Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9f4dbf5b58 | ||
|
|
a723bc1393 | ||
|
|
14b2ad7281 | ||
|
|
f463c3611b | ||
|
|
417a6e5ce9 | ||
|
|
8b1aabd2a7 | ||
|
|
06de2249b5 | ||
|
|
7c56a5fa65 | ||
|
|
60383f3479 | ||
|
|
0d16ffbb38 | ||
|
|
376b338da4 | ||
|
|
0b619c6751 | ||
|
|
fba67c8aef | ||
|
|
f79d8d3e0a | ||
|
|
b7ae61a21b | ||
|
|
66040ff693 | ||
|
|
bf31eeeee8 | ||
|
|
19286de949 | ||
|
|
159b4147ae | ||
|
|
2adf1074e4 | ||
|
|
f6ad003ecf | ||
|
|
ff8dbeaea2 | ||
|
|
414b674e7c | ||
|
|
c5548964bf | ||
|
|
e946c1762a | ||
|
|
4d1b079ac6 | ||
|
|
fe3ce1da2b | ||
|
|
41ca3ff801 | ||
|
|
77f4a19e4e | ||
|
|
89645a2265 | ||
|
|
851bccc5a1 | ||
|
|
2b24897c64 | ||
|
|
011f157473 | ||
|
|
b3efdb08bd | ||
|
|
38dfbc0462 | ||
|
|
96936dcdab | ||
|
|
d61efe262b | ||
|
|
b55dbfdc1e | ||
|
|
2327cb8332 | ||
|
|
2c50f32188 | ||
|
|
bc6393b238 | ||
|
|
015872cba9 | ||
|
|
40fa732370 | ||
|
|
37b7f9ed76 | ||
|
|
5773bce67f | ||
|
|
4c0de19d1b | ||
|
|
2358a7881c | ||
|
|
593f1e35d7 | ||
|
|
863a0dbd20 | ||
|
|
0a3856d2c4 | ||
|
|
64a1132d74 | ||
|
|
7a0ca2b0c7 | ||
|
|
c057a9b862 | ||
|
|
6fc5dc883e | ||
|
|
d44cb7d304 | ||
|
|
e51b6ade48 | ||
|
|
babe8e1954 | ||
|
|
b6d8f4bcf7 | ||
|
|
4a2abf6faa | ||
|
|
419ef16980 | ||
|
|
8f9cf97d96 | ||
|
|
6dd373ebab | ||
|
|
fc5f2e310e | ||
|
|
7000688bfc | ||
|
|
35e6e7bfe9 | ||
|
|
5d900d5216 | ||
|
|
0f862dd540 | ||
|
|
5dd7596365 | ||
|
|
1bf261f075 | ||
|
|
63aaf0dba0 | ||
|
|
53f747143d | ||
|
|
ea155b7f8b | ||
|
|
8a2c86ea10 | ||
|
|
c02a729605 | ||
|
|
0b53de22db | ||
|
|
86039977b2 | ||
|
|
62bffa3ef0 | ||
|
|
5f01b84397 | ||
|
|
12f0fa2a6a | ||
|
|
905b16ef04 | ||
|
|
3267c08327 | ||
|
|
4b7c993dc2 | ||
|
|
7a9bb15a3c | ||
|
|
68e2731590 | ||
|
|
3602d7ba6a | ||
|
|
203987b1f6 | ||
|
|
ea2b2d9b49 | ||
|
|
28d84645bb | ||
|
|
94a0e96ade | ||
|
|
480c85c467 | ||
|
|
d9e9d845a5 | ||
|
|
f0903fa41f | ||
|
|
f12b694d74 | ||
|
|
1a035f7c01 | ||
|
|
b8be986508 | ||
|
|
3967e289ce | ||
|
|
1f6eacb5f2 | ||
|
|
fd10c6096f | ||
|
|
a7ff07d136 | ||
|
|
efb73dcab3 | ||
|
|
4621e0afc1 | ||
|
|
4d05c5e4c3 | ||
|
|
b3059b496a | ||
|
|
c5dc89ae15 | ||
|
|
e080b58ad2 | ||
|
|
063f6cb1f6 | ||
|
|
368f38ff7e | ||
|
|
30e201af17 | ||
|
|
7fbd853c14 | ||
|
|
e496dc109f | ||
|
|
47b7602b32 | ||
|
|
52d14ab8a0 | ||
|
|
88cc2316d2 | ||
|
|
932d1ded69 | ||
|
|
dae8f07882 | ||
|
|
d2d4121e41 | ||
|
|
1ba011353f | ||
|
|
d6ed4b9543 | ||
|
|
77e391dcf0 | ||
|
|
7361f7b44e | ||
|
|
a1b85f0dc5 | ||
|
|
d2ec48155a | ||
|
|
032b797c12 | ||
|
|
030c95db8b | ||
|
|
d396fa4d7b | ||
|
|
23a90cc905 | ||
|
|
2a15134ad8 | ||
|
|
49c2c7f047 | ||
|
|
70098b1589 | ||
|
|
4f0ae1f09f | ||
|
|
5bfdeeb223 | ||
|
|
c828da6fd2 | ||
|
|
47181231d7 | ||
|
|
f4bf81792a | ||
|
|
9f0648fcdb | ||
|
|
836542c79d | ||
|
|
a6213e6566 | ||
|
|
5b14ab9dc9 | ||
|
|
50e99b5431 | ||
|
|
a6c4c2e290 | ||
|
|
524fb791e1 | ||
|
|
a680251f6b | ||
|
|
1216351b41 | ||
|
|
c4135d6b8e | ||
|
|
391b853668 | ||
|
|
881c1a4e65 | ||
|
|
eddebea2b4 | ||
|
|
d1e2909418 | ||
|
|
7db4c7b5b5 | ||
|
|
d8c4983127 | ||
|
|
2b6899f41f | ||
|
|
232eb5b99c | ||
|
|
f034123382 | ||
|
|
bbc2f43f5f | ||
|
|
ed6abf57cb | ||
|
|
2f19fa2364 | ||
|
|
745452dd8d | ||
|
|
751e78699c | ||
|
|
6fac8250fe | ||
|
|
882ab80d57 | ||
|
|
e89954332f | ||
|
|
c6b94cea88 | ||
|
|
bd3d28a0e1 | ||
|
|
19ad23141e | ||
|
|
4db1370d72 | ||
|
|
4ebf39bfb0 | ||
|
|
0ac301ced6 | ||
|
|
88633933a0 | ||
|
|
9032c19495 | ||
|
|
c802ba3785 | ||
|
|
89beaff53c | ||
|
|
0fa725f3bf | ||
|
|
4d555ab24a | ||
|
|
91a4d82324 | ||
|
|
1ddd383a5c | ||
|
|
8d21fb1375 | ||
|
|
1dfe15d60e | ||
|
|
05fccbb44f | ||
|
|
452a20766e | ||
|
|
bb4175dc30 | ||
|
|
513eac3fa9 | ||
|
|
a7580c035f | ||
|
|
d9d1c24e08 | ||
|
|
ebd1736e8f | ||
|
|
0ffe6373a5 | ||
|
|
05bec7caf8 | ||
|
|
2fbf06bcc8 | ||
|
|
07fc520149 | ||
|
|
f3b8d1f983 | ||
|
|
a407a2a647 | ||
|
|
ffec7b548a | ||
|
|
2a55bd28af | ||
|
|
7d27e29272 | ||
|
|
0f4fb51b1f | ||
|
|
29c4e473a5 | ||
|
|
659792d80a | ||
|
|
0910a0b9fb | ||
|
|
46da8e1665 | ||
|
|
7cda99b512 | ||
|
|
793c8a025a | ||
|
|
5564fe84c5 | ||
|
|
0b693c3cc3 | ||
|
|
da97d91bbf | ||
|
|
2ac13a1d85 | ||
|
|
aeac83f581 | ||
|
|
c0f4d881ad | ||
|
|
c5f5e28dcd | ||
|
|
00b2212e0d | ||
|
|
08ac7f3da1 | ||
|
|
0a58ce1677 | ||
|
|
874d107342 | ||
|
|
9548421f81 | ||
|
|
d96510b789 | ||
|
|
33e22751d5 | ||
|
|
1c0426be14 | ||
|
|
de9953980e | ||
|
|
a1daec7a10 | ||
|
|
199727a752 | ||
|
|
a5607f268d | ||
|
|
84ddf924f1 | ||
|
|
f9cc7d28c5 | ||
|
|
6b658869ba | ||
|
|
0a2a4750b3 | ||
|
|
a9fb68beb3 | ||
|
|
a9eff2fe00 | ||
|
|
fd4f29edf2 | ||
|
|
22e77ee039 | ||
|
|
2ca671d4d2 | ||
|
|
e3d0f21f53 | ||
|
|
1e98c82a59 | ||
|
|
b0e27f785a | ||
|
|
8850c3eb35 | ||
|
|
04b5e1489a | ||
|
|
a75a475780 | ||
|
|
160d5cb860 | ||
|
|
ad385e3aaa | ||
|
|
585530bce3 | ||
|
|
975203a88d | ||
|
|
9f3efdacd0 | ||
|
|
7a6c7b4622 | ||
|
|
53d275bcf7 | ||
|
|
41810688a1 | ||
|
|
8c6e8dd6c1 | ||
|
|
1151904454 | ||
|
|
abcb1ed6e5 | ||
|
|
ed677aad5b | ||
|
|
44eb0b53da | ||
|
|
b61ea69aa3 | ||
|
|
b8f0ed1a12 | ||
|
|
18103754d2 | ||
|
|
44da510c99 | ||
|
|
3a403b358a | ||
|
|
89a68a7d46 | ||
|
|
9a9a197636 | ||
|
|
19c5764f41 | ||
|
|
f0c059899e | ||
|
|
6605a0132b | ||
|
|
ce1eb06d2a | ||
|
|
aa9637307b | ||
|
|
13f7fc506f | ||
|
|
f48478f001 | ||
|
|
5a4f843d3e | ||
|
|
8a5052e802 | ||
|
|
ed04eeab8a | ||
|
|
9a5a8bc9dd | ||
|
|
db1c68a9c1 | ||
|
|
2faa53af39 | ||
|
|
9a350f520a | ||
|
|
c1b270ae40 | ||
|
|
d6b5a7bd1b | ||
|
|
f54fe6f19c | ||
|
|
f5933d79ca | ||
|
|
b134097b24 | ||
|
|
0e54a77925 | ||
|
|
88a65863a5 | ||
|
|
5675d2de03 | ||
|
|
c071a6581e | ||
|
|
b89e028c05 | ||
|
|
5c15917576 | ||
|
|
3c3d03e138 | ||
|
|
b08b711e2a | ||
|
|
ec9d326340 | ||
|
|
7a178c0287 | ||
|
|
a49c3566a7 | ||
|
|
5b8794da73 | ||
|
|
d29938ee0d | ||
|
|
526b51ec93 | ||
|
|
bbc6cb37ae | ||
|
|
b44a3cb109 | ||
|
|
8e4c7e687f | ||
|
|
0d4ec7d9ac | ||
|
|
d7112a033e | ||
|
|
aa691f6fb4 | ||
|
|
c653b35f51 | ||
|
|
c4f131dce9 | ||
|
|
11941bb7c6 | ||
|
|
857a10c5ac | ||
|
|
7c8c5acdcf | ||
|
|
496d013619 | ||
|
|
c4c7fdf98e | ||
|
|
7a3e203b2d | ||
|
|
c81992af09 | ||
|
|
9285be523f | ||
|
|
1d276ca824 | ||
|
|
9996a31fcb | ||
|
|
20d459121d | ||
|
|
b7601f1e78 | ||
|
|
258b3ae519 | ||
|
|
0b80655d1b | ||
|
|
438e0483b7 | ||
|
|
5d72579040 | ||
|
|
9a99e3c47e | ||
|
|
db11e9d7be | ||
|
|
73027787e1 | ||
|
|
3d0d33a56e | ||
|
|
652333b000 | ||
|
|
29baaada1d | ||
|
|
7c704b42da | ||
|
|
871a3ebc69 | ||
|
|
20a5f2b794 | ||
|
|
d41be7b849 | ||
|
|
1d6b2871c2 | ||
|
|
bcea85a562 | ||
|
|
83032e39d7 | ||
|
|
1105a4fcfc | ||
|
|
ff349e3d68 | ||
|
|
1e9a6f3e14 | ||
|
|
47e040c48e | ||
|
|
4c80eea432 | ||
|
|
607c35a5c1 | ||
|
|
71986a4364 | ||
|
|
f324e5035a | ||
|
|
b5906d8cf0 | ||
|
|
17d466904b | ||
|
|
2e19f9ff58 | ||
|
|
445adcb95d | ||
|
|
e28efdcf09 | ||
|
|
69c1260911 | ||
|
|
d50a91b4b5 | ||
|
|
3db330edf8 | ||
|
|
6c0d104d75 | ||
|
|
538e4f74bf | ||
|
|
d1288b14be | ||
|
|
2d032cd20f | ||
|
|
31474958ea | ||
|
|
c05a5e1d73 | ||
|
|
031da3eb0c | ||
|
|
a45a2e965c | ||
|
|
f00527a575 | ||
|
|
a9a775cdda | ||
|
|
377cb850d2 | ||
|
|
b6effcfad3 | ||
|
|
932edca56d | ||
|
|
2fb9f87ccc | ||
|
|
af8a702ffa | ||
|
|
bed2bf2ec7 | ||
|
|
e385b3f9b9 | ||
|
|
e77ffda2f2 | ||
|
|
453e098b25 | ||
|
|
b05158a67d | ||
|
|
f3214d80cc | ||
|
|
5b4db46db2 | ||
|
|
676ee9185a | ||
|
|
cbf9f32246 | ||
|
|
69dfa864d5 | ||
|
|
6a33380ecf | ||
|
|
98ec74d568 | ||
|
|
3abc7a1f90 | ||
|
|
fc7e537b45 | ||
|
|
ca6dd4b475 | ||
|
|
a8ab505429 | ||
|
|
ef1fd9eb5e | ||
|
|
cf5edf83ec | ||
|
|
c1bf2a2775 | ||
|
|
448e2663ac | ||
|
|
83e6c42cdd | ||
|
|
c177dec7c5 | ||
|
|
cc80af09cd | ||
|
|
fcf1934be8 | ||
|
|
bfdef2abaf | ||
|
|
ecb10f595d | ||
|
|
fb2888c3a5 | ||
|
|
081a9dc448 | ||
|
|
0f1c24fec6 | ||
|
|
3ba7bb9664 | ||
|
|
92fd5d1b25 | ||
|
|
ada7ae72c3 | ||
|
|
cf1ddc33ee | ||
|
|
33cd4d9181 | ||
|
|
743770f874 | ||
|
|
33ae0e092b | ||
|
|
d89c1b9466 | ||
|
|
64bbd43587 | ||
|
|
f560610eff | ||
|
|
e0c92f8713 | ||
|
|
d7372aa85b | ||
|
|
078cef089c | ||
|
|
de3940d1ea | ||
|
|
d63b8ea4d0 | ||
|
|
4e272d5a1c | ||
|
|
720b0c0d51 | ||
|
|
4e3697a06e | ||
|
|
d1828d831e | ||
|
|
35949f9ac8 | ||
|
|
e9755e2570 | ||
|
|
bd27d0df2b | ||
|
|
4ef5f38576 | ||
|
|
e009a9de75 | ||
|
|
d967b49681 | ||
|
|
e0c03c4a8c | ||
|
|
95194a972c | ||
|
|
3617d02264 | ||
|
|
7c290f0115 | ||
|
|
70e4b82cd9 | ||
|
|
d1bd7d654f | ||
|
|
253ed9c697 | ||
|
|
5ce02fb8f5 | ||
|
|
e4cf833007 | ||
|
|
2c352f5b03 | ||
|
|
3184f5e1a8 | ||
|
|
02bf1aae84 | ||
|
|
cbc7936c23 | ||
|
|
5651d4d917 | ||
|
|
65e40464b9 | ||
|
|
f2e926483f | ||
|
|
0d50d3b07f | ||
|
|
d05f92796b | ||
|
|
2cc17e1b1c | ||
|
|
7e1e879d56 | ||
|
|
1fd69a8213 | ||
|
|
7a18159352 | ||
|
|
a364df15a9 | ||
|
|
a9c551e555 | ||
|
|
8572954ead | ||
|
|
9cf990271f | ||
|
|
346b91444e | ||
|
|
87519dfd8f | ||
|
|
0cae8f10b7 | ||
|
|
5936aeafed | ||
|
|
e49d73b94b | ||
|
|
10684df873 | ||
|
|
378dbacd83 | ||
|
|
7b4467366d | ||
|
|
631758bd3a | ||
|
|
2ec8ca31c0 | ||
|
|
c3b2b710be | ||
|
|
5468d7a070 | ||
|
|
4d1a4aadbb | ||
|
|
e754375df7 | ||
|
|
e4dcfc0e1e | ||
|
|
a0e5d39d03 | ||
|
|
6b57edb1ab | ||
|
|
1b2692a5b9 | ||
|
|
8c97518725 | ||
|
|
bf79880554 | ||
|
|
9e1b196510 | ||
|
|
d006ab34d2 | ||
|
|
f02cc38da0 | ||
|
|
21996d3904 | ||
|
|
dace425c59 | ||
|
|
aae4d811bc | ||
|
|
d5e086f492 | ||
|
|
b456d81fba | ||
|
|
7734aca6a1 | ||
|
|
92442341b6 | ||
|
|
44f8595983 | ||
|
|
0321a1fd00 | ||
|
|
17db42659c | ||
|
|
6af1573bdb | ||
|
|
5bf955196b | ||
|
|
3cc252d992 | ||
|
|
ca193080b8 | ||
|
|
8bc362cc47 | ||
|
|
db23bb6075 | ||
|
|
3e277745be | ||
|
|
8e76a261e4 | ||
|
|
efbab336ac | ||
|
|
fa253950d9 | ||
|
|
bc7aed2a6b | ||
|
|
0b034daf8e | ||
|
|
eb19518256 | ||
|
|
efdac14a77 | ||
|
|
af17ccb8e5 | ||
|
|
8b9d13a3c1 | ||
|
|
8ce32752e6 | ||
|
|
7c644b7bf5 | ||
|
|
f2af5e6496 | ||
|
|
5c64e82dd6 | ||
|
|
7644620ee7 | ||
|
|
7c051497fa | ||
|
|
c58e05413c | ||
|
|
94d633f808 | ||
|
|
3524472293 | ||
|
|
2dec8208b9 | ||
|
|
e0cb2d799b | ||
|
|
2e977649df | ||
|
|
e33315f886 | ||
|
|
b628c1221e | ||
|
|
24a73837dd | ||
|
|
d165d9ba2d | ||
|
|
7e10c4f8c5 | ||
|
|
70725073a9 | ||
|
|
690d5cd519 | ||
|
|
f7bf1751e5 | ||
|
|
e638dbf10c | ||
|
|
b0c5373e6c | ||
|
|
e3201af06f | ||
|
|
b4fa6115f0 | ||
|
|
3d2f774d23 | ||
|
|
dbc8f28aa4 | ||
|
|
9937ce8e73 | ||
|
|
50f29e14b4 | ||
|
|
b5251afe9b | ||
|
|
7726fff532 | ||
|
|
955ee4992d | ||
|
|
1fd0d83a38 | ||
|
|
1ac91b4140 | ||
|
|
f5199566db | ||
|
|
a244965075 | ||
|
|
7bc44cccc1 | ||
|
|
bdea0ea015 | ||
|
|
2109456871 | ||
|
|
03fbf41ea8 | ||
|
|
f76bf38ff6 | ||
|
|
8f89bb0c54 | ||
|
|
0fc328e58e | ||
|
|
d97a30ec77 | ||
|
|
f0cd6e4f2c | ||
|
|
ba91cab8d2 | ||
|
|
a14975ce0c | ||
|
|
54a51ed666 | ||
|
|
1e6579f325 | ||
|
|
c74524f856 | ||
|
|
db90edaeaa | ||
|
|
1eacb4b9e4 | ||
|
|
3c2e0ad5b3 | ||
|
|
00e2b9d750 | ||
|
|
032bed7f96 | ||
|
|
9c2f4c2fdc | ||
|
|
6d12a64fe5 | ||
|
|
76be4e69ee | ||
|
|
3f4f076701 | ||
|
|
74d29b18ad | ||
|
|
303fd2fb85 | ||
|
|
b656ab5ead | ||
|
|
3207a16d0d | ||
|
|
c097e59568 | ||
|
|
29e5061922 | ||
|
|
71155af8fc | ||
|
|
a0ad3116d2 | ||
|
|
60774ae636 | ||
|
|
7ee7aa860b | ||
|
|
a94f717d71 | ||
|
|
2bf23735a3 | ||
|
|
b11c4861bb | ||
|
|
3918f862a0 | ||
|
|
ecc25fbd15 | ||
|
|
28f47481cc | ||
|
|
ecb78c1a40 | ||
|
|
7d2b1dfede | ||
|
|
310390c8b8 | ||
|
|
54b0110b75 | ||
|
|
6de9bf2601 | ||
|
|
0f8ca600f1 | ||
|
|
c151a9588b | ||
|
|
4a83846ddd | ||
|
|
83c70e073b | ||
|
|
92f198ef9d | ||
|
|
07b49d7453 | ||
|
|
a8c55a41d5 | ||
|
|
38c6c10ac9 | ||
|
|
23ae36911c | ||
|
|
b7055d7988 | ||
|
|
48e7dcf0d2 | ||
|
|
f4a29a0750 | ||
|
|
6d6a3a820a | ||
|
|
5c82ca42b3 | ||
|
|
465d41bd1c | ||
|
|
7ea5188c2d | ||
|
|
8ab0fa49c7 | ||
|
|
59dbcb0b0a | ||
|
|
774cbd433a | ||
|
|
5addd0b6cd | ||
|
|
87ebc102ad | ||
|
|
093dc899d3 | ||
|
|
b5b9469b27 | ||
|
|
390213c7e4 | ||
|
|
23f81e6d93 | ||
|
|
7035aa0ee2 | ||
|
|
b27e8b331c | ||
|
|
9164ae2297 | ||
|
|
b972f8e3a2 | ||
|
|
388eb181d6 | ||
|
|
93b433d299 | ||
|
|
8f541851f4 | ||
|
|
39ba8c7737 | ||
|
|
3892831333 | ||
|
|
4409333f34 | ||
|
|
e69bed0b94 | ||
|
|
a1c04a4f16 | ||
|
|
4dc228da3d | ||
|
|
f3e8fd8e4a | ||
|
|
4bcdedcf07 | ||
|
|
8a5c01f19e | ||
|
|
e6aee23f88 | ||
|
|
ac84e86dd8 | ||
|
|
e652cd7642 | ||
|
|
b1627aebb8 | ||
|
|
c35cd8f3a0 | ||
|
|
2cb64871bb | ||
|
|
d41b478b81 | ||
|
|
00eb58ff9c | ||
|
|
a783af3e86 | ||
|
|
a4aef00d65 | ||
|
|
6db4de888e | ||
|
|
5480ae18d3 | ||
|
|
853a83725f | ||
|
|
1517558cd3 | ||
|
|
d6b3b3507f | ||
|
|
ffb4d9e0ba | ||
|
|
e7ca8c91ec | ||
|
|
da92bed4d5 | ||
|
|
7f2d8ae5da | ||
|
|
13a08d776f | ||
|
|
14f8d8220c | ||
|
|
3aa81ceb1c | ||
|
|
7a86f936b8 | ||
|
|
f72883c6ae | ||
|
|
e9c45e3dbf | ||
|
|
0c97e821ee | ||
|
|
d27cd59a97 | ||
|
|
9eea2d2964 | ||
|
|
1f897c49f1 | ||
|
|
0676d1377a | ||
|
|
c1a94681f2 | ||
|
|
6539c8dd1b | ||
|
|
2dbcb34643 | ||
|
|
e013e99c1c | ||
|
|
46f6e09b51 | ||
|
|
97c708294d | ||
|
|
d77da4225c | ||
|
|
3e612906f4 | ||
|
|
636785e7eb | ||
|
|
7afdd95114 | ||
|
|
a53c04f050 | ||
|
|
5165085bfb | ||
|
|
2d77ffe6bb | ||
|
|
8f110ca521 | ||
|
|
944f9271ac | ||
|
|
75636f9b01 | ||
|
|
8bdc865433 | ||
|
|
383ca63dee | ||
|
|
5465641352 | ||
|
|
2464e106df | ||
|
|
e8bff09ffb | ||
|
|
ae1a01ff3d | ||
|
|
bc2014dbbe | ||
|
|
feb6270d6f | ||
|
|
c209a20108 | ||
|
|
913562f0d3 | ||
|
|
ebfeba4f78 | ||
|
|
a9a62db641 | ||
|
|
4161a9a0e5 | ||
|
|
795b23217b | ||
|
|
49f7dba060 | ||
|
|
93f3b0ddba | ||
|
|
9822caa29b | ||
|
|
47edbd3c53 | ||
|
|
fd56caffe6 | ||
|
|
76365d5f86 | ||
|
|
409886d852 | ||
|
|
f225d11b53 | ||
|
|
553a2acba8 | ||
|
|
affc5a912e | ||
|
|
309173748f | ||
|
|
a78ef43fe3 | ||
|
|
dc856c0bcf | ||
|
|
b74a3907a5 | ||
|
|
0a2897853b | ||
|
|
444d3d9f97 | ||
|
|
177931360d | ||
|
|
d356572dda | ||
|
|
ce5fc01c92 | ||
|
|
daf3551b86 | ||
|
|
9960be0a54 | ||
|
|
5a16eacf6f | ||
|
|
b1a6907e81 | ||
|
|
9f5cecf887 | ||
|
|
6d7a4c30a2 | ||
|
|
fdf81716b4 | ||
|
|
e69b2928cf | ||
|
|
1872751420 | ||
|
|
355ac59256 | ||
|
|
3f9371b30c | ||
|
|
5557ac8a6f | ||
|
|
311f97e2d4 | ||
|
|
fea199b0ce | ||
|
|
623d40c98e | ||
|
|
d3b9504e44 | ||
|
|
910ceb6004 | ||
|
|
e5052c8526 | ||
|
|
81537dce5b | ||
|
|
933b976829 | ||
|
|
d46865e1e9 | ||
|
|
91f92550dc | ||
|
|
da68f57b1c | ||
|
|
68d2587454 | ||
|
|
738c82a017 | ||
|
|
ff1a145792 | ||
|
|
ad8fd9b034 | ||
|
|
76d886a4e3 | ||
|
|
26c738828f | ||
|
|
6f15e1a200 | ||
|
|
1cbe92ed8c | ||
|
|
430cc35151 | ||
|
|
6ee56d59da | ||
|
|
ed09ec058a | ||
|
|
6b524e41e5 | ||
|
|
dc797e5833 | ||
|
|
dafa96c13e | ||
|
|
448b6882f6 | ||
|
|
14d41c9db7 | ||
|
|
2ba7551844 | ||
|
|
36e7d4808c | ||
|
|
4ebc7953b1 | ||
|
|
5a51c60f58 | ||
|
|
0cdec93645 | ||
|
|
14dfb38385 | ||
|
|
06201ee79d | ||
|
|
67a781e65c | ||
|
|
696be5b2ee | ||
|
|
2ca6b13626 | ||
|
|
845eb1f0ed | ||
|
|
8c19a64364 | ||
|
|
a2f7b8a534 | ||
|
|
63b93f0682 | ||
|
|
cd7d1b6d68 | ||
|
|
bea9285506 | ||
|
|
82580033db | ||
|
|
20990845d8 | ||
|
|
704e4daff8 | ||
|
|
98a3748577 | ||
|
|
4e5d7e4fff | ||
|
|
5db09e69de | ||
|
|
b45ded3b33 | ||
|
|
93472ba538 | ||
|
|
0a583f82eb | ||
|
|
5d98af56f2 | ||
|
|
65f2bd61ae | ||
|
|
91a8c60f0e | ||
|
|
4facc02671 | ||
|
|
05ceebcb1b | ||
|
|
30579c29be | ||
|
|
d7c212118e | ||
|
|
4d5ef757af | ||
|
|
42783352fc | ||
|
|
ff2047b685 | ||
|
|
b16a1e6c07 | ||
|
|
770279e013 | ||
|
|
1ab0c02604 | ||
|
|
61ed35e09c | ||
|
|
fe359f7a21 | ||
|
|
f2080c6915 | ||
|
|
71e5c19636 | ||
|
|
188bd721a5 | ||
|
|
50874e9ec7 | ||
|
|
4eef79de8a | ||
|
|
38113dbdb1 | ||
|
|
db77363f8c | ||
|
|
085c5a5d9b | ||
|
|
97e69e38a6 | ||
|
|
95787a5532 | ||
|
|
289fd68776 | ||
|
|
b1b6267a8a | ||
|
|
50b789e229 | ||
|
|
c0c9f5afd6 | ||
|
|
ed4eee1e51 | ||
|
|
1f802e5618 | ||
|
|
a64888719c | ||
|
|
971a043b47 | ||
|
|
8c3613e29f | ||
|
|
879dcb926c | ||
|
|
797af0ae2d | ||
|
|
0658d99891 | ||
|
|
31d7f00538 | ||
|
|
444deec2a0 | ||
|
|
36345eaba4 | ||
|
|
867b6769fe | ||
|
|
c4cd50192d | ||
|
|
7a6894cb7f | ||
|
|
a3fb29404e | ||
|
|
e05fe79dd3 | ||
|
|
a10c0cd87c | ||
|
|
76e6cf505e | ||
|
|
5ac5be4ca9 | ||
|
|
ead09b5724 | ||
|
|
58ec718890 | ||
|
|
0154c3b77b | ||
|
|
6fbb344271 | ||
|
|
22076c62a1 | ||
|
|
fdc65eb9ec | ||
|
|
03db30d50e | ||
|
|
74373ce898 | ||
|
|
11f8ef90da | ||
|
|
dfcaadf673 | ||
|
|
01d404c4ad | ||
|
|
9b681678ee | ||
|
|
e5c3961bf6 | ||
|
|
494617bce2 | ||
|
|
d647b53008 | ||
|
|
ae61729064 | ||
|
|
9891a60571 | ||
|
|
589cf29b85 | ||
|
|
832c2e6b68 | ||
|
|
569a2c2b5f | ||
|
|
4b186490dd | ||
|
|
d0c7cc3abe | ||
|
|
ae7644fbdc | ||
|
|
8756f35d48 | ||
|
|
6a009a5e2c | ||
|
|
cb39d9525b | ||
|
|
7c80f7895f | ||
|
|
cc738d9655 | ||
|
|
8bc0b080dc | ||
|
|
d4fb9a4b93 | ||
|
|
b7e31c54f2 | ||
|
|
bb11721d68 | ||
|
|
2b19800425 | ||
|
|
046bc782ab | ||
|
|
99b2fa2479 | ||
|
|
f5a2086f1f | ||
|
|
542d079eb1 | ||
|
|
31eb153edb | ||
|
|
92f39ccb5b | ||
|
|
e2f3912e14 | ||
|
|
523d1871dc | ||
|
|
29ef7aeb04 | ||
|
|
98afc1a6dd | ||
|
|
1bb3dd1911 | ||
|
|
a7f6945b12 | ||
|
|
59c9c71f36 | ||
|
|
c41e161d06 | ||
|
|
0b04e719ae | ||
|
|
7bcbe0f387 | ||
|
|
de6d4c73d2 | ||
|
|
f562d83ce6 | ||
|
|
3f56f26766 | ||
|
|
139c403ce5 | ||
|
|
956206dda4 | ||
|
|
ece11c796a | ||
|
|
8bce19c1ea | ||
|
|
bc8f6178e7 | ||
|
|
356005f612 | ||
|
|
5a21c108fe | ||
|
|
ca5b25ad68 | ||
|
|
88b6cb8b8b | ||
|
|
63118d1444 | ||
|
|
4fe6e5b494 | ||
|
|
d49cd04515 | ||
|
|
0128b3dcd6 | ||
|
|
f0eda70e86 | ||
|
|
b07c1edbba | ||
|
|
677b20a94c | ||
|
|
f7540a5483 | ||
|
|
2c38bd4799 | ||
|
|
a386cb22a0 | ||
|
|
80ba794a42 | ||
|
|
5a7f05ee3c | ||
|
|
c65ab74d31 | ||
|
|
c2dde474aa | ||
|
|
1cca07d601 | ||
|
|
653b008950 | ||
|
|
1386155331 | ||
|
|
9777316c64 | ||
|
|
5f57c9f71c | ||
|
|
9b8836481d | ||
|
|
fe012b4db4 | ||
|
|
12eb4bc93c | ||
|
|
5b17e46285 | ||
|
|
f8d7bb61a8 | ||
|
|
65cc2ab6a5 | ||
|
|
728ee05d45 | ||
|
|
b9e3320bf4 | ||
|
|
3ebd394165 | ||
|
|
128b7183fd | ||
|
|
aaa0b7a55e | ||
|
|
0ab62f7ab9 | ||
|
|
773efb00d2 | ||
|
|
f4440dd30a | ||
|
|
275c562ce7 | ||
|
|
d845cb6745 | ||
|
|
28b4db7239 | ||
|
|
a86f1249ee | ||
|
|
6a51d9b6de | ||
|
|
a797df31d7 | ||
|
|
13ce1be5d3 | ||
|
|
d5400f7e7d | ||
|
|
2eb5511c39 | ||
|
|
2ce9908f2d | ||
|
|
5a74ff52c2 | ||
|
|
3022504c0b | ||
|
|
262ed7420f | ||
|
|
fc77335828 | ||
|
|
c0e2300901 | ||
|
|
19dd51b6ab | ||
|
|
92a43c0ead | ||
|
|
b7ba53e732 | ||
|
|
a7b7c601a5 | ||
|
|
6cac6ea83b | ||
|
|
9c6a6f9134 | ||
|
|
37cb6b93fd | ||
|
|
72b349b75c | ||
|
|
f276cf10c8 | ||
|
|
5040108c31 | ||
|
|
55d21ef131 | ||
|
|
e035fcc62a | ||
|
|
21879ffd57 | ||
|
|
bf1eb3b85d | ||
|
|
b2cc42052f | ||
|
|
aa4d04e680 | ||
|
|
2b48d4ec91 | ||
|
|
e2edd40cb4 | ||
|
|
b5fb6892fe | ||
|
|
1365b51c71 | ||
|
|
399e2fd233 | ||
|
|
17560312bb | ||
|
|
b7b65b35b6 | ||
|
|
86bdb760d7 | ||
|
|
f3a548988c | ||
|
|
ec5fcd0136 | ||
|
|
a6cde7c0f6 | ||
|
|
fe3bf8f43e | ||
|
|
5f8a100d65 | ||
|
|
a3d418e155 | ||
|
|
08d50931b6 | ||
|
|
d12037b665 | ||
|
|
24b4cd45a2 | ||
|
|
7c5699736b | ||
|
|
9a56f03c4c | ||
|
|
60f146a7d0 | ||
|
|
3fa4e557e0 | ||
|
|
e40d5d6b71 | ||
|
|
5c24ec251e | ||
|
|
8a507eb203 | ||
|
|
3999dda5a5 | ||
|
|
3514d179dd | ||
|
|
387182e77e | ||
|
|
1c75aa99a1 | ||
|
|
02bd4cd4b4 | ||
|
|
36961e2937 | ||
|
|
17184891e7 | ||
|
|
07510d963a | ||
|
|
cf56ac2b41 | ||
|
|
8b99611ece | ||
|
|
09e3a00249 | ||
|
|
b7e4d6e217 | ||
|
|
cdb49c3672 | ||
|
|
036cffcc86 | ||
