Compare commits
108
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
58d4e6452a | ||
|
|
779ec9984d | ||
|
|
8181ca0d97 | ||
|
|
bbe6cf8aed | ||
|
|
d72d9d5858 | ||
|
|
70fcea59c5 | ||
|
|
f69f6d9d65 | ||
|
|
a8ac2df240 | ||
|
|
ddf3b86e0b | ||
|
|
9644984506 | ||
|
|
228aed11b2 | ||
|
|
1cac29a57c | ||
|
|
7bd0a3c6a2 | ||
|
|
013e87384b | ||
|
|
29173e699a | ||
|
|
598a07a616 | ||
|
|
9a3a8f524c | ||
|
|
71083d9a1a | ||
|
|
3eae25e2ef | ||
|
|
88e814e0e4 | ||
|
|
72f2207fc5 | ||
|
|
6439173dae | ||
|
|
d92f5ce987 | ||
|
|
960012de77 | ||
|
|
484b950181 | ||
|
|
28aae970ea | ||
|
|
bc892cc381 | ||
|
|
794bd47f6d | ||
|
|
ae47f254c7 | ||
|
|
f149d3087f | ||
|
|
1ed281f48e | ||
|
|
77092470f0 | ||
|
|
0b51f38570 | ||
|
|
a4da60cb18 | ||
|
|
95dd83a7bc | ||
|
|
cbe6d5d7e1 | ||
|
|
cbba858415 | ||
|
|
916d7e4d87 | ||
|
|
eb4ad81ccb | ||
|
|
610e44c0e1 | ||
|
|
abf344768f | ||
|
|
aa6802d74b | ||
|
|
cf77da1598 | ||
|
|
db54e2dd5c | ||
|
|
0c0c7ae630 | ||
|
|
e1b256f3b7 | ||
|
|
abc4784748 | ||
|
|
779ceee98a | ||
|
|
aa3ed1b594 | ||
|
|
adb73a5926 | ||
|
|
981af8798a | ||
|
|
eae6301d93 | ||
|
|
1f6c540eb5 | ||
|
|
8c99375816 | ||
|
|
d5eb49141a | ||
|
|
0dce2c6123 | ||
|
|
242af366a8 | ||
|
|
b0ef27d2d7 | ||
|
|
3024c922ff | ||
|
|
3873426088 | ||
|
|
df79d703ed | ||
|
|
8cd91651ca | ||
|
|
5af98b88f1 | ||
|
|
26cde354f2 | ||
|
|
11496d8be5 | ||
|
|
855af5daaa | ||
|
|
d932ee4853 | ||
|
|
d1c848f8ca | ||
|
|
863cda8fd0 | ||
|
|
b40e492c83 | ||
|
|
718be0d6a2 | ||
|
|
390bdd73d2 | ||
|
|
01b8938dcb | ||
|
|
c149639f1a | ||
|
|
446f5852c6 | ||
|
|
d4b59ed307 | ||
|
|
9ab672f69e | ||
|
|
05e61fc99c | ||
|
|
4c8eb049f1 | ||
|
|
c66c4e78c9 | ||
|
|
26c0f0424c | ||
|
|
bd575ac7ec | ||
|
|
798f680440 | ||
|
|
ed9062cb49 | ||
|
|
938a013c39 | ||
|
|
f9e63ab5d9 | ||
|
|
83f94c2255 | ||
|
|
84e7b77ba8 | ||
|
|
43da4bdf27 | ||
|
|
c6076cafe2 | ||
|
|
37ab9b45c7 | ||
|
|
76c46f0fd3 | ||
|
|
6de0ec806a | ||
|
|
1ac5fa17b0 | ||
|
|
ba6db14388 | ||
|
|
65c60ad5eb | ||
|
|
cee7943a1b | ||
|
|
4bdc863453 | ||
|
|
c92cfa7eae | ||
|
|
511687b15b | ||
|
|
6950929fa4 | ||
|
|
4d588491b1 | ||
|
|
a7021ba3f7 | ||
|
|
758ea2a01d | ||
|
|
522f945e0f | ||
|
|
857d8059b1 | ||
|
|
f9d2229db9 | ||
|
|
ed420395f8 |
@@ -1,3 +1,49 @@
|
||||
--- 9.6-ESV-R8b1 released ---
|
||||
|
||||
3354. [func] Improve OpenSSL error logging. [RT #29932]
|
||||
|
||||
3352. [bug] Ensure that learned server attributes timeout of the
|
||||
adb cache. [RT #29856]
|
||||
|
||||
3350. [bug] Memory read overrun in isc___mem_reallocate if
|
||||
ISC_MEM_DEBUGCTX memory debugging flag is set.
|
||||
[RT #30240]
|
||||
|
||||
3348. [bug] Prevent RRSIG data from being cached if a negative
|
||||
record matching the covering type exists at a higher
|
||||
trust level. Such data already can't be retrieved from
|
||||
the cache since change 3218 -- this prevents it
|
||||
being inserted into the cache as well. [RT #26809]
|
||||
|
||||
3346. [security] Bad-cache data could be used before it was
|
||||
initialized, causing an assert. [RT #30025]
|
||||
|
||||
3343. [bug] Relax isc_random_jitter() REQUIRE tests. [RT #29821]
|
||||
|
||||
3342. [bug] Change #3314 broke saving of stub zones to disk
|
||||
resulting in excessive cpu usage in some cases.
|
||||
[RT #29952]
|
||||
|
||||
3337. [bug] Change #3294 broke support for the multiple keys
|
||||
in controls. [RT #29694]
|
||||
|
||||
3335. [func] nslookup: return a nonzero exit code when unable
|
||||
to get an answer. [RT #29492]
|
||||
|
||||
3332. [bug] Re-use cached DS rrsets if possible. [RT #29446]
|
||||
|
||||
3331. [security] dns_rdataslab_fromrdataset could produce bad
|
||||
rdataslabs. [RT #29644]
|
||||
|
||||
3329. [bug] Handle RRSIG signer-name case consistently: We
|
||||
generate RRSIG records with the signer-name in
|
||||
lower case. We accept them with any case, but if
|
||||
they fail to validate, we try again in lower case.
|
||||
[RT #27451]
|
||||
|
||||
3328. [bug] Fixed inconsistent data checking in dst_parse.c.
|
||||
[RT #29401]
|
||||
|
||||
--- 9.6-ESV-R7 released ---
|
||||
|
||||
3318. [tuning] Reduce the amount of work performed while holding a
|
||||
|
||||
@@ -48,9 +48,14 @@ BIND 9
|
||||
For up-to-date release notes and errata, see
|
||||
http://www.isc.org/software/bind9/releasenotes
|
||||
|
||||
BIND 9.6-ESV-R8 (Extended Support Version)
|
||||
|
||||
BIND 9.6-ESV-R8 includes several bug fixes and patches security
|
||||
flaws described in CVE-2012-1667 and CVE-2012-3817.
|
||||
|
||||
BIND 9.6-ESV-R7 (Extended Support Version)
|
||||
|
||||
BIND 9.4-ESV-R7 is a maintenance release, fixing bugs in BIND
|
||||
BIND 9.6-ESV-R7 is a maintenance release, fixing bugs in BIND
|
||||
9.6-ESV-R6.
|
||||
|
||||
BIND 9.6-ESV-R6 (Extended Support Version)
|
||||
@@ -60,7 +65,7 @@ BIND 9.6-ESV-R6 (Extended Support Version)
|
||||
|
||||
BIND 9.6-ESV-R5 (Extended Support Version)
|
||||
|
||||
BIND 9.4-ESV-R5 is a maintenance release, fixing bugs in BIND
|
||||
BIND 9.6-ESV-R5 is a maintenance release, fixing bugs in BIND
|
||||
9.6-ESV-R4.
