Compare commits
396
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5f937ddc1d | ||
|
|
8c6b0bf1b6 | ||
|
|
65f2a80791 | ||
|
|
2cb9116a7e | ||
|
|
c3092672d6 | ||
|
|
6854c1e017 | ||
|
|
1131c8e18c | ||
|
|
07c7186ddc | ||
|
|
863e87c5a2 | ||
|
|
a544ccef2b | ||
|
|
1cbf526c45 | ||
|
|
95edc4bf94 | ||
|
|
f438b6e70f | ||
|
|
6f0e3d46c9 | ||
|
|
55a75a4532 | ||
|
|
d21bf53329 | ||
|
|
af2f49db64 | ||
|
|
d06d697c47 | ||
|
|
343d42c792 | ||
|
|
729d61cbaa | ||
|
|
05e50f7b86 | ||
|
|
8268526294 | ||
|
|
d70daa29f7 | ||
|
|
4761213e80 | ||
|
|
599c1d2a6b | ||
|
|
eeead1cfe7 | ||
|
|
ed22d12f10 | ||
|
|
ced79790b3 | ||
|
|
03697f1bcc | ||
|
|
0fb4fc1897 | ||
|
|
85870ad9ee | ||
|
|
b3a058e7bb | ||
|
|
e8a64d0cbe | ||
|
|
bc203d6082 | ||
|
|
da0d85d748 | ||
|
|
3ec5d2d6ed | ||
|
|
e353700189 | ||
|
|
a962475948 | ||
|
|
e888c62fbd | ||
|
|
99906df09e | ||
|
|
8f6e4dfa15 | ||
|
|
4c008d20e6 | ||
|
|
ff22498849 | ||
|
|
8495edc31d | ||
|
|
5ccb28d6d8 | ||
|
|
cd52953f8a | ||
|
|
e42cb1f198 | ||
|
|
7ba3a06935 | ||
|
|
71dd44339f | ||
|
|
ae7fa0a308 | ||
|
|
9c27a3b0e2 | ||
|
|
9241363f36 | ||
|
|
c9f28777f6 | ||
|
|
dcb6a0c4f8 | ||
|
|
51546e8892 | ||
|
|
f0f3370e14 | ||
|
|
9fcc028f5c | ||
|
|
bfa4b9c141 | ||
|
|
612f277877 | ||
|
|
5c271f91e1 | ||
|
|
fe1bbba259 | ||
|
|
c289913e5c | ||
|
|
7e37b5e379 | ||
|
|
5dc3b25d03 | ||
|
|
fd8dd9841d | ||
|
|
01b125ff05 | ||
|
|
13b20ef411 | ||
|
|
7f91f1ecaa | ||
|
|
79b5ccbf34 | ||
|
|
e6ca2a651f | ||
|
|
6437bcc488 | ||
|
|
27850a5ad2 | ||
|
|
c259cecc90 | ||
|
|
514053f244 | ||
|
|
8fbb42c49c | ||
|
|
f4751a91f7 | ||
|
|
bbe1c06a8b | ||
|
|
c752dff3b4 | ||
|
|
f98a6a5308 | ||
|
|
49d2a12e7c | ||
|
|
ad5b0402c9 | ||
|
|
1d4d008fc9 | ||
|
|
420a71df57 | ||
|
|
53a5776025 | ||
|
|
c7085be211 | ||
|
|
7e7a946d44 | ||
|
|
ccc6378355 | ||
|
|
a85df3ff9c | ||
|
|
5f0ee7c303 | ||
|
|
8537878c01 | ||
|
|
ec30944aa4 | ||
|
|
e9f4d00bf0 | ||
|
|
173ad9cf46 | ||
|
|
00392921f0 | ||
|
|
49312d6bb2 | ||
|
|
05c97f2329 | ||
|
|
704ad2907f | ||
|
|
286b57c7f1 | ||
|
|
0a76f186a5 | ||
|
|
96b7f9f9aa | ||
|
|
4e0d576858 | ||
|
|
53ef8835c1 | ||
|
|
342c06c335 | ||
|
|
41a60a0e21 | ||
|
|
b103f516d0 | ||
|
|
524fce77fe | ||
|
|
b0f6fc7f2f | ||
|
|
188684a31d | ||
|
|
53dd4f02c1 | ||
|
|
8ace9e0c62 | ||
|
|
49c804f8b7 | ||
|
|
6ddac2d56d | ||
|
|
a761aa59e3 | ||
|
|
1357d44605 | ||
|
|
178aef5b8c | ||
|
|
785f6d470f | ||
|
|
2d2d87a615 | ||
|
|
315b3c3a1a | ||
|
|
9992f7808c | ||
|
|
2e42414522 | ||
|
|
473d5a8d03 | ||
|
|
ca1da46ac1 | ||
|
|
e532d39146 | ||
|
|
037468f6a4 | ||
|
|
328d11297d | ||
|
|
ec1e8e7001 | ||
|
|
6be83f2eb7 | ||
|
|
1c77f55dc6 | ||
|
|
338df9e1ff | ||
|
|
6bcfa0c4ec | ||
|
|
bfaf88ce7d | ||
|
|
ae73a8d87a | ||
|
|
e369c90369 | ||
|
|
f251d69eba | ||
|
|
0b68596c45 | ||
|
|
d128656d2e | ||
|
|
8fa27365ec | ||
|
|
3db335bca0 | ||
|
|
bbb4cdb92d | ||
|
|
acf5986a7c | ||
|
|
67dbe0ae4d | ||
|
|
8098a58581 | ||
|
|
5d34a14f22 | ||
|
|
b40d1e8467 | ||
|
|
e48af36981 | ||
|
|
d4c2395fff | ||
|
|
9bcf45f4ce | ||
|
|
f23e86b96b | ||
|
|
18efcdc65f | ||
|
|
963f6a2203 | ||
|
|
e229d46a87 | ||
|
|
9d8e8a4fcc | ||
|
|
51147fa567 | ||
|
|
b5a5eed7a0 | ||
|
|
f24b26188d | ||
|
|
d811cca3c6 | ||
|
|
d75b953489 | ||
|
|
6bd025942c | ||
|
|
1bb56bb0fc | ||
|
|
a53ed01d03 | ||
|
|
be34b1c535 | ||
|
|
f3ca90a804 | ||
|
|
488b1a776c | ||
|
|
f3228df622 | ||
|
|
4043fe9090 | ||
|
|
98820aef7e | ||
|
|
284b2ce106 | ||
|
|
6b52160a5b | ||
|
|
60f5f78b8d | ||
|
|
347ce4f590 | ||
|
|
117dac11d1 | ||
|
|
ef0d7177b6 | ||
|
|
600b6abc05 | ||
|
|
4ca74eee49 | ||
|
|
5bcac990dd | ||
|
|
ce8703a79e | ||
|
|
d36938321e | ||
|
|
4c356d2770 | ||
|
|
ed3dd45da8 | ||
|
|
b8b99603f1 | ||
|
|
f6453c1bc7 | ||
|
|
b220fb32bd | ||
|
|
e2636b1de0 | ||
|
|
26f817f574 | ||
|
|
48039fa25e | ||
|
|
bbaade23eb | ||
|
|
5e4580d479 | ||
|
|
0bde07261b | ||
|
|
0e57fc160e | ||
|
|
9422a5da44 | ||
|
|
0069a689a6 | ||
|
|
53e1b41660 | ||
|
|
dc9ba2d3ef | ||
|
|
759ad04eb8 | ||
|
|
7cef148b5a | ||
|
|
5076355822 | ||
|
|
40caf57cf5 | ||
|
|
ecf042991c | ||
|
|
be339b3c83 | ||
|
|
3b2d680c5b | ||
|
|
92cce1da65 | ||
|
|
be5be5aa39 | ||
|
|
e2555a306f | ||
|
|
3268627916 | ||
|
|
713444e51a | ||
|
|
88418c3372 | ||
|
|
e42d5d8875 | ||
|
|
600f9010d2 | ||
|
|
1c462a63ec | ||
|
|
f7482b68b9 | ||
|
|
df0bc2b3b6 | ||
|
|
653db956f0 | ||
|
|
2070dcf99d | ||
|
|
fd5e39cc76 | ||
|
|
39730a503d | ||
|
|
b645e28167 | ||
|
|
d0c2113693 | ||
|
|
f216eb0d64 | ||
|
|
ddd5b0ff89 | ||
|
|
30fda4cb52 | ||
|
|
d01562f22b | ||
|
|
30f4bdb17e | ||
|
|
b215018067 | ||
|
|
2bcf5a5315 | ||
|
|
4f5b4662b6 | ||
|
|
306a3c0803 | ||
|
|
987ad32fac | ||
|
|
8fed1b6461 | ||
|
|
8643bbab84 | ||
|
|
037549c405 | ||
|
|
3c7b04d015 | ||
|
|
63f3ad3e3c | ||
|
|
53bc8905ab | ||
|
|
08c2728ed1 | ||
|
|
4d2f5754af | ||
|
|
d2597e3496 | ||
|
|
c3fd94cd4d | ||
|
|
08026c7ded | ||
|
|
9f1c439335 | ||
|
|
ebfdb50ac7 | ||
|
|
4716c56ebb | ||
|
|
0697288b9d | ||
|
|
1b25b76921 | ||
|
|
b6d40b3c4e | ||
|
|
ae4cd57ed5 | ||
|
|
0c35bda762 | ||
|
|
ee359d6ffa | ||
|
|
a89d9e0fa6 | ||
|
|
b735182ae0 | ||
|
|
408b362169 | ||
|
|
cd3b58622c | ||
|
|
45a73c113f | ||
|
|
92338f2e29 | ||
|
|
04361b0ad5 | ||
|
|
4444b168db | ||
|
|
5fbbc312a7 | ||
|
|
39df399d9f | ||
|
|
f286c845b0 | ||
|
|
1e7d666bf5 | ||
|
|
62bd5cb08c | ||
|
|
8715be1e4b | ||
|
|
62e15bb06d | ||
|
|
f4ae230d41 | ||
|
|
cdce681cf7 | ||
|
|
39004d3b33 | ||
|
|
7365400610 | ||
|
|
5fa60c1ce9 | ||
|
|
48c44fe6d4 | ||
|
|
fcc9ac7bd8 | ||
|
|
f0edf07fbc | ||
|
|
6914a4cda3 | ||
|
|
8058d64dda | ||
|
|
63989e98ac | ||
|
|
7fd61f9403 | ||
|
|
4dbad65bfd | ||
|
|
2774b497a6 | ||
|
|
3c83a9d503 | ||
|
|
bd3b310eae | ||
|
|
f8cb0ac141 | ||
|
|
16dec1ff58 | ||
|
|
f7225db822 | ||
|
|
09d6cf89df | ||
|
|
9437ea08e1 | ||
|
|
2b5b777c07 | ||
|
|
b686b5c161 | ||
|
|
f713984886 | ||
|
|
98961e86b8 | ||
|
|
4abd58aa8f | ||
|
|
f57585a599 | ||
|
|
bb60622250 | ||
|
|
62cf6a77cf | ||
|
|
44aa8ef997 | ||
|
|
b9cb29076f | ||
|
|
47b6e5d038 | ||
|
|
0893b5fb79 | ||
|
|
89935864e9 | ||
|
|
9e70c6887a | ||
|
|
b42681c4e9 | ||
|
|
59c3b17ad0 | ||
|
|
0500345513 | ||
|
|
ecc920682e | ||
|
|
1d8788464e | ||
|
|
927d5ff89c | ||
|
|
3de17e9185 | ||
|
|
40652a8879 | ||
|
|
7845f51178 | ||
|
|
a449709441 | ||
|
|
468cf3cdc2 | ||
|
|
bfe287f4a4 | ||
|
|
11a0b41370 | ||
|
|
c586445894 | ||
|
|
d45f0e1d9e | ||
|
|
f998e7e3c2 | ||
|
|
00ba6967b1 | ||
|
|
01bd7d1024 | ||
|
|
a321b28916 | ||
|
|
2ae84702ad | ||
|
|
858e522b4e | ||
|
|
34a3b35b08 | ||
|
|
e97c35b3bc | ||
|
|
d975e6630f | ||
|
|
f5c66f311a | ||
|
|
a8ac23c73c | ||
|
|
123b57db36 | ||
|
|
6de4dfcc8c | ||
|
|
c068c3c771 | ||
|
|
9c02bd1021 | ||
|
|
e8ac7cf6ec | ||
|
|
c2cf69fcc4 | ||
|
|
c3a715123b | ||
|
|
46bd46f253 | ||
|
|
d3fed6f400 | ||
|
|
bba5a1780d | ||
|
|
e42f7d2722 | ||
|
|
79ddedabf8 | ||
|
|
f81debe1c8 | ||
|
|
737e658602 | ||
|
|
3b53680458 | ||
|
|
e97ed8d9b6 | ||
|
|
f6b996f6fc | ||
|
|
8109e924b5 | ||
|
|
9d398572f0 | ||
|
|
986b364fe6 | ||
|
|
d799d7358d | ||
|
|
f386fab2e2 | ||
|
|
f00f521e9c | ||
|
|
bff7dbeef9 | ||
|
|
1e711dcccb | ||
|
|
9c81a45279 | ||
|
|
5d2dd94cf8 | ||
|
|
b983df403a | ||
|
|
67092442d6 | ||
|
|
7ba786dedb | ||
|
|
4c03d814ed | ||
|
|
31988745fc | ||
|
|
a90f4c4ffa | ||
|
|
0af8bbd49b | ||
|
|
8a4f098dee | ||
|
|
eba66665a5 | ||
|
|
221e1bc2a3 | ||
|
|
0725fcad38 | ||
|
|
ad01bca9fd | ||
|
|
3f16408405 | ||
|
|
1d706f328c | ||
|
|
8a2305fe1a | ||
|
|
a938db2170 | ||
|
|
fb87022115 | ||
|
|
65abbca79b | ||
|
|
84878f18d2 | ||
|
|
81d3584116 | ||
|
|
27b709cc75 | ||
|
|
4a6c66288f | ||
|
|
5f9d4b5db4 | ||
|
|
62337d433f | ||
|
|
d7dfa2dc4b | ||
|
|
2fd967136a | ||
|
|
6b937ed5f6 | ||
|
|
3697560f04 | ||
|
|
2941a480cd | ||
|
|
ee3ba3cac9 | ||
|
|
8c82b0f2d0 | ||
|
|
4379e16996 | ||
|
|
b1af79acc7 | ||
|
|
4b1c70de90 | ||
|
|
2c81fa9013 | ||
|
|
933ed9d537 | ||
|
|
5c6b50027a | ||
|
|
3bd4318fcc | ||
|
|
920a2e730b | ||
|
|
f693c9b1a7 | ||
|
|
d2bbd4d81c | ||
|
|
49a32c076c | ||
|
|
3b45759849 | ||
|
|
ccfe682508 | ||
|
|
db82318477 | ||
|
|
8c4d5d5623 |
+36
-16
@@ -7,6 +7,9 @@ variables:
|
||||
CI_REGISTRY_IMAGE: registry.gitlab.isc.org/isc-projects/images/bind9
|
||||
CCACHE_DIR: "/ccache"
|
||||
SOFTHSM2_CONF: "/var/tmp/softhsm2/softhsm2.conf"
|
||||
OPENSSL_ENGINES: "/usr/lib/x86_64-linux-gnu/engines-1.1"
|
||||
DEFAULT_OPENSSL_CONF: "/etc/ssl/openssl.cnf"
|
||||
OPENSSL_CONF: "/var/tmp/etc/openssl.cnf"
|
||||
|
||||
GIT_DEPTH: 1
|
||||
BUILD_PARALLEL_JOBS: 6
|
||||
@@ -309,15 +312,10 @@ stages:
|
||||
sudo sh -x bin/tests/system/ifconfig.sh up;
|
||||
fi
|
||||
|
||||
.setup_softhsm: &setup_softhsm
|
||||
- export SLOT=$(sh -x bin/tests/prepare-softhsm2.sh)
|
||||
- test -n "${SLOT}" && test "${SLOT}" -gt 0
|
||||
|
||||
.system_test_common: &system_test_common
|
||||
<<: *default_triggering_rules
|
||||
stage: system
|
||||
before_script:
|
||||
- *setup_softhsm
|
||||
- *retrieve_out_of_tree_workspace
|
||||
- *setup_interfaces
|
||||
script:
|
||||
@@ -358,7 +356,6 @@ stages:
|
||||
<<: *default_triggering_rules
|
||||
stage: unit
|
||||
before_script:
|
||||
- *setup_softhsm
|
||||
- *retrieve_out_of_tree_workspace
|
||||
script:
|
||||
- make -j${TEST_PARALLEL_JOBS:-1} -k unit V=1
|
||||
@@ -397,9 +394,6 @@ stages:
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k doc V=1
|
||||
- qpdf --check doc/arm/_build/latex/Bv9ARM.pdf
|
||||
- find doc/man/ -maxdepth 1 -name "*.[0-9]" -exec mandoc -T lint "{}" \; | ( ! grep -v -e "skipping paragraph macro. sp after" -e "unknown font, skipping request. ft C" )
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 month"
|
||||
|
||||
### Job Definitions
|
||||
|
||||
@@ -508,16 +502,19 @@ tarball-create:
|
||||
- autoreconf -fi
|
||||
- ./configure --enable-maintainer-mode
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} all V=1
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; git diff > diff.patch; exit 1; fi
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} dist V=1
|
||||
artifacts:
|
||||
paths:
|
||||
- diff.patch
|
||||
- bind-*.tar.${TARBALL_EXTENSION}
|
||||
when: always
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
|
||||
# Jobs for doc builds on Debian 11 "bullseye" (amd64)
|
||||
# Long "docs" job artifact retention is needed for bind.isc.org web site
|
||||
|
||||
docs:
|
||||
<<: *release_branch_triggering_rules
|
||||
@@ -528,9 +525,12 @@ docs:
|
||||
needs:
|
||||
- job: autoreconf
|
||||
artifacts: true
|
||||
artifacts:
|
||||
untracked: true
|
||||
expire_in: "1 month"
|
||||
|
||||
docs:tarball:
|
||||
<<: *schedules_tags_web_triggering_rules
|
||||
<<: *default_triggering_rules
|
||||
<<: *base_image
|
||||
<<: *docs_job
|
||||
before_script:
|
||||
@@ -679,6 +679,7 @@ unit:gcc:buster:amd64:
|
||||
artifacts: true
|
||||
|
||||
# Jobs for regular GCC builds on Debian 11 "bullseye" (amd64)
|
||||
# (The second unit test job also executes unstable unit tests.)
|
||||
|
||||
gcc:bullseye:amd64:
|
||||
variables:
|
||||
@@ -702,6 +703,20 @@ unit:gcc:bullseye:amd64:
|
||||
- job: gcc:bullseye:amd64
|
||||
artifacts: true
|
||||
|
||||
unit:gcc:bullseye:unstable:amd64:
|
||||
<<: *debian_bullseye_amd64_image
|
||||
<<: *unit_test_job
|
||||
variables:
|
||||
CI_ENABLE_ALL_TESTS: 1
|
||||
needs:
|
||||
- job: gcc:bullseye:amd64
|
||||
artifacts: true
|
||||
only:
|
||||
- api
|
||||
- schedules
|
||||
- triggers
|
||||
- web
|
||||
|
||||
# Jobs for cross-compiled GCC builds on Debian 11 "bullseye" (amd64) with
|
||||
# 32-bit libraries
|
||||
|
||||
@@ -930,13 +945,17 @@ unit:gcc:focal:amd64:
|
||||
gcc:asan:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined"
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -Wno-error=stringop-overread"
|
||||
LDFLAGS: "-fsanitize=address,undefined"
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --without-jemalloc"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:asan:
|
||||
variables:
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
LSAN_OPTIONS: "suppressions=$CI_PROJECT_DIR/suppr-lsan.txt"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *system_test_job
|
||||
needs:
|
||||
@@ -980,12 +999,14 @@ gcc:tsan:
|
||||
CC: gcc
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread"
|
||||
LDFLAGS: "-fsanitize=thread"
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock --without-jemalloc"
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
system:gcc:tsan:
|
||||
variables:
|
||||
SOFTHSM2_MODULE: "/lib64/libsofthsm2.so"
|
||||
TSAN_OPTIONS: ${TSAN_OPTIONS_COMMON}
|
||||
<<: *fedora_35_amd64_image
|
||||
<<: *system_test_tsan_job
|
||||
@@ -1186,10 +1207,10 @@ release:
|
||||
)
|
||||
- test "$(md5sum cov-analysis-linux64.tgz | awk '{ print $1 }')" = "$(cat cov-analysis-linux64.md5)"
|
||||
- tar --extract --gzip --file=cov-analysis-linux64.tgz
|
||||
- test -d cov-analysis-linux64-2020.09
|
||||
- test -d cov-analysis-linux64-2021.12.1
|
||||
|
||||
.coverity_build: &coverity_build
|
||||
- cov-analysis-linux64-2020.09/bin/cov-build --dir cov-int sh -c 'make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1'
|
||||
- cov-analysis-linux64-2021.12.1/bin/cov-build --dir cov-int sh -c 'make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1'
|
||||
- tar --create --gzip --file=cov-int.tar.gz cov-int/
|
||||
- curl -v https://scan.coverity.com/builds?project=$COVERITY_SCAN_PROJECT_NAME
|
||||
--form token=$COVERITY_SCAN_TOKEN
|
||||
@@ -1225,7 +1246,7 @@ coverity:
|
||||
- $COVERITY_SCAN_PROJECT_NAME
|
||||
- $COVERITY_SCAN_TOKEN
|
||||
cache:
|
||||
key: cov-analysis-linux64-2020.09
|
||||
key: cov-analysis-linux64-2021.12.1
|
||||
paths:
|
||||
- cov-analysis-linux64.md5
|
||||
- cov-analysis-linux64.tgz
|
||||
@@ -1297,7 +1318,6 @@ respdiff-third-party:
|
||||
script:
|
||||
- *configure
|
||||
- *setup_interfaces
|
||||
- *setup_softhsm
|
||||
- make -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||
- make DESTDIR="${INSTALL_PATH}" install
|
||||
- git clone --depth 1 https://gitlab-ci-token:${CI_JOB_TOKEN}@gitlab.isc.org/isc-private/bind-qa.git
|
||||
|
||||
@@ -1,3 +1,147 @@
|
||||
5834. [cleanup] C99 variable-length arrays are difficult to use safely,
|
||||
so avoid them except in test code. [GL #3201]
|
||||
|
||||
5833. [bug] When encountering socket error while trying to initiate
|
||||
a TCP connection to a server, dig could hang
|
||||
indefinitely, when there were more servers to try.
|
||||
[GL #3205]
|
||||
|
||||
5832. [bug] When timing-out or having other types of socket errors
|
||||
during a query, dig wasn't trying to perform the lookup
|
||||
using other servers, in case they exist. [GL #3128]
|
||||
|
||||
5831. [bug] When resending a UDP request in the result of a timeout,
|
||||
the recv_done() function in dighost.c was prepending
|
||||
the new query into the loookup's queries list instead
|
||||
of inserting, which could cause an assertion failure
|
||||
when the resent query's result was SERVFAIL. [GL #3020]
|
||||
|
||||
5830. [func] Implement incremental resizing of isc_ht hash tables to
|
||||
perform the rehashing gradually. [GL #3212]
|
||||
|
||||
5829. [func] Refactor and simplify isc_timer API in preparation
|
||||
for further refactoring on top of network manager
|
||||
loops. [GL #3202]
|
||||
|
||||
5828. [bug] Replace single TCP write timer with per-TCP write
|
||||
timers. [GL #3200]
|
||||
|
||||
5827. [cleanup] The command-line utilities printed their version numbers
|
||||
inconsistently; they all now print to stdout. (They are
|
||||
still inconsistent abotut whether you use `-v` or `-V`
|
||||
to request the version). [GL #3189]
|
||||
|
||||
5826. [cleanup] Stop dig from complaining about lack of IDN support when
|
||||
the user asks for no IDN translation. [GL #3188]
|
||||
|
||||
5825. [func] Set the minimum MTU on UDPv6 and TCPv6 sockets and
|
||||
limit TCP maximum segment size (TCP_MAXSEG) to (1220)
|
||||
for both TCPv4 and TCPv6 sockets. [GL #2201]
|
||||
|
||||
5824. [bug] Invalid dnssec-policy definitions were being accepted
|
||||
where the defined keys did not cover both KSK and ZSK
|
||||
roles for a given algorithm. This is now checked for
|
||||
and the dnssec-policy is rejected if both roles are
|
||||
not present for all algorithms in use. [GL #3142]
|
||||
|
||||
5823. [func] Replace hazard pointers based lock-free list with
|
||||
locked-list based queue that's simpler and has no or
|
||||
little performance impact. [GL #3180]
|
||||
|
||||
5822. [bug] When calling dns_dispatch_send(), attach/detach
|
||||
dns_request_t object as the read callback could
|
||||
be called before send callback dereferencing
|
||||
dns_request_t object too early. [GL #3105]
|
||||
|
||||
5821. [bug] Fix query context management issues in the TCP part
|
||||
of dig. [GL #3184]
|
||||
|
||||
5820. [security] An assertion could occur in resume_dslookup() if the
|
||||
fetch had been shut down earlier. (CVE-2022-0667)
|
||||
[GL #3129]
|
||||
|
||||
5819. [security] Lookups involving a DNAME could trigger an INSIST when
|
||||
"synth-from-dnssec" was enabled. (CVE-2022-0635)
|
||||
[GL #3158]
|
||||
|
||||
5818. [security] A synchronous call to closehandle_cb() caused
|
||||
isc__nm_process_sock_buffer() to be called recursively,
|
||||
which in turn left TCP connections hanging in the
|
||||
CLOSE_WAIT state blocking indefinitely when
|
||||
out-of-order processing was disabled. (CVE-2022-0396)
|
||||
[GL #3112]
|
||||
|
||||
5817. [security] The rules for acceptance of records into the cache
|
||||
have been tightened to prevent the possibility of
|
||||
poisoning if forwarders send records outside
|
||||
the configured bailiwick. (CVE-2021-25220) [GL #2950]
|
||||
|
||||
5816. [bug] Make BIND compile with LibreSSL 3.5.0, as it was using
|
||||
not very accurate pre-processor checks for using shims.
|
||||
[GL #3172]
|
||||
|
||||
5815. [bug] If an oversized key name of a specific length was used
|
||||
in the text form of an HTTP or SVBC record, an INSIST
|
||||
could be triggered when parsing it. [GL #3175]
|
||||
|
||||
5814. [bug] The RecursClients statistics counter could underflow
|
||||
in certain resolution scenarios. [GL #3147]
|
||||
|
||||
5813. [func] The "keep-response-order" ACL has been declared
|
||||
obsolete, and is now non-operational. [GL #3140]
|
||||
|
||||
5812. [func] Drop the artificial limit on the number of queries
|
||||
processed in a single TCP read callback. [GL #3141]
|
||||
|
||||
5811. [bug] Reimplement the maximum and idle timeouts for outgoing
|
||||
zone tranfers. [GL #1897]
|
||||
|
||||
5810. [func] New option '-J' for dnssec-signzone and dnssec-verify
|
||||
allows loading journal files. [GL #2486]
|
||||
|
||||
5809. [bug] Reset client TCP connection when data received cannot
|
||||
be parsed as a valid DNS request. [GL #3149]
|
||||
|
||||
5808. [bug] Certain TCP failures were not caught and handled
|
||||
correctly by the dispatch manager, causing
|
||||
connections to time out rather than returning
|
||||
SERVFAIL. [GL #3133]
|
||||
|
||||
5807. [bug] Add a TCP "write" timer, and time out writing
|
||||
connections after the "tcp-idle-timeout" period
|
||||
has elapsed. [GL #3132]
|
||||
|
||||
5806. [bug] An error in checking the "blackhole" ACL could cause
|
||||
DNS requests sent by named to fail if the
|
||||
destination address or prefix was specifically
|
||||
excluded from the ACL. [GL #3157]
|
||||
|
||||
5805. [func] The result of each resolver priming attempt is now
|
||||
included in the "resolver priming query complete" log
|
||||
message. [GL #3139]
|
||||
|
||||
5804. [func] Add a debug log message when starting and ending
|
||||
the task exclusive mode. [GL #3137]
|
||||
|
||||
5803. [func] Use compile-time paths in the documentation.
|
||||
[GL #2717]
|
||||
|
||||
5802. [test] Add system test to test engine_pkcs11. [GL !5727]
|
||||
|
||||
5801. [bug] Log "quota reached" message when hard quota
|
||||
is reached when accepting a connection. [GL #3125]
|
||||
|
||||
5800. [func] Add ECS support to the DLZ interface. [GL #3082]
|
||||
|
||||
5799. [bug] Use L1 cache-line size detected at runtime. [GL #3108]
|
||||
|
||||
5798. [test] Add system test to test dnssec-keyfromlabel. [GL #3092]
|
||||
|
||||
5797. [bug] A failed view configuration during a named
|
||||
reconfiguration procedure could cause inconsistencies
|
||||
in BIND internal structures, causing a crash or other
|
||||
unexpected errors. [GL #3060]
|
||||
|
||||
5796. [bug] Ignore the invalid (<= 0) values returned
|
||||
by the sysconf() check for the L1 cache line
|
||||
size. [GL #3108]
|
||||
|
||||
+32
-10
@@ -9,6 +9,16 @@ AM_V_SPHINX_0 = @echo " SPHINX $@";
|
||||
|
||||
SPHINXBUILDDIR = $(builddir)/_build
|
||||
|
||||
LF = \n
|
||||
RNDC_CONF = .. |rndc_conf| replace:: ``$(sysconfdir)/rndc.conf``
|
||||
RNDC_KEY = .. |rndc_key| replace:: ``$(sysconfdir)/rndc.key``
|
||||
NAMED_CONF = .. |named_conf| replace:: ``$(sysconfdir)/named.conf``
|
||||
BIND_KEYS = .. |bind_keys| replace:: ``$(sysconfdir)/bind.keys``
|
||||
NAMED_PID = .. |named_pid| replace:: ``$(runstatedir)/named.pid``
|
||||
SESSION_KEY = .. |session_key| replace:: ``$(runstatedir)/session.key``
|
||||
|
||||
export RST_EPILOG = $(RNDC_CONF)$(LF)$(RNDC_KEY)$(LF)$(NAMED_CONF)$(LF)$(BIND_KEYS)$(LF)$(NAMED_PID)$(LF)$(SESSION_KEY)
|
||||
|
||||
common_SPHINXOPTS = \
|
||||
-W \
|
||||
-c $(srcdir) \
|
||||
@@ -17,18 +27,30 @@ common_SPHINXOPTS = \
|
||||
|
||||
# The "today" variable set below is not directly used in the ARM, but its value
|
||||
# is implicitly inserted on the title page of the PDF file produced by Sphinx.
|
||||
ALLSPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D today="$(RELEASE_DATE)" \
|
||||
$(SPHINXOPTS) \
|
||||
ALLSPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D today="$(RELEASE_DATE)" \
|
||||
-D rst_epilog="$$(printf "$${RST_EPILOG}")" \
|
||||
$(SPHINXOPTS) \
|
||||
$(srcdir)
|
||||
|
||||
man_SPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D version="@""PACKAGE_VERSION@"\
|
||||
-D today="@""RELEASE_DATE@" \
|
||||
-D release="@""PACKAGE_VERSION@"\
|
||||
$(SPHINXOPTS) \
|
||||
_ = @
|
||||
man_RNDC_CONF = .. |rndc_conf| replace:: ``$(_)sysconfdir$(_)/rndc.conf``
|
||||
man_RNDC_KEY = .. |rndc_key| replace:: ``$(_)sysconfdir$(_)/rndc.key``
|
||||
man_NAMED_CONF = .. |named_conf| replace:: ``$(_)sysconfdir$(_)/named.conf``
|
||||
man_BIND_KEYS = .. |bind_keys| replace:: ``$(_)sysconfdir$(_)/bind.keys``
|
||||
man_NAMED_PID = .. |named_pid| replace:: ``$(_)runstatedir$(_)/named.pid``
|
||||
man_SESSION_KEY = .. |session_key| replace:: ``$(_)runstatedir$(_)/session.key``
|
||||
|
||||
export man_RST_EPILOG = $(man_RNDC_CONF)$(LF)$(man_RNDC_KEY)$(LF)$(man_NAMED_CONF)$(LF)$(man_BIND_KEYS)$(LF)$(man_NAMED_PID)$(LF)$(man_SESSION_KEY)
|
||||
|
||||
man_SPHINXOPTS = \
|
||||
$(common_SPHINXOPTS) \
|
||||
-D version="@""PACKAGE_VERSION@" \
|
||||
-D today="@""RELEASE_DATE@" \
|
||||
-D release="@""PACKAGE_VERSION@" \
|
||||
-D rst_epilog="$$(printf "$${man_RST_EPILOG}")" \
|
||||
$(SPHINXOPTS) \
|
||||
$(srcdir)
|
||||
|
||||
AM_V_SED = $(AM_V_SED_@AM_V@)
|
||||
|
||||
@@ -7,6 +7,9 @@ TESTS = $(check_PROGRAMS)
|
||||
|
||||
LOG_COMPILER = $(builddir)/../../unit-test-driver.sh
|
||||
|
||||
AM_CFLAGS += \
|
||||
$(TEST_CFLAGS)
|
||||
|
||||
AM_CPPFLAGS += \
|
||||
$(CMOCKA_CFLAGS) \
|
||||
-DNAMED_PLUGINDIR=\"$(libdir)/named\" \
|
||||
|
||||
-119
@@ -1,119 +0,0 @@
|
||||
<!--
|
||||
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
|
||||
SPDX-License-Identifier: MPL-2.0
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
|
||||
See the COPYRIGHT file distributed with this work for additional
|
||||
information regarding copyright ownership.
|
||||
-->
|
||||
## Supported platforms
|
||||
|
||||
In general, this version of BIND will build and run on any POSIX-compliant
|
||||
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
||||
IPv6 support, and POSIX-compliant threads, plus the following mandatory
|
||||
libraries:
|
||||
|
||||
- `libuv` for asynchronous I/O operations and event loops
|
||||
- `libssl` and `libcrypto` from OpenSSL for cryptography
|
||||
|
||||
Use of the following libraries is optional:
|
||||
|
||||
- `libjemalloc` for improved memory allocation performance
|
||||
- `libnghttp2` for DNS-over-HTTPS (DoH) support
|
||||
|
||||
The following C11 features are used in BIND 9:
|
||||
|
||||
* Atomic operations support, either in the form of C11 atomics or
|
||||
`__atomic` builtin operations.
|
||||
|
||||
* Thread Local Storage support, either in the form of C11
|
||||
`_Thread_local`/`thread_local`, or the `__thread` GCC extension.
|
||||
|
||||
The C11 variants are preferred.
|
||||
|
||||
BIND 9.17 requires a fairly recent version of `libuv` (at least 1.x). For
|
||||
some of the older systems listed below, you will have to install an updated
|
||||
`libuv` package from sources such as EPEL, PPA, or other native sources for
|
||||
updated packages. The other option is to build and install `libuv` from
|
||||
source.
|
||||
|
||||
Certain optional BIND features have additional library dependencies.
|
||||
These include:
|
||||
|
||||
* `libfstrm` and `libprotobuf-c` for DNSTAP
|
||||
* `libidn2` for display of internationalized domain names in `dig`
|
||||
* `libjson-c` for JSON statistics
|
||||
* `libmaxminddb` for geolocation
|
||||
* `libnghttp2` for DNS over HTTPS
|
||||
* `libxml2` for XML statistics
|
||||
* `libz` for compression of the HTTP statistics channel
|
||||
* `readline` for line editing in `nsupdate` and `nslookup`
|
||||
|
||||
ISC regularly tests BIND on many operating systems and architectures, but
|
||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||
offer support on a "best effort" basis for some.
|
||||
|
||||
### Regularly tested platforms
|
||||
|
||||
As of Dec 2021, BIND 9.17 is fully supported and regularly tested on the
|
||||
following systems:
|
||||
|
||||
* Debian 9, 10, 11
|
||||
* Ubuntu LTS 18.04, 20.04
|
||||
* Fedora 35
|
||||
* Red Hat Enterprise Linux / CentOS / Oracle Linux 7, 8
|
||||
* FreeBSD 12.3, 13.0
|
||||
* OpenBSD 7.0
|
||||
* Alpine Linux 3.15
|
||||
|
||||
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
||||
|
||||
### Best effort
|
||||
|
||||
The following are platforms on which BIND is known to build and run.
|
||||
ISC makes every effort to fix bugs on these platforms, but may be unable
|
||||
to do so quickly due to lack of hardware, less familiarity on the part
|
||||
of engineering staff, and other constraints. None of these are tested
|
||||
regularly by ISC.
|
||||
|
||||
* macOS 10.12+
|
||||
* Solaris 11
|
||||
* NetBSD
|
||||
* Other Linux distributions still supported by their vendors, such as:
|
||||
* Ubuntu 20.10+
|
||||
* Gentoo
|
||||
* Arch Linux
|
||||
* OpenWRT/LEDE 17.01+
|
||||
* Other CPU architectures (mips, mipsel, sparc, ...)
|
||||
|
||||
### Community maintained
|
||||
|
||||
These systems may not all have the required dependencies for building BIND
|
||||
easily available, although it will be possible in many cases to compile
|
||||
those directly from source. The community and interested parties may wish
|
||||
to help with maintenance, and we welcome patch contributions, although we
|
||||
cannot guarantee that we will accept them. All contributions will be
|
||||
assessed against the risk of adverse effect on officially supported
|
||||
platforms.
|
||||
|
||||
* Platforms past or close to their respective EOL dates, such as:
|
||||
* Ubuntu 14.04, 16.04 (Ubuntu ESM releases are not supported)
|
||||
* CentOS 6
|
||||
* Debian Jessie
|
||||
* FreeBSD 10.x, 11.x
|
||||
|
||||
## Unsupported platforms
|
||||
|
||||
These are platforms on which BIND 9.17 is known *not* to build or run:
|
||||
|
||||
* Platforms without at least OpenSSL 1.0.2
|
||||
* Windows
|
||||
* Solaris 10 and older
|
||||
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
||||
* Platforms that don't support atomic operations (via compiler or library)
|
||||
* Linux without NPTL (Native POSIX Thread Library)
|
||||
* Platforms on which `libuv` cannot be compiled
|
||||
@@ -18,9 +18,6 @@ information regarding copyright ownership.
|
||||
1. [Reporting bugs and getting help](#help)
|
||||
1. [Contributing to BIND](#contrib)
|
||||
1. [Building BIND](#build)
|
||||
1. [macOS](#macos)
|
||||
1. [Dependencies](#dependencies)
|
||||
1. [Compile-time options](#opts)
|
||||
1. [Automated testing](#testing)
|
||||
1. [Documentation](#doc)
|
||||
1. [Change log](#changes)
|
||||
@@ -58,7 +55,9 @@ CHANGES file format.
|
||||
For up-to-date versions and release notes, see
|
||||
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||
|
||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
||||
For information about supported platforms, see the
|
||||
["Supported Platforms"](doc/arm/platforms.rst) section in the BIND 9
|
||||
Administrator Reference Manual.
|
||||
|
||||
### <a name="help"/> Reporting bugs and getting help
|
||||
|
||||
@@ -125,142 +124,9 @@ including your patch as an attachment, preferably generated by
|
||||
|
||||
### <a name="build"/> Building BIND 9
|
||||
|
||||
At a minimum, BIND requires a Unix or Linux system with an ANSI C compiler,
|
||||
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||
`libuv` asynchronous I/O library, the `nghttp2` HTTP/2 library, the
|
||||
`jemalloc` memory allocation library, and the OpenSSL cryptography
|
||||
library. On Linux, BIND requires the `libcap` library to set process
|
||||
privileges, though this requirement can be overridden by disabling
|
||||
capability support at compile time. See [Compile-time options](#opts)
|
||||
below for details on other libraries that may be required to support
|
||||
optional features.
|
||||
|
||||
Successful builds have been observed on many versions of Linux and Unix,
|
||||
including RHEL/CentOS/Oracle Linux, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
||||
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana,
|
||||
OmniOS CE, HP-UX, and OpenWRT.
|
||||
|
||||
To build on a Unix or Linux system, use:
|
||||
|
||||
$ autoreconf -fi (if you are building in the git repository)
|
||||
$ ./configure
|
||||
$ make
|
||||
|
||||
If you're using Emacs, you might find `make tags` helpful.
|
||||
|
||||
Several environment variables, which can be set before running `configure`,
|
||||
affect compilation. Significant ones are:
|
||||
|
||||
|Variable|Description |
|
||||
|--------------------|-----------------------------------------------|
|
||||
|`CC`|The C compiler to use. `configure` tries to figure out the right one for supported systems.|
|
||||
|`CFLAGS`|C compiler flags. Defaults to include -g and/or -O2 as supported by the compiler. Please include '-g' if you need to set `CFLAGS`. |
|
||||
|`LDFLAGS`|Linker flags. Defaults to empty string.|
|
||||
|
||||
Additional environment variables affecting the build are listed at the
|
||||
end of the `configure` help text, which can be obtained by running the
|
||||
command:
|
||||
|
||||
$ ./configure --help
|
||||
|
||||
#### <a name="macos"> macOS
|
||||
|
||||
Building on macOS assumes that the "Command Tools for Xcode" are installed.
|
||||
These can be downloaded from
|
||||
[https://developer.apple.com/download/more/](https://developer.apple.com/download/more/)
|
||||
or, if you have Xcode already installed, you can run `xcode-select --install`.
|
||||
(Note that an Apple ID may be required to access the download page.)
|
||||
|
||||
#### <a name="dependencies"> Dependencies
|
||||
|
||||
To build BIND you need to have the following packages installed:
|
||||
|
||||
libuv
|
||||
pkg-config / pkgconfig / pkgconf
|
||||
|
||||
To build BIND from the git repository, you need the following tools
|
||||
installed:
|
||||
|
||||
autoconf (includes autoreconf)
|
||||
automake
|
||||
libtool
|
||||
|
||||
#### <a name="opts"/> Compile-time options
|
||||
|
||||
To see a full list of configuration options, run `configure --help`.
|
||||
|
||||
For the server to support DNSSEC, you need to build it with crypto support.
|
||||
To use OpenSSL, you must have OpenSSL 1.0.2e or newer installed. If the
|
||||
OpenSSL library is installed in a nonstandard location, specify the prefix
|
||||
using `--with-openssl=<PREFIX>` on the configure command line. To use a
|
||||
PKCS#11 hardware service module for cryptographic operations, it will
|
||||
be necessary to compile and use engine_pkcs11 from the OpenSC project.
|
||||
|
||||
To support DNS over HTTPS, the server must be linked with `libnghttp2`.
|
||||
|
||||
To support the HTTP statistics channel, the server must be linked with at
|
||||
least one of the following libraries: `libxml2`
|
||||
[http://xmlsoft.org](http://xmlsoft.org) or `json-c`
|
||||
[https://github.com/json-c/json-c](https://github.com/json-c/json-c).
|
||||
If these are installed at a nonstandard location, then:
|
||||
|
||||
* for `libxml2`, specify the prefix using `--with-libxml2=/prefix`.
|
||||
* for `json-c`, adjust `PKG_CONFIG_PATH`.
|
||||
|
||||
To support compression on the HTTP statistics channel, the server must be
|
||||
linked against `libzlib`. If this is installed in a nonstandard location,
|
||||
specify the prefix using `--with-zlib=/prefix`.
|
||||
|
||||
To support storing configuration data for runtime-added zones in an LMDB
|
||||
database, the server must be linked with `liblmdb`. If this is installed in a
|
||||
nonstandard location, specify the prefix using `with-lmdb=/prefix`.
|
||||
|
||||
To support MaxMind GeoIP2 location-based ACLs, the server must be linked
|
||||
with `libmaxminddb`. This is turned on by default if the library is
|
||||
found; if the library is installed in a nonstandard location,
|
||||
specify the prefix using `--with-maxminddb=/prefix`. GeoIP2 support
|
||||
can be switched off with `--disable-geoip`.
|
||||
|
||||
For DNSTAP packet logging, you must have installed `libfstrm`
|
||||
[https://github.com/farsightsec/fstrm](https://github.com/farsightsec/fstrm)
|
||||
and `libprotobuf-c`
|
||||
[https://developers.google.com/protocol-buffers](https://developers.google.com/protocol-buffers),
|
||||
and BIND must be configured with `--enable-dnstap`.
|
||||
|
||||
Certain compiled-in constants and default settings can be decreased to
|
||||
values better suited to small machines, e.g. OpenWRT boxes, by specifying
|
||||
`--with-tuning=small` on the `configure` command line. This decreases
|
||||
memory usage by using smaller structures, but degrades performance.
|
||||
|
||||
On Linux, process capabilities are managed in user space using
|
||||
the `libcap` library, which can be installed on most Linux systems via
|
||||
the `libcap-dev` or `libcap-devel` package. Process capability support can
|
||||
also be disabled by configuring with `--disable-linux-caps`.
|
||||
|
||||
On some platforms it is necessary to explicitly request large file support
|
||||
to handle files bigger than 2GB. This can be done by using
|
||||
`--enable-largefile` on the `configure` command line.
|
||||
|
||||
Support for the "fixed" rrset-order option can be enabled or disabled by
|
||||
specifying `--enable-fixed-rrset` or `--disable-fixed-rrset` on the
|
||||
configure command line. By default, fixed rrset-order is disabled to
|
||||
reduce memory footprint.
|
||||
|
||||
The `--enable-querytrace` option causes `named` to log every step of
|
||||
processing every query. The `--enable-singletrace` option turns on the
|
||||
same verbose tracing, but allows an individual query to be separately
|
||||
traced by setting its query ID to 0. These options should only be enabled
|
||||
when debugging, because they have a significant negative impact on query
|
||||
performance.
|
||||
|
||||
`make install` installs `named` and the various BIND 9 libraries. By
|
||||
default, installation is into /usr/local, but this can be changed with the
|
||||
`--prefix` option when running `configure`.
|
||||
|
||||
You may specify the option `--sysconfdir` to set the directory where
|
||||
configuration files like `named.conf` go by default, and `--localstatedir`
|
||||
to set the default parent directory of `run/named.pid`. `--sysconfdir`
|
||||
defaults to `$prefix/etc` and `--localstatedir` defaults to `$prefix/var`.
|
||||
For information about building BIND 9, see the
|
||||
["Building BIND 9"](doc/arm/build.rst) section in the BIND 9
|
||||
Administrator Reference Manual.
|
||||
|
||||
### <a name="testing"/> Automated testing
|
||||
|
||||
|
||||
@@ -593,7 +593,7 @@ load_zone(isc_mem_t *mctx, const char *zonename, const char *filename,
|
||||
zonename, filename, classname);
|
||||
}
|
||||
|
||||
CHECK(dns_zone_create(&zone, mctx));
|
||||
CHECK(dns_zone_create(&zone, mctx, 0));
|
||||
|
||||
dns_zone_settype(zone, dns_zone_primary);
|
||||
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named-checkconf
|
||||
.. program:: named-checkconf
|
||||
.. _man_named-checkconf:
|
||||
|
||||
named-checkconf - named configuration file syntax checking tool
|
||||
@@ -24,72 +26,83 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named-checkconf`` checks the syntax, but not the semantics, of a
|
||||
``named`` configuration file. The file, along with all files included by it, is parsed and checked for syntax
|
||||
:program:`named-checkconf` checks the syntax, but not the semantics, of a
|
||||
:iscman:`named` configuration file. The file, along with all files included by it, is parsed and checked for syntax
|
||||
errors. If no file is specified,
|
||||
``/etc/named.conf`` is read by default.
|
||||
|named_conf| is read by default.
|
||||
|
||||
Note: files that ``named`` reads in separate parser contexts, such as
|
||||
Note: files that :iscman:`named` reads in separate parser contexts, such as
|
||||
``rndc.key`` and ``bind.keys``, are not automatically read by
|
||||
``named-checkconf``. Configuration errors in these files may cause
|
||||
``named`` to fail to run, even if ``named-checkconf`` was successful.
|
||||
However, ``named-checkconf`` can be run on these files explicitly.
|
||||
:program:`named-checkconf`. Configuration errors in these files may cause
|
||||
:iscman:`named` to fail to run, even if :program:`named-checkconf` was successful.
|
||||
However, :program:`named-checkconf` can be run on these files explicitly.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
``-j``
|
||||
When loading a zonefile, this option instructs ``named`` to read the journal if it exists.
|
||||
.. option:: -j
|
||||
|
||||
When loading a zonefile, this option instructs :iscman:`named` to read the journal if it exists.
|
||||
|
||||
.. option:: -l
|
||||
|
||||
``-l``
|
||||
This option lists all the configured zones. Each line of output contains the zone
|
||||
name, class (e.g. IN), view, and type (e.g. primary or secondary).
|
||||
|
||||
``-c``
|
||||
.. option:: -c
|
||||
|
||||
This option specifies that only the "core" configuration should be checked. This suppresses the loading of
|
||||
plugin modules, and causes all parameters to ``plugin`` statements to
|
||||
be ignored.
|
||||
|
||||
``-i``
|
||||
.. option:: -i
|
||||
|
||||
This option ignores warnings on deprecated options.
|
||||
|
||||
``-p``
|
||||
This option prints out the ``named.conf`` and included files in canonical form if
|
||||
no errors were detected. See also the ``-x`` option.
|
||||
.. option:: -p
|
||||
|
||||
``-t directory``
|
||||
This option instructs ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
||||
This option prints out the :iscman:`named.conf` and included files in canonical form if
|
||||
no errors were detected. See also the :option:`-x` option.
|
||||
|
||||
.. option:: -t directory
|
||||
|
||||
This option instructs :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
``named``.
|
||||
:iscman:`named`.
|
||||
|
||||
``-v``
|
||||
This option prints the version of the ``named-checkconf`` program and exits.
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version of the :program:`named-checkconf` program and exits.
|
||||
|
||||
.. option:: -x
|
||||
|
||||
``-x``
|
||||
When printing the configuration files in canonical form, this option obscures
|
||||
shared secrets by replacing them with strings of question marks
|
||||
(``?``). This allows the contents of ``named.conf`` and related files
|
||||
(``?``). This allows the contents of :iscman:`named.conf` and related files
|
||||
to be shared - for example, when submitting bug reports -
|
||||
without compromising private data. This option cannot be used without
|
||||
``-p``.
|
||||
:option:`-p`.
|
||||
|
||||
``-z``
|
||||
This option performs a test load of all zones of type ``primary`` found in ``named.conf``.
|
||||
.. option:: -z
|
||||
|
||||
This option performs a test load of all zones of type ``primary`` found in :iscman:`named.conf`.
|
||||
|
||||
.. option:: filename
|
||||
|
||||
``filename``
|
||||
This indicates the name of the configuration file to be checked. If not specified,
|
||||
it defaults to ``/etc/named.conf``.
|
||||
it defaults to |named_conf|.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``named-checkconf`` returns an exit status of 1 if errors were detected
|
||||
:program:`named-checkconf` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkzone(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkzone(8) <named-checkzone>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
@@ -11,60 +11,65 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
named-checkzone, named-compilezone - zone file validity checking or converting tool
|
||||
-----------------------------------------------------------------------------------
|
||||
.. BEWARE: Do not forget to edit also named-compilezone.rst!
|
||||
|
||||
.. iscman:: named-checkzone
|
||||
.. program:: named-checkzone
|
||||
.. _man_named-checkzone:
|
||||
|
||||
named-checkzone - zone file validation tool
|
||||
-------------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
:program:`named-checkzone` [**-d**] [**-h**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-M** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-o** filename] [**-r** mode] [**-s** style] [**-S** mode] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {zonename} {filename}
|
||||
|
||||
:program:`named-compilezone` [**-d**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-C** mode] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-r** mode] [**-s** style] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {**-o** filename} {zonename} {filename}
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named-checkzone`` checks the syntax and integrity of a zone file. It
|
||||
performs the same checks as ``named`` does when loading a zone. This
|
||||
makes ``named-checkzone`` useful for checking zone files before
|
||||
:program:`named-checkzone` checks the syntax and integrity of a zone file. It
|
||||
performs the same checks as :iscman:`named` does when loading a zone. This
|
||||
makes :program:`named-checkzone` useful for checking zone files before
|
||||
configuring them into a name server.
|
||||
|
||||
``named-compilezone`` is similar to ``named-checkzone``, but it always
|
||||
dumps the zone contents to a specified file in a specified format.
|
||||
It also applies stricter check levels by default, since the
|
||||
dump output is used as an actual zone file loaded by ``named``.
|
||||
When manually specified otherwise, the check levels must at least be as
|
||||
strict as those specified in the ``named`` configuration file.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-d``
|
||||
.. option:: -d
|
||||
|
||||
This option enables debugging.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which only sets an exit code to indicate
|
||||
successful or failed completion.
|
||||
|
||||
``-v``
|
||||
This option prints the version of the ``named-checkzone`` program and exits.
|
||||
.. option:: -v
|
||||
|
||||
``-j``
|
||||
When loading a zone file, this option tells ``named`` to read the journal if it exists. The journal
|
||||
This option prints the version of the :program:`named-checkzone` program and exits.
|
||||
|
||||
.. option:: -j
|
||||
|
||||
When loading a zone file, this option tells :iscman:`named` to read the journal if it exists. The journal
|
||||
file name is assumed to be the zone file name with the
|
||||
string ``.jnl`` appended.
|
||||
|
||||
``-J filename``
|
||||
When loading the zone file, this option tells ``named`` to read the journal from the given file, if
|
||||
it exists. This implies ``-j``.
|
||||
.. option:: -J filename
|
||||
|
||||
When loading the zone file, this option tells :iscman:`named` to read the journal from the given file, if
|
||||
it exists. This implies :option:`-j`.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option specifies the class of the zone. If not specified, ``IN`` is assumed.
|
||||
|
||||
``-i mode``
|
||||
.. option:: -i mode
|
||||
|
||||
This option performs post-load zone integrity checks. Possible modes are
|
||||
``full`` (the default), ``full-sibling``, ``local``,
|
||||
``local-sibling``, and ``none``.
|
||||
@@ -90,113 +95,128 @@ Options
|
||||
|
||||
Mode ``none`` disables the checks.
|
||||
|
||||
``-f format``
|
||||
.. option:: -f format
|
||||
|
||||
This option specifies the format of the zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``.
|
||||
|
||||
``-F format``
|
||||
.. option:: -F format
|
||||
|
||||
This option specifies the format of the output file specified. For
|
||||
``named-checkzone``, this does not have any effect unless it dumps
|
||||
:program:`named-checkzone`, this does not have any effect unless it dumps
|
||||
the zone contents.
|
||||
|
||||
Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone, and ``raw`` and ``raw=N``, which
|
||||
store the zone in a binary format for rapid loading by ``named``.
|
||||
store the zone in a binary format for rapid loading by :iscman:`named`.
|
||||
``raw=N`` specifies the format version of the raw zone file: if ``N`` is
|
||||
0, the raw file can be read by any version of ``named``; if N is 1, the
|
||||
0, the raw file can be read by any version of :iscman:`named`; if N is 1, the
|
||||
file can only be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
``-k mode``
|
||||
.. option:: -k mode
|
||||
|
||||
This option performs ``check-names`` checks with the specified failure mode.
|
||||
Possible modes are ``fail`` (the default for ``named-compilezone``),
|
||||
``warn`` (the default for ``named-checkzone``), and ``ignore``.
|
||||
Possible modes are ``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -l ttl
|
||||
|
||||
``-l ttl``
|
||||
This option sets a maximum permissible TTL for the input file. Any record with a
|
||||
TTL higher than this value causes the zone to be rejected. This
|
||||
is similar to using the ``max-zone-ttl`` option in ``named.conf``.
|
||||
is similar to using the ``max-zone-ttl`` option in :iscman:`named.conf`.
|
||||
|
||||
.. option:: -L serial
|
||||
|
||||
``-L serial``
|
||||
When compiling a zone to ``raw`` format, this option sets the "source
|
||||
serial" value in the header to the specified serial number. This is
|
||||
expected to be used primarily for testing purposes.
|
||||
|
||||
``-m mode``
|
||||
.. option:: -m mode
|
||||
|
||||
This option specifies whether MX records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and
|
||||
``ignore``.
|
||||
|
||||
``-M mode``
|
||||
.. option:: -M mode
|
||||
|
||||
This option checks whether a MX record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-n mode``
|
||||
.. option:: -n mode
|
||||
|
||||
This option specifies whether NS records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail`` (the default for
|
||||
``named-compilezone``), ``warn`` (the default for ``named-checkzone``),
|
||||
and ``ignore``.