|
|
7f7bce08e3 | ||
|
|
902c59120a | ||
|
|
e2b48e4a4b | ||
|
|
9239151bf5 | ||
|
|
3703129570 | ||
|
|
550e575a3e | ||
|
|
02f120a9f7 | ||
|
|
80a84bb8cb | ||
|
|
a5840f0a32 | ||
|
|
9cfdae0afd | ||
|
|
ecc9331cdb | ||
|
|
02181a6c74 | ||
|
|
76117ff568 | ||
|
|
f45c817901 | ||
|
|
3ca4e5d7e1 | ||
|
|
ad0471f93b | ||
|
|
4cff55249c | ||
|
|
45c349c278 | ||
|
|
e23b840d9e | ||
|
|
0832af2661 | ||
|
|
605f3a5ef6 | ||
|
|
c733ede7c7 | ||
|
|
d80c2f805e | ||
|
|
bf8c3776f1 | ||
|
|
6dc9dcbea2 | ||
|
|
74a7310253 | ||
|
|
d6b258b138 | ||
|
|
75e3a3db1a | ||
|
|
f83f6e989c | ||
|
|
5b5e98e2c4 | ||
|
|
22d9b3c470 | ||
|
|
8596334ced | ||
|
|
f0585f5ffe | ||
|
|
34a49b9046 | ||
|
|
d13a0a65c3 | ||
|
|
ae27fcf6ad | ||
|
|
a150f937e0 | ||
|
|
56eae9923e | ||
|
|
002eb7e1bc | ||
|
|
4827ffd3b5 | ||
|
|
f88543fba8 | ||
|
|
b8451d4055 | ||
|
|
0036997ea6 | ||
|
|
55fe737bf7 | ||
|
|
11d477b0ce | ||
|
|
e24ccb512c | ||
|
|
cb1aaddd19 | ||
|
|
94e718f9cb | ||
|
|
1cc4291e10 | ||
|
|
98886b12f1 | ||
|
|
63af1a646a | ||
|
|
e0cc71935a | ||
|
|
5b13795dbe | ||
|
|
3f2280d2fc | ||
|
|
db8dce00b0 | ||
|
|
478d64f58f | ||
|
|
23df967ec2 | ||
|
|
a694635ee9 | ||
|
|
eb19109585 | ||
|
|
2b631b5d6f | ||
|
|
ec58c4ca54 | ||
|
|
5ee4d3f2ee | ||
|
|
784332dee8 | ||
|
|
6e13ffa218 | ||
|
|
4a885f26a0 | ||
|
|
9d80d23172 | ||
|
|
3056f9d0d5 | ||
|
|
bbc312f167 | ||
|
|
49d8f90140 | ||
|
|
2ef4d30f72 | ||
|
|
e74c3a0f59 | ||
|
|
6894f7e981 | ||
|
|
21bade5e85 | ||
|
|
d018916728 | ||
|
|
02d7775718 | ||
|
|
a7f02c9c6b | ||
|
|
40b038c826 | ||
|
|
be0f31ad9f | ||
|
|
61ccf5b46b | ||
|
|
44cab72e7e | ||
|
|
10acc63770 | ||
|
|
b48dc1327b | ||
|
|
07b05ade91 | ||
|
|
3b239c7b3b | ||
|
|
b7bc86a4d3 | ||
|
|
9f9ba278d7 | ||
|
|
0c1a5f0a1a | ||
|
|
bd2b0c9ae5 | ||
|
|
3a7b1fb32a | ||
|
|
b42093b971 | ||
|
|
01f93d7ceb | ||
|
|
6146308cc3 | ||
|
|
675cc80975 | ||
|
|
838ae5b351 | ||
|
|
a20996ab6f | ||
|
|
fcf0d7cce2 | ||
|
|
6404ecd08d | ||
|
|
a2d2fc17b0 | ||
|
|
82404f5aef | ||
|
|
e2fe51aab4 | ||
|
|
cf6c9f9005 | ||
|
|
8302431386 | ||
|
|
a4003c3c4b | ||
|
|
80852eb5a8 | ||
|
|
0fde13e46f | ||
|
|
a2cb929b48 | ||
|
|
a2c8607929 | ||
|
|
a27bbd21cf | ||
|
|
8e187acb28 | ||
|
|
29f0da7fb8 | ||
|
|
db3ae6b658 | ||
|
|
b00de53de2 | ||
|
|
43998395c9 | ||
|
|
9db86b94c3 | ||
|
|
789515c1d0 | ||
|
|
7a01ff0136 | ||
|
|
5b02faec3c | ||
|
|
dbf3418d74 | ||
|
|
636718021d | ||
|
|
57b47bca26 | ||
|
|
0eca13810e | ||
|
|
68d79f2a0f | ||
|
|
e68aa47d4c | ||
|
|
249dcf3932 | ||
|
|
ead77b9ad4 | ||
|
|
bdc5b20680 | ||
|
|
269a35ff01 | ||
|
|
248b9ab0b0 | ||
|
|
0329504246 | ||
|
|
2c35fdceff | ||
|
|
48b36fa08b | ||
|
|
0f82d123cf | ||
|
|
ff4b3adaa4 | ||
|
|
3718c6396e | ||
|
|
6875da69bb | ||
|
|
5cb766e596 | ||
|
|
2f34efede1 | ||
|
|
529f589a83 | ||
|
|
e5d6b3ba09 | ||
|
|
051dec6fb7 | ||
|
|
b8612502e2 | ||
|
|
6420e53c12 | ||
|
|
8e22c73f3e | ||
|
|
810048c754 | ||
|
|
9fa39c73fc | ||
|
|
c177980194 | ||
|
|
00f1c3f453 | ||
|
|
57cb4281fa | ||
|
|
b4c6ce22d0 | ||
|
|
491d1d3463 | ||
|
|
d544482827 | ||
|
|
00f7383ab0 | ||
|
|
e27d55e3ee | ||
|
|
74040af06f | ||
|
|
2d0accdb56 | ||
|
|
637427aed9 | ||
|
|
0a960506d0 | ||
|
|
36025dc74f | ||
|
|
2cde638aa9 | ||
|
|
973c0609a2 | ||
|
|
3fea8ab161 | ||
|
|
43641877ac | ||
|
|
7d9be933d7 | ||
|
|
0d013d4f2e | ||
|
|
d2761fe281 | ||
|
|
9ba7b9cd1f | ||
|
|
02e8b3e120 | ||
|
|
3cbd3a3f36 | ||
|
|
abb239e7fc | ||
|
|
c4700949e7 | ||
|
|
15c961a1dd | ||
|
|
8b96e18c96 | ||
|
|
19dbf2e20d | ||
|
|
0dc9c323d2 | ||
|
|
1969b8c679 | ||
|
|
2aec4cb735 | ||
|
|
2e023d9a29 | ||
|
|
63fe01ab22 | ||
|
|
5ae2eac4c1 | ||
|
|
0b610fdb6e | ||
|
|
37eeb883b6 | ||
|
|
40be22dada | ||
|
|
5b02fc32d6 | ||
|
|
756f9eb63a | ||
|
|
b667946fa5 | ||
|
|
492cae1877 | ||
|
|
bef75d63d7 | ||
|
|
c3e2e3b317 | ||
|
|
3bb935c499 | ||
|
|
59d000d7ec | ||
|
|
3b56f0f090 | ||
|
|
3ab6f6505b | ||
|
|
da00b95e55 | ||
|
|
bf80fd4841 | ||
|
|
32f985bcf4 | ||
|
|
facf31bace | ||
|
|
5928877cd0 | ||
|
|
e9d613fa9d | ||
|
|
6ffc3748d9 | ||
|
|
8438d8e0b4 | ||
|
|
ed30e0358b | ||
|
|
eaf0bd1fd7 | ||
|
|
d8624c1f19 | ||
|
|
1d32fae40d | ||
|
|
3f12adb3f0 | ||
|
|
cebadbc797 | ||
|
|
400b8856c9 | ||
|
|
7fad6b61d2 | ||
|
|
78f3ed4bc2 | ||
|
|
a64f7707cc | ||
|
|
e5d4f0c9e2 | ||
|
|
1edd0adfcc | ||
|
|
37db859ba3 | ||
|
|
1bf082f6da | ||
|
|
1af8f0c951 | ||
|
|
4dd3ec797d | ||
|
|
e08a20aa98 | ||
|
|
0f51e50b08 | ||
|
|
d7a77415c1 | ||
|
|
6be22e19ef | ||
|
|
a35d309d39 | ||
|
|
11bbddd195 | ||
|
|
c687d21e23 | ||
|
|
721c4a65f3 | ||
|
|
98744b5111 | ||
|
|
0517d21ebd | ||
|
|
8d31dd9ab6 | ||
|
|
4201914311 | ||
|
|
507aef0c77 | ||
|
|
e1263b4b9c | ||
|
|
78f9a0a2b8 | ||
|
|
6d58400178 | ||
|
|
777d3c3963 | ||
|
|
7ac162ea7e | ||
|
|
d0f5f4f46e | ||
|
|
9abc3592ad | ||
|
|
bd5842db3d | ||
|
|
ee980f5002 | ||
|
|
4d95e549ed | ||
|
|
53835b8fd8 | ||
|
|
112f416309 | ||
|
|
6285ade4fb | ||
|
|
c9c7fc6a01 | ||
|
|
c385687ce6 | ||
|
|
cbf3cd3bc2 | ||
|
|
6e3cd11729 | ||
|
|
e6bc9ed3b0 | ||
|
|
3ec79bbc03 | ||
|
|
a1bfc38679 | ||
|
|
fa3174b8f1 | ||
|
|
7e621e1c51 | ||
|
|
0284e57b9b | ||
|
|
d7d098e901 | ||
|
|
b4159c080b | ||
|
|
515c7f3c43 | ||
|
|
71324ae046 | ||
|
|
c453a50776 | ||
|
|
4d4be2e895 | ||
|
|
cb5e85be18 | ||
|
|
9ba22e3716 | ||
|
|
9f91506fed | ||
|
|
61215a0d76 | ||
|
|
dc64df4479 | ||
|
|
462d82f8e5 | ||
|
|
8fe68ee01c | ||
|
|
812b6d8d11 | ||
|
|
778a01b1aa | ||
|
|
d133eb632a | ||
|
|
44f175a90a | ||
|
|
d2dd525033 | ||
|
|
286bbb3ca4 | ||
|
|
b756b7d22f | ||
|
|
21991bd14e | ||
|
|
db2113fd6b | ||
|
|
e6e37613eb | ||
|
|
e2350edd17 | ||
|
|
78f8d31dc6 | ||
|
|
1e6032fe39 | ||
|
|
73120f904b | ||
|
|
4deef8a463 | ||
|
|
0463ffd804 | ||
|
|
b335299322 | ||
|
|
b7bcdb3eaa | ||
|
|
5a77c5e18e | ||
|
|
04161382a2 | ||
|
|
928ec8b49a | ||
|
|
4d781d52a7 | ||
|
|
06da8b9b9a | ||
|
|
ff5c52617e | ||
|
|
a7094451a0 | ||
|
|
84108b14a2 | ||
|
|
bd72d2c9fc | ||
|
|
e12030c433 | ||
|
|
8d5279c34e | ||
|
|
49560ac770 | ||
|
|
448d93c5e8 | ||
|
|
2dbcecfaaa | ||
|
|
f93222ee85 | ||
|
|
e18c62b1da | ||
|
|
7a1448aa57 | ||
|
|
064dac4abe | ||
|
|
92a7fc7c7c | ||
|
|
21d9ee0d73 | ||
|
|
7625198d01 | ||
|
|
5c40acf215 | ||
|
|
5666e005bd | ||
|
|
c466590f32 | ||
|
|
70e41f6536 | ||
|
|
3fc5a9f930 | ||
|
|
711d4218c4 | ||
|
|
8b7d3aeda2 | ||
|
|
7f87e0c4c7 | ||
|
|
6c0e2269be | ||
|
|
fe3db97ee9 | ||
|
|
f083a44415 | ||
|
|
30165893f7 | ||
|
|
8f295da232 | ||
|
|
b72434ce64 | ||
|
|
d9025d3f48 | ||
|
|
a6d76b4886 | ||
|
|
108300f7f1 | ||
|
|
74cfabb955 | ||
|
|
0391c5c44f | ||
|
|
bb828e2c51 | ||
|
|
2fca4a3321 | ||
|
|
43a0c58e70 | ||
|
|
2cb4e94838 | ||
|
|
a955420bed | ||
|
|
efc6a99370 | ||
|
|
6ffd34dcf0 | ||
|
|
d3d4428652 | ||
|
|
f52d9bc6f9 | ||
|
|
056f9c917a | ||
|
|
d779f5e15d | ||
|
|
121f783b66 | ||
|
|
36b08488a1 | ||
|
|
8ba4364153 | ||
|
|
d3798f2bff | ||
|
|
435add4fdd | ||
|
|
08e3b67977 | ||
|
|
6b2090a39f | ||
|
|
4526d04e04 | ||
|
|
5faf500982 | ||
|
|
f2ae969065 | ||
|
|
a3eae83762 | ||
|
|
9d9805c096 | ||
|
|
3fd5ddfd6a | ||
|
|
1c21efedfe | ||
|
|
707d9fbd86 | ||
|
|
abe0aa7baa | ||
|
|
09eff142e8 | ||
|
|
fbfdea68e4 | ||
|
|
ea069464d5 | ||
|
|
b1dff14a06 | ||
|
|
1acd60951d | ||
|
|
2b76d22baf | ||
|
|
a5796bf961 | ||
|
|
bb9298e008 | ||
|
|
a6e12d97a4 | ||
|
|
db28b5db67 | ||
|
|
8fc1064130 | ||
|
|
b780afe5f7 | ||
|
|
b98844704e | ||
|
|
70e94a99a6 | ||
|
|
7b9099f4f2 | ||
|
|
72d4d83e2a | ||
|
|
5d43557478 | ||
|
|
01206bd597 | ||
|
|
6ab18ae52c | ||
|
|
97137e17ff | ||
|
|
0958becf7e | ||
|
|
ed840b1045 | ||
|
|
1df2b7edfe | ||
|
|
0932d830f0 | ||
|
|
9100c2db3b | ||
|
|
ed2fa6ce1b | ||
|
|
63412b419b | ||
|
|
0098207a9a | ||
|
|
3f95fa336e | ||
|
|
21c0dce246 | ||
|
|
ebc813c9cf | ||
|
|
05addc4e62 | ||
|
|
fd95cc0da9 | ||
|
|
ac897ce3b9 | ||
|
|
cf4f3cbdaa | ||
|
|
7005c5aa84 | ||
|
|
bb6d33103e | ||
|
|
426848b63c | ||
|
|
70c8087f2d | ||
|
|
428539b1c9 | ||
|
|
7b63825d03 | ||
|
|
cc6d67469c | ||
|
|
592a269a64 | ||
|
|
414302b95c | ||
|
|
7fb2b51201 | ||
|
|
f6034c5012 | ||
|
|
421abc0d01 | ||
|
|
0a199807e7 | ||
|
|
03d50bfec1 | ||
|
|
644973f327 | ||
|
|
fe28c38a24 | ||
|
|
0c23dd6c9c | ||
|
|
804754e626 | ||
|
|
3b1372a22b | ||
|
|
e104ca4071 | ||
|
|
1e9848fb2b | ||
|
|
7ac3315851 | ||
|
|
b008ad3de2 | ||
|
|
f603422ae3 | ||
|
|
71dc0e9e72 | ||
|
|
58394f5b6f | ||
|
|
bc4ffe7eaf | ||
|
|
c45d848e2a | ||
|
|
bf766b1599 | ||
|
|
16fb327e1b | ||
|
|
0abd3cca60 | ||
|
|
4bb846d522 | ||
|
|
e77e6219d3 | ||
|
|
253087fcaa | ||
|
|
ee0be9c2a0 | ||
|
|
247488ff07 | ||
|
|
73b2849f2a | ||
|
|
ef4f584745 | ||
|
|
7dc38ccd52 | ||
|
|
80ef7645ff | ||
|
|
fadff54087 | ||
|
|
95a5f28754 | ||
|
|
aff1c988a4 | ||
|
|
127e1bde3a | ||
|
|
6d30079412 | ||
|
|
8f1b19fb7e | ||
|
|
c6704835aa | ||
|
|
55b4b92b8f | ||
|
|
93afb677c0 | ||
|
|
1b4ca70d35 | ||
|
|
ce164dbd9c | ||
|
|
a821347c7f | ||
|
|
4a9cce26cd | ||
|
|
c854efc784 | ||
|
|
fdb544b336 | ||
|
|
33497e72d0 | ||
|
|
3e0c546e3b | ||
|
|
f15cde2b63 | ||
|
|
85465e7616 | ||
|
|
2178b22c8f | ||
|
|
1b47e4478f | ||
|
|
c2020d90fb | ||
|
|
8b0294d5fe | ||
|
|
c6217b2899 | ||
|
|
c449fbf343 | ||
|
|
c89c2619cb | ||
|
|
86077a2e87 | ||
|
|
f952eb45cc | ||
|
|
ee034830da | ||
|
|
b254e67fd1 | ||
|
|
91bcd9e3a0 | ||
|
|
2c6198111f | ||
|
|
1b9ebde1c3 | ||
|
|
e9e30a8196 | ||
|
|
35baf2aace | ||
|
|
666abd5c09 | ||
|
|
c94f40fc0a | ||
|
|
cf582b8729 | ||
|
|
54d78b4325 | ||
|
|
2e790f9762 | ||
|
|
314b6614cb | ||
|
|
8391ea7dd9 | ||
|
|
b8d036c434 | ||
|
|
54bfb51dd8 | ||
|
|
b1fa56e8da | ||
|
|
51ed1b13d3 | ||
|
|
efc9a1d6db | ||
|
|
ce7c7cb24d | ||
|
|
d5c454aff6 | ||
|
|
26351a2c19 | ||
|
|
c2014ab592 | ||
|
|
bde4e0e663 | ||
|
|
0e38f474fc | ||
|
|
62e9bef633 | ||
|
|
8d02d21009 | ||
|
|
b24330955a | ||
|
|
e2c5a3e25b | ||
|
|
2e908bf62a | ||
|
|
7da0a5ddc6 | ||
|
|
b0f519e7a8 | ||
|
|
bb43709356 | ||
|
|
106ff8cce0 | ||
|
|
8997cd5560 | ||
|
|
80db127967 | ||
|
|
f666841997 | ||
|
|
533d473b7d | ||
|
|
c4e59874fb | ||
|
|
003fd2f720 | ||
|
|
0e52c6229b | ||
|
|
2ec7565474 | ||
|
|
e63dcf7530 | ||
|
|
daa021383a | ||
|
|
5f17ed0d9b | ||
|
|
49eadb2f98 | ||
|
|
873dc64585 | ||
|
|
8f3a7f332a | ||
|
|
b2f0fad78f | ||
|
|
230987e819 | ||
|
|
3fe2c091cc | ||
|
|
957a8884fb | ||
|
|
acdcd2b694 | ||
|
|
bf685734ec | ||
|
|
d32a806351 | ||
|
|
3e48ba0dbc | ||
|
|
7f3d57dda8 | ||
|
|
a80d26914a | ||
|
|
c08a0ebc07 | ||
|
|
c19f322914 | ||
|
|
0ee3a9dadd | ||
|
|
ff9301990d | ||
|
|
f3c46d66e3 | ||
|
|
4be2f76938 | ||
|
|
02d3754d1e | ||
|
|
fa2cb8d61d | ||
|
|
d24d074ee4 | ||
|
|
659826ba3e | ||
|
|
e6ab0dd2ca | ||
|
|
08fb52ec8c | ||
|
|
b9df4728f1 | ||
|
|
8da33254f4 | ||
|
|
f6e4558074 | ||
|
|
7b2366db70 | ||
|
|
9c511a0dc7 | ||
|
|
9537e40e79 | ||
|
|
58416c69a3 | ||
|
|
83f43b00a5 | ||
|
|
7354bb18cf | ||
|
|
f383f03df7 | ||
|
|
3767befe3a | ||
|
|
239618e700 | ||
|
|
58be84825d | ||
|
|
2f884b27c2 | ||
|
|
27eb2ffd3b | ||
|
|
247daab1a7 | ||
|
|
d938014328 | ||
|
|
64c43af4f4 | ||
|
|
261995c57e | ||
|
|
c5259c013b | ||
|
|
7bf3739b88 | ||
|
|
f4d60f891f | ||
|
|
3f42eeb121 | ||
|
|
b0e6be3355 | ||
|
|
39158a4c93 | ||
|
|
2c244f981f | ||
|
|
0a1d6361d8 | ||
|
|
b12035d190 | ||
|
|
44c5f7fe76 | ||
|
|
99da34a4bf | ||
|
|
ce0a4906ad | ||
|
|
ba4f254aa9 | ||
|
|
cec94b0eeb | ||
|
|
637a4234fa | ||
|
|
a5c06c85fa | ||
|
|
da32ac49ce | ||
|
|
3942243c5d | ||
|
|
5e95cf76e4 | ||
|
|
690a5f9158 | ||
|
|
6c8a888822 | ||
|
|
5488182a69 | ||
|
|
44012dd60d | ||
|
|
4d42b714be | ||
|
|
f51de9fb15 | ||
|
|
129090f0f6 | ||
|
|
2351787aa6 | ||
|
|
4db00f967f | ||
|
|
8d90748586 | ||
|
|
40b08512c4 | ||
|
|
22c4126ba5 | ||
|
|
017032bb4b | ||
|
|
71d4ae3fd0 | ||
|
|
56c2c3835f | ||
|
|
bc12bc0a1f | ||
|
|
fa291c34fb | ||
|
|
850e3057ed | ||
|
|
a3c95f281a | ||
|
|
b1003ace6f | ||
|
|
d8c9997a13 | ||
|
|
bf54a8b514 | ||
|
|
2473968416 | ||
|
|
92348098eb | ||
|
|
f7033a3346 | ||
|
|
5388178e8a | ||
|
|
41094cee0b | ||
|
|
d1a5fdc34a | ||
|
|
2e20dea9fc | ||
|
|
13396661f4 | ||
|
|
ddab8bd093 | ||
|
|
f16199c056 | ||
|
|
0f2d3b866b | ||
|
|
b8cfef5271 | ||
|
|
2b7197054f | ||
|
|
ad0a222ec0 | ||
|
|
6e08e9d982 | ||
|
|
3083bd21de | ||
|
|
02e9bb7bf8 | ||
|
|
6f8edd57ae | ||
|
|
c76ae1723f | ||
|
|
69c3b7fd9d | ||
|
|
d7f6bf262e | ||
|
|
bea427cebd | ||
|
|
ae905b0ae1 | ||
|
|
9e057920ce | ||
|
|
ac0680e9eb | ||
|
|
7a671773f2 | ||
|
|
87d4ee6113 | ||
|
|
e474b9e989 | ||
|
|
2b5eae2b09 | ||
|
|
01ded85842 | ||
|
|
cc9ed75dd9 | ||
|
|
b1416abab6 | ||
|
|
bf9b61c790 | ||
|
|
a179df7937 | ||
|
|
13c1b482dd | ||
|
|
71b0add384 | ||
|
|
ac89fac641 | ||
|
|
96769258cb | ||
|
|
db8b916444 | ||
|
|
46ef4ef03a | ||
|
|
64f8608ed6 | ||
|
|
f4b095c42e | ||
|
|
d1f2b629d4 | ||
|
|
330d764d3b | ||
|
|
8b026a66fd | ||
|
|
7788acb1ab | ||
|
|
2cd05e5976 | ||
|
|
3cea95052a | ||
|
|
20c68c9993 | ||
|
|
49853562e2 | ||
|
|
ac7ef3ec32 | ||
|
|
e1bd9f2ed3 | ||
|
|
f5d0b9895b | ||
|
|
2fad51aae1 | ||
|
|
9745e31cb8 | ||
|
|
bd2b08d5a3 | ||
|
|
8ce46dbe07 | ||
|
|
8a98023414 | ||
|
|
233f603cc1 | ||
|
|
0cae66577c | ||
|
|
507806f969 | ||
|
|
8f79637669 | ||
|
|
dea0471d46 | ||
|
|
026483186a | ||
|
|
906effb54f | ||
|
|
9544bc192d | ||
|
|
efa22d3d71 | ||
|
|
23beef88a9 | ||
|
|
1c5db966aa | ||
|
|
6ad40b3a85 | ||
|
|
6b5ba346d0 | ||
|
|
b469d5cc62 | ||
|
|
aef8f792fb | ||
|
|
e8474de3ea | ||
|
|
3ab7336ea7 | ||
|
|
43048c7f74 | ||
|
|
680033ce4d | ||
|
|
397feff56e | ||
|
|
53ff7d91a8 | ||
|
|
8077efca7d | ||
|
|
77c3728447 | ||
|
|
693c4232df | ||
|
|
aa356e53b8 | ||
|
|
d956434b59 | ||
|
|
9a27cf1e9d | ||
|
|
aa38b0b73b | ||
|
|
d3cbd6b05c | ||
|
|
312a3b089d | ||
|
|
b846bbd819 | ||
|
|
f7eb6b70fb | ||
|
|
f56be26f60 | ||
|
|
4c54be504c | ||
|
|
b1f36f06ca | ||
|
|
d3bf64ad4b | ||
|
|
e49bcccfb1 | ||
|
|
62ab12711f | ||
|
|
d7097d666b | ||
|
|
975f01067b | ||
|
|
92d0305964 | ||
|
|
7da62bfb79 | ||
|
|
4129583cb6 | ||
|
|
e5bc7669fd | ||
|
|
79464adea1 | ||
|
|
4722228b86 | ||
|
|
df7774663c | ||
|
|
e83e8d39d7 | ||
|
|
6b92b96bb2 | ||
|
|
21a5f882a1 | ||
|
|
0eec014e5d | ||
|
|
ea5cfc962a | ||
|
|
46da311781 | ||
|
|
e4d9adbd71 | ||
|
|
36c043703a | ||
|
|
72f771ef45 | ||
|
|
a4b427d4c3 | ||
|
|
52bf33a5bc | ||
|
|
627987d8ff | ||
|
|
3541946aed | ||
|
|
44feb9a567 | ||
|
|
08d64f0387 | ||
|
|
00a673b03c | ||
|
|
13e2c6d8e1 | ||
|
|
6f1b350c3a | ||
|
|
55690c7b8d | ||
|
|
9a83aa49de | ||
|
|
d90a737187 | ||
|
|
73aa4c1671 | ||
|
|
701f97890a | ||
|
|
89600e8dd6 | ||
|
|
e690855bc3 | ||
|
|
b497531c76 | ||
|
|
995eaa289b | ||
|
|
fecec879a7 | ||
|
|
3a28f0dc73 | ||
|
|
139cedabf9 | ||
|
|
8a29ed59df | ||
|
|
da45568ba3 | ||
|
|
fc819d0bd9 | ||
|
|
63f9161f72 | ||
|
|
734033a05f | ||
|
|
157ef67688 | ||
|
|
6a2827695a | ||
|
|
e047f16684 | ||
|
|
9ade382800 | ||
|
|
44d0f0256f | ||
|
|
7d47e3d387 | ||
|
|
8ac908b38a | ||
|
|
db95cc18d8 | ||
|
|
8b061d7ed2 | ||
|
|
f1c89cb4f5 | ||
|
|
91bb55c45d | ||
|
|
418cc93231 | ||
|
|
aa52ab8208 | ||
|
|
c696c12cff | ||
|
|
e83e226e08 | ||
|
|
f4e0a6b968 | ||
|
|
85166e0140 | ||
|
|
02973df5f2 | ||
|
|
17b58ef7ea | ||
|
|
0b24b2d3c4 | ||
|
|
c060401781 | ||
|
|
d0fd036e37 | ||
|
|
dcfca6f18d | ||
|
|
46b40010ae | ||
|
|
06d38550f3 | ||
|
|
63328d4091 | ||
|
|
aad3d15976 | ||
|
|
36f7ffd0c9 | ||
|
|
c2e3270948 | ||
|
|
36b044f81e | ||
|
|
5968779f4b | ||
|
|
ebaf977ecf | ||
|
|
834a31a021 | ||
|
|
b43febe8c3 | ||
|
|
8a7f5ae9a9 | ||
|
|
41866eed87 | ||
|
|
140cf92b3b | ||
|
|
63171ebb07 | ||
|
|
68ea797082 | ||
|
|
78d46b371f | ||
|
|
a56df93f31 | ||
|
|
875be659a1 | ||
|
|
19a62c240d | ||
|
|
e8f796f8a6 | ||
|
|
6c2b739c53 | ||
|
|
5201210bae | ||
|
|
36f9773b90 | ||
|
|
6467699ca4 | ||
|
|
4a5d8786ed | ||
|
|
6fb11c619a | ||
|
|
133d92da58 | ||
|
|
fd3a378353 | ||
|
|
3ae6ec7ef6 | ||
|
|
327c37def7 | ||
|
|
0185a9358c | ||
|
|
a9a7e2f270 | ||
|
|
c46b6864af | ||
|
|
da4a8c89a8 | ||
|
|
e87e7b378a | ||
|
|
56334ccb2d | ||
|
|
6bb16fca28 |
@@ -0,0 +1,5 @@
|
||||
Content-Type: application/X-atf-atffile; version="1"
|
||||
|
||||
prop: test-suite = bind9
|
||||
|
||||
tp: lib
|
||||
@@ -1,4 +1,4 @@
|
||||
Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright (C) 1996-2003 Internet Software Consortium.
|
||||
|
||||
Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,9 +13,15 @@ LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
$Id: COPYRIGHT,v 1.15.188.1 2010/01/04 23:48:10 tbox Exp $
|
||||
$Id: COPYRIGHT,v 1.15.188.3 2011/02/22 06:36:35 marka Exp $
|
||||
|
||||
Portions Copyright (C) 1996-2001 Nominum, Inc.
|
||||
Portions of this code release fall under one or more of the
|
||||
following Copyright notices. Please see individual source
|
||||
files for details.
|
||||
|
||||
For binary releases also see: OpenSSL-LICENSE.
|
||||
|
||||
Copyright (C) 1996-2001 Nominum, Inc.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -28,3 +34,485 @@ ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
|
||||
OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (C) 1995-2000 by Network Associates, Inc.
|
||||
|
||||
Permission to use, copy, modify, and/or distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND ISC AND NETWORK ASSOCIATES DISCLAIMS
|
||||
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED
|
||||
WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE
|
||||
FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
|
||||
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (C) 2002 Stichting NLnet, Netherlands, stichting@nlnet.nl.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the
|
||||
above copyright notice and this permission notice appear in all
|
||||
copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND STICHTING NLNET
|
||||
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
|
||||
STICHTING NLNET BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
|
||||
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
|
||||
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
|
||||
USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
The development of Dynamically Loadable Zones (DLZ) for Bind 9 was
|
||||
conceived and contributed by Rob Butler.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the
|
||||
above copyright notice and this permission notice appear in all
|
||||
copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND ROB BUTLER
|
||||
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
|
||||
ROB BUTLER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
|
||||
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
|
||||
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
|
||||
USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1987, 1990, 1993, 1994
|
||||
The Regents of the University of California. All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
3. All advertising materials mentioning features or use of this software
|
||||
must display the following acknowledgement:
|
||||
This product includes software developed by the University of
|
||||
California, Berkeley and its contributors.
|
||||
4. Neither the name of the University nor the names of its contributors
|
||||
may be used to endorse or promote products derived from this software
|
||||
without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (C) The Internet Society 2005. This version of
|
||||
this module is part of RFC 4178; see the RFC itself for
|
||||
full legal notices.
|
||||
|
||||
(The above copyright notice is per RFC 3978 5.6 (a), q.v.)
