|
||||
|
||||
To support compression on the HTTP statistics channel, the server must be
|
||||
linked against `libzlib`. If this is installed in a nonstandard location,
|
||||
specify the prefix using `--with-zlib=/prefix`.
|
||||
|
||||
To support storing configuration data for runtime-added zones in an LMDB
|
||||
database, the server must be linked with `liblmdb`. If this is installed in a
|
||||
nonstandard location, specify the prefix using `with-lmdb=/prefix`.
|
||||
|
||||
To support MaxMind GeoIP2 location-based ACLs, the server must be linked
|
||||
with `libmaxminddb`. This is turned on by default if the library is
|
||||
found; if the library is installed in a nonstandard location,
|
||||
specify the prefix using `--with-maxminddb=/prefix`. GeoIP2 support
|
||||
can be switched off with `--disable-geoip`.
|
||||
|
||||
For DNSTAP packet logging, you must have installed `libfstrm`
|
||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||
and `libprotobuf-c`
|
||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
||||
and BIND must be configured with `--enable-dnstap`.
|
||||
|
||||
Certain compiled-in constants and default settings can be decreased to
|
||||
values better suited to small machines, e.g. OpenWRT boxes, by specifying
|
||||
`--with-tuning=small` on the `configure` command line. This decreases
|
||||
memory usage by using smaller structures, but degrades performance.
|
||||
|
||||
On Linux, process capabilities are managed in user space using
|
||||
the `libcap` library, which can be installed on most Linux systems via
|
||||
the `libcap-dev` or `libcap-devel` package. Process capability support can
|
||||
also be disabled by configuring with `--disable-linux-caps`.
|
||||
|
||||
On some platforms it is necessary to explicitly request large file support
|
||||
to handle files bigger than 2GB. This can be done by using
|
||||
`--enable-largefile` on the `configure` command line.
|
||||
|
||||
Support for the "fixed" rrset-order option can be enabled or disabled by
|
||||
specifying `--enable-fixed-rrset` or `--disable-fixed-rrset` on the
|
||||
configure command line. By default, fixed rrset-order is disabled to
|
||||
reduce memory footprint.
|
||||
|
||||
The `--enable-querytrace` option causes `named` to log every step of
|
||||
processing every query. The `--enable-singletrace` option turns on the
|
||||
same verbose tracing, but allows an individual query to be separately
|
||||
traced by setting its query ID to 0. These options should only be enabled
|
||||
when debugging, because they have a significant negative impact on query
|
||||
performance.
|
||||
|
||||
`make install` installs `named` and the various BIND 9 libraries. By
|
||||
default, installation is into /usr/local, but this can be changed with the
|
||||
`--prefix` option when running `configure`.
|
||||
|
||||
You may specify the option `--sysconfdir` to set the directory where
|
||||
configuration files like `named.conf` go by default, and `--localstatedir`
|
||||
to set the default parent directory of `run/named.pid`. `--sysconfdir`
|
||||
defaults to `$prefix/etc` and `--localstatedir` defaults to `$prefix/var`.
|
||||
For information about building BIND 9, see the
|
||||
["Building BIND 9"](doc/arm/build.rst) section in the BIND 9
|
||||
Administrator Reference Manual.
|
||||
|
||||
### <a name="testing"/> Automated testing
|
||||
|
||||
|
||||
@@ -593,7 +593,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||
zonename, filename, classname);
|
||||
}
|
||||
|
||||
CHECK(dns_zone_create(&zone, mctx));
|
||||
CHECK(dns_zone_create(&zone, mctx, 0));
|
||||
|
||||
dns_zone_settype(zone, dns_zone_primary);
|
||||
|
||||
|
||||
@@ -58,7 +58,7 @@ isc_log_t *logc = NULL;
|
||||
} while (0)
|
||||
|
||||
/*% usage */
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -306,8 +306,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRR;
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKDUPRRFAIL;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_CHECKDUPRR;
|
||||
@@ -326,8 +325,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKMX;
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKMXFAIL;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_CHECKMX;
|
||||
@@ -357,8 +355,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
||||
zone_options |= DNS_ZONEOPT_IGNOREMXCNAME;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_WARNMXCNAME;
|
||||
@@ -377,8 +374,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
||||
zone_options |= DNS_ZONEOPT_IGNORESRVCNAME;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_WARNSRVCNAME;
|
||||
@@ -401,8 +397,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKSPF;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_CHECKSPF;
|
||||
@@ -420,8 +415,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKNAMES;
|
||||
zone_options &= ~DNS_ZONEOPT_CHECKNAMESFAIL;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
} else {
|
||||
zone_options |= DNS_ZONEOPT_CHECKNAMES;
|
||||
@@ -437,8 +431,7 @@ configure_zone(const char *vclass, const char *view, const cfg_obj_t *zconfig,
|
||||
} else if (strcasecmp(masterformatstr, "raw") == 0) {
|
||||
masterformat = dns_masterformat_raw;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -677,7 +670,7 @@ main(int argc, char **argv) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
usage();
|
||||
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named-checkconf
|
||||
.. program:: named-checkconf
|
||||
.. _man_named-checkconf:
|
||||
|
||||
named-checkconf - named configuration file syntax checking tool
|
||||
@@ -24,72 +26,83 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named-checkconf`` checks the syntax, but not the semantics, of a
|
||||
``named`` configuration file. The file, along with all files included by it, is parsed and checked for syntax
|
||||
:program:`named-checkconf` checks the syntax, but not the semantics, of a
|
||||
:iscman:`named` configuration file. The file, along with all files included by it, is parsed and checked for syntax
|
||||
errors. If no file is specified,
|
||||
``/etc/named.conf`` is read by default.
|
||||
|named_conf| is read by default.
|
||||
|
||||
Note: files that ``named`` reads in separate parser contexts, such as
|
||||
Note: files that :iscman:`named` reads in separate parser contexts, such as
|
||||
``rndc.key`` and ``bind.keys``, are not automatically read by
|
||||
``named-checkconf``. Configuration errors in these files may cause
|
||||
``named`` to fail to run, even if ``named-checkconf`` was successful.
|
||||
However, ``named-checkconf`` can be run on these files explicitly.
|
||||
:program:`named-checkconf`. Configuration errors in these files may cause
|
||||
:iscman:`named` to fail to run, even if :program:`named-checkconf` was successful.
|
||||
However, :program:`named-checkconf` can be run on these files explicitly.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
``-j``
|
||||
When loading a zonefile, this option instructs ``named`` to read the journal if it exists.
|
||||
.. option:: -j
|
||||
|
||||
When loading a zonefile, this option instructs :iscman:`named` to read the journal if it exists.
|
||||
|
||||
.. option:: -l
|
||||
|
||||
``-l``
|
||||
This option lists all the configured zones. Each line of output contains the zone
|
||||
name, class (e.g. IN), view, and type (e.g. primary or secondary).
|
||||
|
||||
``-c``
|
||||
.. option:: -c
|
||||
|
||||
This option specifies that only the "core" configuration should be checked. This suppresses the loading of
|
||||
plugin modules, and causes all parameters to ``plugin`` statements to
|
||||
be ignored.
|
||||
|
||||
``-i``
|
||||
.. option:: -i
|
||||
|
||||
This option ignores warnings on deprecated options.
|
||||
|
||||
``-p``
|
||||
This option prints out the ``named.conf`` and included files in canonical form if
|
||||
no errors were detected. See also the ``-x`` option.
|
||||
.. option:: -p
|
||||
|
||||
``-t directory``
|
||||
This option instructs ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
||||
This option prints out the :iscman:`named.conf` and included files in canonical form if
|
||||
no errors were detected. See also the :option:`-x` option.
|
||||
|
||||
.. option:: -t directory
|
||||
|
||||
This option instructs :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
``named``.
|
||||
:iscman:`named`.
|
||||
|
||||
``-v``
|
||||
This option prints the version of the ``named-checkconf`` program and exits.
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version of the :program:`named-checkconf` program and exits.
|
||||
|
||||
.. option:: -x
|
||||
|
||||
``-x``
|
||||
When printing the configuration files in canonical form, this option obscures
|
||||
shared secrets by replacing them with strings of question marks
|
||||
(``?``). This allows the contents of ``named.conf`` and related files
|
||||
(``?``). This allows the contents of :iscman:`named.conf` and related files
|
||||
to be shared - for example, when submitting bug reports -
|
||||
without compromising private data. This option cannot be used without
|
||||
``-p``.
|
||||
:option:`-p`.
|
||||
|
||||
``-z``
|
||||
This option performs a test load of all zones of type ``primary`` found in ``named.conf``.
|
||||
.. option:: -z
|
||||
|
||||
This option performs a test load of all zones of type ``primary`` found in :iscman:`named.conf`.
|
||||
|
||||
.. option:: filename
|
||||
|
||||
``filename``
|
||||
This indicates the name of the configuration file to be checked. If not specified,
|
||||
it defaults to ``/etc/named.conf``.
|
||||
it defaults to |named_conf|.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``named-checkconf`` returns an exit status of 1 if errors were detected
|
||||
:program:`named-checkconf` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkzone(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkzone(8) <named-checkzone>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
@@ -65,7 +65,7 @@ static enum { progmode_check, progmode_compile } progmode;
|
||||
} \
|
||||
} while (0)
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -147,8 +147,7 @@ main(int argc, char **argv) {
|
||||
} else if (PROGCMP("named-compilezone")) {
|
||||
progmode = progmode_compile;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
/* Compilation specific defaults */
|
||||
@@ -426,7 +425,7 @@ main(int argc, char **argv) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
prog_name, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
usage();
|
||||
|
||||
|
||||
@@ -11,60 +11,65 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
named-checkzone, named-compilezone - zone file validity checking or converting tool
|
||||
-----------------------------------------------------------------------------------
|
||||
.. BEWARE: Do not forget to edit also named-compilezone.rst!
|
||||
|
||||
.. iscman:: named-checkzone
|
||||
.. program:: named-checkzone
|
||||
.. _man_named-checkzone:
|
||||
|
||||
named-checkzone - zone file validation tool
|
||||
-------------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
:program:`named-checkzone` [**-d**] [**-h**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-M** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-o** filename] [**-r** mode] [**-s** style] [**-S** mode] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {zonename} {filename}
|
||||
|
||||
:program:`named-compilezone` [**-d**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-C** mode] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-r** mode] [**-s** style] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {**-o** filename} {zonename} {filename}
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named-checkzone`` checks the syntax and integrity of a zone file. It
|
||||
performs the same checks as ``named`` does when loading a zone. This
|
||||
makes ``named-checkzone`` useful for checking zone files before
|
||||
:program:`named-checkzone` checks the syntax and integrity of a zone file. It
|
||||
performs the same checks as :iscman:`named` does when loading a zone. This
|
||||
makes :program:`named-checkzone` useful for checking zone files before
|
||||
configuring them into a name server.
|
||||
|
||||
``named-compilezone`` is similar to ``named-checkzone``, but it always
|
||||
dumps the zone contents to a specified file in a specified format.
|
||||
It also applies stricter check levels by default, since the
|
||||
dump output is used as an actual zone file loaded by ``named``.
|
||||
When manually specified otherwise, the check levels must at least be as
|
||||
strict as those specified in the ``named`` configuration file.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-d``
|
||||
.. option:: -d
|
||||
|
||||
This option enables debugging.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which only sets an exit code to indicate
|
||||
successful or failed completion.
|
||||
|
||||
``-v``
|
||||
This option prints the version of the ``named-checkzone`` program and exits.
|
||||
.. option:: -v
|
||||
|
||||
``-j``
|
||||
When loading a zone file, this option tells ``named`` to read the journal if it exists. The journal
|
||||
This option prints the version of the :program:`named-checkzone` program and exits.
|
||||
|
||||
.. option:: -j
|
||||
|
||||
When loading a zone file, this option tells :iscman:`named` to read the journal if it exists. The journal
|
||||
file name is assumed to be the zone file name with the
|
||||
string ``.jnl`` appended.
|
||||
|
||||
``-J filename``
|
||||
When loading the zone file, this option tells ``named`` to read the journal from the given file, if
|
||||
it exists. This implies ``-j``.
|
||||
.. option:: -J filename
|
||||
|
||||
When loading the zone file, this option tells :iscman:`named` to read the journal from the given file, if
|
||||
it exists. This implies :option:`-j`.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option specifies the class of the zone. If not specified, ``IN`` is assumed.
|
||||
|
||||
``-i mode``
|
||||
.. option:: -i mode
|
||||
|
||||
This option performs post-load zone integrity checks. Possible modes are
|
||||
``full`` (the default), ``full-sibling``, ``local``,
|
||||
``local-sibling``, and ``none``.
|
||||
@@ -90,113 +95,128 @@ Options
|
||||
|
||||
Mode ``none`` disables the checks.
|
||||
|
||||
``-f format``
|
||||
.. option:: -f format
|
||||
|
||||
This option specifies the format of the zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``.
|
||||
|
||||
``-F format``
|
||||
.. option:: -F format
|
||||
|
||||
This option specifies the format of the output file specified. For
|
||||
``named-checkzone``, this does not have any effect unless it dumps
|
||||
:program:`named-checkzone`, this does not have any effect unless it dumps
|
||||
the zone contents.
|
||||
|
||||
Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone, and ``raw`` and ``raw=N``, which
|
||||
store the zone in a binary format for rapid loading by ``named``.
|
||||
store the zone in a binary format for rapid loading by :iscman:`named`.
|
||||
``raw=N`` specifies the format version of the raw zone file: if ``N`` is
|
||||
0, the raw file can be read by any version of ``named``; if N is 1, the
|
||||
0, the raw file can be read by any version of :iscman:`named`; if N is 1, the
|
||||
file can only be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
``-k mode``
|
||||
.. option:: -k mode
|
||||
|
||||
This option performs ``check-names`` checks with the specified failure mode.
|
||||
Possible modes are ``fail`` (the default for ``named-compilezone``),
|
||||
``warn`` (the default for ``named-checkzone``), and ``ignore``.
|
||||
Possible modes are ``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -l ttl
|
||||
|
||||
``-l ttl``
|
||||
This option sets a maximum permissible TTL for the input file. Any record with a
|
||||
TTL higher than this value causes the zone to be rejected. This
|
||||
is similar to using the ``max-zone-ttl`` option in ``named.conf``.
|
||||
is similar to using the ``max-zone-ttl`` option in :iscman:`named.conf`.
|
||||
|
||||
.. option:: -L serial
|
||||
|
||||
``-L serial``
|
||||
When compiling a zone to ``raw`` format, this option sets the "source
|
||||
serial" value in the header to the specified serial number. This is
|
||||
expected to be used primarily for testing purposes.
|
||||
|
||||
``-m mode``
|
||||
.. option:: -m mode
|
||||
|
||||
This option specifies whether MX records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and
|
||||
``ignore``.
|
||||
|
||||
``-M mode``
|
||||
.. option:: -M mode
|
||||
|
||||
This option checks whether a MX record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-n mode``
|
||||
.. option:: -n mode
|
||||
|
||||
This option specifies whether NS records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail`` (the default for
|
||||
``named-compilezone``), ``warn`` (the default for ``named-checkzone``),
|
||||
and ``ignore``.
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -o filename
|
||||
|
||||
``-o filename``
|
||||
This option writes the zone output to ``filename``. If ``filename`` is ``-``, then
|
||||
the zone output is written to standard output. This is mandatory for ``named-compilezone``.
|
||||
the zone output is written to standard output.
|
||||
|
||||
.. option:: -r mode
|
||||
|
||||
``-r mode``
|
||||
This option checks for records that are treated as different by DNSSEC but are
|
||||
semantically equal in plain DNS. Possible modes are ``fail``,
|
||||
``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-s style``
|
||||
.. option:: -s style
|
||||
|
||||
This option specifies the style of the dumped zone file. Possible styles are
|
||||
``full`` (the default) and ``relative``. The ``full`` format is most
|
||||
suitable for processing automatically by a separate script.
|
||||
The relative format is more human-readable and is thus
|
||||
suitable for editing by hand. For ``named-checkzone``, this does not
|
||||
have any effect unless it dumps the zone contents. It also does not
|
||||
have any meaning if the output format is not text.
|
||||
suitable for editing by hand. This does not have any effect unless it dumps
|
||||
the zone contents. It also does not have any meaning if the output format
|
||||
is not text.
|
||||
|
||||
.. option:: -S mode
|
||||
|
||||
``-S mode``
|
||||
This option checks whether an SRV record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-t directory``
|
||||
This option tells ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
``named``.
|
||||
:iscman:`named`.
|
||||
|
||||
.. option:: -T mode
|
||||
|
||||
``-T mode``
|
||||
This option checks whether Sender Policy Framework (SPF) records exist and issues a
|
||||
warning if an SPF-formatted TXT record is not also present. Possible
|
||||
modes are ``warn`` (the default) and ``ignore``.
|
||||
|
||||
``-w directory``
|
||||
This option instructs ``named`` to chdir to ``directory``, so that relative filenames in master file
|
||||
.. option:: -w directory
|
||||
|
||||
This option instructs :iscman:`named` to chdir to ``directory``, so that relative filenames in master file
|
||||
``$INCLUDE`` directives work. This is similar to the directory clause in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
``-D``
|
||||
This option dumps the zone file in canonical format. This is always enabled for
|
||||
``named-compilezone``.
|
||||
.. option:: -D
|
||||
|
||||
This option dumps the zone file in canonical format.
|
||||
|
||||
.. option:: -W mode
|
||||
|
||||
``-W mode``
|
||||
This option specifies whether to check for non-terminal wildcards. Non-terminal
|
||||
wildcards are almost always the result of a failure to understand the
|
||||
wildcard matching algorithm (:rfc:`1034`). Possible modes are ``warn``
|
||||
wildcard matching algorithm (:rfc:`4592`). Possible modes are ``warn``
|
||||
(the default) and ``ignore``.
|
||||
|
||||
``zonename``
|
||||
.. option:: zonename
|
||||
|
||||
This indicates the domain name of the zone being checked.
|
||||
|
||||
``filename``
|
||||
.. option:: filename
|
||||
|
||||
This is the name of the zone file.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``named-checkzone`` returns an exit status of 1 if errors were detected
|
||||
:program:`named-checkzone` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkconf(8)`, :rfc:`1035`, BIND 9 Administrator Reference
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-compilezone(8) <named-compilezone>`, :rfc:`1035`, BIND 9 Administrator Reference
|
||||
Manual.
|
||||
|
||||
@@ -0,0 +1,224 @@
|
||||
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
..
|
||||
.. SPDX-License-Identifier: MPL-2.0
|
||||
..
|
||||
.. This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.. License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
..
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. BEWARE: Do not forget to edit also named-checkzone.rst!
|
||||
|
||||
.. iscman:: named-compilezone
|
||||
.. program:: named-compilezone
|
||||
.. _man_named-compilezone:
|
||||
|
||||
named-compilezone - zone file converting tool
|
||||
---------------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` [**-d**] [**-h**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-M** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-r** mode] [**-s** style] [**-S** mode] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {**-o** filename} {zonename} {filename}
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` checks the syntax and integrity of a zone file,
|
||||
and dumps the zone contents to a specified file in a specified format.
|
||||
It applies strict check levels by default, since the
|
||||
dump output is used as an actual zone file loaded by :iscman:`named`.
|
||||
When manually specified otherwise, the check levels must at least be as
|
||||
strict as those specified in the :iscman:`named` configuration file.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
.. option:: -d
|
||||
|
||||
This option enables debugging.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which only sets an exit code to indicate
|
||||
successful or failed completion.
|
||||
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version of the :iscman:`named-checkzone` program and exits.
|
||||
|
||||
.. option:: -j
|
||||
|
||||
When loading a zone file, this option tells :iscman:`named` to read the journal if it exists. The journal
|
||||
file name is assumed to be the zone file name with the
|
||||
string ``.jnl`` appended.
|
||||
|
||||
.. option:: -J filename
|
||||
|
||||
When loading the zone file, this option tells :iscman:`named` to read the journal from the given file, if
|
||||
it exists. This implies :option:`-j`.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the class of the zone. If not specified, ``IN`` is assumed.
|
||||
|
||||
.. option:: -i mode
|
||||
|
||||
This option performs post-load zone integrity checks. Possible modes are
|
||||
``full`` (the default), ``full-sibling``, ``local``,
|
||||
``local-sibling``, and ``none``.
|
||||
|
||||
Mode ``full`` checks that MX records refer to A or AAAA records
|
||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
||||
checks MX records which refer to in-zone hostnames.
|
||||
|
||||
Mode ``full`` checks that SRV records refer to A or AAAA records
|
||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
||||
checks SRV records which refer to in-zone hostnames.
|
||||
|
||||
Mode ``full`` checks that delegation NS records refer to A or AAAA
|
||||
records (both in-zone and out-of-zone hostnames). It also checks that
|
||||
glue address records in the zone match those advertised by the child.
|
||||
Mode ``local`` only checks NS records which refer to in-zone
|
||||
hostnames or verifies that some required glue exists, i.e., when the
|
||||
name server is in a child zone.
|
||||
|
||||
Modes ``full-sibling`` and ``local-sibling`` disable sibling glue
|
||||
checks, but are otherwise the same as ``full`` and ``local``,
|
||||
respectively.
|
||||
|
||||
Mode ``none`` disables the checks.
|
||||
|
||||
.. option:: -f format
|
||||
|
||||
This option specifies the format of the zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``.
|
||||
|
||||
.. option:: -F format
|
||||
|
||||
This option specifies the format of the output file specified. For
|
||||
:iscman:`named-checkzone`, this does not have any effect unless it dumps
|
||||
the zone contents.
|
||||
|
||||
Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone, and ``raw`` and ``raw=N``, which
|
||||
store the zone in a binary format for rapid loading by :iscman:`named`.
|
||||
``raw=N`` specifies the format version of the raw zone file: if ``N`` is
|
||||
0, the raw file can be read by any version of :iscman:`named`; if N is 1, the
|
||||
file can only be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
.. option:: -k mode
|
||||
|
||||
This option performs ``check-names`` checks with the specified failure mode.
|
||||
Possible modes are ``fail`` (the default), ``warn``, and ``ignore``.
|
||||
|
||||
.. option:: -l ttl
|
||||
|
||||
This option sets a maximum permissible TTL for the input file. Any record with a
|
||||
TTL higher than this value causes the zone to be rejected. This
|
||||
is similar to using the ``max-zone-ttl`` option in :iscman:`named.conf`.
|
||||
|
||||
.. option:: -L serial
|
||||
|
||||
When compiling a zone to ``raw`` format, this option sets the "source
|
||||
serial" value in the header to the specified serial number. This is
|
||||
expected to be used primarily for testing purposes.
|
||||
|
||||
.. option:: -m mode
|
||||
|
||||
This option specifies whether MX records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and
|
||||
``ignore``.
|
||||
|
||||
.. option:: -M mode
|
||||
|
||||
This option checks whether a MX record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -n mode
|
||||
|
||||
This option specifies whether NS records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail`` (the default), ``warn``, and
|
||||
``ignore``.
|
||||
|
||||
.. option:: -o filename
|
||||
|
||||
This option writes the zone output to ``filename``. If ``filename`` is ``-``, then
|
||||
the zone output is written to standard output. This is mandatory for :program:`named-compilezone`.
|
||||
|
||||
.. option:: -r mode
|
||||
|
||||
This option checks for records that are treated as different by DNSSEC but are
|
||||
semantically equal in plain DNS. Possible modes are ``fail``,
|
||||
``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -s style
|
||||
|
||||
This option specifies the style of the dumped zone file. Possible styles are
|
||||
``full`` (the default) and ``relative``. The ``full`` format is most
|
||||
suitable for processing automatically by a separate script.
|
||||
The relative format is more human-readable and is thus
|
||||
suitable for editing by hand.
|
||||
|
||||
.. option:: -S mode
|
||||
|
||||
This option checks whether an SRV record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
:iscman:`named`.
|
||||
|
||||
.. option:: -T mode
|
||||
|
||||
This option checks whether Sender Policy Framework (SPF) records exist and issues a
|
||||
warning if an SPF-formatted TXT record is not also present. Possible
|
||||
modes are ``warn`` (the default) and ``ignore``.
|
||||
|
||||
.. option:: -w directory
|
||||
|
||||
This option instructs :iscman:`named` to chdir to ``directory``, so that relative filenames in master file
|
||||
``$INCLUDE`` directives work. This is similar to the directory clause in
|
||||
:iscman:`named.conf`.
|
||||
|
||||
.. option:: -D
|
||||
|
||||
This option dumps the zone file in canonical format. This is always enabled for
|
||||
:program:`named-compilezone`.
|
||||
|
||||
.. option:: -W mode
|
||||
|
||||
This option specifies whether to check for non-terminal wildcards. Non-terminal
|
||||
wildcards are almost always the result of a failure to understand the
|
||||
wildcard matching algorithm (:rfc:`4592`). Possible modes are ``warn``
|
||||
(the default) and ``ignore``.
|
||||
|
||||
.. option:: zonename
|
||||
|
||||
This indicates the domain name of the zone being checked.
|
||||
|
||||
.. option:: filename
|
||||
|
||||
This is the name of the zone file.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-checkzone(8) <named-checkzone>`, `:rfc:`1035`,
|
||||
BIND 9 Administrator Reference Manual.
|
||||
@@ -0,0 +1,96 @@
|
||||
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
..
|
||||
.. SPDX-License-Identifier: MPL-2.0
|
||||
..
|
||||
.. This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.. License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
..
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. BEWARE: Do not forget to edit also tsig-keygen.rst!
|
||||
|
||||
.. iscman:: ddns-confgen
|
||||
.. program:: ddns-confgen
|
||||
.. _man_ddns-confgen:
|
||||
|
||||
ddns-confgen - TSIG key generation tool
|
||||
---------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-s** name] [**-z** zone]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
:program:`ddns-confgen` is an utility that generates keys for use in TSIG signing.
|
||||
The resulting keys can be used, for example, to secure dynamic DNS updates
|
||||
to a zone, or for the :iscman:`rndc` command channel.
|
||||
|
||||
The key name can specified using :option:`-k` parameter and defaults to ``ddns-key``.
|
||||
The generated key is accompanied by configuration text and instructions that
|
||||
can be used with :iscman:`nsupdate` and :iscman:`named` when setting up dynamic DNS,
|
||||
including an example ``update-policy`` statement.
|
||||
(This usage is similar to the :iscman:`rndc-confgen` command for setting up
|
||||
command-channel security.)
|
||||
|
||||
Note that :iscman:`named` itself can configure a local DDNS key for use with
|
||||
:option:`nsupdate -l`; it does this when a zone is configured with
|
||||
``update-policy local;``. :program:`ddns-confgen` is only needed when a more
|
||||
elaborate configuration is required: for instance, if :iscman:`nsupdate` is to
|
||||
be used from a remote system.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384,
|
||||
and hmac-sha512. The default is hmac-sha256. Options are
|
||||
case-insensitive, and the "hmac-" prefix may be omitted.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of options and arguments.
|
||||
|
||||
.. option:: -k keyname
|
||||
|
||||
This option specifies the key name of the DDNS authentication key. The
|
||||
default is ``ddns-key`` when neither the :option:`-s` nor :option:`-z` option is
|
||||
specified; otherwise, the default is ``ddns-key`` as a separate label
|
||||
followed by the argument of the option, e.g., ``ddns-key.example.com.``
|
||||
The key name must have the format of a valid domain name, consisting of
|
||||
letters, digits, hyphens, and periods.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
This option enables quiet mode, which prints only the key, with no
|
||||
explanatory text or usage examples. This is essentially identical to
|
||||
:iscman:`tsig-keygen`.
|
||||
|
||||
.. option:: -s name
|
||||
|
||||
This option generates a configuration example to allow dynamic updates
|
||||
of a single hostname. The example :iscman:`named.conf` text shows how to set
|
||||
an update policy for the specified name using the "name" nametype. The
|
||||
default key name is ``ddns-key.name``. Note that the "self" nametype
|
||||
cannot be used, since the name to be updated may differ from the key
|
||||
name. This option cannot be used with the :option:`-z` option.
|
||||
|
||||
.. option:: -z zone
|
||||
|
||||
This option generates a configuration example to allow
|
||||
dynamic updates of a zone. The example :iscman:`named.conf` text shows how
|
||||
to set an update policy for the specified zone using the "zonesub"
|
||||
nametype, allowing updates to all subdomain names within that zone.
|
||||
This option cannot be used with the :option:`-s` option.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:iscman:`nsupdate(1) <nsupdate>`, :iscman:`named.conf(5) <named.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
@@ -61,7 +61,7 @@ bool verbose = false;
|
||||
|
||||
const char *keyfile, *keydef;
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(int status);
|
||||
|
||||
static void
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc-confgen
|
||||
.. program:: rndc-confgen
|
||||
.. _man_rndc-confgen:
|
||||
|
||||
rndc-confgen - rndc key generation tool
|
||||
@@ -24,86 +26,96 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc-confgen`` generates configuration files for ``rndc``. It can be
|
||||
used as a convenient alternative to writing the ``rndc.conf`` file and
|
||||
the corresponding ``controls`` and ``key`` statements in ``named.conf``
|
||||
by hand. Alternatively, it can be run with the ``-a`` option to set up a
|
||||
``rndc.key`` file and avoid the need for a ``rndc.conf`` file and a
|
||||
:program:`rndc-confgen` generates configuration files for :iscman:`rndc`. It can be
|
||||
used as a convenient alternative to writing the :iscman:`rndc.conf` file and
|
||||
the corresponding ``controls`` and ``key`` statements in :iscman:`named.conf`
|
||||
by hand. Alternatively, it can be run with the :option:`-a` option to set up a
|
||||
``rndc.key`` file and avoid the need for a :iscman:`rndc.conf` file and a
|
||||
``controls`` statement altogether.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a``
|
||||
This option sets automatic ``rndc`` configuration, which creates a file ``rndc.key``
|
||||
in ``/etc`` (or a different ``sysconfdir`` specified when BIND
|
||||
was built) that is read by both ``rndc`` and ``named`` on startup.
|
||||
.. option:: -a
|
||||
|
||||
This option sets automatic :iscman:`rndc` configuration, which creates a file
|
||||
|rndc_key| that is read by both :iscman:`rndc` and :iscman:`named` on startup.
|
||||
The ``rndc.key`` file defines a default command channel and
|
||||
authentication key allowing ``rndc`` to communicate with ``named`` on
|
||||
authentication key allowing :iscman:`rndc` to communicate with :iscman:`named` on
|
||||
the local host with no further configuration.
|
||||
|
||||
If a more elaborate configuration than that generated by
|
||||
``rndc-confgen -a`` is required, for example if rndc is to be used
|
||||
remotely, run ``rndc-confgen`` without the ``-a`` option
|
||||
and set up ``rndc.conf`` and ``named.conf`` as directed.
|
||||
:option:`rndc-confgen -a` is required, for example if rndc is to be used
|
||||
remotely, run :program:`rndc-confgen` without the :option:`-a` option
|
||||
and set up :iscman:`rndc.conf` and :iscman:`named.conf` as directed.
|
||||
|
||||
.. option:: -A algorithm
|
||||
|
||||
``-A algorithm``
|
||||
This option specifies the algorithm to use for the TSIG key. Available choices
|
||||
are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384, and
|
||||
hmac-sha512. The default is hmac-sha256.
|
||||
|
||||
``-b keysize``
|
||||
.. option:: -b keysize
|
||||
|
||||
This option specifies the size of the authentication key in bits. The size must be between
|
||||
1 and 512 bits; the default is the hash size.
|
||||
|
||||
``-c keyfile``
|
||||
This option is used with the ``-a`` option to specify an alternate location for
|
||||
.. option:: -c keyfile
|
||||
|
||||
This option is used with the :option:`-a` option to specify an alternate location for
|
||||
``rndc.key``.
|
||||
|
||||
``-h``
|
||||
This option prints a short summary of the options and arguments to
|
||||
``rndc-confgen``.
|
||||
.. option:: -h
|
||||
|
||||
``-k keyname``
|
||||
This option specifies the key name of the ``rndc`` authentication key. This must be a
|
||||
This option prints a short summary of the options and arguments to
|
||||
:program:`rndc-confgen`.
|
||||
|
||||
.. option:: -k keyname
|
||||
|
||||
This option specifies the key name of the :iscman:`rndc` authentication key. This must be a
|
||||
valid domain name. The default is ``rndc-key``.
|
||||
|
||||
``-p port``
|
||||
This option specifies the command channel port where ``named`` listens for
|
||||
connections from ``rndc``. The default is 953.
|
||||
.. option:: -p port
|
||||
|
||||
This option specifies the command channel port where :iscman:`named` listens for
|
||||
connections from :iscman:`rndc`. The default is 953.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
``-q``
|
||||
This option prevets printing the written path in automatic configuration mode.
|
||||
|
||||
``-s address``
|
||||
This option specifies the IP address where ``named`` listens for command-channel
|
||||
connections from ``rndc``. The default is the loopback address
|
||||
.. option:: -s address
|
||||
|
||||
This option specifies the IP address where :iscman:`named` listens for command-channel
|
||||
connections from :iscman:`rndc`. The default is the loopback address
|
||||
127.0.0.1.
|
||||
|
||||
``-t chrootdir``
|
||||
This option is used with the ``-a`` option to specify a directory where ``named``
|
||||
.. option:: -t chrootdir
|
||||
|
||||
This option is used with the :option:`-a` option to specify a directory where :iscman:`named`
|
||||
runs chrooted. An additional copy of the ``rndc.key`` is
|
||||
written relative to this directory, so that it is found by the
|
||||
chrooted ``named``.
|
||||
chrooted :iscman:`named`.
|
||||
|
||||
``-u user``
|
||||
This option is used with the ``-a`` option to set the owner of the generated ``rndc.key`` file.
|
||||
If ``-t`` is also specified, only the file in the chroot
|
||||
.. option:: -u user
|
||||
|
||||
This option is used with the :option:`-a` option to set the owner of the generated ``rndc.key`` file.
|
||||
If :option:`-t` is also specified, only the file in the chroot
|
||||
area has its owner changed.
|
||||
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
To allow ``rndc`` to be used with no manual configuration, run:
|
||||
To allow :iscman:`rndc` to be used with no manual configuration, run:
|
||||
|
||||
``rndc-confgen -a``
|
||||
|
||||
To print a sample ``rndc.conf`` file and the corresponding ``controls`` and
|
||||
``key`` statements to be manually inserted into ``named.conf``, run:
|
||||
To print a sample :iscman:`rndc.conf` file and the corresponding ``controls`` and
|
||||
``key`` statements to be manually inserted into :iscman:`named.conf`, run:
|
||||
|
||||
``rndc-confgen``
|
||||
:program:`rndc-confgen`
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc(8)`, :manpage:`rndc.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`rndc(8) <rndc>`, :iscman:`rndc.conf(5) <rndc.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
@@ -54,7 +54,7 @@ const char *progname;
|
||||
static enum { progmode_keygen, progmode_confgen } progmode;
|
||||
bool verbose = false; /* needed by util.c but not used here */
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(int status);
|
||||
|
||||
static void
|
||||
@@ -121,8 +121,7 @@ main(int argc, char **argv) {
|
||||
} else if (PROGCMP("ddns-confgen")) {
|
||||
progmode = progmode_confgen;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
isc_commandline_errprint = false;
|
||||
|
||||
+19
-56
@@ -11,81 +11,44 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
tsig-keygen, ddns-confgen - TSIG key generation tool
|
||||
----------------------------------------------------
|
||||
.. BEWARE: Do not forget to edit also ddns-confgen.rst!
|
||||
|
||||
.. iscman:: tsig-keygen
|
||||
.. program:: tsig-keygen
|
||||
.. _man_tsig-keygen:
|
||||
|
||||
tsig-keygen - TSIG key generation tool
|
||||
--------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [**-r** randomfile] [name]
|
||||
|
||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-r** randomfile] [**-s** name] [**-z** zone]
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [name]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``tsig-keygen`` and ``ddns-confgen`` are invocation methods for a
|
||||
utility that generates keys for use in TSIG signing. The resulting keys
|
||||
can be used, for example, to secure dynamic DNS updates to a zone, or for
|
||||
the ``rndc`` command channel.
|
||||
:program:`tsig-keygen` is an utility that generates keys for use in TSIG signing.
|
||||
The resulting keys can be used, for example, to secure dynamic DNS updates
|
||||
to a zone, or for the :iscman:`rndc` command channel.
|
||||
|
||||
When run as ``tsig-keygen``, a domain name can be specified on the
|
||||
command line to be used as the name of the generated key. If no
|
||||
name is specified, the default is ``tsig-key``.
|
||||
|
||||
When run as ``ddns-confgen``, the key name can specified using ``-k``
|
||||
parameter and defaults to ``ddns-key``. The generated key is accompanied
|
||||
by configuration text and instructions that can be used with ``nsupdate``
|
||||
and ``named`` when setting up dynamic DNS, including an example
|
||||
``update-policy`` statement. (This usage is similar to the ``rndc-confgen``
|
||||
command for setting up command-channel security.)
|
||||
|
||||
Note that ``named`` itself can configure a local DDNS key for use with
|
||||
``nsupdate -l``; it does this when a zone is configured with
|
||||
``update-policy local;``. ``ddns-confgen`` is only needed when a more
|
||||
elaborate configuration is required: for instance, if ``nsupdate`` is to
|
||||
be used from a remote system.
|
||||
A domain name can be specified on the command line to be used as the name
|
||||
of the generated key. If no name is specified, the default is ``tsig-key``.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384,
|
||||
and hmac-sha512. The default is hmac-sha256. Options are
|
||||
case-insensitive, and the "hmac-" prefix may be omitted.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of options and arguments.
|
||||
|
||||
``-k keyname``
|
||||
This option specifies the key name of the DDNS authentication key. The
|
||||
default is ``ddns-key`` when neither the ``-s`` nor ``-z`` option is
|
||||
specified; otherwise, the default is ``ddns-key`` as a separate label
|
||||
followed by the argument of the option, e.g., ``ddns-key.example.com.``
|
||||
The key name must have the format of a valid domain name, consisting of
|
||||
letters, digits, hyphens, and periods.
|
||||
|
||||
``-q`` (``ddns-confgen`` only)
|
||||
This option enables quiet mode, which prints only the key, with no
|
||||
explanatory text or usage examples. This is essentially identical to
|
||||
``tsig-keygen``.
|
||||
|
||||
``-s name`` (``ddns-confgen`` only)
|
||||
This option generates a configuration example to allow dynamic updates
|
||||
of a single hostname. The example ``named.conf`` text shows how to set
|
||||
an update policy for the specified name using the "name" nametype. The
|
||||
default key name is ``ddns-key.name``. Note that the "self" nametype
|
||||
cannot be used, since the name to be updated may differ from the key
|
||||
name. This option cannot be used with the ``-z`` option.
|
||||
|
||||
``-z zone`` (``ddns-confgen`` only)
|
||||
This option generates a configuration example to allow
|
||||
dynamic updates of a zone. The example ``named.conf`` text shows how
|
||||
to set an update policy for the specified zone using the "zonesub"
|
||||
nametype, allowing updates to all subdomain names within that zone.
|
||||
This option cannot be used with the ``-s`` option.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`nsupdate(1)`, :manpage:`named.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`nsupdate(1) <nsupdate>`, :iscman:`named.conf(5) <named.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+1
-1
@@ -36,7 +36,7 @@ ISC_LANG_BEGINDECLS
|
||||
void
|
||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_LANG_ENDDECLS
|
||||
|
||||
+6
-25
@@ -208,7 +208,7 @@ usage(void) {
|
||||
exit(1);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
static void
|
||||
@@ -1325,7 +1325,6 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
||||
case 'h':
|
||||
usage();
|
||||
exit(0);
|
||||
/* NOTREACHED */
|
||||
case 'i':
|
||||
no_sigs = true;
|
||||
root_validation = false;
|
||||
@@ -1334,12 +1333,10 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
||||
/* handled in preparse_args() */
|
||||
break;
|
||||
case 'v':
|
||||
fprintf(stderr, "delv %s\n", PACKAGE_VERSION);
|
||||
printf("delv %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
/* NOTREACHED */
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
if (strlen(option) > 1U) {
|
||||
option = &option[1];
|
||||
@@ -1477,7 +1474,7 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
||||
fprintf(stderr, "Invalid option: -%s\n", option);
|
||||
usage();
|
||||
}
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (false);
|
||||
}
|
||||
|
||||
@@ -1721,12 +1718,10 @@ main(int argc, char *argv[]) {
|
||||
dns_rdataset_t *rdataset;
|
||||
dns_namelist_t namelist;
|
||||
unsigned int resopt;
|
||||
isc_appctx_t *actx = NULL;
|
||||
isc_nm_t *netmgr = NULL;
|
||||
isc_taskmgr_t *taskmgr = NULL;
|
||||
isc_timermgr_t *timermgr = NULL;
|
||||
dns_master_style_t *style = NULL;
|
||||
struct sigaction sa;
|
||||
|
||||
progname = argv[0];
|
||||
preparse_args(argc, argv);
|
||||
@@ -1741,8 +1736,6 @@ main(int argc, char *argv[]) {
|
||||
fatal("dst_lib_init failed: %d", result);
|
||||
}
|
||||
|
||||
CHECK(isc_appctx_create(mctx, &actx));
|
||||
|
||||
isc_managers_create(mctx, 1, 0, &netmgr, &taskmgr, &timermgr);
|
||||
|
||||
parse_args(argc, argv);
|
||||
@@ -1751,18 +1744,9 @@ main(int argc, char *argv[]) {
|
||||
|
||||
setup_logging(stderr);
|
||||
|
||||
CHECK(isc_app_ctxstart(actx));
|
||||
|
||||
/* Unblock SIGINT if it's been blocked by isc_app_ctxstart() */
|
||||
memset(&sa, 0, sizeof(sa));
|
||||
sa.sa_handler = SIG_DFL;
|
||||
if (sigfillset(&sa.sa_mask) != 0 || sigaction(SIGINT, &sa, NULL) < 0) {
|
||||
fatal("Couldn't set up signal handler");
|
||||
}
|
||||
|
||||
/* Create client */
|
||||
result = dns_client_create(mctx, actx, taskmgr, netmgr, timermgr, 0,
|
||||
&client, srcaddr4, srcaddr6);
|
||||
result = dns_client_create(mctx, taskmgr, netmgr, timermgr, 0, &client,
|
||||
srcaddr4, srcaddr6);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
delv_log(ISC_LOG_ERROR, "dns_client_create: %s",
|
||||
isc_result_totext(result));
|
||||
@@ -1847,9 +1831,6 @@ cleanup:
|
||||
|
||||
isc_managers_destroy(&netmgr, &taskmgr, &timermgr);
|
||||
|
||||
if (actx != NULL) {
|
||||
isc_appctx_destroy(&actx);
|
||||
}
|
||||
if (lctx != NULL) {
|
||||
isc_log_destroy(&lctx);
|
||||
}
|
||||
|
||||
+121
-83
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: delv
|
||||
.. program:: delv
|
||||
.. _man_delv:
|
||||
|
||||
delv - DNS lookup and validation utility
|
||||
@@ -30,10 +32,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``delv`` is a tool for sending DNS queries and validating the results,
|
||||
using the same internal resolver and validator logic as ``named``.
|
||||
:program:`delv` is a tool for sending DNS queries and validating the results,
|
||||
using the same internal resolver and validator logic as :iscman:`named`.
|
||||
|
||||
``delv`` sends to a specified name server all queries needed to
|
||||
:program:`delv` sends to a specified name server all queries needed to
|
||||
fetch and validate the requested data; this includes the original
|
||||
requested query, subsequent queries to follow CNAME or DNAME chains,
|
||||
queries for DNSKEY, and DS records to establish a chain of trust for
|
||||
@@ -42,25 +44,25 @@ simulates the behavior of a name server configured for DNSSEC validating
|
||||
and forwarding.
|
||||
|
||||
By default, responses are validated using the built-in DNSSEC trust anchor
|
||||
for the root zone ("."). Records returned by ``delv`` are either fully
|
||||
for the root zone ("."). Records returned by :program:`delv` are either fully
|
||||
validated or were not signed. If validation fails, an explanation of the
|
||||
failure is included in the output; the validation process can be traced
|
||||
in detail. Because ``delv`` does not rely on an external server to carry
|
||||
in detail. Because :program:`delv` does not rely on an external server to carry
|
||||
out validation, it can be used to check the validity of DNS responses in
|
||||
environments where local name servers may not be trustworthy.
|
||||
|
||||
Unless it is told to query a specific name server, ``delv`` tries
|
||||
Unless it is told to query a specific name server, :program:`delv` tries
|
||||
each of the servers listed in ``/etc/resolv.conf``. If no usable server
|
||||
addresses are found, ``delv`` sends queries to the localhost
|
||||
addresses are found, :program:`delv` sends queries to the localhost
|
||||
addresses (127.0.0.1 for IPv4, ::1 for IPv6).
|
||||
|
||||
When no command-line arguments or options are given, ``delv``
|
||||
When no command-line arguments or options are given, :program:`delv`
|
||||
performs an NS query for "." (the root zone).
|
||||
|
||||
Simple Usage
|
||||
~~~~~~~~~~~~
|
||||
|
||||
A typical invocation of ``delv`` looks like:
|
||||
A typical invocation of :program:`delv` looks like:
|
||||
|
||||
::
|
||||
|
||||
@@ -68,125 +70,142 @@ A typical invocation of ``delv`` looks like:
|
||||
|
||||
where:
|
||||
|
||||
``server``
|
||||
.. option:: server
|
||||
|
||||
is the name or IP address of the name server to query. This can be an
|
||||
IPv4 address in dotted-decimal notation or an IPv6 address in
|
||||
colon-delimited notation. When the supplied ``server`` argument is a
|
||||
hostname, ``delv`` resolves that name before querying that name
|
||||
hostname, :program:`delv` resolves that name before querying that name
|
||||
server (note, however, that this initial lookup is *not* validated by
|
||||
DNSSEC).
|
||||
|
||||
If no ``server`` argument is provided, ``delv`` consults
|
||||
If no ``server`` argument is provided, :program:`delv` consults
|
||||
``/etc/resolv.conf``; if an address is found there, it queries the
|
||||
name server at that address. If either of the ``-4`` or ``-6``
|
||||
name server at that address. If either of the :option:`-4` or :option:`-6`
|
||||
options is in use, then only addresses for the corresponding
|
||||
transport are tried. If no usable addresses are found, ``delv``
|
||||
transport are tried. If no usable addresses are found, :program:`delv`
|
||||
sends queries to the localhost addresses (127.0.0.1 for IPv4, ::1
|
||||
for IPv6).
|
||||
|
||||
``name``
|
||||
.. option:: name
|
||||
|
||||
is the domain name to be looked up.
|
||||
|
||||
``type``
|
||||
.. option:: type
|
||||
|
||||
indicates what type of query is required - ANY, A, MX, etc.
|
||||
``type`` can be any valid query type. If no ``type`` argument is
|
||||
supplied, ``delv`` performs a lookup for an A record.
|
||||
supplied, :program:`delv` performs a lookup for an A record.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a anchor-file``
|
||||
.. option:: -a anchor-file
|
||||
|
||||
This option specifies a file from which to read DNSSEC trust anchors. The default
|
||||
is ``/etc/bind.keys``, which is included with BIND 9 and contains one
|
||||
is |bind_keys|, which is included with BIND 9 and contains one
|
||||
or more trust anchors for the root zone (".").
|
||||
|
||||
Keys that do not match the root zone name are ignored. An alternate
|
||||
key name can be specified using the ``+root=NAME`` options.
|
||||
|
||||
Note: When reading the trust anchor file, ``delv`` treats ``trust-anchors``,
|
||||
Note: When reading the trust anchor file, :program:`delv` treats ``trust-anchors``,
|
||||
``initial-key``, and ``static-key`` identically. That is, for a managed key,
|
||||
it is the *initial* key that is trusted; :rfc:`5011` key management is not
|
||||
supported. ``delv`` does not consult the managed-keys database maintained by
|
||||
``named``, which means that if either of the keys in ``/etc/bind.keys`` is
|
||||
revoked and rolled over, ``/etc/bind.keys`` must be updated to
|
||||
use DNSSEC validation in ``delv``.
|
||||
supported. :program:`delv` does not consult the managed-keys database maintained by
|
||||
:iscman:`named`, which means that if either of the keys in |bind_keys| is
|
||||
revoked and rolled over, |bind_keys| must be updated to
|
||||
use DNSSEC validation in :program:`delv`.
|
||||
|
||||
.. option:: -b address
|
||||
|
||||
``-b address``
|
||||
This option sets the source IP address of the query to ``address``. This must be
|
||||
a valid address on one of the host's network interfaces, or ``0.0.0.0``,
|
||||
or ``::``. An optional source port may be specified by appending
|
||||
``#<port>``
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option sets the query class for the requested data. Currently, only class
|
||||
"IN" is supported in ``delv`` and any other value is ignored.
|
||||
"IN" is supported in :program:`delv` and any other value is ignored.
|
||||
|
||||
.. option:: -d level
|
||||
|
||||
``-d level``
|
||||
This option sets the systemwide debug level to ``level``. The allowed range is
|
||||
from 0 to 99. The default is 0 (no debugging). Debugging traces from
|
||||
``delv`` become more verbose as the debug level increases. See the
|
||||
:program:`delv` become more verbose as the debug level increases. See the
|
||||
``+mtrace``, ``+rtrace``, and ``+vtrace`` options below for
|
||||
additional debugging details.
|
||||
|
||||
``-h``
|
||||
This option displays the ``delv`` help usage output and exits.
|
||||
.. option:: -h
|
||||
|
||||
This option displays the :program:`delv` help usage output and exits.
|
||||
|
||||
.. option:: -i
|
||||
|
||||
``-i``
|
||||
This option sets insecure mode, which disables internal DNSSEC validation. (Note,
|
||||
however, that this does not set the CD bit on upstream queries. If the
|
||||
server being queried is performing DNSSEC validation, then it does
|
||||
not return invalid data; this can cause ``delv`` to time out. When it
|
||||
not return invalid data; this can cause :program:`delv` to time out. When it
|
||||
is necessary to examine invalid data to debug a DNSSEC problem, use
|
||||
``dig +cd``.)
|
||||
|
||||
``-m``
|
||||
.. option:: -m
|
||||
|
||||
This option enables memory usage debugging.
|
||||
|
||||
``-p port#``
|
||||
.. option:: -p port#
|
||||
|
||||
This option specifies a destination port to use for queries, instead of the
|
||||
standard DNS port number 53. This option is used with a name
|
||||
server that has been configured to listen for queries on a
|
||||
non-standard port number.
|
||||
|
||||
``-q name``
|
||||
.. option:: -q name
|
||||
|
||||
This option sets the query name to ``name``. While the query name can be
|
||||
specified without using the ``-q`` option, it is sometimes necessary to
|
||||
specified without using the :option:`-q` option, it is sometimes necessary to
|
||||
disambiguate names from types or classes (for example, when looking
|
||||
up the name "ns", which could be misinterpreted as the type NS, or
|
||||
"ch", which could be misinterpreted as class CH).