|
||||
|
||||
BIND 9.6.3/BIND 9.6-ESV-R4
|
||||
|
||||
+8
-1
@@ -57,6 +57,7 @@ static isc_boolean_t in_use = ISC_FALSE;
|
||||
static char defclass[MXRD] = "IN";
|
||||
static char deftype[MXRD] = "A";
|
||||
static isc_event_t *global_event = NULL;
|
||||
static int query_error = 1, print_error = 0;
|
||||
|
||||
static char domainopt[DNS_NAME_MAXTEXT];
|
||||
|
||||
@@ -406,6 +407,9 @@ isc_result_t
|
||||
printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
char servtext[ISC_SOCKADDR_FORMATSIZE];
|
||||
|
||||
/* I've we've gotten this far, we've reached a server. */
|
||||
query_error = 0;
|
||||
|
||||
debug("printmessage()");
|
||||
|
||||
isc_sockaddr_format(&query->sockaddr, servtext, sizeof(servtext));
|
||||
@@ -433,6 +437,9 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
(msg->rcode != dns_rcode_nxdomain) ? nametext :
|
||||
query->lookup->textname, rcode_totext(msg->rcode));
|
||||
debug("returning with rcode == 0");
|
||||
|
||||
/* the lookup failed */
|
||||
print_error |= 1;
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
@@ -903,5 +910,5 @@ main(int argc, char **argv) {
|
||||
destroy_libs();
|
||||
isc_app_finish();
|
||||
|
||||
return (0);
|
||||
return (query_error | print_error);
|
||||
}
|
||||
|
||||
@@ -373,8 +373,10 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||
if (result == ISC_R_SUCCESS)
|
||||
break;
|
||||
isc_mem_put(listener->mctx, secret.rstart, REGION_SIZE(secret));
|
||||
log_invalid(&conn->ccmsg, result);
|
||||
goto cleanup;
|
||||
if (result != ISCCC_R_BADAUTH) {
|
||||
log_invalid(&conn->ccmsg, result);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
if (key == NULL) {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2006-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2006-2008, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -84,16 +84,19 @@ static const char *nsstats_desc[dns_nsstatscounter_max];
|
||||
static const char *resstats_desc[dns_resstatscounter_max];
|
||||
static const char *zonestats_desc[dns_zonestatscounter_max];
|
||||
static const char *sockstats_desc[isc_sockstatscounter_max];
|
||||
static const char *dnssecstats_desc[dns_dnssecstats_max];
|
||||
#ifdef HAVE_LIBXML2
|
||||
static const char *nsstats_xmldesc[dns_nsstatscounter_max];
|
||||
static const char *resstats_xmldesc[dns_resstatscounter_max];
|
||||
static const char *zonestats_xmldesc[dns_zonestatscounter_max];
|
||||
static const char *sockstats_xmldesc[isc_sockstatscounter_max];
|
||||
static const char *dnssecstats_xmldesc[dns_dnssecstats_max];
|
||||
#else
|
||||
#define nsstats_xmldesc NULL
|
||||
#define resstats_xmldesc NULL
|
||||
#define zonestats_xmldesc NULL
|
||||
#define sockstats_xmldesc NULL
|
||||
#define dnssecstats_xmldesc NULL
|
||||
#endif /* HAVE_LIBXML2 */
|
||||
|
||||
#define TRY0(a) do { xmlrc = (a); if (xmlrc < 0) goto error; } while(0)
|
||||
@@ -107,6 +110,7 @@ static int nsstats_index[dns_nsstatscounter_max];
|
||||
static int resstats_index[dns_resstatscounter_max];
|
||||
static int zonestats_index[dns_zonestatscounter_max];
|
||||
static int sockstats_index[isc_sockstatscounter_max];
|
||||
static int dnssecstats_index[dns_dnssecstats_max];
|
||||
|
||||
static inline void
|
||||
set_desc(int counter, int maxcounter, const char *fdesc, const char **fdescs,
|
||||
@@ -408,6 +412,33 @@ init_desc(void) {
|
||||
"FDwatchRecvErr");
|
||||
INSIST(i == isc_sockstatscounter_max);
|
||||
|
||||
/* Initialize DNSSEC statistics */
|
||||
for (i = 0; i < dns_dnssecstats_max; i++)
|
||||
dnssecstats_desc[i] = NULL;
|
||||
#ifdef HAVE_LIBXML2
|
||||
for (i = 0; i < dns_dnssecstats_max; i++)
|
||||
dnssecstats_xmldesc[i] = NULL;
|
||||
#endif
|
||||
|
||||
#define SET_DNSSECSTATDESC(counterid, desc, xmldesc) \
|
||||
do { \
|
||||
set_desc(dns_dnssecstats_ ## counterid, \
|
||||
dns_dnssecstats_max, \
|
||||
desc, dnssecstats_desc,\
|
||||
xmldesc, dnssecstats_xmldesc); \
|
||||
dnssecstats_index[i++] = dns_dnssecstats_ ## counterid; \
|
||||
} while (0)
|
||||
|
||||
i = 0;
|
||||
SET_DNSSECSTATDESC(asis, "dnssec validation success with signer "
|
||||
"\"as is\"", "DNSSECasis");
|
||||
SET_DNSSECSTATDESC(downcase, "dnssec validation success with signer "
|
||||
"lower cased", "DNSSECdowncase");
|
||||
SET_DNSSECSTATDESC(wildcard, "dnssec validation of wildcard signature",
|
||||
"DNSSECwild");
|
||||
SET_DNSSECSTATDESC(fail, "dnssec validation failures", "DNSSECfail");
|
||||
INSIST(i == dns_dnssecstats_max);
|
||||
|
||||
/* Sanity check */
|
||||
for (i = 0; i < dns_nsstatscounter_max; i++)
|
||||
INSIST(nsstats_desc[i] != NULL);
|
||||
@@ -417,6 +448,8 @@ init_desc(void) {
|
||||
INSIST(zonestats_desc[i] != NULL);
|
||||
for (i = 0; i < isc_sockstatscounter_max; i++)
|
||||
INSIST(sockstats_desc[i] != NULL);
|
||||
for (i = 0; i < dns_dnssecstats_max; i++)
|
||||
INSIST(dnssecstats_desc[i] != NULL);
|
||||
#ifdef HAVE_LIBXML2
|
||||
for (i = 0; i < dns_nsstatscounter_max; i++)
|
||||
INSIST(nsstats_xmldesc[i] != NULL);
|
||||
@@ -426,6 +459,8 @@ init_desc(void) {
|
||||
INSIST(zonestats_xmldesc[i] != NULL);
|
||||
for (i = 0; i < isc_sockstatscounter_max; i++)
|
||||
INSIST(sockstats_xmldesc[i] != NULL);
|
||||
for (i = 0; i < dns_dnssecstats_max; i++)
|
||||
INSIST(dnssecstats_xmldesc[i] != NULL);
|
||||
#endif
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
+25
-15
@@ -179,7 +179,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
if (p == NULL) {
|
||||
t_info("getcwd failed %d\n", errno);
|
||||
++*nprobs;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = dst_key_fromfile(name1, id1, alg, type, current, mctx, &key1);
|
||||
@@ -187,7 +187,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_key_fromfile(%d) returned: %s\n",
|
||||
alg, dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = dst_key_fromfile(name2, id2, alg, type, current, mctx, &key2);
|
||||
@@ -195,7 +195,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_key_fromfile(%d) returned: %s\n",
|
||||
alg, dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = isc_file_mktemplate("/tmp/", tmp, sizeof(tmp));
|
||||
@@ -203,7 +203,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("isc_file_mktemplate failed %s\n",
|
||||
isc_result_totext(ret));
|
||||
++*nprobs;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = isc_dir_createunique(tmp);
|
||||
@@ -211,7 +211,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("isc_dir_createunique failed %s\n",
|
||||
isc_result_totext(ret));
|
||||
++*nprobs;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = dst_key_tofile(key1, type, tmp);
|
||||
@@ -219,7 +219,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_key_tofile(%d) returned: %s\n",
|
||||
alg, dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = dst_key_tofile(key2, type, tmp);
|
||||
@@ -227,7 +227,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_key_tofile(%d) returned: %s\n",