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 2004 Masarykova universita
|
||||
(Masaryk University, Brno, Czech Republic)
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions are met:
|
||||
|
||||
1. Redistributions of source code must retain the above copyright notice,
|
||||
this list of conditions and the following disclaimer.
|
||||
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
|
||||
3. Neither the name of the University nor the names of its contributors may
|
||||
be used to endorse or promote products derived from this software
|
||||
without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
||||
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
|
||||
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
POSSIBILITY OF SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1997 - 2003 Kungliga Tekniska Högskolan
|
||||
(Royal Institute of Technology, Stockholm, Sweden).
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
|
||||
3. Neither the name of the Institute nor the names of its contributors
|
||||
may be used to endorse or promote products derived from this software
|
||||
without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1998 Doug Rabson
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright ((c)) 2002, Rice University
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions are
|
||||
met:
|
||||
|
||||
* Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
|
||||
* Redistributions in binary form must reproduce the above
|
||||
copyright notice, this list of conditions and the following
|
||||
disclaimer in the documentation and/or other materials provided
|
||||
with the distribution.
|
||||
|
||||
* Neither the name of Rice University (RICE) nor the names of its
|
||||
contributors may be used to endorse or promote products derived
|
||||
from this software without specific prior written permission.
|
||||
|
||||
|
||||
This software is provided by RICE and the contributors on an "as is"
|
||||
basis, without any representations or warranties of any kind, express
|
||||
or implied including, but not limited to, representations or
|
||||
warranties of non-infringement, merchantability or fitness for a
|
||||
particular purpose. In no event shall RICE or contributors be liable
|
||||
for any direct, indirect, incidental, special, exemplary, or
|
||||
consequential damages (including, but not limited to, procurement of
|
||||
substitute goods or services; loss of use, data, or profits; or
|
||||
business interruption) however caused and on any theory of liability,
|
||||
whether in contract, strict liability, or tort (including negligence
|
||||
or otherwise) arising in any way out of the use of this software, even
|
||||
if advised of the possibility of such damage.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1993 by Digital Equipment Corporation.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies, and that
|
||||
the name of Digital Equipment Corporation not be used in advertising or
|
||||
publicity pertaining to distribution of the document or software without
|
||||
specific, written prior permission.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND DIGITAL EQUIPMENT CORP. DISCLAIMS ALL
|
||||
WARRANTIES WITH REGARD TO THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES
|
||||
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL DIGITAL EQUIPMENT
|
||||
CORPORATION BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
|
||||
DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
|
||||
PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
|
||||
ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
|
||||
SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright 2000 Aaron D. Gifford. All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
3. Neither the name of the copyright holder nor the names of contributors
|
||||
may be used to endorse or promote products derived from this software
|
||||
without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) AND CONTRIBUTOR(S) ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR(S) OR CONTRIBUTOR(S) BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1998 Doug Rabson.
|
||||
Copyright (c) 2001 Jake Burkholder.
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
|
||||
All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in the
|
||||
documentation and/or other materials provided with the distribution.
|
||||
3. Neither the name of the project nor the names of its contributors
|
||||
may be used to endorse or promote products derived from this software
|
||||
without specific prior written permission.
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
|
||||
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1999-2000 by Nortel Networks Corporation
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND NORTEL NETWORKS DISCLAIMS
|
||||
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
|
||||
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL NORTEL NETWORKS
|
||||
BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES
|
||||
OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,
|
||||
WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,
|
||||
ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
|
||||
SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 2000-2002 Japan Network Information Center. All rights reserved.
|
||||
|
||||
By using this file, you agree to the terms and conditions set forth bellow.
|
||||
|
||||
LICENSE TERMS AND CONDITIONS
|
||||
|
||||
The following License Terms and Conditions apply, unless a different
|
||||
license is obtained from Japan Network Information Center ("JPNIC"),
|
||||
a Japanese association, Kokusai-Kougyou-Kanda Bldg 6F, 2-3-4 Uchi-Kanda,
|
||||
Chiyoda-ku, Tokyo 101-0047, Japan.
|
||||
|
||||
1. Use, Modification and Redistribution (including distribution of any
|
||||
modified or derived work) in source and/or binary forms is permitted
|
||||
under this License Terms and Conditions.
|
||||
|
||||
2. Redistribution of source code must retain the copyright notices as they
|
||||
appear in each source code file, this License Terms and Conditions.
|
||||
|
||||
3. Redistribution in binary form must reproduce the Copyright Notice,
|
||||
this License Terms and Conditions, in the documentation and/or other
|
||||
materials provided with the distribution. For the purposes of binary
|
||||
distribution the "Copyright Notice" refers to the following language:
|
||||
"Copyright (c) 2000-2002 Japan Network Information Center. All rights
|
||||
reserved."
|
||||
|
||||
4. The name of JPNIC may not be used to endorse or promote products
|
||||
derived from this Software without specific prior written approval of
|
||||
JPNIC.
|
||||
|
||||
5. Disclaimer/Limitation of Liability: THIS SOFTWARE IS PROVIDED BY JPNIC
|
||||
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
|
||||
PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL JPNIC BE LIABLE
|
||||
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
|
||||
BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
|
||||
WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
|
||||
OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
|
||||
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (C) 2004 Nominet, Ltd.
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND NOMINET DISCLAIMS ALL WARRANTIES WITH
|
||||
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Portions Copyright RSA Security Inc.
|
||||
|
||||
License to copy and use this software is granted provided that it is
|
||||
identified as "RSA Security Inc. PKCS #11 Cryptographic Token Interface
|
||||
(Cryptoki)" in all material mentioning or referencing this software.
|
||||
|
||||
License is also granted to make and use derivative works provided that
|
||||
such works are identified as "derived from the RSA Security Inc. PKCS #11
|
||||
Cryptographic Token Interface (Cryptoki)" in all material mentioning or
|
||||
referencing the derived work.
|
||||
|
||||
RSA Security Inc. makes no representations concerning either the
|
||||
merchantability of this software or the suitability of this software for
|
||||
any particular purpose. It is provided "as is" without express or implied
|
||||
warranty of any kind.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 1996, David Mazieres <dm@uun.org>
|
||||
Copyright (c) 2008, Damien Miller <djm@openbsd.org>
|
||||
|
||||
Permission to use, copy, modify, and distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
||||
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
||||
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
Copyright (c) 2000-2001 The OpenSSL Project. All rights reserved.
|
||||
|
||||
Redistribution and use in source and binary forms, with or without
|
||||
modification, are permitted provided that the following conditions
|
||||
are met:
|
||||
|
||||
1. Redistributions of source code must retain the above copyright
|
||||
notice, this list of conditions and the following disclaimer.
|
||||
|
||||
2. Redistributions in binary form must reproduce the above copyright
|
||||
notice, this list of conditions and the following disclaimer in
|
||||
the documentation and/or other materials provided with the
|
||||
distribution.
|
||||
|
||||
3. All advertising materials mentioning features or use of this
|
||||
software must display the following acknowledgment:
|
||||
"This product includes software developed by the OpenSSL Project
|
||||
for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
|
||||
|
||||
4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
|
||||
endorse or promote products derived from this software without
|
||||
prior written permission. For written permission, please contact
|
||||
licensing@OpenSSL.org.
|
||||
|
||||
5. Products derived from this software may not be called "OpenSSL"
|
||||
nor may "OpenSSL" appear in their names without prior written
|
||||
permission of the OpenSSL Project.
|
||||
|
||||
6. Redistributions of any form whatsoever must retain the following
|
||||
acknowledgment:
|
||||
"This product includes software developed by the OpenSSL Project
|
||||
for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
|
||||
|
||||
THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
|
||||
EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
|
||||
ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
||||
NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
|
||||
LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
||||
STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
||||
OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
|
||||
|
||||
@@ -0,0 +1,68 @@
|
||||
2988. [experimental] Added a "dlopen" DLZ driver, allowing the creation
|
||||
of external DLZ drivers that can be loaded as
|
||||
shared objects at runtime rather than linked with
|
||||
named. Currently this is switched on via a
|
||||
compile-time option, "configure --with-dlz-dlopen".
|
||||
Note: the syntax for configuring DLZ zones
|
||||
is likely to be refined in future releases.
|
||||
(Contributed by Andrew Tridgell of the Samba
|
||||
project.) [RT #22629]
|
||||
|
||||
3000. [bug] More TKEY/GSS fixes:
|
||||
- nsupdate can now get the default realm from
|
||||
the user's Kerberos principal
|
||||
- corrected gsstest compilation flags
|
||||
- improved documentation
|
||||
- fixed some NULL dereferences
|
||||
[RT #22795]
|
||||
|
||||
3003. [experimental] Added update-policy match type "external",
|
||||
enabling named to defer the decision of whether to
|
||||
allow a dynamic update to an external daemon.
|
||||
(Contributed by Andrew Tridgell.) [RT #22758]
|
||||
|
||||
|
||||
2991. [contrib] contrib/zone-edit.sh: A simple zone editing tool for
|
||||
dynamic zones. [RT #22365]
|
||||
|
||||
2992. [contrib] contrib/check-secure-delegation.pl: A simple tool
|
||||
for looking at a secure delegation. [RT #22059]
|
||||
|
||||
3005. [port] Solaris: Work around the lack of
|
||||
gsskrb5_register_acceptor_identity() by setting
|
||||
the KRB5_KTNAME environment variable to the
|
||||
contents of tkey-gssapi-keytab. Also fixed
|
||||
test errors on MacOSX. [RT #22853]
|
||||
|
||||
2948. [port] MacOS: provide a mechanism to configure the test
|
||||
interfaces at reboot. See bin/tests/system/README
|
||||
for details.
|
||||
|
||||
3013. [bug] The DNS64 ttl was not always being set as expected.
|
||||
[RT #23034]
|
||||
|
||||
3022. [bug] Fixed rpz SERVFAILs after failed zone transfers
|
||||
[RT #23246]
|
||||
|
||||
3038. [bug] Install <dns/rpz.h>. [RT #23342]
|
||||
|
||||
3045. [removed] Replaced by change #3050.
|
||||
|
||||
3054. [bug] Added elliptic curve support check in
|
||||
GOST OpenSSL engine detection. [RT #23485]
|
||||
|
||||
3072. [bug] dns_dns64_aaaaok() potential NULL pointer dereference.
|
||||
[RT #20256]
|
||||
|
||||
3082. [port] strtok_r is threads only. [RT #23747]
|
||||
|
||||
3087. [bug] DDNS updates using SIG(0) with update-policy match
|
||||
type "external" could cause a crash. [RT #23735]
|
||||
|
||||
3093. [bug] Fix gssapi/kerberos dependencies [RT #23836]
|
||||
|
||||
3094. [doc] Expand dns64 documentation.
|
||||
|
||||
3096. [bug] Set KRB5_KTNAME before calling log_cred() in
|
||||
dst_gssapi_acceptctx(). [RT #24004]
|
||||
|
||||
@@ -0,0 +1,313 @@
|
||||
Summary of functional enhancements from prior major releases of BIND 9:
|
||||
|
||||
BIND 9.6.0
|
||||
|
||||
Full NSEC3 support
|
||||
|
||||
Automatic zone re-signing
|
||||
|
||||
New update-policy methods tcp-self and 6to4-self
|
||||
|
||||
The BIND 8 resolver library, libbind, has been removed from the
|
||||
BIND 9 distribution and is now available as a separate download.
|
||||
|
||||
Change the default pid file location from /var/run to
|
||||
/var/run/{named,lwresd} for improved chroot/setuid support.
|
||||
|
||||
BIND 9.5.0
|
||||
|
||||
GSS-TSIG support (RFC 3645).
|
||||
|
||||
DHCID support.
|
||||
|
||||
Experimental http server and statistics support for named via xml.
|
||||
|
||||
More detailed statistics counters including those supported in BIND 8.
|
||||
|
||||
Faster ACL processing.
|
||||
|
||||
Use Doxygen to generate internal documentation.
|
||||
|
||||
Efficient LRU cache-cleaning mechanism.
|
||||
|
||||
NSID support.
|
||||
|
||||
BIND 9.4.0
|
||||
|
||||
Implemented "additional section caching (or acache)", an
|
||||
internal cache framework for additional section content to
|
||||
improve response performance. Several configuration options
|
||||
were provided to control the behavior.
|
||||
|
||||
New notify type 'master-only'. Enable notify for master
|
||||
zones only.
|
||||
|
||||
Accept 'notify-source' style syntax for query-source.
|
||||
|
||||
rndc now allows addresses to be set in the server clauses.
|
||||
|
||||
New option "allow-query-cache". This lets "allow-query"
|
||||
be used to specify the default zone access level rather
|
||||
than having to have every zone override the global value.
|
||||
"allow-query-cache" can be set at both the options and view
|
||||
levels. If "allow-query-cache" is not set then "allow-recursion"
|
||||
is used if set, otherwise "allow-query" is used if set
|
||||
unless "recursion no;" is set in which case "none;" is used,
|
||||
otherwise the default (localhost; localnets;) is used.
|
||||
|
||||
rndc: the source address can now be specified.
|
||||
|
||||
ixfr-from-differences now takes master and slave in addition
|
||||
to yes and no at the options and view levels.
|
||||
|
||||
Allow the journal's name to be changed via named.conf.
|
||||
|
||||
'rndc notify zone [class [view]]' resend the NOTIFY messages
|
||||
for the specified zone.
|
||||
|
||||
'dig +trace' now randomly selects the next servers to try.
|
||||
Report if there is a bad delegation.
|
||||
|
||||
Improve check-names error messages.
|
||||
|
||||
Make public the function to read a key file, dst_key_read_public().
|
||||
|
||||
dig now returns the byte count for axfr/ixfr.
|
||||
|
||||
allow-update is now settable at the options / view level.
|
||||
|
||||
named-checkconf now checks the logging configuration.
|
||||
|
||||
host now can turn on memory debugging flags with '-m'.
|
||||
|
||||
Don't send notify messages to self.
|
||||
|
||||
Perform sanity checks on NS records which refer to 'in zone' names.
|
||||
|
||||
New zone option "notify-delay". Specify a minimum delay
|
||||
between sets of NOTIFY messages.
|
||||
|
||||
Extend adjusting TTL warning messages.
|
||||
|
||||
Named and named-checkzone can now both check for non-terminal
|
||||
wildcard records.
|
||||
|
||||
"rndc freeze/thaw" now freezes/thaws all zones.
|
||||
|
||||
named-checkconf now check acls to verify that they only
|
||||
refer to existing acls.
|
||||
|
||||
The server syntax has been extended to support a range of
|
||||
servers.
|
||||
|
||||
Report differences between hints and real NS rrset and
|
||||
associated address records.
|
||||
|
||||
Preserve the case of domain names in rdata during zone
|
||||
transfers.
|
||||
|
||||
Restructured the data locking framework using architecture
|
||||
dependent atomic operations (when available), improving
|
||||
response performance on multi-processor machines significantly.
|
||||
x86, x86_64, alpha, powerpc, and mips are currently supported.
|
||||
|
||||
UNIX domain controls are now supported.
|
||||
|
||||
Add support for additional zone file formats for improving
|
||||
loading performance. The masterfile-format option in
|
||||
named.conf can be used to specify a non-default format. A
|
||||
separate command named-compilezone was provided to generate
|
||||
zone files in the new format. Additionally, the -I and -O
|
||||
options for dnssec-signzone specify the input and output
|
||||
formats.
|
||||
|
||||
dnssec-signzone can now randomize signature end times
|
||||
(dnssec-signzone -j jitter).
|
||||
|
||||
Add support for CH A record.
|
||||
|
||||
Add additional zone data constancy checks. named-checkzone
|
||||
has extended checking of NS, MX and SRV record and the hosts
|
||||
they reference. named has extended post zone load checks.
|
||||
New zone options: check-mx and integrity-check.
|
||||
|
||||
|
||||
edns-udp-size can now be overridden on a per server basis.
|
||||
|
||||
dig can now specify the EDNS version when making a query.
|
||||
|
||||
Added framework for handling multiple EDNS versions.
|
||||
|
||||
Additional memory debugging support to track size and mctx
|
||||
arguments.
|
||||
|
||||
Detect duplicates of UDP queries we are recursing on and
|
||||
drop them. New stats category "duplicates".
|
||||
|
||||
"USE INTERNAL MALLOC" is now runtime selectable.
|
||||
|
||||
The lame cache is now done on a <qname,qclass,qtype> basis
|
||||
as some servers only appear to be lame for certain query
|
||||
types.
|
||||
|
||||
Limit the number of recursive clients that can be waiting
|
||||
for a single query (<qname,qtype,qclass>) to resolve. New
|
||||
options clients-per-query and max-clients-per-query.
|
||||
|
||||
dig: report the number of extra bytes still left in the
|
||||
packet after processing all the records.
|
||||
|
||||
Support for IPSECKEY rdata type.
|
||||
|
||||
Raise the UDP recieve buffer size to 32k if it is less than 32k.
|
||||
|
||||
x86 and x86_64 now have seperate atomic locking implementations.
|
||||
|
||||
named-checkconf now validates update-policy entries.
|
||||
|
||||
Attempt to make the amount of work performed in a iteration
|
||||
self tuning. The covers nodes clean from the cache per
|
||||
iteration, nodes written to disk when rewriting a master
|
||||
file and nodes destroyed per iteration when destroying a
|
||||
zone or a cache.
|
||||
|
||||
ISC string copy API.
|
||||
|
||||
Automatic empty zone creation for D.F.IP6.ARPA and friends.
|
||||
Note: RFC 1918 zones are not yet covered by this but are
|
||||
likely to be in a future release.
|
||||
|
||||
New options: empty-server, empty-contact, empty-zones-enable
|
||||
and disable-empty-zone.
|
||||
|
||||
dig now has a '-q queryname' and '+showsearch' options.
|
||||
|
||||
host/nslookup now continue (default)/fail on SERVFAIL.
|
||||
|
||||
dig now warns if 'RA' is not set in the answer when 'RD'
|
||||
was set in the query. host/nslookup skip servers that fail
|
||||
to set 'RA' when 'RD' is set unless a server is explicitly
|
||||
set.
|
||||
|
||||
Integrate contibuted DLZ code into named.
|
||||
|
||||
Integrate contibuted IDN code from JPNIC.
|
||||
|
||||
libbind: corresponds to that from BIND 8.4.7.
|
||||
|
||||
BIND 9.3.0
|
||||
|
||||
DNSSEC is now DS based (RFC 3658).
|
||||
See also RFC 3845, doc/draft/draft-ietf-dnsext-dnssec-*.
|
||||
|
||||
DNSSEC lookaside validation.
|
||||
|
||||
check-names is now implemented.
|
||||
rrset-order in more complete.
|
||||
|
||||
IPv4/IPv6 transition support, dual-stack-servers.
|
||||
|
||||
IXFR deltas can now be generated when loading master files,
|
||||
ixfr-from-differences.
|
||||
|
||||
It is now possible to specify the size of a journal, max-journal-size.
|
||||
|
||||
It is now possible to define a named set of master servers to be
|
||||
used in masters clause, masters.
|
||||
|
||||
The advertised EDNS UDP size can now be set, edns-udp-size.
|
||||
|
||||
allow-v6-synthesis has been obsoleted.
|
||||
|
||||
NOTE:
|
||||
* Zones containing MD and MF will now be rejected.
|
||||
* dig, nslookup name. now report "Not Implemented" as
|
||||
NOTIMP rather than NOTIMPL. This will have impact on scripts
|
||||
that are looking for NOTIMPL.
|
||||
|
||||
libbind: corresponds to that from BIND 8.4.5.
|
||||
|
||||
BIND 9.2.0
|
||||
|
||||
The size of the cache can now be limited using the
|
||||
"max-cache-size" option.
|
||||
|
||||
The server can now automatically convert RFC1886-style recursive
|
||||
lookup requests into RFC2874-style lookups, when enabled using the
|
||||
new option "allow-v6-synthesis". This allows stub resolvers that
|
||||
support AAAA records but not A6 record chains or binary labels to
|
||||
perform lookups in domains that make use of these IPv6 DNS
|
||||
features.
|
||||
|
||||
Performance has been improved.
|
||||
|
||||
The man pages now use the more portable "man" macros rather than
|
||||
the "mandoc" macros, and are installed by "make install".
|
||||
|
||||
The named.conf parser has been completely rewritten. It now
|
||||
supports "include" directives in more places such as inside "view"
|
||||
statements, and it no longer has any reserved words.
|
||||
|
||||
The "rndc status" command is now implemented.
|
||||
|
||||
rndc can now be configured automatically.
|
||||
|
||||
A BIND 8 compatible stub resolver library is now included in
|
||||
lib/bind.
|
||||
|
||||
OpenSSL has been removed from the distribution. This means that to
|
||||
use DNSSEC, OpenSSL must be installed and the --with-openssl option
|
||||
must be supplied to configure. This does not apply to the use of
|
||||
TSIG, which does not require OpenSSL.
|
||||
|
||||
The source distribution now builds on Windows. See
|
||||
win32utils/readme1.txt and win32utils/win32-build.txt for details.
|
||||
|
||||
This distribution also includes a new lightweight stub
|
||||
resolver library and associated resolver daemon that fully
|
||||
support forward and reverse lookups of both IPv4 and IPv6
|
||||
addresses. This library is considered experimental and
|
||||
is not a complete replacement for the BIND 8 resolver library.
|
||||
Applications that use the BIND 8 res_* functions to perform
|
||||
DNS lookups or dynamic updates still need to be linked against
|
||||
the BIND 8 libraries. For DNS lookups, they can also use the
|
||||
new "getrrsetbyname()" API.
|
||||
|
||||
BIND 9.2 is capable of acting as an authoritative server
|
||||
for DNSSEC secured zones. This functionality is believed to
|
||||
be stable and complete except for lacking support for
|
||||
verifications involving wildcard records in secure zones.
|
||||
|
||||
When acting as a caching server, BIND 9.2 can be configured
|
||||
to perform DNSSEC secure resolution on behalf of its clients.
|
||||
This part of the DNSSEC implementation is still considered
|
||||
experimental. For detailed information about the state of the
|
||||
DNSSEC implementation, see the file doc/misc/dnssec.
|
||||
|
||||
There are a few known bugs:
|
||||
|
||||
On some systems, IPv6 and IPv4 sockets interact in
|
||||
unexpected ways. For details, see doc/misc/ipv6.
|
||||
To reduce the impact of these problems, the server
|
||||
no longer listens for requests on IPv6 addresses
|
||||
by default. If you need to accept DNS queries over
|
||||
IPv6, you must specify "listen-on-v6 { any; };"
|
||||
in the named.conf options statement.
|
||||
|
||||
FreeBSD prior to 4.2 (and 4.2 if running as non-root)
|
||||
and OpenBSD prior to 2.8 log messages like
|
||||
"fcntl(8, F_SETFL, 4): Inappropriate ioctl for device".
|
||||
This is due to a bug in "/dev/random" and impacts the
|
||||
server's DNSSEC support.
|
||||
|
||||
OS X 10.1.4 (Darwin 5.4), OS X 10.1.5 (Darwin 5.5) and
|
||||
OS X 10.2 (Darwin 6.0) reports errors like
|
||||
"fcntl(3, F_SETFL, 4): Operation not supported by device".
|
||||
This is due to a bug in "/dev/random" and impacts the
|
||||
server's DNSSEC support.
|
||||
|
||||
--with-libtool does not work on AIX.
|
||||
|
||||
A bug in some versions of the Microsoft DNS server can cause zone
|
||||
transfers from a BIND 9 server to a W2K server to fail. For details,
|
||||
see the "Zone Transfers" section in doc/misc/migration.
|
||||
+4
-3
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2002 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.58 2009/11/26 20:52:44 marka Exp $
|
||||
# $Id: Makefile.in,v 1.58.8.2 2011/02/28 01:19:26 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -21,7 +21,7 @@ top_srcdir = @top_srcdir@
|
||||
|
||||
@BIND9_VERSION@
|
||||
|
||||
SUBDIRS = make lib bin doc @LIBEXPORT@
|
||||
SUBDIRS = make unit lib bin doc @LIBEXPORT@
|
||||
TARGETS =
|
||||
|
||||
MANPAGES = isc-config.sh.1
|
||||
@@ -65,6 +65,7 @@ check: test
|
||||
|
||||
test:
|
||||
(cd bin/tests && ${MAKE} ${MAKEDEFS} test)
|
||||
(test -f unit/unittest.sh && $(SHELL) unit/unittest.sh)
|
||||
|
||||
FAQ: FAQ.xml
|
||||
${XSLTPROC} doc/xsl/isc-docbook-text.xsl FAQ.xml | \
|
||||
|
||||
@@ -42,6 +42,43 @@ BIND 9
|
||||
Stichting NLnet - NLnet Foundation
|
||||
Nominum, Inc.
|
||||
|
||||
For a summary of functional enhancements in previous
|
||||
releases, see the HISTORY file.
|
||||
|
||||
For a detailed list of user-visible changes from
|
||||
previous releases, see the CHANGES file.
|
||||
|
||||
BIND 9.7.3
|
||||
|
||||
BIND 9.7.3 is a maintenance release, fixing bugs in 9.7.2.
|
||||
|
||||
BIND 9.7.2
|
||||
|
||||
BIND 9.7.2 will address bugs in 9.7.1, and also introduces
|
||||
some new functionality:
|
||||
|
||||
- "rndc loadkeys" to allow new keys to be added to a managed
|
||||
zone without having them sign the content immediately.
|
||||
- "rndc addzone" and "rndc delzone" allow adding and deleting
|
||||
zones at runtime. This requires the view to have the
|
||||
"new-zone-file" option set to a filename. Zone configuration
|
||||
information for new zones is specified in the 'rndc addzone'
|
||||
command line, and is stored in that file. To make new
|
||||
zones persist after a restart, "include" the file
|
||||
into named.conf in the appropriate view. (Note:
|
||||
This feature is not yet documented, and its syntax
|
||||
is expected to change.)
|
||||
- "rndc secroots" dumps a list of the current trusted and
|
||||
managed DNSSEC keys for each view.
|
||||
- "filter-aaaa-on-v4" can now be applied selectively to
|
||||
some IPv4 clients but not others, using the "filter-aaaa"
|
||||
ACL. (This feature requires BIND 9 to be built with
|
||||
the --enable-filter-aaaa configure option.)
|
||||
|
||||
BIND 9.7.1
|
||||
|
||||
BIND 9.7.1 is a maintenance release, fixing bugs in 9.7.0.
|
||||
|
||||
BIND 9.7.0
|
||||
|
||||
BIND 9.7.0 includes a number of changes from BIND 9.6 and earlier
|
||||
@@ -60,383 +97,64 @@ BIND 9.7.0
|
||||
- DNS rebinding attack prevention.
|
||||
- New default values for dnssec-keygen parameters.
|
||||
- Support for RFC 5011 automated trust anchor maintenance
|
||||
(see README.rfc5011 for additional details).
|
||||
- Smart signing: simplified tools for zone signing and key
|
||||
maintenance.
|
||||
- The "statistics-channels" option is now available on Windows.
|
||||
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
|
||||
(see README.libdns for details).
|
||||
- On some platforms, named and other binaries can now print out
|
||||
a stack backtrace on assertion failure, to aid in debugging.
|
||||
- A "tools only" installation mode on Windows, which only installs
|
||||
dig, host, nslookup and nsupdate.
|
||||
- Improved PKCS#11 support, including Keyper support and explicit
|
||||
OpenSSL engine selection (see README.pkcs11 for additional details).
|
||||
|
||||
COMPATIBILITY NOTES:
|
||||
|
||||
- If you had built BIND 9.6 with any of ALLOW_NSEC3PARAM_UPDATE,
|
||||
ALLOW_SECURE_TO_INSECURE or ALLOW_INSECURE_TO_SECURE defined, then
|
||||
you should ensure that all changes that are in progress have
|
||||
completed prior to upgrading to BIND 9.7. BIND 9.7 implements
|
||||
those features in a way which is not backwards compatible.
|
||||
|
||||
- Prior releases had a bug which caused HMAC-SHA* keys with long
|
||||
secrets to be used incorrectly. Fixing this bug means that older
|
||||
versions of BIND 9 may fail to interoperate with this version
|
||||
when using TSIG keys. If this occurs, the new "isc-hmac-fixup"
|
||||
tool will convert a key with a long secret into a form that works
|
||||
correctly with all versions of BIND 9. See the "isc-hmac-fixup"
|
||||
man page for additional details.
|
||||
|
||||
- Revoking a DNSSEC key with "dnssec-revoke" changes its key ID.
|
||||
It is possible for the new key ID to collide with that of a
|
||||
different key. Newly generated keys will not have this problem,
|
||||
as "dnssec-keygen" looks for potential collisions before
|
||||
generating keys, but exercise caution if using key revokation
|
||||
with keys that were generated by older versions of BIND 9.
|
||||
See README.rfc5011 for more details.
|
||||
|
||||
- A bug was fixed in which a key's scheduled inactivity date was
|
||||
stored incorectly. Users who participated in the 9.7.0 BETA
|
||||
test and had DNSSEC keys with scheduled inactivity dates will
|
||||
need to reset those keys' dates using "dnssec-settime -I".
|
||||
|
||||
BIND 9.6.0
|
||||
|
||||
BIND 9.6.0 includes a number of changes from BIND 9.5 and earlier
|
||||
releases, including:
|
||||
|
||||
Full NSEC3 support
|
||||
|
||||
Automatic zone re-signing
|
||||
|
||||
New update-policy methods tcp-self and 6to4-self
|
||||
|
||||
The BIND 8 resolver library, libbind, has been removed from the
|
||||
BIND 9 distribution and is now available as a separate download.
|
||||
|
||||
Change the default pid file location from /var/run to
|
||||
/var/run/{named,lwresd} for improved chroot/setuid support.
|
||||
|
||||
BIND 9.5.0
|
||||
|
||||
BIND 9.5.0 has a number of new features over 9.4,
|
||||
including:
|
||||
|
||||
GSS-TSIG support (RFC 3645).
|
||||
|
||||
DHCID support.
|
||||
|
||||
Experimental http server and statistics support for named via xml.
|
||||
|
||||
More detailed statistics counters including those supported in BIND 8.
|
||||
|
||||
Faster ACL processing.
|
||||
|
||||
Use Doxygen to generate internal documentation.
|
||||
|
||||
Efficient LRU cache-cleaning mechanism.
|
||||
|
||||
NSID support.
|
||||
|
||||
BIND 9.4.0
|
||||
|
||||
BIND 9.4.0 has a number of new features over 9.3,
|
||||
including:
|
||||
|
||||
Implemented "additional section caching (or acache)", an
|
||||
internal cache framework for additional section content to
|
||||
improve response performance. Several configuration options
|
||||
were provided to control the behavior.
|
||||
|
||||
New notify type 'master-only'. Enable notify for master
|
||||
zones only.
|
||||
|
||||
Accept 'notify-source' style syntax for query-source.
|
||||
|
||||
rndc now allows addresses to be set in the server clauses.
|
||||
|
||||
New option "allow-query-cache". This lets "allow-query"
|
||||
be used to specify the default zone access level rather
|
||||
than having to have every zone override the global value.