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option sets the query type to ``type``, which can be any valid query type
|
||||
supported in BIND 9 except for zone transfer types AXFR and IXFR. As
|
||||
with ``-q``, this is useful to distinguish query-name types or classes
|
||||
with :option:`-q`, this is useful to distinguish query-name types or classes
|
||||
when they are ambiguous. It is sometimes necessary to disambiguate
|
||||
names from types.
|
||||
|
||||
The default query type is "A", unless the ``-x`` option is supplied
|
||||
The default query type is "A", unless the :option:`-x` option is supplied
|
||||
to indicate a reverse lookup, in which case it is "PTR".
|
||||
|
||||
``-v``
|
||||
This option prints the ``delv`` version and exits.
|
||||
.. option:: -v
|
||||
|
||||
This option prints the :program:`delv` version and exits.
|
||||
|
||||
.. option:: -x addr
|
||||
|
||||
``-x addr``
|
||||
This option performs a reverse lookup, mapping an address to a name. ``addr``
|
||||
is an IPv4 address in dotted-decimal notation, or a colon-delimited
|
||||
IPv6 address. When ``-x`` is used, there is no need to provide the
|
||||
``name`` or ``type`` arguments; ``delv`` automatically performs a
|
||||
IPv6 address. When :option:`-x` is used, there is no need to provide the
|
||||
``name`` or ``type`` arguments; :program:`delv` automatically performs a
|
||||
lookup for a name like ``11.12.13.10.in-addr.arpa`` and sets the
|
||||
query type to PTR. IPv6 addresses are looked up using nibble format
|
||||
under the IP6.ARPA domain.
|
||||
|
||||
``-4``
|
||||
This option forces ``delv`` to only use IPv4.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option forces ``delv`` to only use IPv6.
|
||||
This option forces :program:`delv` to only use IPv4.
|
||||
|
||||
.. option:: -6
|
||||
|
||||
This option forces :program:`delv` to only use IPv6.
|
||||
|
||||
Query Options
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``delv`` provides a number of query options which affect the way results
|
||||
:program:`delv` provides a number of query options which affect the way results
|
||||
are displayed, and in some cases the way lookups are performed.
|
||||
|
||||
Each query option is identified by a keyword preceded by a plus sign
|
||||
@@ -195,69 +214,79 @@ the string ``no`` to negate the meaning of that keyword. Other keywords
|
||||
assign values to options like the timeout interval. They have the form
|
||||
``+keyword=value``. The query options are:
|
||||
|
||||
``+[no]cdflag``
|
||||
.. option:: +[no]cdflag
|
||||
|
||||
This option controls whether to set the CD (checking disabled) bit in queries
|
||||
sent by ``delv``. This may be useful when troubleshooting DNSSEC
|
||||
sent by :program:`delv`. This may be useful when troubleshooting DNSSEC
|
||||
problems from behind a validating resolver. A validating resolver
|
||||
blocks invalid responses, making it difficult to retrieve them
|
||||
for analysis. Setting the CD flag on queries causes the resolver
|
||||
to return invalid responses, which ``delv`` can then validate
|
||||
to return invalid responses, which :program:`delv` can then validate
|
||||
internally and report the errors in detail.
|
||||
|
||||
``+[no]class``
|
||||
.. option:: +[no]class
|
||||
|
||||
This option controls whether to display the CLASS when printing a record. The
|
||||
default is to display the CLASS.
|
||||
|
||||
``+[no]ttl``
|
||||
.. option:: +[no]ttl
|
||||
|
||||
This option controls whether to display the TTL when printing a record. The
|
||||
default is to display the TTL.
|
||||
|
||||
``+[no]rtrace``
|
||||
.. option:: +[no]rtrace
|
||||
|
||||
This option toggles resolver fetch logging. This reports the name and type of each
|
||||
query sent by ``delv`` in the process of carrying out the resolution
|
||||
query sent by :program:`delv` in the process of carrying out the resolution
|
||||
and validation process, including the original query
|
||||
and all subsequent queries to follow CNAMEs and to establish a chain
|
||||
of trust for DNSSEC validation.
|
||||
|
||||
This is equivalent to setting the debug level to 1 in the "resolver"
|
||||
logging category. Setting the systemwide debug level to 1 using the
|
||||
``-d`` option produces the same output, but affects other
|
||||
:option:`-d` option produces the same output, but affects other
|
||||
logging categories as well.
|
||||
|
||||
``+[no]mtrace``
|
||||
.. option:: +[no]mtrace
|
||||
|
||||
This option toggles message logging. This produces a detailed dump of the
|
||||
responses received by ``delv`` in the process of carrying out the
|
||||
responses received by :program:`delv` in the process of carrying out the
|
||||
resolution and validation process.
|
||||
|
||||
This is equivalent to setting the debug level to 10 for the "packets"
|
||||
module of the "resolver" logging category. Setting the systemwide
|
||||
debug level to 10 using the ``-d`` option produces the same
|
||||
debug level to 10 using the :option:`-d` option produces the same
|
||||
output, but affects other logging categories as well.
|
||||
|
||||
``+[no]vtrace``
|
||||
.. option:: +[no]vtrace
|
||||
|
||||
This option toggles validation logging. This shows the internal process of the
|
||||
validator as it determines whether an answer is validly signed,
|
||||
unsigned, or invalid.
|
||||
|
||||
This is equivalent to setting the debug level to 3 for the
|
||||
"validator" module of the "dnssec" logging category. Setting the
|
||||
systemwide debug level to 3 using the ``-d`` option produces the
|
||||
systemwide debug level to 3 using the :option:`-d` option produces the
|
||||
same output, but affects other logging categories as well.
|
||||
|
||||
``+[no]short``
|
||||
.. option:: +[no]short
|
||||
|
||||
This option toggles between verbose and terse answers. The default is to print the answer in a
|
||||
verbose form.
|
||||
|
||||
``+[no]comments``
|
||||
.. option:: +[no]comments
|
||||
|
||||
This option toggles the display of comment lines in the output. The default is to
|
||||
print comments.
|
||||
|
||||
``+[no]rrcomments``
|
||||
.. option:: +[no]rrcomments
|
||||
|
||||
This option toggles the display of per-record comments in the output (for example,
|
||||
human-readable key information about DNSKEY records). The default is
|
||||
to print per-record comments.
|
||||
|
||||
``+[no]crypto``
|
||||
.. option:: +[no]crypto
|
||||
|
||||
This option toggles the display of cryptographic fields in DNSSEC records. The
|
||||
contents of these fields are unnecessary to debug most DNSSEC
|
||||
validation failures and removing them makes it easier to see the
|
||||
@@ -265,62 +294,71 @@ assign values to options like the timeout interval. They have the form
|
||||
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
||||
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
||||
|
||||
``+[no]trust``
|
||||
.. option:: +[no]trust
|
||||
|
||||
This option controls whether to display the trust level when printing a record.
|
||||
The default is to display the trust level.
|
||||
|
||||
``+[no]split[=W]``
|
||||
.. option:: +[no]split[=W]
|
||||
|
||||
This option splits long hex- or base64-formatted fields in resource records into
|
||||
chunks of ``W`` characters (where ``W`` is rounded up to the nearest
|
||||
multiple of 4). ``+nosplit`` or ``+split=0`` causes fields not to be
|
||||
split at all. The default is 56 characters, or 44 characters when
|
||||
multiline mode is active.
|
||||
|
||||
``+[no]all``
|
||||
.. option:: +[no]all
|
||||
|
||||
This option sets or clears the display options ``+[no]comments``,
|
||||
``+[no]rrcomments``, and ``+[no]trust`` as a group.
|
||||
|
||||
``+[no]multiline``
|
||||
.. option:: +[no]multiline
|
||||
|
||||
This option prints long records (such as RRSIG, DNSKEY, and SOA records) in a
|
||||
verbose multi-line format with human-readable comments. The default
|
||||
is to print each record on a single line, to facilitate machine
|
||||
parsing of the ``delv`` output.
|
||||
parsing of the :program:`delv` output.
|
||||
|
||||
``+[no]dnssec``
|
||||
This option indicates whether to display RRSIG records in the ``delv`` output.
|
||||
The default is to do so. Note that (unlike in ``dig``) this does
|
||||
.. option:: +[no]dnssec
|
||||
|
||||
This option indicates whether to display RRSIG records in the :program:`delv` output.
|
||||
The default is to do so. Note that (unlike in :iscman:`dig`) this does
|
||||
*not* control whether to request DNSSEC records or to
|
||||
validate them. DNSSEC records are always requested, and validation
|
||||
always occurs unless suppressed by the use of ``-i`` or
|
||||
always occurs unless suppressed by the use of :option:`-i` or
|
||||
``+noroot``.
|
||||
|
||||
``+[no]root[=ROOT]``
|
||||
.. option:: +[no]root[=ROOT]
|
||||
|
||||
This option indicates whether to perform conventional DNSSEC validation, and if so,
|
||||
specifies the name of a trust anchor. The default is to validate using a
|
||||
trust anchor of "." (the root zone), for which there is a built-in key. If
|
||||
specifying a different trust anchor, then ``-a`` must be used to specify a
|
||||
specifying a different trust anchor, then :option:`-a` must be used to specify a
|
||||
file containing the key.
|
||||
|
||||
``+[no]tcp``
|
||||
.. option:: +[no]tcp
|
||||
|
||||
This option controls whether to use TCP when sending queries. The default is to
|
||||
use UDP unless a truncated response has been received.
|
||||
|
||||
``+[no]unknownformat``
|
||||
.. option:: +[no]unknownformat
|
||||
|
||||
This option prints all RDATA in unknown RR-type presentation format (:rfc:`3597`).
|
||||
The default is to print RDATA for known types in the type's
|
||||
presentation format.
|
||||
|
||||
``+[no]yaml``
|
||||
.. option:: +[no]yaml
|
||||
|
||||
This option prints response data in YAML format.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/bind.keys``
|
||||
|bind_keys|
|
||||
|
||||
``/etc/resolv.conf``
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`named(8)`, :rfc:`4034`, :rfc:`4035`, :rfc:`4431`, :rfc:`5074`, :rfc:`5155`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`named(8) <named>`, :rfc:`4034`, :rfc:`4035`, :rfc:`4431`, :rfc:`5074`, :rfc:`5155`.
|
||||
|
||||
+166
-48
@@ -59,7 +59,7 @@
|
||||
|
||||
dig_lookup_t *default_lookup = NULL;
|
||||
|
||||
static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uintptr_t batchname = 0;
|
||||
static FILE *batchfp = NULL;
|
||||
static char *argv0;
|
||||
static int addresscount = 0;
|
||||
@@ -113,7 +113,7 @@ usage(void) {
|
||||
fprintf(stderr, "Press <Help> for complete list of options\n");
|
||||
}
|
||||
#else /* if TARGET_OS_IPHONE */
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -125,12 +125,6 @@ usage(void) {
|
||||
}
|
||||
#endif /* if TARGET_OS_IPHONE */
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "DiG %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
/*% help */
|
||||
static void
|
||||
help(void) {
|
||||
@@ -232,7 +226,12 @@ help(void) {
|
||||
" +[no]https[=###] (DNS-over-HTTPS mode) "
|
||||
"[/]\n"
|
||||
" +[no]https-get (Use GET instead of "
|
||||
"default POST method\n"
|
||||
"default POST method while using HTTPS)\n"
|
||||
" +[no]http-plain[=###] (DNS over plain HTTP "
|
||||
"mode) "
|
||||
"[/]\n"
|
||||
" +[no]https-plain-get (Use GET instead of "
|
||||
"default POST method while using plain HTTP)\n"
|
||||
" +[no]identify (ID responders in short "
|
||||
"answers)\n"
|
||||
#ifdef HAVE_LIBIDN2
|
||||
@@ -295,6 +294,14 @@ help(void) {
|
||||
" +[no]tcp (TCP mode (+[no]vc))\n"
|
||||
" +timeout=### (Set query timeout) [5]\n"
|
||||
" +[no]tls (DNS-over-TLS mode)\n"
|
||||
" +[no]tls-ca[=file] (Enable remote server's "
|
||||
"TLS certificate validation)\n"
|
||||
" +[no]tls-hostname=hostname (Explicitly set "
|
||||
"the expected TLS hostname)\n"
|
||||
" +[no]tls-certfile=file (Load client TLS "
|
||||
"certificate chain from file)\n"
|
||||
" +[no]tls-keyfile=file (Load client TLS "
|
||||
"private key from file)\n"
|
||||
" +[no]trace (Trace delegation down "
|
||||
"from root "
|
||||
"[+dnssec])\n"
|
||||
@@ -346,7 +353,7 @@ received(unsigned int bytes, isc_sockaddr_t *from, dig_query_t *query) {
|
||||
} else {
|
||||
printf(";; Query time: %ld msec\n", (long)diff / 1000);
|
||||
}
|
||||
if (query->lookup->tls_mode) {
|
||||
if (dig_lookup_is_tls(query->lookup)) {
|
||||
proto = "TLS";
|
||||
} else if (query->lookup->https_mode) {
|
||||
if (query->lookup->http_plain) {
|
||||
@@ -496,10 +503,12 @@ dns64prefix_answer(dns_message_t *msg, isc_buffer_t *buf) {
|
||||
}
|
||||
|
||||
result = dns_dns64_findprefix(rdataset, prefix, &count);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
return (ISC_R_SUCCESS);
|
||||
if (count > 10)
|
||||
}
|
||||
if (count > 10) {
|
||||
count = 10;
|
||||
}
|
||||
for (i = 0; i < count; i++) {
|
||||
result = isc_netaddr_totext(&prefix[i].addr, buf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -909,8 +918,9 @@ repopulate_buffer:
|
||||
check_result(result, "dns_message_sectiontotext");
|
||||
} else if (dns64prefix) {
|
||||
result = dns64prefix_answer(msg, buf);
|
||||
if (result == ISC_R_NOSPACE)
|
||||
if (result == ISC_R_NOSPACE) {
|
||||
goto buftoosmall;
|
||||
}
|
||||
check_result(result, "dns64prefix_answer");
|
||||
} else {
|
||||
result = short_answer(msg, flags, buf, query);
|
||||
@@ -1018,6 +1028,128 @@ printgreeting(int argc, char **argv, dig_lookup_t *lookup) {
|
||||
}
|
||||
}
|
||||
|
||||
#define FULLCHECK(A) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if (_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
#define FULLCHECK2(A, B) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if ((_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) && \
|
||||
(_l >= sizeof(B) || strncasecmp(cmd, B, _l) != 0)) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
#define FULLCHECK6(A, B, C, D, E, F) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if ((_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) && \
|
||||
(_l >= sizeof(B) || strncasecmp(cmd, B, _l) != 0) && \
|
||||
(_l >= sizeof(C) || strncasecmp(cmd, C, _l) != 0) && \
|
||||
(_l >= sizeof(D) || strncasecmp(cmd, D, _l) != 0) && \
|
||||
(_l >= sizeof(E) || strncasecmp(cmd, E, _l) != 0) && \
|
||||
(_l >= sizeof(F) || strncasecmp(cmd, F, _l) != 0)) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
|
||||
static bool
|
||||
plus_tls_options(const char *cmd, const char *value, const bool state,
|
||||
dig_lookup_t *lookup) {
|
||||
/*
|
||||
* Using TLS implies "TCP-like" mode.
|
||||
*/
|
||||
if (!lookup->tcp_mode_set) {
|
||||
lookup->tcp_mode = state;
|
||||
}
|
||||
switch (cmd[3]) {
|
||||
case '-':
|
||||
/*
|
||||
* Assume that if any of the +tls-* options are set, then we
|
||||
* need to verify the remote certificate (compatibility with
|
||||
* kdig).
|
||||
*/
|
||||
if (state) {
|
||||
lookup->tls_ca_set = state;
|
||||
}
|
||||
switch (cmd[4]) {
|
||||
case 'c':
|
||||
switch (cmd[5]) {
|
||||
case 'a':
|
||||
FULLCHECK("tls-ca");
|
||||
lookup->tls_ca_set = state;
|
||||
if (state && value != NULL) {
|
||||
lookup->tls_ca_file =
|
||||
isc_mem_strdup(mctx, value);
|
||||
}
|
||||
break;
|
||||
case 'e':
|
||||
FULLCHECK("tls-certfile");
|
||||
lookup->tls_cert_file_set = state;
|
||||
if (state) {
|
||||
if (value != NULL && *value != '\0') {
|
||||
lookup->tls_cert_file =
|
||||
isc_mem_strdup(mctx,
|
||||
value);
|
||||
} else {
|
||||
fprintf(stderr,
|
||||
";; TLS certificate "
|
||||
"file is "
|
||||
"not specified\n");
|
||||
goto invalid_option;
|
||||
}
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
}
|
||||
break;
|
||||
case 'h':
|
||||
FULLCHECK("tls-hostname");
|
||||
lookup->tls_hostname_set = state;
|
||||
if (state) {
|
||||
if (value != NULL && *value != '\0') {
|
||||
lookup->tls_hostname =
|
||||
isc_mem_strdup(mctx, value);
|
||||
} else {
|
||||
fprintf(stderr, ";; TLS hostname is "
|
||||
"not specified\n");
|
||||
goto invalid_option;
|
||||
}
|
||||
}
|
||||
break;
|
||||
case 'k':
|
||||
FULLCHECK("tls-keyfile");
|
||||
lookup->tls_key_file_set = state;
|
||||
if (state) {
|
||||
if (value != NULL && *value != '\0') {
|
||||
lookup->tls_key_file =
|
||||
isc_mem_strdup(mctx, value);
|
||||
} else {
|
||||
fprintf(stderr,
|
||||
";; TLS private key file is "
|
||||
"not specified\n");
|
||||
goto invalid_option;
|
||||
}
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
}
|
||||
break;
|
||||
case '\0':
|
||||
FULLCHECK("tls");
|
||||
lookup->tls_mode = state;
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
}
|
||||
|
||||
return true;
|
||||
invalid_option:
|
||||
return false;
|
||||
}
|
||||
|
||||
/*%
|
||||
* We're not using isc_commandline_parse() here since the command line
|
||||
* syntax of dig is quite a bit different from that which can be described
|
||||
@@ -1047,31 +1179,6 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
/* parse the rest of the string */
|
||||
value = strtok_r(NULL, "", &last);
|
||||
|
||||
#define FULLCHECK(A) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if (_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
#define FULLCHECK2(A, B) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if ((_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) && \
|
||||
(_l >= sizeof(B) || strncasecmp(cmd, B, _l) != 0)) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
#define FULLCHECK6(A, B, C, D, E, F) \
|
||||
do { \
|
||||
size_t _l = strlen(cmd); \
|
||||
if ((_l >= sizeof(A) || strncasecmp(cmd, A, _l) != 0) && \
|
||||
(_l >= sizeof(B) || strncasecmp(cmd, B, _l) != 0) && \
|
||||
(_l >= sizeof(C) || strncasecmp(cmd, C, _l) != 0) && \
|
||||
(_l >= sizeof(D) || strncasecmp(cmd, D, _l) != 0) && \
|
||||
(_l >= sizeof(E) || strncasecmp(cmd, E, _l) != 0) && \
|
||||
(_l >= sizeof(F) || strncasecmp(cmd, F, _l) != 0)) \
|
||||
goto invalid_option; \
|
||||
} while (0)
|
||||
|
||||
switch (cmd[0]) {
|
||||
case 'a':
|
||||
switch (cmd[1]) {
|
||||
@@ -1515,8 +1622,11 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
case 'i':
|
||||
FULLCHECK("idnin");
|
||||
#ifndef HAVE_LIBIDN2
|
||||
fprintf(stderr, ";; IDN input support"
|
||||
if (state) {
|
||||
fprintf(stderr,
|
||||
";; IDN input support"
|
||||
" not enabled\n");
|
||||
}
|
||||
#else /* ifndef HAVE_LIBIDN2 */
|
||||
lookup->idnin = state;
|
||||
#endif /* ifndef HAVE_LIBIDN2 */
|
||||
@@ -1524,8 +1634,11 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
case 'o':
|
||||
FULLCHECK("idnout");
|
||||
#ifndef HAVE_LIBIDN2
|
||||
fprintf(stderr, ";; IDN output support"
|
||||
if (state) {
|
||||
fprintf(stderr,
|
||||
";; IDN output support"
|
||||
" not enabled\n");
|
||||
}
|
||||
#else /* ifndef HAVE_LIBIDN2 */
|
||||
lookup->idnout = state;
|
||||
#endif /* ifndef HAVE_LIBIDN2 */
|
||||
@@ -1934,10 +2047,15 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
}
|
||||
break;
|
||||
case 'l':
|
||||
FULLCHECK("tls");
|
||||
lookup->tls_mode = state;
|
||||
if (!lookup->tcp_mode_set) {
|
||||
lookup->tcp_mode = state;
|
||||
switch (cmd[2]) {
|
||||
case 's':
|
||||
if (!plus_tls_options(cmd, value, state,
|
||||
lookup)) {
|
||||
goto invalid_option;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
goto invalid_option;
|
||||
}
|
||||
break;
|
||||
case 'o':
|
||||
@@ -2112,7 +2230,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
have_ipv6 = false;
|
||||
} else {
|
||||
fatal("can't find IPv4 networking");
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (false);
|
||||
}
|
||||
break;
|
||||
@@ -2122,7 +2240,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
have_ipv4 = false;
|
||||
} else {
|
||||
fatal("can't find IPv6 networking");
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (false);
|
||||
}
|
||||
break;
|
||||
@@ -2158,7 +2276,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
(*lookup)->use_usec = true;
|
||||
break;
|
||||
case 'v':
|
||||
version();
|
||||
printf("DiG %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
break;
|
||||
}
|
||||
@@ -2374,7 +2492,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
fprintf(stderr, "Invalid option: -%s\n", option);
|
||||
usage();
|
||||
}
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (false);
|
||||
}
|
||||
|
||||
|
||||
+265
-146
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dig
|
||||
.. program:: dig
|
||||
.. _man_dig:
|
||||
|
||||
dig - DNS lookup utility
|
||||
@@ -27,41 +29,41 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dig`` is a flexible tool for interrogating DNS name servers. It
|
||||
:program:`dig` is a flexible tool for interrogating DNS name servers. It
|
||||
performs DNS lookups and displays the answers that are returned from the
|
||||
name server(s) that were queried. Most DNS administrators use ``dig`` to
|
||||
name server(s) that were queried. Most DNS administrators use :program:`dig` to
|
||||
troubleshoot DNS problems because of its flexibility, ease of use, and
|
||||
clarity of output. Other lookup tools tend to have less functionality
|
||||
than ``dig``.
|
||||
than :program:`dig`.
|
||||
|
||||
Although ``dig`` is normally used with command-line arguments, it also
|
||||
Although :program:`dig` is normally used with command-line arguments, it also
|
||||
has a batch mode of operation for reading lookup requests from a file. A
|
||||
brief summary of its command-line arguments and options is printed when
|
||||
the ``-h`` option is given. The BIND 9
|
||||
implementation of ``dig`` allows multiple lookups to be issued from the
|
||||
the :option:`-h` option is given. The BIND 9
|
||||
implementation of :program:`dig` allows multiple lookups to be issued from the
|
||||
command line.
|
||||
|
||||
Unless it is told to query a specific name server, ``dig`` tries each
|
||||
Unless it is told to query a specific name server, :program:`dig` tries each
|
||||
of the servers listed in ``/etc/resolv.conf``. If no usable server
|
||||
addresses are found, ``dig`` sends the query to the local host.
|
||||
addresses are found, :program:`dig` sends the query to the local host.
|
||||
|
||||
When no command-line arguments or options are given, ``dig``
|
||||
When no command-line arguments or options are given, :program:`dig`
|
||||
performs an NS query for "." (the root).
|
||||
|
||||
It is possible to set per-user defaults for ``dig`` via
|
||||
It is possible to set per-user defaults for :program:`dig` via
|
||||
``${HOME}/.digrc``. This file is read and any options in it are applied
|
||||
before the command-line arguments. The ``-r`` option disables this
|
||||
before the command-line arguments. The :option:`-r` option disables this
|
||||
feature, for scripts that need predictable behavior.
|
||||
|
||||
The IN and CH class names overlap with the IN and CH top-level domain
|
||||
names. Either use the ``-t`` and ``-c`` options to specify the type and
|
||||
class, use the ``-q`` to specify the domain name, or use "IN." and
|
||||
names. Either use the :option:`-t` and :option:`-c` options to specify the type and
|
||||
class, use the :option:`-q` to specify the domain name, or use "IN." and
|
||||
"CH." when looking up these top-level domains.
|
||||
|
||||
Simple Usage
|
||||
~~~~~~~~~~~~
|
||||
|
||||
A typical invocation of ``dig`` looks like:
|
||||
A typical invocation of :program:`dig` looks like:
|
||||
|
||||
::
|
||||
|
||||
@@ -69,83 +71,101 @@ A typical invocation of ``dig`` looks like:
|
||||
|
||||
where:
|
||||
|
||||
``server``
|
||||
.. option:: server
|
||||
|
||||
is the name or IP address of the name server to query. This can be an
|
||||
IPv4 address in dotted-decimal notation or an IPv6 address in
|
||||
colon-delimited notation. When the supplied ``server`` argument is a
|
||||
hostname, ``dig`` resolves that name before querying that name
|
||||
hostname, :program:`dig` resolves that name before querying that name
|
||||
server.
|
||||
|
||||
If no ``server`` argument is provided, ``dig`` consults
|
||||
If no ``server`` argument is provided, :program:`dig` consults
|
||||
``/etc/resolv.conf``; if an address is found there, it queries the
|
||||
name server at that address. If either of the ``-4`` or ``-6``
|
||||
name server at that address. If either of the :option:`-4` or :option:`-6`
|
||||
options are in use, then only addresses for the corresponding
|
||||
transport are tried. If no usable addresses are found, ``dig``
|
||||
transport are tried. If no usable addresses are found, :program:`dig`
|
||||
sends the query to the local host. The reply from the name server
|
||||
that responds is displayed.
|
||||
|
||||
``name``
|
||||
.. option:: name
|
||||
|
||||
is the name of the resource record that is to be looked up.
|
||||
|
||||
``type``
|
||||
.. option:: type
|
||||
|
||||
indicates what type of query is required - ANY, A, MX, SIG, etc.
|
||||
``type`` can be any valid query type. If no ``type`` argument is
|
||||
supplied, ``dig`` performs a lookup for an A record.
|
||||
supplied, :program:`dig` performs a lookup for an A record.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option indicates that only IPv4 should be used.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option indicates that only IPv6 should be used.
|
||||
|
||||
``-b address[#port]``
|
||||
.. option:: -b address[#port]
|
||||
|
||||
This option sets the source IP address of the query. The ``address`` must be a
|
||||
valid address on one of the host's network interfaces, or "0.0.0.0"
|
||||
or "::". An optional port may be specified by appending ``#port``.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option sets the query class. The default ``class`` is IN; other classes are
|
||||
HS for Hesiod records or CH for Chaosnet records.
|
||||
|
||||
``-f file``
|
||||
This option sets batch mode, in which ``dig`` reads a list of lookup requests to process from
|
||||
.. option:: -f file
|
||||
|
||||
This option sets batch mode, in which :program:`dig` reads a list of lookup requests to process from
|
||||
the given ``file``. Each line in the file should be organized in the
|
||||
same way it would be presented as a query to ``dig`` using the
|
||||
same way it would be presented as a query to :program:`dig` using the
|
||||
command-line interface.
|
||||
|
||||
``-k keyfile``
|
||||
This option tells ``named`` to sign queries using TSIG using a key read from the given file. Key
|
||||
files can be generated using ``tsig-keygen``. When using TSIG
|
||||
authentication with ``dig``, the name server that is queried needs to
|
||||
.. option:: -h
|
||||
|
||||
Print a usage summary.
|
||||
|
||||
.. option:: -k keyfile
|
||||
|
||||
This option tells :iscman:`named` to sign queries using TSIG using a key read from the given file. Key
|
||||
files can be generated using :iscman:`tsig-keygen`. When using TSIG
|
||||
authentication with :program:`dig`, the name server that is queried needs to
|
||||
know the key and algorithm that is being used. In BIND, this is done
|
||||
by providing appropriate ``key`` and ``server`` statements in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
.. option:: -m
|
||||
|
||||
``-m``
|
||||
This option enables memory usage debugging.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option sends the query to a non-standard port on the server, instead of the
|
||||
default port 53. This option is used to test a name server that
|
||||
has been configured to listen for queries on a non-standard port
|
||||
number.
|
||||
|
||||
``-q name``
|
||||
.. option:: -q name
|
||||
|
||||
This option specifies the domain name to query. This is useful to distinguish the ``name``
|
||||
from other arguments.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option indicates that options from ``${HOME}/.digrc`` should not be read. This is useful for
|
||||
scripts that need predictable behavior.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the resource record type to query, which can be any valid query type. If
|
||||
it is a resource record type supported in BIND 9, it can be given by
|
||||
the type mnemonic (such as ``NS`` or ``AAAA``). The default query type is
|
||||
``A``, unless the ``-x`` option is supplied to indicate a reverse
|
||||
``A``, unless the :option:`-x` option is supplied to indicate a reverse
|
||||
lookup. A zone transfer can be requested by specifying a type of
|
||||
AXFR. When an incremental zone transfer (IXFR) is required, set the
|
||||
``type`` to ``ixfr=N``. The incremental zone transfer contains
|
||||
@@ -156,23 +176,27 @@ Options
|
||||
the number of the type. If the resource record type is not supported
|
||||
in BIND 9, the result is displayed as described in :rfc:`3597`.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option indicates that print query times should be provided in microseconds instead of milliseconds.
|
||||
|
||||
``-v``
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-x addr``
|
||||
.. option:: -x addr
|
||||
|
||||
This option sets simplified reverse lookups, for mapping addresses to names. The
|
||||
``addr`` is an IPv4 address in dotted-decimal notation, or a
|
||||
colon-delimited IPv6 address. When the ``-x`` option is used, there is no
|
||||
colon-delimited IPv6 address. When the :option:`-x` option is used, there is no
|
||||
need to provide the ``name``, ``class``, and ``type`` arguments.
|
||||
``dig`` automatically performs a lookup for a name like
|
||||
:program:`dig` automatically performs a lookup for a name like
|
||||
``94.2.0.192.in-addr.arpa`` and sets the query type and class to PTR
|
||||
and IN respectively. IPv6 addresses are looked up using nibble format
|
||||
under the IP6.ARPA domain.
|
||||
|
||||
``-y [hmac:]keyname:secret``
|
||||
.. option:: -y [hmac:]keyname:secret
|
||||
|
||||
This option signs queries using TSIG with the given authentication key.
|
||||
``keyname`` is the name of the key, and ``secret`` is the
|
||||
base64-encoded shared secret. ``hmac`` is the name of the key algorithm;
|
||||
@@ -181,15 +205,15 @@ Options
|
||||
not specified, the default is ``hmac-md5``; if MD5 was disabled, the default is
|
||||
``hmac-sha256``.
|
||||
|
||||
.. note:: Only the ``-k`` option should be used, rather than the ``-y`` option,
|
||||
because with ``-y`` the shared secret is supplied as a command-line
|
||||
.. note:: Only the :option:`-k` option should be used, rather than the :option:`-y` option,
|
||||
because with :option:`-y` the shared secret is supplied as a command-line
|
||||
argument in clear text. This may be visible in the output from ``ps1`` or
|
||||
in a history file maintained by the user's shell.
|
||||
|
||||
Query Options
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``dig`` provides a number of query options which affect the way in which
|
||||
:program:`dig` provides a number of query options which affect the way in which
|
||||
lookups are made and the results displayed. Some of these set or reset
|
||||
flag bits in the query header, some determine which sections of the
|
||||
answer get printed, and others determine the timeout and retry
|
||||
@@ -203,17 +227,21 @@ assign values to options, like the timeout interval. They have the form
|
||||
abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+cdflag``. The query options are:
|
||||
|
||||
``+[no]aaflag``
|
||||
.. option:: +[no]aaflag
|
||||
|
||||
This option is a synonym for ``+[no]aaonly``.
|
||||
|
||||
``+[no]aaonly``
|
||||
.. option:: +[no]aaonly
|
||||
|
||||
This option sets the ``aa`` flag in the query.
|
||||
|
||||
``+[no]additional``
|
||||
.. option:: +[no]additional
|
||||
|
||||
This option displays [or does not display] the additional section of a reply. The
|
||||
default is to display it.
|
||||
|
||||
``+[no]adflag``
|
||||
.. option:: +[no]adflag
|
||||
|
||||
This option sets [or does not set] the AD (authentic data) bit in the query. This
|
||||
requests the server to return whether all of the answer and authority
|
||||
sections have been validated as secure, according to the security
|
||||
@@ -222,44 +250,54 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
indicates that some part of the answer was insecure or not validated.
|
||||
This bit is set by default.
|
||||
|
||||
``+[no]all``
|
||||
.. option:: +[no]all
|
||||
|
||||
This option sets or clears all display flags.
|
||||
|
||||
``+[no]answer``
|
||||
.. option:: +[no]answer
|
||||
|
||||
This option displays [or does not display] the answer section of a reply. The default
|
||||
is to display it.
|
||||
|
||||
``+[no]authority``
|
||||
.. option:: +[no]authority
|
||||
|
||||
This option displays [or does not display] the authority section of a reply. The
|
||||
default is to display it.
|
||||
|
||||
``+[no]badcookie``
|
||||
.. option:: +[no]badcookie
|
||||
|
||||
This option retries the lookup with a new server cookie if a BADCOOKIE response is
|
||||
received.
|
||||
|
||||
``+[no]besteffort``
|
||||
.. option:: +[no]besteffort
|
||||
|
||||
This option attempts to display the contents of messages which are malformed. The
|
||||
default is to not display malformed answers.
|
||||
|
||||
``+bufsize[=B]``
|
||||
.. option:: +bufsize[=B]
|
||||
|
||||
This option sets the UDP message buffer size advertised using EDNS0 to
|
||||
``B`` bytes. The maximum and minimum sizes of this buffer are 65535 and
|
||||
0, respectively. ``+bufsize`` restores the default buffer size.
|
||||
|
||||
``+[no]cdflag``
|
||||
.. option:: +[no]cdflag
|
||||
|
||||
This option sets [or does not set] the CD (checking disabled) bit in the query. This
|
||||
requests the server to not perform DNSSEC validation of responses.
|
||||
|
||||
``+[no]class``
|
||||
.. option:: +[no]class
|
||||
|
||||
This option displays [or does not display] the CLASS when printing the record.
|
||||
|
||||
``+[no]cmd``
|
||||
.. option:: +[no]cmd
|
||||
|
||||
This option toggles the printing of the initial comment in the output, identifying the
|
||||
version of ``dig`` and the query options that have been applied. This option
|
||||
version of :program:`dig` and the query options that have been applied. This option
|
||||
always has a global effect; it cannot be set globally and then overridden on a
|
||||
per-lookup basis. The default is to print this comment.
|
||||
|
||||
``+[no]comments``
|
||||
.. option:: +[no]comments
|
||||
|
||||
This option toggles the display of some comment lines in the output, with
|
||||
information about the packet header and OPT pseudosection, and the names of
|
||||
the response section. The default is to print these comments.
|
||||
@@ -268,7 +306,8 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
can be controlled using other command-line switches. These include
|
||||
``+[no]cmd``, ``+[no]question``, ``+[no]stats``, and ``+[no]rrcomments``.
|
||||
|
||||
``+[no]cookie=####``
|
||||
.. option:: +[no]cookie=####
|
||||
|
||||
This option sends [or does not send] a COOKIE EDNS option, with an optional value. Replaying a COOKIE
|
||||
from a previous response allows the server to identify a previous
|
||||
client. The default is ``+cookie``.
|
||||
@@ -276,7 +315,8 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+cookie`` is also set when ``+trace`` is set to better emulate the
|
||||
default queries from a nameserver.
|
||||
|
||||
``+[no]crypto``
|
||||
.. option:: +[no]crypto
|
||||
|
||||
This option toggles the display of cryptographic fields in DNSSEC records. The
|
||||
contents of these fields are unnecessary for debugging most DNSSEC
|
||||
validation failures and removing them makes it easier to see the
|
||||
@@ -284,62 +324,75 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
||||
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
||||
|
||||
``+[no]defname``
|
||||
.. option:: +[no]defname
|
||||
|
||||
This option, which is deprecated, is treated as a synonym for ``+[no]search``.
|
||||
|
||||
``+[no]dns64prefix``
|
||||
.. option:: +[no]dns64prefix
|
||||
|
||||
Lookup IPV4ONLY.ARPA AAAA and print any DNS64 prefixes found.
|
||||
|
||||
``+[no]dnssec``
|
||||
.. option:: +[no]dnssec
|
||||
|
||||
This option requests that DNSSEC records be sent by setting the DNSSEC OK (DO) bit in
|
||||
the OPT record in the additional section of the query.
|
||||
|
||||
``+domain=somename``
|
||||
.. option:: +domain=somename
|
||||
|
||||
This option sets the search list to contain the single domain ``somename``, as if
|
||||
specified in a ``domain`` directive in ``/etc/resolv.conf``, and
|
||||
enables search list processing as if the ``+search`` option were
|
||||
given.
|
||||
|
||||
``+dscp=value``
|
||||
.. option:: +dscp=value
|
||||
|
||||
This option sets the DSCP code point to be used when sending the query. Valid DSCP
|
||||
code points are in the range [0...63]. By default no code point is
|
||||
explicitly set.
|
||||
|
||||
``+[no]edns[=#]``
|
||||
.. option:: +[no]edns[=#]
|
||||
|
||||
This option specifies the EDNS version to query with. Valid values are 0 to 255.
|
||||
Setting the EDNS version causes an EDNS query to be sent.
|
||||
``+noedns`` clears the remembered EDNS version. EDNS is set to 0 by
|
||||
default.
|
||||
|
||||
``+[no]ednsflags[=#]``
|
||||
.. option:: +[no]ednsflags[=#]
|
||||
|
||||
This option sets the must-be-zero EDNS flags bits (Z bits) to the specified value.
|
||||
Decimal, hex, and octal encodings are accepted. Setting a named flag
|
||||
(e.g., DO) is silently ignored. By default, no Z bits are set.
|
||||
|
||||
``+[no]ednsnegotiation``
|
||||
.. option:: +[no]ednsnegotiation
|
||||
|
||||
This option enables/disables EDNS version negotiation. By default, EDNS version
|
||||
negotiation is enabled.
|
||||
|
||||
``+[no]ednsopt[=code[:value]]``
|
||||
.. option:: +[no]ednsopt[=code[:value]]
|
||||
|
||||
This option specifies the EDNS option with code point ``code`` and an optional payload
|
||||
of ``value`` as a hexadecimal string. ``code`` can be either an EDNS
|
||||
option name (for example, ``NSID`` or ``ECS``) or an arbitrary
|
||||
numeric value. ``+noednsopt`` clears the EDNS options to be sent.
|
||||
|
||||
``+[no]expire``
|
||||
.. option:: +[no]expire
|
||||
|
||||
This option sends an EDNS Expire option.
|
||||
|
||||
``+[no]fail``
|
||||
This option indicates that ``named`` should try [or not try] the next server if a SERVFAIL is received. The default is
|
||||
.. option:: +[no]fail
|
||||
|
||||
This option indicates that :iscman:`named` should try [or not try] the next server if a SERVFAIL is received. The default is
|
||||
to not try the next server, which is the reverse of normal stub
|
||||
resolver behavior.
|
||||
|
||||
``+[no]header-only``
|
||||
.. option:: +[no]header-only
|
||||
|
||||
This option sends a query with a DNS header without a question section. The
|
||||
default is to add a question section. The query type and query name
|
||||
are ignored when this is set.
|
||||
|
||||
``+[no]https[=value]``
|
||||
.. option:: +[no]https[=value]
|
||||
|
||||
This option indicates whether to use DNS over HTTPS (DoH) when querying
|
||||
name servers. When this option is in use, the port number defaults to 443.
|
||||
The HTTP POST request mode is used when sending the query.
|
||||
@@ -348,64 +401,77 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
query URI; the default is ``/dns-query``. So, for example, ``dig
|
||||
@example.com +https`` will use the URI ``https://example.com/dns-query``.
|
||||
|
||||
``+[no]https-get[=value]``
|
||||
.. option:: +[no]https-get[=value]
|
||||
|
||||
Similar to ``+https``, except that the HTTP GET request mode is used
|
||||
when sending the query.
|
||||
|
||||
``+[no]https-post[=value]``
|
||||
.. option:: +[no]https-post[=value]
|
||||
|
||||
Same as ``+https``.
|
||||
|
||||
``+[no]http-plain[=value]``
|
||||
.. option:: +[no]http-plain[=value]
|
||||
|
||||
Similar to ``+https``, except that HTTP queries will be sent over a
|
||||
non-encrypted channel. When this option is in use, the port number
|
||||
defaults to 80 and the HTTP request mode is POST.
|
||||
|
||||
``+[no]http-plain-get[=value]``
|
||||
.. option:: +[no]http-plain-get[=value]
|
||||
|
||||
Similar to ``+http-plain``, except that the HTTP request mode is GET.
|
||||
|
||||
``+[no]http-plain-post[=value]``
|
||||
.. option:: +[no]http-plain-post[=value]
|
||||
|
||||
Same as ``+http-plain``.
|
||||
|
||||
``+[no]identify``
|
||||
.. option:: +[no]identify
|
||||
|
||||
This option shows [or does not show] the IP address and port number that
|
||||
supplied the answer, when the ``+short`` option is enabled. If short
|
||||
form answers are requested, the default is not to show the source
|
||||
address and port number of the server that provided the answer.
|
||||
|
||||
``+[no]idnin``
|
||||
.. option:: +[no]idnin
|
||||
|
||||
This option processes [or does not process] IDN domain names on input. This requires
|
||||
``IDN SUPPORT`` to have been enabled at compile time.
|
||||
|
||||
The default is to process IDN input when standard output is a tty.
|
||||
The IDN processing on input is disabled when ``dig`` output is redirected
|
||||
The IDN processing on input is disabled when :program:`dig` output is redirected
|
||||
to files, pipes, and other non-tty file descriptors.
|
||||
|
||||
``+[no]idnout``
|
||||
.. option:: +[no]idnout
|
||||
|
||||
This option converts [or does not convert] puny code on output. This requires
|
||||
``IDN SUPPORT`` to have been enabled at compile time.
|
||||
|
||||
The default is to process puny code on output when standard output is
|
||||
a tty. The puny code processing on output is disabled when ``dig`` output
|
||||
a tty. The puny code processing on output is disabled when :program:`dig` output
|
||||
is redirected to files, pipes, and other non-tty file descriptors.
|
||||
|
||||
``+[no]ignore``
|
||||
.. option:: +[no]ignore
|
||||
|
||||
This option ignores [or does not ignore] truncation in UDP responses instead of retrying with TCP. By
|
||||
default, TCP retries are performed.
|
||||
|
||||
``+[no]keepalive``
|
||||
.. option:: +[no]keepalive
|
||||
|
||||
This option sends [or does not send] an EDNS Keepalive option.
|
||||
|
||||
``+[no]keepopen``
|
||||
.. option:: +[no]keepopen
|
||||
|
||||
This option keeps [or does not keep] the TCP socket open between queries, and reuses it rather than
|
||||
creating a new TCP socket for each lookup. The default is
|
||||
``+nokeepopen``.
|
||||
|
||||
``+[no]multiline``
|
||||
.. option:: +[no]multiline
|
||||
|
||||
This option prints [or does not print] records, like the SOA records, in a verbose multi-line format
|
||||
with human-readable comments. The default is to print each record on
|
||||
a single line to facilitate machine parsing of the ``dig`` output.
|
||||
a single line to facilitate machine parsing of the :program:`dig` output.
|
||||
|
||||
.. option:: +ndots=D
|
||||
|
||||
``+ndots=D``
|
||||
This option sets the number of dots (``D``) that must appear in ``name`` for
|
||||
it to be considered absolute. The default value is that defined using
|
||||
the ``ndots`` statement in ``/etc/resolv.conf``, or 1 if no ``ndots``
|
||||
@@ -414,24 +480,29 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``search`` or ``domain`` directive in ``/etc/resolv.conf`` if
|
||||
``+search`` is set.
|
||||
|
||||
``+[no]nsid``
|
||||
.. option:: +[no]nsid
|
||||
|
||||
When enabled, this option includes an EDNS name server ID request when sending a query.
|
||||
|
||||
``+[no]nssearch``
|
||||
When this option is set, ``dig`` attempts to find the authoritative
|
||||
.. option:: +[no]nssearch
|
||||
|
||||
When this option is set, :program:`dig` attempts to find the authoritative
|
||||
name servers for the zone containing the name being looked up, and
|
||||
display the SOA record that each name server has for the zone.
|
||||
Addresses of servers that did not respond are also printed.
|
||||
|
||||
``+[no]onesoa``
|
||||
.. option:: +[no]onesoa
|
||||
|
||||
When enabled, this option prints only one (starting) SOA record when performing an AXFR. The
|
||||
default is to print both the starting and ending SOA records.
|
||||
|
||||
``+[no]opcode=value``
|
||||
.. option:: +[no]opcode=value
|
||||
|
||||
When enabled, this option sets (restores) the DNS message opcode to the specified value. The
|
||||
default value is QUERY (0).
|
||||
|
||||
``+padding=value``
|
||||
.. option:: +padding=value
|
||||
|
||||
This option pads the size of the query packet using the EDNS Padding option to
|
||||
blocks of ``value`` bytes. For example, ``+padding=32`` causes a
|
||||
48-byte query to be padded to 64 bytes. The default block size is 0,
|
||||
@@ -440,42 +511,51 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
mandatory. Responses to padded queries may also be padded, but only
|
||||
if the query uses TCP or DNS COOKIE.
|
||||
|
||||
``+qid=value``
|
||||
.. option:: +qid=value
|
||||
|
||||
This option specifies the query ID to use when sending queries.
|
||||
|
||||
``+[no]qr``
|
||||
.. option:: +[no]qr
|
||||
|
||||
This option toggles the display of the query message as it is sent. By default, the query
|
||||
is not printed.
|
||||
|
||||
``+[no]question``
|
||||
.. option:: +[no]question
|
||||
|
||||
This option toggles the display of the question section of a query when an answer is
|
||||
returned. The default is to print the question section as a comment.
|
||||
|
||||
``+[no]raflag``
|
||||
.. option:: +[no]raflag
|
||||
|
||||
This option sets [or does not set] the RA (Recursion Available) bit in the query. The
|
||||
default is ``+noraflag``. This bit is ignored by the server for
|
||||
QUERY.