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -o filename
|
||||
|
||||
``-o filename``
|
||||
This option writes the zone output to ``filename``. If ``filename`` is ``-``, then
|
||||
the zone output is written to standard output. This is mandatory for ``named-compilezone``.
|
||||
the zone output is written to standard output.
|
||||
|
||||
.. option:: -r mode
|
||||
|
||||
``-r mode``
|
||||
This option checks for records that are treated as different by DNSSEC but are
|
||||
semantically equal in plain DNS. Possible modes are ``fail``,
|
||||
``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-s style``
|
||||
.. option:: -s style
|
||||
|
||||
This option specifies the style of the dumped zone file. Possible styles are
|
||||
``full`` (the default) and ``relative``. The ``full`` format is most
|
||||
suitable for processing automatically by a separate script.
|
||||
The relative format is more human-readable and is thus
|
||||
suitable for editing by hand. For ``named-checkzone``, this does not
|
||||
have any effect unless it dumps the zone contents. It also does not
|
||||
have any meaning if the output format is not text.
|
||||
suitable for editing by hand. This does not have any effect unless it dumps
|
||||
the zone contents. It also does not have any meaning if the output format
|
||||
is not text.
|
||||
|
||||
.. option:: -S mode
|
||||
|
||||
``-S mode``
|
||||
This option checks whether an SRV record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
``-t directory``
|
||||
This option tells ``named`` to chroot to ``directory``, so that ``include`` directives in the
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
``named``.
|
||||
:iscman:`named`.
|
||||
|
||||
.. option:: -T mode
|
||||
|
||||
``-T mode``
|
||||
This option checks whether Sender Policy Framework (SPF) records exist and issues a
|
||||
warning if an SPF-formatted TXT record is not also present. Possible
|
||||
modes are ``warn`` (the default) and ``ignore``.
|
||||
|
||||
``-w directory``
|
||||
This option instructs ``named`` to chdir to ``directory``, so that relative filenames in master file
|
||||
.. option:: -w directory
|
||||
|
||||
This option instructs :iscman:`named` to chdir to ``directory``, so that relative filenames in master file
|
||||
``$INCLUDE`` directives work. This is similar to the directory clause in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
``-D``
|
||||
This option dumps the zone file in canonical format. This is always enabled for
|
||||
``named-compilezone``.
|
||||
.. option:: -D
|
||||
|
||||
This option dumps the zone file in canonical format.
|
||||
|
||||
.. option:: -W mode
|
||||
|
||||
``-W mode``
|
||||
This option specifies whether to check for non-terminal wildcards. Non-terminal
|
||||
wildcards are almost always the result of a failure to understand the
|
||||
wildcard matching algorithm (:rfc:`1034`). Possible modes are ``warn``
|
||||
wildcard matching algorithm (:rfc:`4592`). Possible modes are ``warn``
|
||||
(the default) and ``ignore``.
|
||||
|
||||
``zonename``
|
||||
.. option:: zonename
|
||||
|
||||
This indicates the domain name of the zone being checked.
|
||||
|
||||
``filename``
|
||||
.. option:: filename
|
||||
|
||||
This is the name of the zone file.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``named-checkzone`` returns an exit status of 1 if errors were detected
|
||||
:program:`named-checkzone` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkconf(8)`, :rfc:`1035`, BIND 9 Administrator Reference
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-compilezone(8) <named-compilezone>`, :rfc:`1035`, BIND 9 Administrator Reference
|
||||
Manual.
|
||||
|
||||
@@ -0,0 +1,224 @@
|
||||
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
..
|
||||
.. SPDX-License-Identifier: MPL-2.0
|
||||
..
|
||||
.. This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.. License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
..
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. BEWARE: Do not forget to edit also named-checkzone.rst!
|
||||
|
||||
.. iscman:: named-compilezone
|
||||
.. program:: named-compilezone
|
||||
.. _man_named-compilezone:
|
||||
|
||||
named-compilezone - zone file converting tool
|
||||
---------------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` [**-d**] [**-h**] [**-j**] [**-q**] [**-v**] [**-c** class] [**-f** format] [**-F** format] [**-J** filename] [**-i** mode] [**-k** mode] [**-m** mode] [**-M** mode] [**-n** mode] [**-l** ttl] [**-L** serial] [**-r** mode] [**-s** style] [**-S** mode] [**-t** directory] [**-T** mode] [**-w** directory] [**-D**] [**-W** mode] {**-o** filename} {zonename} {filename}
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` checks the syntax and integrity of a zone file,
|
||||
and dumps the zone contents to a specified file in a specified format.
|
||||
It applies strict check levels by default, since the
|
||||
dump output is used as an actual zone file loaded by :iscman:`named`.
|
||||
When manually specified otherwise, the check levels must at least be as
|
||||
strict as those specified in the :iscman:`named` configuration file.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
.. option:: -d
|
||||
|
||||
This option enables debugging.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
This option prints the usage summary and exits.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which only sets an exit code to indicate
|
||||
successful or failed completion.
|
||||
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version of the :iscman:`named-checkzone` program and exits.
|
||||
|
||||
.. option:: -j
|
||||
|
||||
When loading a zone file, this option tells :iscman:`named` to read the journal if it exists. The journal
|
||||
file name is assumed to be the zone file name with the
|
||||
string ``.jnl`` appended.
|
||||
|
||||
.. option:: -J filename
|
||||
|
||||
When loading the zone file, this option tells :iscman:`named` to read the journal from the given file, if
|
||||
it exists. This implies :option:`-j`.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the class of the zone. If not specified, ``IN`` is assumed.
|
||||
|
||||
.. option:: -i mode
|
||||
|
||||
This option performs post-load zone integrity checks. Possible modes are
|
||||
``full`` (the default), ``full-sibling``, ``local``,
|
||||
``local-sibling``, and ``none``.
|
||||
|
||||
Mode ``full`` checks that MX records refer to A or AAAA records
|
||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
||||
checks MX records which refer to in-zone hostnames.
|
||||
|
||||
Mode ``full`` checks that SRV records refer to A or AAAA records
|
||||
(both in-zone and out-of-zone hostnames). Mode ``local`` only
|
||||
checks SRV records which refer to in-zone hostnames.
|
||||
|
||||
Mode ``full`` checks that delegation NS records refer to A or AAAA
|
||||
records (both in-zone and out-of-zone hostnames). It also checks that
|
||||
glue address records in the zone match those advertised by the child.
|
||||
Mode ``local`` only checks NS records which refer to in-zone
|
||||
hostnames or verifies that some required glue exists, i.e., when the
|
||||
name server is in a child zone.
|
||||
|
||||
Modes ``full-sibling`` and ``local-sibling`` disable sibling glue
|
||||
checks, but are otherwise the same as ``full`` and ``local``,
|
||||
respectively.
|
||||
|
||||
Mode ``none`` disables the checks.
|
||||
|
||||
.. option:: -f format
|
||||
|
||||
This option specifies the format of the zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``.
|
||||
|
||||
.. option:: -F format
|
||||
|
||||
This option specifies the format of the output file specified. For
|
||||
:iscman:`named-checkzone`, this does not have any effect unless it dumps
|
||||
the zone contents.
|
||||
|
||||
Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone, and ``raw`` and ``raw=N``, which
|
||||
store the zone in a binary format for rapid loading by :iscman:`named`.
|
||||
``raw=N`` specifies the format version of the raw zone file: if ``N`` is
|
||||
0, the raw file can be read by any version of :iscman:`named`; if N is 1, the
|
||||
file can only be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
.. option:: -k mode
|
||||
|
||||
This option performs ``check-names`` checks with the specified failure mode.
|
||||
Possible modes are ``fail`` (the default), ``warn``, and ``ignore``.
|
||||
|
||||
.. option:: -l ttl
|
||||
|
||||
This option sets a maximum permissible TTL for the input file. Any record with a
|
||||
TTL higher than this value causes the zone to be rejected. This
|
||||
is similar to using the ``max-zone-ttl`` option in :iscman:`named.conf`.
|
||||
|
||||
.. option:: -L serial
|
||||
|
||||
When compiling a zone to ``raw`` format, this option sets the "source
|
||||
serial" value in the header to the specified serial number. This is
|
||||
expected to be used primarily for testing purposes.
|
||||
|
||||
.. option:: -m mode
|
||||
|
||||
This option specifies whether MX records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail``, ``warn`` (the default), and
|
||||
``ignore``.
|
||||
|
||||
.. option:: -M mode
|
||||
|
||||
This option checks whether a MX record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -n mode
|
||||
|
||||
This option specifies whether NS records should be checked to see if they are
|
||||
addresses. Possible modes are ``fail`` (the default), ``warn``, and
|
||||
``ignore``.
|
||||
|
||||
.. option:: -o filename
|
||||
|
||||
This option writes the zone output to ``filename``. If ``filename`` is ``-``, then
|
||||
the zone output is written to standard output. This is mandatory for :program:`named-compilezone`.
|
||||
|
||||
.. option:: -r mode
|
||||
|
||||
This option checks for records that are treated as different by DNSSEC but are
|
||||
semantically equal in plain DNS. Possible modes are ``fail``,
|
||||
``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -s style
|
||||
|
||||
This option specifies the style of the dumped zone file. Possible styles are
|
||||
``full`` (the default) and ``relative``. The ``full`` format is most
|
||||
suitable for processing automatically by a separate script.
|
||||
The relative format is more human-readable and is thus
|
||||
suitable for editing by hand.
|
||||
|
||||
.. option:: -S mode
|
||||
|
||||
This option checks whether an SRV record refers to a CNAME. Possible modes are
|
||||
``fail``, ``warn`` (the default), and ``ignore``.
|
||||
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :iscman:`named` to chroot to ``directory``, so that ``include`` directives in the
|
||||
configuration file are processed as if run by a similarly chrooted
|
||||
:iscman:`named`.
|
||||
|
||||
.. option:: -T mode
|
||||
|
||||
This option checks whether Sender Policy Framework (SPF) records exist and issues a
|
||||
warning if an SPF-formatted TXT record is not also present. Possible
|
||||
modes are ``warn`` (the default) and ``ignore``.
|
||||
|
||||
.. option:: -w directory
|
||||
|
||||
This option instructs :iscman:`named` to chdir to ``directory``, so that relative filenames in master file
|
||||
``$INCLUDE`` directives work. This is similar to the directory clause in
|
||||
:iscman:`named.conf`.
|
||||
|
||||
.. option:: -D
|
||||
|
||||
This option dumps the zone file in canonical format. This is always enabled for
|
||||
:program:`named-compilezone`.
|
||||
|
||||
.. option:: -W mode
|
||||
|
||||
This option specifies whether to check for non-terminal wildcards. Non-terminal
|
||||
wildcards are almost always the result of a failure to understand the
|
||||
wildcard matching algorithm (:rfc:`4592`). Possible modes are ``warn``
|
||||
(the default) and ``ignore``.
|
||||
|
||||
.. option:: zonename
|
||||
|
||||
This indicates the domain name of the zone being checked.
|
||||
|
||||
.. option:: filename
|
||||
|
||||
This is the name of the zone file.
|
||||
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
:program:`named-compilezone` returns an exit status of 1 if errors were detected
|
||||
and 0 otherwise.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-checkzone(8) <named-checkzone>`, `:rfc:`1035`,
|
||||
BIND 9 Administrator Reference Manual.
|
||||
@@ -0,0 +1,96 @@
|
||||
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
..
|
||||
.. SPDX-License-Identifier: MPL-2.0
|
||||
..
|
||||
.. This Source Code Form is subject to the terms of the Mozilla Public
|
||||
.. License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
..
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. BEWARE: Do not forget to edit also tsig-keygen.rst!
|
||||
|
||||
.. iscman:: ddns-confgen
|
||||
.. program:: ddns-confgen
|
||||
.. _man_ddns-confgen:
|
||||
|
||||
ddns-confgen - TSIG key generation tool
|
||||
---------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-s** name] [**-z** zone]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
:program:`ddns-confgen` is an utility that generates keys for use in TSIG signing.
|
||||
The resulting keys can be used, for example, to secure dynamic DNS updates
|
||||
to a zone, or for the :iscman:`rndc` command channel.
|
||||
|
||||
The key name can specified using :option:`-k` parameter and defaults to ``ddns-key``.
|
||||
The generated key is accompanied by configuration text and instructions that
|
||||
can be used with :iscman:`nsupdate` and :iscman:`named` when setting up dynamic DNS,
|
||||
including an example ``update-policy`` statement.
|
||||
(This usage is similar to the :iscman:`rndc-confgen` command for setting up
|
||||
command-channel security.)
|
||||
|
||||
Note that :iscman:`named` itself can configure a local DDNS key for use with
|
||||
:option:`nsupdate -l`; it does this when a zone is configured with
|
||||
``update-policy local;``. :program:`ddns-confgen` is only needed when a more
|
||||
elaborate configuration is required: for instance, if :iscman:`nsupdate` is to
|
||||
be used from a remote system.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384,
|
||||
and hmac-sha512. The default is hmac-sha256. Options are
|
||||
case-insensitive, and the "hmac-" prefix may be omitted.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of options and arguments.
|
||||
|
||||
.. option:: -k keyname
|
||||
|
||||
This option specifies the key name of the DDNS authentication key. The
|
||||
default is ``ddns-key`` when neither the :option:`-s` nor :option:`-z` option is
|
||||
specified; otherwise, the default is ``ddns-key`` as a separate label
|
||||
followed by the argument of the option, e.g., ``ddns-key.example.com.``
|
||||
The key name must have the format of a valid domain name, consisting of
|
||||
letters, digits, hyphens, and periods.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
This option enables quiet mode, which prints only the key, with no
|
||||
explanatory text or usage examples. This is essentially identical to
|
||||
:iscman:`tsig-keygen`.
|
||||
|
||||
.. option:: -s name
|
||||
|
||||
This option generates a configuration example to allow dynamic updates
|
||||
of a single hostname. The example :iscman:`named.conf` text shows how to set
|
||||
an update policy for the specified name using the "name" nametype. The
|
||||
default key name is ``ddns-key.name``. Note that the "self" nametype
|
||||
cannot be used, since the name to be updated may differ from the key
|
||||
name. This option cannot be used with the :option:`-z` option.
|
||||
|
||||
.. option:: -z zone
|
||||
|
||||
This option generates a configuration example to allow
|
||||
dynamic updates of a zone. The example :iscman:`named.conf` text shows how
|
||||
to set an update policy for the specified zone using the "zonesub"
|
||||
nametype, allowing updates to all subdomain names within that zone.
|
||||
This option cannot be used with the :option:`-s` option.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:iscman:`nsupdate(1) <nsupdate>`, :iscman:`named.conf(5) <named.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc-confgen
|
||||
.. program:: rndc-confgen
|
||||
.. _man_rndc-confgen:
|
||||
|
||||
rndc-confgen - rndc key generation tool
|
||||
@@ -24,86 +26,96 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc-confgen`` generates configuration files for ``rndc``. It can be
|
||||
used as a convenient alternative to writing the ``rndc.conf`` file and
|
||||
the corresponding ``controls`` and ``key`` statements in ``named.conf``
|
||||
by hand. Alternatively, it can be run with the ``-a`` option to set up a
|
||||
``rndc.key`` file and avoid the need for a ``rndc.conf`` file and a
|
||||
:program:`rndc-confgen` generates configuration files for :iscman:`rndc`. It can be
|
||||
used as a convenient alternative to writing the :iscman:`rndc.conf` file and
|
||||
the corresponding ``controls`` and ``key`` statements in :iscman:`named.conf`
|
||||
by hand. Alternatively, it can be run with the :option:`-a` option to set up a
|
||||
``rndc.key`` file and avoid the need for a :iscman:`rndc.conf` file and a
|
||||
``controls`` statement altogether.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a``
|
||||
This option sets automatic ``rndc`` configuration, which creates a file ``rndc.key``
|
||||
in ``/etc`` (or a different ``sysconfdir`` specified when BIND
|
||||
was built) that is read by both ``rndc`` and ``named`` on startup.
|
||||
.. option:: -a
|
||||
|
||||
This option sets automatic :iscman:`rndc` configuration, which creates a file
|
||||
|rndc_key| that is read by both :iscman:`rndc` and :iscman:`named` on startup.
|
||||
The ``rndc.key`` file defines a default command channel and
|
||||
authentication key allowing ``rndc`` to communicate with ``named`` on
|
||||
authentication key allowing :iscman:`rndc` to communicate with :iscman:`named` on
|
||||
the local host with no further configuration.
|
||||
|
||||
If a more elaborate configuration than that generated by
|
||||
``rndc-confgen -a`` is required, for example if rndc is to be used
|
||||
remotely, run ``rndc-confgen`` without the ``-a`` option
|
||||
and set up ``rndc.conf`` and ``named.conf`` as directed.
|
||||
:option:`rndc-confgen -a` is required, for example if rndc is to be used
|
||||
remotely, run :program:`rndc-confgen` without the :option:`-a` option
|
||||
and set up :iscman:`rndc.conf` and :iscman:`named.conf` as directed.
|
||||
|
||||
.. option:: -A algorithm
|
||||
|
||||
``-A algorithm``
|
||||
This option specifies the algorithm to use for the TSIG key. Available choices
|
||||
are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384, and
|
||||
hmac-sha512. The default is hmac-sha256.
|
||||
|
||||
``-b keysize``
|
||||
.. option:: -b keysize
|
||||
|
||||
This option specifies the size of the authentication key in bits. The size must be between
|
||||
1 and 512 bits; the default is the hash size.
|
||||
|
||||
``-c keyfile``
|
||||
This option is used with the ``-a`` option to specify an alternate location for
|
||||
.. option:: -c keyfile
|
||||
|
||||
This option is used with the :option:`-a` option to specify an alternate location for
|
||||
``rndc.key``.
|
||||
|
||||
``-h``
|
||||
This option prints a short summary of the options and arguments to
|
||||
``rndc-confgen``.
|
||||
.. option:: -h
|
||||
|
||||
``-k keyname``
|
||||
This option specifies the key name of the ``rndc`` authentication key. This must be a
|
||||
This option prints a short summary of the options and arguments to
|
||||
:program:`rndc-confgen`.
|
||||
|
||||
.. option:: -k keyname
|
||||
|
||||
This option specifies the key name of the :iscman:`rndc` authentication key. This must be a
|
||||
valid domain name. The default is ``rndc-key``.
|
||||
|
||||
``-p port``
|
||||
This option specifies the command channel port where ``named`` listens for
|
||||
connections from ``rndc``. The default is 953.
|
||||
.. option:: -p port
|
||||
|
||||
This option specifies the command channel port where :iscman:`named` listens for
|
||||
connections from :iscman:`rndc`. The default is 953.
|
||||
|
||||
.. option:: -q
|
||||
|
||||
``-q``
|
||||
This option prevets printing the written path in automatic configuration mode.
|
||||
|
||||
``-s address``
|
||||
This option specifies the IP address where ``named`` listens for command-channel
|
||||
connections from ``rndc``. The default is the loopback address
|
||||
.. option:: -s address
|
||||
|
||||
This option specifies the IP address where :iscman:`named` listens for command-channel
|
||||
connections from :iscman:`rndc`. The default is the loopback address
|
||||
127.0.0.1.
|
||||
|
||||
``-t chrootdir``
|
||||
This option is used with the ``-a`` option to specify a directory where ``named``
|
||||
.. option:: -t chrootdir
|
||||
|
||||
This option is used with the :option:`-a` option to specify a directory where :iscman:`named`
|
||||
runs chrooted. An additional copy of the ``rndc.key`` is
|
||||
written relative to this directory, so that it is found by the
|
||||
chrooted ``named``.
|
||||
chrooted :iscman:`named`.
|
||||
|
||||
``-u user``
|
||||
This option is used with the ``-a`` option to set the owner of the generated ``rndc.key`` file.
|
||||
If ``-t`` is also specified, only the file in the chroot
|
||||
.. option:: -u user
|
||||
|
||||
This option is used with the :option:`-a` option to set the owner of the generated ``rndc.key`` file.
|
||||
If :option:`-t` is also specified, only the file in the chroot
|
||||
area has its owner changed.
|
||||
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
To allow ``rndc`` to be used with no manual configuration, run:
|
||||
To allow :iscman:`rndc` to be used with no manual configuration, run:
|
||||
|
||||
``rndc-confgen -a``
|
||||
|
||||
To print a sample ``rndc.conf`` file and the corresponding ``controls`` and
|
||||
``key`` statements to be manually inserted into ``named.conf``, run:
|
||||
To print a sample :iscman:`rndc.conf` file and the corresponding ``controls`` and
|
||||
``key`` statements to be manually inserted into :iscman:`named.conf`, run:
|
||||
|
||||
``rndc-confgen``
|
||||
:program:`rndc-confgen`
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc(8)`, :manpage:`rndc.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`rndc(8) <rndc>`, :iscman:`rndc.conf(5) <rndc.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+19
-56
@@ -11,81 +11,44 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
tsig-keygen, ddns-confgen - TSIG key generation tool
|
||||
----------------------------------------------------
|
||||
.. BEWARE: Do not forget to edit also ddns-confgen.rst!
|
||||
|
||||
.. iscman:: tsig-keygen
|
||||
.. program:: tsig-keygen
|
||||
.. _man_tsig-keygen:
|
||||
|
||||
tsig-keygen - TSIG key generation tool
|
||||
--------------------------------------
|
||||
|
||||
Synopsis
|
||||
~~~~~~~~
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [**-r** randomfile] [name]
|
||||
|
||||
:program:`ddns-confgen` [**-a** algorithm] [**-h**] [**-k** keyname] [**-q**] [**-r** randomfile] [**-s** name] [**-z** zone]
|
||||
:program:`tsig-keygen` [**-a** algorithm] [**-h**] [name]
|
||||
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``tsig-keygen`` and ``ddns-confgen`` are invocation methods for a
|
||||
utility that generates keys for use in TSIG signing. The resulting keys
|
||||
can be used, for example, to secure dynamic DNS updates to a zone, or for
|
||||
the ``rndc`` command channel.
|
||||
:program:`tsig-keygen` is an utility that generates keys for use in TSIG signing.
|
||||
The resulting keys can be used, for example, to secure dynamic DNS updates
|
||||
to a zone, or for the :iscman:`rndc` command channel.
|
||||
|
||||
When run as ``tsig-keygen``, a domain name can be specified on the
|
||||
command line to be used as the name of the generated key. If no
|
||||
name is specified, the default is ``tsig-key``.
|
||||
|
||||
When run as ``ddns-confgen``, the key name can specified using ``-k``
|
||||
parameter and defaults to ``ddns-key``. The generated key is accompanied
|
||||
by configuration text and instructions that can be used with ``nsupdate``
|
||||
and ``named`` when setting up dynamic DNS, including an example
|
||||
``update-policy`` statement. (This usage is similar to the ``rndc-confgen``
|
||||
command for setting up command-channel security.)
|
||||
|
||||
Note that ``named`` itself can configure a local DDNS key for use with
|
||||
``nsupdate -l``; it does this when a zone is configured with
|
||||
``update-policy local;``. ``ddns-confgen`` is only needed when a more
|
||||
elaborate configuration is required: for instance, if ``nsupdate`` is to
|
||||
be used from a remote system.
|
||||
A domain name can be specified on the command line to be used as the name
|
||||
of the generated key. If no name is specified, the default is ``tsig-key``.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option specifies the algorithm to use for the TSIG key. Available
|
||||
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256, hmac-sha384,
|
||||
and hmac-sha512. The default is hmac-sha256. Options are
|
||||
case-insensitive, and the "hmac-" prefix may be omitted.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of options and arguments.
|
||||
|
||||
``-k keyname``
|
||||
This option specifies the key name of the DDNS authentication key. The
|
||||
default is ``ddns-key`` when neither the ``-s`` nor ``-z`` option is
|
||||
specified; otherwise, the default is ``ddns-key`` as a separate label
|
||||
followed by the argument of the option, e.g., ``ddns-key.example.com.``
|
||||
The key name must have the format of a valid domain name, consisting of
|
||||
letters, digits, hyphens, and periods.
|
||||
|
||||
``-q`` (``ddns-confgen`` only)
|
||||
This option enables quiet mode, which prints only the key, with no
|
||||
explanatory text or usage examples. This is essentially identical to
|
||||
``tsig-keygen``.
|
||||
|
||||
``-s name`` (``ddns-confgen`` only)
|
||||
This option generates a configuration example to allow dynamic updates
|
||||
of a single hostname. The example ``named.conf`` text shows how to set
|
||||
an update policy for the specified name using the "name" nametype. The
|
||||
default key name is ``ddns-key.name``. Note that the "self" nametype
|
||||
cannot be used, since the name to be updated may differ from the key
|
||||
name. This option cannot be used with the ``-z`` option.
|
||||
|
||||
``-z zone`` (``ddns-confgen`` only)
|
||||
This option generates a configuration example to allow
|
||||
dynamic updates of a zone. The example ``named.conf`` text shows how
|
||||
to set an update policy for the specified zone using the "zonesub"
|
||||
nametype, allowing updates to all subdomain names within that zone.
|
||||
This option cannot be used with the ``-s`` option.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`nsupdate(1)`, :manpage:`named.conf(5)`, :manpage:`named(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`nsupdate(1) <nsupdate>`, :iscman:`named.conf(5) <named.conf>`, :iscman:`named(8) <named>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+1
-1
@@ -1334,7 +1334,7 @@ dash_option(char *option, char *next, bool *open_type_class) {
|
||||
/* handled in preparse_args() */
|
||||
break;
|
||||
case 'v':
|
||||
fprintf(stderr, "delv %s\n", PACKAGE_VERSION);
|
||||
printf("delv %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
/* NOTREACHED */
|
||||
default:
|
||||
|
||||
+121
-83
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: delv
|
||||
.. program:: delv
|
||||
.. _man_delv:
|
||||
|
||||
delv - DNS lookup and validation utility
|
||||
@@ -30,10 +32,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``delv`` is a tool for sending DNS queries and validating the results,
|
||||
using the same internal resolver and validator logic as ``named``.
|
||||
:program:`delv` is a tool for sending DNS queries and validating the results,
|
||||
using the same internal resolver and validator logic as :iscman:`named`.
|
||||
|
||||
``delv`` sends to a specified name server all queries needed to
|
||||
:program:`delv` sends to a specified name server all queries needed to
|
||||
fetch and validate the requested data; this includes the original
|
||||
requested query, subsequent queries to follow CNAME or DNAME chains,
|
||||
queries for DNSKEY, and DS records to establish a chain of trust for
|
||||
@@ -42,25 +44,25 @@ simulates the behavior of a name server configured for DNSSEC validating
|
||||
and forwarding.
|
||||
|
||||
By default, responses are validated using the built-in DNSSEC trust anchor
|
||||
for the root zone ("."). Records returned by ``delv`` are either fully
|
||||
for the root zone ("."). Records returned by :program:`delv` are either fully
|
||||
validated or were not signed. If validation fails, an explanation of the
|
||||
failure is included in the output; the validation process can be traced
|
||||
in detail. Because ``delv`` does not rely on an external server to carry
|
||||
in detail. Because :program:`delv` does not rely on an external server to carry
|
||||
out validation, it can be used to check the validity of DNS responses in
|
||||
environments where local name servers may not be trustworthy.
|
||||
|
||||
Unless it is told to query a specific name server, ``delv`` tries
|
||||
Unless it is told to query a specific name server, :program:`delv` tries
|
||||
each of the servers listed in ``/etc/resolv.conf``. If no usable server
|
||||
addresses are found, ``delv`` sends queries to the localhost
|
||||
addresses are found, :program:`delv` sends queries to the localhost
|
||||
addresses (127.0.0.1 for IPv4, ::1 for IPv6).
|
||||
|
||||
When no command-line arguments or options are given, ``delv``
|
||||
When no command-line arguments or options are given, :program:`delv`
|
||||
performs an NS query for "." (the root zone).
|
||||
|
||||
Simple Usage
|
||||
~~~~~~~~~~~~
|
||||
|
||||
A typical invocation of ``delv`` looks like:
|
||||
A typical invocation of :program:`delv` looks like:
|
||||
|
||||
::
|
||||
|
||||
@@ -68,125 +70,142 @@ A typical invocation of ``delv`` looks like:
|
||||
|
||||
where:
|
||||
|
||||
``server``
|
||||
.. option:: server
|
||||
|
||||
is the name or IP address of the name server to query. This can be an
|
||||
IPv4 address in dotted-decimal notation or an IPv6 address in
|
||||
colon-delimited notation. When the supplied ``server`` argument is a
|
||||
hostname, ``delv`` resolves that name before querying that name
|
||||
hostname, :program:`delv` resolves that name before querying that name
|
||||
server (note, however, that this initial lookup is *not* validated by
|
||||
DNSSEC).
|
||||
|
||||
If no ``server`` argument is provided, ``delv`` consults
|
||||
If no ``server`` argument is provided, :program:`delv` consults
|
||||
``/etc/resolv.conf``; if an address is found there, it queries the
|
||||
name server at that address. If either of the ``-4`` or ``-6``
|
||||
name server at that address. If either of the :option:`-4` or :option:`-6`
|
||||
options is in use, then only addresses for the corresponding
|
||||
transport are tried. If no usable addresses are found, ``delv``
|
||||
transport are tried. If no usable addresses are found, :program:`delv`
|
||||
sends queries to the localhost addresses (127.0.0.1 for IPv4, ::1
|
||||
for IPv6).
|
||||
|
||||
``name``
|
||||
.. option:: name
|
||||
|
||||
is the domain name to be looked up.
|
||||
|
||||
``type``
|
||||
.. option:: type
|
||||
|
||||
indicates what type of query is required - ANY, A, MX, etc.
|
||||
``type`` can be any valid query type. If no ``type`` argument is
|
||||
supplied, ``delv`` performs a lookup for an A record.
|
||||
supplied, :program:`delv` performs a lookup for an A record.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a anchor-file``
|
||||
.. option:: -a anchor-file
|
||||
|
||||
This option specifies a file from which to read DNSSEC trust anchors. The default
|
||||
is ``/etc/bind.keys``, which is included with BIND 9 and contains one
|
||||
is |bind_keys|, which is included with BIND 9 and contains one
|
||||
or more trust anchors for the root zone (".").
|
||||
|
||||
Keys that do not match the root zone name are ignored. An alternate
|
||||
key name can be specified using the ``+root=NAME`` options.
|
||||
|
||||
Note: When reading the trust anchor file, ``delv`` treats ``trust-anchors``,
|
||||
Note: When reading the trust anchor file, :program:`delv` treats ``trust-anchors``,
|
||||
``initial-key``, and ``static-key`` identically. That is, for a managed key,
|
||||
it is the *initial* key that is trusted; :rfc:`5011` key management is not
|
||||
supported. ``delv`` does not consult the managed-keys database maintained by
|
||||
``named``, which means that if either of the keys in ``/etc/bind.keys`` is
|
||||
revoked and rolled over, ``/etc/bind.keys`` must be updated to
|
||||
use DNSSEC validation in ``delv``.
|
||||
supported. :program:`delv` does not consult the managed-keys database maintained by
|
||||
:iscman:`named`, which means that if either of the keys in |bind_keys| is
|
||||
revoked and rolled over, |bind_keys| must be updated to
|
||||
use DNSSEC validation in :program:`delv`.
|
||||
|
||||
.. option:: -b address
|
||||
|
||||
``-b address``
|
||||
This option sets the source IP address of the query to ``address``. This must be
|
||||
a valid address on one of the host's network interfaces, or ``0.0.0.0``,
|
||||
or ``::``. An optional source port may be specified by appending
|
||||
``#<port>``
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option sets the query class for the requested data. Currently, only class
|
||||
"IN" is supported in ``delv`` and any other value is ignored.
|
||||
"IN" is supported in :program:`delv` and any other value is ignored.
|
||||
|
||||
.. option:: -d level
|
||||
|
||||
``-d level``
|
||||
This option sets the systemwide debug level to ``level``. The allowed range is
|
||||
from 0 to 99. The default is 0 (no debugging). Debugging traces from
|
||||
``delv`` become more verbose as the debug level increases. See the
|
||||
:program:`delv` become more verbose as the debug level increases. See the
|
||||
``+mtrace``, ``+rtrace``, and ``+vtrace`` options below for
|
||||
additional debugging details.
|
||||
|
||||
``-h``
|
||||
This option displays the ``delv`` help usage output and exits.
|
||||
.. option:: -h
|
||||
|
||||
This option displays the :program:`delv` help usage output and exits.
|
||||
|
||||
.. option:: -i
|
||||
|
||||
``-i``
|
||||
This option sets insecure mode, which disables internal DNSSEC validation. (Note,
|
||||
however, that this does not set the CD bit on upstream queries. If the
|
||||
server being queried is performing DNSSEC validation, then it does
|
||||
not return invalid data; this can cause ``delv`` to time out. When it
|
||||
not return invalid data; this can cause :program:`delv` to time out. When it
|
||||
is necessary to examine invalid data to debug a DNSSEC problem, use
|
||||
``dig +cd``.)
|
||||
|
||||
``-m``
|
||||
.. option:: -m
|
||||
|
||||
This option enables memory usage debugging.
|
||||
|
||||
``-p port#``
|
||||
.. option:: -p port#
|
||||
|
||||
This option specifies a destination port to use for queries, instead of the
|
||||
standard DNS port number 53. This option is used with a name
|
||||
server that has been configured to listen for queries on a
|
||||
non-standard port number.
|
||||
|
||||
``-q name``
|
||||
.. option:: -q name
|
||||
|
||||
This option sets the query name to ``name``. While the query name can be
|
||||
specified without using the ``-q`` option, it is sometimes necessary to
|
||||
specified without using the :option:`-q` option, it is sometimes necessary to
|
||||
disambiguate names from types or classes (for example, when looking
|
||||
up the name "ns", which could be misinterpreted as the type NS, or
|
||||
"ch", which could be misinterpreted as class CH).
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option sets the query type to ``type``, which can be any valid query type
|
||||
supported in BIND 9 except for zone transfer types AXFR and IXFR. As
|
||||
with ``-q``, this is useful to distinguish query-name types or classes
|
||||
with :option:`-q`, this is useful to distinguish query-name types or classes
|
||||
when they are ambiguous. It is sometimes necessary to disambiguate
|
||||
names from types.
|
||||
|
||||
The default query type is "A", unless the ``-x`` option is supplied
|
||||
The default query type is "A", unless the :option:`-x` option is supplied
|
||||
to indicate a reverse lookup, in which case it is "PTR".
|
||||
|
||||
``-v``
|
||||
This option prints the ``delv`` version and exits.
|
||||
.. option:: -v
|
||||
|
||||
This option prints the :program:`delv` version and exits.
|
||||
|
||||
.. option:: -x addr
|
||||
|
||||
``-x addr``
|
||||
This option performs a reverse lookup, mapping an address to a name. ``addr``
|
||||
is an IPv4 address in dotted-decimal notation, or a colon-delimited
|
||||
IPv6 address. When ``-x`` is used, there is no need to provide the
|
||||
``name`` or ``type`` arguments; ``delv`` automatically performs a
|
||||
IPv6 address. When :option:`-x` is used, there is no need to provide the
|
||||
``name`` or ``type`` arguments; :program:`delv` automatically performs a
|
||||
lookup for a name like ``11.12.13.10.in-addr.arpa`` and sets the
|
||||
query type to PTR. IPv6 addresses are looked up using nibble format
|
||||
under the IP6.ARPA domain.
|
||||
|
||||
``-4``
|
||||
This option forces ``delv`` to only use IPv4.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option forces ``delv`` to only use IPv6.
|
||||
This option forces :program:`delv` to only use IPv4.
|
||||
|
||||
.. option:: -6
|
||||
|
||||
This option forces :program:`delv` to only use IPv6.
|
||||
|
||||
Query Options
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``delv`` provides a number of query options which affect the way results
|
||||
:program:`delv` provides a number of query options which affect the way results
|
||||
are displayed, and in some cases the way lookups are performed.
|
||||
|
||||
Each query option is identified by a keyword preceded by a plus sign
|
||||
@@ -195,69 +214,79 @@ the string ``no`` to negate the meaning of that keyword. Other keywords
|
||||
assign values to options like the timeout interval. They have the form
|
||||
``+keyword=value``. The query options are:
|
||||
|
||||
``+[no]cdflag``
|
||||
.. option:: +[no]cdflag
|
||||
|
||||
This option controls whether to set the CD (checking disabled) bit in queries
|
||||
sent by ``delv``. This may be useful when troubleshooting DNSSEC
|
||||
sent by :program:`delv`. This may be useful when troubleshooting DNSSEC
|
||||
problems from behind a validating resolver. A validating resolver
|
||||
blocks invalid responses, making it difficult to retrieve them
|
||||
for analysis. Setting the CD flag on queries causes the resolver
|
||||
to return invalid responses, which ``delv`` can then validate
|
||||
to return invalid responses, which :program:`delv` can then validate
|
||||
internally and report the errors in detail.
|
||||
|
||||
``+[no]class``
|
||||
.. option:: +[no]class
|
||||
|
||||
This option controls whether to display the CLASS when printing a record. The
|
||||
default is to display the CLASS.
|
||||
|
||||
``+[no]ttl``
|
||||
.. option:: +[no]ttl
|
||||
|
||||
This option controls whether to display the TTL when printing a record. The
|
||||
default is to display the TTL.
|
||||
|
||||
``+[no]rtrace``
|
||||
.. option:: +[no]rtrace
|
||||
|
||||
This option toggles resolver fetch logging. This reports the name and type of each
|
||||
query sent by ``delv`` in the process of carrying out the resolution
|
||||
query sent by :program:`delv` in the process of carrying out the resolution
|
||||
and validation process, including the original query
|
||||
and all subsequent queries to follow CNAMEs and to establish a chain
|
||||
of trust for DNSSEC validation.
|
||||
|
||||
This is equivalent to setting the debug level to 1 in the "resolver"
|
||||
logging category. Setting the systemwide debug level to 1 using the
|
||||
``-d`` option produces the same output, but affects other
|
||||
:option:`-d` option produces the same output, but affects other
|
||||
logging categories as well.
|
||||
|
||||
``+[no]mtrace``
|
||||
.. option:: +[no]mtrace
|
||||
|
||||
This option toggles message logging. This produces a detailed dump of the
|
||||
responses received by ``delv`` in the process of carrying out the
|
||||
responses received by :program:`delv` in the process of carrying out the
|
||||
resolution and validation process.
|
||||
|
||||
This is equivalent to setting the debug level to 10 for the "packets"
|
||||
module of the "resolver" logging category. Setting the systemwide
|
||||
debug level to 10 using the ``-d`` option produces the same
|
||||
debug level to 10 using the :option:`-d` option produces the same
|
||||
output, but affects other logging categories as well.
|
||||
|
||||
``+[no]vtrace``
|
||||
.. option:: +[no]vtrace
|
||||
|
||||
This option toggles validation logging. This shows the internal process of the
|
||||
validator as it determines whether an answer is validly signed,
|
||||
unsigned, or invalid.
|
||||
|
||||
This is equivalent to setting the debug level to 3 for the
|
||||
"validator" module of the "dnssec" logging category. Setting the
|
||||
systemwide debug level to 3 using the ``-d`` option produces the
|
||||
systemwide debug level to 3 using the :option:`-d` option produces the
|
||||
same output, but affects other logging categories as well.
|
||||
|
||||
``+[no]short``
|
||||
.. option:: +[no]short
|
||||
|
||||
This option toggles between verbose and terse answers. The default is to print the answer in a
|
||||
verbose form.
|
||||
|
||||
``+[no]comments``
|
||||
.. option:: +[no]comments
|
||||
|
||||
This option toggles the display of comment lines in the output. The default is to
|
||||
print comments.
|
||||
|
||||
``+[no]rrcomments``
|
||||
.. option:: +[no]rrcomments
|
||||
|
||||
This option toggles the display of per-record comments in the output (for example,
|
||||
human-readable key information about DNSKEY records). The default is
|
||||
to print per-record comments.
|
||||
|
||||
``+[no]crypto``
|
||||
.. option:: +[no]crypto
|
||||
|
||||
This option toggles the display of cryptographic fields in DNSSEC records. The
|
||||
contents of these fields are unnecessary to debug most DNSSEC
|
||||
validation failures and removing them makes it easier to see the
|
||||
@@ -265,62 +294,71 @@ assign values to options like the timeout interval. They have the form
|
||||
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
||||
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
||||
|
||||
``+[no]trust``
|
||||
.. option:: +[no]trust
|
||||
|
||||
This option controls whether to display the trust level when printing a record.
|
||||
The default is to display the trust level.
|
||||
|
||||
``+[no]split[=W]``
|
||||
.. option:: +[no]split[=W]
|
||||
|
||||
This option splits long hex- or base64-formatted fields in resource records into
|
||||
chunks of ``W`` characters (where ``W`` is rounded up to the nearest
|
||||
multiple of 4). ``+nosplit`` or ``+split=0`` causes fields not to be
|
||||
split at all. The default is 56 characters, or 44 characters when
|
||||
multiline mode is active.
|
||||
|
||||
``+[no]all``
|
||||
.. option:: +[no]all
|
||||
|
||||
This option sets or clears the display options ``+[no]comments``,
|
||||
``+[no]rrcomments``, and ``+[no]trust`` as a group.
|
||||
|
||||
``+[no]multiline``
|
||||
.. option:: +[no]multiline
|
||||
|
||||
This option prints long records (such as RRSIG, DNSKEY, and SOA records) in a
|
||||
verbose multi-line format with human-readable comments. The default
|
||||
is to print each record on a single line, to facilitate machine
|
||||
parsing of the ``delv`` output.
|
||||
parsing of the :program:`delv` output.
|
||||
|
||||
``+[no]dnssec``
|
||||
This option indicates whether to display RRSIG records in the ``delv`` output.
|
||||
The default is to do so. Note that (unlike in ``dig``) this does
|
||||
.. option:: +[no]dnssec
|
||||
|
||||
This option indicates whether to display RRSIG records in the :program:`delv` output.
|
||||
The default is to do so. Note that (unlike in :iscman:`dig`) this does
|
||||
*not* control whether to request DNSSEC records or to
|
||||
validate them. DNSSEC records are always requested, and validation
|
||||
always occurs unless suppressed by the use of ``-i`` or
|
||||
always occurs unless suppressed by the use of :option:`-i` or
|
||||
``+noroot``.
|
||||
|
||||
``+[no]root[=ROOT]``
|
||||
.. option:: +[no]root[=ROOT]
|
||||
|
||||
This option indicates whether to perform conventional DNSSEC validation, and if so,
|
||||
specifies the name of a trust anchor. The default is to validate using a
|
||||
trust anchor of "." (the root zone), for which there is a built-in key. If
|
||||
specifying a different trust anchor, then ``-a`` must be used to specify a
|
||||
specifying a different trust anchor, then :option:`-a` must be used to specify a
|
||||
file containing the key.
|
||||
|
||||
``+[no]tcp``
|
||||
.. option:: +[no]tcp
|
||||
|
||||
This option controls whether to use TCP when sending queries. The default is to
|
||||
use UDP unless a truncated response has been received.
|
||||
|
||||
``+[no]unknownformat``
|
||||
.. option:: +[no]unknownformat
|
||||
|
||||
This option prints all RDATA in unknown RR-type presentation format (:rfc:`3597`).
|
||||
The default is to print RDATA for known types in the type's
|
||||
presentation format.
|
||||
|
||||
``+[no]yaml``
|
||||
.. option:: +[no]yaml
|
||||
|
||||
This option prints response data in YAML format.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/bind.keys``
|
||||
|bind_keys|
|
||||
|
||||
``/etc/resolv.conf``
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`named(8)`, :rfc:`4034`, :rfc:`4035`, :rfc:`4431`, :rfc:`5074`, :rfc:`5155`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`named(8) <named>`, :rfc:`4034`, :rfc:`4035`, :rfc:`4431`, :rfc:`5074`, :rfc:`5155`.
|
||||
|
||||
+22
-14
@@ -59,7 +59,7 @@
|
||||
|
||||
dig_lookup_t *default_lookup = NULL;
|
||||
|
||||
static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uintptr_t batchname = 0;
|
||||
static FILE *batchfp = NULL;
|
||||
static char *argv0;
|
||||
static int addresscount = 0;
|
||||
@@ -125,12 +125,6 @@ usage(void) {
|
||||
}
|
||||
#endif /* if TARGET_OS_IPHONE */
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "DiG %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
/*% help */
|
||||
static void
|
||||
help(void) {
|
||||
@@ -496,10 +490,12 @@ dns64prefix_answer(dns_message_t *msg, isc_buffer_t *buf) {
|
||||
}
|
||||
|
||||
result = dns_dns64_findprefix(rdataset, prefix, &count);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
return (ISC_R_SUCCESS);
|
||||
if (count > 10)
|
||||
}
|
||||
if (count > 10) {
|
||||
count = 10;
|
||||
}
|
||||
for (i = 0; i < count; i++) {
|
||||
result = isc_netaddr_totext(&prefix[i].addr, buf);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -909,8 +905,9 @@ repopulate_buffer:
|
||||
check_result(result, "dns_message_sectiontotext");
|
||||
} else if (dns64prefix) {
|
||||
result = dns64prefix_answer(msg, buf);
|
||||
if (result == ISC_R_NOSPACE)
|
||||
if (result == ISC_R_NOSPACE) {
|
||||
goto buftoosmall;
|
||||
}
|
||||
check_result(result, "dns64prefix_answer");
|
||||
} else {
|
||||
result = short_answer(msg, flags, buf, query);
|
||||
@@ -1515,8 +1512,11 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
case 'i':
|
||||
FULLCHECK("idnin");
|
||||
#ifndef HAVE_LIBIDN2
|
||||
fprintf(stderr, ";; IDN input support"
|
||||
if (state) {
|
||||
fprintf(stderr,
|
||||
";; IDN input support"
|
||||
" not enabled\n");
|
||||
}
|
||||
#else /* ifndef HAVE_LIBIDN2 */
|
||||
lookup->idnin = state;
|
||||
#endif /* ifndef HAVE_LIBIDN2 */
|
||||
@@ -1524,8 +1524,11 @@ plus_option(char *option, bool is_batchfile, bool *need_clone,
|
||||
case 'o':
|
||||
FULLCHECK("idnout");
|
||||
#ifndef HAVE_LIBIDN2
|
||||
fprintf(stderr, ";; IDN output support"
|
||||
if (state) {
|
||||
fprintf(stderr,
|
||||
";; IDN output support"
|
||||
" not enabled\n");
|
||||
}
|
||||
#else /* ifndef HAVE_LIBIDN2 */
|
||||
lookup->idnout = state;
|
||||
#endif /* ifndef HAVE_LIBIDN2 */
|
||||
@@ -2158,7 +2161,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
||||
(*lookup)->use_usec = true;
|
||||
break;
|
||||
case 'v':
|
||||
version();
|
||||
printf("DiG %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
break;
|
||||
}
|
||||
@@ -2921,12 +2924,18 @@ dig_query_setup(bool is_batchfile, bool config_only, int argc, char **argv) {
|
||||
void
|
||||
dig_startup(void) {
|
||||
isc_result_t result;
|
||||
isc_event_t *event;
|
||||
|
||||
debug("dig_startup()");
|
||||
|
||||
result = isc_app_onrun(mctx, global_task, onrun_callback, NULL);
|
||||
check_result(result, "isc_app_onrun");
|
||||
isc_app_run();
|
||||
|
||||
event = isc_event_allocate(mctx, global_task, ISC_APPEVENT_SHUTDOWN,
|
||||
onshutdown_callback, NULL, sizeof(*event));
|
||||
|
||||
isc_task_send(global_task, &event);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -2943,7 +2952,6 @@ dig_shutdown(void) {
|
||||
}
|
||||
atomic_store(&batchname, 0);
|
||||
}
|
||||
cancel_all();
|
||||
destroy_libs();
|
||||
isc_app_finish();
|
||||
}
|
||||
|
||||
+247
-146
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dig
|
||||
.. program:: dig
|
||||
.. _man_dig:
|
||||
|
||||
dig - DNS lookup utility
|
||||
@@ -27,41 +29,41 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dig`` is a flexible tool for interrogating DNS name servers. It
|
||||
:program:`dig` is a flexible tool for interrogating DNS name servers. It
|
||||
performs DNS lookups and displays the answers that are returned from the
|
||||
name server(s) that were queried. Most DNS administrators use ``dig`` to
|
||||
name server(s) that were queried. Most DNS administrators use :program:`dig` to
|
||||
troubleshoot DNS problems because of its flexibility, ease of use, and
|
||||
clarity of output. Other lookup tools tend to have less functionality
|
||||
than ``dig``.
|
||||
than :program:`dig`.
|
||||
|
||||
Although ``dig`` is normally used with command-line arguments, it also
|
||||
Although :program:`dig` is normally used with command-line arguments, it also
|
||||
has a batch mode of operation for reading lookup requests from a file. A
|
||||
brief summary of its command-line arguments and options is printed when
|
||||
the ``-h`` option is given. The BIND 9
|
||||
implementation of ``dig`` allows multiple lookups to be issued from the
|
||||
the :option:`-h` option is given. The BIND 9
|
||||
implementation of :program:`dig` allows multiple lookups to be issued from the
|
||||
command line.
|
||||
|
||||
Unless it is told to query a specific name server, ``dig`` tries each
|
||||
Unless it is told to query a specific name server, :program:`dig` tries each
|
||||
of the servers listed in ``/etc/resolv.conf``. If no usable server
|
||||
addresses are found, ``dig`` sends the query to the local host.
|
||||
addresses are found, :program:`dig` sends the query to the local host.
|
||||
|
||||
When no command-line arguments or options are given, ``dig``
|
||||
When no command-line arguments or options are given, :program:`dig`
|
||||
performs an NS query for "." (the root).
|
||||
|
||||
It is possible to set per-user defaults for ``dig`` via
|
||||
It is possible to set per-user defaults for :program:`dig` via
|
||||
``${HOME}/.digrc``. This file is read and any options in it are applied
|
||||
before the command-line arguments. The ``-r`` option disables this
|
||||
before the command-line arguments. The :option:`-r` option disables this
|
||||
feature, for scripts that need predictable behavior.
|
||||
|
||||
The IN and CH class names overlap with the IN and CH top-level domain
|
||||
names. Either use the ``-t`` and ``-c`` options to specify the type and
|
||||
class, use the ``-q`` to specify the domain name, or use "IN." and
|
||||
names. Either use the :option:`-t` and :option:`-c` options to specify the type and
|
||||
class, use the :option:`-q` to specify the domain name, or use "IN." and
|
||||
"CH." when looking up these top-level domains.
|
||||
|
||||
Simple Usage
|
||||
~~~~~~~~~~~~
|
||||
|
||||
A typical invocation of ``dig`` looks like:
|
||||
A typical invocation of :program:`dig` looks like:
|
||||
|
||||
::
|
||||
|
||||
@@ -69,83 +71,101 @@ A typical invocation of ``dig`` looks like:
|
||||
|
||||
where:
|
||||
|
||||
``server``
|
||||
.. option:: server
|
||||
|
||||
is the name or IP address of the name server to query. This can be an
|
||||
IPv4 address in dotted-decimal notation or an IPv6 address in
|
||||
colon-delimited notation. When the supplied ``server`` argument is a
|
||||
hostname, ``dig`` resolves that name before querying that name
|
||||
hostname, :program:`dig` resolves that name before querying that name
|
||||
server.
|
||||
|
||||
If no ``server`` argument is provided, ``dig`` consults
|
||||
If no ``server`` argument is provided, :program:`dig` consults
|
||||
``/etc/resolv.conf``; if an address is found there, it queries the
|
||||
name server at that address. If either of the ``-4`` or ``-6``
|
||||
name server at that address. If either of the :option:`-4` or :option:`-6`
|
||||
options are in use, then only addresses for the corresponding
|
||||
transport are tried. If no usable addresses are found, ``dig``
|
||||
transport are tried. If no usable addresses are found, :program:`dig`
|
||||
sends the query to the local host. The reply from the name server
|
||||
that responds is displayed.
|
||||
|
||||
``name``
|
||||
.. option:: name
|
||||
|
||||
is the name of the resource record that is to be looked up.
|
||||
|
||||
``type``
|
||||
.. option:: type
|
||||
|
||||
indicates what type of query is required - ANY, A, MX, SIG, etc.
|
||||
``type`` can be any valid query type. If no ``type`` argument is
|
||||
supplied, ``dig`` performs a lookup for an A record.
|
||||
supplied, :program:`dig` performs a lookup for an A record.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option indicates that only IPv4 should be used.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option indicates that only IPv6 should be used.
|
||||
|
||||
``-b address[#port]``
|
||||
.. option:: -b address[#port]
|
||||
|
||||
This option sets the source IP address of the query. The ``address`` must be a
|
||||
valid address on one of the host's network interfaces, or "0.0.0.0"
|
||||
or "::". An optional port may be specified by appending ``#port``.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option sets the query class. The default ``class`` is IN; other classes are
|
||||
HS for Hesiod records or CH for Chaosnet records.
|
||||
|
||||
``-f file``
|
||||
This option sets batch mode, in which ``dig`` reads a list of lookup requests to process from
|
||||
.. option:: -f file
|
||||
|
||||
This option sets batch mode, in which :program:`dig` reads a list of lookup requests to process from
|
||||
the given ``file``. Each line in the file should be organized in the
|
||||
same way it would be presented as a query to ``dig`` using the
|
||||
same way it would be presented as a query to :program:`dig` using the
|
||||
command-line interface.
|
||||
|
||||
``-k keyfile``
|
||||
This option tells ``named`` to sign queries using TSIG using a key read from the given file. Key
|
||||
files can be generated using ``tsig-keygen``. When using TSIG
|
||||
authentication with ``dig``, the name server that is queried needs to
|
||||
.. option:: -h
|
||||
|
||||
Print a usage summary.
|
||||
|
||||
.. option:: -k keyfile
|
||||
|
||||
This option tells :iscman:`named` to sign queries using TSIG using a key read from the given file. Key
|
||||
files can be generated using :iscman:`tsig-keygen`. When using TSIG
|
||||
authentication with :program:`dig`, the name server that is queried needs to
|
||||
know the key and algorithm that is being used. In BIND, this is done
|
||||
by providing appropriate ``key`` and ``server`` statements in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
.. option:: -m
|
||||
|
||||
``-m``
|
||||
This option enables memory usage debugging.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option sends the query to a non-standard port on the server, instead of the
|
||||
default port 53. This option is used to test a name server that
|
||||
has been configured to listen for queries on a non-standard port
|
||||
number.
|
||||
|
||||
``-q name``
|
||||
.. option:: -q name
|
||||
|
||||
This option specifies the domain name to query. This is useful to distinguish the ``name``
|
||||
from other arguments.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option indicates that options from ``${HOME}/.digrc`` should not be read. This is useful for
|
||||
scripts that need predictable behavior.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the resource record type to query, which can be any valid query type. If
|
||||
it is a resource record type supported in BIND 9, it can be given by
|
||||
the type mnemonic (such as ``NS`` or ``AAAA``). The default query type is
|
||||
``A``, unless the ``-x`` option is supplied to indicate a reverse
|
||||
``A``, unless the :option:`-x` option is supplied to indicate a reverse
|
||||
lookup. A zone transfer can be requested by specifying a type of
|
||||
AXFR. When an incremental zone transfer (IXFR) is required, set the
|
||||
``type`` to ``ixfr=N``. The incremental zone transfer contains
|
||||
@@ -156,23 +176,27 @@ Options
|
||||
the number of the type. If the resource record type is not supported
|
||||
in BIND 9, the result is displayed as described in :rfc:`3597`.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option indicates that print query times should be provided in microseconds instead of milliseconds.