|
||||
"allow-query-cache" can be set at both the options and view
|
||||
levels. If "allow-query-cache" is not set then "allow-recursion"
|
||||
is used if set, otherwise "allow-query" is used if set
|
||||
unless "recursion no;" is set in which case "none;" is used,
|
||||
otherwise the default (localhost; localnets;) is used.
|
||||
|
||||
rndc: the source address can now be specified.
|
||||
|
||||
ixfr-from-differences now takes master and slave in addition
|
||||
to yes and no at the options and view levels.
|
||||
|
||||
Allow the journal's name to be changed via named.conf.
|
||||
|
||||
'rndc notify zone [class [view]]' resend the NOTIFY messages
|
||||
for the specified zone.
|
||||
|
||||
'dig +trace' now randomly selects the next servers to try.
|
||||
Report if there is a bad delegation.
|
||||
|
||||
Improve check-names error messages.
|
||||
|
||||
Make public the function to read a key file, dst_key_read_public().
|
||||
|
||||
dig now returns the byte count for axfr/ixfr.
|
||||
|
||||
allow-update is now settable at the options / view level.
|
||||
|
||||
named-checkconf now checks the logging configuration.
|
||||
|
||||
host now can turn on memory debugging flags with '-m'.
|
||||
|
||||
Don't send notify messages to self.
|
||||
|
||||
Perform sanity checks on NS records which refer to 'in zone' names.
|
||||
|
||||
New zone option "notify-delay". Specify a minimum delay
|
||||
between sets of NOTIFY messages.
|
||||
|
||||
Extend adjusting TTL warning messages.
|
||||
|
||||
Named and named-checkzone can now both check for non-terminal
|
||||
wildcard records.
|
||||
|
||||
"rndc freeze/thaw" now freezes/thaws all zones.
|
||||
|
||||
named-checkconf now check acls to verify that they only
|
||||
refer to existing acls.
|
||||
|
||||
The server syntax has been extended to support a range of
|
||||
servers.
|
||||
|
||||
Report differences between hints and real NS rrset and
|
||||
associated address records.
|
||||
|
||||
Preserve the case of domain names in rdata during zone
|
||||
transfers.
|
||||
|
||||
Restructured the data locking framework using architecture
|
||||
dependent atomic operations (when available), improving
|
||||
response performance on multi-processor machines significantly.
|
||||
x86, x86_64, alpha, powerpc, and mips are currently supported.
|
||||
|
||||
UNIX domain controls are now supported.
|
||||
|
||||
Add support for additional zone file formats for improving
|
||||
loading performance. The masterfile-format option in
|
||||
named.conf can be used to specify a non-default format. A
|
||||
separate command named-compilezone was provided to generate
|
||||
zone files in the new format. Additionally, the -I and -O
|
||||
options for dnssec-signzone specify the input and output
|
||||
formats.
|
||||
|
||||
dnssec-signzone can now randomize signature end times
|
||||
(dnssec-signzone -j jitter).
|
||||
|
||||
Add support for CH A record.
|
||||
|
||||
Add additional zone data constancy checks. named-checkzone
|
||||
has extended checking of NS, MX and SRV record and the hosts
|
||||
they reference. named has extended post zone load checks.
|
||||
New zone options: check-mx and integrity-check.
|
||||
|
||||
|
||||
edns-udp-size can now be overridden on a per server basis.
|
||||
|
||||
dig can now specify the EDNS version when making a query.
|
||||
|
||||
Added framework for handling multiple EDNS versions.
|
||||
|
||||
Additional memory debugging support to track size and mctx
|
||||
arguments.
|
||||
|
||||
Detect duplicates of UDP queries we are recursing on and
|
||||
drop them. New stats category "duplicates".
|
||||
|
||||
"USE INTERNAL MALLOC" is now runtime selectable.
|
||||
|
||||
The lame cache is now done on a <qname,qclass,qtype> basis
|
||||
as some servers only appear to be lame for certain query
|
||||
types.
|
||||
|
||||
Limit the number of recursive clients that can be waiting
|
||||
for a single query (<qname,qtype,qclass>) to resolve. New
|
||||
options clients-per-query and max-clients-per-query.
|
||||
|
||||
dig: report the number of extra bytes still left in the
|
||||
packet after processing all the records.
|
||||
|
||||
Support for IPSECKEY rdata type.
|
||||
|
||||
Raise the UDP recieve buffer size to 32k if it is less than 32k.
|
||||
|
||||
x86 and x86_64 now have seperate atomic locking implementations.
|
||||
|
||||
named-checkconf now validates update-policy entries.
|
||||
|
||||
Attempt to make the amount of work performed in a iteration
|
||||
self tuning. The covers nodes clean from the cache per
|
||||
iteration, nodes written to disk when rewriting a master
|
||||
file and nodes destroyed per iteration when destroying a
|
||||
zone or a cache.
|
||||
|
||||
ISC string copy API.
|
||||
|
||||
Automatic empty zone creation for D.F.IP6.ARPA and friends.
|
||||
Note: RFC 1918 zones are not yet covered by this but are
|
||||
likely to be in a future release.
|
||||
|
||||
New options: empty-server, empty-contact, empty-zones-enable
|
||||
and disable-empty-zone.
|
||||
|
||||
dig now has a '-q queryname' and '+showsearch' options.
|
||||
|
||||
host/nslookup now continue (default)/fail on SERVFAIL.
|
||||
|
||||
dig now warns if 'RA' is not set in the answer when 'RD'
|
||||
was set in the query. host/nslookup skip servers that fail
|
||||
to set 'RA' when 'RD' is set unless a server is explicitly
|
||||
set.
|
||||
|
||||
Integrate contibuted DLZ code into named.
|
||||
|
||||
Integrate contibuted IDN code from JPNIC.
|
||||
|
||||
libbind: corresponds to that from BIND 8.4.7.
|
||||
|
||||
BIND 9.3.0
|
||||
|
||||
BIND 9.3.0 has a number of new features over 9.2,
|
||||
including:
|
||||
|
||||
DNSSEC is now DS based (RFC 3658).
|
||||
See also RFC 3845, doc/draft/draft-ietf-dnsext-dnssec-*.
|
||||
|
||||
DNSSEC lookaside validation.
|
||||
|
||||
check-names is now implemented.
|
||||
rrset-order in more complete.
|
||||
|
||||
IPv4/IPv6 transition support, dual-stack-servers.
|
||||
|
||||
IXFR deltas can now be generated when loading master files,
|
||||
ixfr-from-differences.
|
||||
|
||||
It is now possible to specify the size of a journal, max-journal-size.
|
||||
|
||||
It is now possible to define a named set of master servers to be
|
||||
used in masters clause, masters.
|
||||
|
||||
The advertised EDNS UDP size can now be set, edns-udp-size.
|
||||
|
||||
allow-v6-synthesis has been obsoleted.
|
||||
|
||||
NOTE:
|
||||
* Zones containing MD and MF will now be rejected.
|
||||
* dig, nslookup name. now report "Not Implemented" as
|
||||
NOTIMP rather than NOTIMPL. This will have impact on scripts
|
||||
that are looking for NOTIMPL.
|
||||
|
||||
libbind: corresponds to that from BIND 8.4.5.
|
||||
|
||||
BIND 9.2.0
|
||||
|
||||
BIND 9.2.0 has a number of new features over 9.1,
|
||||
including:
|
||||
|
||||
- The size of the cache can now be limited using the
|
||||
"max-cache-size" option.
|
||||
|
||||
- The server can now automatically convert RFC1886-style
|
||||
recursive lookup requests into RFC2874-style lookups,
|
||||
when enabled using the new option "allow-v6-synthesis".
|
||||
This allows stub resolvers that support AAAA records
|
||||
but not A6 record chains or binary labels to perform
|
||||
lookups in domains that make use of these IPv6 DNS
|
||||
features.
|
||||
|
||||
- Performance has been improved.
|
||||
|
||||
- The man pages now use the more portable "man" macros
|
||||
rather than the "mandoc" macros, and are installed
|
||||
by "make install".
|
||||
|
||||
- The named.conf parser has been completely rewritten.
|
||||
It now supports "include" directives in more
|
||||
places such as inside "view" statements, and it no
|
||||
longer has any reserved words.
|
||||
|
||||
- The "rndc status" command is now implemented.
|
||||
|
||||
- rndc can now be configured automatically.
|
||||
|
||||
- A BIND 8 compatible stub resolver library is now
|
||||
included in lib/bind.
|
||||
|
||||
- OpenSSL has been removed from the distribution. This
|
||||
means that to use DNSSEC, OpenSSL must be installed and
|
||||
the --with-openssl option must be supplied to configure.
|
||||
This does not apply to the use of TSIG, which does not
|
||||
require OpenSSL.
|
||||
|
||||
- The source distribution now builds on Windows.
|
||||
See win32utils/readme1.txt and win32utils/win32-build.txt
|
||||
for details.
|
||||
|
||||
This distribution also includes a new lightweight stub
|
||||
resolver library and associated resolver daemon that fully
|
||||
support forward and reverse lookups of both IPv4 and IPv6
|
||||
addresses. This library is considered experimental and
|
||||
is not a complete replacement for the BIND 8 resolver library.
|
||||
Applications that use the BIND 8 res_* functions to perform
|
||||
DNS lookups or dynamic updates still need to be linked against
|
||||
the BIND 8 libraries. For DNS lookups, they can also use the
|
||||
new "getrrsetbyname()" API.
|
||||
|
||||
BIND 9.2 is capable of acting as an authoritative server
|
||||
for DNSSEC secured zones. This functionality is believed to
|
||||
be stable and complete except for lacking support for
|
||||
verifications involving wildcard records in secure zones.
|
||||
|
||||
When acting as a caching server, BIND 9.2 can be configured
|
||||
to perform DNSSEC secure resolution on behalf of its clients.
|
||||
This part of the DNSSEC implementation is still considered
|
||||
experimental. For detailed information about the state of the
|
||||
DNSSEC implementation, see the file doc/misc/dnssec.
|
||||
|
||||
There are a few known bugs:
|
||||
|
||||
On some systems, IPv6 and IPv4 sockets interact in
|
||||
unexpected ways. For details, see doc/misc/ipv6.
|
||||
To reduce the impact of these problems, the server
|
||||
no longer listens for requests on IPv6 addresses
|
||||
by default. If you need to accept DNS queries over
|
||||
IPv6, you must specify "listen-on-v6 { any; };"
|
||||
in the named.conf options statement.
|
||||
|
||||
FreeBSD prior to 4.2 (and 4.2 if running as non-root)
|
||||
and OpenBSD prior to 2.8 log messages like
|
||||
"fcntl(8, F_SETFL, 4): Inappropriate ioctl for device".
|
||||
This is due to a bug in "/dev/random" and impacts the
|
||||
server's DNSSEC support.
|
||||
|
||||
OS X 10.1.4 (Darwin 5.4), OS X 10.1.5 (Darwin 5.5) and
|
||||
OS X 10.2 (Darwin 6.0) reports errors like
|
||||
"fcntl(3, F_SETFL, 4): Operation not supported by device".
|
||||
This is due to a bug in "/dev/random" and impacts the
|
||||
server's DNSSEC support.
|
||||
|
||||
--with-libtool does not work on AIX.
|
||||
|
||||
A bug in some versions of the Microsoft DNS server can cause zone
|
||||
transfers from a BIND 9 server to a W2K server to fail. For details,
|
||||
see the "Zone Transfers" section in doc/misc/migration.
|
||||
|
||||
For a detailed list of user-visible changes from
|
||||
previous releases, see the CHANGES file.
|
||||
|
||||
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
|
||||
- On some platforms, named and other binaries can now print out
|
||||
a stack backtrace on assertion failure, to aid in debugging.
|
||||
- A "tools only" installation mode on Windows, which only installs
|
||||
dig, host, nslookup and nsupdate.
|
||||
- Improved PKCS#11 support, including Keyper support and explicit
|
||||
OpenSSL engine selection.
|
||||
|
||||
Known issues in this release:
|
||||
|
||||
- A validating resolver that has been incorrectly configured with
|
||||
an invalid trust anchor will be unable to resolve names covered
|
||||
by that trust anchor. In all current versions of BIND 9, such a
|
||||
resolver will also generate significant unnecessary DNS traffic
|
||||
while trying to validate. The latter problem will be addressed
|
||||
in future BIND 9 releases. In the meantime, to avoid these
|
||||
problems, exercise caution when configuring "trusted-keys":
|
||||
make sure all keys are correct and current when you add them,
|
||||
and update your configuration in a timely manner when keys
|
||||
roll over.
|
||||
|
||||
- In rare cases, DNSSEC validation can leak memory. When this
|
||||
happens, it will cause an assertion failure when named exits,
|
||||
but is otherwise harmless. A fix exists, but was too late for
|
||||
this release; it will be included in BIND 9.7.1.
|
||||
|
||||
Compatibility notes:
|
||||
|
||||
- If you had built BIND 9.6 with any of ALLOW_NSEC3PARAM_UPDATE,
|
||||
ALLOW_SECURE_TO_INSECURE or ALLOW_INSECURE_TO_SECURE defined, then
|
||||
you should ensure that all changes that are in progress have
|
||||
completed prior to upgrading to BIND 9.7. BIND 9.7 implements
|
||||
those features in a way which is not backwards compatible.
|
||||
|
||||
- Prior releases had a bug which caused HMAC-SHA* keys with long
|
||||
secrets to be used incorrectly. Fixing this bug means that older
|
||||
versions of BIND 9 may fail to interoperate with this version
|
||||
when using TSIG keys. If this occurs, the new "isc-hmac-fixup"
|
||||
tool will convert a key with a long secret into a form that works
|
||||
correctly with all versions of BIND 9. See the "isc-hmac-fixup"
|
||||
man page for additional details.
|
||||
|
||||
- Revoking a DNSSEC key with "dnssec-revoke" changes its key ID.
|
||||
It is possible for the new key ID to collide with that of a
|
||||
different key. Newly generated keys will not have this problem,
|
||||
as "dnssec-keygen" looks for potential collisions before
|
||||
generating keys, but exercise caution if using key revokation
|
||||
with keys that were generated by older versions of BIND 9. See
|
||||
the Administrator's Reference Manual, section 4.10 ("Dynamic
|
||||
Trust Anchor Management") for more details.
|
||||
|
||||
- A bug was fixed in which a key's scheduled inactivity date was
|
||||
stored incorectly. Users who participated in the 9.7.0 BETA test
|
||||
and had DNSSEC keys with scheduled inactivity dates will need to
|
||||
reset those keys' dates using "dnssec-settime -I".
|
||||
|
||||
Building
|
||||
|
||||
@@ -456,9 +174,9 @@ Building
|
||||
Ubuntu 7.04, 7.10
|
||||
Windows XP/2003/2008
|
||||
|
||||
NOTE: As of BIND 9.5.1, 9.4.3, and 9.3.6, older versions of
|
||||
Windows, including Windows NT and Windows 2000, are no longer
|
||||
supported.
|
||||
NOTE: As of BIND 9.5.1, 9.4.3, and 9.3.6, older versions of
|
||||
Windows, including Windows NT and Windows 2000, are no longer
|
||||
supported.
|
||||
|
||||
We have recent reports from the user community that a supported
|
||||
version of BIND will build and run on the following systems:
|
||||
@@ -558,10 +276,10 @@ Building
|
||||
on the configure command line. The default is operating
|
||||
system dependent.
|
||||
|
||||
Support for the "fixed" rrset-order option can be enabled
|
||||
or disabled by specifying "--enable-fixed-rrset" or
|
||||
"--disable-fixed-rrset" on the configure command line.
|
||||
The default is "disabled", to reduce memory footprint.
|
||||
Support for the "fixed" rrset-order option can be enabled
|
||||
or disabled by specifying "--enable-fixed-rrset" or
|
||||
"--disable-fixed-rrset" on the configure command line.
|
||||
The default is "disabled", to reduce memory footprint.
|
||||
|
||||
If your operating system has integrated support for IPv6, it
|
||||
will be used automatically. If you have installed KAME IPv6
|
||||
@@ -627,8 +345,8 @@ Documentation
|
||||
Frequently asked questions and their answers can be found in
|
||||
FAQ.
|
||||
|
||||
Additional information on various subjects can be found
|
||||
in the other README files.
|
||||
Additional information on various subjects can be found
|
||||
in the other README files.
|
||||
|
||||
|
||||
Bug Reports and Mailing Lists
|
||||
|
||||
-186
@@ -1,186 +0,0 @@
|
||||
|
||||
DNSSEC and Dynamic Zones
|
||||
|
||||
As of BIND 9.7.0 it is possible to change a dynamic zone from
|
||||
insecure to secure and back again. A secure zone can use either
|
||||
NSEC or NSEC3 chains.
|
||||
|
||||
Converting from insecure to secure
|
||||
|
||||
Changing a zone from insecure to secure can be done in two ways:
|
||||
using a dynamic DNS update, or the "auto-dnssec" zone option.
|
||||
|
||||
For either method, you need to configure named so that it can see
|
||||
the K* files which contain the public and private parts of the keys
|
||||
that will be used to sign the zone. These files will have been
|
||||
generated by dnssec-keygen. You can do this by placing them in
|
||||
the key-directory, as specified in named.conf:
|
||||
|
||||
zone example.net {
|
||||
type master;
|
||||
update-policy local;
|
||||
file "dynamic/example.net/example.net";
|
||||
key-directory "dynamic/example.net";
|
||||
};
|
||||
|
||||
If one KSK and one ZSK DNSKEY key have been generated, this configuration
|
||||
will cause all records in the zone to be signed with the ZSK, and the
|
||||
DNSKEY RRset to be signed with the KSK as well. An NSEC chain will be
|
||||
generated as part of the initial signing process.
|
||||
|
||||
Dynamic DNS update method
|
||||
|
||||
To insert the keys via dynamic update:
|
||||
|
||||
% nsupdate
|
||||
> ttl 3600
|
||||
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
|
||||
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
|
||||
> send
|
||||
|
||||
While the update request will complete almost immediately, the zone
|
||||
will not be completely signed until named has had time to walk the
|
||||
zone and generate the NSEC and RRSIG records. The NSEC record at the
|
||||
apex will be added last, to signal that there is a complete NSEC chain.
|
||||
|
||||
If you wish to sign using NSEC3 instead of NSEC, you should add an
|
||||
NSEC3PARAM record to the initial update request. If you wish the
|
||||
NSEC3 chain to have the OPTOUT bit set, set it in the flags field
|
||||
of the NSEC3PARAM record.
|
||||
|
||||
% nsupdate
|
||||
> ttl 3600
|
||||
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
|
||||
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
|
||||
> update add example.net NSEC3PARAM 1 1 100 1234567890
|
||||
> send
|
||||
|
||||
Again, this update request will complete almost immediately; however,
|
||||
the record won't show up until named has had a chance to build/remove
|
||||
the relevant chain. A private type record will be created to record
|
||||
the state of the operation (see below for more details), and will be
|
||||
removed once the operation completes.
|
||||
|
||||
While the initial signing and NSEC/NSEC3 chain generation is happening,
|
||||
other updates are possible as well.
|
||||
|
||||
Fully automatic zone signing
|
||||
|
||||
To enable automatic signing, add the "auto-dnssec" option to the zone
|
||||
statement in named.conf. "auto-dnssec" has two possible arguments:
|
||||
"allow" or "maintain".
|
||||
|
||||
With "auto-dnssec allow", named can search the key directory for keys
|
||||
matching the zone, insert them into the zone, and use them to sign the
|
||||
zone. It will do so only when it receives an "rndc sign <zonename>"
|
||||
command.
|
||||
|
||||
"auto-dnssec maintain" includes the above functionality, but will also
|
||||
automatically adjust the zone's DNSKEY records on schedule according to the
|
||||
keys' timing metadata (see the man pages for dnssec-keygen and
|
||||
dnssec-settime for more information). If keys are present in the key
|
||||
directory the first time the zone is loaded, it will be signed
|
||||
immediately, without waiting for an "rndc sign" command. (This
|
||||
command can still be used for unscheduled key changes, however.)
|
||||
|
||||
Using the "auto-dnssec" option requires the zone to be configured to
|
||||
allow dynamic updates, by adding an "allow-update" or "update-policy"
|
||||
statement to the zone configuration. If this has not been done, the
|
||||
configuration will fail.
|
||||
|
||||
Private-type records
|
||||
|
||||
The state of the signing process is signaled by private-type records
|
||||
(with a default type value of 65534). When signing is complete, these
|
||||
records will have a nonzero value for the final octet (for those records
|
||||
which have a nonzero initial octet).
|
||||
|
||||
The private type record format:
|
||||
If the first octet is non-zero then the record indicates that the zone needs
|
||||
to be signed with the key matching the record, or that all signatures that
|
||||
match the record should be removed.
|
||||
|
||||
algorithm (octet 1)
|
||||
key id in network order (octet 2 and 3)
|
||||
removal flag (octet 4)
|
||||
complete flag (octet 5)
|
||||
|
||||
Only records flagged as "complete" can be removed via dynamic update.
|
||||
Attempts to remove other private type records will be silently ignored.
|
||||
|
||||
If the first octet is zero (this is a reserved algorithm number
|
||||
that should never appear in a DNSKEY record) then the record indicates
|
||||
changes to the NSEC3 chains are in progress. The rest of the record
|
||||
contains an NSEC3PARAM record. The flag field tells what operation
|
||||
to perform based on the flag bits.
|
||||
|
||||
0x01 OPTOUT
|
||||
0x80 CREATE
|
||||
0x40 REMOVE
|
||||
0x20 NONSEC
|
||||
|
||||
DNSKEY rollovers via UPDATE
|
||||
|
||||
It is possible to perform key rollovers via dynamic update. You need
|
||||
to add the K* files for the new keys so that named can find them. You
|
||||
can then add the new DNSKEY RRs via dynamic update. Named will then cause
|
||||
the zone to be signed with the new keys. When the signing is
|
||||
complete the private type records will be updated so that the last
|
||||
octet is non zero.
|
||||
|
||||
If this is for a KSK you need to inform the parent and any trust
|
||||
anchor repositories of the new KSK.
|
||||
|
||||
You should then wait for the maximum TTL in the zone before removing the
|
||||
old DNSKEY. If it is a KSK that is being updated, you also need to wait
|
||||
for the DS RRset in the parent to be updated and its TTL to expire.
|
||||
This ensures that all clients will be able to verify at least one
|
||||
signature when you remove the old DNSKEY.
|
||||
|
||||
The old DNSKEY can be removed via UPDATE. Take care to specify
|
||||
the correct key. Named will clean out any signatures generated by
|
||||
the old key after the update completes.
|
||||
|
||||
NSEC3PARAM rollovers via UPDATE
|
||||
|
||||
Add the new NSEC3PARAM record via dynamic update. When the new NSEC3 chain
|
||||
has been generated, the NSEC3PARAM flag field will be zero. At this
|
||||
point you can remove the old NSEC3PARAM record. The old chain will
|
||||
be removed after the update request completes.
|
||||
|
||||
Converting from NSEC to NSEC3
|
||||
|
||||
To do this, you just need to add an NSEC3PARAM record. When the
|
||||
conversion is complete, the NSEC chain will have been removed and
|
||||
the NSEC3PARAM record will have a zero flag field. The NSEC3 chain
|
||||
will be generated before the NSEC chain is destroyed.
|
||||
|
||||
Converting from NSEC3 to NSEC
|
||||
|
||||
To do this, remove all NSEC3PARAM records with a zero flag field. The
|
||||
NSEC chain will be generated before the NSEC3 chain is removed.
|
||||
|
||||
Converting from secure to insecure
|
||||
|
||||
To do this, remove all the DNSKEY records. Any NSEC or NSEC3 chains
|
||||
will be removed as well, along with associated NSEC3PARAM records.
|
||||
This will take place after the update request completes. This
|
||||
requires the "dnssec-secure-to-insecure" option to be set to "yes"
|
||||
in named.conf.
|
||||
|
||||
Periodic re-signing
|
||||
|
||||
In any secure zone which supports dynamic updates, named will
|
||||
periodically re-sign RRsets which have not been re-signed as
|
||||
a result of some update action. The signature lifetimes will
|
||||
be adjusted so as to spread the re-sign load over time rather than
|
||||
all at once.
|
||||
|
||||
NSEC3 and OPTOUT
|
||||
|
||||
Named only supports creating new NSEC3 chains where all the NSEC3
|
||||
records in the zone have the same OPTOUT state. Named supports
|
||||
UPDATES to zones where the NSEC3 records in the chain have mixed
|
||||
OPTOUT state. Named does not support changing the OPTOUT state of
|
||||
an individual NSEC3 record, the entire chain needs to be changed if
|
||||
the OPTOUT state of an individual NSEC3 needs to be changed.
|
||||
-275
@@ -1,275 +0,0 @@
|
||||
|
||||
BIND-9 DNS Library Support
|
||||
|
||||
This version of BIND9 "exports" its internal libraries so that they
|
||||
can be used by third-party applications more easily (we call them
|
||||
"export" libraries in this document). In addition to all major
|
||||
DNS-related APIs BIND9 is currently using, the export libraries
|
||||
provide the following features:
|
||||
|
||||
- The newly created "DNS client" module. This is a higher level API
|
||||
that provides an interface to name resolution, single DNS
|
||||
transaction with a particular server, and dynamic update. Regarding
|
||||
name resolution, it supports advanced features such as DNSSEC
|
||||
validation and caching. This module supports both synchronous and
|
||||
asynchronous mode.
|
||||
- The new "IRS" (Information Retrieval System) library. It provides
|
||||
an interface to parse the traditional resolv.conf file and more
|
||||
advanced, DNS-specific configuration file for the rest of this
|
||||
package (see the description for the dns.conf file below).
|
||||
- As part of the IRS library, newly implemented standard address-name
|
||||
mapping functions, getaddrinfo() and getnameinfo(), are provided.
|
||||
They use the DNSSEC-aware validating resolver backend, and could use
|
||||
other advanced features of the BIND9 libraries such as caching. The
|
||||
getaddrinfo() function resolves both A and AAAA RRs concurrently
|
||||
(when the address family is unspecified).
|
||||
- An experimental framework to support other event libraries than
|
||||
BIND9's internal event task system.
|
||||
|
||||
* Prerequisite
|
||||
|
||||
GNU make is required to build the export libraries (other part of
|
||||
BIND9 can still be built with other types of make). In the reminder
|
||||
of this document, "make" means GNU make. Note that in some platforms
|
||||
you may need to invoke a different command name than "make"
|
||||
(e.g. "gmake") to indicate it's GNU make.
|
||||
|
||||
* Compilation
|
||||
|
||||
1. ./configure --enable-exportlib [other flags]
|
||||
2. make
|
||||
|
||||
This will create (in addition to usual BIND9 programs) and a separate
|
||||
set of libraries under the lib/export directory. For example,
|
||||
lib/export/dns/libdns.a is the archive file of the export version of
|
||||
the BIND9 DNS library.
|
||||
|
||||
Sample application programs using the libraries will also be built
|
||||
under the lib/export/samples directory (see below).
|
||||
|
||||
* Installation
|
||||
|
||||
1. cd lib/export
|
||||
2. make install (root privilege is normally required)
|
||||
(make install at the top directory will do the same)
|
||||
|
||||
This will install library object files under the directory specified
|
||||
by the --with-export-libdir configure option (default:
|
||||
EPREFIX/lib/bind9), and header files under the directory specified by
|
||||
the --with-export-includedir configure option (default:
|
||||
PREFIX/include/bind9).
|
||||
|
||||
To see how to build your own application after the installation, see
|
||||
lib/export/samples/Makefile-postinstall.in
|
||||
|
||||
* Known Defects/Restrictions
|
||||
|
||||
- Currently, win32 is not supported for the export library. (Normal
|
||||
BIND9 application can be built as before).
|
||||
- The "fixed" RRset order is not (currently) supported in the export
|
||||
library. If you want to use "fixed" RRset order for, e.g. named
|
||||
while still building the export library even without the fixed
|
||||
order support, build them separately:
|
||||
% ./configure --enable-fixed-rrset [other flags, but not --enable-exportlib]
|
||||
% make (this doesn't have to be make)
|
||||
% ./configure --enable-exportlib [other flags, but not --enable-fixed-rrset]
|
||||
% cd lib/export
|
||||
% make
|
||||
- The client module and the IRS library currently do not support
|
||||
DNSSEC validation using DLV (the underlying modules can handle it,
|
||||
but there is no tunable interface to enable the feature).
|
||||
- RFC5011 is not supported in the validating stub resolver of the
|
||||
export library. In fact, it is not clear whether it should: trust
|
||||
anchors would be a system-wide configuration which would be managed
|
||||
by an administrator, while the stub resolver will be used by
|
||||
ordinary applications run by a normal user.
|
||||
- Not all common /etc/resolv.conf options are supported in the IRS library.
|
||||
The only available options in this version are "debug" and "ndots".
|
||||
|
||||
* The dns.conf File
|
||||
|
||||
The IRS library supports an "advanced" configuration file related to
|
||||
the DNS library for configuration parameters that would be beyond the
|
||||
capability of the resolv.conf file. Specifically, it is intended to
|
||||
provide DNSSEC related configuration parameters.
|
||||
|
||||
By default the path to this configuration file is /etc/dns.conf.
|
||||
|
||||
This module is very experimental and the configuration syntax or
|
||||
library interfaces may change in future versions. Currently, only the
|
||||
'trusted-keys' statement is supported, whose syntax is the same as the
|
||||
same name of statement for named.conf.
|
||||
|
||||
* Sample Applications
|
||||
|
||||
Some sample application programs using this API are provided for
|
||||
reference. The following is a brief description of these
|
||||
applications.
|
||||
|
||||
- sample: a simple stub resolver utility.
|
||||
|
||||
It sends a query of a given name (of a given optional RR type)
|
||||
to a specified recursive server, and prints the result as a list of
|
||||
RRs. It can also act as a validating stub resolver if a trust
|
||||
anchor is given via a set of command line options.
|
||||
|
||||
Usage: sample [options] server_address hostname
|
||||
|
||||
Options and Arguments:
|
||||
-t RRtype
|
||||
specify the RR type of the query. The default is the A RR.
|
||||
[-a algorithm] [-e] -k keyname -K keystring
|
||||
specify a command-line DNS key to validate the answer. For
|
||||
example, to specify the following DNSKEY of example.com:
|
||||
example.com. 3600 IN DNSKEY 257 3 5 xxx
|
||||
specify the options as follows:
|
||||
-e -k example.com -K "xxx"
|
||||
-e means that this key is a zone's "key signing key" (as known
|
||||
as "secure Entry point").
|
||||
when -a is omitted rsasha1 will be used by default.
|
||||
-s domain:alt_server_address
|
||||
specify a separate recursive server address for the specific
|
||||
"domain". Example: -s example.com:2001:db8::1234
|
||||
server_address
|
||||
an IP(v4/v6) address of the recursive server to which queries
|
||||
are sent.
|
||||
hostname
|
||||
the domain name for the query
|
||||
|
||||
- sample-async: a simple stub resolver, working asynchronously.
|
||||
|
||||
Similar to "sample", but accepts a list of (query) domain names as a
|
||||
separate file and resolves the names asynchronously.
|
||||
|
||||
Usage: sample-async [-s server_address] [-t RR_type] input_file
|
||||
Options and Arguments:
|
||||
-s server_address
|
||||
an IPv4 address of the recursive server to which queries are
|
||||
sent. (IPv6 addresses are not supported in this implementation)
|
||||
-t RR_type
|
||||
specify the RR type of the queries. The default is the A RR.
|
||||
input_file
|
||||
a list of domain names to be resolved. each line consists of a
|
||||
single domain name. Example:
|
||||
www.example.com
|
||||
mx.examle.net
|
||||
ns.xxx.example
|
||||
|
||||
- sample-request: a simple DNS transaction client.
|
||||
|
||||
It sends a query to a specified server, and prints the response with
|
||||
minimal processing. It doesn't act as a "stub resolver": it stops
|
||||
the processing once it gets any response from the server, whether
|
||||
it's a referral or an alias (CNAME or DNAME) that would require
|
||||
further queries to get the ultimate answer. In other words, this
|
||||
utility acts as a very simplified dig.
|
||||
|
||||
Usage: sample-request [-t RRtype] server_address hostname
|
||||
Options and Arguments:
|
||||
-t RRtype
|
||||
specify the RR type of the queries. The default is the A RR.
|
||||
server_address
|
||||
an IP(v4/v6) address of the recursive server to which the query is
|
||||
sent.
|
||||
hostname
|
||||
the domain name for the query
|
||||
|
||||
- sample-gai: getaddrinfo() and getnameinfo() test code.