|
||||
|
||||
``+[no]rdflag``
|
||||
.. option:: +[no]rdflag
|
||||
|
||||
This option is a synonym for ``+[no]recurse``.
|
||||
|
||||
``+[no]recurse``
|
||||
.. option:: +[no]recurse
|
||||
|
||||
This option toggles the setting of the RD (recursion desired) bit in the query.
|
||||
This bit is set by default, which means ``dig`` normally sends
|
||||
This bit is set by default, which means :program:`dig` normally sends
|
||||
recursive queries. Recursion is automatically disabled when the
|
||||
``+nssearch`` or ``+trace`` query option is used.
|
||||
|
||||
``+retry=T``
|
||||
.. option:: +retry=T
|
||||
|
||||
This option sets the number of times to retry UDP and TCP queries to server to ``T``
|
||||
instead of the default, 2. Unlike ``+tries``, this does not include
|
||||
the initial query.
|
||||
|
||||
``+[no]rrcomments``
|
||||
.. option:: +[no]rrcomments
|
||||
|
||||
This option toggles the display of per-record comments in the output (for example,
|
||||
human-readable key information about DNSKEY records). The default is
|
||||
not to print record comments unless multiline mode is active.
|
||||
|
||||
``+[no]search``
|
||||
.. option:: +[no]search
|
||||
|
||||
This option uses [or does not use] the search list defined by the searchlist or domain
|
||||
directive in ``resolv.conf``, if any. The search list is not used by
|
||||
default.
|
||||
@@ -484,36 +564,43 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+ndots``, determines whether the name is treated as relative
|
||||
and hence whether a search is eventually performed.
|
||||
|
||||
``+[no]short``
|
||||
.. option:: +[no]short
|
||||
|
||||
This option toggles whether a terse answer is provided. The default is to print the answer in a verbose
|
||||
form. This option always has a global effect; it cannot be set globally and
|
||||
then overridden on a per-lookup basis.
|
||||
|
||||
``+[no]showbadcookie``
|
||||
.. option:: +[no]showbadcookie
|
||||
|
||||
This option toggles whether to show the message containing the
|
||||
BADCOOKIE rcode before retrying the request or not. The default
|
||||
is to not show the messages.
|
||||
|
||||
``+[no]showsearch``
|
||||
.. option:: +[no]showsearch
|
||||
|
||||
This option performs [or does not perform] a search showing intermediate results.
|
||||
|
||||
``+[no]sigchase``
|
||||
This feature is now obsolete and has been removed; use ``delv``
|
||||
.. option:: +[no]sigchase
|
||||
|
||||
This feature is now obsolete and has been removed; use :iscman:`delv`
|
||||
instead.
|
||||
|
||||
``+split=W``
|
||||
.. option:: +split=W
|
||||
|
||||
This option splits long hex- or base64-formatted fields in resource records into
|
||||
chunks of ``W`` characters (where ``W`` is rounded up to the nearest
|
||||
multiple of 4). ``+nosplit`` or ``+split=0`` causes fields not to be
|
||||
split at all. The default is 56 characters, or 44 characters when
|
||||
multiline mode is active.
|
||||
|
||||
``+[no]stats``
|
||||
.. option:: +[no]stats
|
||||
|
||||
This option toggles the printing of statistics: when the query was made, the size of the
|
||||
reply, etc. The default behavior is to print the query statistics as a
|
||||
comment after each lookup.
|
||||
|
||||
``+[no]subnet=addr[/prefix-length]``
|
||||
.. option:: +[no]subnet=addr[/prefix-length]
|
||||
|
||||
This option sends [or does not send] an EDNS CLIENT-SUBNET option with the specified IP
|
||||
address or network prefix.
|
||||
|
||||
@@ -522,33 +609,57 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
prefix-length of zero, which signals a resolver that the client's
|
||||
address information must *not* be used when resolving this query.
|
||||
|
||||
``+[no]tcflag``
|
||||
.. option:: +[no]tcflag
|
||||
|
||||
This option sets [or does not set] the TC (TrunCation) bit in the query. The default is
|
||||
``+notcflag``. This bit is ignored by the server for QUERY.
|
||||
|
||||
``+[no]tcp``
|
||||
.. option:: +[no]tcp
|
||||
|
||||
This option indicates whether to use TCP when querying name servers.
|
||||
The default behavior is to use UDP unless a type ``any`` or ``ixfr=N``
|
||||
query is requested, in which case the default is TCP. AXFR queries
|
||||
always use TCP.
|
||||
|
||||
``+timeout=T``
|
||||
.. option:: +timeout=T
|
||||
|
||||
This option sets the timeout for a query to ``T`` seconds. The default timeout is
|
||||
5 seconds. An attempt to set ``T`` to less than 1 is silently set to 1.
|
||||
|
||||
``+[no]tls``
|
||||
.. option:: +[no]tls
|
||||
|
||||
This option indicates whether to use DNS over TLS (DoT) when querying
|
||||
name servers. When this option is in use, the port number defaults
|
||||
to 853.
|
||||
|
||||
``+[no]topdown``
|
||||
``+[no]tls-ca[=file-name]``
|
||||
This option enables remote server TLS certificate validation for
|
||||
DNS transports, relying on TLS. Certificate authorities
|
||||
certificates are loaded from the specified PEM file
|
||||
(``file-name``). If the file is not specified, the default
|
||||
certificates from the global certificates store are used.
|
||||
|
||||
``+[no]tls-certfile=file-name`` and ``+[no]tls-keyfile=file-name``
|
||||
These options set the state of certificate-based client
|
||||
authentication for DNS transports, relying on TLS. Both certificate
|
||||
chain file and private key file are expected to be in PEM format.
|
||||
Both options must be specified at the same time.
|
||||
|
||||
``+[no]tls-hostname=hostname``
|
||||
This option makes ``dig`` use the provided hostname during remote
|
||||
server TLS certificate verification. Otherwise, the DNS server name
|
||||
is used. This option has no effect if ``+tls-ca`` is not specified.
|
||||
|
||||
.. option:: +[no]topdown
|
||||
|
||||
This feature is related to ``dig +sigchase``, which is obsolete and
|
||||
has been removed. Use ``delv`` instead.
|
||||
has been removed. Use :iscman:`delv` instead.
|
||||
|
||||
.. option:: +[no]trace
|
||||
|
||||
``+[no]trace``
|
||||
This option toggles tracing of the delegation path from the root name servers for
|
||||
the name being looked up. Tracing is disabled by default. When
|
||||
tracing is enabled, ``dig`` makes iterative queries to resolve the
|
||||
tracing is enabled, :program:`dig` makes iterative queries to resolve the
|
||||
name being looked up. It follows referrals from the root servers,
|
||||
showing the answer from each server that was used to resolve the
|
||||
lookup.
|
||||
@@ -559,46 +670,54 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+dnssec`` is also set when ``+trace`` is set, to better emulate the
|
||||
default queries from a name server.
|
||||
|
||||
``+tries=T``
|
||||
.. option:: +tries=T
|
||||
|
||||
This option sets the number of times to try UDP and TCP queries to server to ``T``
|
||||
instead of the default, 3. If ``T`` is less than or equal to zero,
|
||||
the number of tries is silently rounded up to 1.
|
||||
|
||||
``+trusted-key=####``
|
||||
.. option:: +trusted-key=####
|
||||
|
||||
This option formerly specified trusted keys for use with ``dig +sigchase``. This
|
||||
feature is now obsolete and has been removed; use ``delv`` instead.
|
||||
feature is now obsolete and has been removed; use :iscman:`delv` instead.
|
||||
|
||||
.. option:: +[no]ttlid
|
||||
|
||||
``+[no]ttlid``
|
||||
This option displays [or does not display] the TTL when printing the record.
|
||||
|
||||
``+[no]ttlunits``
|
||||
.. option:: +[no]ttlunits
|
||||
|
||||
This option displays [or does not display] the TTL in friendly human-readable time
|
||||
units of ``s``, ``m``, ``h``, ``d``, and ``w``, representing seconds, minutes,
|
||||
hours, days, and weeks. This implies ``+ttlid``.
|
||||
|
||||
``+[no]unknownformat``
|
||||
.. option:: +[no]unknownformat
|
||||
|
||||
This option prints all RDATA in unknown RR type presentation format (:rfc:`3597`).
|
||||
The default is to print RDATA for known types in the type's
|
||||
presentation format.
|
||||
|
||||
``+[no]vc``
|
||||
.. option:: +[no]vc
|
||||
|
||||
This option uses [or does not use] TCP when querying name servers. This alternate
|
||||
syntax to ``+[no]tcp`` is provided for backwards compatibility. The
|
||||
``vc`` stands for "virtual circuit."
|
||||
|
||||
``+[no]yaml``
|
||||
.. option:: +[no]yaml
|
||||
|
||||
When enabled, this option prints the responses (and, if ``+qr`` is in use, also the
|
||||
outgoing queries) in a detailed YAML format.
|
||||
|
||||
``+[no]zflag``
|
||||
.. option:: +[no]zflag
|
||||
|
||||
This option sets [or does not set] the last unassigned DNS header flag in a DNS query.
|
||||
This flag is off by default.
|
||||
|
||||
Multiple Queries
|
||||
~~~~~~~~~~~~~~~~
|
||||
|
||||
The BIND 9 implementation of ``dig`` supports specifying multiple
|
||||
queries on the command line (in addition to supporting the ``-f`` batch
|
||||
The BIND 9 implementation of :program:`dig` supports specifying multiple
|
||||
queries on the command line (in addition to supporting the :option:`-f` batch
|
||||
file option). Each of those queries can be supplied with its own set of
|
||||
flags, options, and query options.
|
||||
|
||||
@@ -619,19 +738,19 @@ query options. For example:
|
||||
|
||||
dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||
|
||||
shows how ``dig`` can be used from the command line to make three
|
||||
shows how :program:`dig` can be used from the command line to make three
|
||||
lookups: an ANY query for ``www.isc.org``, a reverse lookup of 127.0.0.1,
|
||||
and a query for the NS records of ``isc.org``. A global query option of
|
||||
``+qr`` is applied, so that ``dig`` shows the initial query it made for
|
||||
``+qr`` is applied, so that :program:`dig` shows the initial query it made for
|
||||
each lookup. The final query has a local query option of ``+noqr`` which
|
||||
means that ``dig`` does not print the initial query when it looks up the
|
||||
means that :program:`dig` does not print the initial query when it looks up the
|
||||
NS records for ``isc.org``.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``dig`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``dig``
|
||||
If :program:`dig` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`dig`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, use the parameters
|
||||
@@ -641,7 +760,7 @@ variable.
|
||||
Return Codes
|
||||
~~~~~~~~~~~~
|
||||
|
||||
``dig`` return codes are:
|
||||
:program:`dig` return codes are:
|
||||
|
||||
``0``
|
||||
DNS response received, including NXDOMAIN status
|
||||
@@ -668,7 +787,7 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`delv(1)`, :manpage:`host(1)`, :manpage:`named(8)`, :manpage:`dnssec-keygen(8)`, :rfc:`1035`.
|
||||
:iscman:`delv(1) <delv>`, :iscman:`host(1) <host>`, :iscman:`named(8) <named>`, :iscman:`dnssec-keygen(8) <dnssec-keygen>`, :rfc:`1035`.
|
||||
|
||||
Bugs
|
||||
~~~~
|
||||
|
||||
+471
-118
@@ -89,7 +89,7 @@ dig_lookuplist_t lookup_list;
|
||||
dig_serverlist_t server_list;
|
||||
dig_searchlistlist_t search_list;
|
||||
|
||||
static atomic_bool cancel_now = ATOMIC_VAR_INIT(false);
|
||||
static atomic_bool cancel_now = false;
|
||||
|
||||
bool check_ra = false, have_ipv4 = false, have_ipv6 = false,
|
||||
specified_source = false, free_now = false, usesearch = false,
|
||||
@@ -105,8 +105,8 @@ isc_nm_t *netmgr = NULL;
|
||||
isc_taskmgr_t *taskmgr = NULL;
|
||||
isc_task_t *global_task = NULL;
|
||||
isc_sockaddr_t localaddr;
|
||||
isc_refcount_t sendcount = ATOMIC_VAR_INIT(0);
|
||||
isc_refcount_t recvcount = ATOMIC_VAR_INIT(0);
|
||||
isc_refcount_t sendcount = 0;
|
||||
isc_refcount_t recvcount = 0;
|
||||
int ndots = -1;
|
||||
int tries = -1;
|
||||
int lookup_counter = 0;
|
||||
@@ -231,6 +231,9 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
static void
|
||||
start_udp(dig_query_t *query);
|
||||
|
||||
static void
|
||||
start_tcp(dig_query_t *query);
|
||||
|
||||
static void
|
||||
force_next(dig_query_t *query);
|
||||
|
||||
@@ -639,6 +642,8 @@ make_empty_lookup(void) {
|
||||
ISC_LIST_INIT(looknew->q);
|
||||
ISC_LIST_INIT(looknew->my_server_list);
|
||||
|
||||
looknew->tls_ctx_cache = isc_tlsctx_cache_new(mctx);
|
||||
|
||||
isc_refcount_init(&looknew->references, 1);
|
||||
|
||||
looknew->magic = DIG_LOOKUP_MAGIC;
|
||||
@@ -729,6 +734,30 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
||||
looknew->https_get = lookold->https_get;
|
||||
looknew->http_plain = lookold->http_plain;
|
||||
|
||||
looknew->tls_ca_set = lookold->tls_ca_set;
|
||||
if (lookold->tls_ca_file != NULL) {
|
||||
looknew->tls_ca_file = isc_mem_strdup(mctx,
|
||||
lookold->tls_ca_file);
|
||||
};
|
||||
|
||||
looknew->tls_hostname_set = lookold->tls_hostname_set;
|
||||
if (lookold->tls_hostname != NULL) {
|
||||
looknew->tls_hostname = isc_mem_strdup(mctx,
|
||||
lookold->tls_hostname);
|
||||
}
|
||||
|
||||
looknew->tls_key_file_set = lookold->tls_key_file_set;
|
||||
if (lookold->tls_key_file != NULL) {
|
||||
looknew->tls_key_file = isc_mem_strdup(mctx,
|
||||
lookold->tls_key_file);
|
||||
}
|
||||
|
||||
looknew->tls_cert_file_set = lookold->tls_cert_file_set;
|
||||
if (lookold->tls_cert_file != NULL) {
|
||||
looknew->tls_cert_file = isc_mem_strdup(mctx,
|
||||
lookold->tls_cert_file);
|
||||
}
|
||||
|
||||
looknew->showbadcookie = lookold->showbadcookie;
|
||||
looknew->sendcookie = lookold->sendcookie;
|
||||
looknew->seenbadcookie = lookold->seenbadcookie;
|
||||
@@ -794,6 +823,11 @@ clone_lookup(dig_lookup_t *lookold, bool servers) {
|
||||
dns_fixedname_name(&looknew->fdomain));
|
||||
|
||||
if (servers) {
|
||||
if (lookold->tls_ctx_cache != NULL) {
|
||||
isc_tlsctx_cache_detach(&looknew->tls_ctx_cache);
|
||||
isc_tlsctx_cache_attach(lookold->tls_ctx_cache,
|
||||
&looknew->tls_ctx_cache);
|
||||
}
|
||||
clone_server_list(lookold->my_server_list,
|
||||
&looknew->my_server_list);
|
||||
}
|
||||
@@ -1520,6 +1554,30 @@ check_if_done(void) {
|
||||
}
|
||||
}
|
||||
|
||||
/*%
|
||||
* Check if we're done with all the queries in the lookup, except for
|
||||
* the `except_q` query (can be NULL if no exception is required).
|
||||
* Expects `l` to be a valid and locked lookup.
|
||||
*/
|
||||
static bool
|
||||
check_if_queries_done(dig_lookup_t *l, dig_query_t *except_q) {
|
||||
dig_query_t *q = ISC_LIST_HEAD(l->q);
|
||||
|
||||
debug("check_if_queries_done(%p)", l);
|
||||
|
||||
while (q != NULL) {
|
||||
if (!q->started || isc_refcount_current(&q->references) > 1) {
|
||||
if (!q->canceled && q != except_q) {
|
||||
debug("there is a pending query %p", q);
|
||||
return (false);
|
||||
}
|
||||
}
|
||||
q = ISC_LIST_NEXT(q, link);
|
||||
}
|
||||
|
||||
return (true);
|
||||
}
|
||||
|
||||
static void
|
||||
_destroy_lookup(dig_lookup_t *lookup) {
|
||||
dig_server_t *s;
|
||||
@@ -1574,6 +1632,26 @@ _destroy_lookup(dig_lookup_t *lookup) {
|
||||
isc_mem_free(mctx, lookup->https_path);
|
||||
}
|
||||
|
||||
if (lookup->tls_ctx_cache != NULL) {
|
||||
isc_tlsctx_cache_detach(&lookup->tls_ctx_cache);
|
||||
}
|
||||
|
||||
if (lookup->tls_ca_file != NULL) {
|
||||
isc_mem_free(mctx, lookup->tls_ca_file);
|
||||
}
|
||||
|
||||
if (lookup->tls_hostname != NULL) {
|
||||
isc_mem_free(mctx, lookup->tls_hostname);
|
||||
}
|
||||
|
||||
if (lookup->tls_key_file != NULL) {
|
||||
isc_mem_free(mctx, lookup->tls_key_file);
|
||||
}
|
||||
|
||||
if (lookup->tls_cert_file != NULL) {
|
||||
isc_mem_free(mctx, lookup->tls_cert_file);
|
||||
}
|
||||
|
||||
isc_mem_free(mctx, lookup);
|
||||
}
|
||||
|
||||
@@ -2075,7 +2153,6 @@ _new_query(dig_lookup_t *lookup, char *servname, char *userarg,
|
||||
*query = (dig_query_t){ .sendbuf = lookup->renderbuf,
|
||||
.servname = servname,
|
||||
.userarg = userarg,
|
||||
.first_pass = true,
|
||||
.warn_id = true,
|
||||
.recvspace = isc_mem_get(mctx, COMMSIZE),
|
||||
.tmpsendspace = isc_mem_get(mctx, COMMSIZE) };
|
||||
@@ -2468,8 +2545,7 @@ setup_lookup(dig_lookup_t *lookup) {
|
||||
memmove(addr, &sin6->sin6_addr, addrl);
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
isc_buffer_init(&b, ecsbuf, sizeof(ecsbuf));
|
||||
@@ -2616,18 +2692,29 @@ send_done(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
|
||||
isc_nmhandle_detach(&query->sendhandle);
|
||||
|
||||
if (eresult != ISC_R_SUCCESS) {
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
debug("send failed: %s", isc_result_totext(eresult));
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
debug("send_done: cancel");
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
|
||||
lookup_detach(&l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
debug("send failed: %s", isc_result_totext(eresult));
|
||||
cancel_lookup(l);
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
|
||||
lookup_attach(query->lookup, &l);
|
||||
if (l->ns_search_only && !l->trace_root && !l->tcp_mode) {
|
||||
if (l->ns_search_only && !l->trace_root) {
|
||||
bool tcp_mode = l->tcp_mode;
|
||||
|
||||
debug("sending next, since searching");
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
|
||||
@@ -2637,7 +2724,11 @@ send_done(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
if (next == NULL) {
|
||||
clear_current_lookup();
|
||||
} else {
|
||||
start_udp(next);
|
||||
if (tcp_mode) {
|
||||
start_tcp(next);
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
|
||||
check_if_done();
|
||||
@@ -2666,6 +2757,12 @@ _cancel_lookup(dig_lookup_t *lookup, const char *file, unsigned int line) {
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
ISC_LIST_DEQUEUE(lookup->q, query, link);
|
||||
debug("canceling pending query %p, belonging to %p", query,
|
||||
query->lookup);
|
||||
query->canceled = true;
|
||||
if (query->readhandle != NULL) {
|
||||
isc_nm_cancelread(query->readhandle);
|
||||
}
|
||||
query_detach(&query);
|
||||
query = next;
|
||||
}
|
||||
@@ -2674,6 +2771,106 @@ _cancel_lookup(dig_lookup_t *lookup, const char *file, unsigned int line) {
|
||||
check_if_done();
|
||||
}
|
||||
|
||||
static isc_tlsctx_t *
|
||||
get_create_tls_context(dig_query_t *query, const bool is_https) {
|
||||
isc_result_t result;
|
||||
isc_tlsctx_t *ctx = NULL, *found_ctx = NULL;
|
||||
isc_tls_cert_store_t *store = NULL, *found_store = NULL;
|
||||
char tlsctxname[ISC_SOCKADDR_FORMATSIZE];
|
||||
const uint16_t family = isc_sockaddr_pf(&query->sockaddr) == PF_INET6
|
||||
? AF_INET6
|
||||
: AF_INET;
|
||||
isc_tlsctx_cache_transport_t transport =
|
||||
is_https ? isc_tlsctx_cache_https : isc_tlsctx_cache_tls;
|
||||
const bool hostname_ignore_subject = !is_https;
|
||||
|
||||
if (query->lookup->tls_key_file_set != query->lookup->tls_cert_file_set)
|
||||
{
|
||||
return (NULL);
|
||||
}
|
||||
|
||||
isc_sockaddr_format(&query->sockaddr, tlsctxname, sizeof(tlsctxname));
|
||||
|
||||
result = isc_tlsctx_cache_find(query->lookup->tls_ctx_cache, tlsctxname,
|
||||
transport, family, &found_ctx,
|
||||
&found_store);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
if (query->lookup->tls_ca_set) {
|
||||
if (found_store == NULL) {
|
||||
result = isc_tls_cert_store_create(
|
||||
query->lookup->tls_ca_file, &store);
|
||||
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto failure;
|
||||
}
|
||||
} else {
|
||||
store = found_store;
|
||||
}
|
||||
}
|
||||
|
||||
result = isc_tlsctx_createclient(&ctx);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto failure;
|
||||
}
|
||||
|
||||
if (store != NULL) {
|
||||
const char *hostname =
|
||||
query->lookup->tls_hostname_set
|
||||
? query->lookup->tls_hostname
|
||||
: query->userarg;
|
||||
/*
|
||||
* According to RFC 8310, Subject field MUST NOT be
|
||||
* inspected when verifying hostname for DoT. Only
|
||||
* SubjectAltName must be checked. That is NOT the case
|
||||
* for HTTPS.
|
||||
*/
|
||||
result = isc_tlsctx_enable_peer_verification(
|
||||
ctx, false, store, hostname,
|
||||
hostname_ignore_subject);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto failure;
|
||||
}
|
||||
}
|
||||
|
||||
if (query->lookup->tls_key_file_set &&
|
||||
query->lookup->tls_cert_file_set) {
|
||||
result = isc_tlsctx_load_certificate(
|
||||
ctx, query->lookup->tls_key_file,
|
||||
query->lookup->tls_cert_file);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto failure;
|
||||
}
|
||||
}
|
||||
|
||||
if (!is_https) {
|
||||
isc_tlsctx_enable_dot_client_alpn(ctx);
|
||||
}
|
||||
|
||||
#if HAVE_LIBNGHTTP2
|
||||
if (is_https) {
|
||||
isc_tlsctx_enable_http2client_alpn(ctx);
|
||||
}
|
||||
#endif /* HAVE_LIBNGHTTP2 */
|
||||
|
||||
result = isc_tlsctx_cache_add(query->lookup->tls_ctx_cache,
|
||||
tlsctxname, transport, family,
|
||||
ctx, store, NULL, NULL);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
return (ctx);
|
||||
}
|
||||
|
||||
INSIST(!query->lookup->tls_ca_set || found_store != NULL);
|
||||
return (found_ctx);
|
||||
failure:
|
||||
if (ctx != NULL && found_ctx != ctx) {
|
||||
isc_tlsctx_free(&ctx);
|
||||
}
|
||||
if (store != NULL && store != found_store) {
|
||||
isc_tls_cert_store_free(&store);
|
||||
}
|
||||
return (NULL);
|
||||
}
|
||||
|
||||
static void
|
||||
tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg);
|
||||
|
||||
@@ -2685,19 +2882,24 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg);
|
||||
static void
|
||||
start_tcp(dig_query_t *query) {
|
||||
isc_result_t result;
|
||||
dig_query_t *next;
|
||||
dig_query_t *next = NULL;
|
||||
dig_query_t *connectquery = NULL;
|
||||
isc_tlsctx_t *tlsctx = NULL;
|
||||
bool tls_mode = false;
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
|
||||
debug("start_tcp(%p)", query);
|
||||
|
||||
query_attach(query, &query->lookup->current_query);
|
||||
|
||||
tls_mode = dig_lookup_is_tls(query->lookup);
|
||||
|
||||
/*
|
||||
* For TLS connections, we want to override the default
|
||||
* port number.
|
||||
*/
|
||||
if (!port_set) {
|
||||
if (query->lookup->tls_mode) {
|
||||
if (tls_mode) {
|
||||
port = 853;
|
||||
} else if (query->lookup->https_mode &&
|
||||
!query->lookup->http_plain) {
|
||||
@@ -2775,14 +2977,17 @@ start_tcp(dig_query_t *query) {
|
||||
|
||||
REQUIRE(query != NULL);
|
||||
|
||||
if (query->lookup->tls_mode) {
|
||||
result = isc_tlsctx_createclient(&query->tlsctx);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
isc_tlsctx_enable_dot_client_alpn(query->tlsctx);
|
||||
query_attach(query, &connectquery);
|
||||
|
||||
if (tls_mode) {
|
||||
tlsctx = get_create_tls_context(connectquery, false);
|
||||
if (tlsctx == NULL) {
|
||||
goto failure_tls;
|
||||
}
|
||||
isc_nm_tlsdnsconnect(netmgr, &localaddr,
|
||||
&query->sockaddr, tcp_connected,
|
||||
query, local_timeout, 0,
|
||||
query->tlsctx);
|
||||
connectquery, local_timeout,
|
||||
tlsctx);
|
||||
#if HAVE_LIBNGHTTP2
|
||||
} else if (query->lookup->https_mode) {
|
||||
char uri[4096] = { 0 };
|
||||
@@ -2792,42 +2997,49 @@ start_tcp(dig_query_t *query) {
|
||||
uri, sizeof(uri));
|
||||
|
||||
if (!query->lookup->http_plain) {
|
||||
result =
|
||||
isc_tlsctx_createclient(&query->tlsctx);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
isc_tlsctx_enable_http2client_alpn(
|
||||
query->tlsctx);
|
||||
tlsctx = get_create_tls_context(connectquery,
|
||||
true);
|
||||
if (tlsctx == NULL) {
|
||||
goto failure_tls;
|
||||
}
|
||||
}
|
||||
|
||||
isc_nm_httpconnect(netmgr, &localaddr, &query->sockaddr,
|
||||
uri, !query->lookup->https_get,
|
||||
tcp_connected, query, query->tlsctx,
|
||||
local_timeout, 0);
|
||||
tcp_connected, connectquery, tlsctx,
|
||||
local_timeout);
|
||||
#endif
|
||||
} else {
|
||||
isc_nm_tcpdnsconnect(netmgr, &localaddr,
|
||||
&query->sockaddr, tcp_connected,
|
||||
query, local_timeout, 0);
|
||||
connectquery, local_timeout);
|
||||
}
|
||||
|
||||
/* XXX: set DSCP */
|
||||
}
|
||||
|
||||
/*
|
||||
* If we're at the endgame of a nameserver search, we need to
|
||||
* immediately bring up all the queries. Do it here.
|
||||
*/
|
||||
if (query->lookup->ns_search_only && !query->lookup->trace_root) {
|
||||
debug("sending next, since searching");
|
||||
if (ISC_LINK_LINKED(query, link)) {
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
ISC_LIST_DEQUEUE(query->lookup->q, query, link);
|
||||
} else {
|
||||
next = NULL;
|
||||
}
|
||||
if (next != NULL) {
|
||||
start_tcp(next);
|
||||
}
|
||||
return;
|
||||
|
||||
failure_tls:
|
||||
if (query->lookup->tls_key_file_set != query->lookup->tls_cert_file_set)
|
||||
{
|
||||
dighost_warning(
|
||||
"both TLS client certificate and key file must be "
|
||||
"specified a the same time");
|
||||
} else {
|
||||
dighost_warning("TLS context cannot be created");
|
||||
}
|
||||
|
||||
if (ISC_LINK_LINKED(query, link)) {
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
} else {
|
||||
next = NULL;
|
||||
}
|
||||
query_detach(&query);
|
||||
if (next == NULL) {
|
||||
clear_current_lookup();
|
||||
} else {
|
||||
start_tcp(next);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2861,10 +3073,9 @@ send_udp(dig_query_t *query) {
|
||||
debug("sendcount=%" PRIuFAST32, isc_refcount_current(&sendcount));
|
||||
|
||||
/* XXX qrflag, print_query, etc... */
|
||||
if (!ISC_LIST_EMPTY(query->lookup->q) && query->lookup->qr) {
|
||||
if (query->lookup->qr) {
|
||||
extrabytes = 0;
|
||||
dighost_printmessage(ISC_LIST_HEAD(query->lookup->q),
|
||||
&query->lookup->renderbuf,
|
||||
dighost_printmessage(query, &query->lookup->renderbuf,
|
||||
query->lookup->sendmsg, true);
|
||||
if (query->lookup->stats) {
|
||||
print_query_size(query);
|
||||
@@ -2878,27 +3089,51 @@ udp_ready(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
dig_query_t *readquery = NULL;
|
||||
int local_timeout = timeout * 1000;
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
REQUIRE(query->handle == NULL);
|
||||
|
||||
debug("udp_ready()");
|
||||
|
||||
query->started = true;
|
||||
|
||||
if (atomic_load(&cancel_now)) {
|
||||
query_detach(&query);
|
||||
return;
|
||||
}
|
||||
|
||||
INSIST(!free_now);
|
||||
|
||||
debug("udp_ready(%p, %s, %p)", handle, isc_result_totext(eresult),
|
||||
query);
|
||||
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
dig_lookup_t *l = query->lookup;
|
||||
|
||||
debug("in cancel handler");
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
return;
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
dig_lookup_t *l = query->lookup;
|
||||
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
debug("udp setup failed: %s",
|
||||
isc_result_totext(eresult));
|
||||
}
|
||||
debug("udp setup failed: %s", isc_result_totext(eresult));
|
||||
|
||||
if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
}
|
||||
query_detach(&query);
|
||||
cancel_lookup(l);
|
||||
lookup_detach(&l);
|
||||
query_detach(&query);
|
||||
return;
|
||||
}
|
||||
|
||||
query_attach(query, &readquery);
|
||||
|
||||
debug("recving with lookup=%p, query=%p, handle=%p", query->lookup,
|
||||
query, query->handle);
|
||||
query, handle);
|
||||
|
||||
query->handle = handle;
|
||||
isc_nmhandle_attach(handle, &query->readhandle);
|
||||
@@ -2981,7 +3216,7 @@ start_udp(dig_query_t *query) {
|
||||
query_attach(query, &connectquery);
|
||||
isc_nm_udpconnect(netmgr, &localaddr, &query->sockaddr, udp_ready,
|
||||
connectquery,
|
||||
(timeout ? timeout : UDP_TIMEOUT) * 1000, 0);
|
||||
(timeout ? timeout : UDP_TIMEOUT) * 1000);
|
||||
}
|
||||
|
||||
/*%
|
||||
@@ -3040,7 +3275,8 @@ force_next(dig_query_t *query) {
|
||||
|
||||
if (l->retries > 1) {
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left", l->retries);
|
||||
debug("making new %s request, %d tries left",
|
||||
l->tcp_mode ? "TCP" : "UDP", l->retries);
|
||||
requeue_lookup(l, true);
|
||||
lookup_detach(&l);
|
||||
isc_refcount_decrement0(&recvcount);
|
||||
@@ -3143,8 +3379,6 @@ launch_next_query(dig_query_t *query) {
|
||||
debug("have local timeout of %d", local_timeout);
|
||||
isc_nmhandle_settimeout(query->handle, local_timeout);
|
||||
|
||||
query_attach(query, &readquery);
|
||||
|
||||
xfr = query->lookup->rdtype == dns_rdatatype_ixfr ||
|
||||
query->lookup->rdtype == dns_rdatatype_axfr;
|
||||
if (xfr && isc_nm_socket_type(query->handle) == isc_nm_tlsdnssocket &&
|
||||
@@ -3163,6 +3397,8 @@ launch_next_query(dig_query_t *query) {
|
||||
return;
|
||||
}
|
||||
|
||||
query_attach(query, &readquery);
|
||||
|
||||
isc_nm_read(query->handle, recv_done, readquery);
|
||||
|
||||
if (!query->first_soa_rcvd) {
|
||||
@@ -3187,10 +3423,10 @@ launch_next_query(dig_query_t *query) {
|
||||
isc_refcount_current(&sendcount));
|
||||
|
||||
/* XXX qrflag, print_query, etc... */
|
||||
if (!ISC_LIST_EMPTY(l->q) && l->qr) {
|
||||
if (l->qr) {
|
||||
extrabytes = 0;
|
||||
dighost_printmessage(ISC_LIST_HEAD(l->q), &l->renderbuf,
|
||||
l->sendmsg, true);
|
||||
dighost_printmessage(query, &l->renderbuf, l->sendmsg,
|
||||
true);
|
||||
if (l->stats) {
|
||||
print_query_size(query);
|
||||
}
|
||||
@@ -3213,14 +3449,18 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||
dig_lookup_t *l = NULL;
|
||||
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
REQUIRE(query->handle == NULL);
|
||||
|
||||
debug("tcp_connected()");
|
||||
|
||||
query->started = true;
|
||||
|
||||
if (atomic_load(&cancel_now)) {
|
||||
query_detach(&query);
|
||||
return;
|
||||
}
|
||||
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
REQUIRE(query->handle == NULL);
|
||||
INSIST(!free_now);
|
||||
|
||||
debug("tcp_connected(%p, %s, %p)", handle, isc_result_totext(eresult),
|
||||
@@ -3229,13 +3469,27 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
LOCK_LOOKUP;
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (query->tlsctx != NULL) {
|
||||
isc_tlsctx_free(&query->tlsctx);
|
||||
}
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
if (eresult == ISC_R_CANCELED || eresult == ISC_R_TLSBADPEERCERT ||
|
||||
query->canceled)
|
||||
{
|
||||
debug("in cancel handler");
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
if (eresult == ISC_R_TLSBADPEERCERT) {
|
||||
dighost_warning(
|
||||
"TLS peer certificate verification for "
|
||||
"%s failed: %s",
|
||||
sockstr,
|
||||
isc_nm_verify_tls_peer_result_string(handle));
|
||||
} else if (query->lookup->rdtype == dns_rdatatype_ixfr ||
|
||||
query->lookup->rdtype == dns_rdatatype_axfr)
|
||||
{
|
||||
puts("; Transfer failed.");
|
||||
}
|
||||
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
clear_current_lookup();
|
||||
@@ -3245,12 +3499,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
debug("unsuccessful connection: %s",
|
||||
isc_result_totext(eresult));
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
dighost_warning("Connection to %s(%s) for %s failed: "
|
||||
"%s.",
|
||||
sockstr, query->servname, l->textname,
|
||||
isc_result_totext(eresult));
|
||||
}
|
||||
dighost_warning("Connection to %s(%s) for %s failed: %s.",
|
||||
sockstr, query->servname, l->textname,
|
||||
isc_result_totext(eresult));
|
||||
|
||||
/* XXX Clean up exitcodes */
|
||||
if (exitcode < 9) {
|
||||
@@ -3258,9 +3509,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
}
|
||||
|
||||
if (l->retries > 1) {
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
l->retries--;
|
||||
requeue_lookup(l, true);
|
||||
next = NULL;
|
||||
} else if ((l->current_query != NULL) &&
|
||||
@@ -3272,6 +3523,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
}
|
||||
|
||||
query_detach(&query);
|
||||
if (next == NULL) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
lookup_detach(&l);
|
||||
|
||||
if (next != NULL) {
|
||||
@@ -3579,70 +3833,159 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
isc_refcount_decrement0(&recvcount);
|
||||
debug("recvcount=%" PRIuFAST32, isc_refcount_current(&recvcount));
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
debug("recv_done: cancel");
|
||||
isc_nmhandle_detach(&query->readhandle);
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
clear_current_lookup();
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (query->lookup->use_usec) {
|
||||
TIME_NOW_HIRES(&query->time_recv);
|
||||
} else {
|
||||
TIME_NOW(&query->time_recv);
|
||||
}
|
||||
|
||||
if (eresult == ISC_R_TIMEDOUT && !l->tcp_mode && l->retries > 1) {
|
||||
dig_query_t *newq = NULL;
|
||||
|
||||
l->retries--;
|
||||
debug("resending UDP request to first server, %d tries left",
|
||||
l->retries);
|
||||
newq = new_query(l, query->servname, query->userarg);
|
||||
|
||||
ISC_LIST_PREPEND(l->q, newq, link);
|
||||
|
||||
start_udp(ISC_LIST_HEAD(l->q));
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
if ((!l->pending && !l->ns_search_only) || atomic_load(&cancel_now)) {
|
||||
debug("no longer pending. Got %s", isc_result_totext(eresult));
|
||||
|
||||
goto next_lookup;
|
||||
}
|
||||
|
||||
if (eresult != ISC_R_SUCCESS) {
|
||||
if (eresult == ISC_R_TIMEDOUT) {
|
||||
if (l->retries > 1 && !l->tcp_mode) {
|
||||
dig_query_t *newq = NULL;
|
||||
|
||||
/*
|
||||
* For UDP, insert a copy of the current query just
|
||||
* after itself in the list, and start it to retry the
|
||||
* request.
|
||||
*/
|
||||
newq = new_query(l, query->servname, query->userarg);
|
||||
ISC_LIST_INSERTAFTER(l->q, query, newq, link);
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
l->retries--;
|
||||
debug("making new UDP request, %d tries left",
|
||||
l->retries);
|
||||
start_udp(newq);
|
||||
}
|
||||
if (check_if_queries_done(l, query)) {
|
||||
goto cancel_lookup;
|
||||
}
|
||||
|
||||
goto detach_query;
|
||||
} else if (l->retries > 1 && l->tcp_mode) {
|
||||
/*
|
||||
* For TCP, we have to requeue the whole lookup, see
|
||||
* the comments above the start_tcp() function.
|
||||
*/
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
requeue_lookup(l, true);
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
|
||||
goto cancel_lookup;
|
||||
} else {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
|
||||
/*
|
||||
* No retries left, go to the next query, if there is
|
||||
* one.
|
||||
*/
|
||||
if (next != NULL) {
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
debug("starting next query %p", next);
|
||||
if (l->tcp_mode) {
|
||||
start_tcp(next);
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
if (check_if_queries_done(l, query)) {
|
||||
goto cancel_lookup;
|
||||
}
|
||||
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
/*
|
||||
* Otherwise, print the cmdline and an error message,
|
||||
* and cancel the lookup.
|
||||
*/
|
||||
printf("%s", l->cmdline);
|
||||
dighost_error("connection timed out; "
|
||||
"no servers could be reached\n");
|
||||
if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
}
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
|
||||
goto cancel_lookup;
|
||||
}
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
|
||||
if (eresult == ISC_R_TIMEDOUT) {
|
||||
if (l->retries > 1) {
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
l->retries--;
|
||||
requeue_lookup(l, true);
|
||||
} else {
|
||||
printf("%s", l->cmdline);
|
||||
dighost_error("connection timed out; "
|
||||
"no servers could be reached\n");
|
||||
if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
/*
|
||||
* There was a communication error with the current query,
|
||||
* go to the next query, if there is one.
|
||||
*/
|
||||
if (next != NULL) {
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
debug("starting next query %p", next);
|
||||
if (l->tcp_mode) {
|
||||
start_tcp(next);
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
dighost_error("communications error to %s: %s\n",
|
||||
sockstr, isc_result_totext(eresult));
|
||||
if (check_if_queries_done(l, query)) {
|
||||
goto cancel_lookup;
|
||||
}
|
||||
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
/*
|
||||
* Otherwise, print an error message and cancel the
|
||||
* lookup.
|
||||
*/
|
||||
dighost_error("communications error to %s: %s\n", sockstr,
|
||||
isc_result_totext(eresult));
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
|
||||
if (eresult == ISC_R_EOF) {
|
||||
requeue_or_update_exitcode(l);
|
||||
} else if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
}
|
||||
|
||||
goto cancel_lookup;
|
||||
@@ -3896,15 +4239,6 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* If our query is at the head of the list and there
|
||||
* is no next, we're the only one left, so fall
|
||||
* through to print the message.
|
||||
*/
|
||||
if ((ISC_LIST_HEAD(l->q) != query) ||
|
||||
(ISC_LIST_NEXT(query, link) != NULL)) {
|
||||
dighost_comments(l,
|
||||
"Got %s from %s, trying next "
|
||||
"server",
|
||||
@@ -3912,7 +4246,11 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
? "SERVFAIL reply"
|
||||
: "recursion not available",
|
||||
query->servname);
|
||||
goto next_lookup;
|
||||
if (check_if_queries_done(l, query)) {
|
||||
goto cancel_lookup;
|
||||
}
|
||||
|
||||
goto detach_query;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4030,7 +4368,12 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
l->trace_root = false;
|
||||
usesearch = false;
|
||||
} else {
|
||||
/*
|
||||
* This is a query in the followup lookup
|
||||
*/
|
||||
dighost_printmessage(query, &b, msg, true);
|
||||
|
||||
docancel = check_if_queries_done(l, query);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -4208,6 +4551,7 @@ cancel_all(void) {
|
||||
nq = ISC_LIST_NEXT(q, link);
|
||||
debug("canceling pending query %p, belonging to %p", q,
|
||||
current_lookup);
|
||||
q->canceled = true;
|
||||
if (q->readhandle != NULL) {
|
||||
isc_nm_cancelread(q->readhandle);
|
||||
}
|
||||
@@ -4480,3 +4824,12 @@ dig_idnsetup(dig_lookup_t *lookup, bool active) {
|
||||
return;
|
||||
#endif /* HAVE_LIBIDN2 */
|
||||
}
|
||||
|
||||
bool
|
||||
dig_lookup_is_tls(const dig_lookup_t *lookup) {
|
||||
if (lookup->tls_mode || (lookup->tls_ca_set && !lookup->https_mode)) {
|
||||
return (true);
|
||||
}
|
||||
|
||||
return (false);
|
||||
}
|
||||
|
||||
+18
-4
@@ -177,17 +177,29 @@ struct dig_lookup {
|
||||
bool https_get;
|
||||
char *https_path;
|
||||
};
|
||||
struct {
|
||||
bool tls_ca_set;
|
||||
char *tls_ca_file;
|
||||
bool tls_hostname_set;
|
||||
char *tls_hostname;
|
||||
bool tls_cert_file_set;
|
||||
char *tls_cert_file;
|
||||
bool tls_key_file_set;
|
||||
char *tls_key_file;
|
||||
isc_tlsctx_cache_t *tls_ctx_cache;
|
||||
};
|
||||
};
|
||||
|
||||
/*% The dig_query structure */
|
||||
struct dig_query {
|
||||
unsigned int magic;
|
||||
dig_lookup_t *lookup;
|
||||
bool first_pass;
|
||||
bool started;
|
||||
bool first_soa_rcvd;
|
||||
bool second_rr_rcvd;
|
||||
bool first_repeat_rcvd;
|
||||
bool warn_id;
|
||||
bool canceled;
|
||||
uint32_t first_rr_serial;
|
||||
uint32_t second_rr_serial;
|
||||
uint32_t msg_count;
|
||||
@@ -208,7 +220,6 @@ struct dig_query {
|
||||
isc_time_t time_recv;
|
||||
uint64_t byte_count;
|
||||
isc_timer_t *timer;
|
||||
isc_tlsctx_t *tlsctx;
|
||||
};
|
||||
|
||||
struct dig_server {
|
||||
@@ -275,13 +286,13 @@ getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp);
|
||||
isc_result_t
|
||||
get_reverse(char *reverse, size_t len, char *value, bool strict);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
void
|
||||
warn(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
digexit(void);
|
||||
|
||||
void
|
||||
@@ -446,4 +457,7 @@ dig_idnsetup(dig_lookup_t *lookup, bool active);
|
||||
void
|
||||
dig_shutdown(void);
|
||||
|
||||
bool
|
||||
dig_lookup_is_tls(const dig_lookup_t *lookup);
|
||||
|
||||
ISC_LANG_ENDDECLS
|
||||
|
||||
+3
-9
@@ -101,7 +101,7 @@ rcode_totext(dns_rcode_t rcode) {
|
||||
return (totext.deconsttext);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
show_usage(void);
|
||||
|
||||
static void
|
||||
@@ -584,12 +584,6 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
||||
|
||||
static const char *optstring = "46aAc:dilnm:p:rst:vVwCDN:R:TUW:";
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "host %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
static void
|
||||
pre_parse_args(int argc, char **argv) {
|
||||
int c;
|
||||
@@ -663,7 +657,7 @@ pre_parse_args(int argc, char **argv) {
|
||||
case 'v':
|
||||
break;
|
||||
case 'V':
|
||||
version();
|
||||
printf("host %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
break;
|
||||
case 'w':
|
||||
@@ -776,7 +770,7 @@ parse_args(bool is_batchfile, int argc, char **argv) {
|
||||
break;
|
||||
case 'A':
|
||||
list_almost_all = true;
|
||||
/* FALL THROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'a':
|
||||
if (!lookup->rdtypeset ||
|
||||
lookup->rdtype != dns_rdatatype_axfr) {
|
||||
|
||||
+76
-54
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: host
|
||||
.. program:: host
|
||||
.. _man_host:
|
||||
|
||||
host - DNS lookup utility
|
||||
@@ -24,55 +26,64 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``host`` is a simple utility for performing DNS lookups. It is normally
|
||||
:program:`host` is a simple utility for performing DNS lookups. It is normally
|
||||
used to convert names to IP addresses and vice versa. When no arguments
|
||||
or options are given, ``host`` prints a short summary of its
|
||||
or options are given, :program:`host` prints a short summary of its
|
||||
command-line arguments and options.
|
||||
|
||||
``name`` is the domain name that is to be looked up. It can also be a
|
||||
dotted-decimal IPv4 address or a colon-delimited IPv6 address, in which
|
||||
case ``host`` by default performs a reverse lookup for that address.
|
||||
case :program:`host` by default performs a reverse lookup for that address.
|
||||
``server`` is an optional argument which is either the name or IP
|
||||
address of the name server that ``host`` should query instead of the
|
||||
address of the name server that :program:`host` should query instead of the
|
||||
server or servers listed in ``/etc/resolv.conf``.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
This option specifies that only IPv4 should be used for query transport. See also the ``-6`` option.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option specifies that only IPv6 should be used for query transport. See also the ``-4`` option.
|
||||
This option specifies that only IPv4 should be used for query transport. See also the :option:`-6` option.
|
||||
|
||||
``-a``
|
||||
The ``-a`` ("all") option is normally equivalent to ``-v -t ANY``. It
|
||||
also affects the behavior of the ``-l`` list zone option.
|
||||
.. option:: -6
|
||||
|
||||
``-A``
|
||||
The ``-A`` ("almost all") option is equivalent to ``-a``, except that RRSIG,
|
||||
This option specifies that only IPv6 should be used for query transport. See also the :option:`-4` option.
|
||||
|
||||
.. option:: -a
|
||||
|
||||
The :option:`-a` ("all") option is normally equivalent to :option:`-v` :option:`-t ANY <-t>`. It
|
||||
also affects the behavior of the :option:`-l` list zone option.
|
||||
|
||||
.. option:: -A
|
||||
|
||||
The :option:`-A` ("almost all") option is equivalent to :option:`-a`, except that RRSIG,
|
||||
NSEC, and NSEC3 records are omitted from the output.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the query class, which can be used to lookup HS (Hesiod) or CH (Chaosnet)
|
||||
class resource records. The default class is IN (Internet).
|
||||
|
||||
``-C``
|
||||
This option indicates that ``named`` should check consistency, meaning that ``host`` queries the SOA records for zone
|
||||
.. option:: -C
|
||||
|
||||
This option indicates that :iscman:`named` should check consistency, meaning that :program:`host` queries the SOA records for zone
|
||||
``name`` from all the listed authoritative name servers for that
|
||||
zone. The list of name servers is defined by the NS records that are
|
||||
found for the zone.
|
||||
|
||||
``-d``
|
||||
This option prints debugging traces, and is equivalent to the ``-v`` verbose option.
|
||||
.. option:: -d
|
||||
|
||||
``-l``
|
||||
This option tells ``named`` to list the zone, meaning the ``host`` command performs a zone transfer of zone
|
||||
This option prints debugging traces, and is equivalent to the :option:`-v` verbose option.