|
||||
|
||||
``-v``
|
||||
.. option:: -v
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-x addr``
|
||||
.. option:: -x addr
|
||||
|
||||
This option sets simplified reverse lookups, for mapping addresses to names. The
|
||||
``addr`` is an IPv4 address in dotted-decimal notation, or a
|
||||
colon-delimited IPv6 address. When the ``-x`` option is used, there is no
|
||||
colon-delimited IPv6 address. When the :option:`-x` option is used, there is no
|
||||
need to provide the ``name``, ``class``, and ``type`` arguments.
|
||||
``dig`` automatically performs a lookup for a name like
|
||||
:program:`dig` automatically performs a lookup for a name like
|
||||
``94.2.0.192.in-addr.arpa`` and sets the query type and class to PTR
|
||||
and IN respectively. IPv6 addresses are looked up using nibble format
|
||||
under the IP6.ARPA domain.
|
||||
|
||||
``-y [hmac:]keyname:secret``
|
||||
.. option:: -y [hmac:]keyname:secret
|
||||
|
||||
This option signs queries using TSIG with the given authentication key.
|
||||
``keyname`` is the name of the key, and ``secret`` is the
|
||||
base64-encoded shared secret. ``hmac`` is the name of the key algorithm;
|
||||
@@ -181,15 +205,15 @@ Options
|
||||
not specified, the default is ``hmac-md5``; if MD5 was disabled, the default is
|
||||
``hmac-sha256``.
|
||||
|
||||
.. note:: Only the ``-k`` option should be used, rather than the ``-y`` option,
|
||||
because with ``-y`` the shared secret is supplied as a command-line
|
||||
.. note:: Only the :option:`-k` option should be used, rather than the :option:`-y` option,
|
||||
because with :option:`-y` the shared secret is supplied as a command-line
|
||||
argument in clear text. This may be visible in the output from ``ps1`` or
|
||||
in a history file maintained by the user's shell.
|
||||
|
||||
Query Options
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``dig`` provides a number of query options which affect the way in which
|
||||
:program:`dig` provides a number of query options which affect the way in which
|
||||
lookups are made and the results displayed. Some of these set or reset
|
||||
flag bits in the query header, some determine which sections of the
|
||||
answer get printed, and others determine the timeout and retry
|
||||
@@ -203,17 +227,21 @@ assign values to options, like the timeout interval. They have the form
|
||||
abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+cdflag``. The query options are:
|
||||
|
||||
``+[no]aaflag``
|
||||
.. option:: +[no]aaflag
|
||||
|
||||
This option is a synonym for ``+[no]aaonly``.
|
||||
|
||||
``+[no]aaonly``
|
||||
.. option:: +[no]aaonly
|
||||
|
||||
This option sets the ``aa`` flag in the query.
|
||||
|
||||
``+[no]additional``
|
||||
.. option:: +[no]additional
|
||||
|
||||
This option displays [or does not display] the additional section of a reply. The
|
||||
default is to display it.
|
||||
|
||||
``+[no]adflag``
|
||||
.. option:: +[no]adflag
|
||||
|
||||
This option sets [or does not set] the AD (authentic data) bit in the query. This
|
||||
requests the server to return whether all of the answer and authority
|
||||
sections have been validated as secure, according to the security
|
||||
@@ -222,44 +250,54 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
indicates that some part of the answer was insecure or not validated.
|
||||
This bit is set by default.
|
||||
|
||||
``+[no]all``
|
||||
.. option:: +[no]all
|
||||
|
||||
This option sets or clears all display flags.
|
||||
|
||||
``+[no]answer``
|
||||
.. option:: +[no]answer
|
||||
|
||||
This option displays [or does not display] the answer section of a reply. The default
|
||||
is to display it.
|
||||
|
||||
``+[no]authority``
|
||||
.. option:: +[no]authority
|
||||
|
||||
This option displays [or does not display] the authority section of a reply. The
|
||||
default is to display it.
|
||||
|
||||
``+[no]badcookie``
|
||||
.. option:: +[no]badcookie
|
||||
|
||||
This option retries the lookup with a new server cookie if a BADCOOKIE response is
|
||||
received.
|
||||
|
||||
``+[no]besteffort``
|
||||
.. option:: +[no]besteffort
|
||||
|
||||
This option attempts to display the contents of messages which are malformed. The
|
||||
default is to not display malformed answers.
|
||||
|
||||
``+bufsize[=B]``
|
||||
.. option:: +bufsize[=B]
|
||||
|
||||
This option sets the UDP message buffer size advertised using EDNS0 to
|
||||
``B`` bytes. The maximum and minimum sizes of this buffer are 65535 and
|
||||
0, respectively. ``+bufsize`` restores the default buffer size.
|
||||
|
||||
``+[no]cdflag``
|
||||
.. option:: +[no]cdflag
|
||||
|
||||
This option sets [or does not set] the CD (checking disabled) bit in the query. This
|
||||
requests the server to not perform DNSSEC validation of responses.
|
||||
|
||||
``+[no]class``
|
||||
.. option:: +[no]class
|
||||
|
||||
This option displays [or does not display] the CLASS when printing the record.
|
||||
|
||||
``+[no]cmd``
|
||||
.. option:: +[no]cmd
|
||||
|
||||
This option toggles the printing of the initial comment in the output, identifying the
|
||||
version of ``dig`` and the query options that have been applied. This option
|
||||
version of :program:`dig` and the query options that have been applied. This option
|
||||
always has a global effect; it cannot be set globally and then overridden on a
|
||||
per-lookup basis. The default is to print this comment.
|
||||
|
||||
``+[no]comments``
|
||||
.. option:: +[no]comments
|
||||
|
||||
This option toggles the display of some comment lines in the output, with
|
||||
information about the packet header and OPT pseudosection, and the names of
|
||||
the response section. The default is to print these comments.
|
||||
@@ -268,7 +306,8 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
can be controlled using other command-line switches. These include
|
||||
``+[no]cmd``, ``+[no]question``, ``+[no]stats``, and ``+[no]rrcomments``.
|
||||
|
||||
``+[no]cookie=####``
|
||||
.. option:: +[no]cookie=####
|
||||
|
||||
This option sends [or does not send] a COOKIE EDNS option, with an optional value. Replaying a COOKIE
|
||||
from a previous response allows the server to identify a previous
|
||||
client. The default is ``+cookie``.
|
||||
@@ -276,7 +315,8 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+cookie`` is also set when ``+trace`` is set to better emulate the
|
||||
default queries from a nameserver.
|
||||
|
||||
``+[no]crypto``
|
||||
.. option:: +[no]crypto
|
||||
|
||||
This option toggles the display of cryptographic fields in DNSSEC records. The
|
||||
contents of these fields are unnecessary for debugging most DNSSEC
|
||||
validation failures and removing them makes it easier to see the
|
||||
@@ -284,62 +324,75 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
they are replaced by the string ``[omitted]`` or, in the DNSKEY case, the
|
||||
key ID is displayed as the replacement, e.g. ``[ key id = value ]``.
|
||||
|
||||
``+[no]defname``
|
||||
.. option:: +[no]defname
|
||||
|
||||
This option, which is deprecated, is treated as a synonym for ``+[no]search``.
|
||||
|
||||
``+[no]dns64prefix``
|
||||
.. option:: +[no]dns64prefix
|
||||
|
||||
Lookup IPV4ONLY.ARPA AAAA and print any DNS64 prefixes found.
|
||||
|
||||
``+[no]dnssec``
|
||||
.. option:: +[no]dnssec
|
||||
|
||||
This option requests that DNSSEC records be sent by setting the DNSSEC OK (DO) bit in
|
||||
the OPT record in the additional section of the query.
|
||||
|
||||
``+domain=somename``
|
||||
.. option:: +domain=somename
|
||||
|
||||
This option sets the search list to contain the single domain ``somename``, as if
|
||||
specified in a ``domain`` directive in ``/etc/resolv.conf``, and
|
||||
enables search list processing as if the ``+search`` option were
|
||||
given.
|
||||
|
||||
``+dscp=value``
|
||||
.. option:: +dscp=value
|
||||
|
||||
This option sets the DSCP code point to be used when sending the query. Valid DSCP
|
||||
code points are in the range [0...63]. By default no code point is
|
||||
explicitly set.
|
||||
|
||||
``+[no]edns[=#]``
|
||||
.. option:: +[no]edns[=#]
|
||||
|
||||
This option specifies the EDNS version to query with. Valid values are 0 to 255.
|
||||
Setting the EDNS version causes an EDNS query to be sent.
|
||||
``+noedns`` clears the remembered EDNS version. EDNS is set to 0 by
|
||||
default.
|
||||
|
||||
``+[no]ednsflags[=#]``
|
||||
.. option:: +[no]ednsflags[=#]
|
||||
|
||||
This option sets the must-be-zero EDNS flags bits (Z bits) to the specified value.
|
||||
Decimal, hex, and octal encodings are accepted. Setting a named flag
|
||||
(e.g., DO) is silently ignored. By default, no Z bits are set.
|
||||
|
||||
``+[no]ednsnegotiation``
|
||||
.. option:: +[no]ednsnegotiation
|
||||
|
||||
This option enables/disables EDNS version negotiation. By default, EDNS version
|
||||
negotiation is enabled.
|
||||
|
||||
``+[no]ednsopt[=code[:value]]``
|
||||
.. option:: +[no]ednsopt[=code[:value]]
|
||||
|
||||
This option specifies the EDNS option with code point ``code`` and an optional payload
|
||||
of ``value`` as a hexadecimal string. ``code`` can be either an EDNS
|
||||
option name (for example, ``NSID`` or ``ECS``) or an arbitrary
|
||||
numeric value. ``+noednsopt`` clears the EDNS options to be sent.
|
||||
|
||||
``+[no]expire``
|
||||
.. option:: +[no]expire
|
||||
|
||||
This option sends an EDNS Expire option.
|
||||
|
||||
``+[no]fail``
|
||||
This option indicates that ``named`` should try [or not try] the next server if a SERVFAIL is received. The default is
|
||||
.. option:: +[no]fail
|
||||
|
||||
This option indicates that :iscman:`named` should try [or not try] the next server if a SERVFAIL is received. The default is
|
||||
to not try the next server, which is the reverse of normal stub
|
||||
resolver behavior.
|
||||
|
||||
``+[no]header-only``
|
||||
.. option:: +[no]header-only
|
||||
|
||||
This option sends a query with a DNS header without a question section. The
|
||||
default is to add a question section. The query type and query name
|
||||
are ignored when this is set.
|
||||
|
||||
``+[no]https[=value]``
|
||||
.. option:: +[no]https[=value]
|
||||
|
||||
This option indicates whether to use DNS over HTTPS (DoH) when querying
|
||||
name servers. When this option is in use, the port number defaults to 443.
|
||||
The HTTP POST request mode is used when sending the query.
|
||||
@@ -348,64 +401,77 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
query URI; the default is ``/dns-query``. So, for example, ``dig
|
||||
@example.com +https`` will use the URI ``https://example.com/dns-query``.
|
||||
|
||||
``+[no]https-get[=value]``
|
||||
.. option:: +[no]https-get[=value]
|
||||
|
||||
Similar to ``+https``, except that the HTTP GET request mode is used
|
||||
when sending the query.
|
||||
|
||||
``+[no]https-post[=value]``
|
||||
.. option:: +[no]https-post[=value]
|
||||
|
||||
Same as ``+https``.
|
||||
|
||||
``+[no]http-plain[=value]``
|
||||
.. option:: +[no]http-plain[=value]
|
||||
|
||||
Similar to ``+https``, except that HTTP queries will be sent over a
|
||||
non-encrypted channel. When this option is in use, the port number
|
||||
defaults to 80 and the HTTP request mode is POST.
|
||||
|
||||
``+[no]http-plain-get[=value]``
|
||||
.. option:: +[no]http-plain-get[=value]
|
||||
|
||||
Similar to ``+http-plain``, except that the HTTP request mode is GET.
|
||||
|
||||
``+[no]http-plain-post[=value]``
|
||||
.. option:: +[no]http-plain-post[=value]
|
||||
|
||||
Same as ``+http-plain``.
|
||||
|
||||
``+[no]identify``
|
||||
.. option:: +[no]identify
|
||||
|
||||
This option shows [or does not show] the IP address and port number that
|
||||
supplied the answer, when the ``+short`` option is enabled. If short
|
||||
form answers are requested, the default is not to show the source
|
||||
address and port number of the server that provided the answer.
|
||||
|
||||
``+[no]idnin``
|
||||
.. option:: +[no]idnin
|
||||
|
||||
This option processes [or does not process] IDN domain names on input. This requires
|
||||
``IDN SUPPORT`` to have been enabled at compile time.
|
||||
|
||||
The default is to process IDN input when standard output is a tty.
|
||||
The IDN processing on input is disabled when ``dig`` output is redirected
|
||||
The IDN processing on input is disabled when :program:`dig` output is redirected
|
||||
to files, pipes, and other non-tty file descriptors.
|
||||
|
||||
``+[no]idnout``
|
||||
.. option:: +[no]idnout
|
||||
|
||||
This option converts [or does not convert] puny code on output. This requires
|
||||
``IDN SUPPORT`` to have been enabled at compile time.
|
||||
|
||||
The default is to process puny code on output when standard output is
|
||||
a tty. The puny code processing on output is disabled when ``dig`` output
|
||||
a tty. The puny code processing on output is disabled when :program:`dig` output
|
||||
is redirected to files, pipes, and other non-tty file descriptors.
|
||||
|
||||
``+[no]ignore``
|
||||
.. option:: +[no]ignore
|
||||
|
||||
This option ignores [or does not ignore] truncation in UDP responses instead of retrying with TCP. By
|
||||
default, TCP retries are performed.
|
||||
|
||||
``+[no]keepalive``
|
||||
.. option:: +[no]keepalive
|
||||
|
||||
This option sends [or does not send] an EDNS Keepalive option.
|
||||
|
||||
``+[no]keepopen``
|
||||
.. option:: +[no]keepopen
|
||||
|
||||
This option keeps [or does not keep] the TCP socket open between queries, and reuses it rather than
|
||||
creating a new TCP socket for each lookup. The default is
|
||||
``+nokeepopen``.
|
||||
|
||||
``+[no]multiline``
|
||||
.. option:: +[no]multiline
|
||||
|
||||
This option prints [or does not print] records, like the SOA records, in a verbose multi-line format
|
||||
with human-readable comments. The default is to print each record on
|
||||
a single line to facilitate machine parsing of the ``dig`` output.
|
||||
a single line to facilitate machine parsing of the :program:`dig` output.
|
||||
|
||||
.. option:: +ndots=D
|
||||
|
||||
``+ndots=D``
|
||||
This option sets the number of dots (``D``) that must appear in ``name`` for
|
||||
it to be considered absolute. The default value is that defined using
|
||||
the ``ndots`` statement in ``/etc/resolv.conf``, or 1 if no ``ndots``
|
||||
@@ -414,24 +480,29 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``search`` or ``domain`` directive in ``/etc/resolv.conf`` if
|
||||
``+search`` is set.
|
||||
|
||||
``+[no]nsid``
|
||||
.. option:: +[no]nsid
|
||||
|
||||
When enabled, this option includes an EDNS name server ID request when sending a query.
|
||||
|
||||
``+[no]nssearch``
|
||||
When this option is set, ``dig`` attempts to find the authoritative
|
||||
.. option:: +[no]nssearch
|
||||
|
||||
When this option is set, :program:`dig` attempts to find the authoritative
|
||||
name servers for the zone containing the name being looked up, and
|
||||
display the SOA record that each name server has for the zone.
|
||||
Addresses of servers that did not respond are also printed.
|
||||
|
||||
``+[no]onesoa``
|
||||
.. option:: +[no]onesoa
|
||||
|
||||
When enabled, this option prints only one (starting) SOA record when performing an AXFR. The
|
||||
default is to print both the starting and ending SOA records.
|
||||
|
||||
``+[no]opcode=value``
|
||||
.. option:: +[no]opcode=value
|
||||
|
||||
When enabled, this option sets (restores) the DNS message opcode to the specified value. The
|
||||
default value is QUERY (0).
|
||||
|
||||
``+padding=value``
|
||||
.. option:: +padding=value
|
||||
|
||||
This option pads the size of the query packet using the EDNS Padding option to
|
||||
blocks of ``value`` bytes. For example, ``+padding=32`` causes a
|
||||
48-byte query to be padded to 64 bytes. The default block size is 0,
|
||||
@@ -440,42 +511,51 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
mandatory. Responses to padded queries may also be padded, but only
|
||||
if the query uses TCP or DNS COOKIE.
|
||||
|
||||
``+qid=value``
|
||||
.. option:: +qid=value
|
||||
|
||||
This option specifies the query ID to use when sending queries.
|
||||
|
||||
``+[no]qr``
|
||||
.. option:: +[no]qr
|
||||
|
||||
This option toggles the display of the query message as it is sent. By default, the query
|
||||
is not printed.
|
||||
|
||||
``+[no]question``
|
||||
.. option:: +[no]question
|
||||
|
||||
This option toggles the display of the question section of a query when an answer is
|
||||
returned. The default is to print the question section as a comment.
|
||||
|
||||
``+[no]raflag``
|
||||
.. option:: +[no]raflag
|
||||
|
||||
This option sets [or does not set] the RA (Recursion Available) bit in the query. The
|
||||
default is ``+noraflag``. This bit is ignored by the server for
|
||||
QUERY.
|
||||
|
||||
``+[no]rdflag``
|
||||
.. option:: +[no]rdflag
|
||||
|
||||
This option is a synonym for ``+[no]recurse``.
|
||||
|
||||
``+[no]recurse``
|
||||
.. option:: +[no]recurse
|
||||
|
||||
This option toggles the setting of the RD (recursion desired) bit in the query.
|
||||
This bit is set by default, which means ``dig`` normally sends
|
||||
This bit is set by default, which means :program:`dig` normally sends
|
||||
recursive queries. Recursion is automatically disabled when the
|
||||
``+nssearch`` or ``+trace`` query option is used.
|
||||
|
||||
``+retry=T``
|
||||
.. option:: +retry=T
|
||||
|
||||
This option sets the number of times to retry UDP and TCP queries to server to ``T``
|
||||
instead of the default, 2. Unlike ``+tries``, this does not include
|
||||
the initial query.
|
||||
|
||||
``+[no]rrcomments``
|
||||
.. option:: +[no]rrcomments
|
||||
|
||||
This option toggles the display of per-record comments in the output (for example,
|
||||
human-readable key information about DNSKEY records). The default is
|
||||
not to print record comments unless multiline mode is active.
|
||||
|
||||
``+[no]search``
|
||||
.. option:: +[no]search
|
||||
|
||||
This option uses [or does not use] the search list defined by the searchlist or domain
|
||||
directive in ``resolv.conf``, if any. The search list is not used by
|
||||
default.
|
||||
@@ -484,36 +564,43 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+ndots``, determines whether the name is treated as relative
|
||||
and hence whether a search is eventually performed.
|
||||
|
||||
``+[no]short``
|
||||
.. option:: +[no]short
|
||||
|
||||
This option toggles whether a terse answer is provided. The default is to print the answer in a verbose
|
||||
form. This option always has a global effect; it cannot be set globally and
|
||||
then overridden on a per-lookup basis.
|
||||
|
||||
``+[no]showbadcookie``
|
||||
.. option:: +[no]showbadcookie
|
||||
|
||||
This option toggles whether to show the message containing the
|
||||
BADCOOKIE rcode before retrying the request or not. The default
|
||||
is to not show the messages.
|
||||
|
||||
``+[no]showsearch``
|
||||
.. option:: +[no]showsearch
|
||||
|
||||
This option performs [or does not perform] a search showing intermediate results.
|
||||
|
||||
``+[no]sigchase``
|
||||
This feature is now obsolete and has been removed; use ``delv``
|
||||
.. option:: +[no]sigchase
|
||||
|
||||
This feature is now obsolete and has been removed; use :iscman:`delv`
|
||||
instead.
|
||||
|
||||
``+split=W``
|
||||
.. option:: +split=W
|
||||
|
||||
This option splits long hex- or base64-formatted fields in resource records into
|
||||
chunks of ``W`` characters (where ``W`` is rounded up to the nearest
|
||||
multiple of 4). ``+nosplit`` or ``+split=0`` causes fields not to be
|
||||
split at all. The default is 56 characters, or 44 characters when
|
||||
multiline mode is active.
|
||||
|
||||
``+[no]stats``
|
||||
.. option:: +[no]stats
|
||||
|
||||
This option toggles the printing of statistics: when the query was made, the size of the
|
||||
reply, etc. The default behavior is to print the query statistics as a
|
||||
comment after each lookup.
|
||||
|
||||
``+[no]subnet=addr[/prefix-length]``
|
||||
.. option:: +[no]subnet=addr[/prefix-length]
|
||||
|
||||
This option sends [or does not send] an EDNS CLIENT-SUBNET option with the specified IP
|
||||
address or network prefix.
|
||||
|
||||
@@ -522,33 +609,39 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
prefix-length of zero, which signals a resolver that the client's
|
||||
address information must *not* be used when resolving this query.
|
||||
|
||||
``+[no]tcflag``
|
||||
.. option:: +[no]tcflag
|
||||
|
||||
This option sets [or does not set] the TC (TrunCation) bit in the query. The default is
|
||||
``+notcflag``. This bit is ignored by the server for QUERY.
|
||||
|
||||
``+[no]tcp``
|
||||
.. option:: +[no]tcp
|
||||
|
||||
This option indicates whether to use TCP when querying name servers.
|
||||
The default behavior is to use UDP unless a type ``any`` or ``ixfr=N``
|
||||
query is requested, in which case the default is TCP. AXFR queries
|
||||
always use TCP.
|
||||
|
||||
``+timeout=T``
|
||||
.. option:: +timeout=T
|
||||
|
||||
This option sets the timeout for a query to ``T`` seconds. The default timeout is
|
||||
5 seconds. An attempt to set ``T`` to less than 1 is silently set to 1.
|
||||
|
||||
``+[no]tls``
|
||||
.. option:: +[no]tls
|
||||
|
||||
This option indicates whether to use DNS over TLS (DoT) when querying
|
||||
name servers. When this option is in use, the port number defaults
|
||||
to 853.
|
||||
|
||||
``+[no]topdown``
|
||||
.. option:: +[no]topdown
|
||||
|
||||
This feature is related to ``dig +sigchase``, which is obsolete and
|
||||
has been removed. Use ``delv`` instead.
|
||||
has been removed. Use :iscman:`delv` instead.
|
||||
|
||||
.. option:: +[no]trace
|
||||
|
||||
``+[no]trace``
|
||||
This option toggles tracing of the delegation path from the root name servers for
|
||||
the name being looked up. Tracing is disabled by default. When
|
||||
tracing is enabled, ``dig`` makes iterative queries to resolve the
|
||||
tracing is enabled, :program:`dig` makes iterative queries to resolve the
|
||||
name being looked up. It follows referrals from the root servers,
|
||||
showing the answer from each server that was used to resolve the
|
||||
lookup.
|
||||
@@ -559,46 +652,54 @@ abbreviation is unambiguous; for example, ``+cd`` is equivalent to
|
||||
``+dnssec`` is also set when ``+trace`` is set, to better emulate the
|
||||
default queries from a name server.
|
||||
|
||||
``+tries=T``
|
||||
.. option:: +tries=T
|
||||
|
||||
This option sets the number of times to try UDP and TCP queries to server to ``T``
|
||||
instead of the default, 3. If ``T`` is less than or equal to zero,
|
||||
the number of tries is silently rounded up to 1.
|
||||
|
||||
``+trusted-key=####``
|
||||
.. option:: +trusted-key=####
|
||||
|
||||
This option formerly specified trusted keys for use with ``dig +sigchase``. This
|
||||
feature is now obsolete and has been removed; use ``delv`` instead.
|
||||
feature is now obsolete and has been removed; use :iscman:`delv` instead.
|
||||
|
||||
.. option:: +[no]ttlid
|
||||
|
||||
``+[no]ttlid``
|
||||
This option displays [or does not display] the TTL when printing the record.
|
||||
|
||||
``+[no]ttlunits``
|
||||
.. option:: +[no]ttlunits
|
||||
|
||||
This option displays [or does not display] the TTL in friendly human-readable time
|
||||
units of ``s``, ``m``, ``h``, ``d``, and ``w``, representing seconds, minutes,
|
||||
hours, days, and weeks. This implies ``+ttlid``.
|
||||
|
||||
``+[no]unknownformat``
|
||||
.. option:: +[no]unknownformat
|
||||
|
||||
This option prints all RDATA in unknown RR type presentation format (:rfc:`3597`).
|
||||
The default is to print RDATA for known types in the type's
|
||||
presentation format.
|
||||
|
||||
``+[no]vc``
|
||||
.. option:: +[no]vc
|
||||
|
||||
This option uses [or does not use] TCP when querying name servers. This alternate
|
||||
syntax to ``+[no]tcp`` is provided for backwards compatibility. The
|
||||
``vc`` stands for "virtual circuit."
|
||||
|
||||
``+[no]yaml``
|
||||
.. option:: +[no]yaml
|
||||
|
||||
When enabled, this option prints the responses (and, if ``+qr`` is in use, also the
|
||||
outgoing queries) in a detailed YAML format.
|
||||
|
||||
``+[no]zflag``
|
||||
.. option:: +[no]zflag
|
||||
|
||||
This option sets [or does not set] the last unassigned DNS header flag in a DNS query.
|
||||
This flag is off by default.
|
||||
|
||||
Multiple Queries
|
||||
~~~~~~~~~~~~~~~~
|
||||
|
||||
The BIND 9 implementation of ``dig`` supports specifying multiple
|
||||
queries on the command line (in addition to supporting the ``-f`` batch
|
||||
The BIND 9 implementation of :program:`dig` supports specifying multiple
|
||||
queries on the command line (in addition to supporting the :option:`-f` batch
|
||||
file option). Each of those queries can be supplied with its own set of
|
||||
flags, options, and query options.
|
||||
|
||||
@@ -619,19 +720,19 @@ query options. For example:
|
||||
|
||||
dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||
|
||||
shows how ``dig`` can be used from the command line to make three
|
||||
shows how :program:`dig` can be used from the command line to make three
|
||||
lookups: an ANY query for ``www.isc.org``, a reverse lookup of 127.0.0.1,
|
||||
and a query for the NS records of ``isc.org``. A global query option of
|
||||
``+qr`` is applied, so that ``dig`` shows the initial query it made for
|
||||
``+qr`` is applied, so that :program:`dig` shows the initial query it made for
|
||||
each lookup. The final query has a local query option of ``+noqr`` which
|
||||
means that ``dig`` does not print the initial query when it looks up the
|
||||
means that :program:`dig` does not print the initial query when it looks up the
|
||||
NS records for ``isc.org``.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``dig`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``dig``
|
||||
If :program:`dig` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`dig`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, use the parameters
|
||||
@@ -641,7 +742,7 @@ variable.
|
||||
Return Codes
|
||||
~~~~~~~~~~~~
|
||||
|
||||
``dig`` return codes are:
|
||||
:program:`dig` return codes are:
|
||||
|
||||
``0``
|
||||
DNS response received, including NXDOMAIN status
|
||||
@@ -668,7 +769,7 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`delv(1)`, :manpage:`host(1)`, :manpage:`named(8)`, :manpage:`dnssec-keygen(8)`, :rfc:`1035`.
|
||||
:iscman:`delv(1) <delv>`, :iscman:`host(1) <host>`, :iscman:`named(8) <named>`, :iscman:`dnssec-keygen(8) <dnssec-keygen>`, :rfc:`1035`.
|
||||
|
||||
Bugs
|
||||
~~~~
|
||||
|
||||
+178
-78
@@ -89,7 +89,7 @@ dig_lookuplist_t lookup_list;
|
||||
dig_serverlist_t server_list;
|
||||
dig_searchlistlist_t search_list;
|
||||
|
||||
static atomic_bool cancel_now = ATOMIC_VAR_INIT(false);
|
||||
static atomic_bool cancel_now = false;
|
||||
|
||||
bool check_ra = false, have_ipv4 = false, have_ipv6 = false,
|
||||
specified_source = false, free_now = false, usesearch = false,
|
||||
@@ -105,8 +105,8 @@ isc_nm_t *netmgr = NULL;
|
||||
isc_taskmgr_t *taskmgr = NULL;
|
||||
isc_task_t *global_task = NULL;
|
||||
isc_sockaddr_t localaddr;
|
||||
isc_refcount_t sendcount = ATOMIC_VAR_INIT(0);
|
||||
isc_refcount_t recvcount = ATOMIC_VAR_INIT(0);
|
||||
isc_refcount_t sendcount = 0;
|
||||
isc_refcount_t recvcount = 0;
|
||||
int ndots = -1;
|
||||
int tries = -1;
|
||||
int lookup_counter = 0;
|
||||
@@ -1358,7 +1358,7 @@ setup_libs(void) {
|
||||
|
||||
isc_managers_create(mctx, 1, 0, &netmgr, &taskmgr, NULL);
|
||||
|
||||
result = isc_task_create(taskmgr, 0, &global_task);
|
||||
result = isc_task_create(taskmgr, 0, &global_task, 0);
|
||||
check_result(result, "isc_task_create");
|
||||
isc_task_setname(global_task, "dig", NULL);
|
||||
|
||||
@@ -2616,17 +2616,26 @@ send_done(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
|
||||
isc_nmhandle_detach(&query->sendhandle);
|
||||
|
||||
if (eresult != ISC_R_SUCCESS) {
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
debug("send failed: %s", isc_result_totext(eresult));
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
debug("send_done: cancel");
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
|
||||
lookup_detach(&l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
debug("send failed: %s", isc_result_totext(eresult));
|
||||
cancel_lookup(l);
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
|
||||
lookup_attach(query->lookup, &l);
|
||||
if (l->ns_search_only && !l->trace_root && !l->tcp_mode) {
|
||||
debug("sending next, since searching");
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
@@ -2666,6 +2675,12 @@ _cancel_lookup(dig_lookup_t *lookup, const char *file, unsigned int line) {
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
next = ISC_LIST_NEXT(query, link);
|
||||
ISC_LIST_DEQUEUE(lookup->q, query, link);
|
||||
debug("canceling pending query %p, belonging to %p", query,
|
||||
query->lookup);
|
||||
query->canceled = true;
|
||||
if (query->readhandle != NULL) {
|
||||
isc_nm_cancelread(query->readhandle);
|
||||
}
|
||||
query_detach(&query);
|
||||
query = next;
|
||||
}
|
||||
@@ -2685,7 +2700,8 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg);
|
||||
static void
|
||||
start_tcp(dig_query_t *query) {
|
||||
isc_result_t result;
|
||||
dig_query_t *next;
|
||||
dig_query_t *next = NULL;
|
||||
dig_query_t *connectquery = NULL;
|
||||
REQUIRE(DIG_VALID_QUERY(query));
|
||||
|
||||
debug("start_tcp(%p)", query);
|
||||
@@ -2775,13 +2791,15 @@ start_tcp(dig_query_t *query) {
|
||||
|
||||
REQUIRE(query != NULL);
|
||||
|
||||
query_attach(query, &connectquery);
|
||||
|
||||
if (query->lookup->tls_mode) {
|
||||
result = isc_tlsctx_createclient(&query->tlsctx);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
isc_tlsctx_enable_dot_client_alpn(query->tlsctx);
|
||||
isc_nm_tlsdnsconnect(netmgr, &localaddr,
|
||||
&query->sockaddr, tcp_connected,
|
||||
query, local_timeout, 0,
|
||||
connectquery, local_timeout, 0,
|
||||
query->tlsctx);
|
||||
#if HAVE_LIBNGHTTP2
|
||||
} else if (query->lookup->https_mode) {
|
||||
@@ -2801,13 +2819,13 @@ start_tcp(dig_query_t *query) {
|
||||
|
||||
isc_nm_httpconnect(netmgr, &localaddr, &query->sockaddr,
|
||||
uri, !query->lookup->https_get,
|
||||
tcp_connected, query, query->tlsctx,
|
||||
local_timeout, 0);
|
||||
tcp_connected, connectquery,
|
||||
query->tlsctx, local_timeout, 0);
|
||||
#endif
|
||||
} else {
|
||||
isc_nm_tcpdnsconnect(netmgr, &localaddr,
|
||||
&query->sockaddr, tcp_connected,
|
||||
query, local_timeout, 0);
|
||||
connectquery, local_timeout, 0);
|
||||
}
|
||||
|
||||
/* XXX: set DSCP */
|
||||
@@ -2878,20 +2896,23 @@ udp_ready(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
dig_query_t *readquery = NULL;
|
||||
int local_timeout = timeout * 1000;
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
dig_lookup_t *l = query->lookup;
|
||||
|
||||
debug("in cancel handler");
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
return;
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
dig_lookup_t *l = query->lookup;
|
||||
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
debug("udp setup failed: %s",
|
||||
isc_result_totext(eresult));
|
||||
}
|
||||
|
||||
debug("udp setup failed: %s", isc_result_totext(eresult));
|
||||
query_detach(&query);
|
||||
cancel_lookup(l);
|
||||
lookup_detach(&l);
|
||||
query_detach(&query);
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -3040,7 +3061,8 @@ force_next(dig_query_t *query) {
|
||||
|
||||
if (l->retries > 1) {
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left", l->retries);
|
||||
debug("making new %s request, %d tries left",
|
||||
l->tcp_mode ? "TCP" : "UDP", l->retries);
|
||||
requeue_lookup(l, true);
|
||||
lookup_detach(&l);
|
||||
isc_refcount_decrement0(&recvcount);
|
||||
@@ -3143,8 +3165,6 @@ launch_next_query(dig_query_t *query) {
|
||||
debug("have local timeout of %d", local_timeout);
|
||||
isc_nmhandle_settimeout(query->handle, local_timeout);
|
||||
|
||||
query_attach(query, &readquery);
|
||||
|
||||
xfr = query->lookup->rdtype == dns_rdatatype_ixfr ||
|
||||
query->lookup->rdtype == dns_rdatatype_axfr;
|
||||
if (xfr && isc_nm_socket_type(query->handle) == isc_nm_tlsdnssocket &&
|
||||
@@ -3163,6 +3183,8 @@ launch_next_query(dig_query_t *query) {
|
||||
return;
|
||||
}
|
||||
|
||||
query_attach(query, &readquery);
|
||||
|
||||
isc_nm_read(query->handle, recv_done, readquery);
|
||||
|
||||
if (!query->first_soa_rcvd) {
|
||||
@@ -3233,9 +3255,12 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
isc_tlsctx_free(&query->tlsctx);
|
||||
}
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
debug("in cancel handler");
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
clear_current_lookup();
|
||||
@@ -3245,12 +3270,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
debug("unsuccessful connection: %s",
|
||||
isc_result_totext(eresult));
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
if (eresult != ISC_R_CANCELED) {
|
||||
dighost_warning("Connection to %s(%s) for %s failed: "
|
||||
"%s.",
|
||||
sockstr, query->servname, l->textname,
|
||||
isc_result_totext(eresult));
|
||||
}
|
||||
dighost_warning("Connection to %s(%s) for %s failed: %s.",
|
||||
sockstr, query->servname, l->textname,
|
||||
isc_result_totext(eresult));
|
||||
|
||||
/* XXX Clean up exitcodes */
|
||||
if (exitcode < 9) {
|
||||
@@ -3258,9 +3280,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
}
|
||||
|
||||
if (l->retries > 1) {
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
l->retries--;
|
||||
requeue_lookup(l, true);
|
||||
next = NULL;
|
||||
} else if ((l->current_query != NULL) &&
|
||||
@@ -3272,6 +3294,9 @@ tcp_connected(isc_nmhandle_t *handle, isc_result_t eresult, void *arg) {
|
||||
}
|
||||
|
||||
query_detach(&query);
|
||||
if (next == NULL) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
lookup_detach(&l);
|
||||
|
||||
if (next != NULL) {
|
||||
@@ -3579,64 +3604,139 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
isc_refcount_decrement0(&recvcount);
|
||||
debug("recvcount=%" PRIuFAST32, isc_refcount_current(&recvcount));
|
||||
|
||||
if (eresult == ISC_R_CANCELED) {
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (eresult == ISC_R_CANCELED || query->canceled) {
|
||||
debug("recv_done: cancel");
|
||||
isc_nmhandle_detach(&query->readhandle);
|
||||
if (!query->canceled) {
|
||||
cancel_lookup(l);
|
||||
}
|
||||
query_detach(&query);
|
||||
lookup_detach(&l);
|
||||
UNLOCK_LOOKUP;
|
||||
return;
|
||||
}
|
||||
|
||||
lookup_attach(query->lookup, &l);
|
||||
|
||||
if (query->lookup->use_usec) {
|
||||
TIME_NOW_HIRES(&query->time_recv);
|
||||
} else {
|
||||
TIME_NOW(&query->time_recv);
|
||||
}
|
||||
|
||||
if (eresult == ISC_R_TIMEDOUT && !l->tcp_mode && l->retries > 1) {
|
||||
dig_query_t *newq = NULL;
|
||||
|
||||
l->retries--;
|
||||
debug("resending UDP request to first server, %d tries left",
|
||||
l->retries);
|
||||
newq = new_query(l, query->servname, query->userarg);
|
||||
|
||||
ISC_LIST_PREPEND(l->q, newq, link);
|
||||
|
||||
start_udp(ISC_LIST_HEAD(l->q));
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
if ((!l->pending && !l->ns_search_only) || atomic_load(&cancel_now)) {
|
||||
debug("no longer pending. Got %s", isc_result_totext(eresult));
|
||||
|
||||
goto next_lookup;
|
||||
}
|
||||
|
||||
if (eresult != ISC_R_SUCCESS) {
|
||||
if (eresult == ISC_R_TIMEDOUT) {
|
||||
if (l->retries > 1 && !l->tcp_mode) {
|
||||
dig_query_t *newq = NULL;
|
||||
|
||||
/*
|
||||
* For UDP, insert a copy of the current query just
|
||||
* after itself in the list, and start it to retry the
|
||||
* request.
|
||||
*/
|
||||
newq = new_query(l, query->servname, query->userarg);
|
||||
ISC_LIST_INSERTAFTER(l->q, query, newq, link);
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
l->retries--;
|
||||
debug("making new UDP request, %d tries left",
|
||||
l->retries);
|
||||
start_udp(newq);
|
||||
}
|
||||
|
||||
goto detach_query;
|
||||
} else if (l->retries > 1 && l->tcp_mode) {
|
||||
/*
|
||||
* For TCP, we have to requeue the whole lookup, see
|
||||
* the comments above the start_tcp() function.
|
||||
*/
|
||||
l->retries--;
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
requeue_lookup(l, true);
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
|
||||
goto cancel_lookup;
|
||||
} else {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
|
||||
/*
|
||||
* No retries left, go to the next query, if there is
|
||||
* one.
|
||||
*/
|
||||
if (next != NULL) {
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
debug("starting next query %p", next);
|
||||
if (l->tcp_mode) {
|
||||
start_tcp(next);
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
/*
|
||||
* Otherwise, print the cmdline and an error message,
|
||||
* and cancel the lookup.
|
||||
*/
|
||||
printf("%s", l->cmdline);
|
||||
dighost_error("connection timed out; "
|
||||
"no servers could be reached\n");
|
||||
if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
}
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
|
||||
goto cancel_lookup;
|
||||
}
|
||||
} else if (eresult != ISC_R_SUCCESS) {
|
||||
dig_query_t *next = ISC_LIST_NEXT(query, link);
|
||||
char sockstr[ISC_SOCKADDR_FORMATSIZE];
|
||||
isc_sockaddr_format(&query->sockaddr, sockstr, sizeof(sockstr));
|
||||
|
||||
if (eresult == ISC_R_TIMEDOUT) {
|
||||
if (l->retries > 1) {
|
||||
debug("making new TCP request, %d tries left",
|
||||
l->retries);
|
||||
l->retries--;
|
||||
requeue_lookup(l, true);
|
||||
} else {
|
||||
printf("%s", l->cmdline);
|
||||
dighost_error("connection timed out; "
|
||||
"no servers could be reached\n");
|
||||
if (exitcode < 9) {
|
||||
exitcode = 9;
|
||||
/*
|
||||
* There was a communication error with the current query,
|
||||
* go to the next query, if there is one.
|
||||
*/
|
||||
if (next != NULL) {
|
||||
if (l->current_query == query) {
|
||||
query_detach(&l->current_query);
|
||||
}
|
||||
if (l->current_query == NULL) {
|
||||
debug("starting next query %p", next);
|
||||
if (l->tcp_mode) {
|
||||
start_tcp(next);
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
dighost_error("communications error to %s: %s\n",
|
||||
sockstr, isc_result_totext(eresult));
|
||||
goto detach_query;
|
||||
}
|
||||
|
||||
/*
|
||||
* Otherwise, print an error message and cancel the
|
||||
* lookup.
|
||||
*/
|
||||
dighost_error("communications error to %s: %s\n", sockstr,
|
||||
isc_result_totext(eresult));
|
||||
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
@@ -3896,15 +3996,6 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
} else {
|
||||
start_udp(next);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* If our query is at the head of the list and there
|
||||
* is no next, we're the only one left, so fall
|
||||
* through to print the message.
|
||||
*/
|
||||
if ((ISC_LIST_HEAD(l->q) != query) ||
|
||||
(ISC_LIST_NEXT(query, link) != NULL)) {
|
||||
dighost_comments(l,
|
||||
"Got %s from %s, trying next "
|
||||
"server",
|
||||
@@ -3912,7 +4003,7 @@ recv_done(isc_nmhandle_t *handle, isc_result_t eresult, isc_region_t *region,
|
||||
? "SERVFAIL reply"
|
||||
: "recursion not available",
|
||||
query->servname);
|
||||
goto next_lookup;
|
||||
goto detach_query;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4186,6 +4277,17 @@ onrun_callback(isc_task_t *task, isc_event_t *event) {
|
||||
UNLOCK_LOOKUP;
|
||||
}
|
||||
|
||||
void
|
||||
onshutdown_callback(isc_task_t *task, isc_event_t *event) {
|
||||
UNUSED(task);
|
||||
|
||||
isc_event_free(&event);
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
cancel_all();
|
||||
}
|
||||
|
||||
/*%
|
||||
* Make everything on the lookup queue go away. Mainly used by the
|
||||
* SIGINT handler.
|
||||
@@ -4208,6 +4310,7 @@ cancel_all(void) {
|
||||
nq = ISC_LIST_NEXT(q, link);
|
||||
debug("canceling pending query %p, belonging to %p", q,
|
||||
current_lookup);
|
||||
q->canceled = true;
|
||||
if (q->readhandle != NULL) {
|
||||
isc_nm_cancelread(q->readhandle);
|
||||
}
|
||||
@@ -4237,9 +4340,6 @@ cancel_all(void) {
|
||||
*/
|
||||
void
|
||||
destroy_libs(void) {
|
||||
if (keep != NULL) {
|
||||
isc_nmhandle_detach(&keep);
|
||||
}
|
||||
debug("destroy_libs()");
|
||||
if (global_task != NULL) {
|
||||
debug("freeing task");
|
||||
|
||||
@@ -188,6 +188,7 @@ struct dig_query {
|
||||
bool second_rr_rcvd;
|
||||
bool first_repeat_rcvd;
|
||||
bool warn_id;
|
||||
bool canceled;
|
||||
uint32_t first_rr_serial;
|
||||
uint32_t second_rr_serial;
|
||||
uint32_t msg_count;
|
||||
@@ -305,6 +306,9 @@ start_lookup(void);
|
||||
void
|
||||
onrun_callback(isc_task_t *task, isc_event_t *event);
|
||||
|
||||
void
|
||||
onshutdown_callback(isc_task_t *task, isc_event_t *event);
|
||||
|
||||
int
|
||||
dhmain(int argc, char **argv);
|
||||
|
||||
|
||||
+1
-7
@@ -584,12 +584,6 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf, dns_message_t *msg,
|
||||
|
||||
static const char *optstring = "46aAc:dilnm:p:rst:vVwCDN:R:TUW:";
|
||||
|
||||
/*% version */
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "host %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
static void
|
||||
pre_parse_args(int argc, char **argv) {
|
||||
int c;
|
||||
@@ -663,7 +657,7 @@ pre_parse_args(int argc, char **argv) {
|
||||
case 'v':
|
||||
break;
|
||||
case 'V':
|
||||
version();
|
||||
printf("host %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
break;
|
||||
case 'w':
|
||||
|
||||
+76
-54
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: host
|
||||
.. program:: host
|
||||
.. _man_host:
|
||||
|
||||
host - DNS lookup utility
|
||||
@@ -24,55 +26,64 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``host`` is a simple utility for performing DNS lookups. It is normally
|
||||
:program:`host` is a simple utility for performing DNS lookups. It is normally
|
||||
used to convert names to IP addresses and vice versa. When no arguments
|
||||
or options are given, ``host`` prints a short summary of its
|
||||
or options are given, :program:`host` prints a short summary of its
|
||||
command-line arguments and options.
|
||||
|
||||
``name`` is the domain name that is to be looked up. It can also be a
|
||||
dotted-decimal IPv4 address or a colon-delimited IPv6 address, in which
|
||||
case ``host`` by default performs a reverse lookup for that address.
|
||||
case :program:`host` by default performs a reverse lookup for that address.
|
||||
``server`` is an optional argument which is either the name or IP
|
||||
address of the name server that ``host`` should query instead of the
|
||||
address of the name server that :program:`host` should query instead of the
|
||||
server or servers listed in ``/etc/resolv.conf``.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
This option specifies that only IPv4 should be used for query transport. See also the ``-6`` option.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option specifies that only IPv6 should be used for query transport. See also the ``-4`` option.
|
||||
This option specifies that only IPv4 should be used for query transport. See also the :option:`-6` option.
|
||||
|
||||
``-a``
|
||||
The ``-a`` ("all") option is normally equivalent to ``-v -t ANY``. It
|
||||
also affects the behavior of the ``-l`` list zone option.
|
||||
.. option:: -6
|
||||
|
||||
``-A``
|
||||
The ``-A`` ("almost all") option is equivalent to ``-a``, except that RRSIG,
|
||||
This option specifies that only IPv6 should be used for query transport. See also the :option:`-4` option.
|
||||
|
||||
.. option:: -a
|
||||
|
||||
The :option:`-a` ("all") option is normally equivalent to :option:`-v` :option:`-t ANY <-t>`. It
|
||||
also affects the behavior of the :option:`-l` list zone option.
|
||||
|
||||
.. option:: -A
|
||||
|
||||
The :option:`-A` ("almost all") option is equivalent to :option:`-a`, except that RRSIG,
|
||||
NSEC, and NSEC3 records are omitted from the output.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the query class, which can be used to lookup HS (Hesiod) or CH (Chaosnet)
|
||||
class resource records. The default class is IN (Internet).
|
||||
|
||||
``-C``
|
||||
This option indicates that ``named`` should check consistency, meaning that ``host`` queries the SOA records for zone
|
||||
.. option:: -C
|
||||
|
||||
This option indicates that :iscman:`named` should check consistency, meaning that :program:`host` queries the SOA records for zone
|
||||
``name`` from all the listed authoritative name servers for that
|
||||
zone. The list of name servers is defined by the NS records that are
|
||||
found for the zone.
|
||||
|
||||
``-d``
|
||||
This option prints debugging traces, and is equivalent to the ``-v`` verbose option.
|
||||
.. option:: -d
|
||||
|
||||
``-l``
|
||||
This option tells ``named`` to list the zone, meaning the ``host`` command performs a zone transfer of zone
|
||||
This option prints debugging traces, and is equivalent to the :option:`-v` verbose option.
|
||||
|
||||
.. option:: -l
|
||||
|
||||
This option tells :iscman:`named` to list the zone, meaning the :program:`host` command performs a zone transfer of zone
|
||||
``name`` and prints out the NS, PTR, and address records (A/AAAA).
|
||||
|
||||
Together, the ``-l -a`` options print all records in the zone.
|
||||
Together, the :option:`-l` :option:`-a` options print all records in the zone.
|
||||
|
||||
.. option:: -N ndots
|
||||
|
||||
``-N ndots``
|
||||
This option specifies the number of dots (``ndots``) that have to be in ``name`` for it to be
|
||||
considered absolute. The default value is that defined using the
|
||||
``ndots`` statement in ``/etc/resolv.conf``, or 1 if no ``ndots`` statement
|
||||
@@ -80,85 +91,96 @@ Options
|
||||
and are searched for in the domains listed in the ``search`` or
|
||||
``domain`` directive in ``/etc/resolv.conf``.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option specifies the port to query on the server. The default is 53.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option specifies a non-recursive query; setting this option clears the RD (recursion
|
||||
desired) bit in the query. This means that the name server
|
||||
receiving the query does not attempt to resolve ``name``. The ``-r``
|
||||
option enables ``host`` to mimic the behavior of a name server by
|
||||
receiving the query does not attempt to resolve ``name``. The :option:`-r`
|
||||
option enables :program:`host` to mimic the behavior of a name server by
|
||||
making non-recursive queries, and expecting to receive answers to
|
||||
those queries that can be referrals to other name servers.
|
||||
|
||||
``-R number``
|
||||
.. option:: -R number
|
||||
|
||||
This option specifies the number of retries for UDP queries. If ``number`` is negative or zero,
|
||||
the number of retries is silently set to 1. The default value is 1, or
|
||||
the value of the ``attempts`` option in ``/etc/resolv.conf``, if set.
|
||||
|
||||
``-s``
|
||||
This option tells ``named`` *not* to send the query to the next nameserver if any server responds
|
||||
.. option:: -s
|
||||
|
||||
This option tells :iscman:`named` *not* to send the query to the next nameserver if any server responds
|
||||
with a SERVFAIL response, which is the reverse of normal stub
|
||||
resolver behavior.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option specifies the query type. The ``type`` argument can be any recognized query type:
|
||||
CNAME, NS, SOA, TXT, DNSKEY, AXFR, etc.
|
||||
|
||||
When no query type is specified, ``host`` automatically selects an
|
||||
When no query type is specified, :program:`host` automatically selects an
|
||||
appropriate query type. By default, it looks for A, AAAA, and MX
|
||||
records. If the ``-C`` option is given, queries are made for SOA
|
||||
records. If the :option:`-C` option is given, queries are made for SOA
|
||||
records. If ``name`` is a dotted-decimal IPv4 address or
|
||||
colon-delimited IPv6 address, ``host`` queries for PTR records.
|
||||
colon-delimited IPv6 address, :program:`host` queries for PTR records.
|
||||
|
||||
If a query type of IXFR is chosen, the starting serial number can be
|
||||
specified by appending an equals sign (=), followed by the starting serial
|
||||
number, e.g., ``-t IXFR=12345678``.
|
||||
number, e.g., :option:`-t IXFR=12345678 <-t>`.
|
||||
|
||||
``-T``; ``-U``
|
||||
This option specifies TCP or UDP. By default, ``host`` uses UDP when making queries; the
|
||||
``-T`` option makes it use a TCP connection when querying the name
|
||||
.. option:: -T, -U
|
||||
|
||||
This option specifies TCP or UDP. By default, :program:`host` uses UDP when making queries; the
|
||||
:option:`-T` option makes it use a TCP connection when querying the name
|
||||
server. TCP is automatically selected for queries that require
|
||||
it, such as zone transfer (AXFR) requests. Type ``ANY`` queries default
|
||||
to TCP, but can be forced to use UDP initially via ``-U``.
|
||||
to TCP, but can be forced to use UDP initially via :option:`-U`.
|
||||
|
||||
.. option:: -m flag
|
||||
|
||||
``-m flag``
|
||||
This option sets memory usage debugging: the flag can be ``record``, ``usage``, or
|
||||
``trace``. The ``-m`` option can be specified more than once to set
|
||||
``trace``. The :option:`-m` option can be specified more than once to set
|
||||
multiple flags.
|
||||
|
||||
``-v``
|
||||
This option sets verbose output, and is equivalent to the ``-d`` debug option. Verbose output
|
||||
.. option:: -v
|
||||
|
||||
This option sets verbose output, and is equivalent to the :option:`-d` debug option. Verbose output
|
||||
can also be enabled by setting the ``debug`` option in
|
||||
``/etc/resolv.conf``.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-w``
|
||||
This option sets "wait forever": the query timeout is set to the maximum possible. See
|
||||
also the ``-W`` option.
|
||||
.. option:: -w
|
||||
|
||||
``-W wait``
|
||||
This options sets the length of the wait timeout, indicating that ``named`` should wait for up to ``wait`` seconds for a reply. If ``wait`` is
|
||||
This option sets "wait forever": the query timeout is set to the maximum possible. See
|
||||
also the :option:`-W` option.
|
||||
|
||||
.. option:: -W wait
|
||||
|
||||
This options sets the length of the wait timeout, indicating that :iscman:`named` should wait for up to ``wait`` seconds for a reply. If ``wait`` is
|
||||
less than 1, the wait interval is set to 1 second.
|
||||
|
||||
By default, ``host`` waits for 5 seconds for UDP responses and 10
|
||||
By default, :program:`host` waits for 5 seconds for UDP responses and 10
|
||||
seconds for TCP connections. These defaults can be overridden by the
|
||||
``timeout`` option in ``/etc/resolv.conf``.
|
||||
|
||||
See also the ``-w`` option.
|
||||
See also the :option:`-w` option.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``host`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``host``
|
||||
If :program:`host` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`host`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, define the ``IDN_DISABLE``
|
||||
environment variable. IDN support is disabled if the variable is set
|
||||
when ``host`` runs.
|
||||
when :program:`host` runs.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
@@ -168,4 +190,4 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`named(8)`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`named(8) <named>`.
|
||||
|
||||
+1
-8
@@ -612,17 +612,10 @@ set_ndots(const char *value) {
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "nslookup %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
static void
|
||||
setoption(char *opt) {
|
||||
size_t l = strlen(opt);
|
||||
|
||||
debugging = true;
|
||||
|
||||
#define CHECKOPT(A, N) \
|
||||
((l >= N) && (l < sizeof(A)) && (strncasecmp(opt, A, l) == 0))
|
||||
|
||||
@@ -882,7 +875,7 @@ parse_args(int argc, char **argv) {
|
||||
debug("main parsing %s", argv[0]);
|
||||
if (argv[0][0] == '-') {
|
||||
if (strncasecmp(argv[0], "-ver", 4) == 0) {
|
||||
version();
|
||||
printf("nslookup %s\n", PACKAGE_VERSION);
|
||||
exit(0);
|
||||
} else if (argv[0][1] != 0) {
|
||||
setoption(&argv[0][1]);
|
||||
|
||||
+13
-11
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: nslookup
|
||||
.. program:: nslookup
|
||||
.. _man_nslookup:
|
||||
|
||||
nslookup - query Internet name servers interactively
|
||||
@@ -24,8 +26,8 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``nslookup`` is a program to query Internet domain name servers.
|
||||
``nslookup`` has two modes: interactive and non-interactive. Interactive
|
||||
:program:`nslookup` is a program to query Internet domain name servers.
|
||||
:program:`nslookup` has two modes: interactive and non-interactive. Interactive
|
||||
mode allows the user to query name servers for information about various
|
||||
hosts and domains or to print a list of hosts in a domain.
|
||||
Non-interactive mode prints just the name and requested
|
||||
@@ -54,16 +56,16 @@ seconds, type:
|
||||
|
||||
nslookup -query=hinfo -timeout=10
|
||||
|
||||
The ``-version`` option causes ``nslookup`` to print the version number
|
||||
The ``-version`` option causes :program:`nslookup` to print the version number
|
||||
and immediately exit.
|
||||
|
||||
Interactive Commands
|
||||
~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
``host [server]``
|
||||
This command looks up information for ``host`` using the current default server or
|
||||
using ``server``, if specified. If ``host`` is an Internet address and the
|
||||
query type is A or PTR, the name of the host is returned. If ``host`` is
|
||||
This command looks up information for :iscman:`host` using the current default server or
|
||||
using ``server``, if specified. If :iscman:`host` is an Internet address and the
|
||||
query type is A or PTR, the name of the host is returned. If :iscman:`host` is
|
||||
a name and does not have a trailing period (``.``), the search list is used
|
||||
to qualify the name.