|
||||
|
||||
This is a test program to check getaddrinfo() and getnameinfo()
|
||||
behavior. It takes a host name as an argument, calls getaddrinfo()
|
||||
with the given host name, and calls getnameinfo() with the resulting
|
||||
IP addresses returned by getaddrinfo(). If the dns.conf file exists
|
||||
and defines a trust anchor, the underlying resolver will act as a
|
||||
validating resolver, and getaddrinfo()/getnameinfo() will fail with
|
||||
an EAI_INSECUREDATA error when DNSSEC validation fails.
|
||||
|
||||
Usage: sample-gai hostname
|
||||
|
||||
- sample-update: a simple dynamic update client program
|
||||
|
||||
It accepts a single update command as a command-line argument, sends
|
||||
an update request message to the authoritative server, and shows the
|
||||
response from the server. In other words, this is a simplified
|
||||
nsupdate.
|
||||
|
||||
Usage: sample-update [options] (add|delete) "update data"
|
||||
Options and Arguments:
|
||||
-a auth_server
|
||||
An IP address of the authoritative server that has authority
|
||||
for the zone containing the update name. This should normally
|
||||
be the primary authoritative server that accepts dynamic
|
||||
updates. It can also be a secondary server that is configured
|
||||
to forward update requests to the primary server.
|
||||
-k keyfile
|
||||
A TSIG key file to secure the update transaction. The keyfile
|
||||
format is the same as that for the nsupdate utility.
|
||||
-p prerequisite
|
||||
A prerequisite for the update (only one prerequisite can be
|
||||
specified). The prerequisite format is the same as that is
|
||||
accepted by the nsupdate utility.
|
||||
-r recursive_server
|
||||
An IP address of a recursive server that this utility will
|
||||
use. A recursive server may be necessary to identify the
|
||||
authoritative server address to which the update request is
|
||||
sent.
|
||||
-z zonename
|
||||
The domain name of the zone that contains
|
||||
(add|delete)
|
||||
Specify the type of update operation. Either "add" or "delete"
|
||||
must be specified.
|
||||
"update data"
|
||||
Specify the data to be updated. A typical example of the data
|
||||
would look like "name TTL RRtype RDATA".
|
||||
|
||||
Note: in practice, either -a or -r must be specified. Others can
|
||||
be optional; the underlying library routine tries to identify the
|
||||
appropriate server and the zone name for the update.
|
||||
|
||||
Examples: assuming the primary authoritative server of the
|
||||
dynamic.example.com zone has an IPv6 address 2001:db8::1234,
|
||||
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key add "foo.dynamic.example.com 30 IN A 192.168.2.1"
|
||||
adds an A RR for foo.dynamic.example.com using the given key.
|
||||
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com 30 IN A"
|
||||
removes all A RRs for foo.dynamic.example.com using the given key.
|
||||
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com"
|
||||
removes all RRs for foo.dynamic.example.com using the given key.
|
||||
|
||||
- nsprobe: domain/name server checker in terms of RFC4074.
|
||||
|
||||
It checks a set of domains to see the name servers of the domains
|
||||
behave correctly in terms of RFC4074. This is included in the set
|
||||
of sample programs to show how the export library can be used in a
|
||||
DNS-related application.
|
||||
|
||||
Usage: nsprobe [-d] [-v [-v...]] [-c cache_address] [input_file]
|
||||
Options
|
||||
-d
|
||||
run in the "debug" mode. with this option nsprobe will dump
|
||||
every RRs it receives.
|
||||
-v
|
||||
increase verbosity of other normal log messages. This can be
|
||||
specified multiple times
|
||||
-c cache_address
|
||||
specify an IP address of a recursive (caching) name server.
|
||||
nsprobe uses this server to get the NS RRset of each domain and
|
||||
the A and/or AAAA RRsets for the name servers. The default
|
||||
value is 127.0.0.1.
|
||||
input_file
|
||||
a file name containing a list of domain (zone) names to be
|
||||
probed. when omitted the standard input will be used. Each
|
||||
line of the input file specifies a single domain name such as
|
||||
"example.com". In general this domain name must be the apex
|
||||
name of some DNS zone (unlike normal "host names" such as
|
||||
"www.example.com"). nsprobe first identifies the NS RRsets for
|
||||
the given domain name, and sends A and AAAA queries to these
|
||||
servers for some "widely used" names under the zone;
|
||||
specifically, adding "www" and "ftp" to the zone name.
|
||||
|
||||
* Library References
|
||||
|
||||
As of this writing, there is no formal "manual" of the libraries,
|
||||
except this document, header files (some of them provide pretty
|
||||
detailed explanations), and sample application programs.
|
||||
|
||||
; $Id: README.libdns,v 1.3 2009/09/15 19:12:03 jinmei Exp $
|
||||
-309
@@ -1,309 +0,0 @@
|
||||
|
||||
BIND 9 PKCS #11 (Cryptoki) support
|
||||
|
||||
INTRODUCTION
|
||||
|
||||
PKCS #11 (Public Key Cryptography Standard #11) defines a platform-
|
||||
independent API for the control of hardware security modules (HSMs)
|
||||
and other cryptographic support devices.
|
||||
|
||||
BIND 9 is known to work with two HSMs: The Sun SCA 6000 cryptographic
|
||||
acceleration board, tested under Solaris x86, and the AEP Keyper
|
||||
network-attached key storage device, tested with Debian Linux,
|
||||
Solaris x86 and Windows Server 2003.
|
||||
|
||||
PREREQUISITES
|
||||
|
||||
See the HSM vendor documentation for information about installing,
|
||||
initializing, testing and troubleshooting the HSM.
|
||||
|
||||
BIND 9 uses OpenSSL for cryptography, but stock OpenSSL does not
|
||||
yet fully support PKCS #11. However, a PKCS #11 engine for OpenSSL
|
||||
is available from the OpenSolaris project. It has been modified by
|
||||
ISC to work with with BIND 9, and to provide new features such as
|
||||
PIN management and key by reference.
|
||||
|
||||
The patched OpenSSL depends on a "PKCS #11 provider". This is a shared
|
||||
library object, providing a low-level PKCS #11 interface to the HSM
|
||||
hardware. It is dynamically loaded by OpenSSL at runtime. The PKCS #11
|
||||
provider comes from the HSM vendor, and and is specific to the HSM to be
|
||||
controlled.
|
||||
|
||||
There are two "flavors" of PKCS #11 support provided by the patched
|
||||
OpenSSL, one of which must be chosen at configuration time. The correct
|
||||
choice depends on the HSM hardware:
|
||||
|
||||
- Use 'crypto-accelerator' with HSMs that have hardware cryptographic
|
||||
acceleration features, such as the SCA 6000 board. This causes OpenSSL
|
||||
to run all supported cryptographic operations in the HSM.
|
||||
|
||||
- Use 'sign-only' with HSMs that are designed to function primarily as
|
||||
secure key storage devices, but lack hardware acceleration. These
|
||||
devices are highly secure, but are not necessarily any faster at
|
||||
cryptography than the system CPU--often, they are slower. It is
|
||||
therefore most efficient to use them only for those cryptographic
|
||||
functions that require access to the secured private key, such as
|
||||
zone signing, and to use the system CPU for all other computationally-
|
||||
intensive operations. The AEP Keyper is an example of such a device.
|
||||
|
||||
The modified OpenSSL code is included in the BIND 9.7.0b1 release, in the
|
||||
form of a context diff against OpenSSL 0.9.8l. Before building BIND 9
|
||||
with PKCS #11 support, it will be necessary to build OpenSSL with this
|
||||
patch in place and inform it of the path to the HSM-specific PKCS #11
|
||||
provider library.
|
||||
|
||||
Obtain OpenSSL 0.9.8l:
|
||||
|
||||
wget http://www.openssl.org/source/openssl-0.9.8l.tar.gz
|
||||
|
||||
Extract the tarball:
|
||||
|
||||
tar zxf openssl-0.9.8l.tar.gz
|
||||
|
||||
Apply the patch from the BIND 9 release:
|
||||
|
||||
patch -p1 -d openssl-0.9.8l \
|
||||
< bind-9.7.0b1/bin/pkcs11/openssl-0.9.8l-patch
|
||||
|
||||
(Note that the patch file may not be compatible with the "patch"
|
||||
utility on all operating systems. You may need to install GNU patch.)
|
||||
|
||||
When building OpenSSL, place it in a non-standard location so that it
|
||||
does not interfere with OpenSSL libraries elsewhere on the system.
|
||||
In the following examples, we choose to install into "/opt/pkcs11/usr".
|
||||
We will use this location when we configure BIND 9.
|
||||
|
||||
EXAMPLE 1--BUILDING OPENSSL FOR THE AEP KEYPER ON LINUX:
|
||||
|
||||
The AEP Keyper is a highly secure key storage device, but does
|
||||
not provide hardware cryptographic acceleration. It can carry out
|
||||
cryptographic operations, but it is probably slower than your
|
||||
system's CPU. Therefore, we choose the 'sign-only' flavor when
|
||||
building OpenSSL.
|
||||
|
||||
The Keyper-specific PKCS #11 provider library is delivered with the
|
||||
Keyper software. In this example, we place it /opt/pkcs11/usr/lib:
|
||||
|
||||
cp pkcs11.GCC4.0.2.so.4.05 /opt/pkcs11/usr/lib/libpkcs11.so
|
||||
|
||||
This library is only available for Linux as a 32-bit binary. If we are
|
||||
compiling on a 64-bit Linux system, it is necessary to force a 32-bit
|
||||
build, by specifying -m32 in the build options.
|
||||
|
||||
Finally, the Keyper library requires threads, so we must specify -pthread.
|
||||
|
||||
cd openssl-0.9.8l
|
||||
./Configure linux-generic32 -m32 -pthread \
|
||||
--pk11-libname=/opt/pkcs11/usr/lib/libpkcs11.so \
|
||||
--pk11-flavor=sign-only \
|
||||
--prefix=/opt/pkcs11/usr
|
||||
|
||||
After configuring, run "make" and "make test". If "make test" fails
|
||||
with "pthread_atfork() not found", you forgot to add the -pthread
|
||||
above.
|
||||
|
||||
EXAMPLE 2--BUILDING OPENSSL FOR THE SCA 6000 ON SOLARIS:
|
||||
|
||||
The SCA-6000 PKCS #11 provider is installed as a system library,
|
||||
libpkcs11. It is a true crypto accelerator, up to 4 times faster
|
||||
than any CPU, so the flavor shall be 'crypto-accelerator'.
|
||||
|
||||
In this example, we are building on Solaris x86 on an AMD64 system.
|
||||
|
||||
cd openssl-0.9.8l
|
||||
./Configure solaris64-x86_64-cc \
|
||||
--pk11-libname=/usr/lib/64/libpkcs11.so \
|
||||
--pk11-flavor=crypto-accelerator \
|
||||
--prefix=/opt/pkcs11/usr
|
||||
|
||||
(For a 32-bit build, use "solaris-x86-cc" and /usr/lib/libpkcs11.so.)
|
||||
|
||||
After configuring, run "make" and "make test".
|
||||
|
||||
Once you have built OpenSSL, run "apps/openssl engine pkcs11" to confirm
|
||||
that PKCS #11 support was compiled in correctly. The output should be
|
||||
one of the following lines, depending on the flavor selected:
|
||||
|
||||
(pkcs11) PKCS #11 engine support (sign only)
|
||||
|
||||
Or:
|
||||
|
||||
(pkcs11) PKCS #11 engine support (crypto accelerator)
|
||||
|
||||
Next, run "apps/openssl engine pkcs11 -t". This will attempt to initialize
|
||||
the PKCS #11 engine. If it is able to do so successfully, it will report
|
||||
"[ available ]".
|
||||
|
||||
If the output is correct, run "make install".
|
||||
|
||||
BUILDING BIND 9
|
||||
|
||||
When building BIND 9, the location of the custom-built OpenSSL
|
||||
library must be specified via configure.
|
||||
|
||||
EXAMPLE 3--CONFIGURING BIND 9 FOR LINUX
|
||||
|
||||
To link with the PKCS #11 provider, threads must be enabled in the
|
||||
BIND 9 build.
|
||||
|
||||
The PKCS #11 library for the AEP Keyper is currently only available as
|
||||
a 32-bit binary. If we are building on a 64-bit host, we must force a
|
||||
32-bit build by adding "-m32" to the CC options on the "configure"
|
||||
command line.
|
||||
|
||||
cd ../bind-9.7.0b1
|
||||
./configure CC="gcc -m32" --enable-threads \
|
||||
--with-openssl=/opt/pkcs11/usr \
|
||||
--with-pkcs11=/opt/pkcs11/usr/lib/libpkcs11.so
|
||||
|
||||
EXAMPLE 4--CONFIGURING BIND 9 FOR SOLARIS
|
||||
|
||||
To link with the PKCS #11 provider, threads must be enabled in the
|
||||
BIND 9 build.
|
||||
|
||||
cd ../bind-9.7.0b1
|
||||
./configure CC="cc -xarch=amd64" --enable-threads \
|
||||
--with-openssl=/opt/pkcs11/usr \
|
||||
--with-pkcs11=/usr/lib/64/libpkcs11.so
|
||||
|
||||
(For a 32-bit build, omit CC="cc -xarch=amd64".)
|
||||
|
||||
If configure complains about OpenSSL not working, you may have a 32/64-bit
|
||||
architecture mismatch. Or, you may have incorrectly specified the path to
|
||||
OpenSSL (it should be the same as the --prefix argument to the OpenSSL
|
||||
Configure).
|
||||
|
||||
After configuring, run "make", "make test" and "make install".
|
||||
|
||||
PKCS #11 TOOLS
|
||||
|
||||
BIND 9 includes a minimal set of tools to operate the HSM, including
|
||||
"pkcs11-keygen" to generate a new key pair within the HSM, "pkcs11-list"
|
||||
to list objects currently available, and "pkcs11-destroy" to remove
|
||||
objects.
|
||||
|
||||
In UNIX/Linux builds, these tools are built only if BIND 9 is configured
|
||||
with the --with-pkcs11 option. (NOTE: If --with-pkcs11 is set to "yes",
|
||||
rather than to the path of the PKCS #11 provider, then the tools will be
|
||||
built but the provider will be left undefined. Use the -m option or the
|
||||
PKCS11_PROVIDER environment variable to specify the path to the provider.)
|
||||
|
||||
USING THE HSM
|
||||
|
||||
First, we must set up the runtime environment so the OpenSSL and PKCS #11
|
||||
libraries can be loaded:
|
||||
|
||||
export LD_LIBRARY_PATH=/opt/pkcs11/usr/lib:${LD_LIBRARY_PATH}
|
||||
|
||||
When operating an AEP Keyper, it is also necessary to specify the
|
||||
location of the "machine" file, which stores information about the Keyper
|
||||
for use by PKCS #11 provider library. If the machine file is in
|
||||
/opt/Keyper/PKCS11Provider/machine, use:
|
||||
|
||||
export KEYPER_LIBRARY_PATH=/opt/Keyper/PKCS11Provider
|
||||
|
||||
These environment variables must be set whenever running any tool
|
||||
that uses the HSM, including pkcs11-keygen, pkcs11-list, pkcs11-destroy,
|
||||
dnssec-keyfromlabel, dnssec-signzone, dnssec-keygen (which will use
|
||||
the HSM for random number generation), and named.
|
||||
|
||||
We can now create and use keys in the HSM. In this case, we will
|
||||
create a 2048 bit key and give it the label "sample-ksk":
|
||||
|
||||
pkcs11-keygen -b 2048 -l sample-ksk
|
||||
|
||||
To confirm that the key exists:
|
||||
|
||||
pkcs11-list
|
||||
Enter PIN:
|
||||
object[0]: handle 2147483658 class 3 label[8] 'sample-ksk' id[0]
|
||||
object[1]: handle 2147483657 class 2 label[8] 'sample-ksk' id[0]
|
||||
|
||||
Before using this key to sign a zone, we must create a pair of BIND 9
|
||||
key files. The "dnssec-keyfromlabel" utility does this. In this case,
|
||||
we will be using the HSM key "sample-ksk" as the key-signing key for
|
||||
"example.net":
|
||||
|
||||
dnssec-keyfromlabel -l sample-ksk -f KSK example.net
|
||||
|
||||
The resulting K*.key and K*.private files can now be used to sign the
|
||||
zone. Unlike normal K* files, which contain both public and private
|
||||
key data, these files will contain only the public key data, plus an
|
||||
identifier for the private key which remains stored within the HSM.
|
||||
The HSM handles signing with the private key.
|
||||
|
||||
If you wish to generate a second key in the HSM for use as a zone-signing
|
||||
key, follow the same procedure above, using a different keylabel, a
|
||||
smaller key size, and omitting "-f KSK" from the dnssec-keyfromlabel
|
||||
arguments:
|
||||
|
||||
pkcs11-keygen -b 1024 -l sample-zsk
|
||||
dnssec-keyfromlabel -l sample-zsk example.net
|
||||
|
||||
Alternatively, you may prefer to generate a conventional on-disk key,
|
||||
using dnssec-keygen:
|
||||
|
||||
dnssec-keygen example.net
|
||||
|
||||
This provides less security than an HSM key, but since HSMs can be
|
||||
slow or cumbersome to use for security reasons, it may be more
|
||||
efficient to reserve HSM keys for use in the less frequent
|
||||
key-signing operation. The zone-signing key can be rolled more
|
||||
frequently, if you wish, to compensate for a reduction in key
|
||||
security.
|
||||
|
||||
Now you can sign the zone. (Note: If not using the -S option to
|
||||
dnssec-signzone, it will be necessary to add the contents of both
|
||||
K*.key files to the zone master file before signing it.)
|
||||
|
||||
dnssec-signzone -S example.net
|
||||
Enter PIN:
|
||||
Verifying the zone using the following algorithms: NSEC3RSASHA1.
|
||||
Zone signing complete:
|
||||
Algorithm: NSEC3RSASHA1: ZSKs: 1, KSKs: 1 active, 0 revoked, 0 stand-by
|
||||
example.net.signed
|
||||
|
||||
SPECIFYING THE ENGINE ON THE COMMAND LINE
|
||||
|
||||
The OpenSSL engine can be specified in named and all of the dnssec-*
|
||||
tools by using the "-E <engine>" command line option. If BIND 9 is built
|
||||
with the --with-pkcs11 option, this option defaults to "pkcs11".
|
||||
Specifying the engine will generally not be necessary unless for
|
||||
some reason you wish to use a different OpenSSL engine.
|
||||
|
||||
If you wish to disable use of the "pkcs11" engine--for troubleshooting
|
||||
purposes, or because the HSM is unavailable--set the engine to the empty
|
||||
string. For example:
|
||||
|
||||
dnssec-signzone -E '' -S example.net
|
||||
|
||||
This causes dnssec-signzone to run as if it were compiled without the
|
||||
--with-pkcs11 option.
|
||||
|
||||
RUNNING NAMED WITH AUTOMATIC ZONE RE-SIGNING
|
||||
|
||||
If you want named to dynamically re-sign zones using HSM keys, and/or to
|
||||
to sign new records inserted via nsupdate, then named must have access
|
||||
to the HSM PIN. This can be accomplished by placing the PIN into the
|
||||
openssl.cnf file (in the above examples, /opt/pkcs11/usr/ssl/openssl.cnf).
|
||||
|
||||
The location of the openssl.cnf file can be overridden by setting the
|
||||
OPENSSL_CONF environment variable before running named.
|
||||
|
||||
Sample openssl.cnf:
|
||||
|
||||
openssl_conf = openssl_def
|
||||
[ openssl_def ]
|
||||
engines = engine_section
|
||||
[ engine_section ]
|
||||
pkcs11 = pkcs11_section
|
||||
[ pkcs11_section ]
|
||||
PIN = <PLACE PIN HERE>
|
||||
|
||||
This will also allow the dnssec-* tools to access the HSM without
|
||||
PIN entry. (The pkcs11-* tools access the HSM directly, not via
|
||||
OpenSSL, so a PIN will still be required to use them.)
|
||||
|
||||
PLEASE NOTE: Placing the HSM's PIN in a text file in this manner
|
||||
may reduce the security advantage of using an HSM. Be sure this
|
||||
is what you want to do before configuring BIND 9 in this way.
|
||||
@@ -1,74 +0,0 @@
|
||||
|
||||
BIND 9 RFC 5011 support
|
||||
|
||||
BIND 9.7.0 introduces support for RFC 5011, dynamic trust anchor
|
||||
management. Using this feature allows named to keep track of changes to
|
||||
critical DNSSEC keys without any need for the operator to make changes to
|
||||
configuration files.
|
||||
|
||||
VALIDATING RESOLVER
|
||||
-------------------
|
||||
|
||||
To configure a validating resolver to use RFC5011 to maintain a trust
|
||||
anchor, configure the trust anchor using a "managed-keys" statement.
|
||||
Information about this can be found in the ARM, in the section titled
|
||||
"managed-keys Statement Definition".
|
||||
|
||||
AUTHORITATIVE SERVER
|
||||
--------------------
|
||||
|
||||
To set up an authoritative zone for RFC5011 trust anchor maintenance,
|
||||
generate two (or more) key signing keys (KSKs) for the zone. Sign the zone
|
||||
with one of them; this is the "active" KSK. All KSK's which do not sign
|
||||
the zone are "stand-by" keys.
|
||||
|
||||
Any validating resolver which is configured to use the active KSK as an
|
||||
RFC5011-managed trust anchor will take note of the stand-by KSKs in the
|
||||
zone's DNSKEY RRset, and store them for future reference. The resolver
|
||||
will recheck the zone periodically, and after 30 days, if the new key is
|
||||
still there, then the key will be accepted by the resolver as a valid
|
||||
trust anchor for the zone. Any time after this 30-day acceptance timer
|
||||
has completed, the active KSK can be revoked, and the zone can be "rolled
|
||||
over" to the newly accepted key.
|
||||
|
||||
The easiest way to place a stand-by key in a zone is to use the "smart
|
||||
signing" features of dnssec-keygen and dnssec-signzone. If a key with a
|
||||
publication date in the past, but an activation date which is unset or in
|
||||
the future, "dnssec-signzone -S" will include the DNSKEY record in the
|
||||
zone, but will not sign with it:
|
||||
|
||||
$ dnssec-keygen -K keys -f KSK -P now -A now+2y example.net
|
||||
$ dnssec-signzone -S -K keys example.net
|
||||
|
||||
To revoke a key, the new command "dnssec-revoke" has been added. This adds
|
||||
the REVOKED bit to the key flags and re-generates the K*.key and K*.private
|
||||
files.
|
||||
|
||||
After revoking the active key, the zone must be signed with both the
|
||||
revoked KSK and the new active KSK. (Smart signing takes care of this
|
||||
automatically.)
|
||||
|
||||
Once a key has been revoked and used to sign the DNSKEY RRset in which it
|
||||
appears, that key will never again be accepted as a valid trust anchor by
|
||||
the resolver. However, validation can proceed using the new active key
|
||||
(which had been accepted by the resolver when it was a stand-by key).
|
||||
|
||||
See RFC 5011 for more details on key rollover scenarios.
|
||||
|
||||
When a key has been revoked, its key ID changes, increasing by
|
||||
128, and wrapping around at 65535. So, for example, the key
|
||||
"Kexample.com.+005+10000" becomes "Kexample.com.+005+10128".
|
||||
|
||||
If two keys have ID's exactly 128 apart, and one is revoked, then the
|
||||
two key ID's will collide, causing several problems. To prevent this,
|
||||
dnssec-keygen will not generate a new key if another key is present which
|
||||
may collide. This checking will only occur if the new keys are written
|
||||
to the same directory which holds all other keys in use for that zone.
|
||||
|
||||
Older versions of BIND 9 did not have this precaution. Exercise caution if
|
||||
using key revocation on keys that were generated by previous releases, or
|
||||
if using keys stored in multiple directories or on multiple machines.
|
||||
|
||||
It is expected that a future release of BIND 9 will address this problem
|
||||
in a different way, by storing revoked keys with their original unrevoked
|
||||
key ID's.
|
||||
@@ -0,0 +1,354 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: RELEASE-NOTES-BIND-9.7.4.html,v 1.1.2.8 2011/07/23 23:46:45 tbox Exp $ -->
|
||||
|
||||
<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title></title><link rel="stylesheet" href="release-notes.css" type="text/css" /><meta name="generator" content="DocBook XSL Stylesheets V1.71.1" /></head><body><div class="article" lang="en" xml:lang="en"><div class="titlepage"><hr /></div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3359852"></a>Introduction</h2></div></div></div>
|
||||
|
||||
<p>
|
||||
BIND 9.7.4 is the current production release of BIND 9.7.
|
||||
</p>
|
||||
<p>
|
||||
This document summarizes changes from BIND 9.7.3 to BIND 9.7.4.
|
||||
Please see the CHANGES file in the source code release for a
|
||||
complete list of all changes.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id2546702"></a>Download</h2></div></div></div>
|
||||
|
||||
<p>
|
||||
The latest version of BIND 9 software can always be found
|
||||
on our web site at
|
||||
<a href="http://www.isc.org/downloads/all" target="_top">http://www.isc.org/downloads/all</a>.
|
||||
There you will find additional information about each release,
|
||||
source code, and some pre-compiled versions for certain operating
|
||||
systems.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id2546736"></a>Support</h2></div></div></div>
|
||||
|
||||
<p>Product support information is available on
|
||||
<a href="http://www.isc.org/services/support" target="_top">http://www.isc.org/services/support</a>
|
||||
for paid support options. Free support is provided by our user
|
||||
community via a mailing list. Information on all public email
|
||||
lists is available at
|
||||
<a href="https://lists.isc.org/mailman/listinfo" target="_top">https://lists.isc.org/mailman/listinfo</a>.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3358885"></a>New Features</h2></div></div></div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h3 class="title"><a id="id3358925"></a>9.7.4</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul type="disc"><li>
|
||||
A new test has been added to check the apex NSEC3 records after DNSKEY
|
||||
records have been added via dynamic update. [RT #23229]
|
||||
</li><li>
|
||||
Added a tool able to generate malformed packets to allow testing
|
||||
of how named handles them.
|
||||
[RT #24096]
|
||||
</li></ul></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3358973"></a>Security Fixes</h2></div></div></div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h3 class="title"><a id="id3358993"></a>9.7.4</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul type="disc"><li>
|
||||
named, set up to be a caching resolver, is vulnerable to a
|
||||
user querying a domain with very large resource record sets (RRSets)
|
||||
when trying to negatively cache the response. Due to an off-by-one
|
||||
error, caching the response could cause named to crash. [RT #24650]
|
||||
[CVE-2011-1910]
|
||||
</li><li>
|
||||
Change #2912 (see CHANGES) exposed a latent bug in the DNS message
|
||||
processing code that could allow certain UPDATE requests to crash named.
|
||||
[RT #24777] [CVE-2011-2464]
|
||||
</li></ul></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3359041"></a>Feature Changes</h2></div></div></div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h3 class="title"><a id="id3359054"></a>9.7.4</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul type="disc"><li>
|
||||
Merged in the NetBSD ATF test framework (currently
|
||||
version 0.12) for development of future unit tests.
|
||||
Use configure --with-atf to build ATF internally
|
||||
or configure --with-atf=prefix to use an external
|
||||
copy. [RT #23209]
|
||||
</li><li>
|
||||
Added more verbose error reporting from DLZ LDAP. [RT #23402]
|
||||
</li><li>
|
||||
Replaced compile time constant with STDTIME_ON_32BITS.
|
||||
[RT #23587]
|
||||
</li></ul></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3359075"></a>Bug Fixes</h2></div></div></div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h3 class="title"><a id="id3359081"></a>9.7.4</h3></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul type="disc"><li>
|
||||
<p>
|
||||
During RFC5011 processing some journal write errors were not detected.
|
||||
This could lead to managed-keys changes being committed but not
|
||||
recorded in the journal files, causing potential inconsistencies
|
||||
during later processing. [RT #20256]
|
||||
</p>
|
||||
<p>
|
||||
A potential NULL pointer deference in the DNS64 code could cause
|
||||
named to terminate unexpectedly. [RT #20256]
|
||||
</p>
|
||||
<p>
|
||||
A state variable relating to DNSSEC could fail to be set during
|
||||
some infrequently-executed code paths, allowing it to be used whilst
|
||||
in an unitialized state during cache updates, with unpredictable results.
|
||||
[RT #20256]
|
||||
</p>
|
||||
<p>
|
||||
A potential NULL pointer deference in DNSSEC signing code could
|
||||
cause named to terminate unexpectedly [RT #20256]
|
||||
</p>
|
||||
<p>
|
||||
Several cosmetic code changes were made to silence warnings
|
||||
generated by a static code analysis tool. [RT #20256]
|
||||
</p>
|
||||
</li><li>
|
||||
When using the -x (sign with only KSK) option on dnssec-signzone,
|
||||
it could incorrectly count the number of ZSKs in the zone. (And in 9.9.0,
|
||||
some code cleanup and improved warning messages). [RT #20852]
|
||||
</li><li>
|
||||
When using _builtin in named.conf, named.conf changes were not found
|
||||
when reloading the config file. Now checks _builtin zone arguments
|
||||
to see if the zone is re-usable or not. [RT #21914]
|
||||
</li><li>
|
||||
After an "rndc reconfig", the refresh timer for managed-keys is
|
||||
ignored, resulting in managed-keys not being refreshed until named is
|
||||
restarted. [RT #22296]
|
||||
</li><li>
|
||||
Running dnssec-settime -f on an old-style key will
|
||||
now force the key to be rewritten to the new key format even if no
|
||||
other change has been specified, using "-P now -A now"
|
||||
as default values. [RT #22474]
|
||||
</li><li>
|
||||
After an external code review, a code cleanup was done. [RT #22521]
|
||||
</li><li>
|
||||
Cause named to terminate at startup or rndc reconfig
|
||||
reload to fail, if a log file specified in the
|
||||
conf file isn't a plain file. (RT #22771]
|
||||
</li><li>
|
||||
named now forces the ADB cache time for glue related data to zero
|
||||
instead of relying on TTL. This corrects problematic behavior in cases
|
||||
where a server was authoritative for the A record of a nameserver for a
|
||||
delegated zone and was queried to recursively resolve records within
|
||||
that zone. [RT #22842]
|
||||
</li><li>
|
||||
When a validating resolver got a NODATA response for DNSKEY, it was
|
||||
not caching the NODATA. Fixed and test added. [RT #22908]
|
||||
</li><li>
|
||||
Fixed a bug in which zone keys that were published
|
||||
and but not immediately activated, automatic signing could fail to trigger.
|
||||
[RT #22911]
|
||||
</li><li>
|
||||
Fixed a possible deadlock due to zone re-signing. [RT #22964]
|
||||
</li><li>
|
||||
Fixed precedence order bug with NS and DNAME records if both are present.
|
||||
(Also fixed timing of autosign test in 9.7+) [RT #23035]
|
||||
</li><li>
|
||||
When a DNSSEC signed dynamic zone's signatures need to be refreshed,
|
||||
named would first delete the old signatures in the zone. If a private
|
||||
key of the same algorithm isn't available to named, the signing would
|
||||
fail but the old signatures would already be deleted. named now checks
|
||||
if it can access the private key before deleting the old signatures and
|
||||
leaves the old signature if no private key is found. [RT #23136]
|
||||
</li><li>
|
||||
When using auto-dnssec and updating DNSKEY records, named did correctly
|
||||
update the zone. [RT #23232]
|
||||
</li><li>
|
||||
When using "auto-dnssec maintain" and rolling to a new key, a
|
||||
private-type record (only used internally by named) could be created
|
||||
and not marked as complete. [RT #23253]
|
||||
</li><li>
|
||||
If a slave initiates a TSIG signed AXFR from the master and the master
|
||||
fails to correctly TSIG sign the final message, the slave would be left
|
||||
with the zone in an unclean state. named detected this error too late
|
||||
and named would crash with an INSIST. The order dependancy has been
|
||||
fixed. [RT #23254]
|
||||
</li><li>
|
||||
Fixed last autosign test report. [RT #23256]
|
||||
</li><li>
|
||||
named didn't save gid at startup and later assumed gid 0.
|
||||
named now saves/restores the gid when creating creating
|
||||
named.pid at startup. [RT #23290]
|
||||
</li><li>
|
||||
If the server has an IPv6 address but does not have IPv6 connectivity
|
||||
to the internet, dig +trace could fail attempting to use IPv6
|
||||
addresses. [RT #23297]
|
||||
</li><li>
|
||||
If named is configured with managed zones, the managed key maint timer
|
||||
can exercise a race condition that can crash the server.
|
||||
[RT #23303]
|
||||
</li><li>
|
||||
Changing TTL did not cause dnssec-signzone to generate new signatures.
|
||||
[RT #23330]
|
||||
</li><li>
|
||||
Have the validating resolver use RRSIG original TTL to compute
|
||||
validated RRset and RRSIG TTL. [RT #23332]
|
||||
</li><li>
|
||||
In "make test" bin/tests/resolver, hold the socket manager lock
|
||||
while freeing the socket.