|
||||
|
||||
.. option:: -l
|
||||
|
||||
This option tells :iscman:`named` to list the zone, meaning the :program:`host` command performs a zone transfer of zone
|
||||
``name`` and prints out the NS, PTR, and address records (A/AAAA).
|
||||
|
||||
Together, the ``-l -a`` options print all records in the zone.
|
||||
Together, the :option:`-l` :option:`-a` options print all records in the zone.
|
||||
|
||||
.. option:: -N ndots
|
||||
|
||||
``-N ndots``
|
||||
This option specifies the number of dots (``ndots``) that have to be in ``name`` for it to be
|
||||
considered absolute. The default value is that defined using the
|
||||
``ndots`` statement in ``/etc/resolv.conf``, or 1 if no ``ndots`` statement
|
||||
@@ -80,85 +91,96 @@ Options
|
||||
and are searched for in the domains listed in the ``search`` or
|
||||
``domain`` directive in ``/etc/resolv.conf``.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option specifies the port to query on the server. The default is 53.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option specifies a non-recursive query; setting this option clears the RD (recursion
|
||||
desired) bit in the query. This means that the name server
|
||||
receiving the query does not attempt to resolve ``name``. The ``-r``
|
||||
option enables ``host`` to mimic the behavior of a name server by
|
||||
receiving the query does not attempt to resolve ``name``. The :option:`-r`
|
||||
option enables :program:`host` to mimic the behavior of a name server by
|
||||
making non-recursive queries, and expecting to receive answers to
|
||||
those queries that can be referrals to other name servers.
|
||||
|
||||
``-R number``
|
||||
.. option:: -R number
|
||||
|
||||
This option specifies the number of retries for UDP queries. If ``number`` is negative or zero,
|
||||
the number of retries is silently set to 1. The default value is 1, or
|
||||
the value of the ``attempts`` option in ``/etc/resolv.conf``, if set.
|
||||
|
||||
``-s``
|
||||
This option tells ``named`` *not* to send the query to the next nameserver if any server responds
|
||||
.. option:: -s
|
||||
|
||||
This option tells :iscman:`named` *not* to send the query to the next nameserver if any server responds
|
||||
with a SERVFAIL response, which is the reverse of normal stub
|
||||
resolver behavior.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option specifies the query type. The ``type`` argument can be any recognized query type:
|
||||
CNAME, NS, SOA, TXT, DNSKEY, AXFR, etc.
|
||||
|
||||
When no query type is specified, ``host`` automatically selects an
|
||||
When no query type is specified, :program:`host` automatically selects an
|
||||
appropriate query type. By default, it looks for A, AAAA, and MX
|
||||
records. If the ``-C`` option is given, queries are made for SOA
|
||||
records. If the :option:`-C` option is given, queries are made for SOA
|
||||
records. If ``name`` is a dotted-decimal IPv4 address or
|
||||
colon-delimited IPv6 address, ``host`` queries for PTR records.
|
||||
colon-delimited IPv6 address, :program:`host` queries for PTR records.
|
||||
|
||||
If a query type of IXFR is chosen, the starting serial number can be
|
||||
specified by appending an equals sign (=), followed by the starting serial
|
||||
number, e.g., ``-t IXFR=12345678``.
|
||||
number, e.g., :option:`-t IXFR=12345678 <-t>`.
|
||||
|
||||
``-T``; ``-U``
|
||||
This option specifies TCP or UDP. By default, ``host`` uses UDP when making queries; the
|
||||
``-T`` option makes it use a TCP connection when querying the name
|
||||
.. option:: -T, -U
|
||||
|
||||
This option specifies TCP or UDP. By default, :program:`host` uses UDP when making queries; the
|
||||
:option:`-T` option makes it use a TCP connection when querying the name
|
||||
server. TCP is automatically selected for queries that require
|
||||
it, such as zone transfer (AXFR) requests. Type ``ANY`` queries default
|
||||
to TCP, but can be forced to use UDP initially via ``-U``.
|
||||
to TCP, but can be forced to use UDP initially via :option:`-U`.
|
||||
|
||||
.. option:: -m flag
|
||||
|
||||
``-m flag``
|
||||
This option sets memory usage debugging: the flag can be ``record``, ``usage``, or
|
||||
``trace``. The ``-m`` option can be specified more than once to set
|
||||
``trace``. The :option:`-m` option can be specified more than once to set
|
||||
multiple flags.
|
||||
|
||||
``-v``
|
||||
This option sets verbose output, and is equivalent to the ``-d`` debug option. Verbose output
|
||||
.. option:: -v
|
||||
|
||||
This option sets verbose output, and is equivalent to the :option:`-d` debug option. Verbose output
|
||||
can also be enabled by setting the ``debug`` option in
|
||||
``/etc/resolv.conf``.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-w``
|
||||
This option sets "wait forever": the query timeout is set to the maximum possible. See
|
||||
also the ``-W`` option.
|
||||
.. option:: -w
|
||||
|
||||
``-W wait``
|
||||
This options sets the length of the wait timeout, indicating that ``named`` should wait for up to ``wait`` seconds for a reply. If ``wait`` is
|
||||
This option sets "wait forever": the query timeout is set to the maximum possible. See
|
||||
also the :option:`-W` option.
|
||||
|
||||
.. option:: -W wait
|
||||
|
||||
This options sets the length of the wait timeout, indicating that :iscman:`named` should wait for up to ``wait`` seconds for a reply. If ``wait`` is
|
||||
less than 1, the wait interval is set to 1 second.
|
||||
|
||||
By default, ``host`` waits for 5 seconds for UDP responses and 10
|
||||
By default, :program:`host` waits for 5 seconds for UDP responses and 10
|
||||
seconds for TCP connections. These defaults can be overridden by the
|
||||
``timeout`` option in ``/etc/resolv.conf``.
|
||||
|
||||
See also the ``-w`` option.
|
||||
See also the :option:`-w` option.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``host`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``host``
|
||||
If :program:`host` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`host`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, define the ``IDN_DISABLE``
|
||||
environment variable. IDN support is disabled if the variable is set
|
||||
when ``host`` runs.
|
||||
when :program:`host` runs.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
@@ -168,4 +190,4 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`named(8)`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`named(8) <named>`.
|
||||
|
||||
+2
-9
@@ -612,17 +612,10 @@ set_ndots(const char *value) {
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "nslookup %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
static void
|
||||
setoption(char *opt) {
|
||||
size_t l = strlen(opt);
|
||||
|
||||
debugging = true;
|
||||
|
||||
#define CHECKOPT(A, N) \
|
||||
((l >= N) && (l < sizeof(A)) && (strncasecmp(opt, A, l) == 0))
|
||||
|
||||
@@ -856,7 +849,7 @@ get_next_command(void) {
|
||||
}
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -882,7 +875,7 @@ parse_args(int argc, char **argv) {
|
||||
debug("main parsing %s", argv[0]);
|
||||
if (argv[0][0] == '-') {
|
||||
if (strncasecmp(argv[0], "-ver", 4) == 0) {
|
||||
version();
|
||||
printf("nslookup %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
} else if (argv[0][1] != 0) {
|
||||
setoption(&argv[0][1]);
|
||||
|
||||
+13
-11
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: nslookup
|
||||
.. program:: nslookup
|
||||
.. _man_nslookup:
|
||||
|
||||
nslookup - query Internet name servers interactively
|
||||
@@ -24,8 +26,8 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``nslookup`` is a program to query Internet domain name servers.
|
||||
``nslookup`` has two modes: interactive and non-interactive. Interactive
|
||||
:program:`nslookup` is a program to query Internet domain name servers.
|
||||
:program:`nslookup` has two modes: interactive and non-interactive. Interactive
|
||||
mode allows the user to query name servers for information about various
|
||||
hosts and domains or to print a list of hosts in a domain.
|
||||
Non-interactive mode prints just the name and requested
|
||||
@@ -54,16 +56,16 @@ seconds, type:
|
||||
|
||||
nslookup -query=hinfo -timeout=10
|
||||
|
||||
The ``-version`` option causes ``nslookup`` to print the version number
|
||||
The ``-version`` option causes :program:`nslookup` to print the version number
|
||||
and immediately exit.
|
||||
|
||||
Interactive Commands
|
||||
~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
``host [server]``
|
||||
This command looks up information for ``host`` using the current default server or
|
||||
using ``server``, if specified. If ``host`` is an Internet address and the
|
||||
query type is A or PTR, the name of the host is returned. If ``host`` is
|
||||
This command looks up information for :iscman:`host` using the current default server or
|
||||
using ``server``, if specified. If :iscman:`host` is an Internet address and the
|
||||
query type is A or PTR, the name of the host is returned. If :iscman:`host` is
|
||||
a name and does not have a trailing period (``.``), the search list is used
|
||||
to qualify the name.
|
||||
|
||||
@@ -181,19 +183,19 @@ Interactive Commands
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``nslookup`` returns with an exit status of 1 if any query failed, and 0
|
||||
:program:`nslookup` returns with an exit status of 1 if any query failed, and 0
|
||||
otherwise.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``nslookup`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``nslookup``
|
||||
If :program:`nslookup` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`nslookup`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, define the ``IDN_DISABLE``
|
||||
environment variable. IDN support is disabled if the variable is set
|
||||
when ``nslookup`` runs, or when the standard output is not a tty.
|
||||
when :program:`nslookup` runs, or when the standard output is not a tty.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
@@ -203,4 +205,4 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`host(1)`, :manpage:`named(8)`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`host(1) <host>`, :iscman:`named(8) <named>`.
|
||||
|
||||
@@ -845,7 +845,7 @@ make_new_ds_set(ds_maker_func_t *ds_from_rdata, uint32_t ttl,
|
||||
}
|
||||
}
|
||||
|
||||
static inline int
|
||||
static int
|
||||
rdata_cmp(const void *rdata1, const void *rdata2) {
|
||||
return (dns_rdata_compare((const dns_rdata_t *)rdata1,
|
||||
(const dns_rdata_t *)rdata2));
|
||||
@@ -1015,7 +1015,7 @@ nsdiff(uint32_t ttl, dns_rdataset_t *oldset, dns_rdataset_t *newset) {
|
||||
}
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
|
||||
+55
-42
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-cds
|
||||
.. program:: dnssec-cds
|
||||
.. _man_dnssec-cds:
|
||||
|
||||
dnssec-cds - change DS records for a child zone based on CDS/CDNSKEY
|
||||
@@ -24,59 +26,60 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-cds`` command changes DS records at a delegation point
|
||||
The :program:`dnssec-cds` command changes DS records at a delegation point
|
||||
based on CDS or CDNSKEY records published in the child zone. If both CDS
|
||||
and CDNSKEY records are present in the child zone, the CDS is preferred.
|
||||
This enables a child zone to inform its parent of upcoming changes to
|
||||
its key-signing keys (KSKs); by polling periodically with ``dnssec-cds``, the
|
||||
its key-signing keys (KSKs); by polling periodically with :program:`dnssec-cds`, the
|
||||
parent can keep the DS records up-to-date and enable automatic rolling
|
||||
of KSKs.
|
||||
|
||||
Two input files are required. The ``-f child-file`` option specifies a
|
||||
Two input files are required. The :option:`-f child-file <-f>` option specifies a
|
||||
file containing the child's CDS and/or CDNSKEY records, plus RRSIG and
|
||||
DNSKEY records so that they can be authenticated. The ``-d path`` option
|
||||
DNSKEY records so that they can be authenticated. The :option:`-d path <-d>` option
|
||||
specifies the location of a file containing the current DS records. For
|
||||
example, this could be a ``dsset-`` file generated by
|
||||
``dnssec-signzone``, or the output of ``dnssec-dsfromkey``, or the
|
||||
output of a previous run of ``dnssec-cds``.
|
||||
:iscman:`dnssec-signzone`, or the output of :iscman:`dnssec-dsfromkey`, or the
|
||||
output of a previous run of :program:`dnssec-cds`.
|
||||
|
||||
The ``dnssec-cds`` command uses special DNSSEC validation logic
|
||||
The :program:`dnssec-cds` command uses special DNSSEC validation logic
|
||||
specified by :rfc:`7344`. It requires that the CDS and/or CDNSKEY records
|
||||
be validly signed by a key represented in the existing DS records. This
|
||||
is typically the pre-existing KSK.
|
||||
|
||||
For protection against replay attacks, the signatures on the child
|
||||
records must not be older than they were on a previous run of
|
||||
``dnssec-cds``. Their age is obtained from the modification time of the
|
||||
``dsset-`` file, or from the ``-s`` option.
|
||||
:program:`dnssec-cds`. Their age is obtained from the modification time of the
|
||||
``dsset-`` file, or from the :option:`-s` option.
|
||||
|
||||
To protect against breaking the delegation, ``dnssec-cds`` ensures that
|
||||
To protect against breaking the delegation, :program:`dnssec-cds` ensures that
|
||||
the DNSKEY RRset can be verified by every key algorithm in the new DS
|
||||
RRset, and that the same set of keys are covered by every DS digest
|
||||
type.
|
||||
|
||||
By default, replacement DS records are written to the standard output;
|
||||
with the ``-i`` option the input file is overwritten in place. The
|
||||
with the :option:`-i` option the input file is overwritten in place. The
|
||||
replacement DS records are the same as the existing records, when no
|
||||
change is required. The output can be empty if the CDS/CDNSKEY records
|
||||
specify that the child zone wants to be insecure.
|
||||
|
||||
.. warning::
|
||||
|
||||
Be careful not to delete the DS records when ``dnssec-cds`` fails!
|
||||
Be careful not to delete the DS records when :program:`dnssec-cds` fails!
|
||||
|
||||
Alternatively, ``dnssec-cds -u`` writes an ``nsupdate`` script to the
|
||||
standard output. The ``-u`` and ``-i`` options can be used together to
|
||||
maintain a ``dsset-`` file as well as emit an ``nsupdate`` script.
|
||||
Alternatively, :option`dnssec-cds -u` writes an :iscman:`nsupdate` script to the
|
||||
standard output. The :option:`-u` and :option:`-i` options can be used together to
|
||||
maintain a ``dsset-`` file as well as emit an :iscman:`nsupdate` script.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
When converting CDS records to DS records, this option specifies
|
||||
the acceptable digest algorithms. This option can be repeated, so
|
||||
that multiple digest types are allowed. If none of the CDS records
|
||||
use an acceptable digest type, ``dnssec-cds`` will try to use CDNSKEY
|
||||
use an acceptable digest type, :program:`dnssec-cds` will try to use CDNSKEY
|
||||
records instead; if there are no CDNSKEY records, it reports an error.
|
||||
|
||||
When converting CDNSKEY records to DS records, this option specifies the
|
||||
@@ -87,35 +90,40 @@ Options
|
||||
are case-insensitive, and the hyphen may be omitted. If no algorithm
|
||||
is specified, the default is SHA-256 only.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zones.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option generates DS records from CDNSKEY records if both CDS and CDNSKEY
|
||||
records are present in the child zone. By default CDS records are
|
||||
preferred.
|
||||
|
||||
``-d path``
|
||||
.. option:: -d path
|
||||
|
||||
This specifies the location of the parent DS records. The path can be the name of a file
|
||||
containing the DS records; if it is a directory, ``dnssec-cds``
|
||||
containing the DS records; if it is a directory, :program:`dnssec-cds`
|
||||
looks for a ``dsset-`` file for the domain inside the directory.
|
||||
|
||||
To protect against replay attacks, child records are rejected if they
|
||||
were signed earlier than the modification time of the ``dsset-``
|
||||
file. This can be adjusted with the ``-s`` option.
|
||||
file. This can be adjusted with the :option:`-s` option.
|
||||
|
||||
.. option:: -f child-file
|
||||
|
||||
``-f child-file``
|
||||
This option specifies the file containing the child's CDS and/or CDNSKEY records, plus its
|
||||
DNSKEY records and the covering RRSIG records, so that they can be
|
||||
authenticated.
|
||||
|
||||
The examples below describe how to generate this file.
|
||||
|
||||
``-iextension``
|
||||
.. option:: -i extension
|
||||
|
||||
This option updates the ``dsset-`` file in place, instead of writing DS records to
|
||||
the standard output.
|
||||
|
||||
There must be no space between the ``-i`` and the extension. If
|
||||
There must be no space between the :option:`-i` and the extension. If
|
||||
no extension is provided, the old ``dsset-`` is discarded. If an
|
||||
extension is present, a backup of the old ``dsset-`` file is kept
|
||||
with the extension appended to its filename.
|
||||
@@ -125,7 +133,8 @@ Options
|
||||
child records, provided that it is later than the file's current
|
||||
modification time.
|
||||
|
||||
``-s start-time``
|
||||
.. option:: -s start-time
|
||||
|
||||
This option specifies the date and time after which RRSIG records become
|
||||
acceptable. This can be either an absolute or a relative time. An
|
||||
absolute start time is indicated by a number in YYYYMMDDHHMMSS
|
||||
@@ -137,24 +146,28 @@ Options
|
||||
If no start-time is specified, the modification time of the
|
||||
``dsset-`` file is used.
|
||||
|
||||
``-T ttl``
|
||||
.. option:: -T ttl
|
||||
|
||||
This option specifies a TTL to be used for new DS records. If not specified, the
|
||||
default is the TTL of the old DS records. If they had no explicit TTL,
|
||||
the new DS records also have no explicit TTL.
|
||||
|
||||
``-u``
|
||||
This option writes an ``nsupdate`` script to the standard output, instead of
|
||||
.. option:: -u
|
||||
|
||||
This option writes an :iscman:`nsupdate` script to the standard output, instead of
|
||||
printing the new DS reords. The output is empty if no change is
|
||||
needed.
|
||||
|
||||
Note: The TTL of new records needs to be specified: it can be done in the
|
||||
original ``dsset-`` file, with the ``-T`` option, or using the
|
||||
``nsupdate`` ``ttl`` command.
|
||||
original ``dsset-`` file, with the :option:`-T` option, or using the
|
||||
:iscman:`nsupdate` ``ttl`` command.
|
||||
|
||||
.. option:: -V
|
||||
|
||||
``-V``
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level. Level 1 is intended to be usefully verbose
|
||||
for general users; higher levels are intended for developers.
|
||||
|
||||
@@ -164,7 +177,7 @@ Options
|
||||
Exit Status
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-cds`` command exits 0 on success, or non-zero if an error
|
||||
The :program:`dnssec-cds` command exits 0 on success, or non-zero if an error
|
||||
occurred.
|
||||
|
||||
If successful, the DS records may or may not need to be
|
||||
@@ -173,12 +186,12 @@ changed.
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
Before running ``dnssec-signzone``, ensure that the delegations
|
||||
are up-to-date by running ``dnssec-cds`` on every ``dsset-`` file.
|
||||
Before running :iscman:`dnssec-signzone`, ensure that the delegations
|
||||
are up-to-date by running :program:`dnssec-cds` on every ``dsset-`` file.
|
||||
|
||||
To fetch the child records required by ``dnssec-cds``, invoke
|
||||
``dig`` as in the script below. It is acceptable if the ``dig`` fails, since
|
||||
``dnssec-cds`` performs all the necessary checking.
|
||||
To fetch the child records required by :program:`dnssec-cds`, invoke
|
||||
:iscman:`dig` as in the script below. It is acceptable if the :iscman:`dig` fails, since
|
||||
:program:`dnssec-cds` performs all the necessary checking.
|
||||
|
||||
::
|
||||
|
||||
@@ -189,8 +202,8 @@ To fetch the child records required by ``dnssec-cds``, invoke
|
||||
dnssec-cds -i -f /dev/stdin -d $f $d
|
||||
done
|
||||
|
||||
When the parent zone is automatically signed by ``named``,
|
||||
``dnssec-cds`` can be used with ``nsupdate`` to maintain a delegation as follows.
|
||||
When the parent zone is automatically signed by :iscman:`named`,
|
||||
:program:`dnssec-cds` can be used with :iscman:`nsupdate` to maintain a delegation as follows.
|
||||
The ``dsset-`` file allows the script to avoid having to fetch and
|
||||
validate the parent DS records, and it maintains the replay attack
|
||||
protection time.
|
||||
@@ -204,5 +217,5 @@ protection time.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`dnssec-settime(8)`, :manpage:`dnssec-signzone(8)`, :manpage:`nsupdate(1)`, BIND 9 Administrator
|
||||
:iscman:`dig(1) <dig>`, :iscman:`dnssec-settime(8) <dnssec-settime>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, :iscman:`nsupdate(1) <nsupdate>`, BIND 9 Administrator
|
||||
Reference Manual, :rfc:`7344`.
|
||||
|
||||
@@ -324,7 +324,7 @@ emits(bool showall, bool cds, dns_rdata_t *rdata) {
|
||||
}
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -434,14 +434,14 @@ main(int argc, char **argv) {
|
||||
}
|
||||
break;
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
/* Reserved for FIPS mode */
|
||||
FALLTHROUGH;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?') {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-dsfromkey
|
||||
.. program:: dnssec-dsfromkey
|
||||
.. _man_dnssec-dsfromkey:
|
||||
|
||||
dnssec-dsfromkey - DNSSEC DS RR generation tool
|
||||
@@ -30,34 +32,37 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-dsfromkey`` command outputs DS (Delegation Signer) resource records
|
||||
(RRs), or CDS (Child DS) RRs with the ``-C`` option.
|
||||
The :program:`dnssec-dsfromkey` command outputs DS (Delegation Signer) resource records
|
||||
(RRs), or CDS (Child DS) RRs with the :option:`-C` option.
|
||||
|
||||
By default, only KSKs are converted (keys with flags = 257). The
|
||||
``-A`` option includes ZSKs (flags = 256). Revoked keys are never
|
||||
:option:`-A` option includes ZSKs (flags = 256). Revoked keys are never
|
||||
included.
|
||||
|
||||
The input keys can be specified in a number of ways:
|
||||
|
||||
By default, ``dnssec-dsfromkey`` reads a key file named in the format
|
||||
``Knnnn.+aaa+iiiii.key``, as generated by ``dnssec-keygen``.
|
||||
By default, :program:`dnssec-dsfromkey` reads a key file named in the format
|
||||
``Knnnn.+aaa+iiiii.key``, as generated by :iscman:`dnssec-keygen`.
|
||||
|
||||
With the ``-f file`` option, ``dnssec-dsfromkey`` reads keys from a zone
|
||||
With the :option:`-f file <-f>` option, :program:`dnssec-dsfromkey` reads keys from a zone
|
||||
file or partial zone file (which can contain just the DNSKEY records).
|
||||
|
||||
With the ``-s`` option, ``dnssec-dsfromkey`` reads a ``keyset-`` file,
|
||||
as generated by ``dnssec-keygen`` ``-C``.
|
||||
With the :option:`-s` option, :program:`dnssec-dsfromkey` reads a ``keyset-`` file,
|
||||
as generated by :iscman:`dnssec-keygen` :option:`-C`.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-1``
|
||||
This option is an abbreviation for ``-a SHA1``.
|
||||
.. option:: -1
|
||||
|
||||
``-2``
|
||||
This option is an abbreviation for ``-a SHA-256``.
|
||||
This option is an abbreviation for :option:`-a SHA1 <-a>`.
|
||||
|
||||
.. option:: -2
|
||||
|
||||
This option is an abbreviation for :option:`-a SHA-256 <-a>`.
|
||||
|
||||
.. option:: -a algorithm
|
||||
|
||||
``-a algorithm``
|
||||
This option specifies a digest algorithm to use when converting DNSKEY records to
|
||||
DS records. This option can be repeated, so that multiple DS records
|
||||
are created for each DNSKEY record.
|
||||
@@ -66,47 +71,57 @@ Options
|
||||
are case-insensitive, and the hyphen may be omitted. If no algorithm
|
||||
is specified, the default is SHA-256.
|
||||
|
||||
``-A``
|
||||
.. option:: -A
|
||||
|
||||
This option indicates that ZSKs are to be included when generating DS records. Without this option, only
|
||||
keys which have the KSK flag set are converted to DS records and
|
||||
printed. This option is only useful in ``-f`` zone file mode.
|
||||
printed. This option is only useful in :option:`-f` zone file mode.
|
||||
|
||||
``-c class``
|
||||
This option specifies the DNS class; the default is IN. This option is only useful in ``-s`` keyset
|
||||
or ``-f`` zone file mode.
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class; the default is IN. This option is only useful in :option:`-s` keyset
|
||||
or :option:`-f` zone file mode.
|
||||
|
||||
.. option:: -C
|
||||
|
||||
``-C``
|
||||
This option generates CDS records rather than DS records.
|
||||
|
||||
``-f file``
|
||||
This option sets zone file mode, in which the final dnsname argument of ``dnssec-dsfromkey`` is the
|
||||
.. option:: -f file
|
||||
|
||||
This option sets zone file mode, in which the final dnsname argument of :program:`dnssec-dsfromkey` is the
|
||||
DNS domain name of a zone whose master file can be read from
|
||||
``file``. If the zone name is the same as ``file``, then it may be
|
||||
omitted.
|
||||
|
||||
If ``file`` is ``-``, then the zone data is read from the standard
|
||||
input. This makes it possible to use the output of the ``dig``
|
||||
input. This makes it possible to use the output of the :iscman:`dig`
|
||||
command as input, as in:
|
||||
|
||||
``dig dnskey example.com | dnssec-dsfromkey -f - example.com``
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints usage information.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option tells BIND 9 to look for key files or ``keyset-`` files in ``directory``.
|
||||
|
||||
``-s``
|
||||
This option enables keyset mode, in which the final dnsname argument from ``dnssec-dsfromkey`` is the DNS
|
||||
.. option:: -s
|
||||
|
||||
This option enables keyset mode, in which the final dnsname argument from :program:`dnssec-dsfromkey` is the DNS
|
||||
domain name used to locate a ``keyset-`` file.
|
||||
|
||||
``-T TTL``
|
||||
.. option:: -T TTL
|
||||
|
||||
This option specifies the TTL of the DS records. By default the TTL is omitted.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
Example
|
||||
@@ -126,7 +141,7 @@ Files
|
||||
|
||||
The keyfile can be designated by the key identification
|
||||
``Knnnn.+aaa+iiiii`` or the full file name ``Knnnn.+aaa+iiiii.key``, as
|
||||
generated by ``dnssec-keygen``.
|
||||
generated by :iscman:`dnssec-keygen`.
|
||||
|
||||
The keyset file name is built from the ``directory``, the string
|
||||
``keyset-``, and the ``dnsname``.
|
||||
@@ -139,6 +154,6 @@ A keyfile error may return "file not found," even if the file exists.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`3658` (DS RRs), :rfc:`4509` (SHA-256 for DS RRs),
|
||||
:rfc:`6605` (SHA-384 for DS RRs), :rfc:`7344` (CDS and CDNSKEY RRs).
|
||||
|
||||
@@ -263,7 +263,7 @@ emit(const char *dir, dns_rdata_t *rdata) {
|
||||
dst_key_free(&key);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -385,7 +385,7 @@ main(int argc, char **argv) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-importkey
|
||||
.. program:: dnssec-importkey
|
||||
.. _man_dnssec-importkey:
|
||||
|
||||
dnssec-importkey - import DNSKEY records from external systems so they can be managed
|
||||
@@ -26,7 +28,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-importkey`` reads a public DNSKEY record and generates a pair
|
||||
:program:`dnssec-importkey` reads a public DNSKEY record and generates a pair
|
||||
of .key/.private files. The DNSKEY record may be read from an
|
||||
existing .key file, in which case a corresponding .private file is
|
||||
generated, or it may be read from any other file or from the standard
|
||||
@@ -34,14 +36,15 @@ input, in which case both .key and .private files are generated.
|
||||
|
||||
The newly created .private file does *not* contain private key data, and
|
||||
cannot be used for signing. However, having a .private file makes it
|
||||
possible to set publication (``-P``) and deletion (``-D``) times for the
|
||||
possible to set publication (:option:`-P`) and deletion (:option:`-D`) times for the
|
||||
key, which means the public key can be added to and removed from the
|
||||
DNSKEY RRset on schedule even if the true private key is stored offline.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-f filename``
|
||||
.. option:: -f filename
|
||||
|
||||
This option indicates the zone file mode. Instead of a public keyfile name, the argument is the
|
||||
DNS domain name of a zone master file, which can be read from
|
||||
``filename``. If the domain name is the same as ``filename``, then it may be
|
||||
@@ -50,23 +53,28 @@ Options
|
||||
If ``filename`` is set to ``"-"``, then the zone data is read from the
|
||||
standard input.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-L ttl``
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
place, in which case the existing TTL takes precedence. Setting the default TTL to ``0`` or ``none``
|
||||
removes it from the key.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
Timing Options
|
||||
@@ -81,21 +89,25 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
@@ -104,10 +116,10 @@ Files
|
||||
|
||||
A keyfile can be designed by the key identification ``Knnnn.+aaa+iiiii``
|
||||
or the full file name ``Knnnn.+aaa+iiiii.key``, as generated by
|
||||
``dnssec-keygen``.
|
||||
:iscman:`dnssec-keygen`.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`5011`.
|
||||
|
||||
@@ -44,7 +44,7 @@
|
||||
|
||||
const char *program = "dnssec-keyfromlabel";
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -315,14 +315,14 @@ main(int argc, char **argv) {
|
||||
prepub = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
/* Reserved for FIPS mode */
|
||||
FALLTHROUGH;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?') {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
@@ -616,7 +616,7 @@ main(int argc, char **argv) {
|
||||
dns_secalg_format(alg, algstr, sizeof(algstr));
|
||||
fatal("failed to get key %s/%s: %s", namestr, algstr,
|
||||
isc_result_totext(ret));
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
exit(-1);
|
||||
}
|
||||
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-keyfromlabel
|
||||
.. program:: dnssec-keyfromlabel
|
||||
.. _man_dnssec-keyfromlabel:
|
||||
|
||||
dnssec-keyfromlabel - DNSSEC key generation tool
|
||||
@@ -24,10 +26,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-keyfromlabel`` generates a pair of key files that reference a
|
||||
:program:`dnssec-keyfromlabel` generates a pair of key files that reference a
|
||||
key object stored in a cryptographic hardware service module (HSM). The
|
||||
private key file can be used for DNSSEC signing of zone data as if it
|
||||
were a conventional signing key created by ``dnssec-keygen``, but the
|
||||
were a conventional signing key created by :iscman:`dnssec-keygen`, but the
|
||||
key material is stored within the HSM and the actual signing takes
|
||||
place there.
|
||||
|
||||
@@ -37,40 +39,44 @@ match the name of the zone for which the key is being generated.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option selects the cryptographic algorithm. The value of ``algorithm`` must
|
||||
be one of RSASHA1, NSEC3RSASHA1, RSASHA256, RSASHA512,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519, or ED448.
|
||||
|
||||
If no algorithm is specified, RSASHA1 is used by default
|
||||
unless the ``-3`` option is specified, in which case NSEC3RSASHA1
|
||||
is used instead. (If ``-3`` is used and an algorithm is
|
||||
unless the :option:`-3` option is specified, in which case NSEC3RSASHA1
|
||||
is used instead. (If :option:`-3` is used and an algorithm is
|
||||
specified, that algorithm is checked for compatibility with
|
||||
NSEC3.)
|
||||
|
||||
These values are case-insensitive. In some cases, abbreviations are
|
||||
supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the ``-3``
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the :option:`-3`
|
||||
option, then NSEC3RSASHA1 is used instead.
|
||||
|
||||
Since BIND 9.12.0, this option is mandatory except when using the
|
||||
``-S`` option, which copies the algorithm from the predecessory key.
|
||||
:option:`-S` option, which copies the algorithm from the predecessory key.
|
||||
Previously, the default for newly generated keys was RSASHA1.
|
||||
|
||||
``-3``
|
||||
.. option:: -3
|
||||
|
||||
This option uses an NSEC3-capable algorithm to generate a DNSSEC key. If this
|
||||
option is used with an algorithm that has both NSEC and NSEC3
|
||||
versions, then the NSEC3 version is used; for example,
|
||||
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-l label``
|
||||
.. option:: -l label
|
||||
|
||||
This option specifies the label for a key pair in the crypto hardware.
|
||||
|
||||
When BIND 9 is built with OpenSSL-based PKCS#11 support, the label is
|
||||
@@ -78,56 +84,67 @@ Options
|
||||
preceded by an optional OpenSSL engine name, followed by a colon, as
|
||||
in ``pkcs11:keylabel``.
|
||||
|
||||
``-n nametype``
|
||||
.. option:: -n nametype
|
||||
|
||||
This option specifies the owner type of the key. The value of ``nametype`` must
|
||||
either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY
|
||||
(for a key associated with a host (KEY)), USER (for a key associated
|
||||
with a user (KEY)), or OTHER (DNSKEY). These values are
|
||||
case-insensitive.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
This option enables compatibility mode, which generates an old-style key, without any metadata.
|
||||
By default, ``dnssec-keyfromlabel`` includes the key's creation
|
||||
By default, :program:`dnssec-keyfromlabel` includes the key's creation
|
||||
date in the metadata stored with the private key; other dates may
|
||||
be set there as well, including publication date, activation date, etc. Keys
|
||||
that include this data may be incompatible with older versions of
|
||||
BIND; the ``-C`` option suppresses them.
|
||||
BIND; the :option:`-C` option suppresses them.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option indicates that the DNS record containing the key should have the
|
||||
specified class. If not specified, class IN is used.
|
||||
|
||||
``-f flag``
|
||||
.. option:: -f flag
|
||||
|
||||
This option sets the specified flag in the ``flag`` field of the KEY/DNSKEY record.
|
||||
The only recognized flags are KSK (Key-Signing Key) and REVOKE.
|
||||
|
||||
``-G``
|
||||
.. option:: -G
|
||||
|
||||
This option generates a key, but does not publish it or sign with it. This option is
|
||||
incompatible with ``-P`` and ``-A``.
|
||||
incompatible with :option:`-P` and :option:`-A`.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
``-h``
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-keyfromlabel``.
|
||||
:program:`dnssec-keyfromlabel`.
|
||||
|
||||
.. option:: -K directory
|
||||
|
||||
``-K directory``
|
||||
This option sets the directory in which the key files are to be written.
|
||||
|
||||
``-k``
|
||||
.. option:: -k
|
||||
|
||||
This option generates KEY records rather than DNSKEY records.
|
||||
|
||||
``-L`` ttl
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
place, in which case the existing TTL would take precedence. Setting
|
||||
the default TTL to ``0`` or ``none`` removes it.
|
||||
|
||||
``-p protocol``
|
||||
.. option:: -p protocol
|
||||
|
||||
This option sets the protocol value for the key. The protocol is a number between
|
||||
0 and 255. The default is 3 (DNSSEC). Other possible values for this
|
||||
argument are listed in :rfc:`2535` and its successors.
|
||||
|
||||
``-S key``
|
||||
.. option:: -S key
|
||||
|
||||
This option generates a key as an explicit successor to an existing key. The name,
|
||||
algorithm, size, and type of the key are set to match the
|
||||
predecessor. The activation date of the new key is set to the
|
||||
@@ -135,19 +152,23 @@ Options
|
||||
set to the activation date minus the prepublication interval, which
|
||||
defaults to 30 days.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the type of the key. ``type`` must be one of AUTHCONF,
|
||||
NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH refers
|
||||
to the ability to authenticate data, and CONF to the ability to encrypt
|
||||
data.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-y``
|
||||
.. option:: -y
|
||||
|
||||
This option allows DNSSEC key files to be generated even if the key ID would
|
||||
collide with that of an existing key, in the event of either key
|
||||
being revoked. (This is only safe to enable if
|
||||
@@ -166,41 +187,49 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it. If not set, and if the ``-G`` option has not been used, the
|
||||
to sign it. If not set, and if the :option:`-G` option has not been used, the
|
||||
default is the current date.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it. If not set,
|
||||
and if the ``-G`` option has not been used, the default is the current date.
|
||||
and if the :option:`-G` option has not been used, the default is the current date.
|
||||
|
||||
.. option:: -R date/offset
|
||||
|
||||
``-R date/offset``
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -221,7 +250,7 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Generated Key Files
|
||||
~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
When ``dnssec-keyfromlabel`` completes successfully, it prints a string
|
||||
When :program:`dnssec-keyfromlabel` completes successfully, it prints a string
|
||||
of the form ``Knnnn.+aaa+iiiii`` to the standard output. This is an
|
||||
identification string for the key files it has generated.
|
||||
|
||||
@@ -231,7 +260,7 @@ identification string for the key files it has generated.
|
||||
|
||||
- ``iiiii`` is the key identifier (or footprint).
|
||||
|
||||
``dnssec-keyfromlabel`` creates two files, with names based on the
|
||||
:program:`dnssec-keyfromlabel` creates two files, with names based on the
|
||||
printed string. ``Knnnn.+aaa+iiiii.key`` contains the public key, and
|
||||
``Knnnn.+aaa+iiiii.private`` contains the private key.
|
||||
|
||||
@@ -244,5 +273,5 @@ security reasons, this file does not have general read permission.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`4034`, :rfc:`7512`.
|
||||
|
||||
@@ -67,7 +67,7 @@ const char *program = "dnssec-keygen";
|
||||
|
||||
isc_log_t *lctx = NULL;
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -1108,14 +1108,14 @@ main(int argc, char **argv) {
|
||||
ctx.prepub = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
/* Reserved for FIPS mode */
|
||||
FALLTHROUGH;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?') {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
+105
-64
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-keygen
|
||||
.. program:: dnssec-keygen
|
||||
.. _man_dnssec-keygen:
|
||||
|
||||
dnssec-keygen: DNSSEC key generation tool
|
||||
@@ -24,7 +26,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-keygen`` generates keys for DNSSEC (Secure DNS), as defined in
|
||||
:program:`dnssec-keygen` generates keys for DNSSEC (Secure DNS), as defined in
|
||||
:rfc:`2535` and :rfc:`4034`. It can also generate keys for use with TSIG
|
||||
(Transaction Signatures) as defined in :rfc:`2845`, or TKEY (Transaction
|
||||
Key) as defined in :rfc:`2930`.
|
||||
@@ -36,32 +38,35 @@ generated.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-3``
|
||||
.. option:: -3
|
||||
|
||||
This option uses an NSEC3-capable algorithm to generate a DNSSEC key. If this
|
||||
option is used with an algorithm that has both NSEC and NSEC3
|
||||
versions, then the NSEC3 version is selected; for example,
|
||||
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option selects the cryptographic algorithm. For DNSSEC keys, the value of
|
||||
``algorithm`` must be one of RSASHA1, NSEC3RSASHA1, RSASHA256,
|
||||
RSASHA512, ECDSAP256SHA256, ECDSAP384SHA384, ED25519, or ED448. For
|
||||
TKEY, the value must be DH (Diffie-Hellman); specifying this value
|
||||
automatically sets the ``-T KEY`` option as well.
|
||||
automatically sets the :option:`-T KEY <-T>` option as well.
|
||||
|
||||
These values are case-insensitive. In some cases, abbreviations are
|
||||
supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the ``-3``
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the :option:`-3`
|
||||
option, NSEC3RSASHA1 is used instead.
|
||||
|
||||
This parameter *must* be specified except when using the ``-S``
|
||||
This parameter *must* be specified except when using the :option:`-S`
|
||||
option, which copies the algorithm from the predecessor key.
|
||||
|
||||
In prior releases, HMAC algorithms could be generated for use as TSIG
|
||||
keys, but that feature was removed in BIND 9.13.0. Use
|
||||
``tsig-keygen`` to generate TSIG keys.
|
||||
:iscman:`tsig-keygen` to generate TSIG keys.
|
||||
|
||||
.. option:: -b keysize
|
||||
|
||||
``-b keysize``
|
||||
This option specifies the number of bits in the key. The choice of key size
|
||||
depends on the algorithm used: RSA keys must be between 1024 and 4096
|
||||
bits; Diffie-Hellman keys must be between 128 and 4096 bits. Elliptic
|
||||
@@ -70,63 +75,74 @@ Options
|
||||
If the key size is not specified, some algorithms have pre-defined
|
||||
defaults. For example, RSA keys for use as DNSSEC zone-signing keys
|
||||
have a default size of 1024 bits; RSA keys for use as key-signing
|
||||
keys (KSKs, generated with ``-f KSK``) default to 2048 bits.
|
||||
keys (KSKs, generated with :option:`-f KSK <-f>`) default to 2048 bits.
|
||||
|
||||
.. option:: -C
|
||||
|
||||
``-C``
|
||||
This option enables compatibility mode, which generates an old-style key, without any timing
|
||||
metadata. By default, ``dnssec-keygen`` includes the key's
|
||||
metadata. By default, :program:`dnssec-keygen` includes the key's
|
||||
creation date in the metadata stored with the private key; other
|
||||
dates may be set there as well, including publication date, activation date,
|
||||
etc. Keys that include this data may be incompatible with older
|
||||
versions of BIND; the ``-C`` option suppresses them.
|
||||
versions of BIND; the :option:`-C` option suppresses them.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option indicates that the DNS record containing the key should have the
|
||||
specified class. If not specified, class IN is used.
|
||||
|
||||
``-d bits``
|
||||
.. option:: -d bits
|
||||
|
||||
This option specifies the key size in bits. For the algorithms RSASHA1, NSEC3RSASA1, RSASHA256, and
|
||||
RSASHA512 the key size must be between 1024 and 4096 bits; DH size is between 128
|
||||
and 4096 bits. This option is ignored for algorithms ECDSAP256SHA256,
|
||||
ECDSAP384SHA384, ED25519, and ED448.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f flag``
|
||||
.. option:: -f flag
|
||||
|
||||
This option sets the specified flag in the flag field of the KEY/DNSKEY record.
|
||||
The only recognized flags are KSK (Key-Signing Key) and REVOKE.
|
||||
|
||||
``-G``
|
||||
.. option:: -G
|
||||
|
||||
This option generates a key, but does not publish it or sign with it. This option is
|
||||
incompatible with ``-P`` and ``-A``.
|
||||
incompatible with :option:`-P` and :option:`-A`.
|
||||
|
||||
.. option:: -g generator
|
||||
|
||||
``-g generator``
|
||||
This option indicates the generator to use if generating a Diffie-Hellman key. Allowed
|
||||
values are 2 and 5. If no generator is specified, a known prime from
|
||||
:rfc:`2539` is used if possible; otherwise the default is 2.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-keygen``.
|
||||
:program:`dnssec-keygen`.
|
||||
|
||||
.. option:: -K directory
|
||||
|
||||
``-K directory``
|
||||
This option sets the directory in which the key files are to be written.
|
||||
|
||||
``-k policy``
|
||||
.. option:: -k policy
|
||||
|
||||
This option creates keys for a specific ``dnssec-policy``. If a policy uses multiple keys,
|
||||
``dnssec-keygen`` generates multiple keys. This also
|
||||
:program:`dnssec-keygen` generates multiple keys. This also
|
||||
creates a ".state" file to keep track of the key state.
|
||||
|
||||
This option creates keys according to the ``dnssec-policy`` configuration, hence
|
||||
it cannot be used at the same time as many of the other options that
|
||||
``dnssec-keygen`` provides.
|
||||
:program:`dnssec-keygen` provides.
|
||||
|
||||
.. option:: -L ttl
|
||||
|
||||
``-L ttl``
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
@@ -135,26 +151,30 @@ Options
|
||||
defaults to the SOA TTL. Setting the default TTL to ``0`` or ``none``
|
||||
is the same as leaving it unset.
|
||||
|
||||
``-l file``
|
||||
.. option:: -l file
|
||||
|
||||
This option provides a configuration file that contains a ``dnssec-policy`` statement
|
||||
(matching the policy set with ``-k``).
|
||||
(matching the policy set with :option:`-k`).
|
||||
|
||||
.. option:: -n nametype
|
||||
|
||||
``-n nametype``
|
||||
This option specifies the owner type of the key. The value of ``nametype`` must
|
||||
either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY
|
||||
(for a key associated with a host (KEY)), USER (for a key associated
|
||||
with a user (KEY)), or OTHER (DNSKEY). These values are
|
||||
case-insensitive. The default is ZONE for DNSKEY generation.
|
||||
|
||||
``-p protocol``
|
||||
.. option:: -p protocol
|
||||
|
||||
This option sets the protocol value for the generated key, for use with
|
||||
``-T KEY``. The protocol is a number between 0 and 255. The default
|
||||
:option:`-T KEY <-T>`. The protocol is a number between 0 and 255. The default
|
||||
is 3 (DNSSEC). Other possible values for this argument are listed in
|
||||
:rfc:`2535` and its successors.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which suppresses unnecessary output, including progress
|
||||
indication. Without this option, when ``dnssec-keygen`` is run
|
||||
indication. Without this option, when :program:`dnssec-keygen` is run
|
||||
interactively to generate an RSA or DSA key pair, it prints a
|
||||
string of symbols to ``stderr`` indicating the progress of the key
|
||||
generation. A ``.`` indicates that a random number has been found which
|
||||
@@ -162,7 +182,8 @@ Options
|
||||
round of the Miller-Rabin primality test; and a space ( ) means that the
|
||||
number has passed all the tests and is a satisfactory key.
|
||||
|
||||
``-S key``
|
||||
.. option:: -S key
|
||||
|
||||
This option creates a new key which is an explicit successor to an existing key.
|
||||
The name, algorithm, size, and type of the key are set to match
|
||||
the existing key. The activation date of the new key is set to
|
||||
@@ -170,77 +191,97 @@ Options
|
||||
set to the activation date minus the prepublication interval,
|
||||
which defaults to 30 days.
|
||||
|
||||
``-s strength``
|
||||
.. option:: -s strength
|
||||
|
||||
This option specifies the strength value of the key. The strength is a number
|
||||
between 0 and 15, and currently has no defined purpose in DNSSEC.
|
||||
|
||||
``-T rrtype``
|
||||
.. option:: -T rrtype
|
||||
|
||||
This option specifies the resource record type to use for the key. ``rrtype``
|
||||
must be either DNSKEY or KEY. The default is DNSKEY when using a
|
||||
DNSSEC algorithm, but it can be overridden to KEY for use with
|
||||
SIG(0).
|
||||
|
||||
``-t type``
|
||||
This option indicates the type of the key for use with ``-T KEY``. ``type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the type of the key for use with :option:`-T KEY <-T>`. ``type``
|
||||
must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
||||
is AUTHCONF. AUTH refers to the ability to authenticate data, and
|
||||
CONF to the ability to encrypt data.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
Timing Options
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS. If the
|
||||
argument begins with a ``+`` or ``-``, it is interpreted as an offset from
|
||||
the present time. For convenience, if such an offset is followed by one
|
||||
of the suffixes ``y``, ``mo``, ``w``, ``d``, ``h``, or ``mi``, then the offset is
|
||||
computed in years (defined as 365 24-hour days, ignoring leap years),
|
||||
months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS
|
||||
(which is the format used inside key files),
|
||||
or 'Day Mon DD HH:MM:SS YYYY' (as printed by ``dnssec-settime -p``),
|
||||
or UNIX epoch time (as printed by ``dnssec-settime -up``),
|
||||
or the literal ``now``.
|
||||
|
||||
The argument can be followed by '+' or '-' and an offset from the
|
||||
given time. The literal ``now`` can be omitted before an offset. The
|
||||
offset can be followed by one of the suffixes 'y', 'mo', 'w', 'd',
|
||||
'h', or 'mi', so that it is computed in years (defined as 365 24-hour
|
||||
days, ignoring leap years), months (defined as 30 24-hour days),
|
||||
weeks, days, hours, or minutes, respectively. Without a suffix, the
|
||||
offset is computed in seconds.
|
||||
|
||||
To unset a date, use ``none`` or ``never``.
|
||||
|
||||
.. option:: -P date/offset
|
||||
|
||||
``-P date/offset``
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it. If not set, and if the ``-G`` option has not been used, the
|
||||
to sign it. If not set, and if the :option:`-G` option has not been used, the
|
||||
default is the current date.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it. If not set,
|
||||
and if the ``-G`` option has not been used, the default is the current date. If set,
|
||||
and ``-P`` is not set, the publication date is set to the
|
||||
and if the :option:`-G` option has not been used, the default is the current date. If set,
|
||||
and :option:`-P` is not set, the publication date is set to the
|
||||
activation date minus the prepublication interval.
|
||||
|
||||
``-R date/offset``
|
||||
.. option:: -R date/offset
|
||||
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -261,7 +302,7 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Generated Keys
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
When ``dnssec-keygen`` completes successfully, it prints a string of the
|
||||
When :program:`dnssec-keygen` completes successfully, it prints a string of the
|
||||
form ``Knnnn.+aaa+iiiii`` to the standard output. This is an
|
||||
identification string for the key it has generated.
|
||||
|
||||
@@ -271,12 +312,12 @@ identification string for the key it has generated.
|
||||
|
||||
- ``iiiii`` is the key identifier (or footprint).
|
||||
|
||||
``dnssec-keygen`` creates two files, with names based on the printed
|
||||
:program:`dnssec-keygen` creates two files, with names based on the printed
|
||||
string. ``Knnnn.+aaa+iiiii.key`` contains the public key, and
|
||||
``Knnnn.+aaa+iiiii.private`` contains the private key.
|
||||
|
||||
The ``.key`` file contains a DNSKEY or KEY record. When a zone is being
|
||||
signed by ``named`` or ``dnssec-signzone -S``, DNSKEY records are
|
||||
signed by :iscman:`named` or :option:`dnssec-signzone -S`, DNSKEY records are
|
||||
included automatically. In other cases, the ``.key`` file can be
|
||||
inserted into a zone file manually or with an ``$INCLUDE`` statement.
|
||||
|
||||
@@ -295,7 +336,7 @@ The command prints a string of the form:
|
||||
|
||||
``Kexample.com.+013+26160``
|
||||
|
||||
In this example, ``dnssec-keygen`` creates the files
|
||||
In this example, :program:`dnssec-keygen` creates the files
|
||||
``Kexample.com.+013+26160.key`` and ``Kexample.com.+013+26160.private``.
|
||||
|
||||
To generate a matching key-signing key, issue the command:
|
||||
@@ -305,5 +346,5 @@ To generate a matching key-signing key, issue the command:
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual, :rfc:`2539`,
|
||||
:iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual, :rfc:`2539`,
|
||||
:rfc:`2845`, :rfc:`4034`.
|
||||
|
||||
@@ -39,7 +39,7 @@ const char *program = "dnssec-revoke";
|
||||
|
||||
static isc_mem_t *mctx = NULL;
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -119,7 +119,7 @@ main(int argc, char **argv) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-revoke
|
||||
.. program:: dnssec-revoke
|
||||
.. _man_dnssec-revoke:
|
||||
|
||||
dnssec-revoke - set the REVOKED bit on a DNSSEC key
|
||||
@@ -24,45 +26,53 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-revoke`` reads a DNSSEC key file, sets the REVOKED bit on the
|
||||
:program:`dnssec-revoke` reads a DNSSEC key file, sets the REVOKED bit on the
|
||||
key as defined in :rfc:`5011`, and creates a new pair of key files
|
||||
containing the now-revoked key.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option indicates to remove the original keyset files after writing the new keyset files.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f``
|
||||
This option indicates a forced overwrite and causes ``dnssec-revoke`` to write the new key pair,
|
||||
.. option:: -f
|
||||
|
||||
This option indicates a forced overwrite and causes :program:`dnssec-revoke` to write the new key pair,
|
||||
even if a file already exists matching the algorithm and key ID of
|
||||
the revoked key.
|
||||
|
||||
``-R``
|
||||
.. option:: -R
|
||||
|
||||
This option prints the key tag of the key with the REVOKE bit set, but does not
|
||||
revoke the key.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, BIND 9 Administrator Reference Manual, :rfc:`5011`.