|
||||
|
||||
@@ -181,19 +183,19 @@ Interactive Commands
|
||||
Return Values
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
``nslookup`` returns with an exit status of 1 if any query failed, and 0
|
||||
:program:`nslookup` returns with an exit status of 1 if any query failed, and 0
|
||||
otherwise.
|
||||
|
||||
IDN Support
|
||||
~~~~~~~~~~~
|
||||
|
||||
If ``nslookup`` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. ``nslookup``
|
||||
If :program:`nslookup` has been built with IDN (internationalized domain name)
|
||||
support, it can accept and display non-ASCII domain names. :program:`nslookup`
|
||||
appropriately converts character encoding of a domain name before sending
|
||||
a request to a DNS server or displaying a reply from the server.
|
||||
To turn off IDN support, define the ``IDN_DISABLE``
|
||||
environment variable. IDN support is disabled if the variable is set
|
||||
when ``nslookup`` runs, or when the standard output is not a tty.
|
||||
when :program:`nslookup` runs, or when the standard output is not a tty.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
@@ -203,4 +205,4 @@ Files
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`host(1)`, :manpage:`named(8)`.
|
||||
:iscman:`dig(1) <dig>`, :iscman:`host(1) <host>`, :iscman:`named(8) <named>`.
|
||||
|
||||
+55
-42
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-cds
|
||||
.. program:: dnssec-cds
|
||||
.. _man_dnssec-cds:
|
||||
|
||||
dnssec-cds - change DS records for a child zone based on CDS/CDNSKEY
|
||||
@@ -24,59 +26,60 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-cds`` command changes DS records at a delegation point
|
||||
The :program:`dnssec-cds` command changes DS records at a delegation point
|
||||
based on CDS or CDNSKEY records published in the child zone. If both CDS
|
||||
and CDNSKEY records are present in the child zone, the CDS is preferred.
|
||||
This enables a child zone to inform its parent of upcoming changes to
|
||||
its key-signing keys (KSKs); by polling periodically with ``dnssec-cds``, the
|
||||
its key-signing keys (KSKs); by polling periodically with :program:`dnssec-cds`, the
|
||||
parent can keep the DS records up-to-date and enable automatic rolling
|
||||
of KSKs.
|
||||
|
||||
Two input files are required. The ``-f child-file`` option specifies a
|
||||
Two input files are required. The :option:`-f child-file <-f>` option specifies a
|
||||
file containing the child's CDS and/or CDNSKEY records, plus RRSIG and
|
||||
DNSKEY records so that they can be authenticated. The ``-d path`` option
|
||||
DNSKEY records so that they can be authenticated. The :option:`-d path <-d>` option
|
||||
specifies the location of a file containing the current DS records. For
|
||||
example, this could be a ``dsset-`` file generated by
|
||||
``dnssec-signzone``, or the output of ``dnssec-dsfromkey``, or the
|
||||
output of a previous run of ``dnssec-cds``.
|
||||
:iscman:`dnssec-signzone`, or the output of :iscman:`dnssec-dsfromkey`, or the
|
||||
output of a previous run of :program:`dnssec-cds`.
|
||||
|
||||
The ``dnssec-cds`` command uses special DNSSEC validation logic
|
||||
The :program:`dnssec-cds` command uses special DNSSEC validation logic
|
||||
specified by :rfc:`7344`. It requires that the CDS and/or CDNSKEY records
|
||||
be validly signed by a key represented in the existing DS records. This
|
||||
is typically the pre-existing KSK.
|
||||
|
||||
For protection against replay attacks, the signatures on the child
|
||||
records must not be older than they were on a previous run of
|
||||
``dnssec-cds``. Their age is obtained from the modification time of the
|
||||
``dsset-`` file, or from the ``-s`` option.
|
||||
:program:`dnssec-cds`. Their age is obtained from the modification time of the
|
||||
``dsset-`` file, or from the :option:`-s` option.
|
||||
|
||||
To protect against breaking the delegation, ``dnssec-cds`` ensures that
|
||||
To protect against breaking the delegation, :program:`dnssec-cds` ensures that
|
||||
the DNSKEY RRset can be verified by every key algorithm in the new DS
|
||||
RRset, and that the same set of keys are covered by every DS digest
|
||||
type.
|
||||
|
||||
By default, replacement DS records are written to the standard output;
|
||||
with the ``-i`` option the input file is overwritten in place. The
|
||||
with the :option:`-i` option the input file is overwritten in place. The
|
||||
replacement DS records are the same as the existing records, when no
|
||||
change is required. The output can be empty if the CDS/CDNSKEY records
|
||||
specify that the child zone wants to be insecure.
|
||||
|
||||
.. warning::
|
||||
|
||||
Be careful not to delete the DS records when ``dnssec-cds`` fails!
|
||||
Be careful not to delete the DS records when :program:`dnssec-cds` fails!
|
||||
|
||||
Alternatively, ``dnssec-cds -u`` writes an ``nsupdate`` script to the
|
||||
standard output. The ``-u`` and ``-i`` options can be used together to
|
||||
maintain a ``dsset-`` file as well as emit an ``nsupdate`` script.
|
||||
Alternatively, :option`dnssec-cds -u` writes an :iscman:`nsupdate` script to the
|
||||
standard output. The :option:`-u` and :option:`-i` options can be used together to
|
||||
maintain a ``dsset-`` file as well as emit an :iscman:`nsupdate` script.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
When converting CDS records to DS records, this option specifies
|
||||
the acceptable digest algorithms. This option can be repeated, so
|
||||
that multiple digest types are allowed. If none of the CDS records
|
||||
use an acceptable digest type, ``dnssec-cds`` will try to use CDNSKEY
|
||||
use an acceptable digest type, :program:`dnssec-cds` will try to use CDNSKEY
|
||||
records instead; if there are no CDNSKEY records, it reports an error.
|
||||
|
||||
When converting CDNSKEY records to DS records, this option specifies the
|
||||
@@ -87,35 +90,40 @@ Options
|
||||
are case-insensitive, and the hyphen may be omitted. If no algorithm
|
||||
is specified, the default is SHA-256 only.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zones.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option generates DS records from CDNSKEY records if both CDS and CDNSKEY
|
||||
records are present in the child zone. By default CDS records are
|
||||
preferred.
|
||||
|
||||
``-d path``
|
||||
.. option:: -d path
|
||||
|
||||
This specifies the location of the parent DS records. The path can be the name of a file
|
||||
containing the DS records; if it is a directory, ``dnssec-cds``
|
||||
containing the DS records; if it is a directory, :program:`dnssec-cds`
|
||||
looks for a ``dsset-`` file for the domain inside the directory.
|
||||
|
||||
To protect against replay attacks, child records are rejected if they
|
||||
were signed earlier than the modification time of the ``dsset-``
|
||||
file. This can be adjusted with the ``-s`` option.
|
||||
file. This can be adjusted with the :option:`-s` option.
|
||||
|
||||
.. option:: -f child-file
|
||||
|
||||
``-f child-file``
|
||||
This option specifies the file containing the child's CDS and/or CDNSKEY records, plus its
|
||||
DNSKEY records and the covering RRSIG records, so that they can be
|
||||
authenticated.
|
||||
|
||||
The examples below describe how to generate this file.
|
||||
|
||||
``-iextension``
|
||||
.. option:: -i extension
|
||||
|
||||
This option updates the ``dsset-`` file in place, instead of writing DS records to
|
||||
the standard output.
|
||||
|
||||
There must be no space between the ``-i`` and the extension. If
|
||||
There must be no space between the :option:`-i` and the extension. If
|
||||
no extension is provided, the old ``dsset-`` is discarded. If an
|
||||
extension is present, a backup of the old ``dsset-`` file is kept
|
||||
with the extension appended to its filename.
|
||||
@@ -125,7 +133,8 @@ Options
|
||||
child records, provided that it is later than the file's current
|
||||
modification time.
|
||||
|
||||
``-s start-time``
|
||||
.. option:: -s start-time
|
||||
|
||||
This option specifies the date and time after which RRSIG records become
|
||||
acceptable. This can be either an absolute or a relative time. An
|
||||
absolute start time is indicated by a number in YYYYMMDDHHMMSS
|
||||
@@ -137,24 +146,28 @@ Options
|
||||
If no start-time is specified, the modification time of the
|
||||
``dsset-`` file is used.
|
||||
|
||||
``-T ttl``
|
||||
.. option:: -T ttl
|
||||
|
||||
This option specifies a TTL to be used for new DS records. If not specified, the
|
||||
default is the TTL of the old DS records. If they had no explicit TTL,
|
||||
the new DS records also have no explicit TTL.
|
||||
|
||||
``-u``
|
||||
This option writes an ``nsupdate`` script to the standard output, instead of
|
||||
.. option:: -u
|
||||
|
||||
This option writes an :iscman:`nsupdate` script to the standard output, instead of
|
||||
printing the new DS reords. The output is empty if no change is
|
||||
needed.
|
||||
|
||||
Note: The TTL of new records needs to be specified: it can be done in the
|
||||
original ``dsset-`` file, with the ``-T`` option, or using the
|
||||
``nsupdate`` ``ttl`` command.
|
||||
original ``dsset-`` file, with the :option:`-T` option, or using the
|
||||
:iscman:`nsupdate` ``ttl`` command.
|
||||
|
||||
.. option:: -V
|
||||
|
||||
``-V``
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level. Level 1 is intended to be usefully verbose
|
||||
for general users; higher levels are intended for developers.
|
||||
|
||||
@@ -164,7 +177,7 @@ Options
|
||||
Exit Status
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-cds`` command exits 0 on success, or non-zero if an error
|
||||
The :program:`dnssec-cds` command exits 0 on success, or non-zero if an error
|
||||
occurred.
|
||||
|
||||
If successful, the DS records may or may not need to be
|
||||
@@ -173,12 +186,12 @@ changed.
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
Before running ``dnssec-signzone``, ensure that the delegations
|
||||
are up-to-date by running ``dnssec-cds`` on every ``dsset-`` file.
|
||||
Before running :iscman:`dnssec-signzone`, ensure that the delegations
|
||||
are up-to-date by running :program:`dnssec-cds` on every ``dsset-`` file.
|
||||
|
||||
To fetch the child records required by ``dnssec-cds``, invoke
|
||||
``dig`` as in the script below. It is acceptable if the ``dig`` fails, since
|
||||
``dnssec-cds`` performs all the necessary checking.
|
||||
To fetch the child records required by :program:`dnssec-cds`, invoke
|
||||
:iscman:`dig` as in the script below. It is acceptable if the :iscman:`dig` fails, since
|
||||
:program:`dnssec-cds` performs all the necessary checking.
|
||||
|
||||
::
|
||||
|
||||
@@ -189,8 +202,8 @@ To fetch the child records required by ``dnssec-cds``, invoke
|
||||
dnssec-cds -i -f /dev/stdin -d $f $d
|
||||
done
|
||||
|
||||
When the parent zone is automatically signed by ``named``,
|
||||
``dnssec-cds`` can be used with ``nsupdate`` to maintain a delegation as follows.
|
||||
When the parent zone is automatically signed by :iscman:`named`,
|
||||
:program:`dnssec-cds` can be used with :iscman:`nsupdate` to maintain a delegation as follows.
|
||||
The ``dsset-`` file allows the script to avoid having to fetch and
|
||||
validate the parent DS records, and it maintains the replay attack
|
||||
protection time.
|
||||
@@ -204,5 +217,5 @@ protection time.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dig(1)`, :manpage:`dnssec-settime(8)`, :manpage:`dnssec-signzone(8)`, :manpage:`nsupdate(1)`, BIND 9 Administrator
|
||||
:iscman:`dig(1) <dig>`, :iscman:`dnssec-settime(8) <dnssec-settime>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, :iscman:`nsupdate(1) <nsupdate>`, BIND 9 Administrator
|
||||
Reference Manual, :rfc:`7344`.
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-dsfromkey
|
||||
.. program:: dnssec-dsfromkey
|
||||
.. _man_dnssec-dsfromkey:
|
||||
|
||||
dnssec-dsfromkey - DNSSEC DS RR generation tool
|
||||
@@ -30,34 +32,37 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
The ``dnssec-dsfromkey`` command outputs DS (Delegation Signer) resource records
|
||||
(RRs), or CDS (Child DS) RRs with the ``-C`` option.
|
||||
The :program:`dnssec-dsfromkey` command outputs DS (Delegation Signer) resource records
|
||||
(RRs), or CDS (Child DS) RRs with the :option:`-C` option.
|
||||
|
||||
By default, only KSKs are converted (keys with flags = 257). The
|
||||
``-A`` option includes ZSKs (flags = 256). Revoked keys are never
|
||||
:option:`-A` option includes ZSKs (flags = 256). Revoked keys are never
|
||||
included.
|
||||
|
||||
The input keys can be specified in a number of ways:
|
||||
|
||||
By default, ``dnssec-dsfromkey`` reads a key file named in the format
|
||||
``Knnnn.+aaa+iiiii.key``, as generated by ``dnssec-keygen``.
|
||||
By default, :program:`dnssec-dsfromkey` reads a key file named in the format
|
||||
``Knnnn.+aaa+iiiii.key``, as generated by :iscman:`dnssec-keygen`.
|
||||
|
||||
With the ``-f file`` option, ``dnssec-dsfromkey`` reads keys from a zone
|
||||
With the :option:`-f file <-f>` option, :program:`dnssec-dsfromkey` reads keys from a zone
|
||||
file or partial zone file (which can contain just the DNSKEY records).
|
||||
|
||||
With the ``-s`` option, ``dnssec-dsfromkey`` reads a ``keyset-`` file,
|
||||
as generated by ``dnssec-keygen`` ``-C``.
|
||||
With the :option:`-s` option, :program:`dnssec-dsfromkey` reads a ``keyset-`` file,
|
||||
as generated by :iscman:`dnssec-keygen` :option:`-C`.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-1``
|
||||
This option is an abbreviation for ``-a SHA1``.
|
||||
.. option:: -1
|
||||
|
||||
``-2``
|
||||
This option is an abbreviation for ``-a SHA-256``.
|
||||
This option is an abbreviation for :option:`-a SHA1 <-a>`.
|
||||
|
||||
.. option:: -2
|
||||
|
||||
This option is an abbreviation for :option:`-a SHA-256 <-a>`.
|
||||
|
||||
.. option:: -a algorithm
|
||||
|
||||
``-a algorithm``
|
||||
This option specifies a digest algorithm to use when converting DNSKEY records to
|
||||
DS records. This option can be repeated, so that multiple DS records
|
||||
are created for each DNSKEY record.
|
||||
@@ -66,47 +71,57 @@ Options
|
||||
are case-insensitive, and the hyphen may be omitted. If no algorithm
|
||||
is specified, the default is SHA-256.
|
||||
|
||||
``-A``
|
||||
.. option:: -A
|
||||
|
||||
This option indicates that ZSKs are to be included when generating DS records. Without this option, only
|
||||
keys which have the KSK flag set are converted to DS records and
|
||||
printed. This option is only useful in ``-f`` zone file mode.
|
||||
printed. This option is only useful in :option:`-f` zone file mode.
|
||||
|
||||
``-c class``
|
||||
This option specifies the DNS class; the default is IN. This option is only useful in ``-s`` keyset
|
||||
or ``-f`` zone file mode.
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class; the default is IN. This option is only useful in :option:`-s` keyset
|
||||
or :option:`-f` zone file mode.
|
||||
|
||||
.. option:: -C
|
||||
|
||||
``-C``
|
||||
This option generates CDS records rather than DS records.
|
||||
|
||||
``-f file``
|
||||
This option sets zone file mode, in which the final dnsname argument of ``dnssec-dsfromkey`` is the
|
||||
.. option:: -f file
|
||||
|
||||
This option sets zone file mode, in which the final dnsname argument of :program:`dnssec-dsfromkey` is the
|
||||
DNS domain name of a zone whose master file can be read from
|
||||
``file``. If the zone name is the same as ``file``, then it may be
|
||||
omitted.
|
||||
|
||||
If ``file`` is ``-``, then the zone data is read from the standard
|
||||
input. This makes it possible to use the output of the ``dig``
|
||||
input. This makes it possible to use the output of the :iscman:`dig`
|
||||
command as input, as in:
|
||||
|
||||
``dig dnskey example.com | dnssec-dsfromkey -f - example.com``
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints usage information.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option tells BIND 9 to look for key files or ``keyset-`` files in ``directory``.
|
||||
|
||||
``-s``
|
||||
This option enables keyset mode, in which the final dnsname argument from ``dnssec-dsfromkey`` is the DNS
|
||||
.. option:: -s
|
||||
|
||||
This option enables keyset mode, in which the final dnsname argument from :program:`dnssec-dsfromkey` is the DNS
|
||||
domain name used to locate a ``keyset-`` file.
|
||||
|
||||
``-T TTL``
|
||||
.. option:: -T TTL
|
||||
|
||||
This option specifies the TTL of the DS records. By default the TTL is omitted.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
Example
|
||||
@@ -126,7 +141,7 @@ Files
|
||||
|
||||
The keyfile can be designated by the key identification
|
||||
``Knnnn.+aaa+iiiii`` or the full file name ``Knnnn.+aaa+iiiii.key``, as
|
||||
generated by ``dnssec-keygen``.
|
||||
generated by :iscman:`dnssec-keygen`.
|
||||
|
||||
The keyset file name is built from the ``directory``, the string
|
||||
``keyset-``, and the ``dnsname``.
|
||||
@@ -139,6 +154,6 @@ A keyfile error may return "file not found," even if the file exists.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`3658` (DS RRs), :rfc:`4509` (SHA-256 for DS RRs),
|
||||
:rfc:`6605` (SHA-384 for DS RRs), :rfc:`7344` (CDS and CDNSKEY RRs).
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-importkey
|
||||
.. program:: dnssec-importkey
|
||||
.. _man_dnssec-importkey:
|
||||
|
||||
dnssec-importkey - import DNSKEY records from external systems so they can be managed
|
||||
@@ -26,7 +28,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-importkey`` reads a public DNSKEY record and generates a pair
|
||||
:program:`dnssec-importkey` reads a public DNSKEY record and generates a pair
|
||||
of .key/.private files. The DNSKEY record may be read from an
|
||||
existing .key file, in which case a corresponding .private file is
|
||||
generated, or it may be read from any other file or from the standard
|
||||
@@ -34,14 +36,15 @@ input, in which case both .key and .private files are generated.
|
||||
|
||||
The newly created .private file does *not* contain private key data, and
|
||||
cannot be used for signing. However, having a .private file makes it
|
||||
possible to set publication (``-P``) and deletion (``-D``) times for the
|
||||
possible to set publication (:option:`-P`) and deletion (:option:`-D`) times for the
|
||||
key, which means the public key can be added to and removed from the
|
||||
DNSKEY RRset on schedule even if the true private key is stored offline.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-f filename``
|
||||
.. option:: -f filename
|
||||
|
||||
This option indicates the zone file mode. Instead of a public keyfile name, the argument is the
|
||||
DNS domain name of a zone master file, which can be read from
|
||||
``filename``. If the domain name is the same as ``filename``, then it may be
|
||||
@@ -50,23 +53,28 @@ Options
|
||||
If ``filename`` is set to ``"-"``, then the zone data is read from the
|
||||
standard input.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-L ttl``
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
place, in which case the existing TTL takes precedence. Setting the default TTL to ``0`` or ``none``
|
||||
removes it from the key.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
Timing Options
|
||||
@@ -81,21 +89,25 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
@@ -104,10 +116,10 @@ Files
|
||||
|
||||
A keyfile can be designed by the key identification ``Knnnn.+aaa+iiiii``
|
||||
or the full file name ``Knnnn.+aaa+iiiii.key``, as generated by
|
||||
``dnssec-keygen``.
|
||||
:iscman:`dnssec-keygen`.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`5011`.
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-keyfromlabel
|
||||
.. program:: dnssec-keyfromlabel
|
||||
.. _man_dnssec-keyfromlabel:
|
||||
|
||||
dnssec-keyfromlabel - DNSSEC key generation tool
|
||||
@@ -24,10 +26,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-keyfromlabel`` generates a pair of key files that reference a
|
||||
:program:`dnssec-keyfromlabel` generates a pair of key files that reference a
|
||||
key object stored in a cryptographic hardware service module (HSM). The
|
||||
private key file can be used for DNSSEC signing of zone data as if it
|
||||
were a conventional signing key created by ``dnssec-keygen``, but the
|
||||
were a conventional signing key created by :iscman:`dnssec-keygen`, but the
|
||||
key material is stored within the HSM and the actual signing takes
|
||||
place there.
|
||||
|
||||
@@ -37,40 +39,44 @@ match the name of the zone for which the key is being generated.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option selects the cryptographic algorithm. The value of ``algorithm`` must
|
||||
be one of RSASHA1, NSEC3RSASHA1, RSASHA256, RSASHA512,
|
||||
ECDSAP256SHA256, ECDSAP384SHA384, ED25519, or ED448.
|
||||
|
||||
If no algorithm is specified, RSASHA1 is used by default
|
||||
unless the ``-3`` option is specified, in which case NSEC3RSASHA1
|
||||
is used instead. (If ``-3`` is used and an algorithm is
|
||||
unless the :option:`-3` option is specified, in which case NSEC3RSASHA1
|
||||
is used instead. (If :option:`-3` is used and an algorithm is
|
||||
specified, that algorithm is checked for compatibility with
|
||||
NSEC3.)
|
||||
|
||||
These values are case-insensitive. In some cases, abbreviations are
|
||||
supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the ``-3``
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the :option:`-3`
|
||||
option, then NSEC3RSASHA1 is used instead.
|
||||
|
||||
Since BIND 9.12.0, this option is mandatory except when using the
|
||||
``-S`` option, which copies the algorithm from the predecessory key.
|
||||
:option:`-S` option, which copies the algorithm from the predecessory key.
|
||||
Previously, the default for newly generated keys was RSASHA1.
|
||||
|
||||
``-3``
|
||||
.. option:: -3
|
||||
|
||||
This option uses an NSEC3-capable algorithm to generate a DNSSEC key. If this
|
||||
option is used with an algorithm that has both NSEC and NSEC3
|
||||
versions, then the NSEC3 version is used; for example,
|
||||
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-l label``
|
||||
.. option:: -l label
|
||||
|
||||
This option specifies the label for a key pair in the crypto hardware.
|
||||
|
||||
When BIND 9 is built with OpenSSL-based PKCS#11 support, the label is
|
||||
@@ -78,56 +84,67 @@ Options
|
||||
preceded by an optional OpenSSL engine name, followed by a colon, as
|
||||
in ``pkcs11:keylabel``.
|
||||
|
||||
``-n nametype``
|
||||
.. option:: -n nametype
|
||||
|
||||
This option specifies the owner type of the key. The value of ``nametype`` must
|
||||
either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY
|
||||
(for a key associated with a host (KEY)), USER (for a key associated
|
||||
with a user (KEY)), or OTHER (DNSKEY). These values are
|
||||
case-insensitive.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
This option enables compatibility mode, which generates an old-style key, without any metadata.
|
||||
By default, ``dnssec-keyfromlabel`` includes the key's creation
|
||||
By default, :program:`dnssec-keyfromlabel` includes the key's creation
|
||||
date in the metadata stored with the private key; other dates may
|
||||
be set there as well, including publication date, activation date, etc. Keys
|
||||
that include this data may be incompatible with older versions of
|
||||
BIND; the ``-C`` option suppresses them.
|
||||
BIND; the :option:`-C` option suppresses them.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option indicates that the DNS record containing the key should have the
|
||||
specified class. If not specified, class IN is used.
|
||||
|
||||
``-f flag``
|
||||
.. option:: -f flag
|
||||
|
||||
This option sets the specified flag in the ``flag`` field of the KEY/DNSKEY record.
|
||||
The only recognized flags are KSK (Key-Signing Key) and REVOKE.
|
||||
|
||||
``-G``
|
||||
.. option:: -G
|
||||
|
||||
This option generates a key, but does not publish it or sign with it. This option is
|
||||
incompatible with ``-P`` and ``-A``.
|
||||
incompatible with :option:`-P` and :option:`-A`.
|
||||
|
||||
.. option:: -h
|
||||
|
||||
``-h``
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-keyfromlabel``.
|
||||
:program:`dnssec-keyfromlabel`.
|
||||
|
||||
.. option:: -K directory
|
||||
|
||||
``-K directory``
|
||||
This option sets the directory in which the key files are to be written.
|
||||
|
||||
``-k``
|
||||
.. option:: -k
|
||||
|
||||
This option generates KEY records rather than DNSKEY records.
|
||||
|
||||
``-L`` ttl
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
place, in which case the existing TTL would take precedence. Setting
|
||||
the default TTL to ``0`` or ``none`` removes it.
|
||||
|
||||
``-p protocol``
|
||||
.. option:: -p protocol
|
||||
|
||||
This option sets the protocol value for the key. The protocol is a number between
|
||||
0 and 255. The default is 3 (DNSSEC). Other possible values for this
|
||||
argument are listed in :rfc:`2535` and its successors.
|
||||
|
||||
``-S key``
|
||||
.. option:: -S key
|
||||
|
||||
This option generates a key as an explicit successor to an existing key. The name,
|
||||
algorithm, size, and type of the key are set to match the
|
||||
predecessor. The activation date of the new key is set to the
|
||||
@@ -135,19 +152,23 @@ Options
|
||||
set to the activation date minus the prepublication interval, which
|
||||
defaults to 30 days.
|
||||
|
||||
``-t type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the type of the key. ``type`` must be one of AUTHCONF,
|
||||
NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH refers
|
||||
to the ability to authenticate data, and CONF to the ability to encrypt
|
||||
data.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-y``
|
||||
.. option:: -y
|
||||
|
||||
This option allows DNSSEC key files to be generated even if the key ID would
|
||||
collide with that of an existing key, in the event of either key
|
||||
being revoked. (This is only safe to enable if
|
||||
@@ -166,41 +187,49 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it. If not set, and if the ``-G`` option has not been used, the
|
||||
to sign it. If not set, and if the :option:`-G` option has not been used, the
|
||||
default is the current date.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it. If not set,
|
||||
and if the ``-G`` option has not been used, the default is the current date.
|
||||
and if the :option:`-G` option has not been used, the default is the current date.
|
||||
|
||||
.. option:: -R date/offset
|
||||
|
||||
``-R date/offset``
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -221,7 +250,7 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Generated Key Files
|
||||
~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
When ``dnssec-keyfromlabel`` completes successfully, it prints a string
|
||||
When :program:`dnssec-keyfromlabel` completes successfully, it prints a string
|
||||
of the form ``Knnnn.+aaa+iiiii`` to the standard output. This is an
|
||||
identification string for the key files it has generated.
|
||||
|
||||
@@ -231,7 +260,7 @@ identification string for the key files it has generated.
|
||||
|
||||
- ``iiiii`` is the key identifier (or footprint).
|
||||
|
||||
``dnssec-keyfromlabel`` creates two files, with names based on the
|
||||
:program:`dnssec-keyfromlabel` creates two files, with names based on the
|
||||
printed string. ``Knnnn.+aaa+iiiii.key`` contains the public key, and
|
||||
``Knnnn.+aaa+iiiii.private`` contains the private key.
|
||||
|
||||
@@ -244,5 +273,5 @@ security reasons, this file does not have general read permission.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`4034`, :rfc:`7512`.
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-keygen
|
||||
.. program:: dnssec-keygen
|
||||
.. _man_dnssec-keygen:
|
||||
|
||||
dnssec-keygen: DNSSEC key generation tool
|
||||
@@ -24,7 +26,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-keygen`` generates keys for DNSSEC (Secure DNS), as defined in
|
||||
:program:`dnssec-keygen` generates keys for DNSSEC (Secure DNS), as defined in
|
||||
:rfc:`2535` and :rfc:`4034`. It can also generate keys for use with TSIG
|
||||
(Transaction Signatures) as defined in :rfc:`2845`, or TKEY (Transaction
|
||||
Key) as defined in :rfc:`2930`.
|
||||
@@ -36,32 +38,35 @@ generated.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-3``
|
||||
.. option:: -3
|
||||
|
||||
This option uses an NSEC3-capable algorithm to generate a DNSSEC key. If this
|
||||
option is used with an algorithm that has both NSEC and NSEC3
|
||||
versions, then the NSEC3 version is selected; for example,
|
||||
``dnssec-keygen -3a RSASHA1`` specifies the NSEC3RSASHA1 algorithm.
|
||||
|
||||
``-a algorithm``
|
||||
.. option:: -a algorithm
|
||||
|
||||
This option selects the cryptographic algorithm. For DNSSEC keys, the value of
|
||||
``algorithm`` must be one of RSASHA1, NSEC3RSASHA1, RSASHA256,
|
||||
RSASHA512, ECDSAP256SHA256, ECDSAP384SHA384, ED25519, or ED448. For
|
||||
TKEY, the value must be DH (Diffie-Hellman); specifying this value
|
||||
automatically sets the ``-T KEY`` option as well.
|
||||
automatically sets the :option:`-T KEY <-T>` option as well.
|
||||
|
||||
These values are case-insensitive. In some cases, abbreviations are
|
||||
supported, such as ECDSA256 for ECDSAP256SHA256 and ECDSA384 for
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the ``-3``
|
||||
ECDSAP384SHA384. If RSASHA1 is specified along with the :option:`-3`
|
||||
option, NSEC3RSASHA1 is used instead.
|
||||
|
||||
This parameter *must* be specified except when using the ``-S``
|
||||
This parameter *must* be specified except when using the :option:`-S`
|
||||
option, which copies the algorithm from the predecessor key.
|
||||
|
||||
In prior releases, HMAC algorithms could be generated for use as TSIG
|
||||
keys, but that feature was removed in BIND 9.13.0. Use
|
||||
``tsig-keygen`` to generate TSIG keys.
|
||||
:iscman:`tsig-keygen` to generate TSIG keys.
|
||||
|
||||
.. option:: -b keysize
|
||||
|
||||
``-b keysize``
|
||||
This option specifies the number of bits in the key. The choice of key size
|
||||
depends on the algorithm used: RSA keys must be between 1024 and 4096
|
||||
bits; Diffie-Hellman keys must be between 128 and 4096 bits. Elliptic
|
||||
@@ -70,63 +75,74 @@ Options
|
||||
If the key size is not specified, some algorithms have pre-defined
|
||||
defaults. For example, RSA keys for use as DNSSEC zone-signing keys
|
||||
have a default size of 1024 bits; RSA keys for use as key-signing
|
||||
keys (KSKs, generated with ``-f KSK``) default to 2048 bits.
|
||||
keys (KSKs, generated with :option:`-f KSK <-f>`) default to 2048 bits.
|
||||
|
||||
.. option:: -C
|
||||
|
||||
``-C``
|
||||
This option enables compatibility mode, which generates an old-style key, without any timing
|
||||
metadata. By default, ``dnssec-keygen`` includes the key's
|
||||
metadata. By default, :program:`dnssec-keygen` includes the key's
|
||||
creation date in the metadata stored with the private key; other
|
||||
dates may be set there as well, including publication date, activation date,
|
||||
etc. Keys that include this data may be incompatible with older
|
||||
versions of BIND; the ``-C`` option suppresses them.
|
||||
versions of BIND; the :option:`-C` option suppresses them.
|
||||
|
||||
.. option:: -c class
|
||||
|
||||
``-c class``
|
||||
This option indicates that the DNS record containing the key should have the
|
||||
specified class. If not specified, class IN is used.
|
||||
|
||||
``-d bits``
|
||||
.. option:: -d bits
|
||||
|
||||
This option specifies the key size in bits. For the algorithms RSASHA1, NSEC3RSASA1, RSASHA256, and
|
||||
RSASHA512 the key size must be between 1024 and 4096 bits; DH size is between 128
|
||||
and 4096 bits. This option is ignored for algorithms ECDSAP256SHA256,
|
||||
ECDSAP384SHA384, ED25519, and ED448.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f flag``
|
||||
.. option:: -f flag
|
||||
|
||||
This option sets the specified flag in the flag field of the KEY/DNSKEY record.
|
||||
The only recognized flags are KSK (Key-Signing Key) and REVOKE.
|
||||
|
||||
``-G``
|
||||
.. option:: -G
|
||||
|
||||
This option generates a key, but does not publish it or sign with it. This option is
|
||||
incompatible with ``-P`` and ``-A``.
|
||||
incompatible with :option:`-P` and :option:`-A`.
|
||||
|
||||
.. option:: -g generator
|
||||
|
||||
``-g generator``
|
||||
This option indicates the generator to use if generating a Diffie-Hellman key. Allowed
|
||||
values are 2 and 5. If no generator is specified, a known prime from
|
||||
:rfc:`2539` is used if possible; otherwise the default is 2.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-keygen``.
|
||||
:program:`dnssec-keygen`.
|
||||
|
||||
.. option:: -K directory
|
||||
|
||||
``-K directory``
|
||||
This option sets the directory in which the key files are to be written.
|
||||
|
||||
``-k policy``
|
||||
.. option:: -k policy
|
||||
|
||||
This option creates keys for a specific ``dnssec-policy``. If a policy uses multiple keys,
|
||||
``dnssec-keygen`` generates multiple keys. This also
|
||||
:program:`dnssec-keygen` generates multiple keys. This also
|
||||
creates a ".state" file to keep track of the key state.
|
||||
|
||||
This option creates keys according to the ``dnssec-policy`` configuration, hence
|
||||
it cannot be used at the same time as many of the other options that
|
||||
``dnssec-keygen`` provides.
|
||||
:program:`dnssec-keygen` provides.
|
||||
|
||||
.. option:: -L ttl
|
||||
|
||||
``-L ttl``
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
@@ -135,26 +151,30 @@ Options
|
||||
defaults to the SOA TTL. Setting the default TTL to ``0`` or ``none``
|
||||
is the same as leaving it unset.
|
||||
|
||||
``-l file``
|
||||
.. option:: -l file
|
||||
|
||||
This option provides a configuration file that contains a ``dnssec-policy`` statement
|
||||
(matching the policy set with ``-k``).
|
||||
(matching the policy set with :option:`-k`).
|
||||
|
||||
.. option:: -n nametype
|
||||
|
||||
``-n nametype``
|
||||
This option specifies the owner type of the key. The value of ``nametype`` must
|
||||
either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY
|
||||
(for a key associated with a host (KEY)), USER (for a key associated
|
||||
with a user (KEY)), or OTHER (DNSKEY). These values are
|
||||
case-insensitive. The default is ZONE for DNSKEY generation.
|
||||
|
||||
``-p protocol``
|
||||
.. option:: -p protocol
|
||||
|
||||
This option sets the protocol value for the generated key, for use with
|
||||
``-T KEY``. The protocol is a number between 0 and 255. The default
|
||||
:option:`-T KEY <-T>`. The protocol is a number between 0 and 255. The default
|
||||
is 3 (DNSSEC). Other possible values for this argument are listed in
|
||||
:rfc:`2535` and its successors.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which suppresses unnecessary output, including progress
|
||||
indication. Without this option, when ``dnssec-keygen`` is run
|
||||
indication. Without this option, when :program:`dnssec-keygen` is run
|
||||
interactively to generate an RSA or DSA key pair, it prints a
|
||||
string of symbols to ``stderr`` indicating the progress of the key
|
||||
generation. A ``.`` indicates that a random number has been found which
|
||||
@@ -162,7 +182,8 @@ Options
|
||||
round of the Miller-Rabin primality test; and a space ( ) means that the
|
||||
number has passed all the tests and is a satisfactory key.
|
||||
|
||||
``-S key``
|
||||
.. option:: -S key
|
||||
|
||||
This option creates a new key which is an explicit successor to an existing key.
|
||||
The name, algorithm, size, and type of the key are set to match
|
||||
the existing key. The activation date of the new key is set to
|
||||
@@ -170,26 +191,31 @@ Options
|
||||
set to the activation date minus the prepublication interval,
|
||||
which defaults to 30 days.
|
||||
|
||||
``-s strength``
|
||||
.. option:: -s strength
|
||||
|
||||
This option specifies the strength value of the key. The strength is a number
|
||||
between 0 and 15, and currently has no defined purpose in DNSSEC.
|
||||
|
||||
``-T rrtype``
|
||||
.. option:: -T rrtype
|
||||
|
||||
This option specifies the resource record type to use for the key. ``rrtype``
|
||||
must be either DNSKEY or KEY. The default is DNSKEY when using a
|
||||
DNSSEC algorithm, but it can be overridden to KEY for use with
|
||||
SIG(0).
|
||||
|
||||
``-t type``
|
||||
This option indicates the type of the key for use with ``-T KEY``. ``type``
|
||||
.. option:: -t type
|
||||
|
||||
This option indicates the type of the key for use with :option:`-T KEY <-T>`. ``type``
|
||||
must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
|
||||
is AUTHCONF. AUTH refers to the ability to authenticate data, and
|
||||
CONF to the ability to encrypt data.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
Timing Options
|
||||
@@ -204,43 +230,51 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it. If not set, and if the ``-G`` option has not been used, the
|
||||
to sign it. If not set, and if the :option:`-G` option has not been used, the
|
||||
default is the current date.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it. If not set,
|
||||
and if the ``-G`` option has not been used, the default is the current date. If set,
|
||||
and ``-P`` is not set, the publication date is set to the
|
||||
and if the :option:`-G` option has not been used, the default is the current date. If set,
|
||||
and :option:`-P` is not set, the publication date is set to the
|
||||
activation date minus the prepublication interval.
|
||||
|
||||
``-R date/offset``
|
||||
.. option:: -R date/offset
|
||||
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -261,7 +295,7 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
Generated Keys
|
||||
~~~~~~~~~~~~~~
|
||||
|
||||
When ``dnssec-keygen`` completes successfully, it prints a string of the
|
||||
When :program:`dnssec-keygen` completes successfully, it prints a string of the
|
||||
form ``Knnnn.+aaa+iiiii`` to the standard output. This is an
|
||||
identification string for the key it has generated.
|
||||
|
||||
@@ -271,12 +305,12 @@ identification string for the key it has generated.
|
||||
|
||||
- ``iiiii`` is the key identifier (or footprint).
|
||||
|
||||
``dnssec-keygen`` creates two files, with names based on the printed
|
||||
:program:`dnssec-keygen` creates two files, with names based on the printed
|
||||
string. ``Knnnn.+aaa+iiiii.key`` contains the public key, and
|
||||
``Knnnn.+aaa+iiiii.private`` contains the private key.
|
||||
|
||||
The ``.key`` file contains a DNSKEY or KEY record. When a zone is being
|
||||
signed by ``named`` or ``dnssec-signzone -S``, DNSKEY records are
|
||||
signed by :iscman:`named` or :option:`dnssec-signzone -S`, DNSKEY records are
|
||||
included automatically. In other cases, the ``.key`` file can be
|
||||
inserted into a zone file manually or with an ``$INCLUDE`` statement.
|
||||
|
||||
@@ -295,7 +329,7 @@ The command prints a string of the form:
|
||||
|
||||
``Kexample.com.+013+26160``
|
||||
|
||||
In this example, ``dnssec-keygen`` creates the files
|
||||
In this example, :program:`dnssec-keygen` creates the files
|
||||
``Kexample.com.+013+26160.key`` and ``Kexample.com.+013+26160.private``.
|
||||
|
||||
To generate a matching key-signing key, issue the command:
|
||||
@@ -305,5 +339,5 @@ To generate a matching key-signing key, issue the command:
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual, :rfc:`2539`,
|
||||
:iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual, :rfc:`2539`,
|
||||
:rfc:`2845`, :rfc:`4034`.
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-revoke
|
||||
.. program:: dnssec-revoke
|
||||
.. _man_dnssec-revoke:
|
||||
|
||||
dnssec-revoke - set the REVOKED bit on a DNSSEC key
|
||||
@@ -24,45 +26,53 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-revoke`` reads a DNSSEC key file, sets the REVOKED bit on the
|
||||
:program:`dnssec-revoke` reads a DNSSEC key file, sets the REVOKED bit on the
|
||||
key as defined in :rfc:`5011`, and creates a new pair of key files
|
||||
containing the now-revoked key.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-r``
|
||||
.. option:: -r
|
||||
|
||||
This option indicates to remove the original keyset files after writing the new keyset files.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f``
|
||||
This option indicates a forced overwrite and causes ``dnssec-revoke`` to write the new key pair,
|
||||
.. option:: -f
|
||||
|
||||
This option indicates a forced overwrite and causes :program:`dnssec-revoke` to write the new key pair,
|
||||
even if a file already exists matching the algorithm and key ID of
|
||||
the revoked key.
|
||||
|
||||
``-R``
|
||||
.. option:: -R
|
||||
|
||||
This option prints the key tag of the key with the REVOKE bit set, but does not
|
||||
revoke the key.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, BIND 9 Administrator Reference Manual, :rfc:`5011`.
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, BIND 9 Administrator Reference Manual, :rfc:`5011`.
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-settime
|
||||
.. program:: dnssec-settime
|
||||
.. _man_dnssec-settime:
|
||||
|
||||
dnssec-settime: set the key timing metadata for a DNSSEC key
|
||||
@@ -24,14 +26,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-settime`` reads a DNSSEC private key file and sets the key
|
||||
timing metadata as specified by the ``-P``, ``-A``, ``-R``, ``-I``, and
|
||||
``-D`` options. The metadata can then be used by ``dnssec-signzone`` or
|
||||
other signing software to determine when a key is to be published,
|
||||
whether it should be used for signing a zone, etc.
|
||||
:program:`dnssec-settime` reads a DNSSEC private key file and sets the key
|
||||
timing metadata as specified by the :option:`-P`, :option:`-A`, :option:`-R`,
|
||||
:option:`-I`, and :option:`-D` options. The metadata can then be used by
|
||||
:iscman:`dnssec-signzone` or other signing software to determine when a key is
|
||||
to be published, whether it should be used for signing a zone, etc.
|
||||
|
||||
If none of these options is set on the command line,
|
||||
``dnssec-settime`` simply prints the key timing metadata already stored
|
||||
:program:`dnssec-settime` simply prints the key timing metadata already stored
|
||||
in the key.
|
||||
|
||||
When key metadata fields are changed, both files of a key pair
|
||||
@@ -44,12 +46,12 @@ the key file. The private file's permissions are always set to be
|
||||
inaccessible to anyone other than the owner (mode 0600).
|
||||
|
||||
When working with state files, it is possible to update the timing metadata in
|
||||
those files as well with ``-s``. With this option, it is also possible to update key
|
||||
states with ``-d`` (DS), ``-k`` (DNSKEY), ``-r`` (RRSIG of KSK), or ``-z``
|
||||
(RRSIG of ZSK). Allowed states are HIDDEN, RUMOURED, OMNIPRESENT, and
|
||||
UNRETENTIVE.
|
||||
those files as well with :option:`-s`. With this option, it is also possible
|
||||
to update key states with :option:`-d` (DS), :option:`-k` (DNSKEY), :option:`-r`
|
||||
(RRSIG of KSK), or :option:`-z` (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||
|
||||
The goal state of the key can also be set with ``-g``. This should be either
|
||||
The goal state of the key can also be set with :option:`-g`. This should be either
|
||||
HIDDEN or OMNIPRESENT, representing whether the key should be removed from the
|
||||
zone or published.
|
||||
|
||||
@@ -59,19 +61,22 @@ purposes.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-f``
|
||||
.. option:: -f
|
||||
|
||||
This option forces an update of an old-format key with no metadata fields. Without
|
||||
this option, ``dnssec-settime`` fails when attempting to update a
|
||||
this option, :program:`dnssec-settime` fails when attempting to update a
|
||||
legacy key. With this option, the key is recreated in the new
|
||||
format, but with the original key data retained. The key's creation
|
||||
date is set to the present time. If no other values are
|
||||
specified, then the key's publication and activation dates are also
|
||||
set to the present time.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option sets the directory in which the key files are to reside.
|
||||
|
||||
``-L ttl``
|
||||
.. option:: -L ttl
|
||||
|
||||
This option sets the default TTL to use for this key when it is converted into a
|
||||
DNSKEY RR. This is the TTL used when the key is imported into a zone,
|
||||
unless there was already a DNSKEY RRset in
|
||||
@@ -80,16 +85,20 @@ Options
|
||||
defaults to the SOA TTL. Setting the default TTL to ``0`` or ``none``
|
||||
removes it from the key.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option emits a usage message and exits.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
@@ -108,47 +117,57 @@ months (defined as 30 24-hour days), weeks, days, hours, or minutes,
|
||||
respectively. Without a suffix, the offset is computed in seconds. To
|
||||
explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
|
||||
``-P date/offset``
|
||||
.. option:: -P date/offset
|
||||
|
||||
This option sets the date on which a key is to be published to the zone. After
|
||||
that date, the key is included in the zone but is not used
|
||||
to sign it.
|
||||
|
||||
``-P ds date/offset``
|
||||
.. option:: -P ds date/offset
|
||||
|
||||
This option sets the date on which DS records that match this key have been
|
||||
seen in the parent zone.
|
||||
|
||||
``-P sync date/offset``
|
||||
.. option:: -P sync date/offset
|
||||
|
||||
This option sets the date on which CDS and CDNSKEY records that match this key
|
||||
are to be published to the zone.
|
||||
|
||||
``-A date/offset``
|
||||
.. option:: -A date/offset
|
||||
|
||||
This option sets the date on which the key is to be activated. After that date,
|
||||
the key is included in the zone and used to sign it.
|
||||
|
||||
``-R date/offset``
|
||||
.. option:: -R date/offset
|
||||
|
||||
This option sets the date on which the key is to be revoked. After that date, the
|
||||
key is flagged as revoked. It is included in the zone and
|
||||
is used to sign it.
|
||||
|
||||
``-I date/offset``
|
||||
.. option:: -I date/offset
|
||||
|
||||
This option sets the date on which the key is to be retired. After that date, the
|
||||
key is still included in the zone, but it is not used to
|
||||
sign it.
|
||||
|
||||
``-D date/offset``
|
||||
.. option:: -D date/offset
|
||||
|
||||
This option sets the date on which the key is to be deleted. After that date, the
|
||||
key is no longer included in the zone. (However, it may remain in the key
|
||||
repository.)
|
||||
|
||||
``-D ds date/offset``
|
||||
.. option:: -D ds date/offset
|
||||
|
||||
This option sets the date on which the DS records that match this key have
|
||||
been seen removed from the parent zone.
|
||||
|
||||
``-D sync date/offset``
|
||||
.. option:: -D sync date/offset
|
||||
|
||||
This option sets the date on which the CDS and CDNSKEY records that match this
|
||||
key are to be deleted.
|
||||
|
||||
``-S predecessor key``
|
||||
.. option:: -S predecessor key
|
||||
|
||||
This option selects a key for which the key being modified is an explicit
|
||||
successor. The name, algorithm, size, and type of the predecessor key
|
||||
must exactly match those of the key being modified. The activation
|
||||
@@ -156,7 +175,8 @@ explicitly prevent a date from being set, use ``none`` or ``never``.
|
||||
predecessor. The publication date is set to the activation date
|
||||
minus the prepublication interval, which defaults to 30 days.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option sets the prepublication interval for a key. If set, then the
|
||||
publication and activation dates must be separated by at least this
|
||||
much time. If the activation date is specified but the publication
|
||||
@@ -183,36 +203,44 @@ purpose, but should never be used in production.
|
||||
|
||||
Known key states are HIDDEN, RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||
|
||||
``-s``
|
||||
.. option:: -s
|
||||
|
||||
This option indicates that when setting key timing data, the state file should also be updated.
|
||||
|
||||
``-g state``
|
||||
.. option:: -g state
|
||||
|
||||
This option sets the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||
|
||||
``-d state date/offset``
|
||||
.. option:: -d state date/offset
|
||||
|
||||
This option sets the DS state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-k state date/offset``
|
||||
.. option:: -k state date/offset
|
||||
|
||||
This option sets the DNSKEY state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-r state date/offset``
|
||||
.. option:: -r state date/offset
|
||||
|
||||
This option sets the RRSIG (KSK) state for this key as of the specified date, offset from the current date.
|
||||
|
||||
``-z state date/offset``
|
||||
.. option:: -z state date/offset
|
||||
|
||||
This option sets the RRSIG (ZSK) state for this key as of the specified date, offset from the current date.
|
||||
|
||||
Printing Options
|
||||
~~~~~~~~~~~~~~~~
|
||||
|
||||
``dnssec-settime`` can also be used to print the timing metadata
|
||||
:program:`dnssec-settime` can also be used to print the timing metadata
|
||||
associated with a key.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option indicates that times should be printed in Unix epoch format.
|
||||
|
||||
``-p C/P/Pds/Psync/A/R/I/D/Dds/Dsync/all``
|
||||
.. option:: -p C/P/Pds/Psync/A/R/I/D/Dds/Dsync/all
|
||||
|
||||
This option prints a specific metadata value or set of metadata values.
|
||||
The ``-p`` option may be followed by one or more of the following letters or
|
||||
The :option:`-p` option may be followed by one or more of the following letters or
|
||||
strings to indicate which value or values to print: ``C`` for the
|
||||
creation date, ``P`` for the publication date, ``Pds` for the DS publication
|
||||
date, ``Psync`` for the CDS and CDNSKEY publication date, ``A`` for the
|
||||
@@ -224,5 +252,5 @@ associated with a key.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, :manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual,
|
||||
:rfc:`5011`.
|
||||
|
||||
@@ -417,17 +417,15 @@ keythatsigned(dns_rdata_rrsig_t *rrsig) {
|
||||
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE, directory, mctx, &privkey);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
dst_key_free(&pubkey);
|
||||
result = dns_dnsseckey_create(mctx, &privkey, &key);
|
||||
dns_dnsseckey_create(mctx, &privkey, &key);
|
||||
} else {
|
||||
result = dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||
dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||
}
|
||||
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
key->force_publish = false;
|
||||
key->force_sign = false;
|
||||
key->index = keycount++;
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
}
|
||||
key->force_publish = false;
|
||||
key->force_sign = false;
|
||||
key->index = keycount++;
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
|
||||
isc_rwlock_unlock(&keylist_lock, isc_rwlocktype_write);
|
||||
return (key);
|
||||
@@ -3191,7 +3189,7 @@ print_version(FILE *fp) {
|
||||
return;
|
||||
}
|
||||
|
||||
fprintf(fp, "; dnssec_signzone version %s\n", PACKAGE_VERSION);
|
||||
fprintf(fp, "; %s version %s\n", program, PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
ISC_NORETURN static void
|
||||
@@ -3359,9 +3357,9 @@ main(int argc, char *argv[]) {
|
||||
atomic_init(&finished, false);
|
||||
|
||||
/* Unused letters: Bb G J q Yy (and F is reserved). */
|
||||
#define CMDLINE_FLAGS \
|
||||
"3:AaCc:Dd:E:e:f:FghH:i:I:j:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:VX:" \
|
||||
"xzZ:"
|
||||
#define CMDLINE_FLAGS \
|
||||
"3:AaCc:Dd:E:e:f:FghH:i:I:j:J:K:k:L:l:m:M:n:N:o:O:PpQqRr:s:ST:tuUv:" \
|
||||
"VX:xzZ:"
|
||||
|
||||
/*
|
||||
* Process memory debugging argument first.
|
||||
@@ -3509,6 +3507,10 @@ main(int argc, char *argv[]) {
|
||||
}
|
||||
break;
|
||||
|
||||
case 'J':
|
||||
journal = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'K':
|
||||
directory = isc_commandline_argument;
|
||||
break;
|
||||
@@ -3812,6 +3814,9 @@ main(int argc, char *argv[]) {
|
||||
gdb = NULL;
|
||||
TIME_NOW(&timer_start);
|
||||
loadzone(file, origin, rdclass, &gdb);
|
||||
if (journal != NULL) {
|
||||
loadjournal(mctx, gdb, journal);
|
||||
}
|
||||
gorigin = dns_db_origin(gdb);
|
||||
gclass = dns_db_class(gdb);
|
||||
get_soa_ttls();
|
||||
@@ -3996,7 +4001,7 @@ main(int argc, char *argv[]) {
|
||||
isc_managers_create(mctx, ntasks, 0, &netmgr, &taskmgr, NULL);
|
||||
|
||||
main_task = NULL;
|
||||
result = isc_task_create(taskmgr, 0, &main_task);
|
||||
result = isc_task_create(taskmgr, 0, &main_task, 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("failed to create task: %s", isc_result_totext(result));
|
||||
}
|
||||
@@ -4004,7 +4009,7 @@ main(int argc, char *argv[]) {
|
||||
tasks = isc_mem_get(mctx, ntasks * sizeof(isc_task_t *));
|
||||
for (i = 0; i < (int)ntasks; i++) {
|
||||
tasks[i] = NULL;
|
||||
result = isc_task_create(taskmgr, 0, &tasks[i]);
|
||||
result = isc_task_create(taskmgr, 0, &tasks[i], 0);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fatal("failed to create task: %s",
|
||||
isc_result_totext(result));
|
||||
|
||||
+112
-68
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-signzone
|
||||
.. program:: dnssec-signzone
|
||||
.. _man_dnssec-signzone:
|
||||
|
||||
dnssec-signzone - DNSSEC zone signing tool
|
||||
@@ -24,7 +26,7 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-signzone`` signs a zone; it generates NSEC and RRSIG records
|
||||
:program:`dnssec-signzone` signs a zone; it generates NSEC and RRSIG records
|
||||
and produces a signed version of the zone. The security status of
|
||||
delegations from the signed zone (that is, whether the child zones are
|
||||
secure) is determined by the presence or absence of a ``keyset``
|
||||
@@ -33,29 +35,35 @@ file for each child zone.
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-a``
|
||||
.. option:: -a
|
||||
|
||||
This option verifies all generated signatures.