|
||||
alg, dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
cleandir(tmp);
|
||||
@@ -238,7 +238,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_computesecret() returned: %s\n",
|
||||
dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
isc_buffer_init(&b2, array2, sizeof(array2));
|
||||
@@ -247,7 +247,7 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
t_info("dst_computesecret() returned: %s\n",
|
||||
dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
isc_buffer_usedregion(&b1, &r1);
|
||||
@@ -256,11 +256,14 @@ dh(dns_name_t *name1, int id1, dns_name_t *name2, int id2, isc_mem_t *mctx,
|
||||
{
|
||||
t_info("computed secrets don't match\n");
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
dst_key_free(&key1);
|
||||
dst_key_free(&key2);
|
||||
cleanup:
|
||||
if (key1 != NULL)
|
||||
dst_key_free(&key1);
|
||||
if (key2 != NULL)
|
||||
dst_key_free(&key2);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -330,12 +333,14 @@ generate(int alg, isc_mem_t *mctx, int size, int *nfails) {
|
||||
t_info("dst_key_generate(%d) returned: %s\n", alg,
|
||||
dst_result_totext(ret));
|
||||
++*nfails;
|
||||
return;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (alg != DST_ALG_DH)
|
||||
use(key, mctx, ISC_R_SUCCESS, nfails);
|
||||
dst_key_free(&key);
|
||||
cleanup:
|
||||
if (key != NULL)
|
||||
dst_key_free(&key);
|
||||
}
|
||||
|
||||
#define DBUFSIZ 25
|
||||
@@ -787,14 +792,20 @@ t2_sigchk(char *datapath, char *sigpath, char *keyname,
|
||||
if (isc_result != ISC_R_SUCCESS) {
|
||||
t_info("dst_context_create returned %s\n",
|
||||
isc_result_totext(isc_result));
|
||||
(void) free(data);
|
||||
dst_key_free(&key);
|
||||
++*nfails;
|
||||
return;
|
||||
}
|
||||
isc_result = dst_context_adddata(ctx, &datareg);
|
||||
if (isc_result != ISC_R_SUCCESS) {
|
||||
t_info("dst_context_adddata returned %s\n",
|
||||
isc_result_totext(isc_result));
|
||||
(void) free(data);
|
||||
dst_context_destroy(&ctx);
|
||||
dst_key_free(&key);
|
||||
++*nfails;
|
||||
return;
|
||||
}
|
||||
isc_result = dst_context_verify(ctx, &sigreg);
|
||||
if ( ((exp_res == 0) && (isc_result != ISC_R_SUCCESS)) ||
|
||||
@@ -803,7 +814,6 @@ t2_sigchk(char *datapath, char *sigpath, char *keyname,
|
||||
t_info("dst_context_verify returned %s, expected %s\n",
|
||||
isc_result_totext(isc_result),
|
||||
expected_result);
|
||||
dst_context_destroy(&ctx);
|
||||
++*nfails;
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2008, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2008, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2008, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -46,7 +46,7 @@ CHECKCONF=$TOP/bin/check/named-checkconf
|
||||
SUBDIRS="acl allow_query builtin cacheclean checkconf checknames checkzone
|
||||
database dlv dlz dname dnssec forward glue ixfr
|
||||
limits logfileconfig lwresd masterfile masterformat notify
|
||||
nsupdate pending resolver rrsetorder sortlist stub tkey
|
||||
nsupdate pending resolver rndc rrsetorder sortlist stub tkey
|
||||
unknown upforwd views xfer xferquota zonechecks"
|
||||
|
||||
# PERL will be an empty string if no perl interpreter was found.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -44,3 +44,5 @@ rm -f signer/example.db
|
||||
rm -f ns2/algroll.db
|
||||
rm -f signer/example.db.after signer/example.db.before
|
||||
rm -f signer/example.db.changed
|
||||
rm -f ns3/lower.example.db ns3/upper.example.db ns3/upper.example.db.lower
|
||||
rm -f ns3/secure.below-cname.example.db
|
||||
|
||||
@@ -119,3 +119,9 @@ ns.insecure.below-cname A 10.53.0.3
|
||||
|
||||
secure.below-cname NS ns.secure.below-cname
|
||||
ns.secure.below-cname A 10.53.0.3
|
||||
|
||||
upper NS ns.upper
|
||||
ns.upper A 10.53.0.3
|
||||
|
||||
LOWER NS NS.LOWER
|
||||
NS.LOWER A 10.53.0.3
|
||||
|
||||
@@ -32,7 +32,7 @@ zonefile=example.db
|
||||
|
||||
for subdomain in secure bogus dynamic keyless nsec3 optout nsec3-unknown \
|
||||
optout-unknown multiple rsasha256 rsasha512 update-nsec3 \
|
||||
secure.below-cname expired
|
||||
secure.below-cname expired upper lower
|
||||
do
|
||||
cp ../ns3/keyset-$subdomain.example. .
|
||||
done
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
; Copyright (C) 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: lower.example.db.in,v 1.1.2.1 2012/01/17 08:31:00 marka Exp $
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA MNAME1. . (
|
||||
2012042407 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
@ NS NS
|
||||
NS A 10.53.0.3
|
||||
@@ -188,4 +188,14 @@ zone "secure.below-cname.example" {
|
||||
file "secure.below-cname.example.db.signed";
|
||||
};
|
||||
|
||||
zone "upper.example" {
|
||||
type master;
|
||||
file "upper.example.db.signed";
|
||||
};
|
||||
|
||||
zone "LOWER.EXAMPLE" {
|
||||
type master;
|
||||
file "lower.example.db.signed";
|
||||
};
|
||||
|
||||
include "trusted.conf";
|
||||
|
||||
@@ -283,3 +283,31 @@ zonefile=secure.below-cname.example.db
|
||||
keyname=`$KEYGEN -r $RANDFILE -a RSASHA1 -b 1024 -n zone $zone`
|
||||
cat $infile $keyname.key >$zonefile
|
||||
$SIGNER -P -r $RANDFILE -o $zone $zonefile > /dev/null 2>&1
|
||||
|
||||
#
|
||||
# A zone where the signer's name has been forced to uppercase.
|
||||
#
|
||||
zone="upper.example."
|
||||
infile="upper.example.db.in"
|
||||
zonefile="upper.example.db"
|
||||
lower="upper.example.db.lower"
|
||||
signedfile="upper.example.db.signed"
|
||||
kskname=`$KEYGEN -r $RANDFILE -a RSASHA1 -b 1024 $zone`
|
||||
zskname=`$KEYGEN -r $RANDFILE -a RSASHA1 -b 1024 -f KSK $zone`
|
||||
cat $infile $kskname.key $zskname.key > $zonefile
|
||||
$SIGNER -P -r $RANDFILE -o $zone -f $lower $zonefile > /dev/null 2>&1
|
||||
$CHECKZONE -D upper.example $lower 2>&- | \
|
||||
sed '/RRSIG/s/ upper.example. / UPPER.EXAMPLE. /' > $signedfile
|
||||
|
||||
#
|
||||
# Check that the signer's name is in lower case when zone name is in
|
||||
# upper case.
|
||||
#
|
||||
zone="LOWER.EXAMPLE."
|
||||
infile="lower.example.db.in"
|
||||
zonefile="lower.example.db"
|
||||
signedfile="lower.example.db.signed"
|
||||
kskname=`$KEYGEN -r $RANDFILE -a RSASHA1 -b 1024 $zone`
|
||||
zskname=`$KEYGEN -r $RANDFILE -a RSASHA1 -b 1024 -f KSK $zone`
|
||||
cat $infile $kskname.key $zskname.key > $zonefile
|
||||
$SIGNER -P -r $RANDFILE -o $zone $zonefile > /dev/null 2>&1
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
; Copyright (C) 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: upper.example.db.in,v 1.1.2.1 2012/01/17 08:31:00 marka Exp $
|
||||
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
2012042407 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
@ NS ns
|
||||
ns A 10.53.0.3
|
||||
@@ -1129,5 +1129,25 @@ n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:testing legacy upper case signer name validation ($n)"
|