|
||||
[RT #23333]
|
||||
</li><li>
|
||||
If named encountered a CNAME instead of a DS record when walking
|
||||
the chain of trust down from the trust anchor, it incorrectly stopped
|
||||
validating. [RT #23338]
|
||||
</li><li>
|
||||
RRSIG records could have time stamps too far in the future.
|
||||
[RT #23356]
|
||||
</li><li>
|
||||
named stores cached data in an in-memory database and keeps track of
|
||||
how recently the data is used with a heap. The heap is stored within the
|
||||
cache's memory space. Under a sustained high query load and with a small
|
||||
cache size, this could lead to the heap exhausting the cache space. This
|
||||
would result in cache misses and SERVFAILs, with named never releasing
|
||||
the cache memory the heap used up and never recovering.
|
||||
|
||||
This fix removes the heap into its own memory space, preventing the heap
|
||||
from exhausting the cache space and allowing named to recover gracefully
|
||||
when the high query load abates. [RT #23371]
|
||||
</li><li>
|
||||
If "dnssec-lookaside auto" is turned on, named pulled in all keys
|
||||
defined in bind.keys, including the root key.
|
||||
named now only loads the desired keys.
|
||||
[RT #23372]
|
||||
</li><li>
|
||||
Fully separated key management on a per view basis. [RT #23419]
|
||||
</li><li>
|
||||
If running on a powerpc CPU and with atomic operations enabled,
|
||||
named could lock up. Added sync instructions to the end of atomic
|
||||
operations. [RT #23469]
|
||||
</li><li>
|
||||
If OpenSSL was built without engine support, named would have
|
||||
compile errors and fail to build.
|
||||
[RT #23473]
|
||||
</li><li>
|
||||
"rndc secroots" would abort on the first error
|
||||
and so could miss remaining views. [RT #23488]
|
||||
</li><li>
|
||||
Handle isc_event_allocate failures in t_tasks test.
|
||||
[RT #23572]
|
||||
</li><li>
|
||||
ixfr-from-differences {master|slave};
|
||||
failed to select the master/slave zones, resulting in on diff/journal
|
||||
file being created.
|
||||
[RT #23580]
|
||||
</li><li>
|
||||
If a DNAME substitution failed, named returned NOERROR. The correct
|
||||
response should be YXDOMAIN.
|
||||
[RT #23591]
|
||||
</li><li>
|
||||
dns_dnssec_findzonekeys{2} used a inconsistant
|
||||
timestamp when determining which keys are active. This could result in
|
||||
some RRsets not being signed/re-signed.
|
||||
[RT #23642]
|
||||
</li><li>
|
||||
Remove bin/tests/system/logfileconfig/ns1/named.conf and
|
||||
add setup.sh in order to resolve changing named.conf issue. [RT #23687]
|
||||
</li><li>
|
||||
NOTIFY messages were not being sent when generating
|
||||
a NSEC3 chain incrementally. [RT #23702]
|
||||
</li><li>
|
||||
Zones using automatic key maintenance could fail to check the key
|
||||
repository for updates. named now checks once per hour and the
|
||||
automatic check bug has been fixed. [RT #23744]
|
||||
</li><li>
|
||||
Signatures for records at the zone apex could go
|
||||
stale due to an incorrect timer setting. [RT #23769]
|
||||
</li><li>
|
||||
The autosign tests attempted to open ports within reserved ranges. Test
|
||||
now avoids those ports.
|
||||
[RT #23957]
|
||||
</li><li>
|
||||
named, acting as authoritative server for DLZ zones, was not correctly
|
||||
setting the authoritative (AA) bit.
|
||||
[RT #24146]
|
||||
</li><li>
|
||||
Clean up some cross-compiling issues and added two undocumented
|
||||
configure options, --with-gost and --with-rlimtype, to allow over-riding
|
||||
default settings (gost=no and rlimtype="long int") when cross-compiling.
|
||||
[RT #24367]
|
||||
</li><li>
|
||||
When trying sign with NSEC3, if dnssec-signzone couldn't find the
|
||||
KSK, it would give an incorrect error "NSEC3 iterations too big for
|
||||
weakest DNSKEY strength" rather than the correct "failed to find
|
||||
keys at the zone apex: not found" [RT #24369]
|
||||
</li><li>
|
||||
Improved consistency checks for dnssec-enable and
|
||||
dnssec-validation, added test cases to the
|
||||
checkconf system test. [RT #24398]
|
||||
</li><li>
|
||||
RT #23136 fixed a problem where named would delete old signatures even
|
||||
when the private key wasn't available to re-sign the zone, resulting in
|
||||
a zone with missing signatures. This fix (CHANGES 3114) did not
|
||||
completely fix all issues. [RT #24577]
|
||||
</li><li>
|
||||
nsupdate could dump core on shutdown when using SIG(0) keys. [RT #24604]
|
||||
</li><li>
|
||||
Named could fail to validate zones list in a DLV that validated insecure
|
||||
without using DLV and had DS records in the parent zone. [RT #24631]
|
||||
</li><li>
|
||||
A bug in FreeBSD kernels causes IPv6 UDP responses greater than
|
||||
1280 bytes to not fragment as they should. Until there is a kernel
|
||||
fix, named will work around this by setting IPV6_USE_MIN_MTU on a
|
||||
per packet basis. [RT #24950]
|
||||
</li><li>
|
||||
To avoid excessive startup time for configurations with large numbers
|
||||
of zones, an environment variable, BIND9_ZONE_TASKS_HINTS, may now
|
||||
be set prior to starting named. Divide your number of zones by 200
|
||||
to find the recommended setting for this environment variable (i.e.,
|
||||
if you have 200000 zones, set BIND9_ZONE_TASKS_HINTS to 1000 before
|
||||
starting named). [RT #25084]
|
||||
</li></ul></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3359538"></a>Known issues in this release</h2></div></div></div>
|
||||
|
||||
<div class="itemizedlist"><ul type="disc"><li>
|
||||
None
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section" lang="en" xml:lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="id3359961"></a>Thank You</h2></div></div></div>
|
||||
|
||||
<p>
|
||||
Thank you to everyone who assisted us in making this release possible.
|
||||
If you would like to contribute to ISC to assist us in continuing to make
|
||||
quality open source software, please visit our donations page at
|
||||
<a href="http://www.isc.org/supportisc" target="_top">http://www.isc.org/supportisc</a>.
|
||||
</p>
|
||||
</div>
|
||||
</div></body></html>
|
||||
Binary file not shown.
@@ -0,0 +1,229 @@
|
||||
__________________________________________________________________
|
||||
|
||||
Introduction
|
||||
|
||||
BIND 9.7.4 is the current production release of BIND 9.7.
|
||||
|
||||
This document summarizes changes from BIND 9.7.3 to BIND 9.7.4. Please
|
||||
see the CHANGES file in the source code release for a complete list of
|
||||
all changes.
|
||||
|
||||
Download
|
||||
|
||||
The latest version of BIND 9 software can always be found on our web
|
||||
site at http://www.isc.org/downloads/all. There you will find
|
||||
additional information about each release, source code, and some
|
||||
pre-compiled versions for certain operating systems.
|
||||
|
||||
Support
|
||||
|
||||
Product support information is available on
|
||||
http://www.isc.org/services/support for paid support options. Free
|
||||
support is provided by our user community via a mailing list.
|
||||
Information on all public email lists is available at
|
||||
https://lists.isc.org/mailman/listinfo.
|
||||
|
||||
New Features
|
||||
|
||||
9.7.4
|
||||
|
||||
* A new test has been added to check the apex NSEC3 records after
|
||||
DNSKEY records have been added via dynamic update. [RT #23229]
|
||||
* Added a tool able to generate malformed packets to allow testing of
|
||||
how named handles them. [RT #24096]
|
||||
|
||||
Security Fixes
|
||||
|
||||
9.7.4
|
||||
|
||||
* named, set up to be a caching resolver, is vulnerable to a user
|
||||
querying a domain with very large resource record sets (RRSets)
|
||||
when trying to negatively cache the response. Due to an off-by-one
|
||||
error, caching the response could cause named to crash. [RT #24650]
|
||||
[CVE-2011-1910]
|
||||
* Change #2912 (see CHANGES) exposed a latent bug in the DNS message
|
||||
processing code that could allow certain UPDATE requests to crash
|
||||
named. [RT #24777] [CVE-2011-2464]
|
||||
|
||||
Feature Changes
|
||||
|
||||
9.7.4
|
||||
|
||||
* Merged in the NetBSD ATF test framework (currently version 0.12)
|
||||
for development of future unit tests. Use configure --with-atf to
|
||||
build ATF internally or configure --with-atf=prefix to use an
|
||||
external copy. [RT #23209]
|
||||
* Added more verbose error reporting from DLZ LDAP. [RT #23402]
|
||||
* Replaced compile time constant with STDTIME_ON_32BITS. [RT #23587]
|
||||
|
||||
Bug Fixes
|
||||
|
||||
9.7.4
|
||||
|
||||
* During RFC5011 processing some journal write errors were not
|
||||
detected. This could lead to managed-keys changes being committed
|
||||
but not recorded in the journal files, causing potential
|
||||
inconsistencies during later processing. [RT #20256]
|
||||
A potential NULL pointer deference in the DNS64 code could cause
|
||||
named to terminate unexpectedly. [RT #20256]
|
||||
A state variable relating to DNSSEC could fail to be set during
|
||||
some infrequently-executed code paths, allowing it to be used
|
||||
whilst in an unitialized state during cache updates, with
|
||||
unpredictable results. [RT #20256]
|
||||
A potential NULL pointer deference in DNSSEC signing code could
|
||||
cause named to terminate unexpectedly [RT #20256]
|
||||
Several cosmetic code changes were made to silence warnings
|
||||
generated by a static code analysis tool. [RT #20256]
|
||||
* When using the -x (sign with only KSK) option on dnssec-signzone,
|
||||
it could incorrectly count the number of ZSKs in the zone. (And in
|
||||
9.9.0, some code cleanup and improved warning messages). [RT
|
||||
#20852]
|
||||
* When using _builtin in named.conf, named.conf changes were not
|
||||
found when reloading the config file. Now checks _builtin zone
|
||||
arguments to see if the zone is re-usable or not. [RT #21914]
|
||||
* After an "rndc reconfig", the refresh timer for managed-keys is
|
||||
ignored, resulting in managed-keys not being refreshed until named
|
||||
is restarted. [RT #22296]
|
||||
* Running dnssec-settime -f on an old-style key will now force the
|
||||
key to be rewritten to the new key format even if no other change
|
||||
has been specified, using "-P now -A now" as default values. [RT
|
||||
#22474]
|
||||
* After an external code review, a code cleanup was done. [RT #22521]
|
||||
* Cause named to terminate at startup or rndc reconfig reload to
|
||||
fail, if a log file specified in the conf file isn't a plain file.
|
||||
(RT #22771]
|
||||
* named now forces the ADB cache time for glue related data to zero
|
||||
instead of relying on TTL. This corrects problematic behavior in
|
||||
cases where a server was authoritative for the A record of a
|
||||
nameserver for a delegated zone and was queried to recursively
|
||||
resolve records within that zone. [RT #22842]
|
||||
* When a validating resolver got a NODATA response for DNSKEY, it was
|
||||
not caching the NODATA. Fixed and test added. [RT #22908]
|
||||
* Fixed a bug in which zone keys that were published and but not
|
||||
immediately activated, automatic signing could fail to trigger. [RT
|
||||
#22911]
|
||||
* Fixed a possible deadlock due to zone re-signing. [RT #22964]
|
||||
* Fixed precedence order bug with NS and DNAME records if both are
|
||||
present. (Also fixed timing of autosign test in 9.7+) [RT #23035]
|
||||
* When a DNSSEC signed dynamic zone's signatures need to be
|
||||
refreshed, named would first delete the old signatures in the zone.
|
||||
If a private key of the same algorithm isn't available to named,
|
||||
the signing would fail but the old signatures would already be
|
||||
deleted. named now checks if it can access the private key before
|
||||
deleting the old signatures and leaves the old signature if no
|
||||
private key is found. [RT #23136]
|
||||
* When using auto-dnssec and updating DNSKEY records, named did
|
||||
correctly update the zone. [RT #23232]
|
||||
* When using "auto-dnssec maintain" and rolling to a new key, a
|
||||
private-type record (only used internally by named) could be
|
||||
created and not marked as complete. [RT #23253]
|
||||
* If a slave initiates a TSIG signed AXFR from the master and the
|
||||
master fails to correctly TSIG sign the final message, the slave
|
||||
would be left with the zone in an unclean state. named detected
|
||||
this error too late and named would crash with an INSIST. The order
|
||||
dependancy has been fixed. [RT #23254]
|
||||
* Fixed last autosign test report. [RT #23256]
|
||||
* named didn't save gid at startup and later assumed gid 0. named now
|
||||
saves/restores the gid when creating creating named.pid at startup.
|
||||
[RT #23290]
|
||||
* If the server has an IPv6 address but does not have IPv6
|
||||
connectivity to the internet, dig +trace could fail attempting to
|
||||
use IPv6 addresses. [RT #23297]
|
||||
* If named is configured with managed zones, the managed key maint
|
||||
timer can exercise a race condition that can crash the server. [RT
|
||||
#23303]
|
||||
* Changing TTL did not cause dnssec-signzone to generate new
|
||||
signatures. [RT #23330]
|
||||
* Have the validating resolver use RRSIG original TTL to compute
|
||||
validated RRset and RRSIG TTL. [RT #23332]
|
||||
* In "make test" bin/tests/resolver, hold the socket manager lock
|
||||
while freeing the socket. [RT #23333]
|
||||
* If named encountered a CNAME instead of a DS record when walking
|
||||
the chain of trust down from the trust anchor, it incorrectly
|
||||
stopped validating. [RT #23338]
|
||||
* RRSIG records could have time stamps too far in the future. [RT
|
||||
#23356]
|
||||
* named stores cached data in an in-memory database and keeps track
|
||||
of how recently the data is used with a heap. The heap is stored
|
||||
within the cache's memory space. Under a sustained high query load
|
||||
and with a small cache size, this could lead to the heap exhausting
|
||||
the cache space. This would result in cache misses and SERVFAILs,
|
||||
with named never releasing the cache memory the heap used up and
|
||||
never recovering. This fix removes the heap into its own memory
|
||||
space, preventing the heap from exhausting the cache space and
|
||||
allowing named to recover gracefully when the high query load
|
||||
abates. [RT #23371]
|
||||
* If "dnssec-lookaside auto" is turned on, named pulled in all keys
|
||||
defined in bind.keys, including the root key. named now only loads
|
||||
the desired keys. [RT #23372]
|
||||
* Fully separated key management on a per view basis. [RT #23419]
|
||||
* If running on a powerpc CPU and with atomic operations enabled,
|
||||
named could lock up. Added sync instructions to the end of atomic
|
||||
operations. [RT #23469]
|
||||
* If OpenSSL was built without engine support, named would have
|
||||
compile errors and fail to build. [RT #23473]
|
||||
* "rndc secroots" would abort on the first error and so could miss
|
||||
remaining views. [RT #23488]
|
||||
* Handle isc_event_allocate failures in t_tasks test. [RT #23572]
|
||||
* ixfr-from-differences {master|slave}; failed to select the
|
||||
master/slave zones, resulting in on diff/journal file being
|
||||
created. [RT #23580]
|
||||
* If a DNAME substitution failed, named returned NOERROR. The correct
|
||||
response should be YXDOMAIN. [RT #23591]
|
||||
* dns_dnssec_findzonekeys{2} used a inconsistant timestamp when
|
||||
determining which keys are active. This could result in some RRsets
|
||||
not being signed/re-signed. [RT #23642]
|
||||
* Remove bin/tests/system/logfileconfig/ns1/named.conf and add
|
||||
setup.sh in order to resolve changing named.conf issue. [RT #23687]
|
||||
* NOTIFY messages were not being sent when generating a NSEC3 chain
|
||||
incrementally. [RT #23702]
|
||||
* Zones using automatic key maintenance could fail to check the key
|
||||
repository for updates. named now checks once per hour and the
|
||||
automatic check bug has been fixed. [RT #23744]
|
||||
* Signatures for records at the zone apex could go stale due to an
|
||||
incorrect timer setting. [RT #23769]
|
||||
* The autosign tests attempted to open ports within reserved ranges.
|
||||
Test now avoids those ports. [RT #23957]
|
||||
* named, acting as authoritative server for DLZ zones, was not
|
||||
correctly setting the authoritative (AA) bit. [RT #24146]
|
||||
* Clean up some cross-compiling issues and added two undocumented
|
||||
configure options, --with-gost and --with-rlimtype, to allow
|
||||
over-riding default settings (gost=no and rlimtype="long int") when
|
||||
cross-compiling. [RT #24367]
|
||||
* When trying sign with NSEC3, if dnssec-signzone couldn't find the
|
||||
KSK, it would give an incorrect error "NSEC3 iterations too big for
|
||||
weakest DNSKEY strength" rather than the correct "failed to find
|
||||
keys at the zone apex: not found" [RT #24369]
|
||||
* Improved consistency checks for dnssec-enable and
|
||||
dnssec-validation, added test cases to the checkconf system test.
|
||||
[RT #24398]
|
||||
* RT #23136 fixed a problem where named would delete old signatures
|
||||
even when the private key wasn't available to re-sign the zone,
|
||||
resulting in a zone with missing signatures. This fix (CHANGES
|
||||
3114) did not completely fix all issues. [RT #24577]
|
||||
* nsupdate could dump core on shutdown when using SIG(0) keys. [RT
|
||||
#24604]
|
||||
* Named could fail to validate zones list in a DLV that validated
|
||||
insecure without using DLV and had DS records in the parent zone.
|
||||
[RT #24631]
|
||||
* A bug in FreeBSD kernels causes IPv6 UDP responses greater than
|
||||
1280 bytes to not fragment as they should. Until there is a kernel
|
||||
fix, named will work around this by setting IPV6_USE_MIN_MTU on a
|
||||
per packet basis. [RT #24950]
|
||||
* To avoid excessive startup time for configurations with large
|
||||
numbers of zones, an environment variable, BIND9_ZONE_TASKS_HINTS,
|
||||
may now be set prior to starting named. Divide your number of zones
|
||||
by 200 to find the recommended setting for this environment
|
||||
variable (i.e., if you have 200000 zones, set
|
||||
BIND9_ZONE_TASKS_HINTS to 1000 before starting named). [RT #25084]
|
||||
|
||||
Known issues in this release
|
||||
|
||||
* None
|
||||
|
||||
Thank You
|
||||
|
||||
Thank you to everyone who assisted us in making this release possible.
|
||||
If you would like to contribute to ISC to assist us in continuing to
|
||||
make quality open source software, please visit our donations page at
|
||||
http://www.isc.org/supportisc.
|
||||
+29
-2
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: check-tool.c,v 1.39 2009/09/01 00:22:24 jinmei Exp $ */
|
||||
/* $Id: check-tool.c,v 1.39.104.2 2010/09/07 23:46:37 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -23,6 +23,10 @@
|
||||
|
||||
#include <stdio.h>
|
||||
|
||||
#ifdef _WIN32
|
||||
#include <Winsock2.h>
|
||||
#endif
|
||||
|
||||
#include "check-tool.h"
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/log.h>
|
||||
@@ -661,3 +665,26 @@ dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
#ifdef _WIN32
|
||||
void
|
||||
InitSockets(void) {
|
||||
WORD wVersionRequested;
|
||||
WSADATA wsaData;
|
||||
int err;
|
||||
|
||||
wVersionRequested = MAKEWORD(2, 0);
|
||||
|
||||
err = WSAStartup( wVersionRequested, &wsaData );
|
||||
if (err != 0) {
|
||||
fprintf(stderr, "WSAStartup() failed: %d\n", err);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
DestroySockets(void) {
|
||||
WSACleanup();
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: check-tool.h,v 1.14 2007/06/18 23:47:17 tbox Exp $ */
|
||||
/* $Id: check-tool.h,v 1.14.560.2 2010/09/07 23:46:37 tbox Exp $ */
|
||||
|
||||
#ifndef CHECK_TOOL_H
|
||||
#define CHECK_TOOL_H
|
||||
@@ -43,6 +43,11 @@ isc_result_t
|
||||
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
|
||||
dns_masterformat_t fileformat, const dns_master_style_t *style);
|
||||
|
||||
#ifdef _WIN32
|
||||
void InitSockets(void);
|
||||
void DestroySockets(void);
|
||||
#endif
|
||||
|
||||
extern int debug;
|
||||
extern isc_boolean_t nomerge;
|
||||
extern isc_boolean_t docheckmx;
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named-checkconf.c,v 1.51 2009/12/04 21:09:32 marka Exp $ */
|
||||
/* $Id: named-checkconf.c,v 1.51.4.5 2011/03/12 04:58:23 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -64,7 +64,7 @@ usage(void) ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
static void
|
||||
usage(void) {
|
||||
fprintf(stderr, "usage: %s [-h] [-j] [-v] [-z] [-t directory] "
|
||||
fprintf(stderr, "usage: %s [-h] [-j] [-p] [-v] [-z] [-t directory] "
|
||||
"[named.conf]\n", program);
|
||||
exit(1);
|
||||
}
|
||||
@@ -190,7 +190,7 @@ configure_zone(const char *vclass, const char *view,
|
||||
if (obj != NULL)
|
||||
maps[i++] = obj;
|
||||
}
|
||||
maps[i++] = NULL;
|
||||
maps[i] = NULL;
|
||||
|
||||
cfg_map_get(zoptions, "type", &typeobj);
|
||||
if (typeobj == NULL)
|
||||
@@ -488,6 +488,10 @@ main(int argc, char **argv) {
|
||||
if (conffile == NULL || conffile[0] == '\0')
|
||||
conffile = NAMED_CONFFILE;
|
||||
|
||||
#ifdef _WIN32
|
||||
InitSockets();
|
||||
#endif
|
||||
|
||||
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||
|
||||
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
|
||||
@@ -531,5 +535,9 @@ main(int argc, char **argv) {
|
||||
|
||||
isc_mem_destroy(&mctx);
|
||||
|
||||
#ifdef _WIN32
|
||||
DestroySockets();
|
||||
#endif
|
||||
|
||||
return (exit_status);
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named-checkzone.c,v 1.59 2009/12/04 22:06:37 tbox Exp $ */
|
||||
/* $Id: named-checkzone.c,v 1.59.4.2 2010/09/07 23:46:37 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -442,6 +442,10 @@ main(int argc, char **argv) {
|
||||
if (isc_commandline_index + 2 != argc)
|
||||
usage();
|
||||
|
||||
#ifdef _WIN32
|
||||
InitSockets();
|
||||
#endif
|
||||
|
||||
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
|
||||
if (!quiet)
|
||||
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx)
|
||||
@@ -476,5 +480,8 @@ main(int argc, char **argv) {
|
||||
isc_hash_destroy();
|
||||
isc_entropy_detach(&ectx);
|
||||
isc_mem_destroy(&mctx);
|
||||
#ifdef _WIN32
|
||||
DestroySockets();
|
||||
#endif
|
||||
return ((result == ISC_R_SUCCESS) ? 0 : 1);
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: ddns-confgen.c,v 1.9 2009/09/29 15:06:05 fdupont Exp $ */
|
||||
/* $Id: ddns-confgen.c,v 1.9.66.2 2011/03/12 04:58:23 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -160,6 +160,7 @@ main(int argc, char **argv) {
|
||||
|
||||
argc -= isc_commandline_index;
|
||||
argv += isc_commandline_index;
|
||||
POST(argv);
|
||||
|
||||
if (self_domain != NULL && zone != NULL)
|
||||
usage(1); /* -s and -z cannot coexist */
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: rndc-confgen.c,v 1.5 2009/09/29 15:06:05 fdupont Exp $ */
|
||||
/* $Id: rndc-confgen.c,v 1.5.66.2 2011/03/12 04:58:23 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -200,6 +200,7 @@ main(int argc, char **argv) {
|
||||
|
||||
argc -= isc_commandline_index;
|
||||
argv += isc_commandline_index;
|
||||
POST(argv);
|
||||
|
||||
if (argc > 0)
|
||||
usage(1);
|
||||
|
||||
+9
-36
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.c,v 1.233 2009/10/03 18:03:53 each Exp $ */
|
||||
/* $Id: dig.c,v 1.233.62.6 2011/03/11 07:11:51 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -44,8 +44,6 @@
|
||||
#include <dns/result.h>
|
||||
#include <dns/tsig.h>
|
||||
|
||||
#include <bind9/getaddresses.h>
|
||||
|
||||
#include <dig/dig.h>
|
||||
|
||||
#define ADD_STRING(b, s) { \
|
||||
@@ -309,6 +307,8 @@ say_message(dns_rdata_t *rdata, dig_query_t *query, isc_buffer_t *buf) {
|
||||
ADD_STRING(buf, " ");
|
||||
}
|
||||
result = dns_rdata_totext(rdata, NULL, buf);
|
||||
if (result == ISC_R_NOSPACE)
|
||||
return (result);
|
||||
check_result(result, "dns_rdata_totext");
|
||||
if (query->lookup->identify) {
|
||||
TIME_NOW(&now);
|
||||
@@ -331,10 +331,8 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
|
||||
{
|
||||
dns_name_t *name;
|
||||
dns_rdataset_t *rdataset;
|
||||
isc_buffer_t target;
|
||||
isc_result_t result, loopresult;
|
||||
dns_name_t empty_name;
|
||||
char t[4096];
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
|
||||
UNUSED(flags);
|
||||
@@ -350,8 +348,6 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
|
||||
name = NULL;
|
||||
dns_message_currentname(msg, DNS_SECTION_ANSWER, &name);
|
||||
|
||||
isc_buffer_init(&target, t, sizeof(t));
|
||||
|
||||
for (rdataset = ISC_LIST_HEAD(name->list);
|
||||
rdataset != NULL;
|
||||
rdataset = ISC_LIST_NEXT(rdataset, link)) {
|
||||
@@ -360,6 +356,8 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
|
||||
dns_rdataset_current(rdataset, &rdata);
|
||||
result = say_message(&rdata, query,
|
||||
buf);
|
||||
if (result == ISC_R_NOSPACE)
|
||||
return (result);
|
||||
check_result(result, "say_message");
|
||||
loopresult = dns_rdataset_next(rdataset);
|
||||
dns_rdata_reset(&rdata);
|
||||
@@ -474,8 +472,6 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
if (!query->lookup->comments)
|
||||
flags |= DNS_MESSAGETEXTFLAG_NOCOMMENTS;
|
||||
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
result = isc_buffer_allocate(mctx, &buf, len);
|
||||
check_result(result, "isc_buffer_allocate");
|
||||
|
||||
@@ -508,6 +504,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
printf(" ad");
|
||||
if ((msg->flags & DNS_MESSAGEFLAG_CD) != 0)
|
||||
printf(" cd");
|
||||
if ((msg->flags & 0x0040U) != 0)
|
||||
printf("; MBZ: 0x4");
|
||||
|
||||
printf("; QUERY: %u, ANSWER: %u, "
|
||||
"AUTHORITY: %u, ADDITIONAL: %u\n",
|
||||
@@ -1426,30 +1424,6 @@ preparse_args(int argc, char **argv) {
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
getaddresses(dig_lookup_t *lookup, const char *host) {
|
||||
isc_result_t result;
|
||||
isc_sockaddr_t sockaddrs[DIG_MAX_ADDRESSES];
|
||||
isc_netaddr_t netaddr;
|
||||
int count, i;
|
||||
dig_server_t *srv;
|
||||
char tmp[ISC_NETADDR_FORMATSIZE];
|
||||
|
||||
result = bind9_getaddresses(host, 0, sockaddrs,
|
||||
DIG_MAX_ADDRESSES, &count);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("couldn't get address for '%s': %s",
|
||||
host, isc_result_totext(result));
|
||||
|
||||
for (i = 0; i < count; i++) {
|
||||
isc_netaddr_fromsockaddr(&netaddr, &sockaddrs[i]);
|
||||
isc_netaddr_format(&netaddr, tmp, sizeof(tmp));
|
||||
srv = make_server(tmp, host);
|
||||
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
|
||||
}
|
||||
addresscount = count;
|
||||
}
|
||||
|
||||
static void
|
||||
parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
int argc, char **argv) {
|
||||
@@ -1544,7 +1518,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
if (strncmp(rv[0], "%", 1) == 0)
|
||||
break;
|
||||
if (strncmp(rv[0], "@", 1) == 0) {
|
||||
getaddresses(lookup, &rv[0][1]);
|
||||
addresscount = getaddresses(lookup, &rv[0][1]);
|
||||
} else if (rv[0][0] == '+') {
|
||||
plus_option(&rv[0][1], is_batchfile,
|
||||
lookup);
|
||||
@@ -1581,7 +1555,6 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
|
||||
(isc_textregion_t *)&tr);
|
||||
if (result == ISC_R_SUCCESS &&
|
||||
rdtype == dns_rdatatype_ixfr) {
|
||||
result = DNS_R_UNKNOWN;
|
||||
fprintf(stderr, ";; Warning, "
|
||||
"ixfr requires a "
|
||||
"serial number\n");
|
||||
|
||||
+82
-42
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dighost.c,v 1.328 2009/11/10 17:27:40 each Exp $ */
|
||||
/* $Id: dighost.c,v 1.328.22.10 2011/03/11 07:11:51 marka Exp $ */
|
||||
|
||||
/*! \file
|
||||
* \note
|
||||
@@ -252,7 +252,7 @@ isc_result_t opentmpkey(isc_mem_t *mctx, const char *file,
|
||||
char **tempp, FILE **fp);
|
||||
isc_result_t removetmpkey(isc_mem_t *mctx, const char *file);
|
||||
void clean_trustedkey(void);
|
||||
void insert_trustedkey(dst_key_t * key);
|
||||
void insert_trustedkey(dst_key_t **key);
|
||||
#if DIG_SIGCHASE_BU
|
||||
isc_result_t getneededrr(dns_message_t *msg);
|
||||
void sigchase_bottom_up(dns_message_t *msg);
|
||||
@@ -566,10 +566,8 @@ make_server(const char *servname, const char *userarg) {
|
||||
if (srv == NULL)
|
||||
fatal("memory allocation failure in %s:%d",
|
||||
__FILE__, __LINE__);
|
||||
strncpy(srv->servername, servname, MXNAME);
|
||||
strncpy(srv->userarg, userarg, MXNAME);
|
||||
srv->servername[MXNAME-1] = 0;
|
||||
srv->userarg[MXNAME-1] = 0;
|
||||
strlcpy(srv->servername, servname, MXNAME);
|
||||
strlcpy(srv->userarg, userarg, MXNAME);
|
||||
ISC_LINK_INIT(srv, link);
|
||||
return (srv);
|
||||
}
|
||||
@@ -1142,7 +1140,6 @@ setup_file_key(void) {
|
||||
keynametext, isc_result_totext(result));
|
||||
goto failure;
|
||||
}
|
||||
dstkey = NULL;
|
||||
failure:
|
||||
if (dstkey != NULL)
|
||||
dst_key_free(&dstkey);
|
||||
@@ -1161,13 +1158,22 @@ make_searchlist_entry(char *domain) {
|
||||
return (search);
|
||||
}
|
||||
|
||||
static void
|
||||
clear_searchlist(void) {
|
||||
dig_searchlist_t *search;
|
||||
while ((search = ISC_LIST_HEAD(search_list)) != NULL) {
|
||||
ISC_LIST_UNLINK(search_list, search, link);
|
||||
isc_mem_free(mctx, search);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
create_search_list(lwres_conf_t *confdata) {
|
||||
int i;
|
||||
dig_searchlist_t *search;
|
||||
|
||||
debug("create_search_list()");
|
||||
ISC_LIST_INIT(search_list);
|
||||
clear_searchlist();
|
||||
|
||||
for (i = 0; i < confdata->searchnxt; i++) {
|
||||
search = make_searchlist_entry(confdata->search[i]);
|
||||
@@ -1210,7 +1216,7 @@ setup_system(void) {
|
||||
else { /* No search list. Use the domain name if any */
|
||||
if (lwconf->domainname != NULL) {
|
||||
domain = make_searchlist_entry(lwconf->domainname);
|
||||
ISC_LIST_INITANDAPPEND(search_list, domain, link);
|
||||
ISC_LIST_APPEND(search_list, domain, link);
|
||||
domain = NULL;
|
||||
}
|
||||
}
|
||||
@@ -1265,15 +1271,6 @@ setup_system(void) {
|
||||
|
||||
}
|
||||
|
||||
static void
|
||||
clear_searchlist(void) {
|
||||
dig_searchlist_t *search;
|
||||
while ((search = ISC_LIST_HEAD(search_list)) != NULL) {
|
||||
ISC_LIST_UNLINK(search_list, search, link);
|
||||
isc_mem_free(mctx, search);
|
||||
}
|
||||
}
|
||||
|
||||
/*%
|
||||
* Override the search list derived from resolv.conf by 'domain'.