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zone.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
This option sets compatibility mode, in which a ``keyset-zonename`` file is generated in addition
|
||||
to ``dsset-zonename`` when signing a zone, for use by older versions
|
||||
of ``dnssec-signzone``.
|
||||
of :program:`dnssec-signzone`.
|
||||
|
||||
.. option:: -d directory
|
||||
|
||||
``-d directory``
|
||||
This option indicates the directory where BIND 9 should look for ``dsset-`` or ``keyset-`` files.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option indicates that only those record types automatically managed by
|
||||
``dnssec-signzone``, i.e., RRSIG, NSEC, NSEC3 and NSEC3PARAM records, should be included in the output.
|
||||
If smart signing (``-S``) is used, DNSKEY records are also included.
|
||||
:program:`dnssec-signzone`, i.e., RRSIG, NSEC, NSEC3 and NSEC3PARAM records, should be included in the output.
|
||||
If smart signing (:option:`-S`) is used, DNSKEY records are also included.
|
||||
The resulting file can be included in the original zone file with
|
||||
``$INCLUDE``. This option cannot be combined with ``-O raw``
|
||||
``$INCLUDE``. This option cannot be combined with :option:`-O raw <-O>`
|
||||
or serial-number updating.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the hardware to use for cryptographic
|
||||
operations, such as a secure key store used for signing, when applicable.
|
||||
|
||||
@@ -63,19 +71,23 @@ Options
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-g``
|
||||
.. option:: -g
|
||||
|
||||
This option indicates that DS records for child zones should be generated from a ``dsset-`` or ``keyset-``
|
||||
file. Existing DS records are removed.
|
||||
|
||||
``-K directory``
|
||||
.. option:: -K directory
|
||||
|
||||
This option specifies the directory to search for DNSSEC keys. If not
|
||||
specified, it defaults to the current directory.
|
||||
|
||||
``-k key``
|
||||
.. option:: -k key
|
||||
|
||||
This option tells BIND 9 to treat the specified key as a key-signing key, ignoring any key flags. This
|
||||
option may be specified multiple times.
|
||||
|
||||
``-M maxttl``
|
||||
.. option:: -M maxttl
|
||||
|
||||
This option sets the maximum TTL for the signed zone. Any TTL higher than ``maxttl``
|
||||
in the input zone is reduced to ``maxttl`` in the output. This
|
||||
provides certainty as to the largest possible TTL in the signed zone,
|
||||
@@ -83,10 +95,11 @@ Options
|
||||
possible time before signatures that have been retrieved by resolvers
|
||||
expire from resolver caches. Zones that are signed with this
|
||||
option should be configured to use a matching ``max-zone-ttl`` in
|
||||
``named.conf``. (Note: This option is incompatible with ``-D``,
|
||||
:iscman:`named.conf`. (Note: This option is incompatible with :option:`-D`,
|
||||
because it modifies non-DNSSEC data in the output zone.)
|
||||
|
||||
``-s start-time``
|
||||
.. option:: -s start-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records become
|
||||
valid. This can be either an absolute or relative time. An absolute
|
||||
start time is indicated by a number in YYYYMMDDHHMMSS notation;
|
||||
@@ -95,7 +108,8 @@ Options
|
||||
time. If no ``start-time`` is specified, the current time minus 1
|
||||
hour (to allow for clock skew) is used.
|
||||
|
||||
``-e end-time``
|
||||
.. option:: -e end-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records expire. As
|
||||
with ``start-time``, an absolute time is indicated in YYYYMMDDHHMMSS
|
||||
notation. A time relative to the start time is indicated with ``+N``,
|
||||
@@ -104,7 +118,8 @@ Options
|
||||
specified, 30 days from the start time is the default.
|
||||
``end-time`` must be later than ``start-time``.
|
||||
|
||||
``-X extended end-time``
|
||||
.. option:: -X extended end-time
|
||||
|
||||
This option specifies the date and time when the generated RRSIG records for the
|
||||
DNSKEY RRset expire. This is to be used in cases when the DNSKEY
|
||||
signatures need to persist longer than signatures on other records;
|
||||
@@ -119,20 +134,24 @@ Options
|
||||
as the default. (``end-time``, in turn, defaults to 30 days from the
|
||||
start time.) ``extended end-time`` must be later than ``start-time``.
|
||||
|
||||
``-f output-file``
|
||||
.. option:: -f output-file
|
||||
|
||||
This option indicates the name of the output file containing the signed zone. The default
|
||||
is to append ``.signed`` to the input filename. If ``output-file`` is
|
||||
set to ``-``, then the signed zone is written to the standard
|
||||
output, with a default output format of ``full``.
|
||||
|
||||
``-h``
|
||||
.. option:: -h
|
||||
|
||||
This option prints a short summary of the options and arguments to
|
||||
``dnssec-signzone``.
|
||||
:program:`dnssec-signzone`.
|
||||
|
||||
.. option:: -V
|
||||
|
||||
``-V``
|
||||
This option prints version information.
|
||||
|
||||
``-i interval``
|
||||
.. option:: -i interval
|
||||
|
||||
This option indicates that, when a previously signed zone is passed as input, records may be
|
||||
re-signed. The ``interval`` option specifies the cycle interval as an
|
||||
offset from the current time, in seconds. If a RRSIG record expires
|
||||
@@ -141,19 +160,21 @@ Options
|
||||
|
||||
The default cycle interval is one quarter of the difference between
|
||||
the signature end and start times. So if neither ``end-time`` nor
|
||||
``start-time`` is specified, ``dnssec-signzone`` generates
|
||||
``start-time`` is specified, :program:`dnssec-signzone` generates
|
||||
signatures that are valid for 30 days, with a cycle interval of 7.5
|
||||
days. Therefore, if any existing RRSIG records are due to expire in
|
||||
less than 7.5 days, they are replaced.
|
||||
|
||||
``-I input-format``
|
||||
.. option:: -I input-format
|
||||
|
||||
This option sets the format of the input zone file. Possible formats are
|
||||
``text`` (the default), and ``raw``. This option is primarily
|
||||
intended to be used for dynamic signed zones, so that the dumped zone
|
||||
file in a non-text format containing updates can be signed directly.
|
||||
This option is not useful for non-dynamic zones.
|
||||
|
||||
``-j jitter``
|
||||
.. option:: -j jitter
|
||||
|
||||
When signing a zone with a fixed signature lifetime, all RRSIG
|
||||
records issued at the time of signing expire simultaneously. If the
|
||||
zone is incrementally signed, i.e., a previously signed zone is passed
|
||||
@@ -168,16 +189,19 @@ Options
|
||||
less congestion than if all validators need to refetch at around the
|
||||
same time.
|
||||
|
||||
``-L serial``
|
||||
.. option:: -L serial
|
||||
|
||||
When writing a signed zone to "raw" format, this option sets the "source
|
||||
serial" value in the header to the specified ``serial`` number. (This is
|
||||
expected to be used primarily for testing purposes.)
|
||||
|
||||
``-n ncpus``
|
||||
.. option:: -n ncpus
|
||||
|
||||
This option specifies the number of threads to use. By default, one thread is
|
||||
started for each detected CPU.
|
||||
|
||||
``-N soa-serial-format``
|
||||
.. option:: -N soa-serial-format
|
||||
|
||||
This option sets the SOA serial number format of the signed zone. Possible formats are
|
||||
``keep`` (the default), ``increment``, ``unixtime``, and
|
||||
``date``.
|
||||
@@ -200,21 +224,24 @@ Options
|
||||
than or equal to that value, in which case it is simply
|
||||
incremented by one.
|
||||
|
||||
``-o origin``
|
||||
.. option:: -o origin
|
||||
|
||||
This option sets the zone origin. If not specified, the name of the zone file is
|
||||
assumed to be the origin.
|
||||
|
||||
``-O output-format``
|
||||
.. option:: -O output-format
|
||||
|
||||
This option sets the format of the output file containing the signed
|
||||
zone. Possible formats are ``text`` (the default), which is the standard
|
||||
textual representation of the zone; ``full``, which is text output in a
|
||||
format suitable for processing by external scripts; and ``raw`` and
|
||||
``raw=N``, which store the zone in binary formats for rapid loading by
|
||||
``named``. ``raw=N`` specifies the format version of the raw zone file:
|
||||
if N is 0, the raw file can be read by any version of ``named``; if N is
|
||||
:iscman:`named`. ``raw=N`` specifies the format version of the raw zone file:
|
||||
if N is 0, the raw file can be read by any version of :iscman:`named`; if N is
|
||||
1, the file can be read by release 9.9.0 or higher. The default is 1.
|
||||
|
||||
``-P``
|
||||
.. option:: -P
|
||||
|
||||
This option disables post-sign verification tests.
|
||||
|
||||
The post-sign verification tests ensure that for each algorithm in
|
||||
@@ -222,36 +249,40 @@ Options
|
||||
revoked KSK keys are self-signed, and that all records in the zone
|
||||
are signed by the algorithm. This option skips these tests.
|
||||
|
||||
``-Q``
|
||||
.. option:: -Q
|
||||
|
||||
This option removes signatures from keys that are no longer active.
|
||||
|
||||
Normally, when a previously signed zone is passed as input to the
|
||||
signer, and a DNSKEY record has been removed and replaced with a new
|
||||
one, signatures from the old key that are still within their validity
|
||||
period are retained. This allows the zone to continue to validate
|
||||
with cached copies of the old DNSKEY RRset. The ``-Q`` option forces
|
||||
``dnssec-signzone`` to remove signatures from keys that are no longer
|
||||
with cached copies of the old DNSKEY RRset. The :option:`-Q` option forces
|
||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||
active. This enables ZSK rollover using the procedure described in
|
||||
:rfc:`4641#4.2.1.1` ("Pre-Publish Key Rollover").
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option enables quiet mode, which suppresses unnecessary output. Without this option, when
|
||||
``dnssec-signzone`` is run it prints three pieces of information to standard output: the number of
|
||||
:program:`dnssec-signzone` is run it prints three pieces of information to standard output: the number of
|
||||
keys in use; the algorithms used to verify the zone was signed correctly and
|
||||
other status information; and the filename containing the signed
|
||||
zone. With the option that output is suppressed, leaving only the filename.
|
||||
|
||||
``-R``
|
||||
.. option:: -R
|
||||
|
||||
This option removes signatures from keys that are no longer published.
|
||||
|
||||
This option is similar to ``-Q``, except it forces
|
||||
``dnssec-signzone`` to remove signatures from keys that are no longer
|
||||
This option is similar to :option:`-Q`, except it forces
|
||||
:program:`dnssec-signzone` to remove signatures from keys that are no longer
|
||||
published. This enables ZSK rollover using the procedure described in
|
||||
:rfc:`4641#4.2.1.2` ("Double Signature Zone Signing Key
|
||||
Rollover").
|
||||
|
||||
``-S``
|
||||
This option enables smart signing, which instructs ``dnssec-signzone`` to search the key
|
||||
.. option:: -S
|
||||
|
||||
This option enables smart signing, which instructs :program:`dnssec-signzone` to search the key
|
||||
repository for keys that match the zone being signed, and to include
|
||||
them in the zone if appropriate.
|
||||
|
||||
@@ -283,11 +314,12 @@ Options
|
||||
If the key's sync deletion date is set and is in the past,
|
||||
synchronization records (type CDS and/or CDNSKEY) are removed.
|
||||
|
||||
``-T ttl``
|
||||
.. option:: -T ttl
|
||||
|
||||
This option specifies a TTL to be used for new DNSKEY records imported into the
|
||||
zone from the key repository. If not specified, the default is the
|
||||
TTL value from the zone's SOA record. This option is ignored when
|
||||
signing without ``-S``, since DNSKEY records are not imported from
|
||||
signing without :option:`-S`, since DNSKEY records are not imported from
|
||||
the key repository in that case. It is also ignored if there are any
|
||||
pre-existing DNSKEY records at the zone apex, in which case new
|
||||
records' TTL values are set to match them, or if any of the
|
||||
@@ -295,51 +327,63 @@ Options
|
||||
conflict between TTL values in imported keys, the shortest one is
|
||||
used.
|
||||
|
||||
``-t``
|
||||
.. option:: -t
|
||||
|
||||
This option prints statistics at completion.
|
||||
|
||||
``-u``
|
||||
.. option:: -u
|
||||
|
||||
This option updates the NSEC/NSEC3 chain when re-signing a previously signed zone.
|
||||
With this option, a zone signed with NSEC can be switched to NSEC3,
|
||||
or a zone signed with NSEC3 can be switched to NSEC or to NSEC3 with
|
||||
different parameters. Without this option, ``dnssec-signzone``
|
||||
different parameters. Without this option, :program:`dnssec-signzone`
|
||||
retains the existing chain when re-signing.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-x``
|
||||
.. option:: -x
|
||||
|
||||
This option indicates that BIND 9 should only sign the DNSKEY, CDNSKEY, and CDS RRsets with key-signing keys,
|
||||
and should omit signatures from zone-signing keys. (This is similar to the
|
||||
``dnssec-dnskey-kskonly yes;`` zone option in ``named``.)
|
||||
``dnssec-dnskey-kskonly yes;`` zone option in :iscman:`named`.)
|
||||
|
||||
.. option:: -z
|
||||
|
||||
``-z``
|
||||
This option indicates that BIND 9 should ignore the KSK flag on keys when determining what to sign. This causes
|
||||
KSK-flagged keys to sign all records, not just the DNSKEY RRset.
|
||||
(This is similar to the ``update-check-ksk no;`` zone option in
|
||||
``named``.)
|
||||
:iscman:`named`.)
|
||||
|
||||
.. option:: -3 salt
|
||||
|
||||
``-3 salt``
|
||||
This option generates an NSEC3 chain with the given hex-encoded salt. A dash
|
||||
(-) can be used to indicate that no salt is to be used when
|
||||
generating the NSEC3 chain.
|
||||
|
||||
``-H iterations``
|
||||
.. option:: -H iterations
|
||||
|
||||
This option indicates that, when generating an NSEC3 chain, BIND 9 should use this many iterations. The default
|
||||
is 10.
|
||||
|
||||
``-A``
|
||||
.. option:: -A
|
||||
|
||||
This option indicates that, when generating an NSEC3 chain, BIND 9 should set the OPTOUT flag on all NSEC3
|
||||
records and should not generate NSEC3 records for insecure delegations.
|
||||
|
||||
Using this option twice (i.e., ``-AA``) turns the OPTOUT flag off for
|
||||
all records. This is useful when using the ``-u`` option to modify an
|
||||
.. option:: -AA
|
||||
|
||||
This option turns the OPTOUT flag off for
|
||||
all records. This is useful when using the :option:`-u` option to modify an
|
||||
NSEC3 chain which previously had OPTOUT set.
|
||||
|
||||
``zonefile``
|
||||
.. option:: zonefile
|
||||
|
||||
This option sets the file containing the zone to be signed.
|
||||
|
||||
``key``
|
||||
.. option:: key
|
||||
|
||||
This option specifies which keys should be used to sign the zone. If no keys are
|
||||
specified, the zone is examined for DNSKEY records at the
|
||||
zone apex. If these records are found and there are matching private keys in
|
||||
@@ -349,11 +393,11 @@ Example
|
||||
~~~~~~~
|
||||
|
||||
The following command signs the ``example.com`` zone with the
|
||||
ECDSAP256SHA256 key generated by ``dnssec-keygen``
|
||||
(Kexample.com.+013+17247). Because the ``-S`` option is not being used,
|
||||
ECDSAP256SHA256 key generated by :iscman:`dnssec-keygen`
|
||||
(Kexample.com.+013+17247). Because the :option:`-S` option is not being used,
|
||||
the zone's keys must be in the master file (``db.example.com``). This
|
||||
invocation looks for ``dsset`` files in the current directory, so that
|
||||
DS records can be imported from them (``-g``).
|
||||
DS records can be imported from them (:option:`-g`).
|
||||
|
||||
::
|
||||
|
||||
@@ -362,9 +406,9 @@ DS records can be imported from them (``-g``).
|
||||
db.example.com.signed
|
||||
%
|
||||
|
||||
In the above example, ``dnssec-signzone`` creates the file
|
||||
In the above example, :program:`dnssec-signzone` creates the file
|
||||
``db.example.com.signed``. This file should be referenced in a zone
|
||||
statement in the ``named.conf`` file.
|
||||
statement in the :iscman:`named.conf` file.
|
||||
|
||||
This example re-signs a previously signed zone with default parameters.
|
||||
The private keys are assumed to be in the current directory.
|
||||
@@ -379,5 +423,5 @@ The private keys are assumed to be in the current directory.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-keygen(8)`, BIND 9 Administrator Reference Manual, :rfc:`4033`,
|
||||
:iscman:`dnssec-keygen(8) <dnssec-keygen>`, BIND 9 Administrator Reference Manual, :rfc:`4033`,
|
||||
:rfc:`4641`.
|
||||
|
||||
@@ -70,10 +70,10 @@ const char *program = "dnssec-verify";
|
||||
static isc_stdtime_t now;
|
||||
static isc_mem_t *mctx = NULL;
|
||||
static dns_masterformat_t inputformat = dns_masterformat_text;
|
||||
static dns_db_t *gdb; /* The database */
|
||||
static dns_dbversion_t *gversion; /* The database version */
|
||||
static dns_rdataclass_t gclass; /* The class */
|
||||
static dns_name_t *gorigin; /* The database origin */
|
||||
static dns_db_t *gdb = NULL; /* The database */
|
||||
static dns_dbversion_t *gversion = NULL; /* The database version */
|
||||
static dns_rdataclass_t gclass; /* The class */
|
||||
static dns_name_t *gorigin = NULL; /* The database origin */
|
||||
static bool ignore_kskflag = false;
|
||||
static bool keyset_kskonly = false;
|
||||
|
||||
@@ -180,7 +180,7 @@ main(int argc, char *argv[]) {
|
||||
char *endp;
|
||||
int ch;
|
||||
|
||||
#define CMDLINE_FLAGS "c:E:hm:o:I:qv:Vxz"
|
||||
#define CMDLINE_FLAGS "c:E:hJ:m:o:I:qv:Vxz"
|
||||
|
||||
/*
|
||||
* Process memory debugging argument first.
|
||||
@@ -226,6 +226,10 @@ main(int argc, char *argv[]) {
|
||||
inputformatstr = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'J':
|
||||
journal = isc_commandline_argument;
|
||||
break;
|
||||
|
||||
case 'm':
|
||||
break;
|
||||
|
||||
@@ -319,6 +323,9 @@ main(int argc, char *argv[]) {
|
||||
gdb = NULL;
|
||||
report("Loading zone '%s' from file '%s'\n", origin, file);
|
||||
loadzone(file, origin, rdclass, &gdb);
|
||||
if (journal != NULL) {
|
||||
loadjournal(mctx, gdb, journal);
|
||||
}
|
||||
gorigin = dns_db_origin(gdb);
|
||||
gclass = dns_db_class(gdb);
|
||||
|
||||
|
||||
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: dnssec-verify
|
||||
.. program:: dnssec-verify
|
||||
.. _man_dnssec-verify:
|
||||
|
||||
dnssec-verify - DNSSEC zone verification tool
|
||||
@@ -24,55 +26,64 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``dnssec-verify`` verifies that a zone is fully signed for each
|
||||
:program:`dnssec-verify` verifies that a zone is fully signed for each
|
||||
algorithm found in the DNSKEY RRset for the zone, and that the
|
||||
NSEC/NSEC3 chains are complete.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-c class``
|
||||
.. option:: -c class
|
||||
|
||||
This option specifies the DNS class of the zone.
|
||||
|
||||
``-E engine``
|
||||
.. option:: -E engine
|
||||
|
||||
This option specifies the cryptographic hardware to use, when applicable.
|
||||
|
||||
When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-I input-format``
|
||||
.. option:: -I input-format
|
||||
|
||||
This option sets the format of the input zone file. Possible formats are ``text``
|
||||
(the default) and ``raw``. This option is primarily intended to be used
|
||||
for dynamic signed zones, so that the dumped zone file in a non-text
|
||||
format containing updates can be verified independently.
|
||||
This option is not useful for non-dynamic zones.
|
||||
|
||||
``-o origin``
|
||||
.. option:: -o origin
|
||||
|
||||
This option indicates the zone origin. If not specified, the name of the zone file is
|
||||
assumed to be the origin.
|
||||
|
||||
``-v level``
|
||||
.. option:: -v level
|
||||
|
||||
This option sets the debugging level.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints version information.
|
||||
|
||||
``-q``
|
||||
This option sets quiet mode, which suppresses output. Without this option, when ``dnssec-verify``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, which suppresses output. Without this option, when :program:`dnssec-verify`
|
||||
is run it prints to standard output the number of keys in use, the
|
||||
algorithms used to verify the zone was signed correctly, and other status
|
||||
information. With this option, all non-error output is suppressed, and only the exit
|
||||
code indicates success.
|
||||
|
||||
``-x``
|
||||
.. option:: -x
|
||||
|
||||
This option verifies only that the DNSKEY RRset is signed with key-signing keys.
|
||||
Without this flag, it is assumed that the DNSKEY RRset is signed
|
||||
by all active keys. When this flag is set, it is not an error if
|
||||
the DNSKEY RRset is not signed by zone-signing keys. This corresponds
|
||||
to the ``-x`` option in ``dnssec-signzone``.
|
||||
to the :option:`-x option in dnssec-signzone <dnssec-signzone -x>`.
|
||||
|
||||
.. option:: -z
|
||||
|
||||
``-z``
|
||||
This option indicates that the KSK flag on the keys should be ignored when determining whether the zone is
|
||||
correctly signed. Without this flag, it is assumed that there is
|
||||
a non-revoked, self-signed DNSKEY with the KSK flag set for each
|
||||
@@ -84,12 +95,13 @@ Options
|
||||
the KSK flag state, and that other RRsets be signed by a
|
||||
non-revoked key for the same algorithm that includes the self-signed
|
||||
key; the same key may be used for both purposes. This corresponds to
|
||||
the ``-z`` option in ``dnssec-signzone``.
|
||||
the :option:`-z option in dnssec-signzone <dnssec-signzone -z>`.
|
||||
|
||||
.. option:: zonefile
|
||||
|
||||
``zonefile``
|
||||
This option indicates the file containing the zone to be signed.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`dnssec-signzone(8)`, BIND 9 Administrator Reference Manual, :rfc:`4033`.
|
||||
:iscman:`dnssec-signzone(8) <dnssec-signzone>`, BIND 9 Administrator Reference Manual, :rfc:`4033`.
|
||||
|
||||
+41
-1
@@ -39,6 +39,7 @@
|
||||
#include <dns/dbiterator.h>
|
||||
#include <dns/dnssec.h>
|
||||
#include <dns/fixedname.h>
|
||||
#include <dns/journal.h>
|
||||
#include <dns/keyvalues.h>
|
||||
#include <dns/log.h>
|
||||
#include <dns/name.h>
|
||||
@@ -64,6 +65,7 @@ static const char *keystates[KEYSTATES_NVALUES] = {
|
||||
|
||||
int verbose = 0;
|
||||
bool quiet = false;
|
||||
const char *journal = NULL;
|
||||
dns_dsdigest_t dtype[8];
|
||||
|
||||
static fatalcallback_t *fatalcallback = NULL;
|
||||
@@ -109,7 +111,7 @@ vbprintf(int level, const char *fmt, ...) {
|
||||
|
||||
void
|
||||
version(const char *name) {
|
||||
fprintf(stderr, "%s %s\n", name, PACKAGE_VERSION);
|
||||
printf("%s %s\n", name, PACKAGE_VERSION);
|
||||
exit(0);
|
||||
}
|
||||
|
||||
@@ -564,3 +566,41 @@ isoptarg(const char *arg, char **argv, void (*usage)(void)) {
|
||||
}
|
||||
return (false);
|
||||
}
|
||||
|
||||
void
|
||||
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *file) {
|
||||
dns_journal_t *jnl = NULL;
|
||||
isc_result_t result;
|
||||
|
||||
result = dns_journal_open(mctx, file, DNS_JOURNAL_READ, &jnl);
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
fprintf(stderr, "%s: journal file %s not found\n", program,
|
||||
file);
|
||||
goto cleanup;
|
||||
} else if (result != ISC_R_SUCCESS) {
|
||||
fatal("unable to open journal %s: %s\n", file,
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (dns_journal_empty(jnl)) {
|
||||
dns_journal_destroy(&jnl);
|
||||
return;
|
||||
}
|
||||
|
||||
result = dns_journal_rollforward(jnl, db, 0);
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
case DNS_R_UPTODATE:
|
||||
break;
|
||||
|
||||
case ISC_R_NOTFOUND:
|
||||
case ISC_R_RANGE:
|
||||
fatal("journal %s out of sync with zone", file);
|
||||
|
||||
default:
|
||||
fatal("journal %s: %s\n", file, isc_result_totext(result));
|
||||
}
|
||||
|
||||
cleanup:
|
||||
dns_journal_destroy(&jnl);
|
||||
}
|
||||
|
||||
@@ -32,6 +32,9 @@ extern bool quiet;
|
||||
/*! program name, statically initialized in each program */
|
||||
extern const char *program;
|
||||
|
||||
/*! journal file */
|
||||
extern const char *journal;
|
||||
|
||||
/*!
|
||||
* List of DS digest types used by dnssec-cds and dnssec-dsfromkey,
|
||||
* defined in dnssectool.c. Filled in by add_dtype() from -a
|
||||
@@ -102,3 +105,6 @@ key_collision(dst_key_t *key, dns_name_t *name, const char *dir,
|
||||
|
||||
bool
|
||||
isoptarg(const char *arg, char **argv, void (*usage)(void));
|
||||
|
||||
void
|
||||
loadjournal(isc_mem_t *mctx, dns_db_t *db, const char *journal);
|
||||
|
||||
@@ -68,7 +68,6 @@ options {\n\
|
||||
"\
|
||||
heartbeat-interval 60;\n\
|
||||
interface-interval 60;\n\
|
||||
# keep-response-order {none;};\n\
|
||||
listen-on {any;};\n\
|
||||
listen-on-v6 {any;};\n\
|
||||
# lock-file \"" NAMED_LOCALSTATEDIR "/run/named/named.lock\";\n\
|
||||
|
||||
@@ -278,9 +278,6 @@ named_control_docommand(isccc_sexpr_t *message, bool readonly,
|
||||
command_compare(command, NAMED_COMMAND_UNFREEZE))
|
||||
{
|
||||
result = named_server_freeze(named_g_server, false, lex, text);
|
||||
} else if (command_compare(command, NAMED_COMMAND_TIMERPOKE)) {
|
||||
isc_timermgr_poke(named_g_timermgr);
|
||||
result = ISC_R_SUCCESS;
|
||||
} else if (command_compare(command, NAMED_COMMAND_TRACE)) {
|
||||
result = named_server_setdebuglevel(named_g_server, lex);
|
||||
} else if (command_compare(command, NAMED_COMMAND_TSIGDELETE)) {
|
||||
|
||||
@@ -1160,9 +1160,13 @@ add_listener(named_controls_t *cp, controllistener_t **listenerp,
|
||||
}
|
||||
#endif
|
||||
|
||||
CHECK(isc_nm_listentcp(
|
||||
named_g_netmgr, &listener->address, control_newconn, listener,
|
||||
sizeof(controlconnection_t), 5, NULL, &listener->sock));
|
||||
/*
|
||||
* The controlconf channel should run on a single thread (0).
|
||||
*/
|
||||
CHECK(isc_nm_listentcp(named_g_netmgr, 1, &listener->address,
|
||||
control_newconn, listener,
|
||||
sizeof(controlconnection_t), 5, NULL,
|
||||
&listener->sock));
|
||||
#if 0
|
||||
/* XXX: no unix socket support yet */
|
||||
if (type == isc_socktype_unix) {
|
||||
|
||||
@@ -48,7 +48,6 @@
|
||||
#define NAMED_COMMAND_FREEZE "freeze"
|
||||
#define NAMED_COMMAND_UNFREEZE "unfreeze"
|
||||
#define NAMED_COMMAND_THAW "thaw"
|
||||
#define NAMED_COMMAND_TIMERPOKE "timerpoke"
|
||||
#define NAMED_COMMAND_RECURSING "recursing"
|
||||
#define NAMED_COMMAND_NULL "null"
|
||||
#define NAMED_COMMAND_NOTIFY "notify"
|
||||
|
||||
@@ -32,7 +32,6 @@
|
||||
#include <isc/dir.h>
|
||||
#include <isc/file.h>
|
||||
#include <isc/hash.h>
|
||||
#include <isc/hp.h>
|
||||
#include <isc/httpd.h>
|
||||
#include <isc/managers.h>
|
||||
#include <isc/netmgr.h>
|
||||
|
||||
+31
-260
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named.conf
|
||||
|
||||
named.conf - configuration file for **named**
|
||||
---------------------------------------------
|
||||
|
||||
@@ -22,10 +24,10 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named.conf`` is the configuration file for ``named``. Statements are
|
||||
enclosed in braces and terminated with a semi-colon. Clauses in the
|
||||
statements are also semi-colon terminated. The usual comment styles are
|
||||
supported:
|
||||
:file:`named.conf` is the configuration file for :iscman:`named`.
|
||||
Statements are enclosed in braces and terminated with a semi-colon.
|
||||
Clauses in the statements are also semi-colon terminated. The usual
|
||||
comment styles are supported:
|
||||
|
||||
C style: /\* \*/
|
||||
|
||||
@@ -152,17 +154,6 @@ See DNSSEC-KEYS.
|
||||
initial-ds ) integer integer
|
||||
integer quoted_string; ... };, deprecated
|
||||
|
||||
MASTERS
|
||||
^^^^^^^
|
||||
|
||||
::
|
||||
|
||||
masters string [ port integer ] [ dscp
|
||||
integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... };
|
||||
|
||||
OPTIONS
|
||||
^^^^^^^
|
||||
|
||||
@@ -198,15 +189,12 @@ OPTIONS
|
||||
avoid-v6-udp-ports { portrange; ... };
|
||||
bindkeys-file quoted_string;
|
||||
blackhole { address_match_element; ... };
|
||||
catalog-zones { zone string [ default-masters [ port integer ]
|
||||
[ dscp integer ] { ( remote-servers | ipv4_address [ port
|
||||
integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ default-primaries [ port
|
||||
integer ] [ dscp integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... } ] [
|
||||
zone-directory quoted_string ] [ in-memory boolean ] [
|
||||
min-update-interval duration ]; ... };
|
||||
catalog-zones { zone string [ default-primaries [ port integer
|
||||
] [ dscp integer ] { ( remote-servers | ipv4_address [
|
||||
port integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ zone-directory
|
||||
quoted_string ] [ in-memory boolean ] [ min-update-interval
|
||||
duration ]; ... };
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
@@ -301,7 +289,6 @@ OPTIONS
|
||||
ipv4only-server string;
|
||||
ixfr-from-differences ( primary | master | secondary | slave |
|
||||
boolean );
|
||||
keep-response-order { address_match_element; ... };
|
||||
key-directory quoted_string;
|
||||
lame-ttl duration;
|
||||
listen-on [ port integer ] [ dscp
|
||||
@@ -632,15 +619,12 @@ VIEW
|
||||
attach-cache string;
|
||||
auth-nxdomain boolean;
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
catalog-zones { zone string [ default-masters [ port integer ]
|
||||
[ dscp integer ] { ( remote-servers | ipv4_address [ port
|
||||
integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ default-primaries [ port
|
||||
integer ] [ dscp integer ] { ( remote-servers |
|
||||
ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... } ] [
|
||||
zone-directory quoted_string ] [ in-memory boolean ] [
|
||||
min-update-interval duration ]; ... };
|
||||
catalog-zones { zone string [ default-primaries [ port integer
|
||||
] [ dscp integer ] { ( remote-servers | ipv4_address [
|
||||
port integer ] | ipv6_address [ port integer ] ) [ key
|
||||
string ] [ tls string ]; ... } ] [ zone-directory
|
||||
quoted_string ] [ in-memory boolean ] [ min-update-interval
|
||||
duration ]; ... };
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
@@ -898,245 +882,32 @@ VIEW
|
||||
validate-except { string; ... };
|
||||
zero-no-soa-ttl boolean;
|
||||
zero-no-soa-ttl-cache boolean;
|
||||
zone string [ class ] {
|
||||
allow-notify { address_match_element; ... };
|
||||
allow-query { address_match_element; ... };
|
||||
allow-query-on { address_match_element; ... };
|
||||
allow-transfer [ port integer ] [ transport string ] {
|
||||
address_match_element; ... };
|
||||
allow-update { address_match_element; ... };
|
||||
allow-update-forwarding { address_match_element; ... };
|
||||
also-notify [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
alt-transfer-source ( ipv4_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
alt-transfer-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
check-mx-cname ( fail | warn | ignore );
|
||||
check-names ( fail | warn | ignore );
|
||||
check-sibling boolean;
|
||||
check-spf ( warn | ignore );
|
||||
check-srv-cname ( fail | warn | ignore );
|
||||
check-wildcard boolean;
|
||||
database string;
|
||||
delegation-only boolean;
|
||||
dialup ( notify | notify-passive | passive | refresh |
|
||||
boolean );
|
||||
dlz string;
|
||||
dnskey-sig-validity integer;
|
||||
dnssec-dnskey-kskonly boolean;
|
||||
dnssec-loadkeys-interval integer;
|
||||
dnssec-policy string;
|
||||
dnssec-secure-to-insecure boolean;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
file quoted_string;
|
||||
forward ( first | only );
|
||||
forwarders [ port integer ] [ dscp integer ] { (
|
||||
ipv4_address | ipv6_address ) [ port integer ] [
|
||||
dscp integer ]; ... };
|
||||
in-view string;
|
||||
inline-signing boolean;
|
||||
ixfr-from-differences boolean;
|
||||
journal quoted_string;
|
||||
key-directory quoted_string;
|
||||
masterfile-format ( raw | text );
|
||||
masterfile-style ( full | relative );
|
||||
masters [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
max-ixfr-ratio ( unlimited | percentage );
|
||||
max-journal-size ( default | unlimited | sizeval );
|
||||
max-records integer;
|
||||
max-refresh-time integer;
|
||||
max-retry-time integer;
|
||||
max-transfer-idle-in integer;
|
||||
max-transfer-idle-out integer;
|
||||
max-transfer-time-in integer;
|
||||
max-transfer-time-out integer;
|
||||
max-zone-ttl ( unlimited | duration );
|
||||
min-refresh-time integer;
|
||||
min-retry-time integer;
|
||||
multi-master boolean;
|
||||
notify ( explicit | master-only | primary-only | boolean );
|
||||
notify-delay integer;
|
||||
notify-source ( ipv4_address | * ) [ port ( integer | *
|
||||
) ] [ dscp integer ];
|
||||
notify-source-v6 ( ipv6_address | * ) [ port ( integer
|
||||
| * ) ] [ dscp integer ];
|
||||
notify-to-soa boolean;
|
||||
parental-agents [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
parental-source ( ipv4_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
parental-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
primaries [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [
|
||||
tls string ]; ... };
|
||||
request-expire boolean;
|
||||
request-ixfr boolean;
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( ipv4_address | ipv6_address ); ... };
|
||||
server-names { string; ... };
|
||||
sig-signing-nodes integer;
|
||||
sig-signing-signatures integer;
|
||||
sig-signing-type integer;
|
||||
sig-validity-interval integer [ integer ];
|
||||
transfer-source ( ipv4_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
transfer-source-v6 ( ipv6_address | * ) [ port (
|
||||
integer | * ) ] [ dscp integer ];
|
||||
try-tcp-refresh boolean;
|
||||
type ( primary | master | secondary | slave | mirror |
|
||||
delegation-only | forward | hint | redirect |
|
||||
static-stub | stub );
|
||||
update-check-ksk boolean;
|
||||
update-policy ( local | { ( deny | grant ) string (
|
||||
6to4-self | external | krb5-self | krb5-selfsub |
|
||||
krb5-subdomain | krb5-subdomain-self-rhs | ms-self |
|
||||
ms-selfsub | ms-subdomain | ms-subdomain-self-rhs |
|
||||
name | self | selfsub | selfwild | subdomain | tcp-self
|
||||
| wildcard | zonesub ) [ string ] rrtypelist; ... };
|
||||
use-alt-transfer-source boolean;
|
||||
zero-no-soa-ttl boolean;
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
|
||||
ZONE
|
||||
^^^^
|
||||
|
||||
::
|
||||
Any of these zone statements can also be set inside the view statement.
|
||||
|
||||
zone string [ class ] {
|
||||
allow-notify { address_match_element; ... };
|
||||
allow-query { address_match_element; ... };
|
||||
allow-query-on { address_match_element; ... };
|
||||
allow-transfer [ port integer ] [ transport string ] {
|
||||
address_match_element; ... };
|
||||
allow-update { address_match_element; ... };
|
||||
allow-update-forwarding { address_match_element; ... };
|
||||
also-notify [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
alt-transfer-source ( ipv4_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
alt-transfer-source-v6 ( ipv6_address | * ) [ port ( integer |
|
||||
* ) ] [ dscp integer ];
|
||||
auto-dnssec ( allow | maintain | off );
|
||||
check-dup-records ( fail | warn | ignore );
|
||||
check-integrity boolean;
|
||||
check-mx ( fail | warn | ignore );
|
||||
check-mx-cname ( fail | warn | ignore );
|
||||
check-names ( fail | warn | ignore );
|
||||
check-sibling boolean;
|
||||
check-spf ( warn | ignore );
|
||||
check-srv-cname ( fail | warn | ignore );
|
||||
check-wildcard boolean;
|
||||
database string;
|
||||
delegation-only boolean;
|
||||
dialup ( notify | notify-passive | passive | refresh | boolean );
|
||||
dlz string;
|
||||
dnskey-sig-validity integer;
|
||||
dnssec-dnskey-kskonly boolean;
|
||||
dnssec-loadkeys-interval integer;
|
||||
dnssec-policy string;
|
||||
dnssec-secure-to-insecure boolean;
|
||||
dnssec-update-mode ( maintain | no-resign );
|
||||
file quoted_string;
|
||||
forward ( first | only );
|
||||
forwarders [ port integer ] [ dscp integer ] { ( ipv4_address
|
||||
| ipv6_address ) [ port integer ] [ dscp integer ]; ... };
|
||||
in-view string;
|
||||
inline-signing boolean;
|
||||
ixfr-from-differences boolean;
|
||||
journal quoted_string;
|
||||
key-directory quoted_string;
|
||||
masterfile-format ( raw | text );
|
||||
masterfile-style ( full | relative );
|
||||
masters [ port integer ] [ dscp integer ] { ( remote-servers
|
||||
| ipv4_address [ port integer ] | ipv6_address [ port
|
||||
integer ] ) [ key string ] [ tls string ]; ... };
|
||||
max-ixfr-ratio ( unlimited | percentage );
|
||||
max-journal-size ( default | unlimited | sizeval );
|
||||
max-records integer;
|
||||
max-refresh-time integer;
|
||||
max-retry-time integer;
|
||||
max-transfer-idle-in integer;
|
||||
max-transfer-idle-out integer;
|
||||
max-transfer-time-in integer;
|
||||
max-transfer-time-out integer;
|
||||
max-zone-ttl ( unlimited | duration );
|
||||
min-refresh-time integer;
|
||||
min-retry-time integer;
|
||||
multi-master boolean;
|
||||
notify ( explicit | master-only | primary-only | boolean );
|
||||
notify-delay integer;
|
||||
notify-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
notify-source-v6 ( ipv6_address | * ) [ port ( integer | * ) ]
|
||||
[ dscp integer ];
|
||||
notify-to-soa boolean;
|
||||
parental-agents [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
parental-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
parental-source-v6 ( ipv6_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
primaries [ port integer ] [ dscp integer ] { (
|
||||
remote-servers | ipv4_address [ port integer ] |
|
||||
ipv6_address [ port integer ] ) [ key string ] [ tls
|
||||
string ]; ... };
|
||||
request-expire boolean;
|
||||
request-ixfr boolean;
|
||||
serial-update-method ( date | increment | unixtime );
|
||||
server-addresses { ( ipv4_address | ipv6_address ); ... };
|
||||
server-names { string; ... };
|
||||
sig-signing-nodes integer;
|
||||
sig-signing-signatures integer;
|
||||
sig-signing-type integer;
|
||||
sig-validity-interval integer [ integer ];
|
||||
transfer-source ( ipv4_address | * ) [ port ( integer | * ) ] [
|
||||
dscp integer ];
|
||||
transfer-source-v6 ( ipv6_address | * ) [ port ( integer | * )
|
||||
] [ dscp integer ];
|
||||
try-tcp-refresh boolean;
|
||||
type ( primary | master | secondary | slave | mirror |
|
||||
delegation-only | forward | hint | redirect | static-stub |
|
||||
stub );
|
||||
update-check-ksk boolean;
|
||||
update-policy ( local | { ( deny | grant ) string ( 6to4-self |
|
||||
external | krb5-self | krb5-selfsub | krb5-subdomain |
|
||||
krb5-subdomain-self-rhs | ms-self | ms-selfsub | ms-subdomain |
|
||||
ms-subdomain-self-rhs | name | self | selfsub | selfwild |
|
||||
subdomain | tcp-self | wildcard | zonesub ) [ string ]
|
||||
rrtypelist; ... };
|
||||
use-alt-transfer-source boolean;
|
||||
zero-no-soa-ttl boolean;
|
||||
zone-statistics ( full | terse | none | boolean );
|
||||
};
|
||||
.. include:: ../../doc/misc/primary.zoneopt.rst
|
||||
.. include:: ../../doc/misc/secondary.zoneopt.rst
|
||||
.. include:: ../../doc/misc/mirror.zoneopt.rst
|
||||
.. include:: ../../doc/misc/forward.zoneopt.rst
|
||||
.. include:: ../../doc/misc/hint.zoneopt.rst
|
||||
.. include:: ../../doc/misc/redirect.zoneopt.rst
|
||||
.. include:: ../../doc/misc/static-stub.zoneopt.rst
|
||||
.. include:: ../../doc/misc/stub.zoneopt.rst
|
||||
.. include:: ../../doc/misc/delegation-only.zoneopt.rst
|
||||
.. include:: ../../doc/misc/in-view.zoneopt.rst
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/named.conf``
|
||||
|named_conf|
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`named(8)`, :manpage:`named-checkconf(8)`, :manpage:`rndc(8)`, :manpage:`rndc-confgen(8)`, :manpage:`tsig-keygen(8)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`named(8) <named>`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`rndc(8) <rndc>`, :iscman:`rndc-confgen(8) <rndc-confgen>`, :iscman:`tsig-keygen(8) <tsig-keygen>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
|
||||
+78
-55
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: named
|
||||
.. program:: named
|
||||
.. _man_named:
|
||||
|
||||
named - Internet domain name server
|
||||
@@ -24,41 +26,47 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``named`` is a Domain Name System (DNS) server, part of the BIND 9
|
||||
:program:`named` is a Domain Name System (DNS) server, part of the BIND 9
|
||||
distribution from ISC. For more information on the DNS, see :rfc:`1033`,
|
||||
:rfc:`1034`, and :rfc:`1035`.
|
||||
|
||||
When invoked without arguments, ``named`` reads the default
|
||||
configuration file ``/etc/named.conf``, reads any initial data, and
|
||||
When invoked without arguments, :program:`named` reads the default
|
||||
configuration file |named_conf|, reads any initial data, and
|
||||
listens for queries.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
This option tells ``named`` to use only IPv4, even if the host machine is capable of IPv6. ``-4`` and
|
||||
``-6`` are mutually exclusive.
|
||||
.. option:: -4
|
||||
|
||||
``-6``
|
||||
This option tells ``named`` to use only IPv6, even if the host machine is capable of IPv4. ``-4`` and
|
||||
``-6`` are mutually exclusive.
|
||||
This option tells :program:`named` to use only IPv4, even if the host machine is capable of IPv6. :option:`-4` and
|
||||
:option:`-6` are mutually exclusive.
|
||||
|
||||
``-c config-file``
|
||||
This option tells ``named`` to use ``config-file`` as its configuration file instead of the default,
|
||||
``/etc/named.conf``. To ensure that the configuration file
|
||||
.. option:: -6
|
||||
|
||||
This option tells :program:`named` to use only IPv6, even if the host machine is capable of IPv4. :option:`-4` and
|
||||
:option:`-6` are mutually exclusive.
|
||||
|
||||
.. option:: -c config-file
|
||||
|
||||
This option tells :program:`named` to use ``config-file`` as its configuration file instead of the default,
|
||||
|named_conf|. To ensure that the configuration file
|
||||
can be reloaded after the server has changed its working directory
|
||||
due to to a possible ``directory`` option in the configuration file,
|
||||
``config-file`` should be an absolute pathname.
|
||||
|
||||
``-d debug-level``
|
||||
This option sets the daemon's debug level to ``debug-level``. Debugging traces from
|
||||
``named`` become more verbose as the debug level increases.
|
||||
.. option:: -d debug-level
|
||||
|
||||
``-D string``
|
||||
This option specifies a string that is used to identify a instance of ``named``
|
||||
This option sets the daemon's debug level to ``debug-level``. Debugging traces from
|
||||
:program:`named` become more verbose as the debug level increases.
|
||||
|
||||
.. option:: -D string
|
||||
|
||||
This option specifies a string that is used to identify a instance of :program:`named`
|
||||
in a process listing. The contents of ``string`` are not examined.
|
||||
|
||||
``-E engine-name``
|
||||
.. option:: -E engine-name
|
||||
|
||||
When applicable, this option specifies the hardware to use for cryptographic
|
||||
operations, such as a secure key store used for signing.
|
||||
|
||||
@@ -66,36 +74,43 @@ Options
|
||||
engine identifier that drives the cryptographic accelerator or
|
||||
hardware service module (usually ``pkcs11``).
|
||||
|
||||
``-f``
|
||||
.. option:: -f
|
||||
|
||||
This option runs the server in the foreground (i.e., do not daemonize).
|
||||
|
||||
``-g``
|
||||
.. option:: -g
|
||||
|
||||
This option runs the server in the foreground and forces all logging to ``stderr``.
|
||||
|
||||
``-L logfile``
|
||||
.. option:: -L logfile
|
||||
|
||||
This option sets the log to the file ``logfile`` by default, instead of the system log.
|
||||
|
||||
``-M option``
|
||||
.. option:: -M option
|
||||
|
||||
This option sets the default memory context options. If set to ``external``,
|
||||
the internal memory manager is bypassed in favor of
|
||||
system-provided memory allocation functions. If set to ``fill``, blocks
|
||||
of memory are filled with tag values when allocated or freed, to
|
||||
assist debugging of memory problems. ``nofill`` disables this behavior,
|
||||
and is the default unless ``named`` has been compiled with developer
|
||||
and is the default unless :program:`named` has been compiled with developer
|
||||
options.
|
||||
|
||||
``-m flag``
|
||||
.. option:: -m flag
|
||||
|
||||
This option turns on memory usage debugging flags. Possible flags are ``usage``,
|
||||
``trace``, ``record``, ``size``, and ``mctx``. These correspond to the
|
||||
``ISC_MEM_DEBUGXXXX`` flags described in ``<isc/mem.h>``.
|
||||
|
||||
``-n #cpus``
|
||||
.. option:: -n #cpus
|
||||
|
||||
This option creates ``#cpus`` worker threads to take advantage of multiple CPUs. If
|
||||
not specified, ``named`` tries to determine the number of CPUs
|
||||
not specified, :program:`named` tries to determine the number of CPUs
|
||||
present and creates one thread per CPU. If it is unable to determine
|
||||
the number of CPUs, a single worker thread is created.
|
||||
|
||||
``-p value``
|
||||
.. option:: -p value
|
||||
|
||||
This option specifies the port(s) on which the server will listen
|
||||
for queries. If ``value`` is of the form ``<portnum>`` or
|
||||
``dns=<portnum>``, the server will listen for DNS queries on
|
||||
@@ -106,8 +121,9 @@ Options
|
||||
listen for HTTPS queries on ``portnum``; the default is 443.
|
||||
If ``value`` is of the form ``http=<portnum>``, the server will
|
||||
listen for HTTP queries on ``portnum``; the default is 80.
|
||||
|
||||
``-s``
|
||||
|
||||
.. option:: -s
|
||||
|
||||
This option writes memory usage statistics to ``stdout`` on exit.
|
||||
|
||||
.. note::
|
||||
@@ -115,7 +131,8 @@ Options
|
||||
This option is mainly of interest to BIND 9 developers and may be
|
||||
removed or changed in a future release.
|
||||
|
||||
``-S #max-socks``
|
||||
.. option:: -S #max-socks
|
||||
|
||||
This option is deprecated and no longer has any function.
|
||||
|
||||
.. warning::
|
||||
@@ -127,61 +144,67 @@ Options
|
||||
exhaustion of file descriptors and the operational environment is
|
||||
known to support the specified number of sockets. Note also that
|
||||
the actual maximum number is normally slightly fewer than the
|
||||
specified value, because ``named`` reserves some file descriptors
|
||||
specified value, because :program:`named` reserves some file descriptors
|
||||
for its internal use.
|
||||
|
||||
``-t directory``
|
||||
This option tells ``named`` to chroot to ``directory`` after processing the command-line arguments, but
|
||||
.. option:: -t directory
|
||||
|
||||
This option tells :program:`named` to chroot to ``directory`` after processing the command-line arguments, but
|
||||
before reading the configuration file.
|
||||
|
||||
.. warning::
|
||||
|
||||
This option should be used in conjunction with the ``-u`` option,
|
||||
This option should be used in conjunction with the :option:`-u` option,
|
||||
as chrooting a process running as root doesn't enhance security on
|
||||
most systems; the way ``chroot`` is defined allows a process
|
||||
with root privileges to escape a chroot jail.
|
||||
|
||||
``-U #listeners``
|
||||
This option tells ``named`` the number of ``#listeners`` worker threads to listen on, for incoming UDP packets on
|
||||
each address. If not specified, ``named`` calculates a default
|
||||
.. option:: -U #listeners
|
||||
|
||||
This option tells :program:`named` the number of ``#listeners`` worker threads to listen on, for incoming UDP packets on
|
||||
each address. If not specified, :program:`named` calculates a default
|
||||
value based on the number of detected CPUs: 1 for 1 CPU, and the
|
||||
number of detected CPUs minus one for machines with more than 1 CPU.
|
||||
This cannot be increased to a value higher than the number of CPUs.
|
||||
If ``-n`` has been set to a higher value than the number of detected
|
||||
CPUs, then ``-U`` may be increased as high as that value, but no
|
||||
If :option:`-n` has been set to a higher value than the number of detected
|
||||
CPUs, then :option:`-U` may be increased as high as that value, but no
|
||||
higher.
|
||||
|
||||
``-u user``
|
||||
.. option:: -u user
|
||||
|
||||
This option sets the setuid to ``user`` after completing privileged operations, such as
|
||||
creating sockets that listen on privileged ports.
|
||||
|
||||
.. note::
|
||||
|
||||
On Linux, ``named`` uses the kernel's capability mechanism to drop
|
||||
On Linux, :program:`named` uses the kernel's capability mechanism to drop
|
||||
all root privileges except the ability to ``bind`` to a
|
||||
privileged port and set process resource limits. Unfortunately,
|
||||
this means that the ``-u`` option only works when ``named`` is run
|
||||
this means that the :option:`-u` option only works when :program:`named` is run
|
||||
on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or later, since
|
||||
previous kernels did not allow privileges to be retained after
|
||||
``setuid``.
|
||||
|
||||
``-v``
|
||||
.. option:: -v
|
||||
|
||||
This option reports the version number and exits.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option reports the version number and build options, and exits.
|
||||
|
||||
``-X lock-file``
|
||||
.. option:: -X lock-file
|
||||
|
||||
This option acquires a lock on the specified file at runtime; this helps to
|
||||
prevent duplicate ``named`` instances from running simultaneously.
|
||||
prevent duplicate :program:`named` instances from running simultaneously.
|
||||
Use of this option overrides the ``lock-file`` option in
|
||||
``named.conf``. If set to ``none``, the lock file check is disabled.
|
||||
:iscman:`named.conf`. If set to ``none``, the lock file check is disabled.
|
||||
|
||||
Signals
|
||||
~~~~~~~
|
||||
|
||||
In routine operation, signals should not be used to control the
|
||||
nameserver; ``rndc`` should be used instead.
|
||||
nameserver; :iscman:`rndc` should be used instead.
|
||||
|
||||
SIGHUP
|
||||
This signal forces a reload of the server.
|
||||
@@ -194,25 +217,25 @@ The result of sending any other signals to the server is undefined.
|
||||
Configuration
|
||||
~~~~~~~~~~~~~
|
||||
|
||||
The ``named`` configuration file is too complex to describe in detail
|
||||
The :program:`named` configuration file is too complex to describe in detail
|
||||
here. A complete description is provided in the BIND 9 Administrator
|
||||
Reference Manual.
|
||||
|
||||
``named`` inherits the ``umask`` (file creation mode mask) from the
|
||||
parent process. If files created by ``named``, such as journal files,
|
||||
:program:`named` inherits the ``umask`` (file creation mode mask) from the
|
||||
parent process. If files created by :program:`named`, such as journal files,
|
||||
need to have custom permissions, the ``umask`` should be set explicitly
|
||||
in the script used to start the ``named`` process.
|
||||
in the script used to start the :program:`named` process.
|
||||
|
||||
Files
|
||||
~~~~~
|
||||
|
||||
``/etc/named.conf``
|
||||
|named_conf|
|
||||
The default configuration file.
|
||||
|
||||
``/var/run/named/named.pid``
|
||||
|named_pid|
|
||||
The default process-id file.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:rfc:`1033`, :rfc:`1034`, :rfc:`1035`, :manpage:`named-checkconf(8)`, :manpage:`named-checkzone(8)`, :manpage:`rndc(8)`, :manpage:`named.conf(5)`, BIND 9 Administrator Reference Manual.
|
||||
:rfc:`1033`, :rfc:`1034`, :rfc:`1035`, :iscman:`named-checkconf(8) <named-checkconf>`, :iscman:`named-checkzone(8) <named-checkzone>`, :iscman:`rndc(8) <rndc>`, :iscman:`named.conf(5) <named.conf>`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+224
-311
@@ -137,11 +137,9 @@
|
||||
|
||||
#ifdef HAVE_LMDB
|
||||
#include <lmdb.h>
|
||||
#define count_newzones count_newzones_db
|
||||
#define configure_newzones configure_newzones_db
|
||||
#define dumpzone dumpzone_db
|
||||
#else /* HAVE_LMDB */
|
||||
#define count_newzones count_newzones_file
|
||||
#define configure_newzones configure_newzones_file
|
||||
#define dumpzone dumpzone_file
|
||||
#endif /* HAVE_LMDB */
|
||||
@@ -154,12 +152,6 @@
|
||||
#define SIZE_AS_PERCENT ((size_t)-2)
|
||||
#endif /* ifndef SIZE_AS_PERCENT */
|
||||
|
||||
#ifdef TUNE_LARGE
|
||||
#define RESOLVER_NTASKS_PERCPU 32
|
||||
#else
|
||||
#define RESOLVER_NTASKS_PERCPU 8
|
||||
#endif /* TUNE_LARGE */
|
||||
|
||||
/* RFC7828 defines timeout as 16-bit value specified in units of 100
|
||||
* milliseconds, so the maximum and minimum advertised and keepalive
|
||||
* timeouts are capped by the data type (it's ~109 minutes)
|
||||
@@ -433,14 +425,18 @@ configure_alternates(const cfg_obj_t *config, dns_view_t *view,
|
||||
|
||||
static isc_result_t
|
||||
configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
const cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
const cfg_obj_t *vconfig, dns_view_t *view,
|
||||
dns_viewlist_t *viewlist, dns_kasplist_t *kasplist,
|
||||
cfg_aclconfctx_t *aclconf, bool added, bool old_rpz_ok,
|
||||
bool modify);
|
||||
|
||||
static void
|
||||
configure_zone_setviewcommit(isc_result_t result, const cfg_obj_t *zconfig,
|
||||
dns_view_t *view);
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx);
|
||||
cfg_aclconfctx_t *actx);
|
||||
|
||||
static isc_result_t
|
||||
add_keydata_zone(dns_view_t *view, const char *directory, isc_mem_t *mctx);
|
||||
@@ -463,13 +459,7 @@ putuint8(isc_buffer_t **b, uint8_t val);
|
||||
static inline isc_result_t
|
||||
putnull(isc_buffer_t **b);
|
||||
|
||||
static int
|
||||
count_zones(const cfg_obj_t *conf);
|
||||
|
||||
#ifdef HAVE_LMDB
|
||||
static isc_result_t
|
||||
migrate_nzf(dns_view_t *view);
|
||||
|
||||
static isc_result_t
|
||||
nzd_writable(dns_view_t *view);
|
||||
|
||||
@@ -484,14 +474,14 @@ nzd_env_close(dns_view_t *view);
|
||||
|
||||
static isc_result_t
|
||||
nzd_close(MDB_txn **txnp, bool commit);
|
||||
|
||||
static isc_result_t
|
||||
nzd_count(dns_view_t *view, int *countp);
|
||||
#else /* ifdef HAVE_LMDB */
|
||||
static isc_result_t
|
||||
nzf_append(dns_view_t *view, const cfg_obj_t *zconfig);
|
||||
#endif /* ifdef HAVE_LMDB */
|
||||
|
||||
static isc_result_t
|
||||
load_nzf(dns_view_t *view, ns_cfgctx_t *nzcfg);
|
||||
|
||||
/*%
|
||||
* Configure a single view ACL at '*aclp'. Get its configuration from
|
||||
* 'vconfig' (for per-view configuration) and maybe from 'config'
|
||||
@@ -1960,7 +1950,7 @@ dns64_reverse(dns_view_t *view, isc_mem_t *mctx, isc_netaddr_t *na,
|
||||
isc_buffer_constinit(&b, reverse, strlen(reverse));
|
||||
isc_buffer_add(&b, strlen(reverse));
|
||||
CHECK(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
||||
CHECK(dns_zone_create(&zone, mctx));
|
||||
CHECK(dns_zone_create(&zone, mctx, 0));
|
||||
CHECK(dns_zone_setorigin(zone, name));
|
||||
dns_zone_setview(zone, view);
|
||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||
@@ -2413,7 +2403,7 @@ configure_rpz_zone(dns_view_t *view, const cfg_listelt_t *element,
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
configure_rpz(dns_view_t *view, const cfg_obj_t **maps,
|
||||
configure_rpz(dns_view_t *view, dns_view_t *pview, const cfg_obj_t **maps,
|
||||
const cfg_obj_t *rpz_obj, bool *old_rpz_okp) {
|
||||
bool dnsrps_enabled;
|
||||
const cfg_listelt_t *zone_element;
|
||||
@@ -2427,7 +2417,7 @@ configure_rpz(dns_view_t *view, const cfg_obj_t **maps,
|
||||
uint32_t minupdateinterval_default;
|
||||
dns_rpz_zones_t *zones;
|
||||
const dns_rpz_zones_t *old;
|
||||
dns_view_t *pview;
|
||||
bool pview_must_detach = false;
|
||||
const dns_rpz_zone_t *old_zone;
|
||||
isc_result_t result;
|
||||
int i;
|
||||
@@ -2573,14 +2563,19 @@ configure_rpz(dns_view_t *view, const cfg_obj_t **maps,
|
||||
zones->p.nsip_wait_recurse = false;
|
||||
}
|
||||
|
||||
pview = NULL;
|
||||
result = dns_viewlist_find(&named_g_server->viewlist, view->name,
|
||||
view->rdclass, &pview);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
if (pview != NULL) {
|
||||
old = pview->rpzs;
|
||||
} else {
|
||||
old = NULL;
|
||||
result = dns_viewlist_find(&named_g_server->viewlist,
|
||||
view->name, view->rdclass, &pview);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
pview_must_detach = true;
|
||||
old = pview->rpzs;
|
||||
} else {
|
||||
old = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
if (old == NULL) {
|
||||
*old_rpz_okp = false;
|
||||
} else {
|
||||
@@ -2602,7 +2597,7 @@ configure_rpz(dns_view_t *view, const cfg_obj_t **maps,
|
||||
add_soa_default, ttl_default, minupdateinterval_default,
|
||||
old_zone, old_rpz_okp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
if (pview != NULL) {
|
||||
if (pview_must_detach) {
|
||||
dns_view_detach(&pview);
|
||||
}
|
||||
return (result);
|
||||
@@ -2639,7 +2634,7 @@ configure_rpz(dns_view_t *view, const cfg_obj_t **maps,
|
||||
view->rpzs->rpz_ver);
|
||||
}
|
||||
|
||||
if (pview != NULL) {
|
||||
if (pview_must_detach) {
|
||||
dns_view_detach(&pview);
|
||||
}
|
||||
|
||||
@@ -2765,10 +2760,10 @@ catz_addmodzone_taskaction(isc_task_t *task, isc_event_t *event0) {
|
||||
result = isc_task_beginexclusive(task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
dns_view_thaw(ev->view);
|
||||
result = configure_zone(
|
||||
cfg->config, zoneobj, cfg->vconfig, ev->cbd->server->mctx,
|
||||
ev->view, &ev->cbd->server->viewlist,
|
||||
&ev->cbd->server->kasplist, cfg->actx, true, false, ev->mod);
|
||||
result = configure_zone(cfg->config, zoneobj, cfg->vconfig, ev->view,
|
||||
&ev->cbd->server->viewlist,
|
||||
&ev->cbd->server->kasplist, cfg->actx, true,
|
||||
false, ev->mod);
|
||||
dns_view_freeze(ev->view);
|
||||
isc_task_endexclusive(task);
|
||||
|
||||
@@ -2968,15 +2963,14 @@ catz_modzone(dns_catz_entry_t *entry, dns_catz_zone_t *origin, dns_view_t *view,
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
configure_catz_zone(dns_view_t *view, const cfg_obj_t *config,
|
||||
const cfg_listelt_t *element) {
|
||||
configure_catz_zone(dns_view_t *view, dns_view_t *pview,
|
||||
const cfg_obj_t *config, const cfg_listelt_t *element) {
|
||||
const cfg_obj_t *catz_obj, *obj;
|
||||
dns_catz_zone_t *zone = NULL;
|
||||
const char *str;
|
||||
isc_result_t result;
|
||||
dns_name_t origin;
|
||||
dns_catz_options_t *opts;
|
||||
dns_view_t *pview = NULL;
|
||||
|
||||
dns_name_init(&origin, NULL);
|
||||
catz_obj = cfg_listelt_value(element);
|
||||
@@ -3007,9 +3001,7 @@ configure_catz_zone(dns_view_t *view, const cfg_obj_t *config,
|
||||
if (result == ISC_R_EXISTS) {
|
||||
isc_ht_iter_t *it = NULL;
|
||||
|
||||
result = dns_viewlist_find(&named_g_server->viewlist,
|
||||
view->name, view->rdclass, &pview);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
RUNTIME_CHECK(pview != NULL);
|
||||
|
||||
/*
|
||||
* xxxwpk todo: reconfigure the zone!!!!