||||
ret=0
|
||||
$DIG +tcp +dnssec -p 5300 +noadd +noauth soa upper.example @10.53.0.4 \
|
||||
> dig.out.ns4.test$n 2>&1
|
||||
grep 'flags:.* ad;' dig.out.ns4.test$n >/dev/null || ret=1
|
||||
grep 'RRSIG.*SOA.* UPPER\.EXAMPLE\. ' dig.out.ns4.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:testing that we lower case signer name ($n)"
|
||||
ret=0
|
||||
$DIG +tcp +dnssec -p 5300 +noadd +noauth soa LOWER.EXAMPLE @10.53.0.4 \
|
||||
> dig.out.ns4.test$n 2>&1
|
||||
grep 'flags:.* ad;' dig.out.ns4.test$n >/dev/null || ret=1
|
||||
grep 'RRSIG.*SOA.* lower\.example\. ' dig.out.ns4.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -25,7 +25,7 @@ rm -f dig.*.foo.*
|
||||
rm -f dig.*.bar.*
|
||||
rm -f dig.*.prime.*
|
||||
rm -f ns4/tld.db
|
||||
rm -r ns6/to-be-removed.tld.db ns6/to-be-removed.tld.db.jnl
|
||||
rm -f ns6/to-be-removed.tld.db ns6/to-be-removed.tld.db.jnl
|
||||
rm -f ns6/K*
|
||||
rm -f ns6/example.net.db.signed ns6/example.net.db
|
||||
rm -f ns6/keyset-example.net. ns6/dsset-example.net.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: clean.sh,v 1.2 2011/03/21 18:06:06 each Exp $
|
||||
|
||||
rm -f ns2/*.db ns2/*.jnl
|
||||
rm -f ns2/session.key
|
||||
rm -f ns2/named.memstats
|
||||
@@ -0,0 +1,63 @@
|
||||
/*
|
||||
* Copyright (C) 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named.conf,v 1.4 2011/06/10 01:32:37 each Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.2; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
};
|
||||
|
||||
key rndc_key {
|
||||
secret "1234abcd8765";
|
||||
algorithm hmac-md5;
|
||||
};
|
||||
|
||||
key secondkey {
|
||||
secret "abcd1234abcd8765";
|
||||
algorithm hmac-md5;
|
||||
};
|
||||
|
||||
controls {
|
||||
inet 10.53.0.2 port 9953 allow { any; } keys { rndc_key; secondkey; };
|
||||
};
|
||||
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
|
||||
zone "nil" {
|
||||
type master;
|
||||
file "nil.db";
|
||||
ixfr-from-differences yes;
|
||||
};
|
||||
|
||||
zone "other" {
|
||||
type master;
|
||||
file "other.db";
|
||||
};
|
||||
|
||||
zone "static" {
|
||||
type master;
|
||||
file "static.db";
|
||||
};
|
||||
@@ -0,0 +1,26 @@
|
||||
/*
|
||||
* Copyright (C) 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: rndc.conf,v 1.5 2007/06/19 23:47:01 tbox Exp $ */
|
||||
|
||||
options {
|
||||
default-key "secondkey";
|
||||
};
|
||||
|
||||
key secondkey {
|
||||
secret "abcd1234abcd8765";
|
||||
algorithm hmac-md5;
|
||||
};
|
||||
@@ -0,0 +1,23 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: setup.sh,v 1.2 2011/03/21 18:06:06 each Exp $
|
||||
|
||||
sh clean.sh
|
||||
|
||||
sh ../genzone.sh 2 >ns2/nil.db
|
||||
sh ../genzone.sh 2 >ns2/other.db
|
||||
sh ../genzone.sh 2 >ns2/static.db
|
||||
@@ -0,0 +1,39 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: tests.sh,v 1.4 2011/06/10 01:32:37 each Exp $
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
RNDCCMD="$RNDC -s 10.53.0.2 -p 9953 -c ../common/rndc.conf"
|
||||
|
||||
status=0
|
||||
|
||||
echo "I:test using primary key"
|
||||
ret=0
|
||||
$RNDCCMD status > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:test using second key"
|
||||
ret=0
|
||||
$RNDC -s 10.53.0.2 -p 9953 -c ns2/secondkey.conf status > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl -w
|
||||
#
|
||||
# Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -21,14 +21,24 @@ SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
status=0
|
||||
echo "I:check that the stub zone has been saved to disk"
|
||||
for i in 1 2 3 4 5 6 7 8 9 20
|
||||
do
|
||||
[ -f ns3/child.example.st ] && break
|
||||
sleep 1
|
||||
done
|
||||
[ -f ns3/child.example.st ] || { status=1; echo "I:failed"; }
|
||||
|
||||
echo "I:trying an axfr that should be denied (NOTAUTH)"
|
||||
for pass in 1 2
|
||||
do
|
||||
|
||||
echo "I:trying an axfr that should be denied (NOTAUTH) (pass=$pass)"
|
||||
ret=0
|
||||
$DIG +tcp data.child.example. @10.53.0.3 axfr -p 5300 > dig.out.ns3 || ret=1
|
||||
$DIG +tcp child.example. @10.53.0.3 axfr -p 5300 > dig.out.ns3 || ret=1
|
||||
grep "; Transfer failed." dig.out.ns3 > /dev/null || ret=1
|
||||
[ $ret = 0 ] || { status=1; echo "I:failed"; }
|
||||
|
||||
echo "I:look for stub zone data without recursion (should not be found)"
|
||||
echo "I:look for stub zone data without recursion (should not be found) (pass=$pass)"
|
||||
for i in 1 2 3 4 5 6 7 8 9
|
||||
do
|
||||
ret=0
|
||||
@@ -41,11 +51,20 @@ done
|
||||
$PERL ../digcomp.pl knowngood.dig.out.norec dig.out.ns3 || ret=1
|
||||
[ $ret = 0 ] || { status=1; echo "I:failed"; }
|
||||
|
||||
echo "I:look for stub zone data with recursion (should be found)"
|
||||
echo "I:look for stub zone data with recursion (should be found) (pass=$pass)"
|
||||
ret=0
|
||||
$DIG +tcp data.child.example. @10.53.0.3 txt -p 5300 > dig.out.ns3 || ret=1
|
||||
$PERL ../digcomp.pl knowngood.dig.out.rec dig.out.ns3 || ret=1
|
||||
[ $ret = 0 ] || { status=1; echo "I:failed"; }
|
||||
|
||||
[ $pass = 1 ] && {
|
||||
echo "I:stopping stub server"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl . ns3
|
||||
|
||||
echo "I:re-starting stub server"
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns3
|
||||
}
|
||||
done
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2005-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005-2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -19,3 +19,6 @@
|
||||
|
||||
rm -f dig.out
|
||||
rm -f */named.memstats
|
||||
rm -f */*.bk
|
||||
rm -f */*.bk.*
|
||||
rm -f ns3/Kexample.*
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -41,6 +41,10 @@ a12 IN A \# 4 0A000001
|
||||
|
||||
null IN NULL \# 1 00
|
||||
empty IN NULL \# 0
|
||||
empty IN TYPE124 \# 0
|
||||
|
||||
emptyplus IN TYPE125 \# 0
|
||||
emptyplus IN TYPE125 \# 1 11
|
||||
|
||||
txt1 IN TXT "hello"
|
||||
txt2 CLASS1 TXT "hello"
|
||||
@@ -53,3 +57,4 @@ txt7 IN TXT \# 6 0568656C6C6F
|
||||
unk1 TYPE123 \# 1 00
|
||||
unk2 CLASS1 TYPE123 \# 1 00
|
||||
unk3 IN TYPE123 \# 1 00
|
||||
$INCLUDE large.db
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,39 @@
|
||||
/*
|
||||
* Copyright (C) 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named.conf,v 1.11 2007/06/19 23:47:06 tbox Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
query-source address 10.53.0.2;
|
||||
notify-source 10.53.0.2;
|
||||
transfer-source 10.53.0.2;
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.2; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
notify no;
|
||||
};
|
||||
|
||||
view "in" {
|
||||
zone "example." {
|
||||
type slave;
|
||||
masters { 10.53.0.1; };
|
||||
file "example-in.bk";
|
||||
};
|
||||
};
|
||||
@@ -0,0 +1,17 @@
|
||||
# Copyright (C) 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: setup.sh,v 1.11 2012/02/23 06:53:15 marka Exp $
|
||||
|
||||
sh clean.sh
|
||||
@@ -22,13 +22,13 @@ SYSTEMTESTTOP=..