|
||||
*/
|
||||
@@ -1386,14 +1383,15 @@ add_opt(dns_message_t *msg, isc_uint16_t udpsize, isc_uint16_t edns,
|
||||
if (dnssec)
|
||||
rdatalist->ttl |= DNS_MESSAGEEXTFLAG_DO;
|
||||
if (nsid) {
|
||||
unsigned char data[4];
|
||||
isc_buffer_t buf;
|
||||
isc_buffer_t *b = NULL;
|
||||
|
||||
isc_buffer_init(&buf, data, sizeof(data));
|
||||
isc_buffer_putuint16(&buf, DNS_OPT_NSID);
|
||||
isc_buffer_putuint16(&buf, 0);
|
||||
rdata->data = data;
|
||||
rdata->length = sizeof(data);
|
||||
result = isc_buffer_allocate(mctx, &b, 4);
|
||||
check_result(result, "isc_buffer_allocate");
|
||||
isc_buffer_putuint16(b, DNS_OPT_NSID);
|
||||
isc_buffer_putuint16(b, 0);
|
||||
rdata->data = isc_buffer_base(b);
|
||||
rdata->length = isc_buffer_usedlength(b);
|
||||
dns_message_takebuffer(msg, &b);
|
||||
} else {
|
||||
rdata->data = NULL;
|
||||
rdata->length = 0;
|
||||
@@ -1767,8 +1765,7 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
dns_rdata_freestruct(&ns);
|
||||
|
||||
/* Initialize lookup if we've not yet */
|
||||
debug("found NS %d %s", numLookups, namestr);
|
||||
numLookups++;
|
||||
debug("found NS %s", namestr);
|
||||
if (!success) {
|
||||
success = ISC_TRUE;
|
||||
lookup_counter++;
|
||||
@@ -1790,9 +1787,8 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
domain = dns_fixedname_name(&lookup->fdomain);
|
||||
dns_name_copy(name, domain, NULL);
|
||||
}
|
||||
srv = make_server(namestr, namestr);
|
||||
debug("adding server %s", srv->servername);
|
||||
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
|
||||
debug("adding server %s", namestr);
|
||||
numLookups += getaddresses(lookup, namestr);
|
||||
dns_rdata_reset(&rdata);
|
||||
}
|
||||
}
|
||||
@@ -1808,17 +1804,25 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
|
||||
if (numLookups > 1) {
|
||||
isc_uint32_t i, j;
|
||||
dig_serverlist_t my_server_list;
|
||||
dig_server_t *next;
|
||||
|
||||
ISC_LIST_INIT(my_server_list);
|
||||
|
||||
for (i = numLookups; i > 0; i--) {
|
||||
i = numLookups;
|
||||
for (srv = ISC_LIST_HEAD(lookup->my_server_list);
|
||||
srv != NULL;
|
||||
srv = ISC_LIST_HEAD(lookup->my_server_list)) {
|
||||
INSIST(i > 0);
|
||||
isc_random_get(&j);
|
||||
j %= i;
|
||||
srv = ISC_LIST_HEAD(lookup->my_server_list);
|
||||
while (j-- > 0)
|
||||
srv = ISC_LIST_NEXT(srv, link);
|
||||
next = ISC_LIST_NEXT(srv, link);
|
||||
while (j-- > 0 && next != NULL) {
|
||||
srv = next;
|
||||
next = ISC_LIST_NEXT(srv, link);
|
||||
}
|
||||
ISC_LIST_DEQUEUE(lookup->my_server_list, srv, link);
|
||||
ISC_LIST_APPEND(my_server_list, srv, link);
|
||||
i--;
|
||||
}
|
||||
ISC_LIST_APPENDLIST(lookup->my_server_list,
|
||||
my_server_list, link);
|
||||
@@ -2401,6 +2405,15 @@ force_timeout(dig_lookup_t *l, dig_query_t *query) {
|
||||
isc_result_totext(ISC_R_NOMEMORY));
|
||||
}
|
||||
isc_task_send(global_task, &event);
|
||||
|
||||
/*
|
||||
* The timer may have expired if, for example, get_address() takes
|
||||
* long time and the timer was running on a different thread.
|
||||
* We need to cancel the possible timeout event not to confuse
|
||||
* ourselves due to the duplicate events.
|
||||
*/
|
||||
if (l->timer != NULL)
|
||||
isc_timer_detach(&l->timer);
|
||||
}
|
||||
|
||||
|
||||
@@ -2424,7 +2437,7 @@ send_tcp_connect(dig_query_t *query) {
|
||||
query->waiting_connect = ISC_TRUE;
|
||||
query->lookup->current_query = query;
|
||||
result = get_address(query->servname, port, &query->sockaddr);
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
/*
|
||||
* This servname doesn't have an address. Try the next server
|
||||
* by triggering an immediate 'timeout' (we lie, but the effect
|
||||
@@ -2506,7 +2519,7 @@ send_udp(dig_query_t *query) {
|
||||
/* XXX Check the sense of this, need assertion? */
|
||||
query->waiting_connect = ISC_FALSE;
|
||||
result = get_address(query->servname, port, &query->sockaddr);
|
||||
if (result == ISC_R_NOTFOUND) {
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
/* This servname doesn't have an address. */
|
||||
force_timeout(l, query);
|
||||
return;
|
||||
@@ -3532,6 +3545,31 @@ get_address(char *host, in_port_t port, isc_sockaddr_t *sockaddr) {
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
int
|
||||
getaddresses(dig_lookup_t *lookup, const char *host) {
|
||||
isc_result_t result;
|
||||
isc_sockaddr_t sockaddrs[DIG_MAX_ADDRESSES];
|
||||
isc_netaddr_t netaddr;
|
||||
int count, i;
|
||||
dig_server_t *srv;
|
||||
char tmp[ISC_NETADDR_FORMATSIZE];
|
||||
|
||||
result = bind9_getaddresses(host, 0, sockaddrs,
|
||||
DIG_MAX_ADDRESSES, &count);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("couldn't get address for '%s': %s",
|
||||
host, isc_result_totext(result));
|
||||
|
||||
for (i = 0; i < count; i++) {
|
||||
isc_netaddr_fromsockaddr(&netaddr, &sockaddrs[i]);
|
||||
isc_netaddr_format(&netaddr, tmp, sizeof(tmp));
|
||||
srv = make_server(tmp, host);
|
||||
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
|
||||
}
|
||||
|
||||
return count;
|
||||
}
|
||||
|
||||
/*%
|
||||
* Initiate either a TCP or UDP lookup
|
||||
*/
|
||||
@@ -4043,14 +4081,15 @@ sigchase_scanname(dns_rdatatype_t type, dns_rdatatype_t covers,
|
||||
}
|
||||
|
||||
void
|
||||
insert_trustedkey(dst_key_t * key)
|
||||
insert_trustedkey(dst_key_t **keyp)
|
||||
{
|
||||
if (key == NULL)
|
||||
if (*keyp == NULL)
|
||||
return;
|
||||
if (tk_list.nb_tk >= MAX_TRUSTED_KEY)
|
||||
return;
|
||||
|
||||
tk_list.key[tk_list.nb_tk++] = key;
|
||||
tk_list.key[tk_list.nb_tk++] = *keyp;
|
||||
*keyp = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -4224,11 +4263,12 @@ get_trusted_key(isc_mem_t *mctx)
|
||||
fclose(fp);
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
insert_trustedkey(key);
|
||||
#if 0
|
||||
dst_key_tofile(key, DST_TYPE_PUBLIC,"/tmp");
|
||||
#endif
|
||||
key = NULL;
|
||||
insert_trustedkey(&key);
|
||||
if (key != NULL)
|
||||
dst_key_free(&key);
|
||||
}
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
+9
-6
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: host.c,v 1.120 2009/09/29 15:06:05 fdupont Exp $ */
|
||||
/* $Id: host.c,v 1.120.66.5 2011/03/11 07:11:51 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -521,6 +521,7 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
|
||||
if ((msg->flags & DNS_MESSAGEFLAG_CD) != 0) {
|
||||
printf("%scd", did_flag ? " " : "");
|
||||
did_flag = ISC_TRUE;
|
||||
POST(did_flag);
|
||||
}
|
||||
printf("; QUERY: %u, ANSWER: %u, "
|
||||
"AUTHORITY: %u, ADDITIONAL: %u\n",
|
||||
@@ -628,7 +629,9 @@ pre_parse_args(int argc, char **argv) {
|
||||
case 'v': break;
|
||||
case 'w': break;
|
||||
case 'C': break;
|
||||
case 'D': break;
|
||||
case 'D':
|
||||
debugging = ISC_TRUE;
|
||||
break;
|
||||
case 'N': break;
|
||||
case 'R': break;
|
||||
case 'T': break;
|
||||
@@ -795,7 +798,7 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
||||
ndots = atoi(isc_commandline_argument);
|
||||
break;
|
||||
case 'D':
|
||||
debugging = ISC_TRUE;
|
||||
/* Handled by pre_parse_args(). */
|
||||
break;
|
||||
case '4':
|
||||
if (have_ipv4) {
|
||||
@@ -822,8 +825,8 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
|
||||
if (isc_commandline_index >= argc)
|
||||
show_usage();
|
||||
|
||||
strncpy(hostname, argv[isc_commandline_index], sizeof(hostname));
|
||||
hostname[sizeof(hostname)-1]=0;
|
||||
strlcpy(hostname, argv[isc_commandline_index], sizeof(hostname));
|
||||
|
||||
if (argc > isc_commandline_index + 1) {
|
||||
set_nameserver(argv[isc_commandline_index+1]);
|
||||
debug("server is %s", argv[isc_commandline_index+1]);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dig.h,v 1.111 2009/09/29 15:06:06 fdupont Exp $ */
|
||||
/* $Id: dig.h,v 1.111.66.2 2011/02/28 01:19:26 tbox Exp $ */
|
||||
|
||||
#ifndef DIG_H
|
||||
#define DIG_H
|
||||
@@ -288,6 +288,9 @@ extern int idnoptions;
|
||||
isc_result_t
|
||||
get_address(char *host, in_port_t port, isc_sockaddr_t *sockaddr);
|
||||
|
||||
int
|
||||
getaddresses(dig_lookup_t *lookup, const char *host);
|
||||
|
||||
isc_result_t
|
||||
get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
|
||||
isc_boolean_t strict);
|
||||
|
||||
+10
-4
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: nslookup.1,v 1.15 2009/07/11 01:12:45 tbox Exp $
|
||||
.\" $Id: nslookup.1,v 1.15.126.1 2010/02/23 02:09:20 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -54,7 +54,13 @@ when the first argument is a hyphen (\-) and the second argument is the host nam
|
||||
Non\-interactive mode is used when the name or Internet address of the host to be looked up is given as the first argument. The optional second argument specifies the host name or address of a name server.
|
||||
.PP
|
||||
Options can also be specified on the command line if they precede the arguments and are prefixed with a hyphen. For example, to change the default query type to host information, and the initial timeout to 10 seconds, type:
|
||||
.sp .RS 4 .nf nslookup \-query=hinfo \-timeout=10 .fi .RE
|
||||
.sp
|
||||
.RS 4
|
||||
.nf
|
||||
nslookup \-query=hinfo \-timeout=10
|
||||
.fi
|
||||
.RE
|
||||
.sp
|
||||
.SH "INTERACTIVE COMMANDS"
|
||||
.PP
|
||||
\fBhost\fR [server]
|
||||
@@ -248,5 +254,5 @@ Try the next nameserver if a nameserver responds with SERVFAIL or a referral (no
|
||||
.PP
|
||||
Andrew Cherenson
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004\-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
+14
-20
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: nslookup.c,v 1.124 2009/10/20 01:04:03 marka Exp $ */
|
||||
/* $Id: nslookup.c,v 1.124.40.2 2011/02/21 23:46:37 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -535,12 +535,6 @@ testclass(char *typetext) {
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
safecpy(char *dest, char *src, int size) {
|
||||
strncpy(dest, src, size);
|
||||
dest[size-1] = 0;
|
||||
}
|
||||
|
||||
static void
|
||||
set_port(const char *value) {
|
||||
isc_uint32_t n;
|
||||
@@ -571,34 +565,34 @@ setoption(char *opt) {
|
||||
show_settings(ISC_TRUE, ISC_FALSE);
|
||||
} else if (strncasecmp(opt, "class=", 6) == 0) {
|
||||
if (testclass(&opt[6]))
|
||||
safecpy(defclass, &opt[6], sizeof(defclass));
|
||||
strlcpy(defclass, &opt[6], sizeof(defclass));
|
||||
} else if (strncasecmp(opt, "cl=", 3) == 0) {
|
||||
if (testclass(&opt[3]))
|
||||
safecpy(defclass, &opt[3], sizeof(defclass));
|
||||
strlcpy(defclass, &opt[3], sizeof(defclass));
|
||||
} else if (strncasecmp(opt, "type=", 5) == 0) {
|
||||
if (testtype(&opt[5]))
|
||||
safecpy(deftype, &opt[5], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[5], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "ty=", 3) == 0) {
|
||||
if (testtype(&opt[3]))
|
||||
safecpy(deftype, &opt[3], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[3], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "querytype=", 10) == 0) {
|
||||
if (testtype(&opt[10]))
|
||||
safecpy(deftype, &opt[10], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[10], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "query=", 6) == 0) {
|
||||
if (testtype(&opt[6]))
|
||||
safecpy(deftype, &opt[6], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[6], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "qu=", 3) == 0) {
|
||||
if (testtype(&opt[3]))
|
||||
safecpy(deftype, &opt[3], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[3], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "q=", 2) == 0) {
|
||||
if (testtype(&opt[2]))
|
||||
safecpy(deftype, &opt[2], sizeof(deftype));
|
||||
strlcpy(deftype, &opt[2], sizeof(deftype));
|
||||
} else if (strncasecmp(opt, "domain=", 7) == 0) {
|
||||
safecpy(domainopt, &opt[7], sizeof(domainopt));
|
||||
strlcpy(domainopt, &opt[7], sizeof(domainopt));
|
||||
set_search_domain(domainopt);
|
||||
usesearch = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "do=", 3) == 0) {
|
||||
safecpy(domainopt, &opt[3], sizeof(domainopt));
|
||||
strlcpy(domainopt, &opt[3], sizeof(domainopt));
|
||||
set_search_domain(domainopt);
|
||||
usesearch = ISC_TRUE;
|
||||
} else if (strncasecmp(opt, "port=", 5) == 0) {
|
||||
@@ -677,11 +671,11 @@ addlookup(char *opt) {
|
||||
lookup = make_empty_lookup();
|
||||
if (get_reverse(store, sizeof(store), opt, lookup->ip6_int, ISC_TRUE)
|
||||
== ISC_R_SUCCESS) {
|
||||
safecpy(lookup->textname, store, sizeof(lookup->textname));
|
||||
strlcpy(lookup->textname, store, sizeof(lookup->textname));
|
||||
lookup->rdtype = dns_rdatatype_ptr;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
} else {
|
||||
safecpy(lookup->textname, opt, sizeof(lookup->textname));
|
||||
strlcpy(lookup->textname, opt, sizeof(lookup->textname));
|
||||
lookup->rdtype = rdtype;
|
||||
lookup->rdtypeset = ISC_TRUE;
|
||||
}
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: nslookup.docbook,v 1.16 2007/06/18 23:47:17 tbox Exp $ -->
|
||||
<!-- $Id: nslookup.docbook,v 1.16.560.2 2010/02/22 23:48:29 tbox Exp $ -->
|
||||
<!--
|
||||
- Copyright (c) 1985, 1989
|
||||
- The Regents of the University of California. All rights reserved.
|
||||
@@ -73,6 +73,7 @@
|
||||
<year>2005</year>
|
||||
<year>2006</year>
|
||||
<year>2007</year>
|
||||
<year>2010</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -129,11 +130,11 @@
|
||||
arguments and are prefixed with a hyphen. For example, to
|
||||
change the default query type to host information, and the initial
|
||||
timeout to 10 seconds, type:
|
||||
<informalexample>
|
||||
<!-- <informalexample> produces bad nroff. -->
|
||||
<programlisting>
|
||||
nslookup -query=hinfo -timeout=10
|
||||
</programlisting>
|
||||
</informalexample>
|
||||
<!-- </informalexample> -->
|
||||
</para>
|
||||
|
||||
</refsect1>
|
||||
|
||||
+13
-11
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: nslookup.html,v 1.22 2009/07/11 01:12:45 tbox Exp $ -->
|
||||
<!-- $Id: nslookup.html,v 1.22.126.1 2010/02/23 02:09:20 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -31,7 +31,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">nslookup</code> [<code class="option">-option</code>] [name | -] [server]</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543355"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543358"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">Nslookup</strong></span>
|
||||
is a program to query Internet domain name servers. <span><strong class="command">Nslookup</strong></span>
|
||||
has two modes: interactive and non-interactive. Interactive mode allows
|
||||
@@ -43,7 +43,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543371"></a><h2>ARGUMENTS</h2>
|
||||
<a name="id2543374"></a><h2>ARGUMENTS</h2>
|
||||
<p>
|
||||
Interactive mode is entered in the following cases:
|
||||
</p>
|
||||
@@ -68,15 +68,17 @@
|
||||
arguments and are prefixed with a hyphen. For example, to
|
||||
change the default query type to host information, and the initial
|
||||
timeout to 10 seconds, type:
|
||||
</p>
|
||||
<div class="informalexample"><pre class="programlisting">
|
||||
|
||||
</p>
|
||||
<pre class="programlisting">
|
||||
nslookup -query=hinfo -timeout=10
|
||||
</pre></div>
|
||||
</pre>
|
||||
<p>
|
||||
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543413"></a><h2>INTERACTIVE COMMANDS</h2>
|
||||
<a name="id2543418"></a><h2>INTERACTIVE COMMANDS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term"><code class="constant">host</code> [<span class="optional">server</span>]</span></dt>
|
||||
<dd>
|
||||
@@ -286,19 +288,19 @@ nslookup -query=hinfo -timeout=10
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2546279"></a><h2>FILES</h2>
|
||||
<a name="id2546284"></a><h2>FILES</h2>
|
||||
<p><code class="filename">/etc/resolv.conf</code>
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2546291"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2546296"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dig</span>(1)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">host</span>(1)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2546325"></a><h2>Author</h2>
|
||||
<a name="id2546330"></a><h2>Author</h2>
|
||||
<p>
|
||||
Andrew Cherenson
|
||||
</p>
|
||||
|
||||
@@ -1,18 +1,18 @@
|
||||
.\" Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-dsfromkey.8,v 1.11 2009/08/27 01:14:39 tbox Exp $
|
||||
.\" $Id: dnssec-dsfromkey.8,v 1.11.106.1 2010/05/18 04:04:36 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
|
||||
@@ -1,20 +1,19 @@
|
||||
<!--
|
||||
- Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-dsfromkey.html,v 1.11 2009/08/27 01:14:39 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-dsfromkey.html,v 1.11.106.1 2010/05/18 04:04:36 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-keyfromlabel.8,v 1.16.24.1 2010/01/20 02:08:51 tbox Exp $
|
||||
.\" $Id: dnssec-keyfromlabel.8,v 1.16.24.2 2011/02/04 02:10:41 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -162,7 +162,7 @@ Sets the date on which the key is to be activated. After that date, the key will
|
||||
Sets the date on which the key is to be revoked. After that date, the key will be flagged as revoked. It will be included in the zone and will be used to sign it.
|
||||
.RE
|
||||
.PP
|
||||
\-U \fIdate/offset\fR
|
||||
\-I \fIdate/offset\fR
|
||||
.RS 4
|
||||
Sets the date on which the key is to be retired. After that date, the key will still be included in the zone, but it will not be used to sign it.
|
||||
.RE
|
||||
@@ -215,5 +215,5 @@ RFC 4034.
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2008\-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2008\-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2007-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2007-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-keyfromlabel.c,v 1.29.8.2 2010/01/19 23:48:12 tbox Exp $ */
|
||||
/* $Id: dnssec-keyfromlabel.c,v 1.29.8.4 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -517,6 +517,9 @@ main(int argc, char **argv) {
|
||||
{
|
||||
isc_buffer_clear(&buf);
|
||||
ret = dst_key_buildfilename(key, 0, directory, &buf);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("dst_key_buildfilename returned: %s\n",
|
||||
isc_result_totext(ret));
|
||||
if (exact)
|
||||
fatal("%s: %s already exists\n", program, filename);
|
||||
|
||||
@@ -541,6 +544,9 @@ main(int argc, char **argv) {
|
||||
|
||||
isc_buffer_clear(&buf);
|
||||
ret = dst_key_buildfilename(key, 0, NULL, &buf);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("dst_key_buildfilename returned: %s\n",
|
||||
isc_result_totext(ret));
|
||||
printf("%s\n", filename);
|
||||
dst_key_free(&key);
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-keyfromlabel.docbook,v 1.15.24.2 2010/01/19 23:48:12 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-keyfromlabel.docbook,v 1.15.24.4 2011/02/03 12:17:22 tbox Exp $ -->
|
||||
<refentry id="man.dnssec-keyfromlabel">
|
||||
<refentryinfo>
|
||||
<date>February 8, 2008</date>
|
||||
@@ -39,6 +39,7 @@
|
||||
<year>2008</year>
|
||||
<year>2009</year>
|
||||
<year>2010</year>
|
||||
<year>2011</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -333,7 +334,7 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-U <replaceable class="parameter">date/offset</replaceable></term>
|
||||
<term>-I <replaceable class="parameter">date/offset</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the date on which the key is to be retired. After that
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dnssec-keyfromlabel.html,v 1.15.24.1 2010/01/20 02:08:51 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-keyfromlabel.html,v 1.15.24.2 2011/02/04 02:10:41 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -31,7 +31,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-y</code>] {name}</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543491"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543494"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
|
||||
gets keys with the given label from a crypto hardware and builds
|
||||
key files for DNSSEC (Secure DNS), as defined in RFC 2535
|
||||
@@ -44,7 +44,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543509"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543512"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||
<dd>
|
||||
@@ -163,7 +163,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543873"></a><h2>TIMING OPTIONS</h2>
|
||||
<a name="id2543876"></a><h2>TIMING OPTIONS</h2>
|
||||
<p>
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
|
||||
If the argument begins with a '+' or '-', it is interpreted as
|
||||
@@ -195,7 +195,7 @@
|
||||
date, the key will be flagged as revoked. It will be included
|
||||
in the zone and will be used to sign it.
|
||||
</p></dd>
|
||||
<dt><span class="term">-U <em class="replaceable"><code>date/offset</code></em></span></dt>
|
||||
<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
|
||||
<dd><p>
|
||||
Sets the date on which the key is to be retired. After that
|
||||
date, the key will still be included in the zone, but it
|
||||
@@ -210,7 +210,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544039"></a><h2>GENERATED KEY FILES</h2>
|
||||
<a name="id2544042"></a><h2>GENERATED KEY FILES</h2>
|
||||
<p>
|
||||
When <span><strong class="command">dnssec-keyfromlabel</strong></span> completes
|
||||
successfully,
|
||||
@@ -249,7 +249,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544112"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2544115"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
@@ -257,7 +257,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544145"></a><h2>AUTHOR</h2>
|
||||
<a name="id2544148"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-keygen.8,v 1.53 2009/11/03 21:58:30 tbox Exp $
|
||||
.\" $Id: dnssec-keygen.8,v 1.53.24.1 2010/08/17 00:08:22 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -33,7 +33,7 @@
|
||||
dnssec\-keygen \- DNSSEC key generation tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP 14
|
||||
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
|
||||
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR
|
||||
@@ -164,6 +164,11 @@ specifies the name of a character device or file containing random data to be us
|
||||
indicates that keyboard input should be used.
|
||||
.RE
|
||||
.PP
|
||||
\-S \fIkey\fR
|
||||
.RS 4
|
||||
Create a new key which is an explicit successor to an existing key. The name, algorithm, size, and type of the key will be set to match the existing key. The activation date of the new key will be set to the inactivation date of the existing one. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days.
|
||||
.RE
|
||||
.PP
|
||||
\-s \fIstrength\fR
|
||||
.RS 4
|
||||
Specifies the strength value of the key. The strength is a number between 0 and 15, and currently has no defined purpose in DNSSEC.
|
||||
@@ -216,6 +221,15 @@ Sets the date on which the key is to be retired. After that date, the key will s
|
||||
.RS 4
|
||||
Sets the date on which the key is to be deleted. After that date, the key will no longer be included in the zone. (It may remain in the key repository, however.)
|
||||
.RE
|
||||
.PP
|
||||
\-i \fIinterval\fR
|
||||
.RS 4
|
||||
Sets the prepublication interval for a key. If set, then the publication and activation dates must be separated by at least this much time. If the activation date is specified but the publication date isn't, then the publication date will default to this much time before the activation date; conversely, if the publication date is specified but activation date isn't, then activation will be set to this much time after publication.
|
||||
.sp
|
||||
If the key is being created as an explicit successor to another key, then the default prepublication interval is 30 days; otherwise it is zero.
|
||||
.sp
|
||||
As with date offsets, if the argument is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the interval is measured in years, months, weeks, days, hours, or minutes, respectively. Without a suffix, the interval is measured in seconds.
|
||||
.RE
|
||||
.SH "GENERATED KEYS"
|
||||
.PP
|
||||
When
|
||||
@@ -284,7 +298,7 @@ RFC 4034.
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004, 2005, 2007\-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004, 2005, 2007\-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
Copyright \(co 2000\-2003 Internet Software Consortium.
|
||||
.br
|
||||
|
||||
+259
-114
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Portions Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -29,7 +29,7 @@
|
||||
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-keygen.c,v 1.108.8.4 2010/01/19 23:48:12 tbox Exp $ */
|
||||
/* $Id: dnssec-keygen.c,v 1.108.8.8 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -92,27 +92,27 @@ usage(void) {
|
||||
"NSEC3RSASHA1 if using -3)\n");
|
||||
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
|
||||
fprintf(stderr, " -b <key size in bits>:\n");
|
||||
fprintf(stderr, " RSAMD5:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA1:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " NSEC3RSASHA1:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA256:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA512:\t[1024..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " DH:\t\t[128..4096]\n");
|
||||
fprintf(stderr, " DSA:\t\t[512..1024] and divisible by 64\n");
|
||||
fprintf(stderr, " NSEC3DSA:\t[512..1024] and divisible "
|
||||
fprintf(stderr, " RSAMD5:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA1:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " NSEC3RSASHA1:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA256:\t[512..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " RSASHA512:\t[1024..%d]\n", MAX_RSA);
|
||||
fprintf(stderr, " DH:\t\t[128..4096]\n");
|
||||
fprintf(stderr, " DSA:\t\t[512..1024] and divisible by 64\n");
|
||||
fprintf(stderr, " NSEC3DSA:\t[512..1024] and divisible "
|
||||
"by 64\n");
|
||||
fprintf(stderr, " HMAC-MD5:\t[1..512]\n");
|
||||
fprintf(stderr, " HMAC-SHA1:\t[1..160]\n");
|
||||
fprintf(stderr, " HMAC-SHA224:\t[1..224]\n");
|
||||
fprintf(stderr, " HMAC-SHA256:\t[1..256]\n");
|
||||
fprintf(stderr, " HMAC-SHA384:\t[1..384]\n");
|
||||
fprintf(stderr, " HMAC-SHA512:\t[1..512]\n");
|
||||
fprintf(stderr, " HMAC-MD5:\t[1..512]\n");
|
||||
fprintf(stderr, " HMAC-SHA1:\t[1..160]\n");
|
||||
fprintf(stderr, " HMAC-SHA224:\t[1..224]\n");
|
||||
fprintf(stderr, " HMAC-SHA256:\t[1..256]\n");
|
||||
fprintf(stderr, " HMAC-SHA384:\t[1..384]\n");
|
||||
fprintf(stderr, " HMAC-SHA512:\t[1..512]\n");
|
||||
fprintf(stderr, " (if using the default algorithm, key size\n"
|
||||
" defaults to 2048 for KSK, or 1024 for all "
|
||||
"others)\n");
|
||||
fprintf(stderr, " -n <nametype>: ZONE | HOST | ENTITY | "
|
||||
"USER | OTHER\n");
|
||||
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
|
||||
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
|
||||
fprintf(stderr, " -c <class>: (default: IN)\n");
|
||||
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
|
||||
#ifdef USE_PKCS11
|
||||
@@ -136,7 +136,7 @@ usage(void) {
|
||||
|
||||
fprintf(stderr, " -h: print usage and exit\n");
|
||||
fprintf(stderr, " -m <memory debugging mode>:\n");
|
||||
fprintf(stderr, " usage | trace | record | size | mctx\n");
|
||||
fprintf(stderr, " usage | trace | record | size | mctx\n");
|
||||
fprintf(stderr, " -v <level>: set verbosity level (0 - 10)\n");
|
||||
fprintf(stderr, "Timing options:\n");
|
||||
fprintf(stderr, " -P date/[+-]offset/none: set key publication date "
|
||||
@@ -151,6 +151,11 @@ usage(void) {
|
||||
fprintf(stderr, " -G: generate key only; do not set -P or -A\n");
|
||||
fprintf(stderr, " -C: generate a backward-compatible key, omitting "
|
||||
"all dates\n");
|
||||
fprintf(stderr, " -S <key>: generate a successor to an existing "
|
||||
"key\n");
|
||||
fprintf(stderr, " -i <interval>: prepublication interval for "
|
||||
"successor key "
|
||||
"(default: 30 days)\n");
|
||||
fprintf(stderr, "Output:\n");
|
||||
fprintf(stderr, " K<name>+<alg>+<id>.key, "
|
||||
"K<name>+<alg>+<id>.private\n");
|
||||
@@ -190,7 +195,7 @@ progress(int p)
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
char *algname = NULL, *nametype = NULL, *type = NULL;
|
||||
char *algname = NULL, *nametype = NULL, *type = NULL;
|
||||
char *classname = NULL;
|
||||
char *endp;
|
||||
dst_key_t *key = NULL;
|
||||
@@ -207,6 +212,8 @@ main(int argc, char **argv) {
|
||||
isc_textregion_t r;
|
||||
char filename[255];
|
||||
const char *directory = NULL;
|
||||
const char *predecessor = NULL;
|
||||
dst_key_t *prevkey = NULL;
|
||||
isc_buffer_t buf;
|
||||
isc_log_t *log = NULL;
|
||||
isc_entropy_t *ectx = NULL;
|
||||
@@ -222,6 +229,7 @@ main(int argc, char **argv) {
|
||||
isc_stdtime_t publish = 0, activate = 0, revoke = 0;
|
||||
isc_stdtime_t inactive = 0, delete = 0;
|
||||
isc_stdtime_t now;
|
||||
int prepub = -1;
|
||||
isc_boolean_t setpub = ISC_FALSE, setact = ISC_FALSE;
|
||||
isc_boolean_t setrev = ISC_FALSE, setinact = ISC_FALSE;
|
||||
isc_boolean_t setdel = ISC_FALSE;
|
||||
@@ -243,7 +251,7 @@ main(int argc, char **argv) {
|
||||
/*
|
||||
* Process memory debugging argument first.