|
||||
@@ -3021,13 +3013,7 @@ configure_catz_zone(dns_view_t *view, const cfg_obj_t *config,
|
||||
* We have to walk through all the member zones and attach
|
||||
* them to current view
|
||||
*/
|
||||
result = dns_catz_get_iterator(zone, &it);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
cfg_obj_log(catz_obj, named_g_lctx,
|
||||
DNS_CATZ_ERROR_LEVEL,
|
||||
"catz: unable to create iterator");
|
||||
goto cleanup;
|
||||
}
|
||||
dns_catz_get_iterator(zone, &it);
|
||||
|
||||
for (result = isc_ht_iter_first(it); result == ISC_R_SUCCESS;
|
||||
result = isc_ht_iter_next(it))
|
||||
@@ -3100,9 +3086,6 @@ configure_catz_zone(dns_view_t *view, const cfg_obj_t *config,
|
||||
}
|
||||
|
||||
cleanup:
|
||||
if (pview != NULL) {
|
||||
dns_view_detach(&pview);
|
||||
}
|
||||
dns_name_free(&origin, view->mctx);
|
||||
|
||||
return (result);
|
||||
@@ -3114,11 +3097,11 @@ static dns_catz_zonemodmethods_t ns_catz_zonemodmethods = {
|
||||
};
|
||||
|
||||
static isc_result_t
|
||||
configure_catz(dns_view_t *view, const cfg_obj_t *config,
|
||||
configure_catz(dns_view_t *view, dns_view_t *pview, const cfg_obj_t *config,
|
||||
const cfg_obj_t *catz_obj) {
|
||||
const cfg_listelt_t *zone_element;
|
||||
const dns_catz_zones_t *old = NULL;
|
||||
dns_view_t *pview = NULL;
|
||||
bool pview_must_detach = false;
|
||||
isc_result_t result;
|
||||
|
||||
/* xxxwpk TODO do it cleaner, once, somewhere */
|
||||
@@ -3133,10 +3116,15 @@ configure_catz(dns_view_t *view, const cfg_obj_t *config,
|
||||
view->mctx, named_g_taskmgr,
|
||||
named_g_timermgr));
|
||||
|
||||
result = dns_viewlist_find(&named_g_server->viewlist, view->name,
|
||||
view->rdclass, &pview);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
if (pview != NULL) {
|
||||
old = pview->catzs;
|
||||
} else {
|
||||
result = dns_viewlist_find(&named_g_server->viewlist,
|
||||
view->name, view->rdclass, &pview);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
pview_must_detach = true;
|
||||
old = pview->catzs;
|
||||
}
|
||||
}
|
||||
|
||||
if (old != NULL) {
|
||||
@@ -3146,7 +3134,7 @@ configure_catz(dns_view_t *view, const cfg_obj_t *config,
|
||||
}
|
||||
|
||||
while (zone_element != NULL) {
|
||||
CHECK(configure_catz_zone(view, config, zone_element));
|
||||
CHECK(configure_catz_zone(view, pview, config, zone_element));
|
||||
zone_element = cfg_list_next(zone_element);
|
||||
}
|
||||
|
||||
@@ -3157,7 +3145,7 @@ configure_catz(dns_view_t *view, const cfg_obj_t *config,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
if (pview != NULL) {
|
||||
if (pview_must_detach) {
|
||||
dns_view_detach(&pview);
|
||||
}
|
||||
|
||||
@@ -3619,7 +3607,7 @@ create_ipv4only_zone(dns_zone_t *pzone, dns_view_t *view,
|
||||
/*
|
||||
* Create the actual zone.
|
||||
*/
|
||||
CHECK(dns_zone_create(&zone, mctx));
|
||||
CHECK(dns_zone_create(&zone, mctx, 0));
|
||||
CHECK(dns_zone_setorigin(zone, name));
|
||||
CHECK(dns_zonemgr_managezone(named_g_server->zonemgr, zone));
|
||||
dns_zone_setclass(zone, view->rdclass);
|
||||
@@ -4036,6 +4024,9 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
isc_mem_t *cmctx = NULL, *hmctx = NULL;
|
||||
dns_dispatch_t *dispatch4 = NULL;
|
||||
dns_dispatch_t *dispatch6 = NULL;
|
||||
bool rpz_configured = false;
|
||||
bool catz_configured = false;
|
||||
bool zones_configured = false;
|
||||
bool shared_cache = false;
|
||||
int i = 0, j = 0, k = 0;
|
||||
const char *str;
|
||||
@@ -4106,14 +4097,16 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
if (view->rdclass == dns_rdataclass_in && need_hints &&
|
||||
named_config_get(maps, "response-policy", &obj) == ISC_R_SUCCESS)
|
||||
{
|
||||
CHECK(configure_rpz(view, maps, obj, &old_rpz_ok));
|
||||
CHECK(configure_rpz(view, NULL, maps, obj, &old_rpz_ok));
|
||||
rpz_configured = true;
|
||||
}
|
||||
|
||||
obj = NULL;
|
||||
if (view->rdclass == dns_rdataclass_in && need_hints &&
|
||||
named_config_get(maps, "catalog-zones", &obj) == ISC_R_SUCCESS)
|
||||
{
|
||||
CHECK(configure_catz(view, config, obj));
|
||||
CHECK(configure_catz(view, NULL, config, obj));
|
||||
catz_configured = true;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -4133,10 +4126,10 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
element = cfg_list_next(element))
|
||||
{
|
||||
const cfg_obj_t *zconfig = cfg_listelt_value(element);
|
||||
CHECK(configure_zone(config, zconfig, vconfig, mctx, view,
|
||||
viewlist, kasplist, actx, false,
|
||||
old_rpz_ok, false));
|
||||
CHECK(configure_zone(config, zconfig, vconfig, view, viewlist,
|
||||
kasplist, actx, false, old_rpz_ok, false));
|
||||
}
|
||||
zones_configured = true;
|
||||
|
||||
/*
|
||||
* Check that a primary or secondary zone was found for each
|
||||
@@ -4170,7 +4163,7 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
* from the newzone file for zones that were added during previous
|
||||
* runs.
|
||||
*/
|
||||
CHECK(configure_newzones(view, config, vconfig, mctx, actx));
|
||||
CHECK(configure_newzones(view, config, vconfig, actx));
|
||||
|
||||
/*
|
||||
* Create Dynamically Loadable Zone driver.
|
||||
@@ -4715,9 +4708,8 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
|
||||
ndisp = 4 * ISC_MIN(named_g_udpdisp, MAX_UDP_DISPATCH);
|
||||
CHECK(dns_view_createresolver(
|
||||
view, named_g_taskmgr, RESOLVER_NTASKS_PERCPU * named_g_cpus,
|
||||
ndisp, named_g_netmgr, named_g_timermgr, resopts,
|
||||
named_g_dispatchmgr, dispatch4, dispatch6));
|
||||
view, named_g_taskmgr, ndisp, named_g_netmgr, named_g_timermgr,
|
||||
resopts, named_g_dispatchmgr, dispatch4, dispatch6));
|
||||
|
||||
if (dscp4 == -1) {
|
||||
dscp4 = named_g_dscp;
|
||||
@@ -5951,6 +5943,91 @@ configure_view(dns_view_t *view, dns_viewlist_t *viewlist, cfg_obj_t *config,
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
cleanup:
|
||||
/*
|
||||
* Revert to the old view if there was an error.
|
||||
*/
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_result_t result2;
|
||||
|
||||
result2 = dns_viewlist_find(&named_g_server->viewlist,
|
||||
view->name, view->rdclass, &pview);
|
||||
if (result2 == ISC_R_SUCCESS) {
|
||||
dns_view_thaw(pview);
|
||||
|
||||
obj = NULL;
|
||||
if (rpz_configured &&
|
||||
pview->rdclass == dns_rdataclass_in && need_hints &&
|
||||
named_config_get(maps, "response-policy", &obj) ==
|
||||
ISC_R_SUCCESS)
|
||||
{
|
||||
/*
|
||||
* We are swapping the places of the `view` and
|
||||
* `pview` in the function's parameters list
|
||||
* because we are reverting the same operation
|
||||
* done previously in the "correct" order.
|
||||
*/
|
||||
result2 = configure_rpz(pview, view, maps, obj,
|
||||
&old_rpz_ok);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_ERROR,
|
||||
"rpz configuration "
|
||||
"revert failed for view "
|
||||
"'%s'",
|
||||
pview->name);
|
||||
}
|
||||
}
|
||||
|
||||
obj = NULL;
|
||||
if (catz_configured &&
|
||||
pview->rdclass == dns_rdataclass_in && need_hints &&
|
||||
named_config_get(maps, "catalog-zones", &obj) ==
|
||||
ISC_R_SUCCESS)
|
||||
{
|
||||
if (pview->catzs != NULL) {
|
||||
dns_catz_catzs_detach(&pview->catzs);
|
||||
}
|
||||
/*
|
||||
* We are swapping the places of the `view` and
|
||||
* `pview` in the function's parameters list
|
||||
* because we are reverting the same operation
|
||||
* done previously in the "correct" order.
|
||||
*/
|
||||
result2 = configure_catz(pview, view, config,
|
||||
obj);
|
||||
if (result2 != ISC_R_SUCCESS) {
|
||||
isc_log_write(named_g_lctx,
|
||||
NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER,
|
||||
ISC_LOG_ERROR,
|
||||
"catz configuration "
|
||||
"revert failed for view "
|
||||
"'%s'",
|
||||
pview->name);
|
||||
}
|
||||
}
|
||||
|
||||
dns_view_freeze(pview);
|
||||
}
|
||||
|
||||
if (pview != NULL) {
|
||||
dns_view_detach(&pview);
|
||||
}
|
||||
|
||||
if (zones_configured) {
|
||||
for (element = cfg_list_first(zonelist);
|
||||
element != NULL; element = cfg_list_next(element))
|
||||
{
|
||||
const cfg_obj_t *zconfig =
|
||||
cfg_listelt_value(element);
|
||||
configure_zone_setviewcommit(result, zconfig,
|
||||
view);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (ntatable != NULL) {
|
||||
dns_ntatable_detach(&ntatable);
|
||||
}
|
||||
@@ -6327,7 +6404,7 @@ create_view(const cfg_obj_t *vconfig, dns_viewlist_t *viewlist,
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
const cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
const cfg_obj_t *vconfig, dns_view_t *view,
|
||||
dns_viewlist_t *viewlist, dns_kasplist_t *kasplist,
|
||||
cfg_aclconfctx_t *aclconf, bool added, bool old_rpz_ok,
|
||||
bool modify) {
|
||||
@@ -6711,7 +6788,8 @@ configure_zone(const cfg_obj_t *config, const cfg_obj_t *zconfig,
|
||||
if (inline_signing) {
|
||||
dns_zone_getraw(zone, &raw);
|
||||
if (raw == NULL) {
|
||||
CHECK(dns_zone_create(&raw, mctx));
|
||||
CHECK(dns_zone_create(&raw, dns_zone_mctx(zone),
|
||||
dns_zone_tid(zone)));
|
||||
CHECK(dns_zone_setorigin(raw, origin));
|
||||
dns_zone_setview(raw, view);
|
||||
dns_zone_setstats(raw, named_g_server->zonestats);
|
||||
@@ -7621,94 +7699,9 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
#ifndef HAVE_LMDB
|
||||
static isc_result_t
|
||||
count_newzones(dns_view_t *view, ns_cfgctx_t *nzcfg, int *num_zonesp) {
|
||||
isc_result_t result;
|
||||
|
||||
/* The new zone file may not exist. That is OK. */
|
||||
if (!isc_file_exists(view->new_zone_file)) {
|
||||
*num_zonesp = 0;
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
/*
|
||||
* In the case of NZF files, we also parse the configuration in
|
||||
* the file at this stage.
|
||||
*
|
||||
* This may be called in multiple views, so we reset
|
||||
* the parser each time.
|
||||
*/
|
||||
cfg_parser_reset(named_g_addparser);
|
||||
result = cfg_parse_file(named_g_addparser, view->new_zone_file,
|
||||
&cfg_type_addzoneconf, &nzcfg->nzf_config);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
int num_zones;
|
||||
|
||||
num_zones = count_zones(nzcfg->nzf_config);
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"NZF file '%s' contains %d zones",
|
||||
view->new_zone_file, num_zones);
|
||||
if (num_zonesp != NULL) {
|
||||
*num_zonesp = num_zones;
|
||||
}
|
||||
} else {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"Error parsing NZF file '%s': %s",
|
||||
view->new_zone_file, isc_result_totext(result));
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
#else /* HAVE_LMDB */
|
||||
|
||||
static isc_result_t
|
||||
count_newzones(dns_view_t *view, ns_cfgctx_t *nzcfg, int *num_zonesp) {
|
||||
isc_result_t result;
|
||||
int n;
|
||||
|
||||
UNUSED(nzcfg);
|
||||
|
||||
REQUIRE(num_zonesp != NULL);
|
||||
|
||||
LOCK(&view->new_zone_lock);
|
||||
|
||||
CHECK(migrate_nzf(view));
|
||||
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"loading NZD zone count from '%s' "
|
||||
"for view '%s'",
|
||||
view->new_zone_db, view->name);
|
||||
|
||||
CHECK(nzd_count(view, &n));
|
||||
|
||||
*num_zonesp = n;
|
||||
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"NZD database '%s' contains %d zones", view->new_zone_db,
|
||||
n);
|
||||
|
||||
cleanup:
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
*num_zonesp = 0;
|
||||
}
|
||||
|
||||
UNLOCK(&view->new_zone_lock);
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
static isc_result_t
|
||||
setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
cfg_parser_t *conf_parser, cfg_aclconfctx_t *actx,
|
||||
int *num_zones) {
|
||||
cfg_parser_t *conf_parser, cfg_aclconfctx_t *actx) {
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
bool allow = false;
|
||||
ns_cfgctx_t *nzcfg = NULL;
|
||||
@@ -7806,28 +7799,29 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
|
||||
if (!allow) {
|
||||
dns_view_setnewzones(view, false, NULL, NULL, 0ULL);
|
||||
if (num_zones != NULL) {
|
||||
*num_zones = 0;
|
||||
}
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
nzcfg = isc_mem_get(view->mctx, sizeof(*nzcfg));
|
||||
*nzcfg = (ns_cfgctx_t){ 0 };
|
||||
|
||||
/*
|
||||
* We attach the parser that was used for config as well
|
||||
* as the one that will be used for added zones, to avoid
|
||||
* a shutdown race later.
|
||||
*/
|
||||
memset(nzcfg, 0, sizeof(*nzcfg));
|
||||
isc_mem_attach(view->mctx, &nzcfg->mctx);
|
||||
cfg_parser_attach(conf_parser, &nzcfg->conf_parser);
|
||||
cfg_parser_attach(named_g_addparser, &nzcfg->add_parser);
|
||||
isc_mem_attach(view->mctx, &nzcfg->mctx);
|
||||
cfg_aclconfctx_attach(actx, &nzcfg->actx);
|
||||
|
||||
result = dns_view_setnewzones(view, true, nzcfg, newzone_cfgctx_destroy,
|
||||
mapsize);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
cfg_aclconfctx_detach(&nzcfg->actx);
|
||||
cfg_parser_destroy(&nzcfg->add_parser);
|
||||
cfg_parser_destroy(&nzcfg->conf_parser);
|
||||
isc_mem_putanddetach(&nzcfg->mctx, nzcfg, sizeof(*nzcfg));
|
||||
dns_view_setnewzones(view, false, NULL, NULL, 0ULL);
|
||||
return (result);
|
||||
}
|
||||
@@ -7837,7 +7831,7 @@ setup_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
cfg_obj_attach(vconfig, &nzcfg->vconfig);
|
||||
}
|
||||
|
||||
result = count_newzones(view, nzcfg, num_zones);
|
||||
result = load_nzf(view, nzcfg);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -7885,7 +7879,7 @@ configure_zone_setviewcommit(isc_result_t result, const cfg_obj_t *zconfig,
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx) {
|
||||
cfg_aclconfctx_t *actx) {
|
||||
isc_result_t result;
|
||||
ns_cfgctx_t *nzctx;
|
||||
const cfg_obj_t *zonelist;
|
||||
@@ -7907,7 +7901,7 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
element = cfg_list_next(element))
|
||||
{
|
||||
const cfg_obj_t *zconfig = cfg_listelt_value(element);
|
||||
CHECK(configure_zone(config, zconfig, vconfig, mctx, view,
|
||||
CHECK(configure_zone(config, zconfig, vconfig, view,
|
||||
&named_g_server->viewlist,
|
||||
&named_g_server->kasplist, actx, true,
|
||||
false, false));
|
||||
@@ -8004,7 +7998,7 @@ cleanup:
|
||||
*/
|
||||
typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, dns_view_t *view,
|
||||
dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx);
|
||||
|
||||
/*%
|
||||
@@ -8020,7 +8014,7 @@ typedef isc_result_t (*newzone_cfg_cb_t)(const cfg_obj_t *zconfig,
|
||||
*/
|
||||
static isc_result_t
|
||||
for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_obj_t *vconfig, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx, MDB_txn *txn, MDB_dbi dbi) {
|
||||
const cfg_obj_t *zconfig, *zlist;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
@@ -8063,7 +8057,7 @@ for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
/*
|
||||
* Invoke callback.
|
||||
*/
|
||||
result = callback(zconfig, config, vconfig, mctx, view, actx);
|
||||
result = callback(zconfig, config, vconfig, view, actx);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
break;
|
||||
}
|
||||
@@ -8090,10 +8084,10 @@ for_all_newzone_cfgs(newzone_cfg_cb_t callback, cfg_obj_t *config,
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_obj_t *vconfig, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx) {
|
||||
return (configure_zone(
|
||||
config, zconfig, vconfig, mctx, view, &named_g_server->viewlist,
|
||||
config, zconfig, vconfig, view, &named_g_server->viewlist,
|
||||
&named_g_server->kasplist, actx, true, false, false));
|
||||
}
|
||||
|
||||
@@ -8102,11 +8096,10 @@ configure_newzone(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
*/
|
||||
static isc_result_t
|
||||
configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
cfg_obj_t *vconfig, isc_mem_t *mctx, dns_view_t *view,
|
||||
cfg_obj_t *vconfig, dns_view_t *view,
|
||||
cfg_aclconfctx_t *actx) {
|
||||
UNUSED(config);
|
||||
UNUSED(vconfig);
|
||||
UNUSED(mctx);
|
||||
UNUSED(actx);
|
||||
|
||||
configure_zone_setviewcommit(ISC_R_FAILURE, zconfig, view);
|
||||
@@ -8116,7 +8109,7 @@ configure_newzone_revert(const cfg_obj_t *zconfig, cfg_obj_t *config,
|
||||
|
||||
static isc_result_t
|
||||
configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
isc_mem_t *mctx, cfg_aclconfctx_t *actx) {
|
||||
cfg_aclconfctx_t *actx) {
|
||||
isc_result_t result;
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
@@ -8139,8 +8132,8 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
"for view '%s'",
|
||||
view->new_zone_db, view->name);
|
||||
|
||||
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, mctx,
|
||||
view, actx, txn, dbi);
|
||||
result = for_all_newzone_cfgs(configure_newzone, config, vconfig, view,
|
||||
actx, txn, dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
/*
|
||||
* An error was encountered while attempting to configure zones
|
||||
@@ -8151,7 +8144,7 @@ configure_newzones(dns_view_t *view, cfg_obj_t *config, cfg_obj_t *vconfig,
|
||||
* terms of trying to make things right.
|
||||
*/
|
||||
(void)for_all_newzone_cfgs(configure_newzone_revert, config,
|
||||
vconfig, mctx, view, actx, txn, dbi);
|
||||
vconfig, view, actx, txn, dbi);
|
||||
}
|
||||
|
||||
(void)nzd_close(&txn, false);
|
||||
@@ -8227,24 +8220,6 @@ cleanup:
|
||||
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
static int
|
||||
count_zones(const cfg_obj_t *conf) {
|
||||
const cfg_obj_t *zonelist = NULL;
|
||||
const cfg_listelt_t *element;
|
||||
int n = 0;
|
||||
|
||||
REQUIRE(conf != NULL);
|
||||
|
||||
cfg_map_get(conf, "zone", &zonelist);
|
||||
for (element = cfg_list_first(zonelist); element != NULL;
|
||||
element = cfg_list_next(element))
|
||||
{
|
||||
n++;
|
||||
}
|
||||
|
||||
return (n);
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
check_lockfile(named_server_t *server, const cfg_obj_t *config,
|
||||
bool first_time) {
|
||||
@@ -8350,7 +8325,6 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
dns_viewlist_t viewlist, builtin_viewlist;
|
||||
in_port_t listen_port, udpport_low, udpport_high;
|
||||
int i, backlog;
|
||||
int num_zones = 0;
|
||||
bool exclusive = false;
|
||||
isc_interval_t interval;
|
||||
isc_logconfig_t *logc = NULL;
|
||||
@@ -8599,15 +8573,6 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
server->sctx->blackholeacl);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set "keep-response-order". Only legal at options or
|
||||
* global defaults level.
|
||||
*/
|
||||
CHECK(configure_view_acl(NULL, config, named_g_config,
|
||||
"keep-response-order", NULL,
|
||||
named_g_aclconfctx, named_g_mctx,
|
||||
&server->sctx->keepresporder));
|
||||
|
||||
obj = NULL;
|
||||
result = named_config_get(maps, "match-mapped-addresses", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
@@ -8975,13 +8940,11 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
interface_interval = cfg_obj_asduration(obj);
|
||||
if (interface_interval == 0) {
|
||||
CHECK(isc_timer_reset(server->interface_timer,
|
||||
isc_timertype_inactive, NULL, NULL,
|
||||
true));
|
||||
isc_timertype_inactive, NULL, true));
|
||||
} else if (server->interface_interval != interface_interval) {
|
||||
isc_interval_set(&interval, interface_interval, 0);
|
||||
CHECK(isc_timer_reset(server->interface_timer,
|
||||
isc_timertype_ticker, NULL, &interval,
|
||||
false));
|
||||
isc_timertype_ticker, &interval, false));
|
||||
}
|
||||
server->interface_interval = interface_interval;
|
||||
|
||||
@@ -9002,22 +8965,20 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
heartbeat_interval = cfg_obj_asuint32(obj) * 60;
|
||||
if (heartbeat_interval == 0) {
|
||||
CHECK(isc_timer_reset(server->heartbeat_timer,
|
||||
isc_timertype_inactive, NULL, NULL,
|
||||
true));
|
||||
isc_timertype_inactive, NULL, true));
|
||||
} else if (server->heartbeat_interval != heartbeat_interval) {
|
||||
isc_interval_set(&interval, heartbeat_interval, 0);
|
||||
CHECK(isc_timer_reset(server->heartbeat_timer,
|
||||
isc_timertype_ticker, NULL, &interval,
|
||||
false));
|
||||
isc_timertype_ticker, &interval, false));
|
||||
}
|
||||
server->heartbeat_interval = heartbeat_interval;
|
||||
|
||||
isc_interval_set(&interval, 1200, 0);
|
||||
CHECK(isc_timer_reset(server->pps_timer, isc_timertype_ticker, NULL,
|
||||
CHECK(isc_timer_reset(server->pps_timer, isc_timertype_ticker,
|
||||
&interval, false));
|
||||
|
||||
isc_interval_set(&interval, named_g_tat_interval, 0);
|
||||
CHECK(isc_timer_reset(server->tat_timer, isc_timertype_ticker, NULL,
|
||||
CHECK(isc_timer_reset(server->tat_timer, isc_timertype_ticker,
|
||||
&interval, false));
|
||||
|
||||
/*
|
||||
@@ -9105,19 +9066,14 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
element = cfg_list_next(element))
|
||||
{
|
||||
cfg_obj_t *vconfig = cfg_listelt_value(element);
|
||||
const cfg_obj_t *voptions = cfg_tuple_get(vconfig, "options");
|
||||
int nzf_num_zones;
|
||||
|
||||
view = NULL;
|
||||
|
||||
CHECK(create_view(vconfig, &viewlist, &view));
|
||||
INSIST(view != NULL);
|
||||
|
||||
num_zones += count_zones(voptions);
|
||||
|
||||
CHECK(setup_newzones(view, config, vconfig, conf_parser,
|
||||
named_g_aclconfctx, &nzf_num_zones));
|
||||
num_zones += nzf_num_zones;
|
||||
named_g_aclconfctx));
|
||||
|
||||
dns_view_detach(&view);
|
||||
}
|
||||
@@ -9127,28 +9083,15 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
* view here.
|
||||
*/
|
||||
if (views == NULL) {
|
||||
int nzf_num_zones;
|
||||
|
||||
CHECK(create_view(NULL, &viewlist, &view));
|
||||
INSIST(view != NULL);
|
||||
|
||||
num_zones = count_zones(config);
|
||||
|
||||
CHECK(setup_newzones(view, config, NULL, conf_parser,
|
||||
named_g_aclconfctx, &nzf_num_zones));
|
||||
num_zones += nzf_num_zones;
|
||||
named_g_aclconfctx));
|
||||
|
||||
dns_view_detach(&view);
|
||||
}
|
||||
|
||||
/*
|
||||
* Zones have been counted; set the zone manager task pool size.
|
||||
*/
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"sizing zone task pool based on %d zones", num_zones);
|
||||
CHECK(dns_zonemgr_setsize(named_g_server->zonemgr, num_zones));
|
||||
|
||||
/*
|
||||
* Configure and freeze all explicit views. Explicit
|
||||
* views that have zones were already created at parsing
|
||||
@@ -9854,31 +9797,21 @@ run_server(isc_task_t *task, isc_event_t *event) {
|
||||
CHECKFATAL(ns_interfacemgr_create(named_g_mctx, server->sctx,
|
||||
named_g_taskmgr, named_g_timermgr,
|
||||
named_g_netmgr, named_g_dispatchmgr,
|
||||
server->task, geoip, named_g_cpus,
|
||||
true, &server->interfacemgr),
|
||||
server->task, geoip, true,
|
||||
&server->interfacemgr),
|
||||
"creating interface manager");
|
||||
|
||||
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
||||
NULL, NULL, server->task,
|
||||
interface_timer_tick, server,
|
||||
&server->interface_timer),
|
||||
"creating interface timer");
|
||||
isc_timer_create(named_g_timermgr, server->task, interface_timer_tick,
|
||||
server, &server->interface_timer);
|
||||
|
||||
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
||||
NULL, NULL, server->task,
|
||||
heartbeat_timer_tick, server,
|
||||
&server->heartbeat_timer),
|
||||
"creating heartbeat timer");
|
||||
isc_timer_create(named_g_timermgr, server->task, heartbeat_timer_tick,
|
||||
server, &server->heartbeat_timer);
|
||||
|
||||
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
||||
NULL, NULL, server->task, tat_timer_tick,
|
||||
server, &server->tat_timer),
|
||||
"creating trust anchor telemetry timer");
|
||||
isc_timer_create(named_g_timermgr, server->task, tat_timer_tick, server,
|
||||
&server->tat_timer);
|
||||
|
||||
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
||||
NULL, NULL, server->task, pps_timer_tick,
|
||||
server, &server->pps_timer),
|
||||
"creating pps timer");
|
||||
isc_timer_create(named_g_timermgr, server->task, pps_timer_tick, server,
|
||||
&server->pps_timer);
|
||||
|
||||
CHECKFATAL(
|
||||
cfg_parser_create(named_g_mctx, named_g_lctx, &named_g_parser),
|
||||
@@ -10084,7 +10017,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
||||
* startup and shutdown of the server, as well as all exclusive
|
||||
* tasks.
|
||||
*/
|
||||
CHECKFATAL(isc_task_create_bound(named_g_taskmgr, 0, &server->task, 0),
|
||||
CHECKFATAL(isc_task_create(named_g_taskmgr, 0, &server->task, 0),
|
||||
"creating server task");
|
||||
isc_task_setname(server->task, "server", server);
|
||||
isc_taskmgr_setexcltask(named_g_taskmgr, server->task);
|
||||
@@ -10125,8 +10058,6 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
||||
named_g_timermgr, named_g_netmgr,
|
||||
&server->zonemgr),
|
||||
"dns_zonemgr_create");
|
||||
CHECKFATAL(dns_zonemgr_setsize(server->zonemgr, 1000), "dns_zonemgr_"
|
||||
"setsize");
|
||||
|
||||
server->statsfile = isc_mem_strdup(server->mctx, "named.stats");
|
||||
CHECKFATAL(server->statsfile == NULL ? ISC_R_NOMEMORY : ISC_R_SUCCESS,
|
||||
@@ -13024,7 +12955,32 @@ cleanup:
|
||||
return (result);
|
||||
}
|
||||
|
||||
#else /* HAVE_LMDB */
|
||||
static isc_result_t
|
||||
load_nzf(dns_view_t *view, ns_cfgctx_t *nzcfg) {
|
||||
isc_result_t result;
|
||||
|
||||
/* The new zone file may not exist. That is OK. */
|
||||
if (!isc_file_exists(view->new_zone_file)) {
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
/*
|
||||
* Parse the configuration in the NZF file. This may be called in
|
||||
* multiple views, so we reset the parser each time.
|
||||
*/
|
||||
cfg_parser_reset(named_g_addparser);
|
||||
result = cfg_parse_file(named_g_addparser, view->new_zone_file,
|
||||
&cfg_type_addzoneconf, &nzcfg->nzf_config);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"Error parsing NZF file '%s': %s",
|
||||
view->new_zone_file, isc_result_totext(result));
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
#else /* HAVE_LMDB */
|
||||
|
||||
static void
|
||||
nzd_setkey(MDB_val *key, dns_name_t *name, char *namebuf, size_t buflen) {
|
||||
@@ -13349,52 +13305,16 @@ nzd_close(MDB_txn **txnp, bool commit) {
|
||||
}
|
||||
|
||||
/*
|
||||
* Count the zones configured in the new zone database for 'view' and store the
|
||||
* result in 'countp'.
|
||||
* If there's an existing NZF file, load it and migrate its data
|
||||
* to the NZD.
|
||||
*
|
||||
* Caller must hold 'view->new_zone_lock'.
|
||||
*/
|
||||
static isc_result_t
|
||||
nzd_count(dns_view_t *view, int *countp) {
|
||||
isc_result_t result;
|
||||
int status;
|
||||
MDB_txn *txn = NULL;
|
||||
MDB_dbi dbi;
|
||||
MDB_stat statbuf;
|
||||
|
||||
REQUIRE(countp != NULL);
|
||||
|
||||
result = nzd_open(view, MDB_RDONLY, &txn, &dbi);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
status = mdb_stat(txn, dbi, &statbuf);
|
||||
if (status != MDB_SUCCESS) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||
"mdb_stat: %s", mdb_strerror(status));
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
*countp = statbuf.ms_entries;
|
||||
|
||||
cleanup:
|
||||
(void)nzd_close(&txn, false);
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Migrate zone configuration from an NZF file to an NZD database.
|
||||
* Caller must hold view->new_zone_lock.
|
||||
*/
|
||||
static isc_result_t
|
||||
migrate_nzf(dns_view_t *view) {
|
||||
load_nzf(dns_view_t *view, ns_cfgctx_t *nzcfg) {
|
||||
isc_result_t result;
|
||||
cfg_obj_t *nzf_config = NULL;
|
||||
int status, n;
|
||||
int status;
|
||||
isc_buffer_t *text = NULL;
|
||||
bool commit = false;
|
||||
const cfg_obj_t *zonelist;
|
||||
@@ -13405,6 +13325,8 @@ migrate_nzf(dns_view_t *view) {
|
||||
MDB_val key, data;
|
||||
ns_dzarg_t dzarg;
|
||||
|
||||
UNUSED(nzcfg);
|
||||
|
||||
/*
|
||||
* If NZF file doesn't exist, or NZD DB exists and already
|
||||
* has data, return without attempting migration.
|
||||
@@ -13414,12 +13336,6 @@ migrate_nzf(dns_view_t *view) {
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = nzd_count(view, &n);
|
||||
if (result == ISC_R_SUCCESS && n > 0) {
|
||||
result = ISC_R_SUCCESS;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||
"Migrating zones from NZF file '%s' to "
|
||||
@@ -13497,7 +13413,7 @@ migrate_nzf(dns_view_t *view) {
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"Error writing zone config to "
|
||||
"buffer in migrate_nzf(): %s",
|
||||
"buffer in load_nzf(): %s",
|
||||
isc_result_totext(result));
|
||||
result = dzarg.result;
|
||||
goto cleanup;
|
||||
@@ -13550,7 +13466,6 @@ cleanup:
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
#endif /* HAVE_LMDB */
|
||||
|
||||
static isc_result_t
|
||||
@@ -13806,10 +13721,9 @@ do_addzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
|
||||
/* Mark view unfrozen and configure zone */
|
||||
dns_view_thaw(view);
|
||||
result = configure_zone(cfg->config, zoneobj, cfg->vconfig,
|
||||
server->mctx, view, &server->viewlist,
|
||||
&server->kasplist, cfg->actx, true, false,
|
||||
false);
|
||||
result = configure_zone(cfg->config, zoneobj, cfg->vconfig, view,
|
||||
&server->viewlist, &server->kasplist, cfg->actx,
|
||||
true, false, false);
|
||||
dns_view_freeze(view);
|
||||
|
||||
isc_task_endexclusive(server->task);
|
||||
@@ -13994,10 +13908,9 @@ do_modzone(named_server_t *server, ns_cfgctx_t *cfg, dns_view_t *view,
|
||||
|
||||
/* Reconfigure the zone */
|
||||
dns_view_thaw(view);
|
||||
result = configure_zone(cfg->config, zoneobj, cfg->vconfig,
|
||||
server->mctx, view, &server->viewlist,
|
||||
&server->kasplist, cfg->actx, true, false,
|
||||
true);
|
||||
result = configure_zone(cfg->config, zoneobj, cfg->vconfig, view,
|
||||
&server->viewlist, &server->kasplist, cfg->actx,
|
||||
true, false, true);
|
||||
dns_view_freeze(view);
|
||||
|
||||
exclusive = false;
|
||||
|
||||
+11
-16
@@ -719,12 +719,6 @@ doshutdown(void) {
|
||||
dns_message_detach(&updatemsg);
|
||||
}
|
||||
|
||||
if (is_dst_up) {
|
||||
ddebug("Destroy DST lib");
|
||||
dst_lib_destroy();
|
||||
is_dst_up = false;
|
||||
}
|
||||
|
||||
ddebug("Destroying request manager");
|
||||
dns_requestmgr_detach(&requestmgr);
|
||||
|
||||
@@ -921,7 +915,7 @@ setup_system(void) {
|
||||
result = dns_dispatchmgr_create(gmctx, netmgr, &dispatchmgr);
|
||||
check_result(result, "dns_dispatchmgr_create");
|
||||
|
||||
result = isc_task_create(taskmgr, 0, &global_task);
|
||||
result = isc_task_create(taskmgr, 0, &global_task, 0);
|
||||
check_result(result, "isc_task_create");
|
||||
|
||||
result = isc_task_onshutdown(global_task, shutdown_program, NULL);
|
||||
@@ -982,11 +976,6 @@ get_addresses(char *host, in_port_t port, isc_sockaddr_t *sockaddr,
|
||||
return (count);
|
||||
}
|
||||
|
||||
static void
|
||||
version(void) {
|
||||
fprintf(stderr, "nsupdate %s\n", PACKAGE_VERSION);
|
||||
}
|
||||
|
||||
#define PARSE_ARGS_FMT "46C:dDghilL:Mok:p:Pr:R:t:Tu:vVy:"
|
||||
|
||||
static void
|
||||
@@ -1061,7 +1050,7 @@ pre_parse_args(int argc, char **argv) {
|
||||
break;
|
||||
|
||||
case 'V':
|
||||
version();
|
||||
printf("nsupdate %s\n", PACKAGE_VERSION);
|
||||
doexit = true;
|
||||
break;
|
||||
|
||||
@@ -3305,6 +3294,9 @@ cleanup(void) {
|
||||
}
|
||||
UNLOCK(&answer_lock);
|
||||
|
||||
ddebug("Shutting down managers");
|
||||
isc_managers_destroy(&netmgr, &taskmgr, NULL);
|
||||
|
||||
#if HAVE_GSSAPI
|
||||
if (tsigkey != NULL) {
|
||||
ddebug("detach tsigkey x%p", tsigkey);
|
||||
@@ -3320,9 +3312,6 @@ cleanup(void) {
|
||||
dst_key_free(&sig0key);
|
||||
}
|
||||
|
||||
ddebug("Shutting down managers");
|
||||
isc_managers_destroy(&netmgr, &taskmgr, NULL);
|
||||
|
||||
ddebug("Destroying event");
|
||||
isc_event_free(&global_event);
|
||||
|
||||
@@ -3356,6 +3345,12 @@ cleanup(void) {
|
||||
isc_mem_destroy(&gmctx);
|
||||
|
||||
isc_mutex_destroy(&answer_lock);
|
||||
|
||||
if (is_dst_up) {
|
||||
ddebug("Destroy DST lib");
|
||||
dst_lib_destroy();
|
||||
is_dst_up = false;
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
|
||||
+80
-53
@@ -9,8 +9,8 @@
|
||||
.. See the COPYRIGHT file distributed with this work for additional
|
||||
.. information regarding copyright ownership.
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: nsupdate
|
||||
.. program:: nsupdate
|
||||
.. _man_nsupdate:
|
||||
|
||||
nsupdate - dynamic DNS update utility
|
||||
@@ -24,18 +24,18 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``nsupdate`` is used to submit Dynamic DNS Update requests, as defined in
|
||||
:program:`nsupdate` is used to submit Dynamic DNS Update requests, as defined in
|
||||
:rfc:`2136`, to a name server. This allows resource records to be added or
|
||||
removed from a zone without manually editing the zone file. A single
|
||||
update request can contain requests to add or remove more than one
|
||||
resource record.
|
||||
|
||||
Zones that are under dynamic control via ``nsupdate`` or a DHCP server
|
||||
Zones that are under dynamic control via :program:`nsupdate` or a DHCP server
|
||||
should not be edited by hand. Manual edits could conflict with dynamic
|
||||
updates and cause data to be lost.
|
||||
|
||||
The resource records that are dynamically added or removed with
|
||||
``nsupdate`` must be in the same zone. Requests are sent to the
|
||||
:program:`nsupdate` must be in the same zone. Requests are sent to the
|
||||
zone's primary server, which is identified by the MNAME field of the
|
||||
zone's SOA record.
|
||||
|
||||
@@ -44,87 +44,110 @@ updates. These use the TSIG resource record type described in :rfc:`2845`,
|
||||
the SIG(0) record described in :rfc:`2535` and :rfc:`2931`, or GSS-TSIG as
|
||||
described in :rfc:`3645`.
|
||||
|
||||
TSIG relies on a shared secret that should only be known to ``nsupdate``
|
||||
TSIG relies on a shared secret that should only be known to :program:`nsupdate`
|
||||
and the name server. For instance, suitable ``key`` and ``server``
|
||||
statements are added to ``/etc/named.conf`` so that the name server
|
||||
statements are added to |named_conf| so that the name server
|
||||
can associate the appropriate secret key and algorithm with the IP
|
||||
address of the client application that is using TSIG
|
||||
authentication. ``ddns-confgen`` can generate suitable
|
||||
configuration fragments. ``nsupdate`` uses the ``-y`` or ``-k`` options
|
||||
authentication. :iscman:`ddns-confgen` can generate suitable
|
||||
configuration fragments. :program:`nsupdate` uses the :option:`-y` or :option:`-k` options
|
||||
to provide the TSIG shared secret; these options are mutually exclusive.
|
||||
|
||||
SIG(0) uses public key cryptography. To use a SIG(0) key, the public key
|
||||
must be stored in a KEY record in a zone served by the name server.
|
||||
|
||||
GSS-TSIG uses Kerberos credentials. Standard GSS-TSIG mode is switched
|
||||
on with the ``-g`` flag. A non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000 can be switched on with the ``-o`` flag.
|
||||
on with the :option:`-g` flag. A non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000 can be switched on with the :option:`-o` flag.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option sets use of IPv4 only.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option sets use of IPv6 only.
|
||||
|
||||
``-C``
|
||||
.. option:: -C
|
||||
|
||||
Overrides the default `resolv.conf` file. This is only intended for testing.
|
||||
|
||||
``-d``
|
||||
.. option:: -d
|
||||
|
||||
This option sets debug mode, which provides tracing information about the update
|
||||
requests that are made and the replies received from the name server.
|
||||
|
||||
``-D``
|
||||
.. option:: -D
|
||||
|
||||
This option sets extra debug mode.
|
||||
|
||||
``-i``
|
||||
.. option:: -g
|
||||
|
||||
This option enables standard GSS-TSIG mode.
|
||||
|
||||
.. option:: -i
|
||||
|
||||
This option forces interactive mode, even when standard input is not a terminal.
|
||||
|
||||
``-k keyfile``
|
||||
.. option:: -k keyfile
|
||||
|
||||
This option indicates the file containing the TSIG authentication key. Keyfiles may be in
|
||||
two formats: a single file containing a ``named.conf``-format ``key``
|
||||
statement, which may be generated automatically by ``ddns-confgen``;
|
||||
two formats: a single file containing a :iscman:`named.conf`-format ``key``
|
||||
statement, which may be generated automatically by :iscman:`ddns-confgen`;
|
||||
or a pair of files whose names are of the format
|
||||
``K{name}.+157.+{random}.key`` and
|
||||
``K{name}.+157.+{random}.private``, which can be generated by
|
||||
``dnssec-keygen``. The ``-k`` option can also be used to specify a SIG(0)
|
||||
:iscman:`dnssec-keygen`. The :option:`-k` option can also be used to specify a SIG(0)
|
||||
key used to authenticate Dynamic DNS update requests. In this case,
|
||||
the key specified is not an HMAC-MD5 key.
|
||||
|
||||
``-l``
|
||||
.. option:: -l
|
||||
|
||||
This option sets local-host only mode, which sets the server address to localhost
|
||||
(disabling the ``server`` so that the server address cannot be
|
||||
overridden). Connections to the local server use a TSIG key
|
||||
found in ``/var/run/named/session.key``, which is automatically
|
||||
generated by ``named`` if any local ``primary`` zone has set
|
||||
found in |session_key|, which is automatically
|
||||
generated by :iscman:`named` if any local ``primary`` zone has set
|
||||
``update-policy`` to ``local``. The location of this key file can be
|
||||
overridden with the ``-k`` option.
|
||||
overridden with the :option:`-k` option.
|
||||
|
||||
.. option:: -L level
|
||||
|
||||
``-L level``
|
||||
This option sets the logging debug level. If zero, logging is disabled.
|
||||
|
||||
``-p port``
|
||||
.. option:: -o
|
||||
|
||||
This option enables a non-standards-compliant variant of GSS-TSIG
|
||||
used by Windows 2000.
|
||||
|
||||
.. option:: -p port
|
||||
|
||||
This option sets the port to use for connections to a name server. The default is
|
||||
53.
|
||||
|
||||
``-P``
|
||||
.. option:: -P
|
||||
|
||||
This option prints the list of private BIND-specific resource record types whose
|
||||
format is understood by ``nsupdate``. See also the ``-T`` option.
|
||||
format is understood by :program:`nsupdate`. See also the :option:`-T` option.
|
||||
|
||||
.. option:: -r udpretries
|
||||
|
||||
``-r udpretries``
|
||||
This option sets the number of UDP retries. The default is 3. If zero, only one update
|
||||
request is made.
|
||||
|
||||
``-t timeout``
|
||||
.. option:: -t timeout
|
||||
|
||||
This option sets the maximum time an update request can take before it is aborted. The
|
||||
default is 300 seconds. If zero, the timeout is disabled.
|
||||
|
||||
``-T``
|
||||
.. option:: -T
|
||||
|
||||
This option prints the list of IANA standard resource record types whose format is
|
||||
understood by ``nsupdate``. ``nsupdate`` exits after the lists
|
||||
are printed. The ``-T`` option can be combined with the ``-P``
|
||||
understood by :program:`nsupdate`. :program:`nsupdate` exits after the lists
|
||||
are printed. The :option:`-T` option can be combined with the :option:`-P`
|
||||
option.
|
||||
|
||||
Other types can be entered using ``TYPEXXXXX`` where ``XXXXX`` is the
|
||||
@@ -132,21 +155,25 @@ Options
|
||||
present, is parsed using the UNKNOWN rdata format, (<backslash>
|
||||
<hash> <space> <length> <space> <hexstring>).
|
||||
|
||||
``-u udptimeout``
|
||||
.. option:: -u udptimeout
|
||||
|
||||
This option sets the UDP retry interval. The default is 3 seconds. If zero, the
|
||||
interval is computed from the timeout interval and number of UDP
|
||||
retries.
|
||||
|
||||
``-v``
|
||||
This option specifies that TCP should be used even for small update requests. By default, ``nsupdate`` uses
|
||||
.. option:: -v
|
||||
|
||||
This option specifies that TCP should be used even for small update requests. By default, :program:`nsupdate` uses
|
||||
UDP to send update requests to the name server unless they are too
|
||||
large to fit in a UDP request, in which case TCP is used. TCP may
|
||||
be preferable when a batch of update requests is made.