|
||||
|
||||
status=0
|
||||
|
||||
DIGOPTS="@10.53.0.1 -p 5300"
|
||||
DIGOPTS="-p 5300"
|
||||
|
||||
echo "I:querying for various representations of an IN A record"
|
||||
for i in 1 2 3 4 5 6 7 8 9 10 11 12
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS a$i.example a in > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 a$i.example a in > dig.out || ret=1
|
||||
echo 10.0.0.1 | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -41,7 +41,7 @@ echo "I:querying for various representations of an IN TXT record"
|
||||
for i in 1 2 3 4 5 6 7
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS txt$i.example txt in > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 txt$i.example txt in > dig.out || ret=1
|
||||
echo '"hello"' | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -54,7 +54,7 @@ echo "I:querying for various representations of an IN TYPE123 record"
|
||||
for i in 1 2 3
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS unk$i.example type123 in > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 unk$i.example type123 in > dig.out || ret=1
|
||||
echo '\# 1 00' | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -65,14 +65,14 @@ done
|
||||
|
||||
echo "I:querying for NULL record"
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS null.example null in > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 null.example null in > dig.out || ret=1
|
||||
echo '\# 1 00' | diff - dig.out || ret=1
|
||||
[ $ret = 0 ] || echo "I: failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:querying for empty NULL record"
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS empty.example null in > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 empty.example null in > dig.out || ret=1
|
||||
echo '\# 0' | diff - dig.out || ret=1
|
||||
[ $ret = 0 ] || echo "I: failed"
|
||||
status=`expr $status + $ret`
|
||||
@@ -81,7 +81,7 @@ echo "I:querying for various representations of a CLASS10 TYPE1 record"
|
||||
for i in 1 2
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS a$i.example a class10 > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 a$i.example a class10 > dig.out || ret=1
|
||||
echo '\# 4 0A000001' | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -94,7 +94,7 @@ echo "I:querying for various representations of a CLASS10 TXT record"
|
||||
for i in 1 2 3 4
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS txt$i.example txt class10 > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 txt$i.example txt class10 > dig.out || ret=1
|
||||
echo '"hello"' | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -107,7 +107,7 @@ echo "I:querying for various representations of a CLASS10 TYPE123 record"
|
||||
for i in 1 2
|
||||
do
|
||||
ret=0
|
||||
$DIG +short $DIGOPTS unk$i.example type123 class10 > dig.out || ret=1
|
||||
$DIG +short $DIGOPTS @10.53.0.1 unk$i.example type123 class10 > dig.out || ret=1
|
||||
echo '\# 1 00' | diff - dig.out || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -120,7 +120,7 @@ echo "I:querying for SOAs of zone that should have failed to load"
|
||||
for i in 1 2 3 4
|
||||
do
|
||||
ret=0
|
||||
$DIG $DIGOPTS broken$i. soa in > dig.out || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.1 broken$i. soa in > dig.out || ret=1
|
||||
grep "SERVFAIL" dig.out > /dev/null || ret=1
|
||||
if [ $ret != 0 ]
|
||||
then
|
||||
@@ -129,5 +129,30 @@ do
|
||||
status=`expr $status + $ret`
|
||||
done
|
||||
|
||||
echo "I:checking large unknown record loading on master"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.1 +tcp +short large.example TYPE45234 > dig.out || { ret=1 ; echo I: dig failed ; }
|
||||
diff -s large.out dig.out > /dev/null || { ret=1 ; echo "I: diff failed"; }
|
||||
[ $ret = 0 ] || echo "I: failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:checking large unknown record loading on slave"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.2 +tcp +short large.example TYPE45234 > dig.out || { ret=1 ; echo I: dig failed ; }
|
||||
diff -s large.out dig.out > /dev/null || { ret=1 ; echo "I: diff failed"; }
|
||||
[ $ret = 0 ] || echo "I: failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:stop and restart slave"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl . ns2
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart . ns2
|
||||
|
||||
echo "I:checking large unknown record loading on slave"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.2 +tcp +short large.example TYPE45234 > dig.out || { ret=1 ; echo I: dig failed ; }
|
||||
diff -s large.out dig.out > /dev/null || { ret=1 ; echo "I: diff failed"; }
|
||||
[ $ret = 0 ] || echo "I: failed"
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2005, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#!/usr/local/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Portions Copyright (C) 2004, 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Portions Copyright (C) 2004, 2006, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Portions Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -9978,7 +9978,7 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea
|
||||
(machine$@REALM) for machine in REALM and
|
||||
and converts it machine.realm allowing the machine
|
||||
to update machine.realm. The REALM to be matched
|
||||
is specified in the <replacable>identity</replacable>
|
||||
is specified in the <replaceable>identity</replaceable>
|
||||
field.
|
||||
</para>
|
||||
</entry>
|
||||
@@ -9995,7 +9995,7 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea
|
||||
converts it to machine.realm allowing the machine
|
||||
to update subdomains of machine.realm. The REALM
|
||||
to be matched is specified in the
|
||||
<replacable>identity</replacable> field.
|
||||
<replaceable>identity</replaceable> field.
|
||||
</para>
|
||||
</entry>
|
||||
</row>
|
||||
@@ -10010,7 +10010,7 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea
|
||||
(host/machine@REALM) for machine in REALM and
|
||||
and converts it machine.realm allowing the machine
|
||||
to update machine.realm. The REALM to be matched
|
||||
is specified in the <replacable>identity</replacable>
|
||||
is specified in the <replaceable>identity</replaceable>
|
||||
field.
|
||||
</para>
|
||||
</entry>
|
||||
@@ -10027,7 +10027,7 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea
|
||||
converts it to machine.realm allowing the machine
|
||||
to update subdomains of machine.realm. The REALM
|
||||
to be matched is specified in the
|
||||
<replacable>identity</replacable> field.
|
||||
<replaceable>identity</replaceable> field.
|
||||
</para>
|
||||
</entry>
|
||||
</row>
|
||||
|
||||
@@ -6255,7 +6255,7 @@ zone <em class="replaceable"><code>zone_name</code></em> [<span class="optional"
|
||||
(machine$@REALM) for machine in REALM and
|
||||
and converts it machine.realm allowing the machine
|
||||
to update machine.realm. The REALM to be matched
|
||||
is specified in the <font color="red"><replacable>identity</replacable></font>
|
||||
is specified in the <em class="replaceable"><code>identity</code></em>
|
||||
field.
|
||||
</p>
|
||||
</td>
|
||||
@@ -6273,7 +6273,7 @@ zone <em class="replaceable"><code>zone_name</code></em> [<span class="optional"
|
||||
converts it to machine.realm allowing the machine
|
||||
to update subdomains of machine.realm. The REALM
|
||||
to be matched is specified in the
|
||||
<font color="red"><replacable>identity</replacable></font> field.
|
||||
<em class="replaceable"><code>identity</code></em> field.
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
@@ -6289,7 +6289,7 @@ zone <em class="replaceable"><code>zone_name</code></em> [<span class="optional"
|
||||
(host/machine@REALM) for machine in REALM and
|
||||
and converts it machine.realm allowing the machine
|
||||
to update machine.realm. The REALM to be matched
|
||||
is specified in the <font color="red"><replacable>identity</replacable></font>
|
||||
is specified in the <em class="replaceable"><code>identity</code></em>
|
||||
field.
|
||||
</p>
|
||||
</td>
|
||||
@@ -6307,7 +6307,7 @@ zone <em class="replaceable"><code>zone_name</code></em> [<span class="optional"
|
||||
converts it to machine.realm allowing the machine
|
||||
to update subdomains of machine.realm. The REALM
|
||||
to be matched is specified in the
|
||||
<font color="red"><replacable>identity</replacable></font> field.
|
||||
<em class="replaceable"><code>identity</code></em> field.
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
+1115
-1124
File diff suppressed because it is too large
Load Diff
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl -w
|
||||
#
|
||||
# Copyright (C) 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2005, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2006, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!@PERL@ -w
|
||||
#
|
||||
# Copyright (C) 2006, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2006, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
+253
-197
@@ -5,22 +5,22 @@ Network Working Group S. Weiler
|
||||
Internet-Draft SPARTA, Inc.
|
||||
Updates: 4033, 4034, 4035, 5155 D. Blacka
|
||||
(if approved) Verisign, Inc.
|
||||
Intended status: Standards Track April 30, 2012
|
||||
Expires: November 1, 2012
|
||||
Intended status: Standards Track July 13, 2012
|
||||
Expires: January 14, 2013
|
||||
|
||||
|
||||
Clarifications and Implementation Notes for DNSSECbis
|
||||
draft-ietf-dnsext-dnssec-bis-updates-18
|
||||
Clarifications and Implementation Notes for DNSSEC
|
||||
draft-ietf-dnsext-dnssec-bis-updates-19
|
||||
|
||||
Abstract
|
||||
|
||||
This document is a collection of technical clarifications to the
|
||||
DNSSECbis document set. It is meant to serve as a resource to
|
||||
implementors as well as a repository of DNSSECbis errata.
|
||||
DNSSEC document set. It is meant to serve as a resource to
|
||||
implementors as well as a repository of DNSSEC errata.
|
||||
|
||||
This document updates the core DNSSECbis documents (RFC4033, RFC4034,
|
||||
This document updates the core DNSSEC documents (RFC4033, RFC4034,
|
||||
and RFC4035) as well as the NSEC3 specification (RFC5155). It also
|
||||
defines NSEC3 and SHA-2 as core parts of the DNSSECbis specification.
|
||||
defines NSEC3 and SHA-2 as core parts of the DNSSEC specification.
|
||||
|
||||
Status of this Memo
|
||||
|
||||
@@ -37,7 +37,7 @@ Status of this Memo
|
||||
time. It is inappropriate to use Internet-Drafts as reference
|
||||
material or to cite them other than as "work in progress."
|
||||
|
||||
This Internet-Draft will expire on November 1, 2012.
|
||||
This Internet-Draft will expire on January 14, 2013.