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, BIND 9 Administrator Reference Manual, :rfc:`5011`.
|
||||
|
||||
@@ -43,7 +43,7 @@ const char *program = "dnssec-settime";
|
||||
|
||||
static isc_mem_t *mctx = NULL;
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -342,7 +342,7 @@ main(int argc, char **argv) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-settime
|
||||
.. program:: dnssec-settime
|
||||
.. _man_dnssec-settime:
|
||||
|
||||
dnssec-settime: set the key timing metadata for a DNSSEC key
|
||||
@@ -24,14 +26,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-settime`` reads a DNSSEC private key file and sets the key
|
||||
timing metadata as specified by the ``-P``, ``-A``, ``-R``, ``-I``, and
|
||||
``-D`` options. The metadata can then be used by ``dnssec-signzone`` or
|
||||
other signing software to determine when a key is to be published,
|
||||
whether it should be used for signing a zone, etc.
|
||||
:program:`dnssec-settime` reads a DNSSEC private key file and sets the key
|
||||
timing metadata as specified by the :option:`-P`, :option:`-A`, :option:`-R`,
|
||||
:option:`-I`, and :option:`-D` options. The metadata can then be used by
|
||||
:iscman:`dnssec-signzone` or other signing software to determine when a key is
|
||||
to be published, whether it should be used for signing a zone, etc.
|
||||
|
||||
If none of these options is set on the command line,
|
||||
``dnssec-settime`` simply prints the key timing metadata already stored
|
||||
:program:`dnssec-settime` simply prints the key timing metadata already stored
|
||||
in the key.
|
||||
|
||||
When key metadata fields are changed, both files of a key pair
|
||||
@@ -44,12 +46,12 @@ the key file. The private file's permissions are always set to be
|
||||
inaccessible to anyone other than the owner (mode 0600).
|
||||
|
||||
When working with state files, it is possible to update the timing metadata in
|
||||
those files as well with ``-s``. With this option, it is also possible to update key
|
||||
states with ``-d`` (DS), ``-k`` (DNSKEY), ``-r`` (RRSIG of KSK), or ``-z``
|
||||
(RRSIG of ZSK). Allowed states are HIDDEN, RUMOURED, OMNIPRESENT, and
|
||||
UNRETENTIVE.
|
||||
those files as well with :option:`-s`. With this option, it is also possible
|
||||
to update key states with :option:`-d` (DS), :option:`-k` (DNSKEY), :option:`-r`
|
||||
(RRSIG of KSK), or :option:`-z` (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||
|
||||
The goal state of the key can also be set with ``-g``. This should be either
|
||||
The goal state of the key can also be set with :option:`-g`. This should be either
|
||||
HIDDEN or OMNIPRESENT, representing whether the key should be removed from the
|
||||
zone or published.
|
||||
|
||||
@@ -59,19 +61,22 @@ purposes.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-f``
|
||||
.. option:: -f
|
||||
|
||||
This option forces an update of an old-format key with no metadata fields. Without
|
||||
this option, ``dnssec-settime`` fails when attempting to update a
|
||||
this option, :program:`dnssec-settime` fails when attempting to update a
|
||||
legacy key. With this option, the key is recreated in the new
|
||||
format, but with the original key data retained. The key's creation
|
||||
date is set to the present time. If no other values are
|
||||
specified, then the key's publication and activation dates are also
|
||||
set to the present time.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-L ttl``
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
@@ -80,16 +85,20 @@ Options
|
||||
defaults to the SOA TTL. Setting the default TTL to ``0`` or ``none``
|
||||
removes it from the key.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
@@ -99,56 +108,73 @@ Options
|
||||
Timing Options
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS. If the
|
||||
argument begins with a ``+`` or ``-``, it is interpreted as an offset from
|
||||
the present time. For convenience, if such an offset is followed by one
|
||||
of the suffixes ``y``, ``mo``, ``w``, ``d``, ``h``, or ``mi``, then the offset is
|
||||
computed in years (defined as 365 24-hour days, ignoring leap years),
|
||||
months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS
|
||||
(which is the format used inside key files),
|
||||
or 'Day Mon DD HH:MM:SS YYYY' (as printed by ``dnssec-settime -p``),
|
||||
or UNIX epoch time (as printed by ``dnssec-settime -up``),
|
||||
or the literal ``now``.
|
||||
|
||||
The argument can be followed by '+' or '-' and an offset from the
|
||||
given time. The literal ``now`` can be omitted before an offset. The
|
||||
offset can be followed by one of the suffixes 'y', 'mo', 'w', 'd',
|
||||
'h', or 'mi', so that it is computed in years (defined as 365 24-hour
|
||||
days, ignoring leap years), months (defined as 30 24-hour days),
|
||||
weeks, days, hours, or minutes, respectively. Without a suffix, the
|
||||
offset is computed in seconds.
|
||||
|
||||
To unset a date, use ``none`` or ``never``.
|
||||
|
||||
.. option:: -P date/offset
|
||||
|
||||
``-P date/offset``
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it.
|
||||
|
||||
``-P ds date/offset``
|
||||
.. option:: -P ds date/offset
|
||||
|
||||
This option sets the date on which DS records that match this key have been
|
||||
seen in the parent zone.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it.
|
||||
|
||||
``-R date/offset``
|
||||
.. option:: -R date/offset
|
||||
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D ds date/offset``
|
||||
.. option:: -D ds date/offset
|
||||
|
||||
This option sets the date on which the DS records that match this key have
|
||||
been seen removed from the parent zone.
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-S predecessor key``
|
||||
.. option:: -S predecessor key
|
||||
|
||||
This option selects a key for which the key being modified is an explicit
|
||||
successor. The name, algorithm, size, and type of the predecessor key
|
||||
must exactly match those of the key being modified. The activation
|
||||
@@ -156,7 +182,8 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
predecessor. The publication date is set to the activation date
|
||||
minus the prepublication interval, which defaults to 30 days.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -183,36 +210,44 @@ purpose, but should never be used in production.
|
||||
|
||||
Known key states are HIDDEN, RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||
|
||||
``-s``
|
||||
.. option:: -s
|
||||
|
||||
This option indicates that when setting key timing data, the state file should also be updated.
|
||||
|
||||
``-g state``
|
||||
.. option:: -g state
|
||||
|
||||
This option sets the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||
|
||||
``-d state date/offset``
|
||||
.. option:: -d state date/offset
|
||||
|
||||
This option sets the DS state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-k state date/offset``
|
||||
.. option:: -k state date/offset
|
||||
|
||||
This option sets the DNSKEY state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-r state date/offset``
|
||||
.. option:: -r state date/offset
|
||||
|
||||
This option sets the RRSIG (KSK) state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-z state date/offset``
|
||||
.. option:: -z state date/offset
|
||||
|
||||
This option sets the RRSIG (ZSK) state for this key as of the specified date, offset from the current date.
|
||||
|
||||
Printing Options
|
||||
~~~~~~~~~~~~~~~~
|
||||
|
||||
``dnssec-settime`` can also be used to print the timing metadata
|
||||
:program:`dnssec-settime` can also be used to print the timing metadata
|
||||
associated with a key.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option indicates that times should be printed in Unix epoch format.
|
||||
|
||||
``-p C/P/Pds/Psync/A/R/I/D/Dds/Dsync/all``
|
||||
.. option:: -p C/P/Pds/Psync/A/R/I/D/Dds/Dsync/all
|
||||
|
||||
This option prints a specific metadata value or set of metadata values.
|
||||
The ``-p`` option may be followed by one or more of the following letters or
|
||||
The :option:`-p` option may be followed by one or more of the following letters or
|
||||
strings to indicate which value or values to print: ``C`` for the
|
||||
creation date, ``P`` for the publication date, ``Pds` for the DS publication
|
||||
date, ``Psync`` for the CDS and CDNSKEY publication date, ``A`` for the
|
||||
@@ -224,5 +259,5 @@ associated with a key.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`5011`.
|
||||
|
||||
@@ -325,28 +325,28 @@ signwithkey(dns_name_t *name, dns_rdataset_t *rdataset, dst_key_t *key,
|
||||
dns_diff_append(add, &tuple);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
issigningkey(dns_dnsseckey_t *key) {
|
||||
return (key->force_sign || key->hint_sign);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
ispublishedkey(dns_dnsseckey_t *key) {
|
||||
return ((key->force_publish || key->hint_publish) && !key->hint_remove);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
iszonekey(dns_dnsseckey_t *key) {
|
||||
return (dns_name_equal(dst_key_name(key->key), gorigin) &&
|
||||
dst_key_iszonekey(key->key));
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
isksk(dns_dnsseckey_t *key) {
|
||||
return (key->ksk);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
iszsk(dns_dnsseckey_t *key) {
|
||||
return (ignore_kskflag || !key->ksk);
|
||||
}
|
||||
@@ -417,17 +417,15 @@ keythatsigned(dns_rdata_rrsig_t *rrsig) {
|
||||
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE, directory, mctx, &privkey);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
dst_key_free(&pubkey);
|
||||
result = dns_dnsseckey_create(mctx, &privkey, &key);
|
||||
dns_dnsseckey_create(mctx, &privkey, &key);
|
||||
} else {
|
||||
result = dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||
dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||
}
|
||||
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
key->force_publish = false;
|
||||
key->force_sign = false;
|
||||
key->index = keycount++;
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
}
|
||||
key->force_publish = false;
|
||||
key->force_sign = false;
|
||||
key->index = keycount++;
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
|
||||
isc_rwlock_unlock(&keylist_lock, isc_rwlocktype_write);
|
||||
return (key);
|
||||
@@ -463,11 +461,11 @@ expecttofindkey(dns_name_t *name) {
|
||||
dns_name_format(name, namestr, sizeof(namestr));
|
||||
fatal("failure looking for '%s DNSKEY' in database: %s", namestr,
|
||||
isc_result_totext(result));
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (false); /* removes a warning */
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
setverifies(dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
||||
dns_rdata_t *rrsig) {
|
||||
isc_result_t result;
|
||||
@@ -1246,7 +1244,7 @@ signname(dns_dbnode_t *node, dns_name_t *name) {
|
||||
* See if the node contains any non RRSIG/NSEC records and report to
|
||||
* caller. Clean out extraneous RRSIG records for node.
|
||||
*/
|
||||
static inline bool
|
||||
static bool
|
||||
active_node(dns_dbnode_t *node) {
|
||||
dns_rdatasetiter_t *rdsiter = NULL;
|
||||
dns_rdatasetiter_t *rdsiter2 = NULL;
|
||||
@@ -3191,10 +3189,10 @@ print_version(FILE *fp) {
|
||||
return;
|
||||
}
|
||||
|
||||
fprintf(fp, "; dnssec_signzone version %s\n", PACKAGE_VERSION);
|
||||
fprintf(fp, "; %s version %s\n", program, PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -3359,9 +3357,9 @@ main(int argc, char *argv[]) {
|
||||
atomic_init(&finished, false);
|
||||
|
||||
/* Unused letters: Bb G J q Yy (and F is reserved). */
|
||||
#define CMDLINE_FLAGS \
|
||||
"3:AaCc:Dd:E:e:f:FghH:i:I:j:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:VX:" \
|
||||
"xzZ:"
|
||||
#define CMDLINE_FLAGS \
|
||||
"3:AaCc:Dd:E:e:f:FghH:i:I:j:J:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:" \
|
||||
"VX:xzZ:"
|
||||
|
||||
/*
|
||||
* Process memory debugging argument first.
|
||||
@@ -3509,6 +3507,10 @@ main(int argc, char *argv[]) {
|
||||
}
|
||||
break;
|
||||
|
||||
case 'J':
|
||||
journal = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'K':
|
||||
directory = isc_commandline_argument;
|
||||
break;
|
||||
@@ -3640,14 +3642,14 @@ main(int argc, char *argv[]) {
|
||||
break;
|
||||
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
/* Reserved for FIPS mode */
|
||||
FALLTHROUGH;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?') {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
@@ -3812,6 +3814,9 @@ main(int argc, char *argv[]) {
|
||||
gdb = NULL;
|
||||
TIME_NOW(&timer_start);
|
||||
loadzone(file, origin, rdclass, &gdb);
|
||||
if (journal != NULL) {
|
||||
loadjournal(mctx, gdb, journal);
|
||||
}
|
||||
gorigin = dns_db_origin(gdb);
|
||||
gclass = dns_db_class(gdb);
|
||||
get_soa_ttls();
|
||||
|
||||
+112
-68
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-signzone
|
||||
.. program:: dnssec-signzone
|
||||
.. _man_dnssec-signzone:
|
||||
|
||||
dnssec-signzone - DNSSEC zone signing tool
|
||||
@@ -24,7 +26,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-signzone`` signs a zone; it generates NSEC and RRSIG records
|
||||
:program:`dnssec-signzone` signs a zone; it generates NSEC and RRSIG records
|
||||
and produces a signed version of the zone. The security status of
|
||||
delegations from the signed zone (that is, whether the child zones are
|
||||
secure) is determined by the presence or absence of a ``keyset``
|
||||
@@ -33,29 +35,35 @@ file for each child zone.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a``
|
||||
.. option:: -a
|
||||
|
||||
This option verifies all generated signatures.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zone.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
This option sets compatibility mode, in which a ``keyset-zonename`` file is generated in addition
|
||||
to ``dsset-zonename`` when signing a zone, for use by older versions
|
||||
of ``dnssec-signzone``.
|
||||
of :program:`dnssec-signzone`.
|
||||
|
||||
.. option:: -d directory
|
||||
|
||||
``-d directory``
|
||||
This option indicates the directory where BIND 9 should look for ``dsset-`` or ``keyset-`` files.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option indicates that only those record types automatically managed by
|
||||
``dnssec-signzone``, i.e., RRSIG, NSEC, NSEC3 and NSEC3PARAM records, should be included in the output.
|
||||
If smart signing (``-S``) is used, DNSKEY records are also included.
|
||||
:program:`dnssec-signzone`, i.e., RRSIG, NSEC, NSEC3 and NSEC3PARAM records, should be included in the output.
|
||||
If smart signing (:option:`-S`) is used, DNSKEY records are also included.
|
||||
The resulting file can be included in the original zone file with
|
||||
``$INCLUDE``. This option cannot be combined with ``-O raw``
|
||||
``$INCLUDE``. This option cannot be combined with :option:`-O raw <-O>`
|
||||
or serial-number updating.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the hardware to use for cryptographic
|
||||
operations, such as a secure key store used for signing, when applicable.
|
||||
|
||||
@@ -63,19 +71,23 @@ Options
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-g``
|
||||
.. option:: -g
|
||||
|
||||
This option indicates that DS records for child zones should be generated from a ``dsset-`` or ``keyset-``
|
||||
file. Existing DS records are removed.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option specifies the directory to search for DNSSEC keys. If not
|
||||
specified, it defaults to the current directory.
|
||||
|
||||
``-k key``
|
||||
.. option:: -k key
|
||||
|
||||
This option tells BIND 9 to treat the specified key as a key-signing key, ignoring any key flags. This
|
||||
option may be specified multiple times.
|
||||
|
||||
``-M maxttl``
|
||||
.. option:: -M maxttl
|
||||
|
||||
This option sets the maximum TTL for the signed zone. Any TTL higher than ``maxttl``
|
||||
in the input zone is reduced to ``maxttl`` in the output. This
|
||||
provides certainty as to the largest possible TTL in the signed zone,
|
||||
@@ -83,10 +95,11 @@ Options
|
||||
possible time before signatures that have been retrieved by resolvers
|
||||
expire from resolver caches. Zones that are signed with this
|
||||
option should be configured to use a matching ``max-zone-ttl`` in
|
||||
``named.conf``. (Note: This option is incompatible with ``-D``,
|
||||
:iscman:`named.conf`. (Note: This option is incompatible with :option:`-D`,
|
||||
because it modifies non-DNSSEC data in the output zone.)
|
||||
|
||||
``-s start-time``
|
||||
.. option:: -s start-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records become
|
||||
valid. This can be either an absolute or relative time. An absolute
|
||||
start time is indicated by a number in YYYYMMDDHHMMSS notation;
|
||||
@@ -95,7 +108,8 @@ Options
|
||||
time. If no ``start-time`` is specified, the current time minus 1
|
||||
hour (to allow for clock skew) is used.
|
||||
|
||||
``-e end-time``
|
||||
.. option:: -e end-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records expire. As
|
||||
with ``start-time``, an absolute time is indicated in YYYYMMDDHHMMSS
|
||||
notation. A time relative to the start time is indicated with ``+N``,
|
||||
@@ -104,7 +118,8 @@ Options
|
||||
specified, 30 days from the start time is the default.
|
||||
``end-time`` must be later than ``start-time``.
|
||||
|
||||
``-X extended end-time``
|
||||
.. option:: -X extended end-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records for the
|
||||
DNSKEY RRset expire. This is to be used in cases when the DNSKEY
|
||||
signatures need to persist longer than signatures on other records;
|
||||
@@ -119,20 +134,24 @@ Options
|
||||
as the default. (``end-time``, in turn, defaults to 30 days from the
|
||||
start time.) ``extended end-time`` must be later than ``start-time``.
|
||||
|
||||
``-f output-file``
|
||||
.. option:: -f output-file
|
||||
|
||||
This option indicates the name of the output file containing the signed zone. The default
|
||||
is to append ``.signed`` to the input filename. If ``output-file`` is
|
||||
set to ``-``, then the signed zone is written to the standard
|
||||
output, with a default output format of ``full``.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-signzone``.
|
||||
:program:`dnssec-signzone`.
|
||||
|
||||
.. option:: -V
|
||||
|
||||
``-V``
|
||||
This option prints version information.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option indicates that, when a previously signed zone is passed as input, records may be
|
||||
re-signed. The ``interval`` option specifies the cycle interval as an
|
||||
offset from the current time, in seconds. If a RRSIG record expires
|
||||
@@ -141,19 +160,21 @@ Options
|
||||
|
||||
The default cycle interval is one quarter of the difference between
|
||||
the signature end and start times. So if neither ``end-time`` nor
|
||||
``start-time`` is specified, ``dnssec-signzone`` generates
|
||||
``start-time`` is specified, :program:`dnssec-signzone` generates
|
||||
signatures that are valid for 30 days, with a cycle interval of 7.5
|
||||
days. Therefore, if any existing RRSIG records are due to expire in
|
||||
less than 7.5 days, they are replaced.
|
||||
|
||||
``-I input-format``
|
||||
.. option:: -I input-format
|
||||
|
||||
This option sets the format of the input zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``. This option is primarily
|
||||
intended to be used for dynamic signed zones, so that the dumped zone
|
||||
file in a non-text format containing updates can be signed directly.
|
||||
This option is not useful for non-dynamic zones.
|
||||
|
||||
``-j jitter``
|
||||
.. option:: -j jitter
|
||||
|
||||
When signing a zone with a fixed signature lifetime, all RRSIG
|
||||
records issued at the time of signing expire simultaneously. If the
|
||||
zone is incrementally signed, i.e., a previously signed zone is passed
|
||||
@@ -168,16 +189,19 @@ Options
|
||||
less congestion than if all validators need to refetch at around the
|
||||
same time.
|
||||
|
||||
``-L serial``
|
||||
.. option:: -L serial
|
||||
|
||||
When writing a signed zone to "raw" format, this option sets the "source
|
||||
serial" value in the header to the specified ``serial`` number. (This is
|
||||
expected to be used primarily for testing purposes.)
|
||||
|
||||
``-n ncpus``
|
||||
.. option:: -n ncpus
|
||||
|
||||
This option specifies the number of threads to use. By default, one thread is
|
||||
started for each detected CPU.
|
||||
|
||||
``-N soa-serial-format``
|
||||
.. option:: -N soa-serial-format
|
||||
|
||||
This option sets the SOA serial number format of the signed zone. Possible formats are
|
||||
``keep`` (the default), ``increment``, ``unixtime``, and
|
||||
``date``.
|
||||
@@ -200,21 +224,24 @@ Options
|
||||
than or equal to that value, in which case it is simply
|
||||
incremented by one.
|
||||
|
||||
``-o origin``
|
||||
.. option:: -o origin
|
||||
|
||||
This option sets the zone origin. If not specified, the name of the zone file is
|
||||
assumed to be the origin.
|
||||
|
||||
``-O output-format``
|
||||
.. option:: -O output-format
|
||||
|
||||
This option sets the format of the output file containing the signed
|
||||
zone. Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone; ``full``, which is text output in a
|
||||
format suitable for processing by external scripts; and ``raw`` and
|
||||
``raw=N``, which store the zone in binary formats for rapid loading by
|
||||
``named``. ``raw=N`` specifies the format version of the raw zone file:
|
||||
if N is 0, the raw file can be read by any version of ``named``; if N is
|
||||
:iscman:`named`. ``raw=N`` specifies the format version of the raw zone file:
|
||||
if N is 0, the raw file can be read by any version of :iscman:`named`; if N is
|
||||
1, the file can be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
``-P``
|
||||
.. option:: -P
|
||||
|
||||
This option disables post-sign verification tests.
|
||||
|
||||
The post-sign verification tests ensure that for each algorithm in
|
||||
@@ -222,36 +249,40 @@ Options
|
||||
revoked KSK keys are self-signed, and that all records in the zone
|
||||
are signed by the algorithm. This option skips these tests.
|
||||
|
||||
``-Q``
|
||||
.. option:: -Q
|
||||
|
||||
This option removes signatures from keys that are no longer active.
|
||||
|
||||
Normally, when a previously signed zone is passed as input to the
|
||||
signer, and a DNSKEY record has been removed and replaced with a new
|
||||
one, signatures from the old key that are still within their validity
|
||||
period are retained. This allows the zone to continue to validate
|
||||
with cached copies of the old DNSKEY RRset. The ``-Q`` option forces
|
||||
``dnssec-signzone`` to remove signatures from keys that are no longer
|
||||
with cached copies of the old DNSKEY RRset. The :option:`-Q` option forces
|
||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||
active. This enables ZSK rollover using the procedure described in
|
||||
:rfc:`4641#4.2.1.1` ("Pre-Publish Key Rollover").
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option enables quiet mode, which suppresses unnecessary output. Without this option, when
|
||||
``dnssec-signzone`` is run it prints three pieces of information to standard output: the number of
|
||||
:program:`dnssec-signzone` is run it prints three pieces of information to standard output: the number of
|
||||
keys in use; the algorithms used to verify the zone was signed correctly and
|
||||
other status information; and the filename containing the signed
|
||||
zone. With the option that output is suppressed, leaving only the filename.
|
||||
|
||||
``-R``
|
||||
.. option:: -R
|
||||
|
||||
This option removes signatures from keys that are no longer published.
|
||||
|
||||
This option is similar to ``-Q``, except it forces
|
||||
``dnssec-signzone`` to remove signatures from keys that are no longer
|
||||
This option is similar to :option:`-Q`, except it forces
|
||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||
published. This enables ZSK rollover using the procedure described in
|
||||
:rfc:`4641#4.2.1.2` ("Double Signature Zone Signing Key
|
||||
Rollover").
|
||||
|
||||
``-S``
|
||||
This option enables smart signing, which instructs ``dnssec-signzone`` to search the key
|
||||
.. option:: -S
|
||||
|
||||
This option enables smart signing, which instructs :program:`dnssec-signzone` to search the key
|
||||
repository for keys that match the zone being signed, and to include
|
||||
them in the zone if appropriate.
|
||||
|
||||
@@ -283,11 +314,12 @@ Options
|
||||
If the key's sync deletion date is set and is in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are removed.
|
||||
|
||||
``-T ttl``
|
||||
.. option:: -T ttl
|
||||
|
||||
This option specifies a TTL to be used for new DNSKEY records imported into the
|
||||
zone from the key repository. If not specified, the default is the
|
||||
TTL value from the zone's SOA record. This option is ignored when
|
||||
signing without ``-S``, since DNSKEY records are not imported from
|
||||
signing without :option:`-S`, since DNSKEY records are not imported from
|
||||
the key repository in that case. It is also ignored if there are any
|
||||
pre-existing DNSKEY records at the zone apex, in which case new
|
||||
records' TTL values are set to match them, or if any of the
|
||||
@@ -295,51 +327,63 @@ Options
|
||||
conflict between TTL values in imported keys, the shortest one is
|
||||
used.
|
||||
|
||||
``-t``
|
||||
.. option:: -t
|
||||
|
||||
This option prints statistics at completion.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option updates the NSEC/NSEC3 chain when re-signing a previously signed zone.
|
||||
With this option, a zone signed with NSEC can be switched to NSEC3,
|
||||
or a zone signed with NSEC3 can be switched to NSEC or to NSEC3 with
|
||||
different parameters. Without this option, ``dnssec-signzone``
|
||||
different parameters. Without this option, :program:`dnssec-signzone`
|
||||
retains the existing chain when re-signing.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-x``
|
||||
.. option:: -x
|
||||
|
||||
This option indicates that BIND 9 should only sign the DNSKEY, CDNSKEY, and CDS RRsets with key-signing keys,
|
||||
and should omit signatures from zone-signing keys. (This is similar to the
|
||||
``dnssec-dnskey-kskonly yes;`` zone option in ``named``.)
|
||||
``dnssec-dnskey-kskonly yes;`` zone option in :iscman:`named`.)
|
||||
|
||||
.. option:: -z
|
||||
|
||||
``-z``
|
||||
This option indicates that BIND 9 should ignore the KSK flag on keys when determining what to sign. This causes
|
||||
KSK-flagged keys to sign all records, not just the DNSKEY RRset.
|
||||
(This is similar to the ``update-check-ksk no;`` zone option in
|
||||
``named``.)
|
||||
:iscman:`named`.)
|
||||
|
||||
.. option:: -3 salt
|
||||
|
||||
``-3 salt``
|
||||
This option generates an NSEC3 chain with the given hex-encoded salt. A dash
|
||||
(-) can be used to indicate that no salt is to be used when
|
||||
generating the NSEC3 chain.
|
||||
|
||||
``-H iterations``
|
||||
.. option:: -H iterations
|
||||
|
||||
This option indicates that, when generating an NSEC3 chain, BIND 9 should use this many iterations. The default
|
||||
is 10.
|
||||
|
||||
``-A``
|
||||
.. option:: -A
|
||||
|
||||
This option indicates that, when generating an NSEC3 chain, BIND 9 should set the OPTOUT flag on all NSEC3
|
||||
records and should not generate NSEC3 records for insecure delegations.
|
||||
|
||||
Using this option twice (i.e., ``-AA``) turns the OPTOUT flag off for
|
||||
all records. This is useful when using the ``-u`` option to modify an
|
||||
.. option:: -AA
|
||||
|
||||
This option turns the OPTOUT flag off for
|
||||
all records. This is useful when using the :option:`-u` option to modify an
|
||||
NSEC3 chain which previously had OPTOUT set.
|
||||
|
||||
``zonefile``
|
||||
.. option:: zonefile
|
||||
|
||||
This option sets the file containing the zone to be signed.
|
||||
|
||||
``key``
|
||||
.. option:: key
|
||||
|
||||
This option specifies which keys should be used to sign the zone. If no keys are
|
||||
specified, the zone is examined for DNSKEY records at the
|
||||
zone apex. If these records are found and there are matching private keys in
|
||||
@@ -349,11 +393,11 @@ Example
|
||||
~~~~~~~
|
||||
|
||||
The following command signs the ``example.com`` zone with the
|
||||
ECDSAP256SHA256 key generated by ``dnssec-keygen``
|
||||
(Kexample.com.+013+17247). Because the ``-S`` option is not being used,
|
||||
ECDSAP256SHA256 key generated by :iscman:`dnssec-keygen`
|
||||
(Kexample.com.+013+17247). Because the :option:`-S` option is not being used,
|
||||
the zone's keys must be in the master file (``db.example.com``). This
|
||||
invocation looks for ``dsset`` files in the current directory, so that
|
||||
DS records can be imported from them (``-g``).
|
||||
DS records can be imported from them (:option:`-g`).
|
||||
|
||||
::
|
||||
|
||||
@@ -362,9 +406,9 @@ DS records can be imported from them (``-g``).
|
||||
db.example.com.signed
|
||||
%
|
||||
|
||||
In the above example, ``dnssec-signzone`` creates the file
|
||||
In the above example, :program:`dnssec-signzone` creates the file
|
||||
``db.example.com.signed``. This file should be referenced in a zone
|
||||
statement in the ``named.conf`` file.
|
||||
statement in the :iscman:`named.conf` file.
|
||||
|
||||
This example re-signs a previously signed zone with default parameters.
|
||||
The private keys are assumed to be in the current directory.
|
||||
@@ -379,5 +423,5 @@ The private keys are assumed to be in the current directory.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, BIND 9 Administrator Reference Manual, :rfc:`4033`,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, BIND 9 Administrator Reference Manual, :rfc:`4033`,
|
||||
:rfc:`4641`.
|
||||
|
||||
@@ -70,10 +70,10 @@ const char *program = "dnssec-verify";
|
||||
static isc_stdtime_t now;
|
||||
static isc_mem_t *mctx = NULL;
|
||||
static dns_masterformat_t inputformat = dns_masterformat_text;
|
||||
static dns_db_t *gdb; /* The database */
|
||||
static dns_dbversion_t *gversion; /* The database version */
|
||||
static dns_rdataclass_t gclass; /* The class */
|
||||
static dns_name_t *gorigin; /* The database origin */
|
||||
static dns_db_t *gdb = NULL; /* The database */
|
||||
static dns_dbversion_t *gversion = NULL; /* The database version */
|
||||
static dns_rdataclass_t gclass; /* The class */
|
||||
static dns_name_t *gorigin = NULL; /* The database origin */
|
||||
static bool ignore_kskflag = false;
|
||||
static bool keyset_kskonly = false;
|
||||
|
||||
@@ -132,14 +132,14 @@ loadzone(char *file, char *origin, dns_rdataclass_t rdclass, dns_db_t **db) {
|
||||
"use -o to specify a different zone origin",
|
||||
origin, file);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
default:
|
||||
fatal("failed loading zone from '%s': %s", file,
|
||||
isc_result_totext(result));
|
||||
}
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(void);
|
||||
|
||||
static void
|
||||
@@ -180,7 +180,7 @@ main(int argc, char *argv[]) {
|
||||
char *endp;
|
||||
int ch;
|
||||
|
||||
#define CMDLINE_FLAGS "c:E:hm:o:I:qv:Vxz"
|
||||
#define CMDLINE_FLAGS "c:E:hJ:m:o:I:qv:Vxz"
|
||||
|
||||
/*
|
||||
* Process memory debugging argument first.
|
||||
@@ -226,6 +226,10 @@ main(int argc, char *argv[]) {
|
||||
inputformatstr = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'J':
|
||||
journal = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'm':
|
||||
break;
|
||||
|
||||
@@ -258,7 +262,7 @@ main(int argc, char *argv[]) {
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
@@ -319,6 +323,9 @@ main(int argc, char *argv[]) {
|
||||
gdb = NULL;
|
||||
report("Loading zone '%s' from file '%s'\n", origin, file);
|
||||
loadzone(file, origin, rdclass, &gdb);
|
||||
if (journal != NULL) {
|
||||
loadjournal(mctx, gdb, journal);
|
||||
}
|
||||
gorigin = dns_db_origin(gdb);
|
||||
gclass = dns_db_class(gdb);
|
||||
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-verify
|
||||
.. program:: dnssec-verify
|
||||
.. _man_dnssec-verify:
|
||||
|
||||
dnssec-verify - DNSSEC zone verification tool
|
||||
@@ -24,55 +26,64 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-verify`` verifies that a zone is fully signed for each
|
||||
:program:`dnssec-verify` verifies that a zone is fully signed for each
|
||||
algorithm found in the DNSKEY RRset for the zone, and that the
|
||||
NSEC/NSEC3 chains are complete.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zone.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-I input-format``
|
||||
.. option:: -I input-format
|
||||
|
||||
This option sets the format of the input zone file. Possible formats are ``text``
|
||||
(the default) and ``raw``. This option is primarily intended to be used
|
||||
for dynamic signed zones, so that the dumped zone file in a non-text
|
||||
format containing updates can be verified independently.
|
||||
This option is not useful for non-dynamic zones.
|
||||
|
||||
``-o origin``
|
||||
.. option:: -o origin
|
||||
|
||||
This option indicates the zone origin. If not specified, the name of the zone file is
|
||||
assumed to be the origin.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-q``
|
||||
This option sets quiet mode, which suppresses output. Without this option, when ``dnssec-verify``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which suppresses output. Without this option, when :program:`dnssec-verify`
|
||||
is run it prints to standard output the number of keys in use, the
|
||||
algorithms used to verify the zone was signed correctly, and other status
|
||||
information. With this option, all non-error output is suppressed, and only the exit
|
||||
code indicates success.
|
||||
|
||||
``-x``
|
||||
.. option:: -x
|
||||
|
||||
This option verifies only that the DNSKEY RRset is signed with key-signing keys.
|
||||
Without this flag, it is assumed that the DNSKEY RRset is signed
|
||||
by all active keys. When this flag is set, it is not an error if
|
||||
the DNSKEY RRset is not signed by zone-signing keys. This corresponds
|
||||
to the ``-x`` option in ``dnssec-signzone``.
|
||||
to the :option:`-x option in dnssec-signzone <dnssec-signzone -x>`.
|
||||
|
||||
.. option:: -z
|
||||
|
||||
``-z``
|
||||
This option indicates that the KSK flag on the keys should be ignored when determining whether the zone is
|
||||
correctly signed. Without this flag, it is assumed that there is
|
||||
a non-revoked, self-signed DNSKEY with the KSK flag set for each
|
||||
@@ -84,12 +95,13 @@ Options
|
||||
the KSK flag state, and that other RRsets be signed by a
|
||||
non-revoked key for the same algorithm that includes the self-signed
|
||||
key; the same key may be used for both purposes. This corresponds to
|
||||
the ``-z`` option in ``dnssec-signzone``.
|
||||
the :option:`-z option in dnssec-signzone <dnssec-signzone -z>`.
|
||||
|
||||
.. option:: zonefile
|
||||
|
||||
``zonefile``
|
||||
This option indicates the file containing the zone to be signed.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual, :rfc:`4033`.
|
||||
:iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual, :rfc:`4033`.
|
||||
|
||||
+60
-4
@@ -33,12 +33,14 @@
|
||||
#include <isc/result.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/time.h>
|
||||
#include <isc/tm.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <dns/db.h>
|
||||
#include <dns/dbiterator.h>
|
||||
#include <dns/dnssec.h>
|
||||
#include <dns/fixedname.h>
|
||||
#include <dns/journal.h>
|
||||
#include <dns/keyvalues.h>
|
||||
#include <dns/log.h>
|
||||
#include <dns/name.h>
|
||||
@@ -64,6 +66,7 @@ static const char *keystates[KEYSTATES_NVALUES] = {
|
||||
|
||||
int verbose = 0;
|
||||
bool quiet = false;
|
||||
const char *journal = NULL;
|
||||
dns_dsdigest_t dtype[8];
|
||||
|
||||
static fatalcallback_t *fatalcallback = NULL;
|
||||
@@ -109,7 +112,7 @@ vbprintf(int level, const char *fmt, ...) {
|
||||
|
||||
void
|
||||
version(const char *name) {
|
||||
fprintf(stderr, "%s %s\n", name, PACKAGE_VERSION);
|
||||
printf("%s %s\n", name, PACKAGE_VERSION);
|
||||
exit(0);
|
||||
}
|
||||
|
||||
@@ -215,7 +218,7 @@ time_units(isc_stdtime_t offset, char *suffix, const char *str) {
|
||||
default:
|
||||
fatal("time value %s is invalid", str);
|
||||
}
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
break;
|
||||
case 'W':
|
||||
case 'w':
|
||||
@@ -233,11 +236,11 @@ time_units(isc_stdtime_t offset, char *suffix, const char *str) {
|
||||
default:
|
||||
fatal("time value %s is invalid", str);
|
||||
}
|
||||
/* NOTREACHED */
|
||||
UNREACHABLE();
|
||||
return (0); /* silence compiler warning */
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
isnone(const char *str) {
|
||||
return ((strcasecmp(str, "none") == 0) ||
|
||||
(strcasecmp(str, "never") == 0));
|
||||
@@ -283,6 +286,7 @@ strtotime(const char *str, int64_t now, int64_t base, bool *setp) {
|
||||
const char *orig = str;
|
||||
char *endp;
|
||||
size_t n;
|
||||
struct tm tm;
|
||||
|
||||
if (isnone(str)) {
|
||||
if (setp != NULL) {
|
||||
@@ -304,6 +308,8 @@ strtotime(const char *str, int64_t now, int64_t base, bool *setp) {
|
||||
* now([+-]offset)
|
||||
* YYYYMMDD([+-]offset)
|
||||
* YYYYMMDDhhmmss([+-]offset)
|
||||
* Day Mon DD HH:MM:SS YYYY([+-]offset)
|
||||
* 1234567890([+-]offset)
|
||||
* [+-]offset
|
||||
*/
|
||||
n = strspn(str, "0123456789");
|
||||
@@ -323,9 +329,21 @@ strtotime(const char *str, int64_t now, int64_t base, bool *setp) {
|
||||
}
|
||||
base = val;
|
||||
str += n;
|
||||
} else if (n == 10u &&
|
||||
(str[n] == '\0' || str[n] == '-' || str[n] == '+')) {
|
||||
base = strtoll(str, &endp, 0);
|
||||
str += 10;
|
||||
} else if (strncmp(str, "now", 3) == 0) {
|
||||
base = now;
|
||||
str += 3;
|
||||
} else if (str[0] >= 'A' && str[0] <= 'Z') {
|
||||
/* parse ctime() format as written by `dnssec-settime -p` */
|
||||
endp = isc_tm_strptime(str, "%a %b %d %H:%M:%S %Y", &tm);
|
||||
if (endp != str + 24) {
|
||||
fatal("time value %s is invalid", orig);
|
||||
}
|
||||
base = mktime(&tm);
|
||||
str += 24;
|
||||
}
|
||||
|
||||
if (str[0] == '\0') {
|
||||
@@ -564,3 +582,41 @@ isoptarg(const char *arg, char **argv, void (*usage)(void)) {
|
||||
}
|
||||
return (false);
|
||||
}
|
||||
|
||||
void
|
||||
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *file) {
|
||||
dns_journal_t *jnl = NULL;
|
||||
isc_result_t result;
|
||||
|
||||
result = dns_journal_open(mctx, file, DNS_JOURNAL_READ, &jnl);
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
fprintf(stderr, "%s: journal file %s not found\n", program,
|
||||
file);
|
||||
goto cleanup;
|
||||
} else if (result != ISC_R_SUCCESS) {
|
||||
fatal("unable to open journal %s: %s\n", file,
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (dns_journal_empty(jnl)) {
|
||||
dns_journal_destroy(&jnl);
|
||||
return;
|
||||
}
|
||||
|
||||
result = dns_journal_rollforward(jnl, db, 0);
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
case DNS_R_UPTODATE:
|
||||
break;
|
||||
|
||||
case ISC_R_NOTFOUND:
|
||||
case ISC_R_RANGE:
|
||||
fatal("journal %s out of sync with zone", file);
|
||||
|
||||
default:
|
||||
fatal("journal %s: %s\n", file, isc_result_totext(result));
|
||||
}
|
||||
|
||||
cleanup:
|
||||
dns_journal_destroy(&jnl);
|
||||
}
|
||||
|
||||
@@ -32,6 +32,9 @@ extern bool quiet;
|
||||
/*! program name, statically initialized in each program */
|
||||
extern const char *program;
|
||||
|
||||
/*! journal file */
|
||||
extern const char *journal;
|
||||
|
||||
/*!
|
||||
* List of DS digest types used by dnssec-cds and dnssec-dsfromkey,
|
||||
* defined in dnssectool.c. Filled in by add_dtype() from -a
|
||||
@@ -43,7 +46,7 @@ extern uint8_t dtype[8];
|
||||
|
||||
typedef void(fatalcallback_t)(void);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
void
|
||||
@@ -55,7 +58,7 @@ check_result(isc_result_t result, const char *message);
|
||||
void
|
||||
vbprintf(int level, const char *fmt, ...) ISC_FORMAT_PRINTF(2, 3);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
version(const char *program);
|
||||
|
||||
void
|
||||
@@ -102,3 +105,6 @@ key_collision(dst_key_t *key, dns_name_t *name, const char *dir,
|
||||
|
||||
bool
|
||||
isoptarg(const char *arg, char **argv, void (*usage)(void));
|
||||
|
||||
void
|
||||
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *journal);
|
||||
|
||||
+21
-14
@@ -20,6 +20,7 @@
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/log.h>
|
||||
#include <isc/mem.h>
|
||||
#include <isc/netmgr.h>
|
||||
#include <isc/parseint.h>
|
||||
#include <isc/region.h>
|
||||
#include <isc/result.h>
|
||||
@@ -59,16 +60,15 @@ options {\n\
|
||||
edns-udp-size 1232;\n\
|
||||
files unlimited;\n"
|
||||
#if defined(HAVE_GEOIP2)
|
||||
" geoip-directory \"" MAXMINDDB_PREFIX "/share/"
|
||||
"GeoIP\";"
|
||||
"\n"
|
||||
"\
|
||||
geoip-directory \"" MAXMINDDB_PREFIX "/share/GeoIP\";\n"
|
||||
#elif defined(HAVE_GEOIP2)
|
||||
" geoip-directory \".\";\n"
|
||||
"\
|
||||
geoip-directory \".\";\n"
|
||||
#endif /* if defined(HAVE_GEOIP2) */
|
||||
"\
|
||||
heartbeat-interval 60;\n\
|
||||
interface-interval 60;\n\
|
||||
# keep-response-order {none;};\n\
|
||||
listen-on {any;};\n\
|
||||
listen-on-v6 {any;};\n\
|
||||
# lock-file \"" NAMED_LOCALSTATEDIR "/run/named/named.lock\";\n\
|
||||
@@ -82,13 +82,22 @@ options {\n\
|
||||
nta-lifetime 3600;\n\
|
||||
nta-recheck 300;\n\
|
||||
# pid-file \"" NAMED_LOCALSTATEDIR "/run/named/named.pid\"; \n\
|
||||
port 53;\n\
|
||||
port 53;\n"
|
||||
#if HAVE_SO_REUSEPORT_LB
|
||||
"\
|
||||
reuseport yes;\n"
|
||||
#else
|
||||
"\
|
||||
reuseport no;\n"
|
||||
#endif
|
||||
"\
|
||||
tls-port 853;\n"
|
||||
#if HAVE_LIBNGHTTP2
|
||||
"http-port 80;\n"
|
||||
"https-port 443;\n"
|
||||
"http-listener-clients 300;\n"
|
||||
"http-streams-per-connection 100;\n"
|
||||
"\
|
||||
http-port 80;\n\
|
||||
https-port 443;\n\
|
||||
http-listener-clients 300;\n\
|
||||
http-streams-per-connection 100;\n"
|
||||
#endif
|
||||
"\
|
||||
prefetch 2 9;\n\
|
||||
@@ -454,8 +463,7 @@ named_config_getzonetype(const cfg_obj_t *zonetypeobj) {
|
||||
} else if (strcasecmp(str, "redirect") == 0) {
|
||||
ztype = dns_zone_redirect;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
return (ztype);
|
||||
}
|
||||
@@ -1067,8 +1075,7 @@ named_config_getkeyalgorithm2(const char *str, const dns_name_t **name,
|
||||
*name = dns_tsig_hmacsha512_name;
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
if (typep != NULL) {
|
||||
|
||||
+1
-4
@@ -59,7 +59,7 @@ getcommand(isc_lex_t *lex, char **cmdp) {
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
static inline bool
|
||||
static bool
|
||||
command_compare(const char *str, const char *command) {
|
||||
return (strcasecmp(str, command) == 0);
|
||||
}
|
||||
@@ -278,9 +278,6 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
||||
command_compare(command, NAMED_COMMAND_UNFREEZE))
|
||||
{
|
||||
result = named_server_freeze(named_g_server, false, lex, text);
|
||||
} else if (command_compare(command, NAMED_COMMAND_TIMERPOKE)) {
|
||||
isc_timermgr_poke(named_g_timermgr);
|
||||
result = ISC_R_SUCCESS;
|
||||
} else if (command_compare(command, NAMED_COMMAND_TRACE)) {
|
||||
result = named_server_setdebuglevel(named_g_server, lex);
|
||||
} else if (command_compare(command, NAMED_COMMAND_TSIGDELETE)) {
|
||||
|
||||
@@ -257,7 +257,7 @@ cleanup_sendhandle:
|
||||
isc_nmhandle_detach(&conn->sendhandle);
|
||||
}
|
||||
|
||||
static inline void
|
||||
static void
|
||||
log_invalid(isccc_ccmsg_t *ccmsg, isc_result_t result) {
|
||||
char socktext[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_t peeraddr = isc_nmhandle_peeraddr(ccmsg->handle);
|
||||
@@ -588,6 +588,9 @@ conn_put(void *arg) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
||||
"freeing control connection");
|
||||
|
||||
isc_mem_put(listener->mctx, conn, sizeof(*conn));
|
||||
|
||||
maybe_free_listener(listener);
|
||||
}
|
||||
|
||||
@@ -597,7 +600,7 @@ newconnection(controllistener_t *listener, isc_nmhandle_t *handle) {
|
||||
|
||||
conn = isc_nmhandle_getdata(handle);
|
||||
if (conn == NULL) {
|
||||
conn = isc_nmhandle_getextra(handle);
|
||||
conn = isc_mem_get(listener->mctx, sizeof(*conn));
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_CONTROL, ISC_LOG_DEBUG(3),
|
||||
"allocate new control connection");
|
||||
@@ -1160,9 +1163,9 @@ add_listener(named_controls_t *cp, controllistener_t **listenerp,
|
||||
}
|
||||
#endif
|
||||
|
||||
CHECK(isc_nm_listentcp(
|
||||
named_g_netmgr, &listener->address, control_newconn, listener,
|
||||
sizeof(controlconnection_t), 5, NULL, &listener->sock));
|
||||
CHECK(isc_nm_listentcp(named_g_netmgr, ISC_NM_LISTEN_ONE,
|
||||
&listener->address, control_newconn, listener, 5,
|
||||
NULL, &listener->sock));
|
||||
#if 0
|
||||
/* XXX: no unix socket support yet */
|
||||
if (type == isc_socktype_unix) {
|
||||
|
||||
@@ -48,7 +48,6 @@
|
||||
#define NAMED_COMMAND_FREEZE "freeze"
|
||||
#define NAMED_COMMAND_UNFREEZE "unfreeze"
|
||||
#define NAMED_COMMAND_THAW "thaw"
|
||||
#define NAMED_COMMAND_TIMERPOKE "timerpoke"
|
||||
#define NAMED_COMMAND_RECURSING "recursing"
|
||||
#define NAMED_COMMAND_NULL "null"
|
||||
#define NAMED_COMMAND_NOTIFY "notify"
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
*/
|
||||
#define NAMED_MAIN_ARGS "46A:c:d:D:E:fFgL:M:m:n:N:p:sS:t:T:U:u:vVx:X:"
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
named_main_earlyfatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
void
|
||||
|
||||
+1
-2
@@ -161,8 +161,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *logconfig) {
|
||||
maxoffset = 0x7fffffffffffffffULL;
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
type = ISC_LOG_TOFILE;
|
||||
|
||||
+6
-8
@@ -32,7 +32,6 @@
|
||||
#include <isc/dir.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/hash.h>
|
||||
#include <isc/hp.h>
|
||||
#include <isc/httpd.h>
|
||||
#include <isc/managers.h>
|
||||
#include <isc/netmgr.h>
|
||||
@@ -186,7 +185,7 @@ named_main_earlyfatal(const char *format, ...) {
|
||||
exit(1);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
||||
const char *cond);
|
||||
|
||||
@@ -240,7 +239,7 @@ assertion_failed(const char *file, int line, isc_assertiontype_t type,
|
||||
exit(1);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
library_fatal_error(const char *file, int line, const char *format,
|
||||
va_list args) ISC_FORMAT_PRINTF(3, 0);
|
||||
|
||||
@@ -729,8 +728,7 @@ parse_port(char *arg) {
|
||||
named_g_httpport = port;
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -861,8 +859,8 @@ parse_command_line(int argc, char *argv[]) {
|
||||
}
|
||||
break;
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
/* Reserved for FIPS mode */
|
||||
FALLTHROUGH;
|
||||
case '?':
|
||||
usage();
|
||||
if (isc_commandline_option == '?') {
|
||||
@@ -877,7 +875,7 @@ parse_command_line(int argc, char *argv[]) {
|
||||
"an argument",
|
||||
isc_commandline_option);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
default:
|
||||
named_main_earlyfatal("parsing options returned %d",
|
||||
ch);
|
||||
|
||||
+34
-260
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named.conf
|
||||
|
||||
named.conf - configuration file for **named**
|
||||
---------------------------------------------
|
||||
|
||||
@@ -22,10 +24,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named.conf`` is the configuration file for ``named``. Statements are
|
||||
enclosed in braces and terminated with a semi-colon. Clauses in the
|
||||
statements are also semi-colon terminated. The usual comment styles are
|
||||
supported:
|
||||
:file:`named.conf` is the configuration file for :iscman:`named`.