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option prints the version number and exits.
|
||||
|
||||
``-y [hmac:]keyname:secret``
|
||||
.. option:: -y [hmac:]keyname:secret
|
||||
|
||||
This option sets the literal TSIG authentication key. ``keyname`` is the name of the key,
|
||||
and ``secret`` is the base64 encoded shared secret. ``hmac`` is the
|
||||
name of the key algorithm; valid choices are ``hmac-md5``,
|
||||
@@ -154,7 +181,7 @@ Options
|
||||
``hmac-sha512``. If ``hmac`` is not specified, the default is
|
||||
``hmac-md5``, or if MD5 was disabled, ``hmac-sha256``.
|
||||
|
||||
NOTE: Use of the ``-y`` option is discouraged because the shared
|
||||
NOTE: Use of the :option:`-y` option is discouraged because the shared
|
||||
secret is supplied as a command-line argument in clear text. This may
|
||||
be visible in the output from ps1 or in a history file maintained by
|
||||
the user's shell.
|
||||
@@ -162,7 +189,7 @@ Options
|
||||
Input Format
|
||||
~~~~~~~~~~~~
|
||||
|
||||
``nsupdate`` reads input from ``filename`` or standard input. Each
|
||||
:program:`nsupdate` reads input from ``filename`` or standard input. Each
|
||||
command is supplied on exactly one line of input. Some commands are for
|
||||
administrative purposes; others are either update instructions or
|
||||
prerequisite checks on the contents of the zone. These checks set
|
||||
@@ -182,7 +209,7 @@ The command formats and their meanings are as follows:
|
||||
|
||||
``server servername port``
|
||||
This command sends all dynamic update requests to the name server ``servername``.
|
||||
When no server statement is provided, ``nsupdate`` sends updates
|
||||
When no server statement is provided, :program:`nsupdate` sends updates
|
||||
to the primary server of the correct zone. The MNAME field of that
|
||||
zone's SOA record identify the primary server for that zone.
|
||||
``port`` is the port number on ``servername`` where the dynamic
|
||||
@@ -191,14 +218,14 @@ The command formats and their meanings are as follows:
|
||||
|
||||
``local address port``
|
||||
This command sends all dynamic update requests using the local ``address``. When
|
||||
no local statement is provided, ``nsupdate`` sends updates using
|
||||
no local statement is provided, :program:`nsupdate` sends updates using
|
||||
an address and port chosen by the system. ``port`` can also
|
||||
be used to force requests to come from a specific port. If no port number
|
||||
is specified, the system assigns one.
|
||||
|
||||
``zone zonename``
|
||||
This command specifies that all updates are to be made to the zone ``zonename``.
|
||||
If no ``zone`` statement is provided, ``nsupdate`` attempts to
|
||||
If no ``zone`` statement is provided, :program:`nsupdate` attempts to
|
||||
determine the correct zone to update based on the rest of the input.
|
||||
|
||||
``class classname``
|
||||
@@ -214,15 +241,15 @@ The command formats and their meanings are as follows:
|
||||
``keyname``-``secret`` pair. If ``hmac`` is specified, it sets
|
||||
the signing algorithm in use. The default is ``hmac-md5``; if MD5
|
||||
was disabled, the default is ``hmac-sha256``. The ``key`` command overrides any key
|
||||
specified on the command line via ``-y`` or ``-k``.
|
||||
specified on the command line via :option:`-y` or :option:`-k`.
|
||||
|
||||
``gsstsig``
|
||||
This command uses GSS-TSIG to sign the updates. This is equivalent to specifying
|
||||
``-g`` on the command line.
|
||||
:option:`-g` on the command line.
|
||||
|
||||
``oldgsstsig``
|
||||
This command uses the Windows 2000 version of GSS-TSIG to sign the updates. This is
|
||||
equivalent to specifying ``-o`` on the command line.
|
||||
equivalent to specifying :option:`-o` on the command line.
|
||||
|
||||
``realm [realm_name]``
|
||||
When using GSS-TSIG, this command specifies the use of ``realm_name`` rather than the default realm
|
||||
@@ -296,7 +323,7 @@ Lines beginning with a semicolon (;) are comments and are ignored.
|
||||
Examples
|
||||
~~~~~~~~
|
||||
|
||||
The examples below show how ``nsupdate`` can be used to insert and
|
||||
The examples below show how :program:`nsupdate` can be used to insert and
|
||||
delete resource records from the ``example.com`` zone. Notice that the
|
||||
input in each example contains a trailing blank line, so that a group of
|
||||
commands is sent as one dynamic update request to the primary name
|
||||
@@ -335,24 +362,24 @@ Files
|
||||
``/etc/resolv.conf``
|
||||
Used to identify the default name server
|
||||
|
||||
``/var/run/named/session.key``
|
||||
|session_key|
|
||||
Sets the default TSIG key for use in local-only mode
|
||||
|
||||
``K{name}.+157.+{random}.key``
|
||||
Base-64 encoding of the HMAC-MD5 key created by ``dnssec-keygen``.
|
||||
Base-64 encoding of the HMAC-MD5 key created by :iscman:`dnssec-keygen`.
|
||||
|
||||
``K{name}.+157.+{random}.private``
|
||||
Base-64 encoding of the HMAC-MD5 key created by ``dnssec-keygen``.
|
||||
Base-64 encoding of the HMAC-MD5 key created by :iscman:`dnssec-keygen`.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:rfc:`2136`, :rfc:`3007`, :rfc:`2104`, :rfc:`2845`, :rfc:`1034`, :rfc:`2535`, :rfc:`2931`,
|
||||
:manpage:`named(8)`, :manpage:`dnssec-keygen(8)`, :manpage:`tsig-keygen(8)`.
|
||||
:iscman:`named(8) <named>`, :iscman:`dnssec-keygen(8) <dnssec-keygen>`, :iscman:`tsig-keygen(8) <tsig-keygen>`.
|
||||
|
||||
Bugs
|
||||
~~~~
|
||||
|
||||
The TSIG key is redundantly stored in two separate files. This is a
|
||||
consequence of ``nsupdate`` using the DST library for its cryptographic
|
||||
consequence of :program:`nsupdate` using the DST library for its cryptographic
|
||||
operations, and may change in future releases.
|
||||
|
||||
@@ -330,7 +330,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
||||
filter_instance_t *inst = NULL;
|
||||
isc_result_t result;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
|
||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
||||
ISC_LOG_INFO,
|
||||
@@ -347,7 +347,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
cfg_line, mctx, lctx, actx));
|
||||
}
|
||||
|
||||
CHECK(isc_ht_init(&inst->ht, mctx, 16));
|
||||
isc_ht_init(&inst->ht, mctx, 16);
|
||||
isc_mutex_init(&inst->hlock);
|
||||
|
||||
/*
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: filter-a
|
||||
.. _man_filter-a:
|
||||
|
||||
filter-a.so - filter A in DNS responses when AAAA is present
|
||||
@@ -24,14 +25,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``filter-a.so`` is a query plugin module for ``named``, enabling
|
||||
``named`` to omit some IPv4 addresses when responding to clients.
|
||||
:program:`filter-a.so` is a query plugin module for :iscman:`named`, enabling
|
||||
:iscman:`named` to omit some IPv4 addresses when responding to clients.
|
||||
|
||||
For example:
|
||||
|
||||
::
|
||||
|
||||
plugin query "/usr/local/lib/filter-a.so" {
|
||||
plugin query "filter-a.so" {
|
||||
filter-a-on-v6 yes;
|
||||
filter-a-on-v4 yes;
|
||||
filter-a { 192.0.2.1; 2001:db8:2::1; };
|
||||
|
||||
@@ -333,7 +333,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
unsigned long cfg_line, isc_mem_t *mctx, isc_log_t *lctx,
|
||||
void *actx, ns_hooktable_t *hooktable, void **instp) {
|
||||
filter_instance_t *inst = NULL;
|
||||
isc_result_t result;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
|
||||
isc_log_write(lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_HOOKS,
|
||||
ISC_LOG_INFO,
|
||||
@@ -350,7 +350,7 @@ plugin_register(const char *parameters, const void *cfg, const char *cfg_file,
|
||||
cfg_line, mctx, lctx, actx));
|
||||
}
|
||||
|
||||
CHECK(isc_ht_init(&inst->ht, mctx, 16));
|
||||
isc_ht_init(&inst->ht, mctx, 16);
|
||||
isc_mutex_init(&inst->hlock);
|
||||
|
||||
/*
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: filter-aaaa
|
||||
.. _man_filter-aaaa:
|
||||
|
||||
filter-aaaa.so - filter AAAA in DNS responses when A is present
|
||||
@@ -24,18 +25,18 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``filter-aaaa.so`` is a query plugin module for ``named``, enabling
|
||||
``named`` to omit some IPv6 addresses when responding to clients.
|
||||
:program:`filter-aaaa.so` is a query plugin module for :iscman:`named`, enabling
|
||||
:iscman:`named` to omit some IPv6 addresses when responding to clients.
|
||||
|
||||
Until BIND 9.12, this feature was implemented natively in ``named`` and
|
||||
Until BIND 9.12, this feature was implemented natively in :iscman:`named` and
|
||||
enabled with the ``filter-aaaa`` ACL and the ``filter-aaaa-on-v4`` and
|
||||
``filter-aaaa-on-v6`` options. These options are now deprecated in
|
||||
``named.conf`` but can be passed as parameters to the
|
||||
:iscman:`named.conf` but can be passed as parameters to the
|
||||
``filter-aaaa.so`` plugin, for example:
|
||||
|
||||
::
|
||||
|
||||
plugin query "/usr/local/lib/filter-aaaa.so" {
|
||||
plugin query "filter-aaaa.so" {
|
||||
filter-aaaa-on-v4 yes;
|
||||
filter-aaaa-on-v6 yes;
|
||||
filter-aaaa { 192.0.2.1; 2001:db8:2::1; };
|
||||
|
||||
+4
-4
@@ -80,9 +80,9 @@ static isccc_region_t secret;
|
||||
static bool failed = false;
|
||||
static bool c_flag = false;
|
||||
static isc_mem_t *rndc_mctx = NULL;
|
||||
static atomic_uint_fast32_t sends = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t recvs = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t connects = ATOMIC_VAR_INIT(0);
|
||||
static atomic_uint_fast32_t sends = 0;
|
||||
static atomic_uint_fast32_t recvs = 0;
|
||||
static atomic_uint_fast32_t connects = 0;
|
||||
static char *command = NULL;
|
||||
static char *args = NULL;
|
||||
static char program[256];
|
||||
@@ -1029,7 +1029,7 @@ main(int argc, char **argv) {
|
||||
|
||||
isc_mem_create(&rndc_mctx);
|
||||
isc_managers_create(rndc_mctx, 1, 0, &netmgr, &taskmgr, NULL);
|
||||
DO("create task", isc_task_create(taskmgr, 0, &rndc_task));
|
||||
DO("create task", isc_task_create(taskmgr, 0, &rndc_task, 0));
|
||||
isc_log_create(rndc_mctx, &log, &logconfig);
|
||||
isc_log_setcontext(log);
|
||||
isc_log_settag(logconfig, progname);
|
||||
|
||||
+17
-15
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc.conf
|
||||
.. program:: rndc.conf
|
||||
.. _man_rndc.conf:
|
||||
|
||||
rndc.conf - rndc configuration file
|
||||
@@ -24,9 +26,9 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc.conf`` is the configuration file for ``rndc``, the BIND 9 name
|
||||
:program:`rndc.conf` is the configuration file for :iscman:`rndc`, the BIND 9 name
|
||||
server control utility. This file has a similar structure and syntax to
|
||||
``named.conf``. Statements are enclosed in braces and terminated with a
|
||||
:iscman:`named.conf`. Statements are enclosed in braces and terminated with a
|
||||
semi-colon. Clauses in the statements are also semi-colon terminated.
|
||||
The usual comment styles are supported:
|
||||
|
||||
@@ -36,13 +38,13 @@ C++ style: // to end of line
|
||||
|
||||
Unix style: # to end of line
|
||||
|
||||
``rndc.conf`` is much simpler than ``named.conf``. The file uses three
|
||||
:program:`rndc.conf` is much simpler than :iscman:`named.conf`. The file uses three
|
||||
statements: an options statement, a server statement, and a key
|
||||
statement.
|
||||
|
||||
The ``options`` statement contains five clauses. The ``default-server``
|
||||
clause is followed by the name or address of a name server. This host
|
||||
is used when no name server is given as an argument to ``rndc``.
|
||||
is used when no name server is given as an argument to :iscman:`rndc`.
|
||||
The ``default-key`` clause is followed by the name of a key, which is
|
||||
identified by a ``key`` statement. If no ``keyid`` is provided on the
|
||||
rndc command line, and no ``key`` clause is found in a matching
|
||||
@@ -67,14 +69,14 @@ IPv4 and IPv6 source address, respectively.
|
||||
|
||||
The ``key`` statement begins with an identifying string, the name of the
|
||||
key. The statement has two clauses. ``algorithm`` identifies the
|
||||
authentication algorithm for ``rndc`` to use; currently only HMAC-MD5
|
||||
authentication algorithm for :iscman:`rndc` to use; currently only HMAC-MD5
|
||||
(for compatibility), HMAC-SHA1, HMAC-SHA224, HMAC-SHA256 (default),
|
||||
HMAC-SHA384, and HMAC-SHA512 are supported. This is followed by a secret
|
||||
clause which contains the base-64 encoding of the algorithm's
|
||||
authentication key. The base-64 string is enclosed in double quotes.
|
||||
|
||||
There are two common ways to generate the base-64 string for the secret.
|
||||
The BIND 9 program ``rndc-confgen`` can be used to generate a random
|
||||
The BIND 9 program :iscman:`rndc-confgen` can be used to generate a random
|
||||
key, or the ``mmencode`` program, also known as ``mimencode``, can be
|
||||
used to generate a base-64 string from known input. ``mmencode`` does
|
||||
not ship with BIND 9 but is available on many systems. See the Example
|
||||
@@ -118,7 +120,7 @@ Example
|
||||
};
|
||||
|
||||
|
||||
In the above example, ``rndc`` by default uses the server at
|
||||
In the above example, :iscman:`rndc` by default uses the server at
|
||||
localhost (127.0.0.1) and the key called "samplekey". Commands to the
|
||||
localhost server use the "samplekey" key, which must also be defined
|
||||
in the server's configuration file with the same name and secret. The
|
||||
@@ -126,16 +128,16 @@ key statement indicates that "samplekey" uses the HMAC-SHA256 algorithm
|
||||
and its secret clause contains the base-64 encoding of the HMAC-SHA256
|
||||
secret enclosed in double quotes.
|
||||
|
||||
If ``rndc -s testserver`` is used, then ``rndc`` connects to the server
|
||||
If :option:`rndc -s testserver <rndc -s>` is used, then :iscman:`rndc` connects to the server
|
||||
on localhost port 5353 using the key "testkey".
|
||||
|
||||
To generate a random secret with ``rndc-confgen``:
|
||||
To generate a random secret with :iscman:`rndc-confgen`:
|
||||
|
||||
``rndc-confgen``
|
||||
:iscman:`rndc-confgen`
|
||||
|
||||
A complete ``rndc.conf`` file, including the randomly generated key,
|
||||
A complete :program:`rndc.conf` file, including the randomly generated key,
|
||||
is written to the standard output. Commented-out ``key`` and
|
||||
``controls`` statements for ``named.conf`` are also printed.
|
||||
``controls`` statements for :iscman:`named.conf` are also printed.
|
||||
|
||||
To generate a base-64 secret with ``mmencode``:
|
||||
|
||||
@@ -145,12 +147,12 @@ Name Server Configuration
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
The name server must be configured to accept rndc connections and to
|
||||
recognize the key specified in the ``rndc.conf`` file, using the
|
||||
controls statement in ``named.conf``. See the sections on the
|
||||
recognize the key specified in the :program:`rndc.conf` file, using the
|
||||
controls statement in :iscman:`named.conf`. See the sections on the
|
||||
``controls`` statement in the BIND 9 Administrator Reference Manual for
|
||||
details.
|
||||
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc(8)`, :manpage:`rndc-confgen(8)`, :manpage:`mmencode(1)`, BIND 9 Administrator Reference Manual.
|
||||
:iscman:`rndc(8) <rndc>`, :iscman:`rndc-confgen(8) <rndc-confgen>`, :manpage:`mmencode(1)`, BIND 9 Administrator Reference Manual.
|
||||
|
||||
+169
-116
@@ -11,6 +11,8 @@
|
||||
|
||||
.. highlight: console
|
||||
|
||||
.. iscman:: rndc
|
||||
.. program:: rndc
|
||||
.. _man_rndc:
|
||||
|
||||
rndc - name server control utility
|
||||
@@ -24,15 +26,14 @@ Synopsis
|
||||
Description
|
||||
~~~~~~~~~~~
|
||||
|
||||
``rndc`` controls the operation of a name server; it supersedes the
|
||||
``ndc`` utility. If ``rndc`` is
|
||||
:program:`rndc` controls the operation of a name server. If :program:`rndc` is
|
||||
invoked with no command line options or arguments, it prints a short
|
||||
summary of the supported commands and the available options and their
|
||||
arguments.
|
||||
|
||||
``rndc`` communicates with the name server over a TCP connection,
|
||||
:program:`rndc` communicates with the name server over a TCP connection,
|
||||
sending commands authenticated with digital signatures. In the current
|
||||
versions of ``rndc`` and ``named``, the only supported authentication
|
||||
versions of :program:`rndc` and :iscman:`named`, the only supported authentication
|
||||
algorithms are HMAC-MD5 (for compatibility), HMAC-SHA1, HMAC-SHA224,
|
||||
HMAC-SHA256 (default), HMAC-SHA384, and HMAC-SHA512. They use a shared
|
||||
secret on each end of the connection, which provides TSIG-style
|
||||
@@ -40,60 +41,71 @@ authentication for the command request and the name server's response.
|
||||
All commands sent over the channel must be signed by a key_id known to
|
||||
the server.
|
||||
|
||||
``rndc`` reads a configuration file to determine how to contact the name
|
||||
:program:`rndc` reads a configuration file to determine how to contact the name
|
||||
server and decide what algorithm and key it should use.
|
||||
|
||||
Options
|
||||
~~~~~~~
|
||||
|
||||
``-4``
|
||||
.. option:: -4
|
||||
|
||||
This option indicates use of IPv4 only.
|
||||
|
||||
``-6``
|
||||
.. option:: -6
|
||||
|
||||
This option indicates use of IPv6 only.
|
||||
|
||||
``-b source-address``
|
||||
.. option:: -b source-address
|
||||
|
||||
This option indicates ``source-address`` as the source address for the connection to the
|
||||
server. Multiple instances are permitted, to allow setting of both the
|
||||
IPv4 and IPv6 source addresses.
|
||||
|
||||
``-c config-file``
|
||||
.. option:: -c config-file
|
||||
|
||||
This option indicates ``config-file`` as the configuration file instead of the default,
|
||||
``/etc/rndc.conf``.
|
||||
|rndc_conf|.
|
||||
|
||||
.. option:: -k key-file
|
||||
|
||||
``-k key-file``
|
||||
This option indicates ``key-file`` as the key file instead of the default,
|
||||
``/etc/rndc.key``. The key in ``/etc/rndc.key`` is used to
|
||||
|rndc_key|. The key in |rndc_key| is used to
|
||||
authenticate commands sent to the server if the config-file does not
|
||||
exist.
|
||||
|
||||
``-s server``
|
||||
.. option:: -s server
|
||||
|
||||
``server`` is the name or address of the server which matches a server
|
||||
statement in the configuration file for ``rndc``. If no server is
|
||||
statement in the configuration file for :program:`rndc`. If no server is
|
||||
supplied on the command line, the host named by the default-server
|
||||
clause in the options statement of the ``rndc`` configuration file
|
||||
clause in the options statement of the :program:`rndc` configuration file
|
||||
is used.
|
||||
|
||||
``-p port``
|
||||
.. option:: -p port
|
||||
|
||||
This option instructs BIND 9 to send commands to TCP port ``port`` instead of its default control
|
||||
channel port, 953.
|
||||
|
||||
``-q``
|
||||
.. option:: -q
|
||||
|
||||
This option sets quiet mode, where message text returned by the server is not printed
|
||||
unless there is an error.
|
||||
|
||||
``-r``
|
||||
This option instructs ``rndc`` to print the result code returned by ``named``
|
||||
.. option:: -r
|
||||
|
||||
This option instructs :program:`rndc` to print the result code returned by :iscman:`named`
|
||||
after executing the requested command (e.g., ISC_R_SUCCESS,
|
||||
ISC_R_FAILURE, etc.).
|
||||
|
||||
``-V``
|
||||
.. option:: -V
|
||||
|
||||
This option enables verbose logging.
|
||||
|
||||
``-y key_id``
|
||||
.. option:: -y key_id
|
||||
|
||||
This option indicates use of the key ``key_id`` from the configuration file. For control message validation to succeed, ``key_id`` must be known
|
||||
by ``named`` with the same algorithm and secret string. If no ``key_id`` is specified,
|
||||
``rndc`` first looks for a key clause in the server statement of
|
||||
by :iscman:`named` with the same algorithm and secret string. If no ``key_id`` is specified,
|
||||
:program:`rndc` first looks for a key clause in the server statement of
|
||||
the server being used, or if no server statement is present for that
|
||||
host, then in the default-key clause of the options statement. Note that
|
||||
the configuration file contains shared secrets which are used to send
|
||||
@@ -103,23 +115,24 @@ Options
|
||||
Commands
|
||||
~~~~~~~~
|
||||
|
||||
A list of commands supported by ``rndc`` can be seen by running ``rndc``
|
||||
A list of commands supported by :program:`rndc` can be seen by running :program:`rndc`
|
||||
without arguments.
|
||||
|
||||
Currently supported commands are:
|
||||
|
||||
``addzone`` *zone* [*class* [*view*]] *configuration*
|
||||
.. option:: addzone zone [class [view]] configuration
|
||||
|
||||
This command adds a zone while the server is running. This command requires the
|
||||
``allow-new-zones`` option to be set to ``yes``. The configuration
|
||||
string specified on the command line is the zone configuration text
|
||||
that would ordinarily be placed in ``named.conf``.
|
||||
that would ordinarily be placed in :iscman:`named.conf`.
|
||||
|
||||
The configuration is saved in a file called ``viewname.nzf`` (or, if
|
||||
``named`` is compiled with liblmdb, an LMDB database file called
|
||||
:iscman:`named` is compiled with liblmdb, an LMDB database file called
|
||||
``viewname.nzd``). ``viewname`` is the name of the view, unless the view
|
||||
name contains characters that are incompatible with use as a file
|
||||
name, in which case a cryptographic hash of the view name is used
|
||||
instead. When ``named`` is restarted, the file is loaded into
|
||||
instead. When :iscman:`named` is restarted, the file is loaded into
|
||||
the view configuration so that zones that were added can persist
|
||||
after a restart.
|
||||
|
||||
@@ -131,9 +144,10 @@ Currently supported commands are:
|
||||
(Note the brackets around and semi-colon after the zone configuration
|
||||
text.)
|
||||
|
||||
See also ``rndc delzone`` and ``rndc modzone``.
|
||||
See also :option:`rndc delzone` and :option:`rndc modzone`.
|
||||
|
||||
.. option:: delzone [-clean] zone [class [view]]
|
||||
|
||||
``delzone`` [**-clean**] *zone* [*class* [*view*]]
|
||||
This command deletes a zone while the server is running.
|
||||
|
||||
If the ``-clean`` argument is specified, the zone's master file (and
|
||||
@@ -144,14 +158,15 @@ Currently supported commands are:
|
||||
|
||||
If the zone was originally added via ``rndc addzone``, then it is
|
||||
removed permanently. However, if it was originally configured in
|
||||
``named.conf``, then that original configuration remains in place;
|
||||
:iscman:`named.conf`, then that original configuration remains in place;
|
||||
when the server is restarted or reconfigured, the zone is
|
||||
recreated. To remove it permanently, it must also be removed from
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
See also ``rndc addzone`` and ``rndc modzone``.
|
||||
See also :option:`rndc addzone` and :option:`rndc modzone`.
|
||||
|
||||
.. option:: dnssec (-status | -rollover -key id [-alg algorithm] [-when time] | -checkds [-key id [-alg algorithm]] [-when time] published | withdraw)) zone [class [view]]
|
||||
|
||||
``dnssec`` ( **-status** | **-rollover** **-key** id [**-alg** *algorithm*] [**-when** *time*] | **-checkds** [**-key** *id* [**-alg** *algorithm*]] [**-when** *time*] ( *published* | *withdrawn* )) *zone* [*class* [*view*]]
|
||||
This command allows you to interact with the "dnssec-policy" of a given
|
||||
zone.
|
||||
|
||||
@@ -161,7 +176,7 @@ Currently supported commands are:
|
||||
``rndc dnssec -rollover`` allows you to schedule key rollover for a
|
||||
specific key (overriding the original key lifetime).
|
||||
|
||||
``rndc dnssec -checkds`` will let ``named`` know that the DS for the given
|
||||
``rndc dnssec -checkds`` will let :iscman:`named` know that the DS for the given
|
||||
key has been seen published into or withdrawn from the parent. This is
|
||||
required in order to complete a KSK rollover. If the ``-key id`` argument
|
||||
is specified, look for the key with the given identifier, otherwise if there
|
||||
@@ -170,56 +185,64 @@ Currently supported commands are:
|
||||
select the correct algorithm). The time that the DS has been published or
|
||||
withdrawn is set to now, unless otherwise specified with the argument ``-when time``.
|
||||
|
||||
``dnstap`` ( **-reopen** | **-roll** [*number*] )
|
||||
.. option:: dnstap (-reopen | -roll [number])
|
||||
|
||||
This command closes and re-opens DNSTAP output files. ``rndc dnstap -reopen`` allows
|
||||
the output file to be renamed externally, so that ``named`` can
|
||||
the output file to be renamed externally, so that :iscman:`named` can
|
||||
truncate and re-open it. ``rndc dnstap -roll`` causes the output file
|
||||
to be rolled automatically, similar to log files. The most recent
|
||||
output file has ".0" appended to its name; the previous most recent
|
||||
output file is moved to ".1", and so on. If ``number`` is specified, then
|
||||
the number of backup log files is limited to that number.
|
||||
|
||||
``dumpdb`` [**-all** | **-cache** | **-zones** | **-adb** | **-bad** | **-expired** | **-fail**] [*view ...*]
|
||||
.. option:: dumpdb [-all | -cache | -zones | -adb | -bad | -expired | -fail] [view ...]
|
||||
|
||||
This command dumps the server's caches (default) and/or zones to the dump file for
|
||||
the specified views. If no view is specified, all views are dumped.
|
||||
(See the ``dump-file`` option in the BIND 9 Administrator Reference
|
||||
Manual.)
|
||||
|
||||
``flush``
|
||||
.. option:: flush
|
||||
|
||||
This command flushes the server's cache.
|
||||
|
||||
``flushname`` *name* [*view*]
|
||||
.. option:: flushname name [view]
|
||||
|
||||
This command flushes the given name from the view's DNS cache and, if applicable,
|
||||
from the view's nameserver address database, bad server cache, and
|
||||
SERVFAIL cache.
|
||||
|
||||
``flushtree`` *name* [*view*]
|
||||
.. option:: flushtree name [view]
|
||||
|
||||
This command flushes the given name, and all of its subdomains, from the view's
|
||||
DNS cache, address database, bad server cache, and SERVFAIL cache.
|
||||
|
||||
``freeze`` [*zone* [*class* [*view*]]]
|
||||
.. option:: freeze [zone [class [view]]]
|
||||
|
||||
This command suspends updates to a dynamic zone. If no zone is specified, then all
|
||||
zones are suspended. This allows manual edits to be made to a zone
|
||||
normally updated by dynamic update, and causes changes in the
|
||||
journal file to be synced into the master file. All dynamic update
|
||||
attempts are refused while the zone is frozen.
|
||||
|
||||
See also ``rndc thaw``.
|
||||
See also :option:`rndc thaw`.
|
||||
|
||||
.. option:: halt [-p]
|
||||
|
||||
``halt`` [**-p**]
|
||||
This command stops the server immediately. Recent changes made through dynamic
|
||||
update or IXFR are not saved to the master files, but are rolled
|
||||
forward from the journal files when the server is restarted. If
|
||||
``-p`` is specified, ``named``'s process ID is returned. This allows
|
||||
an external process to determine when ``named`` has completed
|
||||
``-p`` is specified, :iscman:`named`'s process ID is returned. This allows
|
||||
an external process to determine when :iscman:`named` has completed
|
||||
halting.
|
||||
|
||||
See also ``rndc stop``.
|
||||
See also :option:`rndc stop`.
|
||||
|
||||
.. option:: loadkeys [zone [class [view]]]
|
||||
|
||||
``loadkeys`` [*zone* [*class* [*view*]]]
|
||||
This command fetches all DNSSEC keys for the given zone from the key directory. If
|
||||
they are within their publication period, they are merged into the
|
||||
zone's DNSKEY RRset. Unlike ``rndc sign``, however, the zone is not
|
||||
zone's DNSKEY RRset. Unlike :option:`rndc sign`, however, the zone is not
|
||||
immediately re-signed by the new keys, but is allowed to
|
||||
incrementally re-sign over time.
|
||||
|
||||
@@ -228,7 +251,8 @@ Currently supported commands are:
|
||||
zone to be configured to allow dynamic DNS. (See "Dynamic Update Policies" in
|
||||
the Administrator Reference Manual for more details.)
|
||||
|
||||
``managed-keys`` (*status* | *refresh* | *sync* | *destroy*) [*class* [*view*]]
|
||||
.. option:: managed-keys (status | refresh | sync | destroy) [class [view]]
|
||||
|
||||
This command inspects and controls the "managed-keys" database which handles
|
||||
:rfc:`5011` DNSSEC trust anchor maintenance. If a view is specified, these
|
||||
commands are applied to that view; otherwise, they are applied to all
|
||||
@@ -254,11 +278,11 @@ Currently supported commands are:
|
||||
|
||||
Existing keys that are already trusted are not deleted from
|
||||
memory; DNSSEC validation can continue after this command is used.
|
||||
However, key maintenance operations cease until ``named`` is
|
||||
However, key maintenance operations cease until :iscman:`named` is
|
||||
restarted or reconfigured, and all existing key maintenance states
|
||||
are deleted.
|
||||
|
||||
Running ``rndc reconfig`` or restarting ``named`` immediately
|
||||
Running :option:`rndc reconfig` or restarting :iscman:`named` immediately
|
||||
after this command causes key maintenance to be reinitialized
|
||||
from scratch, just as if the server were being started for the
|
||||
first time. This is primarily intended for testing, but it may
|
||||
@@ -266,47 +290,51 @@ Currently supported commands are:
|
||||
keys in the event of a trust anchor rollover, or as a brute-force
|
||||
repair for key maintenance problems.
|
||||
|
||||
``modzone`` *zone* [*class* [*view*]] *configuration*
|
||||
.. option:: modzone zone [class [view]] configuration
|
||||
|
||||
This command modifies the configuration of a zone while the server is running. This
|
||||
command requires the ``allow-new-zones`` option to be set to ``yes``.
|
||||
As with ``addzone``, the configuration string specified on the
|
||||
command line is the zone configuration text that would ordinarily be
|
||||
placed in ``named.conf``.
|
||||
placed in :iscman:`named.conf`.
|
||||
|
||||
If the zone was originally added via ``rndc addzone``, the
|
||||
If the zone was originally added via :option:`rndc addzone`, the
|
||||
configuration changes are recorded permanently and are still
|
||||
in effect after the server is restarted or reconfigured. However, if
|
||||
it was originally configured in ``named.conf``, then that original
|
||||
it was originally configured in :iscman:`named.conf`, then that original
|
||||
configuration remains in place; when the server is restarted or
|
||||
reconfigured, the zone reverts to its original configuration. To
|
||||
make the changes permanent, it must also be modified in
|
||||
``named.conf``.
|
||||
:iscman:`named.conf`.
|
||||
|
||||
See also ``rndc addzone`` and ``rndc delzone``.
|
||||
See also :option:`rndc addzone` and :option:`rndc delzone`.
|
||||
|
||||
.. option:: notify zone [class [view]]
|
||||
|
||||
``notify`` *zone* [*class* [*view*]]
|
||||
This command resends NOTIFY messages for the zone.
|
||||
|
||||
``notrace``
|
||||
.. option:: notrace
|
||||
|
||||
This command sets the server's debugging level to 0.
|
||||
|
||||
See also ``rndc trace``.
|
||||
See also :option:`rndc trace`.
|
||||
|
||||
.. option:: nta [(-class class | -dump | -force | -remove | -lifetime duration)] domain [view]
|
||||
|
||||
``nta`` [( **-class** *class* | **-dump** | **-force** | **-remove** | **-lifetime** *duration*)] *domain* [*view*]
|
||||
This command sets a DNSSEC negative trust anchor (NTA) for ``domain``, with a
|
||||
lifetime of ``duration``. The default lifetime is configured in
|
||||
``named.conf`` via the ``nta-lifetime`` option, and defaults to one
|
||||
:iscman:`named.conf` via the ``nta-lifetime`` option, and defaults to one
|
||||
hour. The lifetime cannot exceed one week.
|
||||
|
||||
A negative trust anchor selectively disables DNSSEC validation for
|
||||
zones that are known to be failing because of misconfiguration rather
|
||||
than an attack. When data to be validated is at or below an active
|
||||
NTA (and above any other configured trust anchors), ``named``
|
||||
NTA (and above any other configured trust anchors), :iscman:`named`
|
||||
aborts the DNSSEC validation process and treats the data as insecure
|
||||
rather than bogus. This continues until the NTA's lifetime has
|
||||
elapsed.
|
||||
|
||||
NTAs persist across restarts of the ``named`` server. The NTAs for a
|
||||
NTAs persist across restarts of the :iscman:`named` server. The NTAs for a
|
||||
view are saved in a file called ``name.nta``, where ``name`` is the name
|
||||
of the view; if it contains characters that are incompatible with
|
||||
use as a file name, a cryptographic hash is generated from the name of
|
||||
@@ -324,7 +352,7 @@ Currently supported commands are:
|
||||
of existing NTAs is printed. Note that this may include NTAs that are
|
||||
expired but have not yet been cleaned up.
|
||||
|
||||
Normally, ``named`` periodically tests to see whether data below
|
||||
Normally, :iscman:`named` periodically tests to see whether data below
|
||||
an NTA can now be validated (see the ``nta-recheck`` option in the
|
||||
Administrator Reference Manual for details). If data can be
|
||||
validated, then the NTA is regarded as no longer necessary and is
|
||||
@@ -343,24 +371,27 @@ Currently supported commands are:
|
||||
view name that begins with a hyphen, use a double-hyphen (--) on the
|
||||
command line to indicate the end of options.
|
||||
|
||||
``querylog`` [(*on* | *off*)]
|
||||
.. option:: querylog [(on | off)]
|
||||
|
||||
This command enables or disables query logging. For backward compatibility, this
|
||||
command can also be used without an argument to toggle query logging
|
||||
on and off.
|
||||
|
||||
Query logging can also be enabled by explicitly directing the
|
||||
``queries`` ``category`` to a ``channel`` in the ``logging`` section
|
||||
of ``named.conf``, or by specifying ``querylog yes;`` in the
|
||||
``options`` section of ``named.conf``.
|
||||
of :iscman:`named.conf`, or by specifying ``querylog yes;`` in the
|
||||
``options`` section of :iscman:`named.conf`.
|
||||
|
||||
.. option:: reconfig
|
||||
|
||||
``reconfig``
|
||||
This command reloads the configuration file and loads new zones, but does not reload
|
||||
existing zone files even if they have changed. This is faster than a
|
||||
full ``reload`` when there is a large number of zones, because it
|
||||
full :option:`rndc reload` when there is a large number of zones, because it
|
||||
avoids the need to examine the modification times of the zone files.
|
||||
|
||||
``recursing``
|
||||
This command dumps the list of queries ``named`` is currently
|
||||
.. option:: recursing
|
||||
|
||||
This command dumps the list of queries :iscman:`named` is currently
|
||||
recursing on, and the list of domains to which iterative queries
|
||||
are currently being sent.
|
||||
|
||||
@@ -379,16 +410,20 @@ Currently supported commands are:
|
||||
and the next time a fetch is sent to that domain, it is recreated
|
||||
with the counters set to zero).
|
||||
|
||||
``refresh`` *zone* [*class* [*view*]]
|
||||
.. option:: refresh zone [class [view]]
|
||||
|
||||
This command schedules zone maintenance for the given zone.
|
||||
|
||||
``reload``
|
||||
.. option:: reload
|
||||
|
||||
This command reloads the configuration file and zones.
|
||||
|
||||
``reload`` *zone* [*class* [*view*]]
|
||||
.. option:: reload zone [class [view]]
|
||||
|
||||
This command reloads the given zone.
|
||||
|
||||
``retransfer`` *zone* [*class* [*view*]]
|
||||
.. option:: retransfer zone [class [view]]
|
||||
|
||||
This command retransfers the given secondary zone from the primary server.
|
||||
|
||||
If the zone is configured to use ``inline-signing``, the signed
|
||||
@@ -396,12 +431,14 @@ Currently supported commands are:
|
||||
unsigned version is complete, the signed version is regenerated
|
||||
with new signatures.
|
||||
|
||||
``scan``
|
||||
.. option:: scan
|
||||
|
||||
This command scans the list of available network interfaces for changes, without
|
||||
performing a full ``reconfig`` or waiting for the
|
||||
performing a full :option:`rndc reconfig` or waiting for the
|
||||
``interface-interval`` timer.
|
||||
|
||||
``secroots`` [**-**] [*view* ...]
|
||||
.. option:: secroots [-] [view ...]
|
||||
|
||||
This command dumps the security roots (i.e., trust anchors configured via
|
||||
``trust-anchors``, or the ``managed-keys`` or ``trusted-keys`` statements
|
||||
[both deprecated], or ``dnssec-validation auto``) and negative trust anchors
|
||||
@@ -411,31 +448,34 @@ Currently supported commands are:
|
||||
yet been updated by a successful key refresh query).
|
||||
|
||||
If the first argument is ``-``, then the output is returned via the
|
||||
``rndc`` response channel and printed to the standard output.
|
||||
:program:`rndc` response channel and printed to the standard output.
|
||||
Otherwise, it is written to the secroots dump file, which defaults to
|
||||
``named.secroots``, but can be overridden via the ``secroots-file``
|
||||
option in ``named.conf``.
|
||||
option in :iscman:`named.conf`.
|
||||
|
||||
See also ``rndc managed-keys``.
|
||||
See also :option:`rndc managed-keys`.
|
||||
|
||||
.. option:: serve-stale (on | off | reset | status) [class [view]]
|
||||
|
||||
``serve-stale`` (**on** | **off** | **reset** | **status**) [*class* [*view*]]
|
||||
This command enables, disables, resets, or reports the current status of
|
||||
the serving of stale answers as configured in ``named.conf``.
|
||||
the serving of stale answers as configured in :iscman:`named.conf`.
|
||||
|
||||
If serving of stale answers is disabled by ``rndc-serve-stale off``, then it
|
||||
remains disabled even if ``named`` is reloaded or reconfigured. ``rndc
|
||||
serve-stale reset`` restores the setting as configured in ``named.conf``.
|
||||
remains disabled even if :iscman:`named` is reloaded or reconfigured. ``rndc
|
||||
serve-stale reset`` restores the setting as configured in :iscman:`named.conf`.
|
||||
|
||||
``rndc serve-stale status`` reports whether caching and serving of stale
|
||||
answers is currently enabled or disabled. It also reports the values of
|
||||
``stale-answer-ttl`` and ``max-stale-ttl``.
|
||||
|
||||
``showzone`` *zone* [*class* [*view*]]
|
||||
.. option:: showzone zone [class [view]]
|
||||
|
||||
This command prints the configuration of a running zone.
|
||||
|
||||
See also ``rndc zonestatus``.
|
||||
See also :option:`rndc zonestatus`.
|
||||
|
||||
.. option:: sign zone [class [view]]
|
||||
|
||||
``sign`` *zone* [*class* [*view*]]
|
||||
This command fetches all DNSSEC keys for the given zone from the key directory (see
|
||||
the ``key-directory`` option in the BIND 9 Administrator Reference
|
||||
Manual). If they are within their publication period, they are merged into
|
||||
@@ -448,9 +488,10 @@ Currently supported commands are:
|
||||
"Dynamic Update Policies" in the BIND 9 Administrator Reference Manual for more
|
||||
details.)
|
||||
|
||||
See also ``rndc loadkeys``.
|
||||
See also :option:`rndc loadkeys`.
|
||||
|
||||
.. option:: signing [(-list | -clear keyid/algorithm | -clear all | -nsec3param (parameters | none) | -serial value) zone [class [view]]
|
||||
|
||||
``signing`` [(**-list** | **-clear** *keyid/algorithm* | **-clear** *all* | **-nsec3param** ( *parameters* | none ) | **-serial** *value* ) *zone* [*class* [*view*]]
|
||||
This command lists, edits, or removes the DNSSEC signing-state records for the
|
||||
specified zone. The status of ongoing DNSSEC operations, such as
|
||||
signing or generating NSEC3 chains, is stored in the zone in the form
|
||||
@@ -478,7 +519,7 @@ Currently supported commands are:
|
||||
chain should be set. ``iterations`` defines the number of additional times to apply
|
||||
the algorithm when generating an NSEC3 hash. The ``salt`` is a string
|
||||
of data expressed in hexadecimal, a hyphen (`-') if no salt is to be
|
||||
used, or the keyword ``auto``, which causes ``named`` to generate a
|
||||
used, or the keyword ``auto``, which causes :iscman:`named` to generate a
|
||||
random 64-bit salt.
|
||||
|
||||
So, for example, to create an NSEC3 chain using the SHA-1 hash
|
||||
@@ -495,31 +536,36 @@ Currently supported commands are:
|
||||
is rejected. The primary use of this parameter is to set the serial number on inline
|
||||
signed zones.
|
||||
|
||||
``stats``
|
||||
.. option:: stats
|
||||
|
||||
This command writes server statistics to the statistics file. (See the
|
||||
``statistics-file`` option in the BIND 9 Administrator Reference
|
||||
Manual.)
|
||||
|
||||
``status``
|
||||
.. option:: status
|
||||
|
||||
This command displays the status of the server. Note that the number of zones includes
|
||||
the internal ``bind/CH`` zone and the default ``./IN`` hint zone, if
|
||||
there is no explicit root zone configured.
|
||||
|
||||
``stop`` **-p**
|
||||
.. option:: stop -p
|
||||
|
||||
This command stops the server, making sure any recent changes made through dynamic
|
||||
update or IXFR are first saved to the master files of the updated
|
||||
zones. If ``-p`` is specified, ``named(8)`'s process ID is returned.
|
||||
This allows an external process to determine when ``named`` has
|
||||
zones. If ``-p`` is specified, :iscman:`named`'s process ID is returned.
|
||||
This allows an external process to determine when :iscman:`named` has
|
||||
completed stopping.
|
||||
|
||||
See also ``rndc halt``.
|
||||
See also :option:`rndc halt`.
|
||||
|
||||
.. option:: sync -clean [zone [class [view]]]
|
||||
|
||||
``sync`` **-clean** [*zone* [*class* [*view*]]]
|
||||
This command syncs changes in the journal file for a dynamic zone to the master
|
||||
file. If the "-clean" option is specified, the journal file is also
|
||||
removed. If no zone is specified, then all zones are synced.
|
||||
|
||||
``tcp-timeouts`` [*initial* *idle* *keepalive* *advertised*]
|
||||
.. option:: tcp-timeouts [initial idle keepalive advertised]
|
||||
|
||||
When called without arguments, this command displays the current values of the
|
||||
``tcp-initial-timeout``, ``tcp-idle-timeout``,
|
||||
``tcp-keepalive-timeout``, and ``tcp-advertised-timeout`` options.
|
||||
@@ -528,7 +574,8 @@ Currently supported commands are:
|
||||
denial-of-service (DoS) attack. See the descriptions of these options in the BIND 9
|
||||
Administrator Reference Manual for details of their use.
|
||||
|
||||
``thaw`` [*zone* [*class* [*view*]]]
|
||||
.. option:: thaw [zone [class [view]]]
|
||||
|
||||
This command enables updates to a frozen dynamic zone. If no zone is specified,
|
||||
then all frozen zones are enabled. This causes the server to reload
|
||||
the zone from disk, and re-enables dynamic updates after the load has
|
||||
@@ -538,33 +585,39 @@ Currently supported commands are:
|
||||
changes in the zone. Otherwise, if the zone has changed, any existing
|
||||
journal file is removed.
|
||||
|
||||
See also ``rndc freeze``.
|
||||
See also :option:`rndc freeze`.
|
||||
|
||||
.. option:: trace
|
||||
|
||||
``trace``
|
||||
This command increments the server's debugging level by one.
|
||||
|
||||
``trace`` *level*
|
||||
.. option:: trace level
|
||||
|
||||
This command sets the server's debugging level to an explicit value.
|
||||
|
||||
See also ``rndc notrace``.
|
||||
See also :option:`rndc notrace`.
|
||||
|
||||
.. option:: tsig-delete keyname [view]
|
||||
|
||||
``tsig-delete`` *keyname* [*view*]
|
||||
This command deletes a given TKEY-negotiated key from the server. This does not
|
||||
apply to statically configured TSIG keys.
|
||||
|
||||
``tsig-list``
|
||||
.. option:: tsig-list
|
||||
|
||||
This command lists the names of all TSIG keys currently configured for use by
|
||||
``named`` in each view. The list includes both statically configured keys and
|
||||
:iscman:`named` in each view. The list includes both statically configured keys and
|
||||
dynamic TKEY-negotiated keys.
|
||||
|
||||
``validation`` (**on** | **off** | **status**) [*view* ...]``
|
||||
.. option:: validation (on | off | status) [view ...]
|
||||
|
||||
This command enables, disables, or checks the current status of DNSSEC validation. By
|
||||
default, validation is enabled.
|
||||
|
||||
The cache is flushed when validation is turned on or off to avoid using data
|
||||
that might differ between states.
|
||||
|
||||
``zonestatus`` *zone* [*class* [*view*]]
|
||||
.. option:: zonestatus zone [class [view]]
|
||||
|
||||
This command displays the current status of the given zone, including the master
|
||||
file name and any include files from which it was loaded, when it was
|
||||
most recently loaded, the current serial number, the number of nodes,
|
||||
@@ -572,10 +625,10 @@ Currently supported commands are:
|
||||
signed, whether it uses automatic DNSSEC key management or inline
|
||||
signing, and the scheduled refresh or expiry times for the zone.
|
||||
|
||||
See also ``rndc showzone``.
|
||||
See also :option:`rndc showzone`.
|
||||
|
||||
``rndc`` commands that specify zone names, such as ``reload``,
|
||||
``retransfer``, or ``zonestatus``, can be ambiguous when applied to zones
|
||||
:program:`rndc` commands that specify zone names, such as :option:`reload`
|
||||
:option:`retransfer`, or :option:`zonestatus`, can be ambiguous when applied to zones
|
||||
of type ``redirect``. Redirect zones are always called ``.``, and can be
|
||||
confused with zones of type ``hint`` or with secondary copies of the root
|
||||
zone. To specify a redirect zone, use the special zone name
|
||||
@@ -593,6 +646,6 @@ Several error messages could be clearer.
|
||||
See Also
|
||||
~~~~~~~~
|
||||
|
||||
:manpage:`rndc.conf(5)`, :manpage:`rndc-confgen(8)`,
|
||||
:manpage:`named(8)`, :manpage:`named.conf(5)`, :manpage:`ndc(8)`, BIND 9 Administrator
|
||||
:iscman:`rndc.conf(5) <rndc.conf>`, :iscman:`rndc-confgen(8) <rndc-confgen>`,
|
||||
:iscman:`named(8) <named>`, :iscman:`named.conf(5) <named.conf>`, BIND 9 Administrator
|
||||
Reference Manual.
|
||||
|
||||
@@ -7,6 +7,9 @@ noinst_PROGRAMS = \
|
||||
test_server \
|
||||
wire_test
|
||||
|
||||
AM_CFLAGS += \
|
||||
$(TEST_CFLAGS)
|
||||
|
||||
test_client_CPPFLAGS = \
|
||||
$(AM_CPPFLAGS) \
|
||||
$(LIBISC_CFLAGS)
|
||||
@@ -31,5 +34,3 @@ wire_test_CPPFLAGS = \
|
||||
wire_test_LDADD = \
|
||||
$(LIBISC_LIBS) \
|
||||
$(LIBDNS_LIBS)
|
||||
|
||||
EXTRA_DIST = prepare-softhsm2.sh
|
||||
|
||||
@@ -1,22 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
if [ -n "${SOFTHSM2_CONF}" ] && command -v softhsm2-util >/dev/null; then
|
||||
SOFTHSM2_DIR=$(dirname "$SOFTHSM2_CONF")
|
||||
mkdir -p "${SOFTHSM2_DIR}/tokens"
|
||||
echo "directories.tokendir = ${SOFTHSM2_DIR}/tokens" > "${SOFTHSM2_CONF}"
|
||||
echo "objectstore.backend = file" >> "${SOFTHSM2_CONF}"
|
||||
echo "log.level = DEBUG" >> "${SOFTHSM2_CONF}"
|
||||
softhsm2-util --init-token --free --pin 1234 --so-pin 1234 --label "softhsm2" | awk '/^The token has been initialized and is reassigned to slot/ { print $NF }'
|
||||
fi
|
||||
exit 0
|
||||
@@ -8,11 +8,8 @@ named.lock
|
||||
named.pid
|
||||
named.run
|
||||
/feature-test
|
||||
/test.output.*
|
||||
/makejournal
|
||||
/systests.output
|
||||
/random.data
|
||||
parallel.mk
|
||||
/*.log
|
||||
/*.trs
|
||||
/resolve
|
||||
|
||||
@@ -114,6 +114,7 @@ TESTS += \
|
||||
eddsa \
|
||||
ednscompliance \
|
||||
emptyzones \
|
||||
engine_pkcs11 \
|
||||
filter-aaaa \
|
||||
formerr \
|
||||
geoip2 \
|
||||
@@ -125,6 +126,7 @@ TESTS += \
|
||||
hooks \
|
||||
journal \
|
||||
keepalive \
|
||||
keyfromlabel \
|
||||
legacy \
|
||||
limits \
|
||||
logfileconfig \
|
||||
@@ -212,20 +214,18 @@ endif HAVE_PERLMOD_NET_DNS
|
||||
if HAVE_PYTHON
|
||||
TESTS += kasp keymgr2kasp tcp pipelined
|
||||
|
||||
if HAVE_PYMOD_DNS
|
||||
TESTS += checkds dispatch qmin cookie timeouts
|
||||
if HAVE_PYTEST
|
||||
TESTS += checkds dispatch rpzextra shutdown timeouts
|
||||
endif
|
||||
|
||||
if HAVE_PYMOD_DNS
|
||||
TESTS += qmin cookie
|
||||
if HAVE_PERLMOD_NET_DNS
|
||||
TESTS += dnssec
|
||||
if HAVE_PERLMOD_NET_DNS_NAMESERVER
|
||||
TESTS += chain
|
||||
endif HAVE_PERLMOD_NET_DNS_NAMESERVER
|
||||
endif HAVE_PERLMOD_NET_DNS
|
||||
|
||||
if HAVE_PYTEST
|
||||
TESTS += rpzextra shutdown
|
||||
endif
|
||||
|
||||
endif HAVE_PYMOD_DNS
|
||||
|
||||
endif HAVE_PYTHON
|
||||
|
||||
+11
-77
@@ -117,13 +117,7 @@ Running All The System Tests
|
||||
---
|
||||
To run all the system tests, enter the command:
|
||||
|
||||
sh runall.sh [-c] [-n] [numproc]
|
||||
|
||||
The optional flag "-c" forces colored output (by default system test output is
|
||||
not printed in color due to run.sh being piped through "tee").
|
||||
|
||||
The optional flag "-n" has the same effect as it does for "run.sh" - it causes
|
||||
the retention of all output files from all tests.
|
||||
make [-j numproc] test
|
||||
|
||||
The optional "numproc" argument specifies the maximum number of tests that can
|
||||
run in parallel. The default is 1, which means that all of the tests run
|
||||
@@ -132,16 +126,7 @@ new tests being started as tests finish. Each test will get a unique set of
|
||||
ports, so there is no danger of tests interfering with one another. Parallel
|
||||
running will reduce the total time taken to run the BIND system tests, but will
|
||||
mean that the output from all the tests sent to the screen will be mixed up
|
||||
with one another. However, the systests.output file produced at the end of the
|
||||
run (in the bin/tests/system directory) will contain the output from each test
|
||||
in sequential order.
|
||||
|
||||
Note that it is not possible to pass arguments to tests though the "runall.sh"
|
||||
script.
|
||||
|
||||
A run of all the system tests can also be initiated via make:
|
||||
|
||||
make [-j numproc] test
|
||||
with one another.
|
||||
|
||||
In this case, retention of the output files after a test completes successfully
|
||||
is specified by setting the environment variable SYSTEMTEST_NO_CLEAN to 1 prior
|
||||
@@ -153,38 +138,6 @@ while setting environment variable SYSTEMTEST_FORCE_COLOR to 1 forces system
|
||||
test output to be printed in color.
|
||||
|
||||
|
||||
Running Multiple System Test Suites Simultaneously
|
||||
---
|
||||
In some cases it may be desirable to have multiple instances of the system test
|
||||
suite running simultaneously (e.g. from different terminal windows). To do
|
||||
this:
|
||||
|
||||
1. Each installation must have its own directory tree. The system tests create
|
||||
files in the test directories, so separate directory trees are required to
|
||||
avoid interference between the same test running in the different
|
||||
installations.
|
||||
|
||||
2. For one of the test suites, the starting port number must be specified by
|
||||
setting the environment variable STARTPORT before starting the test suite.
|
||||
Each test suite comprises about 100 tests, each being allocated a set of 100
|
||||
ports. The port ranges for each test are allocated sequentially, so each test
|
||||
suite requires about 10,000 ports to itself. By default, the port allocation
|
||||
starts at 5,000. So the following set of commands:
|
||||
|
||||
Terminal Window 1:
|
||||
cd <installation-1>/bin/tests/system
|
||||
sh runall.sh 4
|
||||
|
||||
Terminal Window 2:
|
||||
cd <installation-2>/bin/tests/system
|
||||
STARTPORT=20000 sh runall.sh 4
|
||||
|
||||
... will start the test suite for installation-1 using the default base port
|
||||
of 5,000, so the test suite will use ports 5,000 through 15,000 (or there
|
||||
abouts). The use of "STARTPORT=20000" to prefix the run of the test suite for
|
||||
installation-2 will mean the test suite uses ports 20,000 through 30,000 or so.
|
||||
|
||||
|
||||
Format of Test Output
|
||||
---
|
||||
All output from the system tests is in the form of lines with the following
|
||||
@@ -247,8 +200,8 @@ deleted if the test succeeds but are retained on error. The run.sh script
|
||||
automatically calls a given test's clean.sh script before invoking its setup.sh
|
||||
script.
|
||||
|
||||
Deletion of the files produced by the set of tests (e.g. after the execution
|
||||
of "runall.sh") can be carried out using the command:
|
||||
Deletion of the files produced by the set of tests (e.g. after the execution of
|
||||
make) can be carried out using the command:
|
||||
|
||||
sh cleanall.sh
|
||||
|
||||
@@ -337,7 +290,7 @@ port assignments would be:
|
||||
HIGHPORT = 5299
|
||||
|
||||
When running tests in parallel (i.e. giving a value of "numproc" greater than 1
|
||||
in the "make" or "runall.sh" commands listed above), it is guaranteed that each
|
||||
in the "make" command listed above), it is guaranteed that each
|
||||
test will get a set of unique port numbers.
|
||||
|
||||
|
||||
@@ -373,7 +326,7 @@ arguments, e.g.:
|
||||
(cd mytest ; sh clean.sh -D xyz)
|
||||
|
||||
No arguments will be passed to the test scripts if the test is run as part of
|
||||
a run of the full test suite (e.g. the tests are started with "runall.sh").
|
||||
a run of the full test suite (e.g. the tests are started with make).
|
||||
|
||||
3. Each script should start with the following lines:
|
||||
|
||||
@@ -643,13 +596,10 @@ Adding a Test to the System Test Suite
|
||||
---
|
||||
Once a test has been created, the following files should be edited:
|
||||
|
||||
* conf.sh.in The name of the test should be added to the PARALLELDIRS or
|
||||
SEQUENTIALDIRS variables as appropriate. The former is used for tests that
|
||||
can run in parallel with other tests, the latter for tests that are unable to
|
||||
do so.
|
||||
* conf.sh.common The name of the test should be added to the PARALLEL_COMMON
|
||||
variable.
|
||||
|
||||
* Makefile.in The name of the test should be added to one of the the PARALLEL
|
||||
or SEQUENTIAL variables.
|
||||
* Makefile.am The name of the test should be added to the TESTS variable.
|
||||
|
||||
(It is likely that a future iteration of the system test suite will remove the
|
||||
need to edit multiple files to add a test.)
|
||||
@@ -673,20 +623,12 @@ Notes on Parallel Execution
|
||||
Although execution of an individual test is controlled by "run.sh", which
|
||||
executes the above shell scripts (and starts the relevant servers) for each
|
||||
test, the running of all tests in the test suite is controlled by the Makefile.
|
||||
("runall.sh" does little more than invoke "make" on the Makefile.)
|
||||
|
||||
All system tests are capable of being run in parallel. For this to work, each
|
||||
test needs to use a unique set of ports. To avoid the need to define which
|
||||
tests use which ports (and so risk port clashes as further tests are added),
|
||||
the ports are assigned when the tests are run. This is achieved by having the
|
||||
"test" target in the Makefile depend on "parallel.mk". That file is created
|
||||
when "make check" is run, and contains a target for each test of the form:
|
||||
|
||||
<test-name>:
|
||||
@$(SHELL) run.sh -p <baseport> <test-name>
|
||||
|
||||
The <baseport> is unique and the values of <baseport> for each test are
|
||||
separated by at least 100 ports.
|
||||
the ports are determined by "get_ports.sh", a port broker script which keeps
|
||||
track of ports given to each individual system test.
|
||||
|
||||
|
||||
Cleaning Up From Tests
|
||||
@@ -699,10 +641,6 @@ stored in the test directory.
|
||||
2. Files produced by named which may not be cleaned up if named exits
|
||||
abnormally, e.g. core files, PID files etc., are stored in the test directory.
|
||||
|
||||
3. A file "test.output.<test-name>" containing the text written to stdout by the
|
||||
test is written to bin/tests/system/. This file is only produced when the test
|
||||
is run as part of the entire test suite (e.g. via "runall.sh").
|
||||
|
||||
If the test fails, all these files are retained. But if the test succeeds,
|
||||
they are cleaned up at different times:
|
||||
|
||||
@@ -711,7 +649,3 @@ they are cleaned up at different times:
|
||||
|
||||
2. Files that may not be cleaned up if named exits abnormally can be removed
|
||||
using the "cleanall.sh" script.
|
||||
|
||||
3. "test.output.*" files are deleted when the test suite ends. At this point,
|
||||
the file "testsummary.sh" is called which concatenates all the "test.output.*"
|
||||
files into a single "systests.output" file before deleting them.
|
||||
|
||||
@@ -19,7 +19,7 @@ infile=root.db.in
|
||||
|
||||
(cd ../ns2 && $SHELL keygen.sh )
|
||||
|
||||
cat $infile ../ns2/dsset-example$TP > $zonefile
|
||||
cat $infile ../ns2/dsset-example. > $zonefile
|
||||
|
||||
zskact=`$KEYGEN -3 -a RSASHA1 -q $zone`
|
||||
zskvanish=`$KEYGEN -3 -a RSASHA1 -q $zone`
|
||||
|
||||
@@ -19,18 +19,18 @@
|
||||
for subdomain in secure nsec3 autonsec3 optout rsasha256 rsasha512 nsec3-to-nsec oldsigs sync \
|
||||
dname-at-apex-nsec3
|
||||
do
|
||||
cp ../ns3/dsset-$subdomain.example$TP .
|
||||
cp ../ns3/dsset-$subdomain.example. .
|
||||
done
|
||||
|
||||
# Create keys and pass the DS to the parent.
|
||||
zone=example
|
||||
zonefile="${zone}.db"
|
||||
infile="${zonefile}.in"
|
||||
cat $infile dsset-*.example$TP > $zonefile
|
||||
cat $infile dsset-*.example. > $zonefile
|
||||
|
||||
kskname=`$KEYGEN -a RSASHA1 -3 -q -fk $zone`
|
||||
$KEYGEN -a RSASHA1 -3 -q $zone > /dev/null
|
||||
$DSFROMKEY $kskname.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $kskname.key > dsset-${zone}.
|
||||
|
||||
# Create keys for a private secure zone.
|
||||
zone=private.secure.example
|
||||
@@ -53,4 +53,4 @@ do
|
||||
cp $i `echo $i | sed s/X/K/`
|
||||
done
|
||||
$KEYGEN -a RSASHA1 -q $zone > /dev/null
|
||||
$DSFROMKEY Kbar.+005+30804.key > dsset-bar$TP
|
||||
$DSFROMKEY Kbar.+005+30804.key > dsset-bar.
|
||||
|
||||
@@ -33,7 +33,7 @@ setup secure.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC3/NSEC test zone
|
||||
@@ -42,7 +42,7 @@ setup secure.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC3/NSEC3 test zone
|
||||
@@ -51,7 +51,7 @@ setup nsec3.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Jitter/NSEC3 test zone
|
||||
@@ -75,16 +75,16 @@ setup optout.nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A nsec3 zone (non-optout).
|
||||
#
|
||||
setup nsec3.example
|
||||
cat $infile dsset-*.${zone}$TP > $zonefile
|
||||
cat $infile dsset-*.${zone}. > $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# An NSEC3 zone, with NSEC3 parameters set prior to signing
|
||||
@@ -95,7 +95,7 @@ ksk=`$KEYGEN -G -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.ou
|
||||
echo $ksk > ../autoksk.key
|
||||
zsk=`$KEYGEN -G -q -a $DEFAULT_ALGORITHM -3 $zone 2> kg.out` || dumpit kg.out
|
||||
echo $zsk > ../autozsk.key
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/NSEC test zone
|
||||
@@ -104,7 +104,7 @@ setup secure.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/NSEC3 test zone
|
||||
@@ -113,7 +113,7 @@ setup nsec3.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# OPTOUT/OPTOUT test zone
|
||||
@@ -122,16 +122,16 @@ setup optout.optout.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A optout nsec3 zone.