|
||||
|
||||
Copyright Notice
|
||||
|
||||
@@ -52,9 +52,9 @@ Copyright Notice
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 1]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 1]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
to this document. Code Components extracted from this document must
|
||||
@@ -108,9 +108,9 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 2]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 2]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Table of Contents
|
||||
@@ -118,7 +118,7 @@ Table of Contents
|
||||
1. Introduction and Terminology . . . . . . . . . . . . . . . . . 4
|
||||
1.1. Structure of this Document . . . . . . . . . . . . . . . . 4
|
||||
1.2. Terminology . . . . . . . . . . . . . . . . . . . . . . . 4
|
||||
2. Important Additions to DNSSSECbis . . . . . . . . . . . . . . 4
|
||||
2. Important Additions to DNSSEC . . . . . . . . . . . . . . . . 4
|
||||
2.1. NSEC3 Support . . . . . . . . . . . . . . . . . . . . . . 4
|
||||
2.2. SHA-2 Support . . . . . . . . . . . . . . . . . . . . . . 5
|
||||
3. Scaling Concerns . . . . . . . . . . . . . . . . . . . . . . . 5
|
||||
@@ -127,63 +127,63 @@ Table of Contents
|
||||
4.1. Clarifications on Non-Existence Proofs . . . . . . . . . . 5
|
||||
4.2. Validating Responses to an ANY Query . . . . . . . . . . . 6
|
||||
4.3. Check for CNAME . . . . . . . . . . . . . . . . . . . . . 6
|
||||
4.4. Insecure Delegation Proofs . . . . . . . . . . . . . . . . 6
|
||||
4.4. Insecure Delegation Proofs . . . . . . . . . . . . . . . . 7
|
||||
5. Interoperability Concerns . . . . . . . . . . . . . . . . . . 7
|
||||
5.1. Errors in Canonical Form Type Code List . . . . . . . . . 7
|
||||
5.2. Unknown DS Message Digest Algorithms . . . . . . . . . . . 7
|
||||
5.3. Private Algorithms . . . . . . . . . . . . . . . . . . . . 8
|
||||
5.4. Caution About Local Policy and Multiple RRSIGs . . . . . . 8
|
||||
5.4. Caution About Local Policy and Multiple RRSIGs . . . . . . 9
|
||||
5.5. Key Tag Calculation . . . . . . . . . . . . . . . . . . . 9
|
||||
5.6. Setting the DO Bit on Replies . . . . . . . . . . . . . . 9
|
||||
5.7. Setting the AD Bit on Queries . . . . . . . . . . . . . . 9
|
||||
5.8. Setting the AD Bit on Replies . . . . . . . . . . . . . . 9
|
||||
5.8. Setting the AD Bit on Replies . . . . . . . . . . . . . . 10
|
||||
5.9. Always set the CD bit on Queries . . . . . . . . . . . . . 10
|
||||
5.10. Nested Trust Anchors . . . . . . . . . . . . . . . . . . . 10
|
||||
5.11. Mandatory Algorithm Rules . . . . . . . . . . . . . . . . 11
|
||||
5.12. Ignore Extra Signatures From Unknown Keys . . . . . . . . 11
|
||||
5.12. Ignore Extra Signatures From Unknown Keys . . . . . . . . 12
|
||||
6. Minor Corrections and Clarifications . . . . . . . . . . . . . 12
|
||||
6.1. Finding Zone Cuts . . . . . . . . . . . . . . . . . . . . 12
|
||||
6.2. Clarifications on DNSKEY Usage . . . . . . . . . . . . . . 12
|
||||
6.3. Errors in Examples . . . . . . . . . . . . . . . . . . . . 12
|
||||
6.3. Errors in Examples . . . . . . . . . . . . . . . . . . . . 13
|
||||
6.4. Errors in RFC 5155 . . . . . . . . . . . . . . . . . . . . 13
|
||||
7. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 13
|
||||
8. Security Considerations . . . . . . . . . . . . . . . . . . . 13
|
||||
9. References . . . . . . . . . . . . . . . . . . . . . . . . . . 14
|
||||
9.1. Normative References . . . . . . . . . . . . . . . . . . . 14
|
||||
9.2. Informative References . . . . . . . . . . . . . . . . . . 14
|
||||
9.2. Informative References . . . . . . . . . . . . . . . . . . 15
|
||||
Appendix A. Acknowledgments . . . . . . . . . . . . . . . . . . . 15
|
||||
Appendix B. Discussion of Setting the CD Bit . . . . . . . . . . 15
|
||||
Appendix C. Discussion of Trust Anchor Preference Options . . . . 18
|
||||
C.1. Closest Encloser . . . . . . . . . . . . . . . . . . . . . 18
|
||||
C.2. Accept Any Success . . . . . . . . . . . . . . . . . . . . 19
|
||||
C.3. Preference Based on Source . . . . . . . . . . . . . . . . 19
|
||||
Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 20
|
||||
Appendix B. Discussion of Setting the CD Bit . . . . . . . . . . 16
|
||||
Appendix C. Discussion of Trust Anchor Preference Options . . . . 19
|
||||
C.1. Closest Encloser . . . . . . . . . . . . . . . . . . . . . 19
|
||||
C.2. Accept Any Success . . . . . . . . . . . . . . . . . . . . 20
|
||||
C.3. Preference Based on Source . . . . . . . . . . . . . . . . 20
|
||||
Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 21
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 3]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 3]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
1. Introduction and Terminology
|
||||
|
||||
This document lists some additions, clarifications and corrections to
|
||||
the core DNSSECbis specification, as originally described in
|
||||
[RFC4033], [RFC4034], and [RFC4035], and later amended by [RFC5155].
|
||||
(See section Section 2 for more recent additions to that core
|
||||
document set.)
|
||||
the core DNSSEC specification, as originally described in [RFC4033],
|
||||
[RFC4034], and [RFC4035], and later amended by [RFC5155]. (See
|
||||
section Section 2 for more recent additions to that core document
|
||||
set.)
|
||||
|
||||
It is intended to serve as a resource for implementors and as a
|
||||
repository of items that need to be addressed when advancing the
|
||||
DNSSECbis documents from Proposed Standard to Draft Standard.
|
||||
DNSSEC documents along the Standards Track.
|
||||
|
||||
1.1. Structure of this Document
|
||||
|
||||
The clarifications and changes to DNSSECbis are sorted according to
|
||||
The clarifications and changes to DNSSEC are sorted according to
|
||||
their importance, starting with ones which could, if ignored, lead to
|
||||
security problems and progressing down to clarifications that are
|
||||
expected to have little operational impact.
|
||||
@@ -196,11 +196,11 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
[RFC2119].
|
||||
|
||||
|
||||
2. Important Additions to DNSSSECbis
|
||||
2. Important Additions to DNSSEC
|
||||
|
||||
This section lists some documents that should be considered core
|
||||
DNSSEC protocol documents in addition to those originally specified
|
||||
in Section 10 of [RFC4033].
|
||||
This section lists some documents that are now considered core DNSSEC
|
||||
protocol documents in addition to those originally specified in
|
||||
Section 10 of [RFC4033].
|
||||
|
||||
2.1. NSEC3 Support
|
||||
|
||||
@@ -211,21 +211,21 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
validation of responses using NSEC3 will be hampered in validating
|
||||
large portions of the DNS space.
|
||||
|
||||
[RFC5155] should be considered part of the DNS Security Document
|
||||
Family as described by [RFC4033], Section 10.
|
||||
[RFC5155] is now considered part of the DNS Security Document Family
|
||||
as described by [RFC4033], Section 10.
|
||||
|
||||
Note that the algorithm identifiers defined in RFC5155 (DSA-NSEC3-
|
||||
SHA1 and RSASHA1-NSEC3-SHA1) and RFC5702 (RSASHA256 and RSASHA512)
|
||||
signal that a zone MAY be using NSEC3, rather than NSEC. The zone
|
||||
signal that a zone might be using NSEC3, rather than NSEC. The zone
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 4]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 4]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
MAY be using either and validators supporting these algorithms MUST
|
||||
may be using either and validators supporting these algorithms MUST
|
||||
support both NSEC3 and NSEC responses.
|
||||
|
||||
2.2. SHA-2 Support
|
||||
@@ -236,8 +236,8 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Validator implementations are strongly encouraged to include support
|
||||
for these algorithms for DS, DNSKEY, and RRSIG records.
|
||||
|
||||
Both [RFC4509] and [RFC5702] should also be considered part of the
|
||||
DNS Security Document Family as described by [RFC4033], Section 10.
|
||||
Both [RFC4509] and [RFC5702] are now considered part of the DNS
|
||||
Security Document Family as described by [RFC4033], Section 10.
|
||||
|
||||
|
||||
3. Scaling Concerns
|
||||
@@ -245,9 +245,14 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
3.1. Implement a BAD cache
|
||||
|
||||
Section 4.7 of RFC4035 permits security-aware resolvers to implement
|
||||
a BAD cache. Because of scaling concerns not discussed in this
|
||||
document, that guidance has changed: security-aware resolvers SHOULD
|
||||
implement a BAD cache as described in RFC4035.
|
||||
a BAD cache. That guidance has changed: security-aware resolvers
|
||||
SHOULD implement a BAD cache as described in RFC4035.
|
||||
|
||||
This change in guidance is based on operational experience with
|
||||
DNSSEC administrative errors leading to significant increases in DNS
|
||||
traffic, with an accompanying realization that such events are more
|
||||
likely and more damaging than originally supposed. An example of one
|
||||
such event is documented in "Roll Over and Die" [Huston].
|
||||
|
||||
|
||||
4. Security Concerns
|
||||
@@ -266,6 +271,16 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
o the NS bit set,
|
||||
o the SOA bit clear, and
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 5]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
o a signer field that is shorter than the owner name of the NSEC RR,
|
||||
or the original owner name for the NSEC3 RR.
|
||||
|
||||
@@ -274,13 +289,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
that (original) owner name other than DS RRs, and all RRs below that
|
||||
owner name regardless of type.