|
||||
Statements are enclosed in braces and terminated with a semi-colon.
|
||||
Clauses in the statements are also semi-colon terminated. The usual
|
||||
comment styles are supported:
|
||||
|
||||
C style: /\* \*/
|
||||
|
||||
@@ -152,17 +154,6 @@ See DNSSEC-KEYS.
|
||||
initial-ds ) integer integer
|
||||
integer quoted_string; ... };, deprecated
|
||||
|
||||
MASTERS
|
||||
^^^^^^^
|
||||
|
||||
::
|
||||
|
||||
masters string [ port integer ] [ dscp
|
||||
integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... };
|
||||
|
||||
OPTIONS
|
||||
^^^^^^^
|
||||
|
||||
@@ -198,15 +189,12 @@ OPTIONS
|
||||
avoid-v6-udp-ports { portrange; ... };
|
||||
bindkeys-file quoted_string;
|
||||
blackhole { address_match_element; ... };
|
||||
catalog-zones { zone string [ default-masters [ port integer ]
|
||||
[ dscp integer ] { ( remote-servers | ipv4_address [ port
|
||||
integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ default-primaries [ port
|
||||
integer ] [ dscp integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... } ] [
|
||||
zone-directory quoted_string ] [ in-memory boolean ] [
|
||||
min-update-interval duration ]; ... };
|
||||
catalog-zones { zone string [ default-primaries [ port integer
|
||||
] [ dscp integer ] { ( remote-servers | ipv4_address [
|
||||
port integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ zone-directory
|
||||
quoted_string ] [ in-memory boolean ] [ min-update-interval
|
||||
duration ]; ... };
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
@@ -301,7 +289,6 @@ OPTIONS
|
||||
ipv4only-server string;
|
||||
ixfr-from-differences ( primary | master | secondary | slave |
|
||||
boolean );
|
||||
keep-response-order { address_match_element; ... };
|
||||
key-directory quoted_string;
|
||||
lame-ttl duration;
|
||||
listen-on [ port integer ] [ dscp
|
||||
@@ -422,6 +409,7 @@ OPTIONS
|
||||
[ nsip-enable boolean ] [ nsdname-enable boolean ] [
|
||||
dnsrps-enable boolean ] [ dnsrps-options { unspecified-text
|
||||
} ];
|
||||
reuseport boolean;
|
||||
root-delegation-only [ exclude { string; ... } ];
|
||||
root-key-sentinel boolean;
|
||||
rrset-order { [ class string ] [ type string ] [ name
|
||||
@@ -573,9 +561,11 @@ TLS
|
||||
::
|
||||
|
||||
tls string {
|
||||
ca-file quoted_string;
|
||||
cert-file quoted_string;
|
||||
ciphers string;
|
||||
dhparam-file quoted_string;
|
||||
hostname quoted_string;
|
||||
key-file quoted_string;
|
||||
prefer-server-ciphers boolean;
|
||||
protocols { string; ... };
|
||||
@@ -632,15 +622,12 @@ VIEW
|
||||
attach-cache string;
|
||||
auth-nxdomain boolean;
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
catalog-zones { zone string [ default-masters [ port integer ]
|
||||
[ dscp integer ] { ( remote-servers | ipv4_address [ port
|
||||
integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ default-primaries [ port
|
||||
integer ] [ dscp integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... } ] [
|
||||
zone-directory quoted_string ] [ in-memory boolean ] [
|
||||
min-update-interval duration ]; ... };
|
||||
catalog-zones { zone string [ default-primaries [ port integer
|
||||
] [ dscp integer ] { ( remote-servers | ipv4_address [
|
||||
port integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ zone-directory
|
||||
quoted_string ] [ in-memory boolean ] [ min-update-interval
|
||||
duration ]; ... };
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
@@ -898,245 +885,32 @@ VIEW
|
||||
validate-except { string; ... };
|
||||
zero-no-soa-ttl boolean;
|
||||
zero-no-soa-ttl-cache boolean;
|
||||
zone string [ class ] {
|
||||
allow-notify { address_match_element; ... };
|
||||
allow-query { address_match_element; ... };
|
||||
allow-query-on { address_match_element; ... };
|
||||
allow-transfer [ port integer ] [ transport string ] {
|
||||
address_match_element; ... };
|
||||
allow-update { address_match_element; ... };
|
||||
allow-update-forwarding { address_match_element; ... };
|
||||
also-notify [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
alt-transfer-source ( ipv4_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
alt-transfer-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
check-mx-cname ( fail | warn | ignore );
|
||||
check-names ( fail | warn | ignore );
|
||||
check-sibling boolean;
|
||||
check-spf ( warn | ignore );
|
||||
check-srv-cname ( fail | warn | ignore );
|
||||
check-wildcard boolean;
|
||||
database string;
|
||||
delegation-only boolean;
|
||||
dialup ( notify | notify-passive | passive | refresh |
|
||||
boolean );
|
||||
dlz string;
|
||||
dnskey-sig-validity integer;
|
||||
dnssec-dnskey-kskonly boolean;
|
||||
dnssec-loadkeys-interval integer;
|
||||
dnssec-policy string;
|
||||
dnssec-secure-to-insecure boolean;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
file quoted_string;
|
||||
forward ( first | only );
|
||||
forwarders [ port integer ] [ dscp integer ] { (
|
||||
ipv4_address | ipv6_address ) [ port integer ] [
|
||||
dscp integer ]; ... };
|
||||
in-view string;
|
||||
inline-signing boolean;
|
||||
ixfr-from-differences boolean;
|
||||
journal quoted_string;
|
||||
key-directory quoted_string;
|
||||
masterfile-format ( raw | text );
|
||||
masterfile-style ( full | relative );
|
||||
masters [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
max-ixfr-ratio ( unlimited | percentage );
|
||||
max-journal-size ( default | unlimited | sizeval );
|
||||
max-records integer;
|
||||
max-refresh-time integer;
|
||||
max-retry-time integer;
|
||||
max-transfer-idle-in integer;
|
||||
max-transfer-idle-out integer;
|
||||
max-transfer-time-in integer;
|
||||
max-transfer-time-out integer;
|
||||
max-zone-ttl ( unlimited | duration );
|
||||
min-refresh-time integer;
|
||||
min-retry-time integer;
|
||||
multi-master boolean;
|
||||
notify ( explicit | master-only | primary-only | boolean );
|
||||
notify-delay integer;
|
||||
notify-source ( ipv4_address | * ) [ port ( integer | *
|
||||
) ] [ dscp integer ];
|
||||
notify-source-v6 ( ipv6_address | * ) [ port ( integer
|
||||
| * ) ] [ dscp integer ];
|
||||
notify-to-soa boolean;
|
||||
parental-agents [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
parental-source ( ipv4_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
parental-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
primaries [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
request-expire boolean;
|
||||
request-ixfr boolean;
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( ipv4_address | ipv6_address ); ... };
|
||||
server-names { string; ... };
|
||||
sig-signing-nodes integer;
|
||||
sig-signing-signatures integer;
|
||||
sig-signing-type integer;
|
||||
sig-validity-interval integer [ integer ];
|
||||
transfer-source ( ipv4_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
transfer-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
try-tcp-refresh boolean;
|
||||
type ( primary | master | secondary | slave | mirror |
|
||||
delegation-only | forward | hint | redirect |
|
||||
static-stub | stub );
|
||||
update-check-ksk boolean;
|
||||
update-policy ( local | { ( deny | grant ) string (
|
||||
6to4-self | external | krb5-self | krb5-selfsub |
|
||||
krb5-subdomain | krb5-subdomain-self-rhs | ms-self |
|
||||
ms-selfsub | ms-subdomain | ms-subdomain-self-rhs |
|
||||
name | self | selfsub | selfwild | subdomain | tcp-self
|
||||
| wildcard | zonesub ) [ string ] rrtypelist; ... };
|
||||
use-alt-transfer-source boolean;
|
||||
zero-no-soa-ttl boolean;
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
|
||||
ZONE
|
||||
^^^^
|
||||
|
||||
::
|
||||
Any of these zone statements can also be set inside the view statement.
|
||||
|
||||
zone string [ class ] {
|
||||
allow-notify { address_match_element; ... };
|
||||
allow-query { address_match_element; ... };
|
||||
allow-query-on { address_match_element; ... };
|
||||
allow-transfer [ port integer ] [ transport string ] {
|
||||
address_match_element; ... };
|
||||
allow-update { address_match_element; ... };
|
||||
allow-update-forwarding { address_match_element; ... };
|
||||
also-notify [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
alt-transfer-source ( ipv4_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
alt-transfer-source-v6 ( ipv6_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
check-mx-cname ( fail | warn | ignore );
|
||||
check-names ( fail | warn | ignore );
|
||||
check-sibling boolean;
|
||||
check-spf ( warn | ignore );
|
||||
check-srv-cname ( fail | warn | ignore );
|
||||
check-wildcard boolean;
|
||||
database string;
|
||||
delegation-only boolean;
|
||||
dialup ( notify | notify-passive | passive | refresh | boolean );
|
||||
dlz string;
|
||||
dnskey-sig-validity integer;
|
||||
dnssec-dnskey-kskonly boolean;
|
||||
dnssec-loadkeys-interval integer;
|
||||
dnssec-policy string;
|
||||
dnssec-secure-to-insecure boolean;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
file quoted_string;
|
||||
forward ( first | only );
|
||||
forwarders [ port integer ] [ dscp integer ] { ( ipv4_address
|
||||
| ipv6_address ) [ port integer ] [ dscp integer ]; ... };
|
||||
in-view string;
|
||||
inline-signing boolean;
|
||||
ixfr-from-differences boolean;
|
||||
journal quoted_string;
|
||||
key-directory quoted_string;
|
||||
masterfile-format ( raw | text );
|
||||
masterfile-style ( full | relative );
|
||||
masters [ port integer ] [ dscp integer ] { ( remote-servers
|
||||
| ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... };
|
||||
max-ixfr-ratio ( unlimited | percentage );
|
||||
max-journal-size ( default | unlimited | sizeval );
|
||||
max-records integer;
|
||||
max-refresh-time integer;
|
||||
max-retry-time integer;
|
||||
max-transfer-idle-in integer;
|
||||
max-transfer-idle-out integer;
|
||||
max-transfer-time-in integer;
|
||||
max-transfer-time-out integer;
|
||||
max-zone-ttl ( unlimited | duration );
|
||||
min-refresh-time integer;
|
||||
min-retry-time integer;
|
||||
multi-master boolean;
|
||||
notify ( explicit | master-only | primary-only | boolean );
|
||||
notify-delay integer;
|
||||
notify-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
notify-source-v6 ( ipv6_address | * ) [ port ( integer | * ) ]
|
||||
[ dscp integer ];
|
||||
notify-to-soa boolean;
|
||||
parental-agents [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
parental-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
parental-source-v6 ( ipv6_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
primaries [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
request-expire boolean;
|
||||
request-ixfr boolean;
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( ipv4_address | ipv6_address ); ... };
|
||||
server-names { string; ... };
|
||||
sig-signing-nodes integer;
|
||||
sig-signing-signatures integer;
|
||||
sig-signing-type integer;
|
||||
sig-validity-interval integer [ integer ];
|
||||
transfer-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
transfer-source-v6 ( ipv6_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
try-tcp-refresh boolean;
|
||||
type ( primary | master | secondary | slave | mirror |
|
||||
delegation-only | forward | hint | redirect | static-stub |
|
||||
stub );
|
||||
update-check-ksk boolean;
|
||||
update-policy ( local | { ( deny | grant ) string ( 6to4-self |
|
||||
external | krb5-self | krb5-selfsub | krb5-subdomain |
|
||||
krb5-subdomain-self-rhs | ms-self | ms-selfsub | ms-subdomain |
|
||||
ms-subdomain-self-rhs | name | self | selfsub | selfwild |
|
||||
subdomain | tcp-self | wildcard | zonesub ) [ string ]
|
||||
rrtypelist; ... };
|
||||
use-alt-transfer-source boolean;
|
||||
zero-no-soa-ttl boolean;
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
.. include:: ../../doc/misc/primary.zoneopt.rst
|
||||
.. include:: ../../doc/misc/secondary.zoneopt.rst
|
||||
.. include:: ../../doc/misc/mirror.zoneopt.rst
|
||||
.. include:: ../../doc/misc/forward.zoneopt.rst
|
||||
.. include:: ../../doc/misc/hint.zoneopt.rst
|
||||
.. include:: ../../doc/misc/redirect.zoneopt.rst
|
||||
.. include:: ../../doc/misc/static-stub.zoneopt.rst
|
||||
.. include:: ../../doc/misc/stub.zoneopt.rst
|
||||
.. include:: ../../doc/misc/delegation-only.zoneopt.rst
|
||||
.. include:: ../../doc/misc/in-view.zoneopt.rst
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/named.conf``
|
||||
|named_conf|
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkconf(8)`, :manpage:`rndc(8)`, :manpage:`rndc-confgen(8)`, :manpage:`tsig-keygen(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`rndc(8) <rndc>`, :iscman:`rndc-confgen(8) <rndc-confgen>`, :iscman:`tsig-keygen(8) <tsig-keygen>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
|
||||
+78
-55
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named
|
||||
.. program:: named
|
||||
.. _man_named:
|
||||
|
||||
named - Internet domain name server
|
||||
@@ -24,41 +26,47 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named`` is a Domain Name System (DNS) server, part of the BIND 9
|
||||
:program:`named` is a Domain Name System (DNS) server, part of the BIND 9
|
||||
distribution from ISC. For more information on the DNS, see :rfc:`1033`,
|
||||
:rfc:`1034`, and :rfc:`1035`.
|
||||
|
||||
When invoked without arguments, ``named`` reads the default
|
||||
configuration file ``/etc/named.conf``, reads any initial data, and
|
||||
When invoked without arguments, :program:`named` reads the default
|
||||
configuration file |named_conf|, reads any initial data, and
|
||||
listens for queries.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
This option tells ``named`` to use only IPv4, even if the host machine is capable of IPv6. ``-4`` and
|
||||
``-6`` are mutually exclusive.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option tells ``named`` to use only IPv6, even if the host machine is capable of IPv4. ``-4`` and
|
||||
``-6`` are mutually exclusive.
|
||||
This option tells :program:`named` to use only IPv4, even if the host machine is capable of IPv6. :option:`-4` and
|
||||
:option:`-6` are mutually exclusive.
|
||||
|
||||
``-c config-file``
|
||||
This option tells ``named`` to use ``config-file`` as its configuration file instead of the default,
|
||||
``/etc/named.conf``. To ensure that the configuration file
|
||||
.. option:: -6
|
||||
|
||||
This option tells :program:`named` to use only IPv6, even if the host machine is capable of IPv4. :option:`-4` and
|
||||
:option:`-6` are mutually exclusive.
|
||||
|
||||
.. option:: -c config-file
|
||||
|
||||
This option tells :program:`named` to use ``config-file`` as its configuration file instead of the default,
|
||||
|named_conf|. To ensure that the configuration file
|
||||
can be reloaded after the server has changed its working directory
|
||||
due to to a possible ``directory`` option in the configuration file,
|
||||
``config-file`` should be an absolute pathname.
|
||||
|
||||
``-d debug-level``
|
||||
This option sets the daemon's debug level to ``debug-level``. Debugging traces from
|
||||
``named`` become more verbose as the debug level increases.
|
||||
.. option:: -d debug-level
|
||||
|
||||
``-D string``
|
||||
This option specifies a string that is used to identify a instance of ``named``
|
||||
This option sets the daemon's debug level to ``debug-level``. Debugging traces from
|
||||
:program:`named` become more verbose as the debug level increases.
|
||||
|
||||
.. option:: -D string
|
||||
|
||||
This option specifies a string that is used to identify a instance of :program:`named`
|
||||
in a process listing. The contents of ``string`` are not examined.
|
||||
|
||||
``-E engine-name``
|
||||
.. option:: -E engine-name
|
||||
|
||||
When applicable, this option specifies the hardware to use for cryptographic
|
||||
operations, such as a secure key store used for signing.
|
||||
|
||||
@@ -66,36 +74,43 @@ Options
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f``
|
||||
.. option:: -f
|
||||
|
||||
This option runs the server in the foreground (i.e., do not daemonize).
|
||||
|
||||
``-g``
|
||||
.. option:: -g
|
||||
|
||||
This option runs the server in the foreground and forces all logging to ``stderr``.
|
||||
|
||||
``-L logfile``
|
||||
.. option:: -L logfile
|
||||
|
||||
This option sets the log to the file ``logfile`` by default, instead of the system log.
|
||||
|
||||
``-M option``
|
||||
.. option:: -M option
|
||||
|
||||
This option sets the default memory context options. If set to ``external``,
|
||||
the internal memory manager is bypassed in favor of
|
||||
system-provided memory allocation functions. If set to ``fill``, blocks
|
||||
of memory are filled with tag values when allocated or freed, to
|
||||
assist debugging of memory problems. ``nofill`` disables this behavior,
|
||||
and is the default unless ``named`` has been compiled with developer
|
||||
and is the default unless :program:`named` has been compiled with developer
|
||||
options.
|
||||
|
||||
``-m flag``
|
||||
.. option:: -m flag
|
||||
|
||||
This option turns on memory usage debugging flags. Possible flags are ``usage``,
|
||||
``trace``, ``record``, ``size``, and ``mctx``. These correspond to the
|
||||
``ISC_MEM_DEBUGXXXX`` flags described in ``<isc/mem.h>``.
|
||||
|
||||
``-n #cpus``
|
||||
.. option:: -n #cpus
|
||||
|
||||
This option creates ``#cpus`` worker threads to take advantage of multiple CPUs. If
|
||||
not specified, ``named`` tries to determine the number of CPUs
|
||||
not specified, :program:`named` tries to determine the number of CPUs
|
||||
present and creates one thread per CPU. If it is unable to determine
|
||||
the number of CPUs, a single worker thread is created.
|
||||
|
||||
``-p value``
|
||||
.. option:: -p value
|
||||
|
||||
This option specifies the port(s) on which the server will listen
|
||||
for queries. If ``value`` is of the form ``<portnum>`` or
|
||||
``dns=<portnum>``, the server will listen for DNS queries on
|
||||
@@ -106,8 +121,9 @@ Options
|
||||
listen for HTTPS queries on ``portnum``; the default is 443.
|
||||
If ``value`` is of the form ``http=<portnum>``, the server will
|
||||
listen for HTTP queries on ``portnum``; the default is 80.
|
||||
|
||||
``-s``
|
||||
|
||||
.. option:: -s
|
||||
|
||||
This option writes memory usage statistics to ``stdout`` on exit.
|
||||
|
||||
.. note::
|
||||
@@ -115,7 +131,8 @@ Options
|
||||
This option is mainly of interest to BIND 9 developers and may be
|
||||
removed or changed in a future release.
|
||||
|
||||
``-S #max-socks``
|
||||
.. option:: -S #max-socks
|
||||
|
||||
This option is deprecated and no longer has any function.
|
||||
|
||||
.. warning::
|
||||
@@ -127,61 +144,67 @@ Options
|
||||
exhaustion of file descriptors and the operational environment is
|
||||
known to support the specified number of sockets. Note also that
|
||||
the actual maximum number is normally slightly fewer than the
|
||||
specified value, because ``named`` reserves some file descriptors
|
||||
specified value, because :program:`named` reserves some file descriptors
|
||||
for its internal use.
|
||||
|
||||
``-t directory``
|
||||
This option tells ``named`` to chroot to ``directory`` after processing the command-line arguments, but
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :program:`named` to chroot to ``directory`` after processing the command-line arguments, but
|
||||
before reading the configuration file.
|
||||
|
||||
.. warning::
|
||||
|
||||
This option should be used in conjunction with the ``-u`` option,
|
||||
This option should be used in conjunction with the :option:`-u` option,
|
||||
as chrooting a process running as root doesn't enhance security on
|
||||
most systems; the way ``chroot`` is defined allows a process
|
||||
with root privileges to escape a chroot jail.
|
||||
|
||||
``-U #listeners``
|
||||
This option tells ``named`` the number of ``#listeners`` worker threads to listen on, for incoming UDP packets on
|
||||
each address. If not specified, ``named`` calculates a default
|
||||
.. option:: -U #listeners
|
||||
|
||||
This option tells :program:`named` the number of ``#listeners`` worker threads to listen on, for incoming UDP packets on
|
||||
each address. If not specified, :program:`named` calculates a default
|
||||
value based on the number of detected CPUs: 1 for 1 CPU, and the
|
||||
number of detected CPUs minus one for machines with more than 1 CPU.
|
||||
This cannot be increased to a value higher than the number of CPUs.
|
||||
If ``-n`` has been set to a higher value than the number of detected
|
||||
CPUs, then ``-U`` may be increased as high as that value, but no
|
||||
If :option:`-n` has been set to a higher value than the number of detected
|
||||
CPUs, then :option:`-U` may be increased as high as that value, but no
|
||||
higher.
|
||||
|
||||
``-u user``
|
||||
.. option:: -u user
|
||||
|
||||
This option sets the setuid to ``user`` after completing privileged operations, such as
|
||||
creating sockets that listen on privileged ports.
|
||||
|
||||
.. note::
|
||||
|
||||
On Linux, ``named`` uses the kernel's capability mechanism to drop
|
||||
On Linux, :program:`named` uses the kernel's capability mechanism to drop
|
||||
all root privileges except the ability to ``bind`` to a
|
||||
privileged port and set process resource limits. Unfortunately,
|
||||
this means that the ``-u`` option only works when ``named`` is run
|
||||
this means that the :option:`-u` option only works when :program:`named` is run
|
||||
on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or later, since
|
||||
previous kernels did not allow privileges to be retained after
|
||||
``setuid``.
|
||||
|
||||
``-v``
|
||||
.. option:: -v
|
||||
|
||||
This option reports the version number and exits.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option reports the version number and build options, and exits.
|
||||
|
||||
``-X lock-file``
|
||||
.. option:: -X lock-file
|
||||
|
||||
This option acquires a lock on the specified file at runtime; this helps to
|
||||
prevent duplicate ``named`` instances from running simultaneously.
|
||||
prevent duplicate :program:`named` instances from running simultaneously.
|
||||
Use of this option overrides the ``lock-file`` option in
|
||||
``named.conf``. If set to ``none``, the lock file check is disabled.
|
||||
:iscman:`named.conf`. If set to ``none``, the lock file check is disabled.
|
||||
|
||||
Signals
|
||||
~~~~~~~
|
||||
|
||||
In routine operation, signals should not be used to control the
|
||||
nameserver; ``rndc`` should be used instead.
|
||||
nameserver; :iscman:`rndc` should be used instead.
|
||||
|
||||
SIGHUP
|
||||
This signal forces a reload of the server.
|
||||
@@ -194,25 +217,25 @@ The result of sending any other signals to the server is undefined.
|
||||
Configuration
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
The ``named`` configuration file is too complex to describe in detail
|
||||
The :program:`named` configuration file is too complex to describe in detail
|
||||
here. A complete description is provided in the BIND 9 Administrator
|
||||
Reference Manual.
|
||||
|
||||
``named`` inherits the ``umask`` (file creation mode mask) from the
|
||||
parent process. If files created by ``named``, such as journal files,
|
||||
:program:`named` inherits the ``umask`` (file creation mode mask) from the
|
||||
parent process. If files created by :program:`named`, such as journal files,
|
||||
need to have custom permissions, the ``umask`` should be set explicitly
|
||||
in the script used to start the ``named`` process.
|
||||
in the script used to start the :program:`named` process.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/named.conf``
|
||||
|named_conf|
|
||||
The default configuration file.
|
||||
|
||||
``/var/run/named/named.pid``
|
||||
|named_pid|
|
||||
The default process-id file.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:rfc:`1033`, :rfc:`1034`, :rfc:`1035`, :manpage:`named-checkconf(8)`, :manpage:`named-checkzone(8)`, :manpage:`rndc(8)`, :manpage:`named.conf(5)`, BIND 9 Administrator Reference Manual.
|
||||
:rfc:`1033`, :rfc:`1034`, :rfc:`1035`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-checkzone(8) <named-checkzone>`, :iscman:`rndc(8) <rndc>`, :iscman:`named.conf(5) <named.conf>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+340
-397
File diff suppressed because it is too large
Load Diff
@@ -211,7 +211,7 @@ static int tcpoutsizestats_index[dns_sizecounter_out_max];
|
||||
static int dnstapstats_index[dns_dnstapcounter_max];
|
||||
static int gluecachestats_index[dns_gluecachestatscounter_max];
|
||||
|
||||
static inline void
|
||||
static void
|
||||
set_desc(int counter, int maxcounter, const char *fdesc, const char **fdescs,
|
||||
const char *xdesc, const char **xdescs) {
|
||||
REQUIRE(counter < maxcounter);
|
||||
|
||||
@@ -122,16 +122,10 @@ add_doh_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
||||
parse_transport_bool_option(
|
||||
doh, transport, "prefer-server-ciphers",
|
||||
dns_transport_set_prefer_server_ciphers)
|
||||
#if 0
|
||||
/*
|
||||
* The following two options need to remain unavailable until
|
||||
* TLS certificate verification gets implemented.
|
||||
*/
|
||||
parse_transport_option(doh, transport, "ca-file",
|
||||
dns_transport_set_cafile);
|
||||
parse_transport_option(doh, transport, "ca-file",
|
||||
dns_transport_set_cafile);
|
||||
parse_transport_option(doh, transport, "hostname",
|
||||
dns_transport_set_hostname);
|
||||
#endif
|
||||
}
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -180,16 +174,10 @@ add_tls_transports(const cfg_obj_t *transportlist, dns_transport_list_t *list) {
|
||||
parse_transport_bool_option(
|
||||
tls, transport, "prefer-server-ciphers",
|
||||
dns_transport_set_prefer_server_ciphers)
|
||||
#if 0
|
||||
/*
|
||||
* The following two options need to remain unavailable until
|
||||
* TLS certificate verification gets implemented.
|
||||
*/
|
||||
parse_transport_option(tls, transport, "ca-file",
|
||||
dns_transport_set_cafile);
|
||||
parse_transport_option(tls, transport, "ca-file",
|
||||
dns_transport_set_cafile);
|
||||
parse_transport_option(tls, transport, "hostname",
|
||||
dns_transport_set_hostname);
|
||||
#endif
|
||||
}
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
+18
-34
@@ -133,8 +133,7 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
aclname = "allow-update-forwarding";
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
/* First check to see if ACL is defined within the zone */
|
||||
@@ -246,8 +245,7 @@ configure_zone_ssutable(const cfg_obj_t *zconfig, dns_zone_t *zone,
|
||||
} else if (strcasecmp(str, "deny") == 0) {
|
||||
grant = false;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
str = cfg_obj_asstring(matchtype);
|
||||
@@ -684,7 +682,7 @@ cleanup:
|
||||
/*%
|
||||
* Convert a config file zone type into a server zone type.
|
||||
*/
|
||||
static inline dns_zonetype_t
|
||||
static dns_zonetype_t
|
||||
zonetype_fromconfig(const cfg_obj_t *map) {
|
||||
const cfg_obj_t *obj = NULL;
|
||||
isc_result_t result;
|
||||
@@ -759,8 +757,7 @@ checknames(dns_zonetype_t ztype, const cfg_obj_t **maps,
|
||||
result = named_checknames_get(maps, primary_synonyms, objp);
|
||||
break;
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
INSIST(result == ISC_R_SUCCESS && objp != NULL && *objp != NULL);
|
||||
@@ -1041,8 +1038,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(masterformatstr, "raw") == 0) {
|
||||
masterformat = dns_masterformat_raw;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1065,8 +1061,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(masterstylestr, "relative") == 0) {
|
||||
masterstyle = &dns_master_style_default;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1159,8 +1154,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(dialupstr, "passive") == 0) {
|
||||
dialup = dns_dialuptype_passive;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
if (raw != NULL) {
|
||||
@@ -1186,8 +1180,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(levelstr, "none") == 0) {
|
||||
statlevel = dns_zonestat_none;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
dns_zone_setstatlevel(zone, statlevel);
|
||||
@@ -1266,8 +1259,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
{
|
||||
notifytype = dns_notifytype_masteronly;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
notifytype = process_notifytype(notifytype, ztype, zname,
|
||||
@@ -1460,8 +1452,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
fail = check = false;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
if (raw != NULL) {
|
||||
dns_zone_setoption(raw, DNS_ZONEOPT_CHECKNAMES, check);
|
||||
@@ -1495,8 +1486,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
check = false;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_CHECKSPF, check);
|
||||
|
||||
@@ -1696,8 +1686,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(arg, "off") == 0) {
|
||||
/* Default */
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_ALLOW, allow);
|
||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_CREATE, false);
|
||||
@@ -1756,8 +1745,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(dupcheck, "ignore") == 0) {
|
||||
fail = check = false;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_CHECKDUPRR, check);
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_CHECKDUPRRFAIL, fail);
|
||||
@@ -1773,8 +1761,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
fail = check = false;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_CHECKMX, check);
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_CHECKMXFAIL, fail);
|
||||
@@ -1796,8 +1783,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
warn = ignore = true;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_WARNMXCNAME, warn);
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_IGNOREMXCNAME, ignore);
|
||||
@@ -1813,8 +1799,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(cfg_obj_asstring(obj), "ignore") == 0) {
|
||||
warn = ignore = true;
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_WARNSRVCNAME, warn);
|
||||
dns_zone_setoption(mayberaw, DNS_ZONEOPT_IGNORESRVCNAME,
|
||||
@@ -1837,8 +1822,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
} else if (strcasecmp(arg, "maintain") == 0) {
|
||||
/* Default */
|
||||
} else {
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1874,7 +1858,7 @@ named_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
dns_zone_setxfracl(zone, none);
|
||||
dns_acl_detach(&none);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case dns_zone_secondary:
|
||||
case dns_zone_stub:
|
||||
case dns_zone_redirect:
|
||||
|
||||
+12
-17
@@ -187,7 +187,7 @@ sendrequest(isc_sockaddr_t *destaddr, dns_message_t *msg,
|
||||
static void
|
||||
send_update(dns_name_t *zonename, isc_sockaddr_t *primary);
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
static void
|
||||
@@ -304,7 +304,7 @@ ddebug(const char *format, ...) {
|
||||
}
|
||||
}
|
||||
|
||||
static inline void
|
||||
static void
|
||||
check_result(isc_result_t result, const char *msg) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("%s: %s", msg, isc_result_totext(result));
|
||||
@@ -719,12 +719,6 @@ doshutdown(void) {
|
||||
dns_message_detach(&updatemsg);
|
||||
}
|
||||
|
||||
if (is_dst_up) {
|
||||
ddebug("Destroy DST lib");
|
||||
dst_lib_destroy();
|
||||
is_dst_up = false;
|
||||
}
|
||||
|
||||
ddebug("Destroying request manager");
|
||||
dns_requestmgr_detach(&requestmgr);
|
||||
|
||||
@@ -982,11 +976,6 @@ get_addresses(char *host, in_port_t port, isc_sockaddr_t *sockaddr,
|
||||
return (count);
|
||||
}
|
||||
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "nsupdate %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
#define PARSE_ARGS_FMT "46C:dDghilL:Mok:p:Pr:R:t:Tu:vVy:"
|
||||
|
||||
static void
|
||||
@@ -1061,7 +1050,7 @@ pre_parse_args(int argc, char **argv) {
|
||||
break;
|
||||
|
||||
case 'V':
|
||||
version();
|
||||
printf("nsupdate %s\n", PACKAGE_VERSION);
|
||||
doexit = true;
|
||||
break;
|
||||
|
||||
@@ -3305,6 +3294,9 @@ cleanup(void) {
|
||||
}
|
||||
UNLOCK(&answer_lock);
|
||||
|
||||
ddebug("Shutting down managers");
|
||||
isc_managers_destroy(&netmgr, &taskmgr, NULL);
|
||||
|
||||
#if HAVE_GSSAPI
|
||||
if (tsigkey != NULL) {
|
||||
ddebug("detach tsigkey x%p", tsigkey);
|
||||
@@ -3320,9 +3312,6 @@ cleanup(void) {
|
||||
dst_key_free(&sig0key);
|
||||
}
|
||||
|
||||
ddebug("Shutting down managers");
|
||||
isc_managers_destroy(&netmgr, &taskmgr, NULL);
|
||||
|
||||
ddebug("Destroying event");
|
||||
isc_event_free(&global_event);
|
||||
|
||||
@@ -3356,6 +3345,12 @@ cleanup(void) {
|
||||
isc_mem_destroy(&gmctx);
|
||||
|
||||
isc_mutex_destroy(&answer_lock);
|
||||
|
||||
if (is_dst_up) {
|
||||
ddebug("Destroy DST lib");
|
||||
dst_lib_destroy();
|
||||
is_dst_up = false;
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
|
||||
+80
-53
@@ -9,8 +9,8 @@
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: nsupdate
|
||||
.. program:: nsupdate
|
||||
.. _man_nsupdate:
|
||||
|
||||
nsupdate - dynamic DNS update utility
|
||||
@@ -24,18 +24,18 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``nsupdate`` is used to submit Dynamic DNS Update requests, as defined in
|
||||
:program:`nsupdate` is used to submit Dynamic DNS Update requests, as defined in
|
||||
:rfc:`2136`, to a name server. This allows resource records to be added or
|
||||
removed from a zone without manually editing the zone file. A single
|
||||
update request can contain requests to add or remove more than one
|
||||
resource record.
|
||||
|
||||
Zones that are under dynamic control via ``nsupdate`` or a DHCP server
|
||||
Zones that are under dynamic control via :program:`nsupdate` or a DHCP server
|
||||
should not be edited by hand. Manual edits could conflict with dynamic
|
||||
updates and cause data to be lost.
|
||||
|
||||
The resource records that are dynamically added or removed with
|
||||
``nsupdate`` must be in the same zone. Requests are sent to the
|
||||
:program:`nsupdate` must be in the same zone. Requests are sent to the
|
||||
zone's primary server, which is identified by the MNAME field of the
|
||||
zone's SOA record.
|
||||
|
||||
@@ -44,87 +44,110 @@ updates. These use the TSIG resource record type described in :rfc:`2845`,
|
||||
the SIG(0) record described in :rfc:`2535` and :rfc:`2931`, or GSS-TSIG as
|
||||
described in :rfc:`3645`.
|
||||
|
||||
TSIG relies on a shared secret that should only be known to ``nsupdate``
|
||||
TSIG relies on a shared secret that should only be known to :program:`nsupdate`
|
||||
and the name server. For instance, suitable ``key`` and ``server``
|
||||
statements are added to ``/etc/named.conf`` so that the name server
|
||||
statements are added to |named_conf| so that the name server
|
||||
can associate the appropriate secret key and algorithm with the IP
|
||||
address of the client application that is using TSIG
|
||||
authentication. ``ddns-confgen`` can generate suitable
|
||||
configuration fragments. ``nsupdate`` uses the ``-y`` or ``-k`` options
|
||||
authentication. :iscman:`ddns-confgen` can generate suitable
|
||||
configuration fragments. :program:`nsupdate` uses the :option:`-y` or :option:`-k` options
|
||||
to provide the TSIG shared secret; these options are mutually exclusive.
|
||||
|
||||
SIG(0) uses public key cryptography. To use a SIG(0) key, the public key
|
||||
must be stored in a KEY record in a zone served by the name server.
|
||||
|
||||
GSS-TSIG uses Kerberos credentials. Standard GSS-TSIG mode is switched
|
||||
on with the ``-g`` flag. A non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000 can be switched on with the ``-o`` flag.
|
||||
on with the :option:`-g` flag. A non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000 can be switched on with the :option:`-o` flag.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option sets use of IPv4 only.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option sets use of IPv6 only.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
Overrides the default `resolv.conf` file. This is only intended for testing.
|
||||
|
||||
``-d``
|
||||
.. option:: -d
|
||||
|
||||
This option sets debug mode, which provides tracing information about the update
|
||||
requests that are made and the replies received from the name server.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option sets extra debug mode.
|
||||
|
||||
``-i``
|
||||
.. option:: -g
|
||||
|
||||
This option enables standard GSS-TSIG mode.
|
||||
|
||||
.. option:: -i
|
||||
|
||||
This option forces interactive mode, even when standard input is not a terminal.
|
||||
|
||||
``-k keyfile``
|
||||
.. option:: -k keyfile
|
||||
|
||||
This option indicates the file containing the TSIG authentication key. Keyfiles may be in
|
||||
two formats: a single file containing a ``named.conf``-format ``key``
|
||||
statement, which may be generated automatically by ``ddns-confgen``;
|
||||
two formats: a single file containing a :iscman:`named.conf`-format ``key``
|
||||
statement, which may be generated automatically by :iscman:`ddns-confgen`;
|
||||
or a pair of files whose names are of the format
|
||||
``K{name}.+157.+{random}.key`` and
|
||||
``K{name}.+157.+{random}.private``, which can be generated by
|
||||
``dnssec-keygen``. The ``-k`` option can also be used to specify a SIG(0)
|
||||
:iscman:`dnssec-keygen`. The :option:`-k` option can also be used to specify a SIG(0)
|
||||
key used to authenticate Dynamic DNS update requests. In this case,
|
||||
the key specified is not an HMAC-MD5 key.
|
||||
|
||||
``-l``
|
||||
.. option:: -l
|
||||
|
||||
This option sets local-host only mode, which sets the server address to localhost
|
||||
(disabling the ``server`` so that the server address cannot be
|
||||
overridden). Connections to the local server use a TSIG key
|
||||
found in ``/var/run/named/session.key``, which is automatically
|
||||
generated by ``named`` if any local ``primary`` zone has set
|
||||
found in |session_key|, which is automatically
|
||||
generated by :iscman:`named` if any local ``primary`` zone has set
|
||||
``update-policy`` to ``local``. The location of this key file can be
|
||||
overridden with the ``-k`` option.
|
||||
overridden with the :option:`-k` option.
|
||||
|
||||
.. option:: -L level
|
||||
|
||||
``-L level``
|
||||
This option sets the logging debug level. If zero, logging is disabled.
|
||||
|
||||
``-p port``
|
||||
.. option:: -o
|
||||
|
||||
This option enables a non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000.
|
||||
|
||||
.. option:: -p port
|
||||
|
||||
This option sets the port to use for connections to a name server. The default is
|
||||
53.
|
||||
|
||||
``-P``
|
||||
.. option:: -P
|
||||
|
||||
This option prints the list of private BIND-specific resource record types whose
|
||||
format is understood by ``nsupdate``. See also the ``-T`` option.
|
||||
format is understood by :program:`nsupdate`. See also the :option:`-T` option.
|
||||
|
||||
.. option:: -r udpretries
|
||||
|
||||
``-r udpretries``
|
||||
This option sets the number of UDP retries. The default is 3. If zero, only one update
|
||||
request is made.
|
||||
|
||||
``-t timeout``
|
||||
.. option:: -t timeout
|
||||
|
||||
This option sets the maximum time an update request can take before it is aborted. The
|
||||
default is 300 seconds. If zero, the timeout is disabled.
|
||||
|
||||
``-T``
|
||||
.. option:: -T
|
||||
|
||||
This option prints the list of IANA standard resource record types whose format is
|
||||
understood by ``nsupdate``. ``nsupdate`` exits after the lists
|
||||
are printed. The ``-T`` option can be combined with the ``-P``
|
||||
understood by :program:`nsupdate`. :program:`nsupdate` exits after the lists
|
||||
are printed. The :option:`-T` option can be combined with the :option:`-P`
|
||||
option.
|
||||
|
||||
Other types can be entered using ``TYPEXXXXX`` where ``XXXXX`` is the
|
||||
@@ -132,21 +155,25 @@ Options
|
||||
present, is parsed using the UNKNOWN rdata format, (<backslash>
|
||||
<hash> <space> <length> <space> <hexstring>).
|
||||
|
||||
``-u udptimeout``
|
||||
.. option:: -u udptimeout
|
||||
|
||||
This option sets the UDP retry interval. The default is 3 seconds. If zero, the
|
||||
interval is computed from the timeout interval and number of UDP
|
||||
retries.
|
||||
|
||||
``-v``
|
||||
This option specifies that TCP should be used even for small update requests. By default, ``nsupdate`` uses
|
||||
.. option:: -v
|
||||
|
||||
This option specifies that TCP should be used even for small update requests. By default, :program:`nsupdate` uses
|
||||
UDP to send update requests to the name server unless they are too
|
||||
large to fit in a UDP request, in which case TCP is used. TCP may
|
||||
be preferable when a batch of update requests is made.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-y [hmac:]keyname:secret``
|
||||
.. option:: -y [hmac:]keyname:secret
|
||||
|
||||
This option sets the literal TSIG authentication key. ``keyname`` is the name of the key,
|
||||
and ``secret`` is the base64 encoded shared secret. ``hmac`` is the
|
||||
name of the key algorithm; valid choices are ``hmac-md5``,
|
||||
@@ -154,7 +181,7 @@ Options
|
||||
``hmac-sha512``. If ``hmac`` is not specified, the default is
|
||||
``hmac-md5``, or if MD5 was disabled, ``hmac-sha256``.
|
||||
|
||||
NOTE: Use of the ``-y`` option is discouraged because the shared
|
||||
NOTE: Use of the :option:`-y` option is discouraged because the shared
|
||||
secret is supplied as a command-line argument in clear text. This may
|
||||
be visible in the output from ps1 or in a history file maintained by
|
||||
the user's shell.
|
||||
@@ -162,7 +189,7 @@ Options
|
||||
Input Format
|
||||
~~~~~~~~~~~~
|
||||
|
||||
``nsupdate`` reads input from ``filename`` or standard input. Each
|
||||
:program:`nsupdate` reads input from ``filename`` or standard input. Each
|
||||
command is supplied on exactly one line of input. Some commands are for
|
||||
administrative purposes; others are either update instructions or
|
||||
prerequisite checks on the contents of the zone. These checks set
|
||||
@@ -182,7 +209,7 @@ The command formats and their meanings are as follows:
|
||||
|
||||
``server servername port``
|
||||
This command sends all dynamic update requests to the name server ``servername``.
|
||||
When no server statement is provided, ``nsupdate`` sends updates
|
||||
When no server statement is provided, :program:`nsupdate` sends updates
|
||||
to the primary server of the correct zone. The MNAME field of that
|
||||
zone's SOA record identify the primary server for that zone.
|
||||
``port`` is the port number on ``servername`` where the dynamic
|
||||
@@ -191,14 +218,14 @@ The command formats and their meanings are as follows:
|
||||
|
||||
``local address port``
|
||||
This command sends all dynamic update requests using the local ``address``. When
|
||||
no local statement is provided, ``nsupdate`` sends updates using
|
||||
no local statement is provided, :program:`nsupdate` sends updates using
|
||||
an address and port chosen by the system. ``port`` can also
|
||||
be used to force requests to come from a specific port. If no port number
|
||||
is specified, the system assigns one.
|
||||
|
||||
``zone zonename``
|
||||
This command specifies that all updates are to be made to the zone ``zonename``.
|
||||
If no ``zone`` statement is provided, ``nsupdate`` attempts to
|
||||
If no ``zone`` statement is provided, :program:`nsupdate` attempts to
|
||||
determine the correct zone to update based on the rest of the input.
|
||||
|
||||
``class classname``
|
||||
@@ -214,15 +241,15 @@ The command formats and their meanings are as follows:
|
||||
``keyname``-``secret`` pair. If ``hmac`` is specified, it sets
|
||||
the signing algorithm in use. The default is ``hmac-md5``; if MD5
|
||||
was disabled, the default is ``hmac-sha256``. The ``key`` command overrides any key
|
||||
specified on the command line via ``-y`` or ``-k``.
|
||||
specified on the command line via :option:`-y` or :option:`-k`.
|
||||
|
||||
``gsstsig``
|
||||
This command uses GSS-TSIG to sign the updates. This is equivalent to specifying
|
||||
``-g`` on the command line.
|
||||
:option:`-g` on the command line.
|
||||
|
||||
``oldgsstsig``
|
||||
This command uses the Windows 2000 version of GSS-TSIG to sign the updates. This is
|
||||
equivalent to specifying ``-o`` on the command line.
|
||||
equivalent to specifying :option:`-o` on the command line.
|
||||
|
||||
``realm [realm_name]``
|
||||
When using GSS-TSIG, this command specifies the use of ``realm_name`` rather than the default realm
|
||||
@@ -296,7 +323,7 @@ Lines beginning with a semicolon (;) are comments and are ignored.