|
||||
#
|
||||
setup optout.example
|
||||
cat $infile dsset-*.${zone}$TP > $zonefile
|
||||
cat $infile dsset-*.${zone}. > $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A RSASHA256 zone.
|
||||
@@ -140,7 +140,7 @@ setup rsasha256.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA256 -b 2048 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA256 -b 1024 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A RSASHA512 zone.
|
||||
@@ -149,7 +149,7 @@ setup rsasha512.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA512 -b 2048 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA512 -b 1024 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# NSEC-only zone.
|
||||
@@ -158,7 +158,7 @@ setup nsec.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a RSASHA1 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a RSASHA1 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# Signature refresh test zone. Signatures are set to expire long
|
||||
@@ -301,7 +301,7 @@ setup sync.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk -P sync now $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
echo ns3/$ksk > ../sync.key
|
||||
|
||||
#
|
||||
@@ -311,7 +311,7 @@ setup kskonly.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk -P sync now $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that has a published inactive key that is autosigned.
|
||||
@@ -320,7 +320,7 @@ setup inacksk2.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -Pnow -A now+3600 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that has a published inactive key that is autosigned.
|
||||
@@ -329,7 +329,7 @@ setup inaczsk2.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
@@ -339,7 +339,7 @@ cp $infile $zonefile
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 -fk $zone > kg.out 2>&1 || dumpit kg.out
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with a active KSK + ZSK and a inactive ZSK.
|
||||
@@ -349,7 +349,7 @@ cp $infile $zonefile
|
||||
ksk=`$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$KEYGEN -a $DEFAULT_ALGORITHM -3 -q -P now -A now+3600 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
#
|
||||
# A zone that starts with an active KSK + ZSK and an inactive ZSK, with the
|
||||
@@ -369,4 +369,4 @@ setup dname-at-apex-nsec3.example
|
||||
cp $infile $zonefile
|
||||
ksk=`$KEYGEN -q -a $DEFAULT_ALGORITHM -3 -fk $zone 2> kg.out` || dumpit kg.out
|
||||
$KEYGEN -q -a $DEFAULT_ALGORITHM -3 $zone > kg.out 2>&1 || dumpit kg.out
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}$TP
|
||||
$DSFROMKEY $ksk.key > dsset-${zone}.
|
||||
|
||||
@@ -46,6 +46,14 @@ options {
|
||||
};
|
||||
};
|
||||
|
||||
# A faulty dlz configuration to check if named and catz survive a certain class
|
||||
# of failed configuration attempts (see GL#3060).
|
||||
# We use "dlz" because the dlz processing code is located in an ideal place in
|
||||
# the view configuration function for the test to cover the view reverting code.
|
||||
#T3dlz "bad-dlz" {
|
||||
#T3 database "dlopen bad-dlz.so example.org";
|
||||
#T3};
|
||||
|
||||
zone "catalog1.example" {
|
||||
type secondary;
|
||||
file "catalog1.example.db";
|
||||
|
||||
@@ -369,6 +369,30 @@ wait_for_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "reconfiguring secondary - checking if catz survives a certain class of failed reconfiguration attempts ($n)"
|
||||
ret=0
|
||||
sed -e "s/^#T3//" < ns2/named1.conf.in > ns2/named.conf.tmp
|
||||
copy_setports ns2/named.conf.tmp ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p "${CONTROLPORT}" reconfig > /dev/null 2>&1 && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "checking again that dom3.example. is served by secondary ($n)"
|
||||
ret=0
|
||||
wait_for_soa @10.53.0.2 dom3.example. dig.out.test$n || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "reconfiguring secondary - reverting the bad configuration ($n)"
|
||||
ret=0
|
||||
copy_setports ns2/named1.conf.in ns2/named.conf
|
||||
rndccmd 10.53.0.2 reconfig || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "removing all records from catalog1 zone ($n)"
|
||||
ret=0
|
||||
@@ -1213,7 +1237,7 @@ echo_i "reconfiguring secondary - removing catalog4 catalog zone, adding non-exi
|
||||
ret=0
|
||||
sed -e "s/^#T2//" < ns2/named1.conf.in > ns2/named.conf.tmp
|
||||
copy_setports ns2/named.conf.tmp ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig > /dev/null 2>&1 && ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p "${CONTROLPORT}" reconfig > /dev/null 2>&1 && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
|
||||
@@ -52,7 +52,7 @@ check_stderr() {
|
||||
}
|
||||
|
||||
check_stdout() {
|
||||
$DIFF out.$n "${out:-empty}" >/dev/null && return
|
||||
diff out.$n "${out:-empty}" >/dev/null && return
|
||||
echo_d "stdout did not match '$out'"
|
||||
( echo "wanted"
|
||||
cat "$out"
|
||||
@@ -128,10 +128,10 @@ name='in-place backup correct modification time'
|
||||
testcase 0 $PERL checkmtime.pl 7200 DS.inplace.bak
|
||||
|
||||
name='in-place correct output'
|
||||
testcase 0 $DIFF DS.1 DS.inplace
|
||||
testcase 0 diff DS.1 DS.inplace
|
||||
|
||||
name='in-place backup unmodified'
|
||||
testcase 0 $DIFF DS.1 DS.inplace.bak
|
||||
testcase 0 diff DS.1 DS.inplace.bak
|
||||
|
||||
name='one mangled DS'
|
||||
err='found RRSIG by key'
|
||||
|
||||
+9
-3
@@ -11,8 +11,14 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
keep-response-order {
|
||||
does_not_exist;
|
||||
dnssec-policy ksk-without-zsk {
|
||||
keys {
|
||||
ksk lifetime 30d algorithm 13;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy ksk-without-zsk;
|
||||
};
|
||||
@@ -0,0 +1,27 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* SPDX-License-Identifier: MPL-2.0
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-policy unpaired-keys {
|
||||
keys {
|
||||
/* zsk without ksk */
|
||||
zsk lifetime 30d algorithm 13;
|
||||
/* ksk without zsk */
|
||||
ksk lifetime 30d algorithm 7;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy unpaired-keys;
|
||||
};
|
||||
+10
-6
@@ -11,10 +11,14 @@
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
port @PORT@;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
dnssec-policy zsk-without-ksk {
|
||||
keys {
|
||||
zsk lifetime 30d algorithm 13;
|
||||
};
|
||||
};
|
||||
|
||||
zone "example" {
|
||||
type primary;
|
||||
file "example.db";
|
||||
dnssec-policy zsk-without-ksk;
|
||||
};
|
||||
@@ -54,9 +54,6 @@ options {
|
||||
heartbeat-interval 30;
|
||||
hostname none;
|
||||
interface-interval 30;
|
||||
keep-response-order {
|
||||
10.0.10.0/24;
|
||||
};
|
||||
listen-on port 90 {
|
||||
"any";
|
||||
};
|
||||
|
||||
@@ -1,71 +0,0 @@
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
import os
|
||||
import pytest
|
||||
|
||||
|
||||
def pytest_configure(config):
|
||||
config.addinivalue_line(
|
||||
"markers", "dnspython: mark tests that need dnspython to function"
|
||||
)
|
||||
config.addinivalue_line(
|
||||
"markers", "dnspython2: mark tests that need dnspython >= 2.0.0"
|
||||
)
|
||||
|
||||
|
||||
def pytest_collection_modifyitems(config, items):
|
||||
# pylint: disable=unused-argument,unused-import,too-many-branches
|
||||
# pylint: disable=import-outside-toplevel
|
||||
|
||||
# Test for dnspython module
|
||||
skip_dnspython = pytest.mark.skip(
|
||||
reason="need dnspython module to run")
|
||||
try:
|
||||
import dns.query # noqa: F401
|
||||
except ModuleNotFoundError:
|
||||
for item in items:
|
||||
if "dnspython" in item.keywords:
|
||||
item.add_marker(skip_dnspython)
|
||||
|
||||
# Test for dnspython >= 2.0.0 module
|
||||
skip_dnspython2 = pytest.mark.skip(
|
||||
reason="need dnspython >= 2.0.0 module to run")
|
||||
try:
|
||||
from dns.query import udp_with_fallback # noqa: F401
|
||||
except ImportError:
|
||||
for item in items:
|
||||
if "dnspython2" in item.keywords:
|
||||
item.add_marker(skip_dnspython2)
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def named_port(request):
|
||||
# pylint: disable=unused-argument
|
||||
port = os.getenv("PORT")
|
||||
if port is None:
|
||||
port = 5301
|
||||
else:
|
||||
port = int(port)
|
||||
|
||||
return port
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def control_port(request):
|
||||
# pylint: disable=unused-argument
|
||||
port = os.getenv("CONTROLPORT")
|
||||
if port is None:
|
||||
port = 5301
|
||||
else:
|
||||
port = int(port)
|
||||
|
||||
return port
|
||||
@@ -21,7 +21,7 @@ for subdomain in dspublished reference missing-dspublished bad-dspublished \
|
||||
dswithdrawn missing-dswithdrawn bad-dswithdrawn \
|
||||
multiple-dswithdrawn incomplete-dswithdrawn bad2-dswithdrawn
|
||||
do
|
||||
cp "../ns9/dsset-$subdomain.checkds$TP" .
|
||||
cp "../ns9/dsset-$subdomain.checkds." .
|
||||
done
|
||||
|
||||
zone="checkds"
|
||||
|
||||
@@ -17,9 +17,18 @@ import subprocess
|
||||
import sys
|
||||
import time
|
||||
|
||||
import dns.resolver
|
||||
import pytest
|
||||
|
||||
pytest.importorskip('dns', minversion='2.0.0')
|
||||
import dns.exception
|
||||
import dns.message
|
||||
import dns.name
|
||||
import dns.query
|
||||
import dns.rcode
|
||||
import dns.rdataclass
|
||||
import dns.rdatatype
|
||||
import dns.resolver
|
||||
|
||||
|
||||
def has_signed_apex_nsec(zone, response):
|
||||
has_nsec = False
|
||||
@@ -220,8 +229,6 @@ def wait_for_log(filename, log):
|
||||
assert found
|
||||
|
||||
|
||||
@pytest.mark.dnspython
|
||||
@pytest.mark.dnspython2
|
||||
def test_checkds_dspublished(named_port):
|
||||
# We create resolver instances that will be used to send queries.
|
||||
server = dns.resolver.Resolver()
|
||||
@@ -304,8 +311,6 @@ def test_checkds_dspublished(named_port):
|
||||
# TBD: Check with TLS
|
||||
|
||||
|
||||
@pytest.mark.dnspython
|
||||
@pytest.mark.dnspython2
|
||||
def test_checkds_dswithdrawn(named_port):
|
||||
# We create resolver instances that will be used to send queries.
|
||||
server = dns.resolver.Resolver()
|
||||
|
||||
@@ -192,7 +192,7 @@ status=`expr $status + $ret`
|
||||
|
||||
ret=0
|
||||
# Step 3: Ensure that output conversion from stdin is the same as the output conversion from a file.
|
||||
$DIFF zones/zone1_file.txt zones/zone1_stdin.txt >/dev/null 2>&1 || ret=1
|
||||
diff zones/zone1_file.txt zones/zone1_stdin.txt >/dev/null 2>&1 || ret=1
|
||||
status=`expr $status + $ret`
|
||||
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
|
||||
@@ -31,6 +31,5 @@ rm -f ../random.data
|
||||
for d in $SUBDIRS
|
||||
do
|
||||
test ! -f $d/clean.sh || ( cd $d && $SHELL clean.sh )
|
||||
rm -f test.output.$d
|
||||
test -d $d && find $d -type d -exec rmdir '{}' \; 2> /dev/null
|
||||
done
|
||||
|
||||
@@ -31,13 +31,6 @@ export LANG=C
|
||||
# The "dialup", "delzone", and "dupsigs" tests are also not run by
|
||||
# default because they take a very long time to complete.
|
||||
#
|
||||
# The following tests are hard-coded to use ports 5300 and 9953. For
|
||||
# this reason, these must be run sequentially.
|
||||
#
|
||||
# Sequential tests that only run on unix/linux should be added to
|
||||
# SEQUENTIAL_UNIX in conf.sh.in
|
||||
#
|
||||
SEQUENTIAL_COMMON=""
|
||||
|
||||
#
|
||||
# These tests can use ports assigned by the caller (other than 5300
|
||||
@@ -181,19 +174,19 @@ then
|
||||
printf "${COLOR_END}%s${COLOR_NONE}\n" "$*"
|
||||
}
|
||||
echo_i() {
|
||||
printf '%s\n' "$*" | while read -r __LINE ; do
|
||||
printf '%s\n' "$*" | while IFS= read -r __LINE ; do
|
||||
echoinfo "I:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
|
||||
echo_ic() {
|
||||
printf '%s\n' "$*" | while read -r __LINE ; do
|
||||
printf '%s\n' "$*" | while IFS= read -r __LINE ; do
|
||||
echoinfo "I:$SYSTESTDIR: $__LINE"
|
||||
done
|
||||
}
|
||||
|
||||
echo_d() {
|
||||
printf '%s\n' "$*" | while read -r __LINE ; do
|
||||
printf '%s\n' "$*" | while IFS= read -r __LINE ; do
|
||||
echoinfo "D:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
@@ -218,32 +211,32 @@ else
|
||||
}
|
||||
|
||||
echo_i() {
|
||||
echo "$@" | while read -r __LINE ; do
|
||||
echo "$@" | while IFS= read -r __LINE ; do
|
||||
echoinfo "I:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
|
||||
echo_ic() {
|
||||
echo "$@" | while read -r __LINE ; do
|
||||
echo "$@" | while IFS= read -r __LINE ; do
|
||||
echoinfo "I:$SYSTESTDIR: $__LINE"
|
||||
done
|
||||
}
|
||||
|
||||
echo_d() {
|
||||
echo "$@" | while read -r __LINE ; do
|
||||
echo "$@" | while IFS= read -r __LINE ; do
|
||||
echoinfo "D:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
fi
|
||||
|
||||
cat_i() {
|
||||
while read -r __LINE ; do
|
||||
while IFS= read -r __LINE ; do
|
||||
echoinfo "I:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
|
||||
cat_d() {
|
||||
while read -r __LINE ; do
|
||||
while IFS= read -r __LINE ; do
|
||||
echoinfo "D:$SYSTESTDIR:$__LINE"
|
||||
done
|
||||
}
|
||||
@@ -714,7 +707,6 @@ export ARPANAME
|
||||
export BIGKEY
|
||||
export CDS
|
||||
export CHECKZONE
|
||||
export CYGWIN
|
||||
export DESCRIPTION
|
||||
export DIG
|
||||
export FEATURETEST
|
||||
@@ -738,7 +730,6 @@ export NSUPDATE
|
||||
export NZD2NZF
|
||||
export PERL
|
||||
export PIPEQUERIES
|
||||
export PSSUSPEND
|
||||
export PYTHON
|
||||
export RESOLVE
|
||||
export RNDC
|
||||
|
||||
@@ -23,9 +23,6 @@ TOP_SRCDIR=@abs_top_srcdir@
|
||||
# Provide TMPDIR variable for tests that need it.
|
||||
TMPDIR=${TMPDIR:-/tmp}
|
||||
|
||||
# This is not the windows build.
|
||||
CYGWIN=""
|
||||
|
||||
# Load common values
|
||||
. $TOP_SRCDIR/bin/tests/system/conf.sh.common
|
||||
|
||||
@@ -76,18 +73,17 @@ KRB5_KTNAME=dns.keytab
|
||||
#
|
||||
# Construct the lists of tests to run
|
||||
#
|
||||
SEQUENTIAL_UNIX=""
|
||||
SEQUENTIALDIRS="$SEQUENTIAL_COMMON $SEQUENTIAL_UNIX"
|
||||
|
||||
PARALLEL_UNIX="@DNSTAP@
|
||||
chain
|
||||
PARALLEL_UNIX="chain
|
||||
checkds
|
||||
cookie
|
||||
dlzexternal
|
||||
dnssec
|
||||
dyndb
|
||||
engine_pkcs11
|
||||
filter-aaaa
|
||||
kasp
|
||||
keyfromlabel
|
||||
keymgr2kasp
|
||||
legacy
|
||||
logfileconfig
|
||||
@@ -96,17 +92,7 @@ pipelined
|
||||
qmin
|
||||
shutdown
|
||||
tcp"
|
||||
PARALLELDIRS="$PARALLEL_COMMON $PARALLEL_UNIX"
|
||||
|
||||
SUBDIRS="$SEQUENTIALDIRS $PARALLELDIRS"
|
||||
|
||||
|
||||
# Things that are different on Windows
|
||||
KILL=kill
|
||||
DIFF=diff
|
||||
DOS2UNIX=true
|
||||
# There's no trailing period on Windows
|
||||
TP=.
|
||||
SUBDIRS="$PARALLEL_COMMON $PARALLEL_UNIX"
|
||||
|
||||
# Use the CONFIG_SHELL detected by configure for tests
|
||||
SHELL=@SHELL@
|
||||
@@ -126,9 +112,6 @@ XSLTPROC=@XSLTPROC@
|
||||
# PERL will be an empty string if no perl interpreter was found.
|
||||
PERL=$(command -v "@PERL@")
|
||||
|
||||
# Windows process management leave empty
|
||||
PSSUSPEND=
|
||||
|
||||
PYTHON=$(command -v "@PYTHON@" || true)
|
||||
PYTEST=@PYTEST@
|
||||
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
#!/usr/bin/python3
|
||||
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
@@ -10,16 +12,20 @@
|
||||
# information regarding copyright ownership.
|
||||
|
||||
import os
|
||||
|
||||
import pytest
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def port(request):
|
||||
# pylint: disable=unused-argument
|
||||
env_port = os.getenv("PORT")
|
||||
if env_port is None:
|
||||
env_port = 5300
|
||||
else:
|
||||
env_port = int(env_port)
|
||||
@pytest.fixture(scope='session')
|
||||
def named_port():
|
||||
return int(os.environ.get('PORT', default=5300))
|
||||
|
||||
return env_port
|
||||
|
||||
@pytest.fixture(scope='session')
|
||||
def named_tlsport():
|
||||
return int(os.environ.get('TLSPORT', default=8853))
|
||||
|
||||
|
||||
@pytest.fixture(scope='session')
|
||||
def control_port():
|
||||
return int(os.environ.get('CONTROLPORT', default=9953))
|
||||
@@ -22,7 +22,7 @@ n=0
|
||||
getcookie() {
|
||||
awk '$2 == "COOKIE:" {
|
||||
print $3;
|
||||
}' < $1 | tr -d '\r'
|
||||
}' < $1
|
||||
}
|
||||
|
||||
fullcookie() {
|
||||
|
||||
@@ -1,37 +0,0 @@
|
||||
#!/bin/sh -e
|
||||
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
set -e
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
case $(uname) in
|
||||
Linux*)
|
||||
;;
|
||||
*)
|
||||
echo_i "cpu test only runs on Linux"
|
||||
exit 255
|
||||
;;
|
||||
esac
|
||||
|
||||
# TASKSET will be an empty string if no taskset program was found.
|
||||
TASKSET=$(command -v "taskset" || true)
|
||||
if ! test -x "$TASKSET" ; then
|
||||
exit 255
|
||||
fi
|
||||
|
||||
if ! $TASKSET fff0 true > /dev/null 2>&1; then
|
||||
echo_i "taskset failed"
|
||||
exit 255
|
||||
fi
|
||||
@@ -1,48 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
status=0
|
||||
n=0
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "stop server ($n)"
|
||||
ret=0
|
||||
$PERL ../stop.pl cpu ns1 || ret=1
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "start server with taskset ($n)"
|
||||
ret=0
|
||||
start_server --noclean --taskset fff0 --restart --port "${PORT}" cpu ns1 || ret=1
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check ps output ($n)"
|
||||
ret=0
|
||||
ps -T -o pid,psr,time,comm -e > ps.out
|
||||
pid=$(cat ns1/named.pid)
|
||||
echo_i "pid=$pid"
|
||||
psr=$(awk -v pid="$pid" '$1 == pid && $4 == "isc-net-0000" {print $2}' < ps.out)
|
||||
echo_i "psr=$psr"
|
||||
# The next available cpu relative to the existing affinity mask is 4.
|
||||
test "$psr" -eq 4 || ret=1
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
@@ -0,0 +1,190 @@
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
from __future__ import print_function
|
||||
import os
|
||||
import sys
|
||||
import signal
|
||||
import socket
|
||||
import select
|
||||
import struct
|
||||
|
||||
import dns, dns.message
|
||||
from dns.rcode import *
|
||||
|
||||
modes = [
|
||||
b"silent", # Do not respond
|
||||
b"close", # UDP: same as silent; TCP: also close the connection
|
||||
b"servfail", # Always respond with SERVFAIL
|
||||
b"unstable", # Constantly switch between "silent" and "servfail"
|
||||
]
|
||||
mode = modes[0]
|
||||
n = 0
|
||||
|
||||
def ctrl_channel(msg):
|
||||
global modes, mode, n
|
||||
|
||||
msg = msg.splitlines().pop(0)
|
||||
print("Received control message: %s" % msg)
|
||||
|
||||
if msg in modes:
|
||||
mode = msg
|
||||
n = 0
|
||||
print("New mode: %s" % str(mode))
|
||||
|
||||
def create_servfail(msg):
|
||||
m = dns.message.from_wire(msg)
|
||||
qname = m.question[0].name.to_text()
|
||||
rrtype = m.question[0].rdtype
|
||||
typename = dns.rdatatype.to_text(rrtype)
|
||||
|
||||
with open("query.log", "a") as f:
|
||||
f.write("%s %s\n" % (typename, qname))
|
||||
print("%s %s" % (typename, qname), end=" ")
|
||||
|
||||
r = dns.message.make_response(m)
|
||||
r.set_rcode(SERVFAIL)
|
||||
return r
|
||||
|
||||
def sigterm(signum, frame):
|
||||
print("Shutting down now...")
|
||||
os.remove("ans.pid")
|
||||
running = False
|
||||
sys.exit(0)
|
||||
|
||||
ip4 = "10.53.0.8"
|
||||
|
||||
try: port=int(os.environ["PORT"])
|
||||
except: port=5300
|
||||
|
||||
try: ctrlport=int(os.environ['EXTRAPORT1'])
|
||||
except: ctrlport=5300
|
||||
|
||||
query4_udp = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||
query4_udp.bind((ip4, port))
|
||||
|
||||
query4_tcp = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||
query4_tcp.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
|
||||
query4_tcp.bind((ip4, port))
|
||||
query4_tcp.listen(100)
|
||||
|
||||
ctrl4_tcp = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||
ctrl4_tcp.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
|
||||
ctrl4_tcp.bind((ip4, ctrlport))
|
||||
ctrl4_tcp.listen(100)
|
||||
|
||||
signal.signal(signal.SIGTERM, sigterm)
|
||||
|
||||
f = open("ans.pid", "w")
|
||||
pid = os.getpid()
|
||||
print (pid, file=f)
|
||||
f.close()
|
||||
|
||||
running = True
|
||||
|
||||
print ("Listening on %s port %d" % (ip4, port))
|
||||
print ("Listening on %s port %d" % (ip4, ctrlport))
|
||||
print ("Ctrl-c to quit")
|
||||
|
||||
input = [query4_udp, query4_tcp, ctrl4_tcp]
|
||||
|
||||
hung_conns = []
|
||||
|
||||
while running:
|
||||
try:
|
||||
inputready, outputready, exceptready = select.select(input, [], [])
|
||||
except select.error as e:
|
||||
break
|
||||
except socket.error as e:
|
||||
break
|
||||
except KeyboardInterrupt:
|
||||
break
|
||||
|
||||
for s in inputready:
|
||||
if s == query4_udp:
|
||||
n = n + 1
|
||||
print("UDP query received on %s" % ip4, end=" ")
|
||||
msg = s.recvfrom(65535)
|
||||
if mode == b"silent" or mode == b"close" or (mode == b"unstable" and n % 2 == 1):
|
||||
# Do not respond.
|
||||
print("NO RESPONSE (%s)" % str(mode))
|
||||
continue
|
||||
elif mode == b"servfail" or (mode == b"unstable" and n % 2 == 0):
|
||||
rsp = create_servfail(msg[0])
|
||||
if rsp:
|
||||
print(dns.rcode.to_text(rsp.rcode()))
|
||||
s.sendto(rsp.to_wire(), msg[1])
|
||||
else:
|
||||
print("NO RESPONSE (can not create a response)")
|
||||
else:
|
||||
raise(Exception("unsupported mode: %s" % mode))
|
||||
elif s == query4_tcp:
|
||||
n = n + 1
|
||||
print("TCP query received on %s" % ip4, end=" ")
|
||||
conn = None
|
||||
try:
|
||||
if mode == b"silent" or (mode == b"unstable" and n % 2 == 1):
|
||||
conn, addr = s.accept()
|
||||
# Do not respond and hang the connection.
|
||||
print("NO RESPONSE (%s)" % str(mode))
|
||||
hung_conns.append(conn)
|
||||
continue
|
||||
elif mode == b"close":
|
||||
conn, addr = s.accept()
|
||||
# Do not respond and close the connection.
|
||||
print("NO RESPONSE (%s)" % str(mode))
|
||||
conn.close()
|
||||
continue
|
||||
elif mode == b"servfail" or (mode == b"unstable" and n % 2 == 0):
|
||||
conn, addr = s.accept()
|
||||
# get TCP message length
|
||||
msg = conn.recv(2)
|
||||
if len(msg) != 2:
|
||||
print("NO RESPONSE (can not read the message length)")
|
||||
conn.close()
|
||||
continue
|
||||
length = struct.unpack('>H', msg[:2])[0]
|
||||
msg = conn.recv(length)
|
||||
if len(msg) != length:
|
||||
print("NO RESPONSE (can not read the message)")
|
||||
conn.close()
|
||||
continue
|
||||
rsp = create_servfail(msg)
|
||||
if rsp:
|
||||
print(dns.rcode.to_text(rsp.rcode()))
|
||||
wire = rsp.to_wire()
|
||||
conn.send(struct.pack('>H', len(wire)))
|
||||
conn.send(wire)
|
||||
else:
|
||||
print("NO RESPONSE (can not create a response)")
|
||||
else:
|
||||
raise(Exception("unsupported mode: %s" % mode))
|
||||
except socket.error as e:
|
||||
print("NO RESPONSE (error: %s)" % str(e))
|
||||
if conn:
|
||||
conn.close()
|
||||
elif s == ctrl4_tcp:
|
||||
print("Control channel connected")
|
||||
conn = None
|
||||
try:
|
||||
# Handle control channel input
|
||||
conn, addr = s.accept()
|
||||
msg = conn.recv(1024)
|
||||
if msg:
|
||||
ctrl_channel(msg)
|
||||
conn.close()
|
||||
except s.timeout:
|
||||
pass
|
||||
if conn:
|
||||
conn.close()
|
||||
|
||||
if not running:
|
||||
break
|
||||
@@ -17,6 +17,8 @@ rm -f ./*/anchor.*
|
||||
rm -f ./*/named.conf
|
||||
rm -f ./*/named.memstats
|
||||
rm -f ./*/named.run
|
||||
rm -f ./ans*/ans.run
|
||||
rm -f ./ans*/query.log
|
||||
rm -f ./delv.out.test*
|
||||
rm -f ./dig.out.*test*
|
||||
rm -f ./dig.out.mm.*
|
||||
|
||||
@@ -576,7 +576,7 @@ if [ -x "$DIG" ] ; then
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.3 +ednsopt=llq:0001000200001234567812345678fefefefe +qr a.example > dig.out.test$n 2>&1 || ret=1
|
||||
pat='LLQ: Version: 1, Opcode: 2, Error: 0, Identifier: 1311768465173141112, Lifetime: 4278124286$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -675,7 +675,7 @@ if [ -x "$DIG" ] ; then
|
||||
# First defined EDE code, additional text "foo".
|
||||
dig_with_opts @10.53.0.3 +ednsopt=ede:0000666f6f a.example +qr > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^; EDE: 0 (Other): (foo)$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -684,7 +684,7 @@ if [ -x "$DIG" ] ; then
|
||||
# Last defined EDE code, no additional text.
|
||||
dig_with_opts @10.53.0.3 +ednsopt=ede:0018 a.example +qr > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^; EDE: 24 (Invalid Data)$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -693,7 +693,7 @@ if [ -x "$DIG" ] ; then
|
||||
# First undefined EDE code, additional text "foo".
|
||||
dig_with_opts @10.53.0.3 +ednsopt=ede:0019666f6f a.example +qr > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^; EDE: 25: (foo)$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -702,7 +702,7 @@ if [ -x "$DIG" ] ; then
|
||||
# EDE payload is too short
|
||||
dig_with_opts @10.53.0.3 +ednsopt=ede a.example +qr > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^; EDE:$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -711,7 +711,7 @@ if [ -x "$DIG" ] ; then
|
||||
# EDE payload is too short
|
||||
dig_with_opts @10.53.0.3 +ednsopt=ede:00 a.example +qr > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^; EDE: 00 (".")$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -799,7 +799,7 @@ if [ -x "$DIG" ] ; then
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.3 -q -m > dig.out.test$n 2>&1
|
||||
pat='^;-m\..*IN.*A$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
grep "Dump of all outstanding memory allocations" dig.out.test$n > /dev/null && ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
@@ -913,7 +913,7 @@ if [ -x "$DIG" ] ; then
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.3 +short +expandaaaa AAAA ns2.example > dig.out.test$n 2>&1 || ret=1
|
||||
pat='^fd92:7065:0b8e:ffff:0000:0000:0000:0002$'
|
||||
tr -d '\r' < dig.out.test$n | grep "$pat" > /dev/null || ret=1
|
||||
grep "$pat" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
@@ -998,6 +998,79 @@ if [ -x "$DIG" ] ; then
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# See [GL #3020] for more information
|
||||
n=$((n+1))
|
||||
echo_i "check that dig handles UDP timeout followed by a SERVFAIL correctly ($n)"
|
||||
# Ask ans8 to be in "unstable" mode (switching between "silent" and "servfail" modes)
|
||||
echo "unstable" | sendcmd 10.53.0.8
|
||||
ret=0
|
||||
dig_with_opts +timeout=1 +nofail @10.53.0.8 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: SERVFAIL" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig handles TCP timeout followed by a SERVFAIL correctly ($n)"
|
||||
# Ask ans8 to be in "unstable" mode (switching between "silent" and "servfail" modes)
|
||||
echo "unstable" | sendcmd 10.53.0.8
|
||||
ret=0
|
||||
dig_with_opts +timeout=1 +nofail +tcp @10.53.0.8 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: SERVFAIL" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig tries the next server after a UDP socket read error ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.99 @10.53.0.3 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig tries the next server after a TCP socket read error ($n)"
|
||||
# Ask ans8 to be in "close" mode, which closes the connection after accepting it
|
||||
echo "close" | sendcmd 10.53.0.8
|
||||
ret=0
|
||||
dig_with_opts +tcp @10.53.0.8 @10.53.0.3 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
# Note that we combine TCP socket "connection error" and "timeout" cases in
|
||||
# one, because it is not trivial to simulate the timeout case in a system test
|
||||
# in Linux without a firewall, but the code which handles error cases during
|
||||
# the connection establishment time does not differentiate between timeout and
|
||||
# other types of errors (unlike during reading), so this one check should be
|
||||
# sufficient for both cases.
|
||||
n=$((n+1))
|
||||
echo_i "check that dig tries the next server after a TCP socket connection error/timeout ($n)"
|
||||
ret=0
|
||||
dig_with_opts -d +tcp @10.53.0.99 @10.53.0.3 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
#test $(grep "connection refused\|timed out" dig.out.test$n | wc -l) -eq 3 || ret=1
|
||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig tries the next server after UDP socket read timeouts ($n)"
|
||||
# Ask ans8 to be in "silent" mode
|
||||
echo "silent" | sendcmd 10.53.0.8
|
||||
ret=0
|
||||
dig_with_opts +timeout=1 @10.53.0.8 @10.53.0.3 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig tries the next server after TCP socket read timeouts ($n)"
|
||||
# Ask ans8 to be in "silent" mode
|
||||
echo "silent" | sendcmd 10.53.0.8
|
||||
ret=0
|
||||
dig_with_opts +timeout=1 +tcp @10.53.0.8 @10.53.0.3 a.example > dig.out.test$n 2>&1 || ret=1
|
||||
grep "status: NOERROR" dig.out.test$n > /dev/null || ret=1
|
||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
||||
status=$((status+ret))
|
||||
else
|
||||
echo_i "$DIG is needed, so skipping these dig tests"
|
||||
fi
|
||||
|
||||
@@ -19,8 +19,8 @@ import dns.query
|
||||
import dns.rcode
|
||||
|
||||
|
||||
def test_connreset(port):
|
||||
def test_connreset(named_port):
|
||||
msg = dns.message.make_query("sub.example.", "A", want_dnssec=True,
|
||||
use_edns=0, payload=1232)
|
||||
ans = dns.query.udp(msg, "10.53.0.2", timeout=10, port=port)
|
||||
ans = dns.query.udp(msg, "10.53.0.2", timeout=10, port=named_port)
|
||||
assert ans.rcode() == dns.rcode.SERVFAIL
|
||||
|
||||
@@ -480,8 +480,7 @@ dlz_lookup(const char *zone, const char *name, void *dbdata,
|
||||
* If the DLZ only operates on 'live' data, then version
|
||||
* wouldn't necessarily be needed.
|
||||
*/
|
||||
if (clientinfo != NULL && clientinfo->version >= DNS_CLIENTINFO_VERSION)
|
||||
{
|
||||
if (clientinfo != NULL && clientinfo->version >= 2) {
|
||||
dbversion = clientinfo->dbversion;
|
||||
if (dbversion != NULL && *(bool *)dbversion) {
|
||||
loginfo("dlz_example: lookup against live transaction");
|
||||
@@ -489,6 +488,7 @@ dlz_lookup(const char *zone, const char *name, void *dbdata,
|
||||
}
|
||||
|
||||
if (strcmp(name, "source-addr") == 0) {
|
||||
char ecsbuf[DNS_ECS_FORMATSIZE] = "not supported";
|
||||
strncpy(buf, "unknown", sizeof(buf));
|
||||
if (methods != NULL && methods->sourceip != NULL &&
|
||||
(methods->version - methods->age <=
|
||||
@@ -498,6 +498,17 @@ dlz_lookup(const char *zone, const char *name, void *dbdata,
|
||||
methods->sourceip(clientinfo, &src);
|
||||
fmt_address(src, buf, sizeof(buf));
|
||||
}
|
||||
if (clientinfo != NULL && clientinfo->version >= 3) {
|
||||
if (clientinfo->ecs.addr.family != AF_UNSPEC) {
|
||||
dns_ecs_format(&clientinfo->ecs, ecsbuf,
|
||||
sizeof(ecsbuf));
|
||||
} else {
|
||||
snprintf(ecsbuf, sizeof(ecsbuf), "%s",
|
||||
"not present");
|
||||
}
|
||||
}
|
||||
i = strlen(buf);
|
||||
snprintf(buf + i, sizeof(buf) - i - 1, " ECS %s", ecsbuf);
|
||||
|
||||
loginfo("dlz_example: lookup connection from %s", buf);
|
||||
|
||||
|
||||
@@ -217,5 +217,13 @@ lookups=`grep "lookup #.*\.not\.there" ns1/named.run | wc -l`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
newtest "checking ECS data is passed to driver in clientinfo"
|
||||
$DIG $DIGOPTS +short +subnet=192.0/16 source-addr.example.nil txt > dig.out.ns1.test$n.1 || ret=1
|
||||
grep "192.0.0.0/16/0" dig.out.ns1.test$n.1 > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +short source-addr.example.nil txt > dig.out.ns1.test$n.2 || ret=1
|
||||
grep "not.*present" dig.out.ns1.test$n.2 > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -112,6 +112,7 @@ rm -f ./signer/example.db.after ./signer/example.db.before
|
||||
rm -f ./signer/example.db.changed
|
||||
rm -f ./signer/general/dsset*
|
||||
rm -f ./signer/general/signed.zone
|
||||
rm -f ./signer/general/*.jnl
|
||||
rm -f ./signer/general/signer.out.*
|
||||
rm -f ./signer/nsec3param.out
|
||||
rm -f ./signer/signer.out.*
|
||||
|
||||
@@ -26,12 +26,12 @@ zonefile=root.db
|
||||
|
||||
echo_i "ns1/sign.sh"
|
||||
|
||||
cp "../ns2/dsset-example$TP" .
|
||||
cp "../ns2/dsset-in-addr.arpa$TP" .
|
||||
cp "../ns2/dsset-too-many-iterations$TP" .
|
||||
cp "../ns2/dsset-example." .
|
||||
cp "../ns2/dsset-in-addr.arpa." .
|
||||
cp "../ns2/dsset-too-many-iterations." .
|
||||
|
||||
grep "$DEFAULT_ALGORITHM_NUMBER [12] " "../ns2/dsset-algroll$TP" > "dsset-algroll$TP"
|
||||
cp "../ns6/dsset-optout-tld$TP" .
|
||||
grep "$DEFAULT_ALGORITHM_NUMBER [12] " "../ns2/dsset-algroll." > "dsset-algroll."
|
||||
cp "../ns6/dsset-optout-tld." .
|
||||
|
||||
ksk=$("$KEYGEN" -q -fk -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
|
||||
@@ -24,8 +24,8 @@ echo_i "ns2/sign.sh"
|
||||
# Get the DS records for the "trusted." and "managed." zones.
|
||||
for subdomain in secure unsupported disabled enabled
|
||||
do
|
||||
cp "../ns3/dsset-$subdomain.managed$TP" .
|
||||
cp "../ns3/dsset-$subdomain.trusted$TP" .
|
||||
cp "../ns3/dsset-$subdomain.managed." .
|
||||
cp "../ns3/dsset-$subdomain.trusted." .
|
||||
done
|
||||
|
||||
# Sign the "trusted." and "managed." zones.
|
||||
@@ -65,7 +65,7 @@ for subdomain in secure badds bogus dynamic keyless nsec3 optout \
|
||||
dnskey-nsec3-unknown managed-future revkey \
|
||||
dname-at-apex-nsec3 occluded
|
||||
do
|
||||
cp "../ns3/dsset-$subdomain.example$TP" .
|
||||
cp "../ns3/dsset-$subdomain.example." .
|
||||
done
|
||||
|
||||
# Sign the "example." zone.
|
||||
@@ -83,7 +83,6 @@ cat "$infile" "$keyname1.key" "$keyname2.key" > "$zonefile"
|
||||
|
||||
zonefiletmp=$(mktemp "$zonefile.XXXXXX") || exit 1
|
||||
"$CHECKZONE" -D -q -i local "$zone" "$zonefile.signed" |
|
||||
tr -d '\r' |
|
||||
awk '
|
||||
tolower($1) == "bad-cname.example." && $4 == "RRSIG" && $5 == "CNAME" {
|
||||
for (i = 1; i <= NF; i++ ) {
|
||||
|
||||
@@ -275,7 +275,7 @@ cat "$infile" "$keyname.key" > "$zonefile"
|
||||
|
||||
awk '$4 == "DNSKEY" { $7 = 100 } $4 == "RRSIG" { $6 = 100 } { print }' ${zonefile}.tmp > ${zonefile}.signed
|
||||
|
||||
DSFILE="dsset-${zone}${TP}"
|
||||
DSFILE="dsset-${zone}."
|
||||
$DSFROMKEY -A -f ${zonefile}.signed "$zone" > "$DSFILE"
|
||||
|
||||
#
|
||||
@@ -294,7 +294,7 @@ cat "$infile" "$keyname.key" > "$zonefile"
|
||||
|
||||
awk '$4 == "DNSKEY" { $7 = 255 } $4 == "RRSIG" { $6 = 255 } { print }' ${zonefile}.tmp > ${zonefile}.signed
|
||||
|
||||
DSFILE="dsset-${zone}${TP}"
|
||||
DSFILE="dsset-${zone}."
|
||||
$DSFROMKEY -A -f ${zonefile}.signed "$zone" > "$DSFILE"
|
||||
|
||||
#
|
||||
@@ -328,7 +328,7 @@ cat "$infile" "$keyname.key" > "$zonefile"
|
||||
|
||||
awk '$4 == "DNSKEY" { $7 = 100; print } $4 == "RRSIG" { $6 = 100; print } { print }' ${zonefile}.tmp > ${zonefile}.signed
|
||||
|
||||
DSFILE="dsset-${zone}${TP}"
|
||||
DSFILE="dsset-${zone}."
|
||||
$DSFROMKEY -A -f ${zonefile}.signed "$zone" > "$DSFILE"
|
||||
|
||||
#
|
||||
@@ -606,7 +606,7 @@ keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone
|
||||
cat "$infile" "$keyname.key" > "$zonefile"
|
||||
|
||||
"$SIGNER" -P -o "$zone" "$zonefile" > /dev/null
|
||||
sed -e 's/bogus/badds/g' < dsset-bogus.example$TP > dsset-badds.example$TP
|
||||
sed -e 's/bogus/badds/g' < dsset-bogus.example. > dsset-badds.example.
|
||||
|
||||
#
|
||||
# A zone with future signatures.
|
||||
@@ -668,7 +668,7 @@ kskname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -fk "$zone")
|
||||
zskname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" "$zone")
|
||||
dnskeyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -fk "delegation.$zone")
|
||||
keyname=$("$KEYGEN" -q -a DH -b 1024 -n HOST -T KEY "delegation.$zone")
|
||||
$DSFROMKEY "$dnskeyname.key" > "dsset-delegation.${zone}$TP"
|
||||
$DSFROMKEY "$dnskeyname.key" > "dsset-delegation.${zone}."
|
||||
cat "$infile" "${kskname}.key" "${zskname}.key" "${keyname}.key" \
|
||||
"${dnskeyname}.key" "dsset-delegation.${zone}$TP" >"$zonefile"
|
||||
"${dnskeyname}.key" "dsset-delegation.${zone}." >"$zonefile"
|
||||
"$SIGNER" -P -o "$zone" "$zonefile" > /dev/null
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; SPDX-License-Identifier: MPL-2.0
|
||||
;
|
||||
; This Source Code Form is subject to the terms of the Mozilla Public
|
||||
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
;
|
||||
; See the COPYRIGHT file distributed with this work for additional
|
||||
; information regarding copyright ownership.
|
||||
|
||||
; This is a zone which has two DNSKEY records, both of which have
|
||||
; existing private key files available. They should be loaded automatically
|
||||
; and the zone correctly signed.
|
||||
;
|
||||
$TTL 3600
|
||||
example.com. IN SOA ns hostmaster 00100000 1200 3600 604800 300
|
||||
extra.example.com. IN A 1.2.3.4
|
||||
$include Kexample.com.+008+63613.key
|
||||
$include Kexample.com.+008+15002.key
|
||||
@@ -109,12 +109,11 @@ stripns () {
|
||||
# Ensure there is not a blank line before "Secure roots:".
|
||||
#
|
||||
check_secroots_layout () {
|
||||
tr -d '\r' < "$1" | \
|
||||
awk '$0 == "" { if (empty) exit(1); empty=1; next }
|
||||
/Start view/ { if (!empty) exit(1) }
|
||||
/Secure roots:/ { if (empty) exit(1) }
|
||||
/Negative trust anchors:/ { if (!empty) exit(1) }
|
||||
{ empty=0 }'
|
||||
{ empty=0 }' $1
|
||||
return $?
|
||||
}
|
||||
|
||||
@@ -1407,6 +1406,20 @@ n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
echo_ic "check that dnssec-signzone -J loads journal files ($n)"
|
||||
ret=0
|
||||
(
|
||||
cd signer/general || exit 0
|
||||
rm -f signed.zone
|
||||
$MAKEJOURNAL example.com. test9.zone test10.zone test9.zone.jnl
|
||||
$SIGNER -f signed.zone -o example.com. -J test9.zone.jnl test9.zone > signer.out.$n
|
||||
grep -q extra signed.zone
|
||||
) || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
|
||||
echo_ic "check that dnssec-signzone accepts maximum NSEC3 iterations ($n)"
|
||||
ret=0
|
||||
(
|
||||
@@ -1422,7 +1435,6 @@ status=$((status+ret))
|
||||
get_rsasha1_key_ids_from_sigs() {
|
||||
zone=$1
|
||||
|
||||
tr -d '\r' < signer/$zone.db.signed | \
|
||||
awk '
|
||||
NF < 8 { next }
|
||||
$(NF-5) != "RRSIG" { next }
|
||||
@@ -1432,8 +1444,7 @@ get_rsasha1_key_ids_from_sigs() {
|
||||
getline;
|
||||
print $3;
|
||||
}
|
||||
' | \
|
||||
sort -u
|
||||
' signer/$zone.db.signed | sort -u
|
||||
}
|
||||
|
||||
# Test dnssec-signzone ZSK prepublish smooth rollover.
|
||||
@@ -2152,7 +2163,7 @@ status=$((status+ret))
|
||||
ret=0
|
||||
|
||||
echo_i "killing ns4 with SIGTERM"
|
||||
$KILL -TERM "$(cat ns4/named.pid)"
|
||||
kill -TERM "$(cat ns4/named.pid)"
|
||||
rm -f ns4/named.pid
|
||||
|
||||
#
|
||||
@@ -2214,7 +2225,7 @@ grep "status: SERVFAIL" dig.out.ns4.test$n.2 > /dev/null && ret=1
|
||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.2 > /dev/null || ret=1
|
||||
|
||||
echo_i "killing ns4 with SIGTERM"
|
||||
$KILL -TERM "$(cat ns4/named.pid)"
|
||||
kill -TERM "$(cat ns4/named.pid)"
|
||||
rm -f ns4/named.pid
|
||||
|
||||
echo_i "sleeping for an additional 4 seconds for ns4 to fully shutdown"
|
||||
@@ -2272,7 +2283,7 @@ grep "status: SERVFAIL" dig.out.ns4.test$n.2 > /dev/null && ret=1
|
||||
grep "flags:[^;]* ad[^;]*;" dig.out.ns4.test$n.2 > /dev/null || ret=1
|
||||
|
||||
echo_i "killing ns4 with SIGTERM"
|
||||
$KILL -TERM "$(cat ns4/named.pid)"
|
||||
kill -TERM "$(cat ns4/named.pid)"
|
||||
rm -f named.pid
|
||||
|
||||
echo_i "sleeping for an additional 4 seconds for ns4 to fully shutdown"
|
||||
@@ -2320,7 +2331,7 @@ n=$((n+1))
|
||||
echo_i "testing loading out of bounds lifetime from NTA file ($n)"
|
||||
|
||||
echo_i "killing ns4 with SIGTERM"
|
||||
$KILL -TERM "$(cat ns4/named.pid)"
|
||||
kill -TERM "$(cat ns4/named.pid)"
|
||||
rm -f ns4/named.pid
|
||||
|
||||
echo_i "sleeping for an additional 4 seconds for ns4 to fully shutdown"
|
||||
@@ -2882,8 +2893,8 @@ awk '{
|
||||
for (i=1;i<7;i++) printf("%s ", $i);
|
||||
for (i=7;i<=NF;i++) printf("%s", $i);
|
||||
printf("\n");
|
||||
}' < ns1/dsset-algroll$TP > canonical2.$n || ret=1
|
||||
$DIFF -b canonical1.$n canonical2.$n > /dev/null 2>&1 || ret=1
|
||||
}' < ns1/dsset-algroll. > canonical2.$n || ret=1
|
||||
diff -b canonical1.$n canonical2.$n > /dev/null 2>&1 || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
@@ -2942,7 +2953,7 @@ ret=0
|
||||
dig_with_answeropts +nottlid nosign.example ns @10.53.0.3 | \
|
||||
grep RRSIG | sed 's/[ ][ ]*/ /g' > dig.out.ns3.test$n 2>&1
|
||||
# the NS RRSIG should not be changed
|
||||
$DIFF nosign.before dig.out.ns3.test$n > /dev/null|| ret=1
|
||||
diff nosign.before dig.out.ns3.test$n > /dev/null|| ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
@@ -3460,7 +3471,7 @@ echo send
|
||||
dig_with_opts +noall +answer @10.53.0.2 cds cds-update.secure > dig.out.test$n
|
||||
lines=$(awk '$4 == "CDS" {print}' dig.out.test$n | wc -l)
|
||||
test "${lines:-10}" -eq 1 || ret=1
|
||||
lines=$(tr -d '\r' < dig.out.test$n | awk '$4 == "CDS" && $5 == "0" && $6 == "0" && $7 == "0" && $8 == "00" {print}' | wc -l)
|
||||
lines=$(awk '$4 == "CDS" && $5 == "0" && $6 == "0" && $7 == "0" && $8 == "00" {print}' dig.out.test$n | wc -l)
|
||||
test "$lines" -eq 1 || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
@@ -3532,7 +3543,7 @@ lines=$(awk -v id="${keyid}" '$4 == "RRSIG" && $5 == "CDS" && $11 == id {print}'
|
||||
test "$lines" -eq 1 || ret=1
|
||||
lines=$(awk '$4 == "CDS" {print}' dig.out.test$n | wc -l)
|
||||
test "$lines" -eq 1 || ret=1
|
||||
lines=$(tr -d '\r' < dig.out.test$n | awk '$4 == "CDS" && $5 == "0" && $6 == "0" && $7 == "0" && $8 == "00" {print}' | wc -l)
|
||||
lines=$(awk '$4 == "CDS" && $5 == "0" && $6 == "0" && $7 == "0" && $8 == "00" {print}' dig.out.test$n | wc -l)
|
||||
test "$lines" -eq 1 || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
@@ -3673,7 +3684,7 @@ echo send
|
||||
dig_with_opts +noall +answer @10.53.0.2 cdnskey cdnskey-update.secure > dig.out.test$n
|
||||
lines=$(awk '$4 == "CDNSKEY" {print}' dig.out.test$n | wc -l)
|
||||
test "${lines:-10}" -eq 1 || ret=1
|
||||
lines=$(tr -d '\r' < dig.out.test$n | awk '$4 == "CDNSKEY" && $5 == "0" && $6 == "3" && $7 == "0" && $8 == "AA==" {print}' | wc -l)
|
||||
lines=$(awk '$4 == "CDNSKEY" && $5 == "0" && $6 == "3" && $7 == "0" && $8 == "AA==" {print}' dig.out.test$n | wc -l)
|
||||
test "${lines:-10}" -eq 1 || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
@@ -3750,7 +3761,7 @@ lines=$(awk -v id="${keyid}" '$4 == "RRSIG" && $5 == "CDNSKEY" && $11 == id {pri
|
||||
test "$lines" -eq 1 || ret=1
|
||||
lines=$(awk '$4 == "CDNSKEY" {print}' dig.out.test$n | wc -l)
|
||||
test "$lines" -eq 1 || ret=1
|
||||
lines=$(tr -d '\r' < dig.out.test$n | awk '$4 == "CDNSKEY" && $5 == "0" && $6 == "3" && $7 == "0" && $8 == "AA==" {print}' | wc -l)
|
||||
lines=$(awk '$4 == "CDNSKEY" && $5 == "0" && $6 == "3" && $7 == "0" && $8 == "AA==" {print}' dig.out.test$n | wc -l)
|
||||
test "${lines:-10}" -eq 1 || ret=1
|
||||
n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
|
||||
@@ -11,7 +11,6 @@
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
import os
|
||||
import shutil
|
||||
import subprocess
|
||||
|
||||
@@ -36,8 +35,3 @@ def gnutls_cli_executable():
|
||||
pytest.skip('gnutls-cli does not support the --logfile option')
|
||||
|
||||
return executable
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def named_tlsport():
|
||||
return int(os.environ.get('TLSPORT', '853'))
|
||||
|
||||
@@ -21,6 +21,8 @@ import pytest
|
||||
pytest.importorskip('dns')
|
||||
import dns.exception
|
||||
import dns.message
|
||||
import dns.name
|
||||
import dns.rdataclass
|
||||
import dns.rdatatype
|
||||
|
||||
|
||||
|
||||
@@ -19,8 +19,8 @@ zonefile=root.db
|
||||
|
||||
(cd ../ns2 && $SHELL sign.sh)
|
||||
|
||||
cp ../ns2/dsset-good$TP .
|
||||
cp ../ns2/dsset-bad$TP .
|
||||
cp ../ns2/dsset-good. .
|
||||
cp ../ns2/dsset-bad. .
|
||||
|
||||
key1=`$KEYGEN -q -a RSASHA1 -b 1024 -n zone $zone`
|
||||
key2=`$KEYGEN -q -a RSASHA1 -b 2048 -n zone -f KSK $zone`
|
||||
|
||||
@@ -31,8 +31,8 @@ cat $infile2 $keyname21.key $keyname22.key >$zonefile2
|
||||
$SIGNER -P -g -o $zone1 $zonefile1 > /dev/null
|
||||
$SIGNER -P -g -o $zone2 $zonefile2 > /dev/null
|
||||
|
||||
DSFILENAME1=dsset-${zone1}${TP}
|
||||
DSFILENAME2=dsset-${zone2}${TP}
|
||||
DSFILENAME1=dsset-${zone1}.
|
||||
DSFILENAME2=dsset-${zone2}.
|
||||
$DSFROMKEY -a SHA-256 $keyname12 > $DSFILENAME1
|
||||
$DSFROMKEY -a SHA-256 $keyname22 > $DSFILENAME2
|
||||
|
||||
|
||||
@@ -67,7 +67,7 @@ create_zone(sample_instance_t *const inst, dns_name_t *const name,
|
||||
|
||||
zone_argv[0] = inst->db_name;
|
||||
|
||||
result = dns_zone_create(&raw, inst->mctx);
|
||||
result = dns_zone_create(&raw, inst->mctx, 0); /* FIXME */
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
log_write(ISC_LOG_ERROR, "create_zone: dns_zone_create -> %s\n",
|
||||
isc_result_totext(result));
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
edda 2800 0001 0000 0001 0000 0972 7361
|
||||
7368 6132 3536 0765 7861 6d70 6c65 0000
|
||||
0600 01c0 0c00 3000 0100 0001 2c01 0801
|
||||
0003 0803 0100 0100 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 0000 0000 0000 0000 0000
|
||||
0000 0000 0000 00
|
||||
@@ -0,0 +1,35 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# SPDX-License-Identifier: MPL-2.0
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
#
|
||||
# See the COPYRIGHT file distributed with this work for additional
|
||||
# information regarding copyright ownership.
|
||||
|
||||
# shellcheck source=conf.sh
|
||||
. ../conf.sh
|
||||
|
||||
set -e
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f dsset-*
|
||||
rm -f pin
|
||||
rm -f keyfromlabel.out.*
|
||||
rm -f pkcs11-tool.out.*
|
||||
rm -f signer.out.*
|
||||
rm -f ns1/*.example.db ns1/*.example.db.signed
|
||||
rm -f ns1/*.kskid1 ns1/*.kskid2 ns1/*.zskid1 ns1/*.zskid2
|
||||
rm -f ns1/dig.out.*
|
||||
rm -f ns1/K*
|
||||
rm -f ns1/named.conf ns1/named.run ns1/named.memstats
|
||||
rm -f ns1/update.cmd.*
|
||||
rm -f ns1/update.log.*
|
||||
rm -f ns1/verify.out.*
|
||||
rm -f ns1/zone.*.signed.jnl ns1/zone.*.signed.jbk
|
||||
|
||||
softhsm2-util --delete-token --token "softhsm2-engine_pkcs11" >/dev/null 2>&1 || echo_i "softhsm2-engine_pkcs11 token not found for cleaning"
|
||||
@@ -0,0 +1 @@
|
||||
-E pkcs11 -D engine_pkcs11-ns1 -X named.lock -m record -c named.conf -d 99 -U 4 -T maxcachesize=2097152
|
||||
@@ -0,0 +1,36 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* SPDX-License-Identifier: MPL-2.0
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.1;
|
||||
notify-source 10.53.0.1;
|
||||
transfer-source 10.53.0.1;
|
||||
port @PORT@;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
dnssec-validation no;
|
||||
notify no;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-sha256;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.1 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
||||
};
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user