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 5]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
Similarly, the algorithm would also allow an NSEC RR at the same
|
||||
owner name as a DNAME RR, or an NSEC3 RR at the same original owner
|
||||
name as a DNAME, to prove the non-existence of names beneath that
|
||||
@@ -306,11 +314,11 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
4.3. Check for CNAME
|
||||
|
||||
Section 5 of [RFC4035] says little about validating responses based
|
||||
on (or that should be based on) CNAMEs. When validating a NOERROR/
|
||||
NODATA response, validators MUST check the CNAME bit in the matching
|
||||
NSEC or NSEC3 RR's type bitmap in addition to the bit for the query
|
||||
type.
|
||||
Section 5 of [RFC4035] says nothing explicit about validating
|
||||
responses based on (or that should be based on) CNAMEs. When
|
||||
validating a NOERROR/NODATA response, validators MUST check the CNAME
|
||||
bit in the matching NSEC or NSEC3 RR's type bitmap in addition to the
|
||||
bit for the query type.
|
||||
|
||||
Without this check, an attacker could successfully transform a
|
||||
positive CNAME response into a NOERROR/NODATA response by (e.g.)
|
||||
@@ -320,6 +328,15 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
set, and thus the response should have been a positive CNAME
|
||||
response.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 6]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
4.4. Insecure Delegation Proofs
|
||||
|
||||
[RFC4035] Section 5.2 specifies that a validator, when proving a
|
||||
@@ -330,13 +347,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
alternately make sure that the delegation is covered by an NSEC3 RR
|
||||
with the Opt-Out flag set.
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 6]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
Without this check, an attacker could reuse an NSEC or NSEC3 RR
|
||||
matching a non-delegation name to spoof an unsigned delegation at
|
||||
that name. This would claim that an existing signed RRset (or set of
|
||||
@@ -376,6 +386,13 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
The existing text says:
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 7]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
If the validator does not support any of the algorithms listed in
|
||||
an authenticated DS RRset, then the resolver has no supported
|
||||
authentication path leading from the parent to the child. The
|
||||
@@ -385,14 +402,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
In other words, when determining the security status of a zone, a
|
||||
validator disregards any authenticated DS records that specify
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 7]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
unknown or unsupported DNSKEY algorithms. If none are left, the zone
|
||||
is treated as if it were unsigned.
|
||||
|
||||
@@ -418,20 +427,28 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
In the remaining cases, the security status of the zone depends on
|
||||
whether or not the resolver supports any of the private algorithms in
|
||||
use (provided that these DS records use supported hash functions, as
|
||||
discussed in Section 5.2). In these cases, the resolver MUST
|
||||
retrieve the corresponding DNSKEY for each private algorithm DS
|
||||
record and examine the public key field to determine the algorithm in
|
||||
use. The security-aware resolver MUST ensure that the hash of the
|
||||
DNSKEY RR's owner name and RDATA matches the digest in the DS RR as
|
||||
described in Section 5.2 of [RFC4035], authenticating the DNSKEY. If
|
||||
all of the retrieved and authenticated DNSKEY RRs use unknown or
|
||||
unsupported private algorithms, then the zone is treated as if it
|
||||
were unsigned.
|
||||
use (provided that these DS records use supported message digest
|
||||
algorithms, as discussed in Section 5.2 of this document). In these
|
||||
cases, the resolver MUST retrieve the corresponding DNSKEY for each
|
||||
private algorithm DS record and examine the public key field to
|
||||
determine the algorithm in use. The security-aware resolver MUST
|
||||
ensure that the hash of the DNSKEY RR's owner name and RDATA matches
|
||||
the digest in the DS RR as described in Section 5.2 of [RFC4035],
|
||||
authenticating the DNSKEY. If all of the retrieved and authenticated
|
||||
DNSKEY RRs use unknown or unsupported private algorithms, then the
|
||||
zone is treated as if it were unsigned.
|
||||
|
||||
Note that if none of the private algorithm DS RRs can be securely
|
||||
matched to DNSKEY RRs and no other DS establishes that the zone is
|
||||
secure, the referral should be considered Bogus data as discussed in
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 8]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
[RFC4035].
|
||||
|
||||
This clarification facilitates the broader use of private algorithms,
|
||||
@@ -441,14 +458,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
When multiple RRSIGs cover a given RRset, [RFC4035] Section 5.3.3
|
||||
suggests that "the local resolver security policy determines whether
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 8]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
the resolver also has to test these RRSIG RRs and how to resolve
|
||||
conflicts if these RRSIG RRs lead to differing results."
|
||||
|
||||
@@ -475,18 +484,30 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
5.6. Setting the DO Bit on Replies
|
||||
|
||||
As stated in [RFC3225], the DO bit of the query MUST be copied in the
|
||||
response. However, in order to interoperate with implementations
|
||||
that ignore this rule on sending, resolvers MUST ignore the DO bit in
|
||||
responses.
|
||||
As stated in Section 3 of [RFC3225], the DO bit of the query MUST be
|
||||
copied in the response. However, in order to interoperate with
|
||||
implementations that ignore this rule on sending, resolvers MUST
|
||||
ignore the DO bit in responses.
|
||||
|
||||
5.7. Setting the AD Bit on Queries
|
||||
|
||||
The use of the AD bit in the query was previously undefined. This
|
||||
document defines it as a signal indicating that the requester
|
||||
understands and is interested in the value of the AD bit in the
|
||||
response. This allows a requestor to indicate that it understands
|
||||
the AD bit without also requesting DNSSEC data via the DO bit.
|
||||
The semantics of the AD bit in the query were previously undefined.
|
||||
Section 4.6 of [RFC4035] instructed resolvers to always clear the AD
|
||||
bit when composing queries.
|
||||
|
||||
This document defines setting the AD bit in a query as a signal
|
||||
indicating that the requester understands and is interested in the
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 9]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
value of the AD bit in the response. This allows a requestor to
|
||||
indicate that it understands the AD bit without also requesting
|
||||
DNSSEC data via the DO bit.
|
||||
|
||||
5.8. Setting the AD Bit on Replies
|
||||
|
||||
@@ -498,13 +519,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
in RFC 4035, section 3.2.3, and the request contained either a set DO
|
||||
bit or a set AD bit.
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 9]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
5.9. Always set the CD bit on Queries
|
||||
|
||||
When processing a request with the CD bit set, a resolver SHOULD
|
||||
@@ -525,7 +539,7 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
does the cache need to track the state of the CD bit used to make a
|
||||
given query. The problem arises when the cached response is a server
|
||||
failure (RCODE 2), which may indicate that the requested data failed
|
||||
DNSSEC validation at an upstream validating resolver. (RFC2308
|
||||
DNSSEC validation at an upstream validating resolver. ([RFC2308]
|
||||
permits caching of server failures for up to five minutes.) In these
|
||||
cases, a new query with the CD bit set is required.
|
||||
|
||||
@@ -539,6 +553,14 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
trust to the response zone. For example, imagine a validator
|
||||
configured with trust anchors for "example." and "zone.example."
|
||||
When the validator is asked to validate a response to
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 10]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
"www.sub.zone.example.", either trust anchor could apply.
|
||||
|
||||
When presented with this situation, DNSSEC validators have a choice
|
||||
@@ -553,14 +575,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
The "Accept Any Success" policy is to try all applicable trust
|
||||
anchors until one gives a validation result of Secure, in which case
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 10]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
the final validation result is Secure. If and only if all applicable
|
||||
trust anchors give a result of Insecure, the final validation result
|
||||
is Insecure. If one or more trust anchors lead to a Bogus result and
|
||||
@@ -590,12 +604,20 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Likewise, if there are DS records for multiple keys of the same
|
||||
algorithm, any subset of those may appear in the DNSKEY RRset.
|
||||
|
||||
Lastly, note that this a requirement at the server side, not the
|
||||
client side. Validators SHOULD accept any single valid path. They
|
||||
SHOULD NOT insist that all algorithms signaled in the DS RRset work,
|
||||
and they MUST NOT insist that all algorithms signaled in the DNSKEY
|
||||
RRset work. A validator MAY have a configuration option to perform a
|
||||
signature completeness test to support troubleshooting.
|
||||
This requirement applies to servers, not validators. Validators
|
||||
SHOULD accept any single valid path. They SHOULD NOT insist that all
|
||||
algorithms signaled in the DS RRset work, and they MUST NOT insist
|
||||
that all algorithms signaled in the DNSKEY RRset work. A validator
|
||||
MAY have a configuration option to perform a signature completeness
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 11]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
test to support troubleshooting.
|
||||
|
||||
5.12. Ignore Extra Signatures From Unknown Keys
|
||||
|
||||
@@ -610,27 +632,13 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
zone.