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
The examples below show how ``nsupdate`` can be used to insert and
|
||||
The examples below show how :program:`nsupdate` can be used to insert and
|
||||
delete resource records from the ``example.com`` zone. Notice that the
|
||||
input in each example contains a trailing blank line, so that a group of
|
||||
commands is sent as one dynamic update request to the primary name
|
||||
@@ -335,24 +362,24 @@ Files
|
||||
``/etc/resolv.conf``
|
||||
Used to identify the default name server
|
||||
|
||||
``/var/run/named/session.key``
|
||||
|session_key|
|
||||
Sets the default TSIG key for use in local-only mode
|
||||
|
||||
``K{name}.+157.+{random}.key``
|
||||
Base-64 encoding of the HMAC-MD5 key created by ``dnssec-keygen``.
|
||||
Base-64 encoding of the HMAC-MD5 key created by :iscman:`dnssec-keygen`.
|
||||
|
||||
``K{name}.+157.+{random}.private``
|
||||
Base-64 encoding of the HMAC-MD5 key created by ``dnssec-keygen``.
|
||||
Base-64 encoding of the HMAC-MD5 key created by :iscman:`dnssec-keygen`.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:rfc:`2136`, :rfc:`3007`, :rfc:`2104`, :rfc:`2845`, :rfc:`1034`, :rfc:`2535`, :rfc:`2931`,
|
||||
:manpage:`named(8)`, :manpage:`dnssec-keygen(8)`, :manpage:`tsig-keygen(8)`.
|
||||
:iscman:`named(8) <named>`, :iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`tsig-keygen(8) <tsig-keygen>`.
|
||||
|
||||
Bugs
|
||||
~~~~
|
||||
|
||||
The TSIG key is redundantly stored in two separate files. This is a
|
||||
consequence of ``nsupdate`` using the DST library for its cryptographic
|
||||
consequence of :program:`nsupdate` using the DST library for its cryptographic
|
||||
operations, and may change in future releases.
|
||||
|
||||
@@ -330,7 +330,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
||||
filter_instance_t *inst = NULL;
|
||||
isc_result_t result;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
|
||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
||||
ISC_LOG_INFO,
|
||||
@@ -347,7 +347,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
cfg_line, mctx, lctx, actx));
|
||||
}
|
||||
|
||||
CHECK(isc_ht_init(&inst->ht, mctx, 16));
|
||||
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
||||
isc_mutex_init(&inst->hlock);
|
||||
|
||||
/*
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: filter-a
|
||||
.. _man_filter-a:
|
||||
|
||||
filter-a.so - filter A in DNS responses when AAAA is present
|
||||
@@ -24,14 +25,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``filter-a.so`` is a query plugin module for ``named``, enabling
|
||||
``named`` to omit some IPv4 addresses when responding to clients.
|
||||
:program:`filter-a.so` is a query plugin module for :iscman:`named`, enabling
|
||||
:iscman:`named` to omit some IPv4 addresses when responding to clients.
|
||||
|
||||
For example:
|
||||
|
||||
::
|
||||
|
||||
plugin query "/usr/local/lib/filter-a.so" {
|
||||
plugin query "filter-a.so" {
|
||||
filter-a-on-v6 yes;
|
||||
filter-a-on-v4 yes;
|
||||
filter-a { 192.0.2.1; 2001:db8:2::1; };
|
||||
|
||||
@@ -333,7 +333,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
||||
filter_instance_t *inst = NULL;
|
||||
isc_result_t result;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
|
||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
||||
ISC_LOG_INFO,
|
||||
@@ -350,7 +350,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
cfg_line, mctx, lctx, actx));
|
||||
}
|
||||
|
||||
CHECK(isc_ht_init(&inst->ht, mctx, 16));
|
||||
isc_ht_init(&inst->ht, mctx, 1, ISC_HT_CASE_SENSITIVE);
|
||||
isc_mutex_init(&inst->hlock);
|
||||
|
||||
/*
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: filter-aaaa
|
||||
.. _man_filter-aaaa:
|
||||
|
||||
filter-aaaa.so - filter AAAA in DNS responses when A is present
|
||||
@@ -24,18 +25,18 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``filter-aaaa.so`` is a query plugin module for ``named``, enabling
|
||||
``named`` to omit some IPv6 addresses when responding to clients.
|
||||
:program:`filter-aaaa.so` is a query plugin module for :iscman:`named`, enabling
|
||||
:iscman:`named` to omit some IPv6 addresses when responding to clients.
|
||||
|
||||
Until BIND 9.12, this feature was implemented natively in ``named`` and
|
||||
Until BIND 9.12, this feature was implemented natively in :iscman:`named` and
|
||||
enabled with the ``filter-aaaa`` ACL and the ``filter-aaaa-on-v4`` and
|
||||
``filter-aaaa-on-v6`` options. These options are now deprecated in
|
||||
``named.conf`` but can be passed as parameters to the
|
||||
:iscman:`named.conf` but can be passed as parameters to the
|
||||
``filter-aaaa.so`` plugin, for example:
|
||||
|
||||
::
|
||||
|
||||
plugin query "/usr/local/lib/filter-aaaa.so" {
|
||||
plugin query "filter-aaaa.so" {
|
||||
filter-aaaa-on-v4 yes;
|
||||
filter-aaaa-on-v6 yes;
|
||||
filter-aaaa { 192.0.2.1; 2001:db8:2::1; };
|
||||
|
||||
+7
-8
@@ -80,9 +80,9 @@ static isccc_region_t secret;
|
||||
static bool failed = false;
|
||||
static bool c_flag = false;
|
||||
static isc_mem_t *rndc_mctx = NULL;
|
||||
static atomic_uint_fast32_t sends = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t recvs = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t connects = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t sends = 0;
|
||||
static atomic_uint_fast32_t recvs = 0;
|
||||
static atomic_uint_fast32_t connects = 0;
|
||||
static char *command = NULL;
|
||||
static char *args = NULL;
|
||||
static char program[256];
|
||||
@@ -96,7 +96,7 @@ static isc_nmhandle_t *recvnonce_handle = NULL;
|
||||
static void
|
||||
rndc_startconnect(isc_sockaddr_t *addr);
|
||||
|
||||
ISC_NORETURN static void
|
||||
noreturn static void
|
||||
usage(int status);
|
||||
|
||||
static void
|
||||
@@ -592,13 +592,12 @@ rndc_startconnect(isc_sockaddr_t *addr) {
|
||||
*/
|
||||
fatal("UNIX domain sockets not currently supported");
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
UNREACHABLE();
|
||||
}
|
||||
|
||||
atomic_fetch_add_relaxed(&connects, 1);
|
||||
isc_nm_tcpconnect(netmgr, local, addr, rndc_connected, &rndc_ccmsg,
|
||||
60000, 0);
|
||||
60000);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -1001,7 +1000,7 @@ main(int argc, char **argv) {
|
||||
program, isc_commandline_option);
|
||||
usage(1);
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
FALLTHROUGH;
|
||||
case 'h':
|
||||
usage(0);
|
||||
break;
|
||||
|
||||
+17
-15
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc.conf
|
||||
.. program:: rndc.conf
|
||||
.. _man_rndc.conf:
|
||||
|
||||
rndc.conf - rndc configuration file
|
||||
@@ -24,9 +26,9 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc.conf`` is the configuration file for ``rndc``, the BIND 9 name
|
||||
:program:`rndc.conf` is the configuration file for :iscman:`rndc`, the BIND 9 name
|
||||
server control utility. This file has a similar structure and syntax to
|
||||
``named.conf``. Statements are enclosed in braces and terminated with a
|
||||
:iscman:`named.conf`. Statements are enclosed in braces and terminated with a
|
||||
semi-colon. Clauses in the statements are also semi-colon terminated.
|
||||
The usual comment styles are supported:
|
||||
|
||||
@@ -36,13 +38,13 @@ C++ style: // to end of line
|
||||
|
||||
Unix style: # to end of line
|
||||
|
||||
``rndc.conf`` is much simpler than ``named.conf``. The file uses three
|
||||
:program:`rndc.conf` is much simpler than :iscman:`named.conf`. The file uses three
|
||||
statements: an options statement, a server statement, and a key
|
||||
statement.
|
||||
|
||||
The ``options`` statement contains five clauses. The ``default-server``
|
||||
clause is followed by the name or address of a name server. This host
|
||||
is used when no name server is given as an argument to ``rndc``.
|
||||
is used when no name server is given as an argument to :iscman:`rndc`.
|
||||
The ``default-key`` clause is followed by the name of a key, which is
|
||||
identified by a ``key`` statement. If no ``keyid`` is provided on the
|
||||
rndc command line, and no ``key`` clause is found in a matching
|
||||
@@ -67,14 +69,14 @@ IPv4 and IPv6 source address, respectively.
|
||||
|
||||
The ``key`` statement begins with an identifying string, the name of the
|
||||
key. The statement has two clauses. ``algorithm`` identifies the
|
||||
authentication algorithm for ``rndc`` to use; currently only HMAC-MD5
|
||||
authentication algorithm for :iscman:`rndc` to use; currently only HMAC-MD5
|
||||
(for compatibility), HMAC-SHA1, HMAC-SHA224, HMAC-SHA256 (default),
|
||||
HMAC-SHA384, and HMAC-SHA512 are supported. This is followed by a secret
|
||||
clause which contains the base-64 encoding of the algorithm's
|
||||
authentication key. The base-64 string is enclosed in double quotes.
|
||||
|
||||
There are two common ways to generate the base-64 string for the secret.
|
||||
The BIND 9 program ``rndc-confgen`` can be used to generate a random
|
||||
The BIND 9 program :iscman:`rndc-confgen` can be used to generate a random
|
||||
key, or the ``mmencode`` program, also known as ``mimencode``, can be
|
||||
used to generate a base-64 string from known input. ``mmencode`` does
|
||||
not ship with BIND 9 but is available on many systems. See the Example
|
||||
@@ -118,7 +120,7 @@ Example
|
||||
};
|
||||
|
||||
|
||||
In the above example, ``rndc`` by default uses the server at
|
||||
In the above example, :iscman:`rndc` by default uses the server at
|
||||
localhost (127.0.0.1) and the key called "samplekey". Commands to the
|
||||
localhost server use the "samplekey" key, which must also be defined
|
||||
in the server's configuration file with the same name and secret. The
|
||||
@@ -126,16 +128,16 @@ key statement indicates that "samplekey" uses the HMAC-SHA256 algorithm
|
||||
and its secret clause contains the base-64 encoding of the HMAC-SHA256
|
||||
secret enclosed in double quotes.
|
||||
|
||||
If ``rndc -s testserver`` is used, then ``rndc`` connects to the server
|
||||
If :option:`rndc -s testserver <rndc -s>` is used, then :iscman:`rndc` connects to the server
|
||||
on localhost port 5353 using the key "testkey".
|
||||
|
||||
To generate a random secret with ``rndc-confgen``:
|
||||
To generate a random secret with :iscman:`rndc-confgen`:
|
||||
|
||||
``rndc-confgen``
|
||||
:iscman:`rndc-confgen`
|
||||
|
||||
A complete ``rndc.conf`` file, including the randomly generated key,
|
||||
A complete :program:`rndc.conf` file, including the randomly generated key,
|
||||
is written to the standard output. Commented-out ``key`` and
|
||||
``controls`` statements for ``named.conf`` are also printed.
|
||||
``controls`` statements for :iscman:`named.conf` are also printed.
|
||||
|
||||
To generate a base-64 secret with ``mmencode``:
|
||||
|
||||
@@ -145,12 +147,12 @@ Name Server Configuration
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
The name server must be configured to accept rndc connections and to
|
||||
recognize the key specified in the ``rndc.conf`` file, using the
|
||||
controls statement in ``named.conf``. See the sections on the
|
||||
recognize the key specified in the :program:`rndc.conf` file, using the
|
||||
controls statement in :iscman:`named.conf`. See the sections on the
|
||||
``controls`` statement in the BIND 9 Administrator Reference Manual for
|
||||
details.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc(8)`, :manpage:`rndc-confgen(8)`, :manpage:`mmencode(1)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`rndc(8) <rndc>`, :iscman:`rndc-confgen(8) <rndc-confgen>`, :manpage:`mmencode(1)`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+169
-116
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc
|
||||
.. program:: rndc
|
||||
.. _man_rndc:
|
||||
|
||||
rndc - name server control utility
|
||||
@@ -24,15 +26,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc`` controls the operation of a name server; it supersedes the
|
||||
``ndc`` utility. If ``rndc`` is
|
||||
:program:`rndc` controls the operation of a name server. If :program:`rndc` is
|
||||
invoked with no command line options or arguments, it prints a short
|
||||
summary of the supported commands and the available options and their
|
||||
arguments.
|
||||
|
||||
``rndc`` communicates with the name server over a TCP connection,
|
||||
:program:`rndc` communicates with the name server over a TCP connection,
|
||||
sending commands authenticated with digital signatures. In the current
|
||||
versions of ``rndc`` and ``named``, the only supported authentication
|
||||
versions of :program:`rndc` and :iscman:`named`, the only supported authentication
|
||||
algorithms are HMAC-MD5 (for compatibility), HMAC-SHA1, HMAC-SHA224,
|
||||
HMAC-SHA256 (default), HMAC-SHA384, and HMAC-SHA512. They use a shared
|
||||
secret on each end of the connection, which provides TSIG-style
|
||||
@@ -40,60 +41,71 @@ authentication for the command request and the name server's response.
|
||||
All commands sent over the channel must be signed by a key_id known to
|
||||
the server.
|
||||
|
||||
``rndc`` reads a configuration file to determine how to contact the name
|
||||
:program:`rndc` reads a configuration file to determine how to contact the name
|
||||
server and decide what algorithm and key it should use.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option indicates use of IPv4 only.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option indicates use of IPv6 only.
|
||||
|
||||
``-b source-address``
|
||||
.. option:: -b source-address
|
||||
|
||||
This option indicates ``source-address`` as the source address for the connection to the
|
||||
server. Multiple instances are permitted, to allow setting of both the
|
||||
IPv4 and IPv6 source addresses.
|
||||
|
||||
``-c config-file``
|
||||
.. option:: -c config-file
|
||||
|
||||
This option indicates ``config-file`` as the configuration file instead of the default,
|
||||
``/etc/rndc.conf``.
|
||||
|rndc_conf|.
|
||||
|
||||
.. option:: -k key-file
|
||||
|
||||
``-k key-file``
|
||||
This option indicates ``key-file`` as the key file instead of the default,
|
||||
``/etc/rndc.key``. The key in ``/etc/rndc.key`` is used to
|
||||
|rndc_key|. The key in |rndc_key| is used to
|
||||
authenticate commands sent to the server if the config-file does not
|
||||
exist.
|
||||
|
||||
``-s server``
|
||||
.. option:: -s server
|
||||
|
||||
``server`` is the name or address of the server which matches a server
|
||||
statement in the configuration file for ``rndc``. If no server is
|
||||
statement in the configuration file for :program:`rndc`. If no server is
|
||||
supplied on the command line, the host named by the default-server
|
||||
clause in the options statement of the ``rndc`` configuration file
|
||||
clause in the options statement of the :program:`rndc` configuration file
|
||||
is used.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option instructs BIND 9 to send commands to TCP port ``port`` instead of its default control
|
||||
channel port, 953.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, where message text returned by the server is not printed
|
||||
unless there is an error.
|
||||
|
||||
``-r``
|
||||
This option instructs ``rndc`` to print the result code returned by ``named``
|
||||
.. option:: -r
|
||||
|
||||
This option instructs :program:`rndc` to print the result code returned by :iscman:`named`
|
||||
after executing the requested command (e.g., ISC_R_SUCCESS,
|
||||
ISC_R_FAILURE, etc.).
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option enables verbose logging.
|
||||
|
||||
``-y key_id``
|
||||
.. option:: -y key_id
|
||||
|
||||
This option indicates use of the key ``key_id`` from the configuration file. For control message validation to succeed, ``key_id`` must be known
|
||||
by ``named`` with the same algorithm and secret string. If no ``key_id`` is specified,
|
||||
``rndc`` first looks for a key clause in the server statement of
|
||||
by :iscman:`named` with the same algorithm and secret string. If no ``key_id`` is specified,
|
||||
:program:`rndc` first looks for a key clause in the server statement of
|
||||
the server being used, or if no server statement is present for that
|
||||
host, then in the default-key clause of the options statement. Note that
|
||||
the configuration file contains shared secrets which are used to send
|
||||
@@ -103,23 +115,24 @@ Options
|
||||
Commands
|
||||
~~~~~~~~
|
||||
|
||||
A list of commands supported by ``rndc`` can be seen by running ``rndc``
|
||||
A list of commands supported by :program:`rndc` can be seen by running :program:`rndc`
|
||||
without arguments.
|
||||
|
||||
Currently supported commands are:
|
||||
|
||||
``addzone`` *zone* [*class* [*view*]] *configuration*
|
||||
.. option:: addzone zone [class [view]] configuration
|
||||
|
||||
This command adds a zone while the server is running. This command requires the
|
||||
``allow-new-zones`` option to be set to ``yes``. The configuration
|
||||
string specified on the command line is the zone configuration text
|
||||
that would ordinarily be placed in ``named.conf``.
|
||||
that would ordinarily be placed in :iscman:`named.conf`.
|
||||
|
||||
The configuration is saved in a file called ``viewname.nzf`` (or, if
|
||||
``named`` is compiled with liblmdb, an LMDB database file called
|
||||
:iscman:`named` is compiled with liblmdb, an LMDB database file called
|
||||
``viewname.nzd``). ``viewname`` is the name of the view, unless the view
|
||||
name contains characters that are incompatible with use as a file
|
||||
name, in which case a cryptographic hash of the view name is used
|
||||
instead. When ``named`` is restarted, the file is loaded into
|
||||
instead. When :iscman:`named` is restarted, the file is loaded into
|
||||
the view configuration so that zones that were added can persist
|
||||
after a restart.
|
||||
|
||||
@@ -131,9 +144,10 @@ Currently supported commands are:
|
||||
(Note the brackets around and semi-colon after the zone configuration
|
||||
text.)
|
||||
|
||||
See also ``rndc delzone`` and ``rndc modzone``.
|
||||
See also :option:`rndc delzone` and :option:`rndc modzone`.
|
||||
|
||||
.. option:: delzone [-clean] zone [class [view]]
|
||||
|
||||
``delzone`` [**-clean**] *zone* [*class* [*view*]]
|
||||
This command deletes a zone while the server is running.
|
||||
|
||||
If the ``-clean`` argument is specified, the zone's master file (and
|
||||
@@ -144,14 +158,15 @@ Currently supported commands are:
|
||||
|
||||
If the zone was originally added via ``rndc addzone``, then it is
|
||||
removed permanently. However, if it was originally configured in
|
||||
``named.conf``, then that original configuration remains in place;
|
||||
:iscman:`named.conf`, then that original configuration remains in place;
|
||||
when the server is restarted or reconfigured, the zone is
|
||||
recreated. To remove it permanently, it must also be removed from
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
See also ``rndc addzone`` and ``rndc modzone``.
|
||||
See also :option:`rndc addzone` and :option:`rndc modzone`.
|
||||
|
||||
.. option:: dnssec (-status | -rollover -key id [-alg algorithm] [-when time] | -checkds [-key id [-alg algorithm]] [-when time] published | withdraw)) zone [class [view]]
|
||||
|
||||
``dnssec`` ( **-status** | **-rollover** **-key** id [**-alg** *algorithm*] [**-when** *time*] | **-checkds** [**-key** *id* [**-alg** *algorithm*]] [**-when** *time*] ( *published* | *withdrawn* )) *zone* [*class* [*view*]]
|
||||
This command allows you to interact with the "dnssec-policy" of a given
|
||||
zone.
|
||||
|
||||
@@ -161,7 +176,7 @@ Currently supported commands are:
|
||||
``rndc dnssec -rollover`` allows you to schedule key rollover for a
|
||||
specific key (overriding the original key lifetime).
|
||||
|
||||
``rndc dnssec -checkds`` will let ``named`` know that the DS for the given
|
||||
``rndc dnssec -checkds`` will let :iscman:`named` know that the DS for the given
|
||||
key has been seen published into or withdrawn from the parent. This is
|
||||
required in order to complete a KSK rollover. If the ``-key id`` argument
|
||||
is specified, look for the key with the given identifier, otherwise if there
|
||||
@@ -170,56 +185,64 @@ Currently supported commands are:
|
||||
select the correct algorithm). The time that the DS has been published or
|
||||
withdrawn is set to now, unless otherwise specified with the argument ``-when time``.
|
||||
|
||||
``dnstap`` ( **-reopen** | **-roll** [*number*] )
|
||||
.. option:: dnstap (-reopen | -roll [number])
|
||||
|
||||
This command closes and re-opens DNSTAP output files. ``rndc dnstap -reopen`` allows
|
||||
the output file to be renamed externally, so that ``named`` can
|
||||
the output file to be renamed externally, so that :iscman:`named` can
|
||||
truncate and re-open it. ``rndc dnstap -roll`` causes the output file
|
||||
to be rolled automatically, similar to log files. The most recent
|
||||
output file has ".0" appended to its name; the previous most recent
|
||||
output file is moved to ".1", and so on. If ``number`` is specified, then
|
||||
the number of backup log files is limited to that number.
|
||||
|
||||
``dumpdb`` [**-all** | **-cache** | **-zones** | **-adb** | **-bad** | **-expired** | **-fail**] [*view ...*]
|
||||
.. option:: dumpdb [-all | -cache | -zones | -adb | -bad | -expired | -fail] [view ...]
|
||||
|
||||
This command dumps the server's caches (default) and/or zones to the dump file for
|
||||
the specified views. If no view is specified, all views are dumped.
|
||||
(See the ``dump-file`` option in the BIND 9 Administrator Reference
|
||||
Manual.)
|
||||
|
||||
``flush``
|
||||
.. option:: flush
|
||||
|
||||
This command flushes the server's cache.
|
||||
|
||||
``flushname`` *name* [*view*]
|
||||
.. option:: flushname name [view]
|
||||
|
||||
This command flushes the given name from the view's DNS cache and, if applicable,
|
||||
from the view's nameserver address database, bad server cache, and
|
||||
SERVFAIL cache.
|
||||
|
||||
``flushtree`` *name* [*view*]
|
||||
.. option:: flushtree name [view]
|
||||
|
||||
This command flushes the given name, and all of its subdomains, from the view's
|
||||
DNS cache, address database, bad server cache, and SERVFAIL cache.
|
||||
|
||||
``freeze`` [*zone* [*class* [*view*]]]
|
||||
.. option:: freeze [zone [class [view]]]
|
||||
|
||||
This command suspends updates to a dynamic zone. If no zone is specified, then all
|
||||
zones are suspended. This allows manual edits to be made to a zone
|
||||
normally updated by dynamic update, and causes changes in the
|
||||
journal file to be synced into the master file. All dynamic update
|
||||
attempts are refused while the zone is frozen.
|
||||
|
||||
See also ``rndc thaw``.
|
||||
See also :option:`rndc thaw`.
|
||||
|
||||
.. option:: halt [-p]
|
||||
|
||||
``halt`` [**-p**]
|
||||
This command stops the server immediately. Recent changes made through dynamic
|
||||
update or IXFR are not saved to the master files, but are rolled
|
||||
forward from the journal files when the server is restarted. If
|
||||
``-p`` is specified, ``named``'s process ID is returned. This allows
|
||||
an external process to determine when ``named`` has completed
|
||||
``-p`` is specified, :iscman:`named`'s process ID is returned. This allows
|
||||
an external process to determine when :iscman:`named` has completed
|
||||
halting.
|
||||
|
||||
See also ``rndc stop``.
|
||||
See also :option:`rndc stop`.
|
||||
|
||||
.. option:: loadkeys [zone [class [view]]]
|
||||
|
||||
``loadkeys`` [*zone* [*class* [*view*]]]
|
||||
This command fetches all DNSSEC keys for the given zone from the key directory. If
|
||||
they are within their publication period, they are merged into the
|
||||
zone's DNSKEY RRset. Unlike ``rndc sign``, however, the zone is not
|
||||
zone's DNSKEY RRset. Unlike :option:`rndc sign`, however, the zone is not
|
||||
immediately re-signed by the new keys, but is allowed to
|
||||
incrementally re-sign over time.
|
||||
|
||||
@@ -228,7 +251,8 @@ Currently supported commands are:
|
||||
zone to be configured to allow dynamic DNS. (See "Dynamic Update Policies" in
|
||||
the Administrator Reference Manual for more details.)
|
||||
|
||||
``managed-keys`` (*status* | *refresh* | *sync* | *destroy*) [*class* [*view*]]
|
||||
.. option:: managed-keys (status | refresh | sync | destroy) [class [view]]
|
||||
|
||||
This command inspects and controls the "managed-keys" database which handles
|
||||
:rfc:`5011` DNSSEC trust anchor maintenance. If a view is specified, these
|
||||
commands are applied to that view; otherwise, they are applied to all
|
||||
@@ -254,11 +278,11 @@ Currently supported commands are:
|
||||
|
||||
Existing keys that are already trusted are not deleted from
|
||||
memory; DNSSEC validation can continue after this command is used.
|
||||
However, key maintenance operations cease until ``named`` is
|
||||
However, key maintenance operations cease until :iscman:`named` is
|
||||
restarted or reconfigured, and all existing key maintenance states
|
||||
are deleted.
|
||||
|
||||
Running ``rndc reconfig`` or restarting ``named`` immediately
|
||||
Running :option:`rndc reconfig` or restarting :iscman:`named` immediately
|
||||
after this command causes key maintenance to be reinitialized
|
||||
from scratch, just as if the server were being started for the
|
||||
first time. This is primarily intended for testing, but it may
|
||||
@@ -266,47 +290,51 @@ Currently supported commands are:
|
||||
keys in the event of a trust anchor rollover, or as a brute-force
|
||||
repair for key maintenance problems.
|
||||
|
||||
``modzone`` *zone* [*class* [*view*]] *configuration*
|
||||
.. option:: modzone zone [class [view]] configuration
|
||||
|
||||
This command modifies the configuration of a zone while the server is running. This
|
||||
command requires the ``allow-new-zones`` option to be set to ``yes``.
|
||||
As with ``addzone``, the configuration string specified on the
|
||||
command line is the zone configuration text that would ordinarily be
|
||||
placed in ``named.conf``.
|
||||
placed in :iscman:`named.conf`.
|
||||
|
||||
If the zone was originally added via ``rndc addzone``, the
|
||||
If the zone was originally added via :option:`rndc addzone`, the
|
||||
configuration changes are recorded permanently and are still
|
||||
in effect after the server is restarted or reconfigured. However, if
|
||||
it was originally configured in ``named.conf``, then that original
|
||||
it was originally configured in :iscman:`named.conf`, then that original
|
||||
configuration remains in place; when the server is restarted or
|
||||
reconfigured, the zone reverts to its original configuration. To
|
||||
make the changes permanent, it must also be modified in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
See also ``rndc addzone`` and ``rndc delzone``.
|
||||
See also :option:`rndc addzone` and :option:`rndc delzone`.
|
||||
|
||||
.. option:: notify zone [class [view]]
|
||||
|
||||
``notify`` *zone* [*class* [*view*]]
|
||||
This command resends NOTIFY messages for the zone.
|
||||
|
||||
``notrace``
|
||||
.. option:: notrace
|
||||
|
||||
This command sets the server's debugging level to 0.
|
||||
|
||||
See also ``rndc trace``.
|
||||
See also :option:`rndc trace`.
|
||||
|
||||
.. option:: nta [(-class class | -dump | -force | -remove | -lifetime duration)] domain [view]
|
||||
|
||||
``nta`` [( **-class** *class* | **-dump** | **-force** | **-remove** | **-lifetime** *duration*)] *domain* [*view*]
|
||||
This command sets a DNSSEC negative trust anchor (NTA) for ``domain``, with a
|
||||
lifetime of ``duration``. The default lifetime is configured in
|
||||
``named.conf`` via the ``nta-lifetime`` option, and defaults to one
|
||||
:iscman:`named.conf` via the ``nta-lifetime`` option, and defaults to one
|
||||
hour. The lifetime cannot exceed one week.
|
||||
|
||||
A negative trust anchor selectively disables DNSSEC validation for
|
||||
zones that are known to be failing because of misconfiguration rather
|
||||
than an attack. When data to be validated is at or below an active
|
||||
NTA (and above any other configured trust anchors), ``named``
|
||||
NTA (and above any other configured trust anchors), :iscman:`named`
|
||||
aborts the DNSSEC validation process and treats the data as insecure
|
||||
rather than bogus. This continues until the NTA's lifetime has
|
||||
elapsed.
|
||||
|
||||
NTAs persist across restarts of the ``named`` server. The NTAs for a
|
||||
NTAs persist across restarts of the :iscman:`named` server. The NTAs for a
|
||||
view are saved in a file called ``name.nta``, where ``name`` is the name
|
||||
of the view; if it contains characters that are incompatible with
|
||||
use as a file name, a cryptographic hash is generated from the name of
|
||||
@@ -324,7 +352,7 @@ Currently supported commands are:
|
||||
of existing NTAs is printed. Note that this may include NTAs that are
|
||||
expired but have not yet been cleaned up.
|
||||
|
||||
Normally, ``named`` periodically tests to see whether data below
|
||||
Normally, :iscman:`named` periodically tests to see whether data below
|
||||
an NTA can now be validated (see the ``nta-recheck`` option in the
|
||||
Administrator Reference Manual for details). If data can be
|
||||
validated, then the NTA is regarded as no longer necessary and is
|
||||
@@ -343,24 +371,27 @@ Currently supported commands are:
|
||||
view name that begins with a hyphen, use a double-hyphen (--) on the
|
||||
command line to indicate the end of options.
|
||||
|
||||
``querylog`` [(*on* | *off*)]
|
||||
.. option:: querylog [(on | off)]
|
||||
|
||||
This command enables or disables query logging. For backward compatibility, this
|
||||
command can also be used without an argument to toggle query logging
|
||||
on and off.
|
||||
|
||||
Query logging can also be enabled by explicitly directing the
|
||||
``queries`` ``category`` to a ``channel`` in the ``logging`` section
|
||||
of ``named.conf``, or by specifying ``querylog yes;`` in the
|
||||
``options`` section of ``named.conf``.
|
||||
of :iscman:`named.conf`, or by specifying ``querylog yes;`` in the
|
||||
``options`` section of :iscman:`named.conf`.
|
||||
|
||||
.. option:: reconfig
|
||||
|
||||
``reconfig``
|
||||
This command reloads the configuration file and loads new zones, but does not reload
|
||||
existing zone files even if they have changed. This is faster than a
|
||||
full ``reload`` when there is a large number of zones, because it
|
||||
full :option:`rndc reload` when there is a large number of zones, because it
|
||||
avoids the need to examine the modification times of the zone files.
|
||||
|
||||
``recursing``
|
||||
This command dumps the list of queries ``named`` is currently
|
||||
.. option:: recursing
|
||||
|
||||
This command dumps the list of queries :iscman:`named` is currently
|
||||
recursing on, and the list of domains to which iterative queries
|
||||
are currently being sent.
|
||||
|
||||
@@ -379,16 +410,20 @@ Currently supported commands are:
|
||||
and the next time a fetch is sent to that domain, it is recreated
|
||||
with the counters set to zero).
|
||||
|
||||
``refresh`` *zone* [*class* [*view*]]
|
||||
.. option:: refresh zone [class [view]]
|
||||
|
||||
This command schedules zone maintenance for the given zone.
|
||||
|
||||
``reload``
|
||||
.. option:: reload
|
||||
|
||||
This command reloads the configuration file and zones.
|
||||
|
||||
``reload`` *zone* [*class* [*view*]]
|
||||
.. option:: reload zone [class [view]]
|
||||
|
||||
This command reloads the given zone.
|
||||
|
||||
``retransfer`` *zone* [*class* [*view*]]
|
||||
.. option:: retransfer zone [class [view]]
|
||||
|
||||
This command retransfers the given secondary zone from the primary server.
|
||||
|
||||
If the zone is configured to use ``inline-signing``, the signed
|
||||
@@ -396,12 +431,14 @@ Currently supported commands are:
|
||||
unsigned version is complete, the signed version is regenerated
|
||||
with new signatures.
|
||||
|
||||
``scan``
|
||||
.. option:: scan
|
||||
|
||||
This command scans the list of available network interfaces for changes, without
|
||||
performing a full ``reconfig`` or waiting for the
|
||||
performing a full :option:`rndc reconfig` or waiting for the
|
||||
``interface-interval`` timer.
|
||||
|
||||
``secroots`` [**-**] [*view* ...]
|
||||
.. option:: secroots [-] [view ...]
|
||||
|
||||
This command dumps the security roots (i.e., trust anchors configured via
|
||||
``trust-anchors``, or the ``managed-keys`` or ``trusted-keys`` statements
|
||||
[both deprecated], or ``dnssec-validation auto``) and negative trust anchors
|
||||
@@ -411,31 +448,34 @@ Currently supported commands are:
|
||||
yet been updated by a successful key refresh query).
|
||||
|
||||
If the first argument is ``-``, then the output is returned via the
|
||||
``rndc`` response channel and printed to the standard output.
|
||||
:program:`rndc` response channel and printed to the standard output.
|
||||
Otherwise, it is written to the secroots dump file, which defaults to
|
||||
``named.secroots``, but can be overridden via the ``secroots-file``
|
||||
option in ``named.conf``.
|
||||
option in :iscman:`named.conf`.
|
||||
|
||||
See also ``rndc managed-keys``.
|
||||
See also :option:`rndc managed-keys`.
|
||||
|
||||
.. option:: serve-stale (on | off | reset | status) [class [view]]
|
||||
|
||||
``serve-stale`` (**on** | **off** | **reset** | **status**) [*class* [*view*]]
|
||||
This command enables, disables, resets, or reports the current status of
|
||||
the serving of stale answers as configured in ``named.conf``.
|
||||
the serving of stale answers as configured in :iscman:`named.conf`.
|
||||
|
||||
If serving of stale answers is disabled by ``rndc-serve-stale off``, then it
|
||||
remains disabled even if ``named`` is reloaded or reconfigured. ``rndc
|
||||
serve-stale reset`` restores the setting as configured in ``named.conf``.
|
||||
remains disabled even if :iscman:`named` is reloaded or reconfigured. ``rndc
|
||||
serve-stale reset`` restores the setting as configured in :iscman:`named.conf`.
|
||||
|
||||
``rndc serve-stale status`` reports whether caching and serving of stale
|
||||
answers is currently enabled or disabled. It also reports the values of
|
||||
``stale-answer-ttl`` and ``max-stale-ttl``.
|
||||
|
||||
``showzone`` *zone* [*class* [*view*]]
|
||||
.. option:: showzone zone [class [view]]
|
||||
|
||||
This command prints the configuration of a running zone.
|
||||
|
||||
See also ``rndc zonestatus``.
|
||||
See also :option:`rndc zonestatus`.
|
||||
|
||||
.. option:: sign zone [class [view]]
|
||||
|
||||
``sign`` *zone* [*class* [*view*]]
|
||||
This command fetches all DNSSEC keys for the given zone from the key directory (see
|
||||
the ``key-directory`` option in the BIND 9 Administrator Reference
|
||||
Manual). If they are within their publication period, they are merged into
|
||||
@@ -448,9 +488,10 @@ Currently supported commands are:
|
||||
"Dynamic Update Policies" in the BIND 9 Administrator Reference Manual for more
|
||||
details.)
|
||||
|
||||
See also ``rndc loadkeys``.
|
||||
See also :option:`rndc loadkeys`.
|
||||
|
||||
.. option:: signing [(-list | -clear keyid/algorithm | -clear all | -nsec3param (parameters | none) | -serial value) zone [class [view]]
|
||||
|
||||
``signing`` [(**-list** | **-clear** *keyid/algorithm* | **-clear** *all* | **-nsec3param** ( *parameters* | none ) | **-serial** *value* ) *zone* [*class* [*view*]]
|
||||
This command lists, edits, or removes the DNSSEC signing-state records for the
|
||||
specified zone. The status of ongoing DNSSEC operations, such as
|
||||
signing or generating NSEC3 chains, is stored in the zone in the form
|
||||
@@ -478,7 +519,7 @@ Currently supported commands are:
|
||||
chain should be set. ``iterations`` defines the number of additional times to apply
|
||||
the algorithm when generating an NSEC3 hash. The ``salt`` is a string
|
||||
of data expressed in hexadecimal, a hyphen (`-') if no salt is to be
|
||||
used, or the keyword ``auto``, which causes ``named`` to generate a
|
||||
used, or the keyword ``auto``, which causes :iscman:`named` to generate a
|
||||
random 64-bit salt.
|
||||
|
||||
So, for example, to create an NSEC3 chain using the SHA-1 hash
|
||||
@@ -495,31 +536,36 @@ Currently supported commands are:
|
||||
is rejected. The primary use of this parameter is to set the serial number on inline
|
||||
signed zones.
|
||||
|
||||
``stats``
|
||||
.. option:: stats
|
||||
|
||||
This command writes server statistics to the statistics file. (See the
|
||||
``statistics-file`` option in the BIND 9 Administrator Reference
|
||||
Manual.)
|
||||
|
||||
``status``
|
||||
.. option:: status
|
||||
|
||||
This command displays the status of the server. Note that the number of zones includes
|
||||
the internal ``bind/CH`` zone and the default ``./IN`` hint zone, if
|
||||
there is no explicit root zone configured.
|
||||
|
||||
``stop`` **-p**
|
||||
.. option:: stop -p
|
||||
|
||||
This command stops the server, making sure any recent changes made through dynamic
|
||||
update or IXFR are first saved to the master files of the updated
|
||||
zones. If ``-p`` is specified, ``named(8)`'s process ID is returned.
|
||||
This allows an external process to determine when ``named`` has
|
||||
zones. If ``-p`` is specified, :iscman:`named`'s process ID is returned.
|
||||
This allows an external process to determine when :iscman:`named` has
|
||||
completed stopping.
|
||||
|
||||
See also ``rndc halt``.
|
||||
See also :option:`rndc halt`.
|
||||
|
||||
.. option:: sync -clean [zone [class [view]]]
|
||||
|
||||
``sync`` **-clean** [*zone* [*class* [*view*]]]
|
||||
This command syncs changes in the journal file for a dynamic zone to the master
|
||||
file. If the "-clean" option is specified, the journal file is also
|
||||
removed. If no zone is specified, then all zones are synced.
|
||||
|
||||
``tcp-timeouts`` [*initial* *idle* *keepalive* *advertised*]
|
||||
.. option:: tcp-timeouts [initial idle keepalive advertised]
|
||||
|
||||
When called without arguments, this command displays the current values of the
|
||||
``tcp-initial-timeout``, ``tcp-idle-timeout``,
|
||||
``tcp-keepalive-timeout``, and ``tcp-advertised-timeout`` options.
|
||||
@@ -528,7 +574,8 @@ Currently supported commands are:
|
||||
denial-of-service (DoS) attack. See the descriptions of these options in the BIND 9
|
||||
Administrator Reference Manual for details of their use.
|
||||
|
||||
``thaw`` [*zone* [*class* [*view*]]]
|
||||
.. option:: thaw [zone [class [view]]]
|
||||
|
||||
This command enables updates to a frozen dynamic zone. If no zone is specified,
|
||||
then all frozen zones are enabled. This causes the server to reload
|
||||
the zone from disk, and re-enables dynamic updates after the load has
|
||||
@@ -538,33 +585,39 @@ Currently supported commands are:
|
||||
changes in the zone. Otherwise, if the zone has changed, any existing
|
||||
journal file is removed.
|
||||
|
||||
See also ``rndc freeze``.
|
||||
See also :option:`rndc freeze`.
|
||||
|
||||
.. option:: trace
|
||||
|
||||
``trace``
|
||||
This command increments the server's debugging level by one.
|
||||
|
||||
``trace`` *level*
|
||||
.. option:: trace level
|
||||
|
||||
This command sets the server's debugging level to an explicit value.
|
||||
|
||||
See also ``rndc notrace``.
|
||||
See also :option:`rndc notrace`.
|
||||
|
||||
.. option:: tsig-delete keyname [view]
|
||||
|
||||
``tsig-delete`` *keyname* [*view*]
|
||||
This command deletes a given TKEY-negotiated key from the server. This does not
|
||||
apply to statically configured TSIG keys.
|
||||
|
||||
``tsig-list``
|
||||
.. option:: tsig-list
|
||||
|
||||
This command lists the names of all TSIG keys currently configured for use by
|
||||
``named`` in each view. The list includes both statically configured keys and
|
||||
:iscman:`named` in each view. The list includes both statically configured keys and
|
||||
dynamic TKEY-negotiated keys.
|
||||
|
||||
``validation`` (**on** | **off** | **status**) [*view* ...]``
|
||||
.. option:: validation (on | off | status) [view ...]
|
||||
|
||||
This command enables, disables, or checks the current status of DNSSEC validation. By
|
||||
default, validation is enabled.
|
||||
|
||||
The cache is flushed when validation is turned on or off to avoid using data
|
||||
that might differ between states.
|
||||
|
||||
``zonestatus`` *zone* [*class* [*view*]]
|
||||
.. option:: zonestatus zone [class [view]]
|
||||
|
||||
This command displays the current status of the given zone, including the master
|
||||
file name and any include files from which it was loaded, when it was
|
||||
most recently loaded, the current serial number, the number of nodes,
|
||||
@@ -572,10 +625,10 @@ Currently supported commands are:
|
||||
signed, whether it uses automatic DNSSEC key management or inline
|
||||
signing, and the scheduled refresh or expiry times for the zone.
|
||||
|
||||
See also ``rndc showzone``.
|
||||
See also :option:`rndc showzone`.
|
||||
|
||||
``rndc`` commands that specify zone names, such as ``reload``,
|
||||
``retransfer``, or ``zonestatus``, can be ambiguous when applied to zones
|
||||
:program:`rndc` commands that specify zone names, such as :option:`reload`
|
||||
:option:`retransfer`, or :option:`zonestatus`, can be ambiguous when applied to zones
|
||||
of type ``redirect``. Redirect zones are always called ``.``, and can be
|
||||
confused with zones of type ``hint`` or with secondary copies of the root
|
||||
zone. To specify a redirect zone, use the special zone name
|
||||
@@ -593,6 +646,6 @@ Several error messages could be clearer.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc.conf(5)`, :manpage:`rndc-confgen(8)`,
|
||||
:manpage:`named(8)`, :manpage:`named.conf(5)`, :manpage:`ndc(8)`, BIND 9 Administrator
|
||||
:iscman:`rndc.conf(5) <rndc.conf>`, :iscman:`rndc-confgen(8) <rndc-confgen>`,
|
||||
:iscman:`named(8) <named>`, :iscman:`named.conf(5) <named.conf>`, BIND 9 Administrator
|
||||
Reference Manual.
|
||||
|
||||
+1
-1
@@ -36,7 +36,7 @@ ISC_LANG_BEGINDECLS
|
||||
void
|
||||
notify(const char *fmt, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_NORETURN void
|
||||
noreturn void
|
||||
fatal(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
|
||||
ISC_LANG_ENDDECLS
|
||||
|
||||
@@ -7,6 +7,9 @@ noinst_PROGRAMS = \
|
||||
test_server \
|
||||
wire_test
|
||||
|
||||
AM_CFLAGS += \
|
||||
$(TEST_CFLAGS)
|
||||
|
||||
test_client_CPPFLAGS = \
|
||||
$(AM_CPPFLAGS) \
|
||||
$(LIBISC_CFLAGS)
|
||||
@@ -31,5 +34,3 @@ wire_test_CPPFLAGS = \
|
||||
wire_test_LDADD = \
|
||||
$(LIBISC_LIBS) \
|
||||
$(LIBDNS_LIBS)
|
||||
|
||||
EXTRA_DIST = prepare-softhsm2.sh
|
||||
|
||||
Executable
+150
@@ -0,0 +1,150 @@
|
||||
#!/usr/bin/env python
|
||||
#
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# Convert automake .trs files into JUnit format suitable for Gitlab
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import sys
|
||||
from xml.etree import ElementTree
|
||||
from xml.etree.ElementTree import Element
|
||||
from xml.etree.ElementTree import SubElement
|
||||
|
||||
|
||||
# getting explicit encoding specification right for Python 2/3 would be messy,
|
||||
# so let's hope for the best
|
||||
def read_whole_text(filename):
|
||||
with open(filename) as inf: # pylint: disable-msg=unspecified-encoding
|
||||
return inf.read().strip()
|
||||
|
||||
|
||||
def read_trs_result(filename):
|
||||
result = None
|
||||
with open(filename, "r") as trs: # pylint: disable-msg=unspecified-encoding
|
||||
for line in trs:
|
||||
items = line.split()
|
||||
if len(items) < 2:
|
||||
raise ValueError("unsupported line in trs file", filename, line)
|
||||
if items[0] != (":test-result:"):
|
||||
continue
|
||||
if result is not None:
|
||||
raise NotImplementedError("double :test-result:", filename)
|
||||
result = items[1].upper()
|
||||
|
||||
if result is None:
|
||||
raise ValueError(":test-result: not found", filename)
|
||||
|
||||
return result
|
||||
|
||||
|
||||
def find_test_relative_path(source_dir, in_path):
|
||||
"""Return {in_path}.c if it exists, with fallback to {in_path}"""
|
||||
candidates_relative = [in_path + ".c", in_path]
|
||||
for relative in candidates_relative:
|
||||
absolute = os.path.join(source_dir, relative)
|
||||
if os.path.exists(absolute):
|
||||
return relative
|
||||
raise KeyError
|
||||
|
||||
|
||||
def err_out(exception):
|
||||
raise exception
|
||||
|
||||
|
||||
def walk_trss(source_dir):
|
||||
for cur_dir, _dirs, files in os.walk(source_dir, onerror=err_out):
|
||||
for filename in files:
|
||||
if not filename.endswith(".trs"):
|
||||
continue
|
||||
|
||||
filename_prefix = filename[: -len(".trs")]
|
||||
log_name = filename_prefix + ".log"
|
||||
full_trs_path = os.path.join(cur_dir, filename)
|
||||
full_log_path = os.path.join(cur_dir, log_name)
|
||||
sub_dir = os.path.relpath(cur_dir, source_dir)
|
||||
test_name = os.path.join(sub_dir, filename_prefix)
|
||||
|
||||
t = {
|
||||
"name": test_name,
|
||||
"full_log_path": full_log_path,
|
||||
"rel_log_path": os.path.relpath(full_log_path, source_dir),
|
||||
}
|
||||
t["result"] = read_trs_result(full_trs_path)
|
||||
|
||||
# try to find dir/file path for a clickable link
|
||||
try:
|
||||
t["rel_file_path"] = find_test_relative_path(
|
||||
source_dir, test_name
|
||||
)
|
||||
except KeyError:
|
||||
pass # no existing path found
|
||||
|
||||
yield t
|
||||
|
||||
|
||||
def append_testcase(testsuite, t):
|
||||
# attributes taken from
|
||||
# https://gitlab.com/gitlab-org/gitlab-foss/-/blob/master/lib/gitlab/ci/parsers/test/junit.rb
|
||||
attrs = {"name": t["name"]}
|
||||
if "rel_file_path" in t:
|
||||
attrs["file"] = t["rel_file_path"]
|
||||
|
||||
testcase = SubElement(testsuite, "testcase", attrs)
|
||||
|
||||
# Gitlab accepts only [[ATTACHMENT| links for system-out, not raw text
|
||||
s = SubElement(testcase, "system-out")
|
||||
s.text = "[[ATTACHMENT|" + t["rel_log_path"] + "]]"
|
||||
if t["result"].lower() == "pass":
|
||||
return
|
||||
|
||||
# Gitlab shows output only for failed or skipped tests
|
||||
if t["result"].lower() == "skip":
|
||||
err = SubElement(testcase, "skipped")
|
||||
else:
|
||||
err = SubElement(testcase, "failure")
|
||||
err.text = read_whole_text(t["full_log_path"])
|
||||
|
||||
|
||||
def gen_junit(results):
|
||||
testsuites = Element("testsuites")
|
||||
testsuite = SubElement(testsuites, "testsuite")
|
||||
for test in results:
|
||||
append_testcase(testsuite, test)
|
||||
return testsuites
|
||||
|
||||
|
||||
def check_directory(path):
|
||||
try:
|
||||
os.listdir(path)
|
||||
return path
|
||||
except OSError as ex:
|
||||
msg = "Path {} cannot be listed as a directory: {}".format(path, ex)
|
||||
raise argparse.ArgumentTypeError(msg)
|
||||
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser(
|
||||
description="Recursively search for .trs + .log files and compile "
|
||||
"them into JUnit XML suitable for Gitlab. Paths in the "
|
||||
"XML are relative to the specified top directory."