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 11]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
6. Minor Corrections and Clarifications
|
||||
|
||||
6.1. Finding Zone Cuts
|
||||
|
||||
Appendix C.8 of [RFC4035] discusses sending DS queries to the servers
|
||||
for a parent zone. To do that, a resolver may first need to apply
|
||||
special rules to discover what those servers are.
|
||||
|
||||
As explained in Section 3.1.4.1 of [RFC4035], security-aware name
|
||||
servers need to apply special processing rules to handle the DS RR,
|
||||
and in some situations the resolver may also need to apply special
|
||||
rules to locate the name servers for the parent zone if the resolver
|
||||
does not already have the parent's NS RRset. Section 4.2 of
|
||||
[RFC4035] specifies a mechanism for doing that.
|
||||
for a parent zone but does not state how to find those servers.
|
||||
Specific instructions can be found in Section 4.2 of [RFC4035].
|
||||
|
||||
6.2. Clarifications on DNSKEY Usage
|
||||
|
||||
@@ -655,6 +663,16 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
also possible to use a single DNSKEY, with or without the SEP bit
|
||||
set, to sign the entire zone, including the DNSKEY RRset itself.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 12]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
6.3. Errors in Examples
|
||||
|
||||
The text in [RFC4035] Section C.1 refers to the examples in B.1 as
|
||||
@@ -666,13 +684,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
(antithetically, a label count of 3 would imply the answer was the
|
||||
result of a wildcard expansion).
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 12]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
The first paragraph of [RFC4035] Section C.6 also has a minor error:
|
||||
the reference to "a.z.w.w.example" should instead be "a.z.w.example",
|
||||
as in the previous line.
|
||||
@@ -710,6 +721,14 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
in the documents defining them. Additionally, this document
|
||||
addresses some ambiguities and omissions in the core DNSSEC documents
|
||||
that, if not recognized and addressed in implementations, could lead
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 13]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
to security failures. In particular, the validation algorithm
|
||||
clarifications in Section 4 are critical for preserving the security
|
||||
properties DNSSEC offers. Furthermore, failure to address some of
|
||||
@@ -722,13 +741,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
of trust anchors at an upstream validator.
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 13]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
9. References
|
||||
|
||||
9.1. Normative References
|
||||
@@ -765,8 +777,22 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
and RRSIG Resource Records for DNSSEC", RFC 5702,
|
||||
October 2009.
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 14]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
9.2. Informative References
|
||||
|
||||
[Huston] Michaelson, G., Wallstrom, P., Arends, R., and G. Huston,
|
||||
"Roll Over and Die?", February 2010.
|
||||
|
||||
[RFC2308] Andrews, M., "Negative Caching of DNS Queries (DNS
|
||||
NCACHE)", RFC 2308, March 1998.
|
||||
|
||||
[RFC3755] Weiler, S., "Legacy Resolver Compatibility for Delegation
|
||||
Signer (DS)", RFC 3755, May 2004.
|
||||
|
||||
@@ -777,14 +803,6 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
July 2007.
|
||||
|
||||
[RFC5011] StJohns, M., "Automated Updates of DNS Security (DNSSEC)
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 14]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
Trust Anchors", RFC 5011, September 2007.
|
||||
|
||||
[RFC5074] Weiler, S., "DNSSEC Lookaside Validation (DLV)", RFC 5074,
|
||||
@@ -797,7 +815,7 @@ Appendix A. Acknowledgments
|
||||
an editor of this document.
|
||||
|
||||
The editors are extremely grateful to those who, in addition to
|
||||
finding errors and omissions in the DNSSECbis document set, have
|
||||
finding errors and omissions in the DNSSEC document set, have
|
||||
provided text suitable for inclusion in this document.
|
||||
|
||||
The lack of specificity about handling private algorithms, as
|
||||
@@ -815,6 +833,14 @@ Appendix A. Acknowledgments
|
||||
The errors in the [RFC4035] examples were found by Roy Arends, who
|
||||
also contributed text for Section 6.3 of this document.
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 15]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Text on the mandatory algorithm rules was derived from suggestions by
|
||||
Matthijs Mekking and Ed Lewis.
|
||||
|
||||
@@ -824,23 +850,16 @@ Appendix A. Acknowledgments
|
||||
The editors would like to thank Alfred Hoenes, Ed Lewis, Danny Mayer,
|
||||
Olafur Gudmundsson, Suzanne Woolf, Rickard Bellgrim, Mike St. Johns,
|
||||
Mark Andrews, Wouter Wijngaards, Matthijs Mekking, Andrew Sullivan,
|
||||
and Scott Rose for their substantive comments on the text of this
|
||||
Jeremy Reed, Paul Hoffman, Mohan Parthasarathy, Florian Weimer,
|
||||
Warren Kumari and Scott Rose for their contributions to this
|
||||
document.
|
||||
|
||||
|
||||
Appendix B. Discussion of Setting the CD Bit
|
||||
|
||||
RFC 4035 may be read as relying on the implicit assumption that there
|
||||
is at most one validating system between the stub resolver and the
|
||||
authoritative server for a given zone. It is entirely possible,
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 15]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
[RFC4035] may be read as relying on the implicit assumption that
|
||||
there is at most one validating system between the stub resolver and
|
||||
the authoritative server for a given zone. It is entirely possible,
|
||||
however, for more than one validator to exist between a stub resolver
|
||||
and an authoritative server. If these different validators have
|
||||
disjoint trust anchors configured, then it is possible that each
|
||||
@@ -870,6 +889,14 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
as local policy or from the API in the case of a stub). The second
|
||||
column indicates whether the query needs to be forwarded for
|
||||
resolution (F) or can be satisfied from a local cache (C). The third
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 16]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
column is a line number, so that it can be referred to later in the
|
||||
table. The fourth column indicates any relevant conditions at the
|
||||
resolver: whether the resolver has a covering trust anchor and so on.
|
||||
@@ -877,26 +904,16 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
final column indicates what action the resolver takes.
|
||||
|
||||
The tables differentiate between "cached data" and "cached RCODE=2".
|
||||
This is a shorthand; the point is that one has to treat RCODE=2 as
|
||||
special, because it might indicate a validation failure somewhere
|
||||
upstream. The distinction is really between "cached RCODE=2" and
|
||||
"cached everything else".
|
||||
This is a shorthand; the point is that one has to treat RCODE=2
|
||||
(server failure) as special, because it might indicate a validation
|
||||
failure somewhere upstream. The distinction is really between
|
||||
"cached RCODE=2" and "cached everything else".
|
||||
|
||||
The tables are probably easiest to think of in terms of describing
|
||||
what happens when a stub resolver sends a query to an intermediate
|
||||
resolver, but they are perfectly general and can be applied to any
|
||||
validating resolver.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 16]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
Model 1: "always set"
|
||||
|
||||
This model is so named because the validating resolver sets the CD
|
||||
@@ -918,6 +935,24 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
0 C A5 covering TA Validate cached result and
|
||||
return it.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 17]
|
||||
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Model 2: "never set when receiving CD=0"
|
||||
|
||||
This model is so named because it sets CD=0 on upstream queries for
|
||||
@@ -948,9 +983,30 @@ Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 17]
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 18]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Model 3: "sometimes set"
|
||||
@@ -1004,9 +1060,9 @@ C.1. Closest Encloser
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 18]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 19]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Encloser" policy would choose the "zone.example." trust anchor.
|
||||
@@ -1060,9 +1116,9 @@ C.3. Preference Based on Source
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 19]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 20]
|
||||
|
||||
Internet-Draft DNSSECbis Implementation Notes April 2012
|
||||
Internet-Draft DNSSEC Implementation Notes July 2012
|
||||
|
||||
|
||||
Conversely, a validator might choose to prefer manually configured
|
||||
@@ -1116,5 +1172,5 @@ Authors' Addresses
|
||||
|
||||
|
||||
|
||||
Weiler & Blacka Expires November 1, 2012 [Page 20]
|
||||
Weiler & Blacka Expires January 14, 2013 [Page 21]
|
||||
|
||||
+622
-622
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/perl
|
||||
#
|
||||
# Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/perl
|
||||
#
|
||||
# Copyright (C) 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2007, 2012 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user