|
||||
)
|
||||
parser.add_argument(
|
||||
"top_directory",
|
||||
type=check_directory,
|
||||
help="root directory where to start scanning for .trs files",
|
||||
)
|
||||
args = parser.parse_args()
|
||||
junit = gen_junit(walk_trss(args.top_directory))
|
||||
|
||||
# encode results into file format, on Python 3 it produces bytes
|
||||
xml = ElementTree.tostring(junit, "utf-8")
|
||||
# use stdout as a binary file object, Python2/3 compatibility
|
||||
output = getattr(sys.stdout, "buffer", sys.stdout)
|
||||
output.write(xml)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -1,22 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
if [ -n "${SOFTHSM2_CONF}" ] && command -v softhsm2-util >/dev/null; then
|
||||
SOFTHSM2_DIR=$(dirname "$SOFTHSM2_CONF")
|
||||
mkdir -p "${SOFTHSM2_DIR}/tokens"
|
||||
echo "directories.tokendir = ${SOFTHSM2_DIR}/tokens" > "${SOFTHSM2_CONF}"
|
||||
echo "objectstore.backend = file" >> "${SOFTHSM2_CONF}"
|
||||
echo "log.level = DEBUG" >> "${SOFTHSM2_CONF}"
|
||||
softhsm2-util --init-token --free --pin 1234 --so-pin 1234 --label "softhsm2" | awk '/^The token has been initialized and is reassigned to slot/ { print $NF }'
|
||||
fi
|
||||
exit 0
|
||||
@@ -8,11 +8,8 @@ named.lock
|
||||
named.pid
|
||||
named.run
|
||||
/feature-test
|
||||
/test.output.*
|
||||
/makejournal
|
||||
/systests.output
|
||||
/random.data
|
||||
parallel.mk
|
||||
/*.log
|
||||
/*.trs
|
||||
/resolve
|
||||
|
||||
@@ -114,6 +114,7 @@ TESTS += \
|
||||
eddsa \
|
||||
ednscompliance \
|
||||
emptyzones \
|
||||
engine_pkcs11 \
|
||||
filter-aaaa \
|
||||
formerr \
|
||||
geoip2 \
|
||||
@@ -125,6 +126,7 @@ TESTS += \
|
||||
hooks \
|
||||
journal \
|
||||
keepalive \
|
||||
keyfromlabel \
|
||||
legacy \
|
||||
limits \
|
||||
logfileconfig \
|
||||
@@ -183,7 +185,6 @@ if HAVE_PERLMOD_NET_DNS
|
||||
TESTS += \
|
||||
digdelv \
|
||||
fetchlimit \
|
||||
forward \
|
||||
ixfr \
|
||||
nsupdate \
|
||||
resolver \
|
||||
@@ -212,20 +213,18 @@ endif HAVE_PERLMOD_NET_DNS
|
||||
if HAVE_PYTHON
|
||||
TESTS += kasp keymgr2kasp tcp pipelined
|
||||
|
||||
if HAVE_PYMOD_DNS
|
||||
TESTS += checkds dispatch qmin cookie timeouts
|
||||
if HAVE_PYTEST
|
||||
TESTS += checkds dispatch rpzextra shutdown timeouts
|
||||
endif
|
||||
|
||||
if HAVE_PYMOD_DNS
|
||||
TESTS += qmin cookie
|
||||
if HAVE_PERLMOD_NET_DNS
|
||||
TESTS += dnssec
|
||||
TESTS += dnssec forward
|
||||
if HAVE_PERLMOD_NET_DNS_NAMESERVER
|
||||
TESTS += chain
|
||||
endif HAVE_PERLMOD_NET_DNS_NAMESERVER
|
||||
endif HAVE_PERLMOD_NET_DNS
|
||||
|
||||
if HAVE_PYTEST
|
||||
TESTS += rpzextra shutdown
|
||||
endif
|
||||
|
||||
endif HAVE_PYMOD_DNS
|
||||
|
||||
endif HAVE_PYTHON
|
||||
|
||||
+11
-77
@@ -117,13 +117,7 @@ Running All The System Tests
|
||||
---
|
||||
To run all the system tests, enter the command:
|
||||
|
||||
sh runall.sh [-c] [-n] [numproc]
|
||||
|
||||
The optional flag "-c" forces colored output (by default system test output is
|
||||
not printed in color due to run.sh being piped through "tee").
|
||||
|
||||
The optional flag "-n" has the same effect as it does for "run.sh" - it causes
|
||||
the retention of all output files from all tests.
|
||||
make [-j numproc] test
|
||||
|
||||
The optional "numproc" argument specifies the maximum number of tests that can
|
||||
run in parallel. The default is 1, which means that all of the tests run
|
||||
@@ -132,16 +126,7 @@ new tests being started as tests finish. Each test will get a unique set of
|
||||
ports, so there is no danger of tests interfering with one another. Parallel
|
||||
running will reduce the total time taken to run the BIND system tests, but will
|
||||
mean that the output from all the tests sent to the screen will be mixed up
|
||||
with one another. However, the systests.output file produced at the end of the
|
||||
run (in the bin/tests/system directory) will contain the output from each test
|
||||
in sequential order.
|
||||
|
||||
Note that it is not possible to pass arguments to tests though the "runall.sh"
|
||||
script.
|
||||
|
||||
A run of all the system tests can also be initiated via make:
|
||||
|
||||
make [-j numproc] test
|
||||
with one another.
|
||||
|
||||
In this case, retention of the output files after a test completes successfully
|
||||
is specified by setting the environment variable SYSTEMTEST_NO_CLEAN to 1 prior
|
||||
@@ -153,38 +138,6 @@ while setting environment variable SYSTEMTEST_FORCE_COLOR to 1 forces system
|
||||
test output to be printed in color.
|
||||
|
||||
|
||||
Running Multiple System Test Suites Simultaneously
|
||||
---
|
||||
In some cases it may be desirable to have multiple instances of the system test
|
||||
suite running simultaneously (e.g. from different terminal windows). To do
|
||||
this:
|
||||
|
||||
1. Each installation must have its own directory tree. The system tests create
|
||||
files in the test directories, so separate directory trees are required to
|
||||
avoid interference between the same test running in the different
|
||||
installations.
|
||||
|
||||
2. For one of the test suites, the starting port number must be specified by
|
||||
setting the environment variable STARTPORT before starting the test suite.
|
||||
Each test suite comprises about 100 tests, each being allocated a set of 100
|
||||
ports. The port ranges for each test are allocated sequentially, so each test
|
||||
suite requires about 10,000 ports to itself. By default, the port allocation
|
||||
starts at 5,000. So the following set of commands:
|
||||
|
||||
Terminal Window 1:
|
||||
cd <installation-1>/bin/tests/system
|
||||
sh runall.sh 4
|
||||
|
||||
Terminal Window 2:
|
||||
cd <installation-2>/bin/tests/system
|
||||
STARTPORT=20000 sh runall.sh 4
|
||||
|
||||
... will start the test suite for installation-1 using the default base port
|
||||
of 5,000, so the test suite will use ports 5,000 through 15,000 (or there
|
||||
abouts). The use of "STARTPORT=20000" to prefix the run of the test suite for
|
||||
installation-2 will mean the test suite uses ports 20,000 through 30,000 or so.
|
||||
|
||||
|
||||
Format of Test Output
|
||||
---
|
||||
All output from the system tests is in the form of lines with the following
|
||||
@@ -247,8 +200,8 @@ deleted if the test succeeds but are retained on error. The run.sh script
|
||||
automatically calls a given test's clean.sh script before invoking its setup.sh
|
||||
script.
|
||||
|
||||
Deletion of the files produced by the set of tests (e.g. after the execution
|
||||
of "runall.sh") can be carried out using the command:
|
||||
Deletion of the files produced by the set of tests (e.g. after the execution of
|
||||
make) can be carried out using the command:
|
||||
|
||||
sh cleanall.sh
|
||||
|
||||
@@ -337,7 +290,7 @@ port assignments would be:
|
||||
HIGHPORT = 5299
|
||||
|
||||
When running tests in parallel (i.e. giving a value of "numproc" greater than 1
|
||||
in the "make" or "runall.sh" commands listed above), it is guaranteed that each
|
||||
in the "make" command listed above), it is guaranteed that each
|
||||
test will get a set of unique port numbers.
|
||||
|
||||
|
||||
@@ -373,7 +326,7 @@ arguments, e.g.:
|
||||
(cd mytest ; sh clean.sh -D xyz)
|
||||
|
||||
No arguments will be passed to the test scripts if the test is run as part of
|
||||
a run of the full test suite (e.g. the tests are started with "runall.sh").
|
||||
a run of the full test suite (e.g. the tests are started with make).
|
||||
|
||||
3. Each script should start with the following lines:
|
||||
|
||||
@@ -643,13 +596,10 @@ Adding a Test to the System Test Suite
|
||||
---
|
||||
Once a test has been created, the following files should be edited:
|
||||
|
||||
* conf.sh.in The name of the test should be added to the PARALLELDIRS or
|
||||
SEQUENTIALDIRS variables as appropriate. The former is used for tests that
|
||||
can run in parallel with other tests, the latter for tests that are unable to
|
||||
do so.
|
||||
* conf.sh.common The name of the test should be added to the PARALLEL_COMMON
|
||||
variable.
|
||||
|
||||
* Makefile.in The name of the test should be added to one of the the PARALLEL
|
||||
or SEQUENTIAL variables.
|
||||
* Makefile.am The name of the test should be added to the TESTS variable.
|
||||
|
||||
(It is likely that a future iteration of the system test suite will remove the
|
||||
need to edit multiple files to add a test.)
|
||||
@@ -673,20 +623,12 @@ Notes on Parallel Execution
|
||||
Although execution of an individual test is controlled by "run.sh", which
|
||||
executes the above shell scripts (and starts the relevant servers) for each
|
||||
test, the running of all tests in the test suite is controlled by the Makefile.
|
||||
("runall.sh" does little more than invoke "make" on the Makefile.)
|
||||
|
||||
All system tests are capable of being run in parallel. For this to work, each
|
||||
test needs to use a unique set of ports. To avoid the need to define which
|
||||
tests use which ports (and so risk port clashes as further tests are added),
|
||||
the ports are assigned when the tests are run. This is achieved by having the
|
||||
"test" target in the Makefile depend on "parallel.mk". That file is created
|
||||
when "make check" is run, and contains a target for each test of the form:
|
||||
|
||||
<test-name>:
|
||||
@$(SHELL) run.sh -p <baseport> <test-name>
|
||||
|
||||
The <baseport> is unique and the values of <baseport> for each test are
|
||||
separated by at least 100 ports.
|
||||
the ports are determined by "get_ports.sh", a port broker script which keeps
|
||||
track of ports given to each individual system test.
|
||||
|
||||
|
||||
Cleaning Up From Tests
|
||||
@@ -699,10 +641,6 @@ stored in the test directory.
|
||||
2. Files produced by named which may not be cleaned up if named exits
|
||||
abnormally, e.g. core files, PID files etc., are stored in the test directory.
|
||||
|
||||
3. A file "test.output.<test-name>" containing the text written to stdout by the
|
||||
test is written to bin/tests/system/. This file is only produced when the test
|
||||
is run as part of the entire test suite (e.g. via "runall.sh").
|
||||
|
||||
If the test fails, all these files are retained. But if the test succeeds,
|
||||
they are cleaned up at different times:
|
||||
|
||||
@@ -711,7 +649,3 @@ they are cleaned up at different times:
|
||||
|
||||
2. Files that may not be cleaned up if named exits abnormally can be removed
|
||||
using the "cleanall.sh" script.
|
||||
|
||||
3. "test.output.*" files are deleted when the test suite ends. At this point,
|
||||
the file "testsummary.sh" is called which concatenates all the "test.output.*"
|
||||
files into a single "systests.output" file before deleting them.
|
||||
|
||||
@@ -35,6 +35,8 @@ rm -f ns2/private.secure.example.db ns2/bar.db
|
||||
rm -f ns3/*.nzd ns3/*.nzd-lock ns3/*.nzf
|
||||
rm -f ns3/*.nzf
|
||||
rm -f ns3/autonsec3.example.db
|
||||
rm -f ns3/cdnskey-delete.example.db
|
||||
rm -f ns3/cds-delete.example.db
|
||||
rm -f ns3/delzsk.example.db
|
||||
rm -f ns3/dname-at-apex-nsec3.example.db
|
||||
rm -f ns3/inacksk2.example.db
|
||||
|
||||
@@ -19,7 +19,7 @@ infile=root.db.in
|
||||
|
||||
(cd ../ns2 && $SHELL keygen.sh )
|
||||
|
||||
cat $infile ../ns2/dsset-example$TP > $zonefile
|
||||
cat $infile ../ns2/dsset-example. > $zonefile
|
||||
|
||||
zskact=`$KEYGEN -3 -a RSASHA1 -q $zone`
|
||||
zskvanish=`$KEYGEN -3 -a RSASHA1 -q $zone`
|
||||
|
||||
@@ -16,21 +16,22 @@
|
||||
# Have the child generate subdomain keys and pass DS sets to us.
|
||||
( cd ../ns3 && $SHELL keygen.sh )
|
||||
|
||||
for subdomain in secure nsec3 autonsec3 optout rsasha256 rsasha512 nsec3-to-nsec oldsigs sync \
|
||||
dname-at-apex-nsec3
|
||||
for subdomain in secure nsec3 autonsec3 optout rsasha256 rsasha512 \
|
||||
nsec3-to-nsec oldsigs sync dname-at-apex-nsec3 cds-delete \
|
||||
cdnskey-delete
|
||||
do
|
||||
cp ../ns3/dsset-$subdomain.example$TP .
|
||||
cp ../ns3/dsset-$subdomain.example. .
|
||||
done
|
||||
|
||||
# Create keys and pass the DS to the parent.
|
||||
zone=example
|
||||
zonefile="${zone}.db"
|
||||
infile="${zonefile}.in"
|
||||
cat $infile dsset-*.example$TP > $zonefile
|
||||
cat $infile dsset-*.example. > $zonefile
|
||||
|
||||
kskname=`$KEYGEN -a RSASHA1 -3 -q -fk $zone`
|
||||
$KEYGEN -a RSASHA1 -3 -q $zone > /dev/null
|
||||
$DSFROMKEY $kskname.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $kskname.key > dsset-${zone}.
|
||||
|
||||
# Create keys for a private secure zone.
|
||||
zone=private.secure.example
|
||||
@@ -53,4 +54,4 @@ do
|
||||
cp $i `echo $i | sed s/X/K/`
|
||||
done
|
||||
$KEYGEN -a RSASHA1 -q $zone > /dev/null
|
||||
$DSFROMKEY Kbar.+005+30804.key > dsset-bar$TP
|
||||
$DSFROMKEY Kbar.+005+30804.key > dsset-bar.
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; SPDX-License-Identifier: MPL-2.0
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2009102722 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
z A 10.0.0.26
|
||||
a.a.a.a.a.a.a.a.a.a.e A 10.0.0.27
|
||||
x CNAME a
|
||||
@@ -0,0 +1,28 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; SPDX-License-Identifier: MPL-2.0
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2009102722 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns
|
||||
ns A 10.53.0.3
|
||||
|
||||
a A 10.0.0.1
|
||||
b A 10.0.0.2
|
||||
d A 10.0.0.4
|
||||
z A 10.0.0.26
|
||||
a.a.a.a.a.a.a.a.a.a.e A 10.0.0.27
|
||||
x CNAME a
|
||||
@@ -33,7 +33,7 @@ setup secure.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC3/NSEC test zone
|
||||
@@ -42,7 +42,7 @@ setup secure.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC3/NSEC3 test zone
|
||||
@@ -51,7 +51,7 @@ setup nsec3.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Jitter/NSEC3 test zone
|
||||
@@ -75,16 +75,16 @@ setup optout.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A nsec3 zone (non-optout).
|
||||
#
|
||||
setup nsec3.example
|
||||
cat $infile dsset-*.${zone}$TP > $zonefile
|
||||
cat $infile dsset-*.${zone}. > $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# An NSEC3 zone, with NSEC3 parameters set prior to signing
|
||||
@@ -95,7 +95,7 @@ ksk=`$KEYGEN -G -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.ou
|
||||
echo $ksk > ../autoksk.key
|
||||
zsk=`$KEYGEN -G -q -a $DEFAULT_ALGORITHM -3 $zone 2> kg.out` || dumpit kg.out
|
||||
echo $zsk > ../autozsk.key
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/NSEC test zone
|
||||
@@ -104,7 +104,7 @@ setup secure.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/NSEC3 test zone
|
||||
@@ -113,7 +113,7 @@ setup nsec3.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/OPTOUT test zone
|
||||
@@ -122,16 +122,16 @@ setup optout.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A optout nsec3 zone.
|
||||
#
|
||||
setup optout.example
|
||||
cat $infile dsset-*.${zone}$TP > $zonefile
|
||||
cat $infile dsset-*.${zone}. > $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A RSASHA256 zone.
|
||||
@@ -140,7 +140,7 @@ setup rsasha256.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA256 -b 2048 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA256 -b 1024 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A RSASHA512 zone.
|
||||
@@ -149,7 +149,7 @@ setup rsasha512.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA512 -b 2048 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA512 -b 1024 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC-only zone.
|
||||
@@ -158,7 +158,7 @@ setup nsec.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA1 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA1 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Signature refresh test zone. Signatures are set to expire long
|
||||
@@ -301,7 +301,7 @@ setup sync.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk -P sync now $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
echo ns3/$ksk > ../sync.key
|
||||
|
||||
#
|
||||
@@ -311,7 +311,7 @@ setup kskonly.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk -P sync now $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that has a published inactive key that is autosigned.
|
||||
@@ -320,7 +320,7 @@ setup inacksk2.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -Pnow -A now+3600 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that has a published inactive key that is autosigned.
|
||||
@@ -329,27 +329,27 @@ setup inaczsk2.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
#
|
||||
setup inacksk3.example
|
||||
cp $infile $zonefile
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 -fk $zone > kg.out 2>&1 || dumpit kg.out
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
#
|
||||
setup inaczsk3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with an active KSK + ZSK and an inactive ZSK, with the
|
||||
@@ -363,10 +363,29 @@ zsk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -I now-1w $zone 2>kg.out` || dumpit kg.
|
||||
echo $zsk > ../delzsk.key
|
||||
|
||||
#
|
||||
# Check that NSEC3 are correctly signed and returned from below a DNAME
|
||||
# Check that NSEC3 are correctly signed and returned from below a DNAME
|
||||
#
|
||||
setup dname-at-apex-nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Check that dynamically added CDS (DELETE) is kept in the zone after signing.
|
||||
#
|
||||
setup cds-delete.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Check that dynamically added CDNSKEY (DELETE) is kept in the zone after
|
||||
# signing.
|
||||
#
|
||||
setup cdnskey-delete.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
@@ -318,4 +318,18 @@ zone "dname-at-apex-nsec3.example" {
|
||||
auto-dnssec maintain;
|
||||
};
|
||||
|
||||
zone "cds-delete.example" {
|
||||
type primary;
|
||||
file "cds-delete.example.db";
|
||||
allow-update { any; };
|
||||
auto-dnssec maintain;
|
||||
};
|
||||
|
||||
zone "cdnskey-delete.example" {
|
||||
type primary;
|
||||
file "cdnskey-delete.example.db";
|
||||
allow-update { any; };
|
||||
auto-dnssec maintain;
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -1263,7 +1263,7 @@ $SETTIME -K ns3 -A now+3s $ksk > settime.out.test$n.ksk || ret=1
|
||||
($RNDCCMD 10.53.0.3 loadkeys delay.example. 2>&1 | sed 's/^/ns2 /' | cat_i) || ret=1
|
||||
echo_i "waiting for changes to take effect"
|
||||
sleep 3
|
||||
wait_for_log 10 "add delay\.example\..*NSEC.a\.delay\.example\. NS SOA RRSIG NSEC DNSKEY" ns3/named.run
|
||||
wait_for_log_re 10 "add delay\.example\..*NSEC.a\.delay\.example\. NS SOA RRSIG NSEC DNSKEY" ns3/named.run
|
||||
check_is_signed() {
|
||||
$DIG $DIGOPTS +noall +answer dnskey delay.example. @10.53.0.3 > dig.out.ns3.1.test$n || return 1
|
||||
# DNSKEY expected:
|
||||
@@ -1645,6 +1645,89 @@ inac=`grep "DNSKEY .* is now inactive" ns1/named.run | wc -l`
|
||||
[ "$inac" -eq 1 ] || ret=1
|
||||
del=`grep "DNSKEY .* is now deleted" ns1/named.run | wc -l`
|
||||
[ "$del" -eq 1 ] || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "checking that CDS (DELETE) persists after zone sign ($n)"
|
||||
echo_i "update add cds-delete.example. CDS 0 0 00"
|
||||
ret=0
|
||||
$NSUPDATE > nsupdate.out 2>&1 <<END
|
||||
server 10.53.0.3 ${PORT}
|
||||
zone cds-delete.example.
|
||||
update add cds-delete.example. 3600 CDS 0 0 0 00
|
||||
send
|
||||
END
|
||||
|
||||
_cds_delete() (
|
||||
$DIG $DIGOPTS +noall +answer $1 cds @10.53.0.3 > dig.out.ns3.test$n || return 1
|
||||
grep "CDS.*0.*0.*0.*00" dig.out.ns3.test$n > /dev/null 2>&1 || return 1
|
||||
return 0
|
||||
)
|
||||
_cdnskey_delete_nx() {
|
||||
$DIG $DIGOPTS +noall +answer $1 cdnskey @10.53.0.3 > dig.out.ns3.test$n || return 1
|
||||
grep "CDNSKEY.*0.*3.*0.*AA==" dig.out.ns3.test$n > /dev/null 2>&1 && return 1
|
||||
return 0
|
||||
}
|
||||
|
||||
echo_i "query cds-delete.example. CDS"
|
||||
retry_quiet 10 _cds_delete cds-delete.example. || ret=1
|
||||
echo_i "query cds-delete.example. CDNSKEY"
|
||||
retry_quiet 1 _cdnskey_delete_nx cds-delete.example. || ret=1
|
||||
|
||||
echo_i "sign cds-delete.example."
|
||||
nextpart ns3/named.run >/dev/null
|
||||
$RNDCCMD 10.53.0.3 sign cds-delete.example > /dev/null 2>&1 || ret=1
|
||||
wait_for_log 10 "zone cds-delete.example/IN: next key event" ns3/named.run
|
||||
# The CDS (DELETE) record should still be here.
|
||||
echo_i "query cds-delete.example. CDS"
|
||||
retry_quiet 1 _cds_delete cds-delete.example. || ret=1
|
||||
# The CDNSKEY (DELETE) record should still not be added.
|
||||
echo_i "query cds-delete.example. CDNSKEY"
|
||||
retry_quiet 1 _cdnskey_delete_nx cds-delete.example. || ret=1
|
||||
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "checking that CDNSKEY (DELETE) persists after zone sign ($n)"
|
||||
echo_i "update add cdnskey-delete.example. CDNSKEY 0 3 0 AA=="
|
||||
ret=0
|
||||
$NSUPDATE > nsupdate.out 2>&1 <<END
|
||||
server 10.53.0.3 ${PORT}
|
||||
zone cdnskey-delete.example.
|
||||
update add cdnskey-delete.example. 3600 CDNSKEY 0 3 0 AA==
|
||||
send
|
||||
END
|
||||
|
||||
_cds_delete_nx() (
|
||||
$DIG $DIGOPTS +noall +answer $1 cds @10.53.0.3 > dig.out.ns3.test$n || return 1
|
||||
grep "CDS.*0.*0.*0.*00" dig.out.ns3.test$n > /dev/null 2>&1 && return 1
|
||||
return 0
|
||||
)
|
||||
_cdnskey_delete() {
|
||||
$DIG $DIGOPTS +noall +answer $1 cdnskey @10.53.0.3 > dig.out.ns3.test$n || return 1
|
||||
grep "CDNSKEY.*0.*3.*0.*AA==" dig.out.ns3.test$n > /dev/null 2>&1 || return 1
|
||||
return 0
|
||||
}
|
||||
|
||||
echo_i "query cdnskey-delete.example. CDNSKEY"
|
||||
retry_quiet 10 _cdnskey_delete cdnskey-delete.example. || ret=1
|
||||
echo_i "query cdnskey-delete.example. CDS"
|
||||
retry_quiet 1 _cds_delete_nx cdnskey-delete.example. || ret=1
|
||||
|
||||
echo_i "sign cdsnskey-delete.example."
|
||||
nextpart ns3/named.run >/dev/null
|
||||
$RNDCCMD 10.53.0.3 sign cdnskey-delete.example > /dev/null 2>&1 || ret=1
|
||||
wait_for_log 10 "zone cdnskey-delete.example/IN: next key event" ns3/named.run
|
||||
# The CDNSKEY (DELETE) record should still be here.
|
||||
echo_i "query cdnskey-delete.example. CDNSKEY"
|
||||
retry_quiet 1 _cdnskey_delete cdnskey-delete.example. || ret=1
|
||||
# The CDS (DELETE) record should still not be added.
|
||||
echo_i "query cdnskey-delete.example. CDS"
|
||||
retry_quiet 1 _cds_delete_nx cdnskey-delete.example. || ret=1
|
||||
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
|
||||
@@ -10,8 +10,11 @@
|
||||
/ns2/catalog*.example.db
|
||||
|
||||
/ns1/*dom*.example.db
|
||||
/ns3/dom2.example.db
|
||||
/ns3/dom13.example.db
|
||||
/ns3/dom14.example.db
|
||||
/ns3/dom17.example.db
|
||||
/ns3/dom18.example.db
|
||||
|
||||
/ns2/zonedir
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@ rm -f ns*/named.run.prev
|
||||
rm -f ns1/*dom*example.db
|
||||
rm -f ns2/__catz__*db
|
||||
rm -f ns2/named.conf.tmp
|
||||
rm -f ns3/dom13.example.db ns3/dom14.example.db
|
||||
rm -f ns3/dom2.example.db ns3/dom13.example.db ns3/dom14.example.db ns3/dom17.example.db ns3/dom18.example.db
|
||||
rm -f nsupdate.out.*
|
||||
rm -f ns[123]/catalog[1234].example.db
|
||||
rm -rf ns2/zonedir
|
||||
|
||||
@@ -11,4 +11,4 @@
|
||||
|
||||
@ 3600 SOA . . 1 86400 3600 86400 3600
|
||||
@ 3600 IN NS invalid.
|
||||
version IN TXT "1"
|
||||
version IN TXT "2"
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; SPDX-License-Identifier: MPL-2.0
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
@ 3600 SOA . . 1 86400 3600 86400 3600
|
||||
@ 3600 IN NS invalid.
|
||||
@@ -46,6 +46,19 @@ options {
|
||||
};
|
||||
};
|
||||
|
||||
# A faulty dlz configuration to check if named and catz survive a certain class
|
||||
# of failed configuration attempts (see GL#3060).
|
||||
# We use "dlz" because the dlz processing code is located in an ideal place in
|
||||
# the view configuration function for the test to cover the view reverting code.
|
||||
#T3dlz "bad-dlz" {
|
||||
#T3 database "dlopen bad-dlz.so example.org";
|
||||
#T3};
|
||||
|
||||
zone "dom-existing.example" {
|
||||
type primary;
|
||||
file "dom-existing.example.db";
|
||||
};
|
||||
|
||||
zone "catalog1.example" {
|
||||
type secondary;
|
||||
file "catalog1.example.db";
|
||||
|
||||
@@ -32,6 +32,11 @@ options {
|
||||
# identical to named1.conf.in
|
||||
};
|
||||
|
||||
zone "dom-existing.example" {
|
||||
type primary;
|
||||
file "dom-existing.example.db";
|
||||
};
|
||||
|
||||
zone "catalog1.example" {
|
||||
type secondary;
|
||||
file "catalog1.example.db";
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; SPDX-License-Identifier: MPL-2.0
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
@ 3600 SOA . . 1 86400 3600 86400 3600
|
||||
@ 3600 IN NS invalid.
|
||||
version IN TXT "1"
|
||||
@@ -20,7 +20,7 @@ copy_setports ns2/named1.conf.in ns2/named.conf
|
||||
copy_setports ns3/named.conf.in ns3/named.conf
|
||||
|
||||
cp -f ns1/catalog.example.db.in ns1/catalog1.example.db
|
||||
cp -f ns1/catalog.example.db.in ns3/catalog2.example.db
|
||||
cp -f ns3/catalog.example.db.in ns3/catalog2.example.db
|
||||
cp -f ns1/catalog.example.db.in ns1/catalog3.example.db
|
||||
cp -f ns1/catalog.example.db.in ns1/catalog4.example.db
|
||||
|
||||
|
||||
+541
-25
@@ -266,10 +266,21 @@ echo_i "adding domain dom2.example. to primary via RNDC ($n)"
|
||||
ret=0
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns1/dom2.example.db
|
||||
echo "@ IN NS invalid." >> ns1/dom2.example.db
|
||||
echo "@ IN A 192.0.2.1" >> ns1/dom2.example.db
|
||||
rndccmd 10.53.0.1 addzone dom2.example. '{type primary; file "dom2.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domain dom2.example. to primary ns3 via RNDC ($n)"
|
||||
ret=0
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns3/dom2.example.db
|
||||
echo "@ IN NS invalid." >> ns3/dom2.example.db
|
||||
echo "@ IN A 192.0.2.2" >> ns3/dom2.example.db
|
||||
rndccmd 10.53.0.3 addzone dom2.example. '{type primary; file "dom2.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domain dom4.example. to primary via RNDC ($n)"
|
||||
ret=0
|
||||
@@ -296,7 +307,6 @@ $NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
update add blahblah.636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN TXT "blah blah"
|
||||
update add version.catalog1.example. 3600 IN A 1.2.3.4
|
||||
send
|
||||
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -369,6 +379,236 @@ wait_for_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domain dom2.example. to catalog2 zone to test change of ownership ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update add dom2-without-coo.zones.catalog2.example. 3600 IN PTR dom2.example.
|
||||
update add primaries.dom2-without-coo.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom2.example' from catalog 'catalog2.example'" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that unpermitted change of ownership did not happen ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz_addmodzone_taskaction: zone 'dom2.example' will not be added because another catalog zone already contains an entry with that zone" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom2.example. is served by secondary and that it's the one from ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom2.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.1" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding change of ownership permission record for dom2.example. into catalog1 zone ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add coo.636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN PTR catalog2.example.
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: updating catalog zone 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "catz: update_from_db: new zone merged" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "updating catalog2 zone to initiate a zone transfer ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update delete dom2-without-coo.zones.catalog2.example. 3600 IN PTR dom2.example.
|
||||
update delete primaries.dom2-without-coo.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
update add dom2-with-coo.zones.catalog2.example. 3600 IN PTR dom2.example.
|
||||
update add primaries.dom2-with-coo.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up and checking that the change of ownership was successful ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: zone 'dom2.example' change of ownership from 'catalog1.example' to 'catalog2.example'" &&
|
||||
wait_for_message ns2/named.run "catz: deleting zone 'dom2.example' from catalog 'catalog1.example' - success" &&
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom2.example' from catalog 'catalog2.example'" &&
|
||||
wait_for_message ns2/named.run "transfer of 'dom2.example/IN' from 10.53.0.3#${PORT}: Transfer status: success" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom2.example. is served by secondary and that it's now the one from ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom2.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.2" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "removing dom2.example. and its change of ownership permission record from catalog1 zone ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete 636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN PTR dom2.example.
|
||||
update delete coo.636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN PTR catalog2.example.
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: update_from_db: iteration finished" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding change of ownership permission record for dom2.example. into catalog2 zone ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update add coo.dom2-with-coo.zones.catalog2.example. 3600 IN PTR catalog1.example.
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: update_from_db: iteration finished" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding back dom2.example. into catalog1 zone ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add 636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN PTR dom2.example.
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that the change of ownership did not happen because version '1' catalog2 zone does not support the 'coo' property ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz_addmodzone_taskaction: zone 'dom2.example' will not be added because another catalog zone already contains an entry with that zone" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom2.example. is still served by secondary and that it's still the one from ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom2.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.2" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "reconfiguring secondary - checking if catz survives a certain class of failed reconfiguration attempts ($n)"
|
||||
ret=0
|
||||
sed -e "s/^#T3//" < ns2/named1.conf.in > ns2/named.conf.tmp
|
||||
copy_setports ns2/named.conf.tmp ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p "${CONTROLPORT}" reconfig > /dev/null 2>&1 && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking again that dom3.example. is served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "reconfiguring secondary - reverting the bad configuration ($n)"
|
||||
ret=0
|
||||
copy_setports ns2/named1.conf.in ns2/named.conf
|
||||
rndccmd 10.53.0.2 reconfig || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding a domain dom-existing.example. to primary via RNDC ($n)"
|
||||
ret=0
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns1/dom-existing.example.db
|
||||
echo "@ IN NS invalid." >> ns1/dom-existing.example.db
|
||||
echo "@ IN A 192.0.2.1" >> ns1/dom-existing.example.db
|
||||
rndccmd 10.53.0.1 addzone dom-existing.example. '{type primary; file "dom-existing.example.db"; also-notify { 10.53.0.2; }; notify explicit; };' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom-existing.example. is served by primary ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.1 dom-existing.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domain dom-existing.example. to catalog1 zone to test that existing zones don't get overwritten ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add dom-existing.zones.catalog1.example. 3600 IN PTR dom-existing.example.
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom-existing.example' from catalog 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "catz_addmodzone_taskaction: zone 'dom-existing.example' will not be added because it is an explicitly configured zone" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom-existing.example. is served by secondary and that it's not the one from the primary ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom-existing.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.1" dig.out.test$n > /dev/null && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "removing all records from catalog1 zone ($n)"
|
||||
ret=0
|
||||
@@ -385,8 +625,8 @@ $NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
update delete foobarbaz.b901f492f3ebf6c1e5b597e51766f02f0479eb03.zones.catalog1.example. 3600 IN APL 1:1.2.3.4/30
|
||||
update delete blahblah.636722929740e507aaf27c502812fc395d30fb17.zones.catalog1.example. 3600 IN TXT "blah blah"
|
||||
update delete version.catalog1.example. 3600 IN A 1.2.3.4
|
||||
update delete dom-existing.zones.catalog1.example. 3600 IN PTR dom-existing.example.
|
||||
send
|
||||
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -396,6 +636,9 @@ echo_i "removing all records from catalog2 zone ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update delete dom2-with-coo.zones.catalog2.example. 3600 IN PTR dom2.example.
|
||||
update delete primaries.dom2-with-coo.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
update delete coo.dom2-with-coo.zones.catalog2.example. 3600 IN PTR catalog1.example.
|
||||
update delete de26b88d855397a03f77ff1162fd055d8b419584.zones.catalog2.example. 3600 IN PTR dom4.example.
|
||||
send
|
||||
END
|
||||
@@ -410,7 +653,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add somerandomlabel.zones.catalog1.example. 3600 IN PTR dom5.example.
|
||||
update add primaries.somerandomlabel.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update add primaries.ext.somerandomlabel.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -465,8 +708,8 @@ echo_i "adding dom6.example. and a valid global primaries option (IP without TSI
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add primaries.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update add primaries.catalog1.example. 3600 IN AAAA fd92:7065:b8e:ffff::3
|
||||
update add primaries.ext.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update add primaries.ext.catalog1.example. 3600 IN AAAA fd92:7065:b8e:ffff::3
|
||||
update add 4346f565b4d63ddb99e5d2497ff22d04e878e8f8.zones.catalog1.example. 3600 IN PTR dom6.example.
|
||||
send
|
||||
END
|
||||
@@ -493,8 +736,8 @@ echo_i "removing dom6.example. ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete primaries.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update delete primaries.catalog1.example. 3600 IN AAAA fd92:7065:b8e:ffff::3
|
||||
update delete primaries.ext.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update delete primaries.ext.catalog1.example. 3600 IN AAAA fd92:7065:b8e:ffff::3
|
||||
update delete 4346f565b4d63ddb99e5d2497ff22d04e878e8f8.zones.catalog1.example. 3600 IN PTR dom6.example.
|
||||
send
|
||||
END
|
||||
@@ -522,7 +765,7 @@ echo_i "adding dom6.example. and an invalid global primaries option (TSIG withou
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add label1.primaries.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update add label1.primaries.ext.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update add 4346f565b4d63ddb99e5d2497ff22d04e878e8f8.zones.catalog1.example. 3600 IN PTR dom6.example.
|
||||
send
|
||||
END
|
||||
@@ -533,7 +776,7 @@ n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom6.example' from catalog 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "error \"failure\" while trying to generate config for zone \"dom6.example\"" || ret=1
|
||||
wait_for_message ns2/named.run "error \"failure\" while trying to generate config for zone 'dom6.example'" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -542,7 +785,7 @@ echo_i "removing dom6.example. ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete label1.primaries.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update delete label1.primaries.ext.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update delete 4346f565b4d63ddb99e5d2497ff22d04e878e8f8.zones.catalog1.example. 3600 IN PTR dom6.example.
|
||||
send
|
||||
END
|
||||
@@ -595,7 +838,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add 78833ec3c0059fd4540fee81c7eaddce088e7cd7.zones.catalog1.example. 3600 IN PTR dom7.example.
|
||||
update add allow-query.78833ec3c0059fd4540fee81c7eaddce088e7cd7.zones.catalog1.example. 3600 IN APL 1:10.53.0.1/32 !1:10.53.0.0/30 1:0.0.0.0/0
|
||||
update add allow-query.ext.78833ec3c0059fd4540fee81c7eaddce088e7cd7.zones.catalog1.example. 3600 IN APL 1:10.53.0.1/32 !1:10.53.0.0/30 1:0.0.0.0/0
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -637,8 +880,8 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add cba95222e308baba42417be6021026fdf20827b6.zones.catalog1.example. 3600 IN PTR dom8.example
|
||||
update add allow-query.catalog1.example. 3600 IN APL 1:10.53.0.1/32
|
||||
update add allow-transfer.catalog1.example. 3600 IN APL 1:10.53.0.2/32
|
||||
update add allow-query.ext.catalog1.example. 3600 IN APL 1:10.53.0.1/32
|
||||
update add allow-transfer.ext.catalog1.example. 3600 IN APL 1:10.53.0.2/32
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -688,8 +931,8 @@ echo_i "deleting global allow-query and allow-domain ACLs ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete allow-query.catalog1.example. 3600 IN APL 1:10.53.0.1/32
|
||||
update delete allow-transfer.catalog1.example. 3600 IN APL 1:10.53.0.2/32
|
||||
update delete allow-query.ext.catalog1.example. 3600 IN APL 1:10.53.0.1/32
|
||||
update delete allow-transfer.ext.catalog1.example. 3600 IN APL 1:10.53.0.2/32
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -756,8 +999,8 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN PTR dom9.example.
|
||||
update add label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
update add label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update add label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
update add label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -784,8 +1027,8 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN PTR dom9.example.
|
||||
update delete label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
update delete label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update delete label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
update delete label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -813,7 +1056,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN PTR dom9.example.
|
||||
update add label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update add label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -823,7 +1066,7 @@ n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom9.example' from catalog 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "error \"failure\" while trying to generate config for zone \"dom9.example\"" || ret=1
|
||||
wait_for_message ns2/named.run "error \"failure\" while trying to generate config for zone 'dom9.example'" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -833,7 +1076,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN PTR dom9.example.
|
||||
update delete label1.primaries.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
update delete label1.primaries.ext.f0f989bc71c5c8ca3a1eb9c9ab5246521907e3af.zones.catalog1.example. 3600 IN TXT "tsig_key"
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -1213,7 +1456,7 @@ echo_i "reconfiguring secondary - removing catalog4 catalog zone, adding non-exi
|
||||
ret=0
|
||||
sed -e "s/^#T2//" < ns2/named1.conf.in > ns2/named.conf.tmp
|
||||
copy_setports ns2/named.conf.tmp ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig > /dev/null 2>&1 && ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p "${CONTROLPORT}" reconfig > /dev/null 2>&1 && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -1295,7 +1538,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add 8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN PTR dom13.example.
|
||||
update add primaries.8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
update add primaries.ext.8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN A 10.53.0.1
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -1381,7 +1624,7 @@ ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete 8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN PTR dom13.example.
|
||||
update delete primaries.8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN A 10.53.0.2
|
||||
update delete primaries.ext.8d7989c746b3f92b3bba2479e72afd977198363f.zones.catalog1.example. 3600 IN A 10.53.0.2
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
@@ -1731,6 +1974,279 @@ wait_for_no_soa @10.53.0.2 dom16.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
##########################################################################
|
||||
echo_i "Testing custom properties version '1' and version '2' syntaxes"
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is not served by primary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.1 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is not served by primary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.1 dom18.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domains dom17.example. and dom18.example. to primary ns1 via RNDC ($n)"
|
||||
ret=0
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns1/dom17.example.db
|
||||
echo "@ IN NS invalid." >> ns1/dom17.example.db
|
||||
echo "@ IN A 192.0.2.1" >> ns1/dom17.example.db
|
||||
rndccmd 10.53.0.1 addzone dom17.example. '{type primary; file "dom17.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns1/dom18.example.db
|
||||
echo "@ IN NS invalid." >> ns1/dom18.example.db
|
||||
echo "@ IN A 192.0.2.1" >> ns1/dom18.example.db
|
||||
rndccmd 10.53.0.1 addzone dom18.example. '{type primary; file "dom18.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is now served by primary ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.1 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is now served by primary ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.1 dom18.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is not served by primary ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.3 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is not served by primary ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.3 dom18.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domains dom17.example. and dom18.example. to primary ns3 via RNDC ($n)"
|
||||
ret=0
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns3/dom17.example.db
|
||||
echo "@ IN NS invalid." >> ns3/dom17.example.db
|
||||
echo "@ IN A 192.0.2.2" >> ns3/dom17.example.db
|
||||
rndccmd 10.53.0.3 addzone dom17.example. '{type primary; file "dom17.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
echo "@ 3600 IN SOA . . 1 3600 3600 3600 3600" > ns3/dom18.example.db
|
||||
echo "@ IN NS invalid." >> ns3/dom18.example.db
|
||||
echo "@ IN A 192.0.2.2" >> ns3/dom18.example.db
|
||||
rndccmd 10.53.0.3 addzone dom18.example. '{type primary; file "dom18.example.db";};' || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is now served by primary ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.3 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is now served by primary ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.3 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domains dom17.example. and dom18.example. to catalog1 zone with ns3 as custom primary using different custom properties syntax ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update add dom17.zones.catalog1.example. 3600 IN PTR dom17.example.
|
||||
update add dom18.zones.catalog1.example. 3600 IN PTR dom18.example.
|
||||
update add primaries.dom17.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update add primaries.ext.dom18.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: unknown record in catalog zone - primaries.dom17.zones.catalog1.example IN A(failure) - ignoring" &&
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom17.example' from catalog 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom18.example' from catalog 'catalog1.example'" &&
|
||||
wait_for_message ns2/named.run "transfer of 'dom17.example/IN' from 10.53.0.1#${PORT}: Transfer status: success" &&
|
||||
wait_for_message ns2/named.run "transfer of 'dom18.example/IN' from 10.53.0.3#${PORT}: Transfer status: success" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# The "primaries" custom property for dom17.example. was added using the legacy
|
||||
# syntax into a version 2 catalog1 zone, so we expect that it was ignored, no
|
||||
# override of the default setting happened, and dom17.example. was transferred
|
||||
# from the ns1 primary (the default).
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is served by secondary and that it's the one from ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom17.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.1" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# The "primaries" custom property for dom18.example. was added using a supported
|
||||
# syntax into a version 2 catalog1 zone, so we expect that it was processed,
|
||||
# will override the default setting, and dom18.example. was transferred
|
||||
# from the ns3 primary.
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is served by secondary and that it's the one from ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom18.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.2" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "deleting domain dom17.example. and dom18.example. from catalog1 ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.1 ${PORT}
|
||||
update delete dom17.zones.catalog1.example. 3600 IN PTR dom17.example.
|
||||
update delete dom18.zones.catalog1.example. 3600 IN PTR dom18.example.
|
||||
update delete primaries.dom17.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
update delete primaries.ext.dom18.zones.catalog1.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: deleting zone 'dom17.example' from catalog 'catalog1.example' - success" &&
|
||||
wait_for_message ns2/named.run "catz: deleting zone 'dom18.example' from catalog 'catalog1.example' - success" &&
|
||||
wait_for_message ns2/named.run "zone_shutdown: zone dom17.example/IN: shutting down" &&
|
||||
wait_for_message ns2/named.run "zone_shutdown: zone dom18.example/IN: shutting down" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is not served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.2 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is not served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.2 dom18.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "adding domains dom17.example. and dom18.example. to catalog2 zone with ns3 as custom primary using different custom properties syntax ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update add dom17.zones.catalog2.example. 3600 IN PTR dom17.example.
|
||||
update add dom18.zones.catalog2.example. 3600 IN PTR dom18.example.
|
||||
update add primaries.dom17.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
update add primaries.ext.dom18.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: unknown record in catalog zone - primaries.ext.dom18.zones.catalog2.example IN A(failure) - ignoring" &&
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom17.example' from catalog 'catalog2.example'" &&
|
||||
wait_for_message ns2/named.run "catz: adding zone 'dom18.example' from catalog 'catalog2.example'" &&
|
||||
wait_for_message ns2/named.run "transfer of 'dom17.example/IN' from 10.53.0.3#${PORT}: Transfer status: success" &&
|
||||
wait_for_message ns2/named.run "transfer of 'dom18.example/IN' from 10.53.0.1#${EXTRAPORT1}: Transfer status: success" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# The "primaries" custom property for dom17.example. was added using a supported
|
||||
# syntax into a version 1 catalog1 zone, so we expect that it was processed,
|
||||
# will override the default setting, and dom17.example. was transferred
|
||||
# from the ns3 primary.
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is served by secondary and that it's the one from ns3 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom17.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.2" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# The "primaries" custom property for dom18.example. was added using the new
|
||||
# syntax into a version 1 catalog1 zone, so we expect that it was ignored, no
|
||||
# override of the default setting happened, and dom18.example. was transferred
|
||||
# from the ns1 primary (the default).
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is served by secondary and that it's the one from ns1 ($n)"
|
||||
ret=0
|
||||
wait_for_a @10.53.0.2 dom18.example. dig.out.test$n || ret=1
|
||||
grep "192.0.2.1" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
nextpart ns2/named.run >/dev/null
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "deleting domain dom17.example. and dom18.example. from catalog2 ($n)"
|
||||
ret=0
|
||||
$NSUPDATE -d <<END >> nsupdate.out.test$n 2>&1 || ret=1
|
||||
server 10.53.0.3 ${PORT}
|
||||
update delete dom17.zones.catalog2.example. 3600 IN PTR dom17.example.
|
||||
update delete dom18.zones.catalog2.example. 3600 IN PTR dom18.example.
|
||||
update delete primaries.dom17.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
update delete primaries.ext.dom18.zones.catalog2.example. 3600 IN A 10.53.0.3
|
||||
send
|
||||
END
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "waiting for secondary to sync up ($n)"
|
||||
ret=0
|
||||
wait_for_message ns2/named.run "catz: deleting zone 'dom17.example' from catalog 'catalog2.example' - success" &&
|
||||
wait_for_message ns2/named.run "catz: deleting zone 'dom18.example' from catalog 'catalog2.example' - success" &&
|
||||
wait_for_message ns2/named.run "zone_shutdown: zone dom17.example/IN: shutting down" &&
|
||||
wait_for_message ns2/named.run "zone_shutdown: zone dom18.example/IN: shutting down" || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom17.example. is not served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.2 dom17.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking that dom18.example. is not served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_no_soa @10.53.0.2 dom18.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
##########################################################################
|
||||
n=$((n+1))
|
||||
echo_i "checking that reconfig can delete and restore catalog zone configuration ($n)"
|
||||
ret=0
|
||||
|
||||
@@ -52,7 +52,7 @@ check_stderr() {
|
||||
}
|
||||
|
||||
check_stdout() {
|
||||
$DIFF out.$n "${out:-empty}" >/dev/null && return
|
||||
diff out.$n "${out:-empty}" >/dev/null && return
|
||||
echo_d "stdout did not match '$out'"
|
||||
( echo "wanted"
|
||||
cat "$out"
|
||||
@@ -128,10 +128,10 @@ name='in-place backup correct modification time'
|
||||
testcase 0 $PERL checkmtime.pl 7200 DS.inplace.bak
|
||||
|
||||
name='in-place correct output'
|
||||
testcase 0 $DIFF DS.1 DS.inplace
|
||||
testcase 0 diff DS.1 DS.inplace
|
||||
|
||||
name='in-place backup unmodified'
|
||||
testcase 0 $DIFF DS.1 DS.inplace.bak
|
||||
testcase 0 diff DS.1 DS.inplace.bak
|
||||
|
||||
name='one mangled DS'
|
||||
err='found RRSIG by key'
|
||||
|
||||
+9
-3
@@ -11,8 +11,14 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
keep-response-order {
|
||||
does_not_exist;
|
||||
dnssec-policy ksk-without-zsk {
|
||||
keys {
|
||||
ksk lifetime 30d algorithm 13;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy ksk-without-zsk;
|
||||
};
|
||||
@@ -0,0 +1,27 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* SPDX-License-Identifier: MPL-2.0
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-policy unpaired-keys {
|
||||
keys {
|
||||
/* zsk without ksk */
|
||||
zsk lifetime 30d algorithm 13;
|
||||
/* ksk without zsk */
|
||||
ksk lifetime 30d algorithm 7;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy unpaired-keys;
|
||||
};
|
||||
+10
-6
@@ -11,10 +11,14 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
port @PORT@;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
dnssec-policy zsk-without-ksk {
|
||||
keys {
|
||||
zsk lifetime 30d algorithm 13;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy zsk-without-ksk;
|
||||
};
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user