|
||||
*/
|
||||
#define CMDLINE_FLAGS "3a:b:Cc:d:E:eFf:g:K:km:n:p:qr:s:T:t:v:hGP:A:R:I:D:"
|
||||
#define CMDLINE_FLAGS "3A:a:b:Cc:D:d:E:eFf:Gg:hI:i:K:km:n:P:p:qR:r:S:s:T:t:v:"
|
||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||
switch (ch) {
|
||||
case 'm':
|
||||
@@ -436,6 +444,12 @@ main(int argc, char **argv) {
|
||||
unsetdel = ISC_TRUE;
|
||||
}
|
||||
break;
|
||||
case 'S':
|
||||
predecessor = isc_commandline_argument;
|
||||
break;
|
||||
case 'i':
|
||||
prepub = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case 'F':
|
||||
/* Reserved for FIPS mode */
|
||||
/* FALLTHROUGH */
|
||||
@@ -467,87 +481,205 @@ main(int argc, char **argv) {
|
||||
|
||||
setup_logging(verbose, mctx, &log);
|
||||
|
||||
if (argc < isc_commandline_index + 1)
|
||||
fatal("the key name was not specified");
|
||||
if (argc > isc_commandline_index + 1)
|
||||
fatal("extraneous arguments");
|
||||
if (predecessor == NULL) {
|
||||
if (prepub == -1)
|
||||
prepub = 0;
|
||||
|
||||
if (algname == NULL) {
|
||||
use_default = ISC_TRUE;
|
||||
if (use_nsec3)
|
||||
algname = strdup(DEFAULT_NSEC3_ALGORITHM);
|
||||
else
|
||||
algname = strdup(DEFAULT_ALGORITHM);
|
||||
if (verbose > 0)
|
||||
fprintf(stderr, "no algorithm specified; "
|
||||
"defaulting to %s\n", algname);
|
||||
}
|
||||
if (argc < isc_commandline_index + 1)
|
||||
fatal("the key name was not specified");
|
||||
if (argc > isc_commandline_index + 1)
|
||||
fatal("extraneous arguments");
|
||||
|
||||
if (strcasecmp(algname, "RSA") == 0) {
|
||||
fprintf(stderr, "The use of RSA (RSAMD5) is not recommended.\n"
|
||||
"If you still wish to use RSA (RSAMD5) please "
|
||||
"specify \"-a RSAMD5\"\n");
|
||||
return (1);
|
||||
} else if (strcasecmp(algname, "HMAC-MD5") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACMD5;
|
||||
} else if (strcasecmp(algname, "HMAC-SHA1") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACSHA1;
|
||||
} else if (strcasecmp(algname, "HMAC-SHA224") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACSHA224;
|
||||
} else if (strcasecmp(algname, "HMAC-SHA256") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACSHA256;
|
||||
} else if (strcasecmp(algname, "HMAC-SHA384") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACSHA384;
|
||||
} else if (strcasecmp(algname, "HMAC-SHA512") == 0) {
|
||||
options |= DST_TYPE_KEY;
|
||||
alg = DST_ALG_HMACSHA512;
|
||||
} else {
|
||||
r.base = algname;
|
||||
r.length = strlen(algname);
|
||||
ret = dns_secalg_fromtext(&alg, &r);
|
||||
dns_fixedname_init(&fname);
|
||||
name = dns_fixedname_name(&fname);
|
||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||
strlen(argv[isc_commandline_index]));
|
||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("unknown algorithm %s", algname);
|
||||
if (alg == DST_ALG_DH)
|
||||
options |= DST_TYPE_KEY;
|
||||
}
|
||||
fatal("invalid key name %s: %s",
|
||||
argv[isc_commandline_index],
|
||||
isc_result_totext(ret));
|
||||
|
||||
if (use_nsec3 &&
|
||||
alg != DST_ALG_NSEC3DSA && alg != DST_ALG_NSEC3RSASHA1 &&
|
||||
alg != DST_ALG_RSASHA256 && alg!= DST_ALG_RSASHA512) {
|
||||
fatal("%s is incompatible with NSEC3; "
|
||||
"do not use the -3 option", algname);
|
||||
}
|
||||
|
||||
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
|
||||
if (strcasecmp(type, "NOAUTH") == 0)
|
||||
flags |= DNS_KEYTYPE_NOAUTH;
|
||||
else if (strcasecmp(type, "NOCONF") == 0)
|
||||
flags |= DNS_KEYTYPE_NOCONF;
|
||||
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
|
||||
flags |= (DNS_KEYTYPE_NOAUTH | DNS_KEYTYPE_NOCONF);
|
||||
if (size < 0)
|
||||
size = 0;
|
||||
}
|
||||
else if (strcasecmp(type, "AUTHCONF") == 0)
|
||||
/* nothing */;
|
||||
else
|
||||
fatal("invalid type %s", type);
|
||||
}
|
||||
|
||||
if (size < 0) {
|
||||
if (use_default) {
|
||||
size = ((kskflag & DNS_KEYFLAG_KSK) != 0) ? 2048 : 1024;
|
||||
if (algname == NULL) {
|
||||
use_default = ISC_TRUE;
|
||||
if (use_nsec3)
|
||||
algname = strdup(DEFAULT_NSEC3_ALGORITHM);
|
||||
else
|
||||
algname = strdup(DEFAULT_ALGORITHM);
|
||||
if (verbose > 0)
|
||||
fprintf(stderr, "key size not specified; "
|
||||
"defaulting to %d\n", size);
|
||||
} else {
|
||||
fatal("key size not specified (-b option)");
|
||||
fprintf(stderr, "no algorithm specified; "
|
||||
"defaulting to %s\n", algname);
|
||||
}
|
||||
|
||||
if (strcasecmp(algname, "RSA") == 0) {
|
||||
fprintf(stderr, "The use of RSA (RSAMD5) is not "
|
||||
"recommended.\nIf you still wish to "
|
||||
"use RSA (RSAMD5) please specify "
|
||||
"\"-a RSAMD5\"\n");
|
||||
return (1);
|
||||
} else if (strcasecmp(algname, "HMAC-MD5") == 0)
|
||||
alg = DST_ALG_HMACMD5;
|
||||
else if (strcasecmp(algname, "HMAC-SHA1") == 0)
|
||||
alg = DST_ALG_HMACSHA1;
|
||||
else if (strcasecmp(algname, "HMAC-SHA224") == 0)
|
||||
alg = DST_ALG_HMACSHA224;
|
||||
else if (strcasecmp(algname, "HMAC-SHA256") == 0)
|
||||
alg = DST_ALG_HMACSHA256;
|
||||
else if (strcasecmp(algname, "HMAC-SHA384") == 0)
|
||||
alg = DST_ALG_HMACSHA384;
|
||||
else if (strcasecmp(algname, "HMAC-SHA512") == 0)
|
||||
alg = DST_ALG_HMACSHA512;
|
||||
else {
|
||||
r.base = algname;
|
||||
r.length = strlen(algname);
|
||||
ret = dns_secalg_fromtext(&alg, &r);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("unknown algorithm %s", algname);
|
||||
if (alg == DST_ALG_DH)
|
||||
options |= DST_TYPE_KEY;
|
||||
}
|
||||
|
||||
if (use_nsec3 &&
|
||||
alg != DST_ALG_NSEC3DSA && alg != DST_ALG_NSEC3RSASHA1 &&
|
||||
alg != DST_ALG_RSASHA256 && alg!= DST_ALG_RSASHA512) {
|
||||
fatal("%s is incompatible with NSEC3; "
|
||||
"do not use the -3 option", algname);
|
||||
}
|
||||
|
||||
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
|
||||
if (strcasecmp(type, "NOAUTH") == 0)
|
||||
flags |= DNS_KEYTYPE_NOAUTH;
|
||||
else if (strcasecmp(type, "NOCONF") == 0)
|
||||
flags |= DNS_KEYTYPE_NOCONF;
|
||||
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
|
||||
flags |= (DNS_KEYTYPE_NOAUTH |
|
||||
DNS_KEYTYPE_NOCONF);
|
||||
if (size < 0)
|
||||
size = 0;
|
||||
}
|
||||
else if (strcasecmp(type, "AUTHCONF") == 0)
|
||||
/* nothing */;
|
||||
else
|
||||
fatal("invalid type %s", type);
|
||||
}
|
||||
|
||||
if (size < 0) {
|
||||
if (use_default) {
|
||||
if ((kskflag & DNS_KEYFLAG_KSK) != 0)
|
||||
size = 2048;
|
||||
else
|
||||
size = 1024;
|
||||
if (verbose > 0)
|
||||
fprintf(stderr, "key size not "
|
||||
"specified; defaulting "
|
||||
"to %d\n", size);
|
||||
} else {
|
||||
fatal("key size not specified (-b option)");
|
||||
}
|
||||
}
|
||||
|
||||
if (!oldstyle && prepub > 0) {
|
||||
if (setpub && setact && (activate - prepub) < publish)
|
||||
fatal("Activation and publication dates "
|
||||
"are closer together than the\n\t"
|
||||
"prepublication interval.");
|
||||
|
||||
if (!setpub && !setact) {
|
||||
setpub = setact = ISC_TRUE;
|
||||
publish = now;
|
||||
activate = now + prepub;
|
||||
} else if (setpub && !setact) {
|
||||
setact = ISC_TRUE;
|
||||
activate = publish + prepub;
|
||||
} else if (setact && !setpub) {
|
||||
setpub = ISC_TRUE;
|
||||
publish = activate - prepub;
|
||||
}
|
||||
|
||||
if ((activate - prepub) < now)
|
||||
fatal("Time until activation is shorter "
|
||||
"than the\n\tprepublication interval.");
|
||||
}
|
||||
} else {
|
||||
char keystr[DST_KEY_FORMATSIZE];
|
||||
isc_stdtime_t when;
|
||||
int major, minor;
|
||||
|
||||
if (prepub == -1)
|
||||
prepub = (30 * 86400);
|
||||
|
||||
if (algname != NULL)
|
||||
fatal("-S and -a cannot be used together");
|
||||
if (size >= 0)
|
||||
fatal("-S and -b cannot be used together");
|
||||
if (nametype != NULL)
|
||||
fatal("-S and -n cannot be used together");
|
||||
if (type != NULL)
|
||||
fatal("-S and -t cannot be used together");
|
||||
if (setpub || unsetpub)
|
||||
fatal("-S and -P cannot be used together");
|
||||
if (setact || unsetact)
|
||||
fatal("-S and -A cannot be used together");
|
||||
if (use_nsec3)
|
||||
fatal("-S and -3 cannot be used together");
|
||||
if (oldstyle)
|
||||
fatal("-S and -C cannot be used together");
|
||||
if (genonly)
|
||||
fatal("-S and -G cannot be used together");
|
||||
|
||||
ret = dst_key_fromnamedfile(predecessor, directory,
|
||||
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE,
|
||||
mctx, &prevkey);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("Invalid keyfile %s: %s",
|
||||
filename, isc_result_totext(ret));
|
||||
if (!dst_key_isprivate(prevkey))
|
||||
fatal("%s is not a private key", filename);
|
||||
|
||||
name = dst_key_name(prevkey);
|
||||
alg = dst_key_alg(prevkey);
|
||||
size = dst_key_size(prevkey);
|
||||
flags = dst_key_flags(prevkey);
|
||||
|
||||
dst_key_format(prevkey, keystr, sizeof(keystr));
|
||||
dst_key_getprivateformat(prevkey, &major, &minor);
|
||||
if (major != DST_MAJOR_VERSION || minor < DST_MINOR_VERSION)
|
||||
fatal("Key %s has incompatible format version %d.%d\n\t"
|
||||
"It is not possible to generate a successor key.",
|
||||
keystr, major, minor);
|
||||
|
||||
ret = dst_key_gettime(prevkey, DST_TIME_ACTIVATE, &when);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("Key %s has no activation date.\n\t"
|
||||
"You must use dnssec-settime -A to set one "
|
||||
"before generating a successor.", keystr);
|
||||
|
||||
ret = dst_key_gettime(prevkey, DST_TIME_INACTIVE, &activate);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("Key %s has no inactivation date.\n\t"
|
||||
"You must use dnssec-settime -I to set one "
|
||||
"before generating a successor.", keystr);
|
||||
|
||||
publish = activate - prepub;
|
||||
if (publish < now)
|
||||
fatal("Key %s becomes inactive\n\t"
|
||||
"sooner than the prepublication period "
|
||||
"for the new key ends.\n\t"
|
||||
"Either change the inactivation date with "
|
||||
"dnssec-settime -I,\n\t"
|
||||
"or use the -i option to set a shorter "
|
||||
"prepublication interval.", keystr);
|
||||
|
||||
ret = dst_key_gettime(prevkey, DST_TIME_DELETE, &when);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fprintf(stderr, "%s: WARNING: Key %s has no removal "
|
||||
"date;\n\t it will remain in the zone "
|
||||
"indefinitely after rollover.\n\t "
|
||||
"You can use dnssec-settime -D to "
|
||||
"change this.\n", program, keystr);
|
||||
|
||||
setpub = setact = ISC_TRUE;
|
||||
}
|
||||
|
||||
switch (alg) {
|
||||
@@ -572,6 +704,7 @@ main(int argc, char **argv) {
|
||||
fatal("invalid DSS key size: %d", size);
|
||||
break;
|
||||
case DST_ALG_HMACMD5:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 512)
|
||||
fatal("HMAC-MD5 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 80 || dbits > 128))
|
||||
@@ -581,6 +714,7 @@ main(int argc, char **argv) {
|
||||
dbits);
|
||||
break;
|
||||
case DST_ALG_HMACSHA1:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 160)
|
||||
fatal("HMAC-SHA1 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 80 || dbits > 160))
|
||||
@@ -590,6 +724,7 @@ main(int argc, char **argv) {
|
||||
dbits);
|
||||
break;
|
||||
case DST_ALG_HMACSHA224:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 224)
|
||||
fatal("HMAC-SHA224 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 112 || dbits > 224))
|
||||
@@ -599,6 +734,7 @@ main(int argc, char **argv) {
|
||||
dbits);
|
||||
break;
|
||||
case DST_ALG_HMACSHA256:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 256)
|
||||
fatal("HMAC-SHA256 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 128 || dbits > 256))
|
||||
@@ -608,6 +744,7 @@ main(int argc, char **argv) {
|
||||
dbits);
|
||||
break;
|
||||
case DST_ALG_HMACSHA384:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 384)
|
||||
fatal("HMAC-384 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 192 || dbits > 384))
|
||||
@@ -617,6 +754,7 @@ main(int argc, char **argv) {
|
||||
dbits);
|
||||
break;
|
||||
case DST_ALG_HMACSHA512:
|
||||
options |= DST_TYPE_KEY;
|
||||
if (size < 1 || size > 512)
|
||||
fatal("HMAC-SHA512 key size %d out of range", size);
|
||||
if (dbits != 0 && (dbits < 256 || dbits > 512))
|
||||
@@ -685,16 +823,6 @@ main(int argc, char **argv) {
|
||||
fatal("a key with algorithm '%s' cannot be a zone key",
|
||||
algname);
|
||||
|
||||
dns_fixedname_init(&fname);
|
||||
name = dns_fixedname_name(&fname);
|
||||
isc_buffer_init(&buf, argv[isc_commandline_index],
|
||||
strlen(argv[isc_commandline_index]));
|
||||
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
|
||||
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("invalid key name %s: %s", argv[isc_commandline_index],
|
||||
isc_result_totext(ret));
|
||||
|
||||
switch(alg) {
|
||||
case DNS_KEYALG_RSAMD5:
|
||||
case DNS_KEYALG_RSASHA1:
|
||||
@@ -763,9 +891,18 @@ main(int argc, char **argv) {
|
||||
/*
|
||||
* Set key timing metadata (unless using -C)
|
||||
*
|
||||
* Publish and activation dates are set to "now" by default,
|
||||
* but can be overridden. Creation date is always set to
|
||||
* "now".
|
||||
* Creation date is always set to "now".
|
||||
*
|
||||
* For a new key without an explicit predecessor, publish
|
||||
* and activation dates are set to "now" by default, but
|
||||
* can both be overridden.
|
||||
*
|
||||
* For a successor key, activation is set to match the
|
||||
* predecessor's inactivation date. Publish is set to 30
|
||||
* days earlier than that (XXX: this should be configurable).
|
||||
* If either of the resulting dates are in the past, that's
|
||||
* an error; the inactivation date of the predecessor key
|
||||
* must be updated before a successor key can be created.
|
||||
*/
|
||||
if (!oldstyle) {
|
||||
dst_key_settime(key, DST_TIME_CREATED, now);
|
||||
@@ -832,12 +969,15 @@ main(int argc, char **argv) {
|
||||
|
||||
if (verbose > 0) {
|
||||
isc_buffer_clear(&buf);
|
||||
dst_key_buildfilename(key, 0, directory, &buf);
|
||||
fprintf(stderr,
|
||||
"%s: %s already exists, or might "
|
||||
"collide with another key upon "
|
||||
"revokation. Generating a new key\n",
|
||||
program, filename);
|
||||
ret = dst_key_buildfilename(key, 0,
|
||||
directory, &buf);
|
||||
if (ret == ISC_R_SUCCESS)
|
||||
fprintf(stderr,
|
||||
"%s: %s already exists, or "
|
||||
"might collide with another "
|
||||
"key upon revokation. "
|
||||
"Generating a new key\n",
|
||||
program, filename);
|
||||
}
|
||||
|
||||
dst_key_free(&key);
|
||||
@@ -858,8 +998,13 @@ main(int argc, char **argv) {
|
||||
|
||||
isc_buffer_clear(&buf);
|
||||
ret = dst_key_buildfilename(key, 0, NULL, &buf);
|
||||
if (ret != ISC_R_SUCCESS)
|
||||
fatal("dst_key_buildfilename returned: %s\n",
|
||||
isc_result_totext(ret));
|
||||
printf("%s\n", filename);
|
||||
dst_key_free(&key);
|
||||
if (prevkey != NULL)
|
||||
dst_key_free(&prevkey);
|
||||
|
||||
cleanup_logging(&log);
|
||||
cleanup_entropy(&ectx);
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-keygen.docbook,v 1.33 2009/11/03 21:44:46 each Exp $ -->
|
||||
<!-- $Id: dnssec-keygen.docbook,v 1.33.24.2 2010/08/16 23:46:30 tbox Exp $ -->
|
||||
<refentry id="man.dnssec-keygen">
|
||||
<refentryinfo>
|
||||
<date>June 30, 2000</date>
|
||||
@@ -42,6 +42,7 @@
|
||||
<year>2007</year>
|
||||
<year>2008</year>
|
||||
<year>2009</year>
|
||||
<year>2010</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
<copyright>
|
||||
@@ -71,6 +72,7 @@
|
||||
<arg><option>-g <replaceable class="parameter">generator</replaceable></option></arg>
|
||||
<arg><option>-h</option></arg>
|
||||
<arg><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||
<arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
|
||||
<arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
||||
<arg><option>-k</option></arg>
|
||||
<arg><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||
@@ -78,6 +80,7 @@
|
||||
<arg><option>-q</option></arg>
|
||||
<arg><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
|
||||
<arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
|
||||
<arg><option>-S <replaceable class="parameter">key</replaceable></option></arg>
|
||||
<arg><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
|
||||
<arg><option>-t <replaceable class="parameter">type</replaceable></option></arg>
|
||||
<arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
|
||||
@@ -341,6 +344,21 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-S <replaceable class="parameter">key</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Create a new key which is an explicit successor to an
|
||||
existing key. The name, algorithm, size, and type of the
|
||||
key will be set to match the existing key. The activation
|
||||
date of the new key will be set to the inactivation date of
|
||||
the existing one. The publication date will be set to the
|
||||
activation date minus the prepublication interval, which
|
||||
defaults to 30 days.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-s <replaceable class="parameter">strength</replaceable></term>
|
||||
<listitem>
|
||||
@@ -463,6 +481,34 @@
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-i <replaceable class="parameter">interval</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the prepublication interval for a key. If set, then
|
||||
the publication and activation dates must be separated by at least
|
||||
this much time. If the activation date is specified but the
|
||||
publication date isn't, then the publication date will default
|
||||
to this much time before the activation date; conversely, if
|
||||
the publication date is specified but activation date isn't,
|
||||
then activation will be set to this much time after publication.
|
||||
</para>
|
||||
<para>
|
||||
If the key is being created as an explicit successor to another
|
||||
key, then the default prepublication interval is 30 days;
|
||||
otherwise it is zero.
|
||||
</para>
|
||||
<para>
|
||||
As with date offsets, if the argument is followed by one of
|
||||
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
|
||||
interval is measured in years, months, weeks, days, hours,
|
||||
or minutes, respectively. Without a suffix, the interval is
|
||||
measured in seconds.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: dnssec-keygen.html,v 1.45 2009/11/03 21:58:30 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-keygen.html,v 1.45.24.1 2010/08/17 00:08:22 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -29,10 +29,10 @@
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543558"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543578"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-keygen</strong></span>
|
||||
generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
|
||||
and RFC 4034. It can also generate keys for use with
|
||||
@@ -46,7 +46,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543576"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543596"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
|
||||
<dd>
|
||||
@@ -203,6 +203,16 @@
|
||||
<code class="filename">keyboard</code> indicates that keyboard
|
||||
input should be used.
|
||||
</p></dd>
|
||||
<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
|
||||
<dd><p>
|
||||
Create a new key which is an explicit successor to an
|
||||
existing key. The name, algorithm, size, and type of the
|
||||
key will be set to match the existing key. The activation
|
||||
date of the new key will be set to the inactivation date of
|
||||
the existing one. The publication date will be set to the
|
||||
activation date minus the prepublication interval, which
|
||||
defaults to 30 days.
|
||||
</p></dd>
|
||||
<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies the strength value of the key. The strength is
|
||||
@@ -238,7 +248,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544128"></a><h2>TIMING OPTIONS</h2>
|
||||
<a name="id2544301"></a><h2>TIMING OPTIONS</h2>
|
||||
<p>
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
|
||||
If the argument begins with a '+' or '-', it is interpreted as
|
||||
@@ -282,10 +292,34 @@
|
||||
date, the key will no longer be included in the zone. (It
|
||||
may remain in the key repository, however.)
|
||||
</p></dd>
|
||||
<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the prepublication interval for a key. If set, then
|
||||
the publication and activation dates must be separated by at least
|
||||
this much time. If the activation date is specified but the
|
||||
publication date isn't, then the publication date will default
|
||||
to this much time before the activation date; conversely, if
|
||||
the publication date is specified but activation date isn't,
|
||||
then activation will be set to this much time after publication.
|
||||
</p>
|
||||
<p>
|
||||
If the key is being created as an explicit successor to another
|
||||
key, then the default prepublication interval is 30 days;
|
||||
otherwise it is zero.
|
||||
</p>
|
||||
<p>
|
||||
As with date offsets, if the argument is followed by one of
|
||||
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
|
||||
interval is measured in years, months, weeks, days, hours,
|
||||
or minutes, respectively. Without a suffix, the interval is
|
||||
measured in seconds.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544226"></a><h2>GENERATED KEYS</h2>
|
||||
<a name="id2544491"></a><h2>GENERATED KEYS</h2>
|
||||
<p>
|
||||
When <span><strong class="command">dnssec-keygen</strong></span> completes
|
||||
successfully,
|
||||
@@ -331,7 +365,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544308"></a><h2>EXAMPLE</h2>
|
||||
<a name="id2544642"></a><h2>EXAMPLE</h2>
|
||||
<p>
|
||||
To generate a 768-bit DSA key for the domain
|
||||
<strong class="userinput"><code>example.com</code></strong>, the following command would be
|
||||
@@ -352,7 +386,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544352"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2544685"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
<em class="citetitle">RFC 2539</em>,
|
||||
@@ -361,7 +395,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544451"></a><h2>AUTHOR</h2>
|
||||
<a name="id2544716"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
@@ -1,18 +1,18 @@
|
||||
.\" Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-revoke.8,v 1.8 2009/11/03 21:58:30 tbox Exp $
|
||||
.\" $Id: dnssec-revoke.8,v 1.8.24.1 2010/05/18 04:04:36 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-revoke.c,v 1.18.34.2 2009/12/18 23:48:18 tbox Exp $ */
|
||||
/* $Id: dnssec-revoke.c,v 1.18.34.4 2010/05/06 23:49:37 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -161,6 +161,10 @@ main(int argc, char **argv) {
|
||||
fatal("cannot process filename %s: %s",
|
||||
argv[isc_commandline_index],
|
||||
isc_result_totext(result));
|
||||
if (strcmp(dir, ".") == 0) {
|
||||
isc_mem_free(mctx, dir);
|
||||
dir = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
if (ectx == NULL)
|
||||
@@ -224,10 +228,8 @@ main(int argc, char **argv) {
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
printf("%s\n", newname);
|
||||
|
||||
isc_buffer_clear(&buf);
|
||||
dst_key_buildfilename(key, DST_TYPE_PRIVATE, dir, &buf);
|
||||
dst_key_buildfilename(key, 0, dir, &buf);
|
||||
printf("%s\n", newname);
|
||||
|
||||
/*
|
||||
@@ -259,7 +261,8 @@ cleanup:
|
||||
cleanup_entropy(&ectx);
|
||||
if (verbose > 10)
|
||||
isc_mem_stats(mctx, stdout);
|
||||
isc_mem_free(mctx, dir);
|
||||
if (dir != NULL)
|
||||
isc_mem_free(mctx, dir);
|
||||
isc_mem_destroy(&mctx);
|
||||
|
||||
return (0);
|
||||
|
||||
@@ -1,20 +1,19 @@
|
||||
<!--
|
||||
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-revoke.html,v 1.8 2009/11/03 21:58:30 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-revoke.html,v 1.8.24.1 2010/05/18 04:04:36 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
|
||||
+25
-11
@@ -1,18 +1,18 @@
|
||||
.\" Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: dnssec-settime.8,v 1.9 2009/11/03 21:58:30 tbox Exp $
|
||||
.\" $Id: dnssec-settime.8,v 1.9.24.7 2011/03/22 02:10:54 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -59,7 +59,7 @@ and
|
||||
.RS 4
|
||||
Force an update of an old\-format key with no metadata fields. Without this option,
|
||||
\fBdnssec\-settime\fR
|
||||
will fail when attempting to update a legacy key. With this option, the key will be recreated in the new format, but with the original key data retained. The key's creation date will be set to the present time.
|
||||
will fail when attempting to update a legacy key. With this option, the key will be recreated in the new format, but with the original key data retained. The key's creation date will be set to the present time. If no other values are specified, then the key's publication and activation dates will also be set to the present time.
|
||||
.RE
|
||||
.PP
|
||||
\-K \fIdirectory\fR
|
||||
@@ -109,6 +109,20 @@ Sets the date on which the key is to be retired. After that date, the key will s
|
||||
.RS 4
|
||||
Sets the date on which the key is to be deleted. After that date, the key will no longer be included in the zone. (It may remain in the key repository, however.)
|
||||
.RE
|
||||
.PP
|
||||
\-S \fIpredecessor key\fR
|
||||
.RS 4
|
||||
Select a key for which the key being modified will be an explicit successor. The name, algorithm, size, and type of the predecessor key must exactly match those of the key being modified. The activation date of the successor key will be set to the inactivation date of the predecessor. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days.
|
||||
.RE
|
||||
.PP
|
||||
\-i \fIinterval\fR
|
||||
.RS 4
|
||||
Sets the prepublication interval for a key. If set, then the publication and activation dates must be separated by at least this much time. If the activation date is specified but the publication date isn't, then the publication date will default to this much time before the activation date; conversely, if the publication date is specified but activation date isn't, then activation will be set to this much time after publication.
|
||||
.sp
|
||||
If the key is being set to be an explicit successor to another key, then the default prepublication interval is 30 days; otherwise it is zero.
|
||||
.sp
|
||||
As with date offsets, if the argument is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the interval is measured in years, months, weeks, days, hours, or minutes, respectively. Without a suffix, the interval is measured in seconds.
|
||||
.RE
|
||||
.SH "PRINTING OPTIONS"
|
||||
.PP
|
||||
\fBdnssec\-settime\fR
|
||||
@@ -119,7 +133,7 @@ can also be used to print the timing metadata associated with a key.
|
||||
Print times in UNIX epoch format.
|
||||
.RE
|
||||
.PP
|
||||
\-p \fIC/P/A/R/U/D/all\fR
|
||||
\-p \fIC/P/A/R/I/D/all\fR
|
||||
.RS 4
|
||||
Print a specific metadata value or set of metadata values. The
|
||||
\fB\-p\fR
|
||||
@@ -131,9 +145,9 @@ for the publication date,
|
||||
\fBA\fR
|
||||
for the activation date,
|
||||
\fBR\fR
|
||||
for the revokation date,
|
||||
\fBU\fR
|
||||
for the unpublication date, or
|
||||
for the revocation date,
|
||||
\fBI\fR
|
||||
for the inactivation date, or
|
||||
\fBD\fR
|
||||
for the deletion date. To print all of the metadata, use
|
||||
\fB\-p all\fR.
|
||||
@@ -148,5 +162,5 @@ RFC 5011.
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2009\-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
+150
-29
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-settime.c,v 1.19.34.5 2010/01/07 19:16:30 each Exp $ */
|
||||
/* $Id: dnssec-settime.c,v 1.19.34.12 2011/06/02 20:23:48 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -80,9 +80,8 @@ usage(void) {
|
||||
fprintf(stderr, " -D date/[+-]offset/none: set/unset key "
|
||||
"deletion date\n");
|
||||
fprintf(stderr, "Printing options:\n");
|
||||
fprintf(stderr, " -p C/P/A/R/U/D/all: print a particular time "
|
||||
"value or values "
|
||||
"[default: all]\n");
|
||||
fprintf(stderr, " -p C/P/A/R/I/D/all: print a particular time "
|
||||
"value or values\n");
|
||||
fprintf(stderr, " -u: print times in unix epoch "
|
||||
"format\n");
|
||||
fprintf(stderr, "Output:\n");
|
||||
@@ -117,20 +116,27 @@ printtime(dst_key_t *key, int type, const char *tag, isc_boolean_t epoch,
|
||||
|
||||
int
|
||||
main(int argc, char **argv) {
|
||||
isc_result_t result;
|
||||
isc_result_t result;
|
||||
#ifdef USE_PKCS11
|
||||
const char *engine = "pkcs11";
|
||||
const char *engine = "pkcs11";
|
||||
#else
|
||||
const char *engine = NULL;
|
||||
const char *engine = NULL;
|
||||
#endif
|
||||
char *filename = NULL, *directory = NULL;
|
||||
char newname[1024];
|
||||
char keystr[DST_KEY_FORMATSIZE];
|
||||
char *endp, *p;
|
||||
int ch;
|
||||
isc_entropy_t *ectx = NULL;
|
||||
dst_key_t *key = NULL;
|
||||
isc_buffer_t buf;
|
||||
char *filename = NULL, *directory = NULL;
|
||||
char newname[1024];
|
||||
char keystr[DST_KEY_FORMATSIZE];
|
||||
char *endp, *p;
|
||||
int ch;
|
||||
isc_entropy_t *ectx = NULL;
|
||||
const char *predecessor = NULL;
|
||||
dst_key_t *prevkey = NULL;
|
||||
dst_key_t *key = NULL;
|
||||
isc_buffer_t buf;
|
||||
dns_name_t *name = NULL;
|
||||
dns_secalg_t alg = 0;
|
||||
unsigned int size = 0;
|
||||
isc_uint16_t flags = 0;
|
||||
int prepub = -1;
|
||||
isc_stdtime_t now;
|
||||
isc_stdtime_t pub = 0, act = 0, rev = 0, inact = 0, del = 0;
|
||||
isc_boolean_t setpub = ISC_FALSE, setact = ISC_FALSE;
|
||||
@@ -159,8 +165,8 @@ main(int argc, char **argv) {
|
||||
|
||||
isc_stdtime_get(&now);
|
||||
|
||||
while ((ch = isc_commandline_parse(argc, argv,
|
||||
"E:fK:uhp:v:P:A:R:I:D:")) != -1) {
|
||||
#define CMDLINE_FLAGS "A:D:E:fhI:i:K:P:p:R:S:uv:"
|
||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||
switch (ch) {
|
||||
case 'E':
|
||||
engine = isc_commandline_argument;
|
||||
@@ -293,6 +299,12 @@ main(int argc, char **argv) {
|
||||
now, now);
|
||||
}
|
||||
break;
|
||||
case 'S':
|
||||
predecessor = isc_commandline_argument;
|
||||
break;
|
||||
case 'i':
|
||||
prepub = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?')
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
@@ -314,17 +326,6 @@ main(int argc, char **argv) {
|
||||
if (argc > isc_commandline_index + 1)
|
||||
fatal("Extraneous arguments");
|
||||
|
||||
if (directory != NULL) {
|
||||
filename = argv[isc_commandline_index];
|
||||
} else {
|
||||
result = isc_file_splitpath(mctx, argv[isc_commandline_index],
|
||||
&directory, &filename);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot process filename %s: %s",
|
||||
argv[isc_commandline_index],
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
if (ectx == NULL)
|
||||
setup_entropy(mctx, NULL, &ectx);
|
||||
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
|
||||
@@ -337,6 +338,105 @@ main(int argc, char **argv) {
|
||||
isc_result_totext(result));
|
||||
isc_entropy_stopcallbacksources(ectx);
|
||||
|
||||
if (predecessor != NULL) {
|
||||
char keystr[DST_KEY_FORMATSIZE];
|
||||
isc_stdtime_t when;
|
||||
int major, minor;
|
||||
|
||||
if (prepub == -1)
|
||||
prepub = (30 * 86400);
|
||||
|
||||
if (setpub || unsetpub)
|
||||
fatal("-S and -P cannot be used together");
|
||||
if (setact || unsetact)
|
||||
fatal("-S and -A cannot be used together");
|
||||
|
||||
result = dst_key_fromnamedfile(predecessor, directory,
|
||||
DST_TYPE_PUBLIC |
|
||||
DST_TYPE_PRIVATE,
|
||||
mctx, &prevkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Invalid keyfile %s: %s",
|
||||
filename, isc_result_totext(result));
|
||||
if (!dst_key_isprivate(prevkey))
|
||||
fatal("%s is not a private key", filename);
|
||||
|
||||
name = dst_key_name(prevkey);
|
||||
alg = dst_key_alg(prevkey);
|
||||
size = dst_key_size(prevkey);
|
||||
flags = dst_key_flags(prevkey);
|
||||
|
||||
dst_key_format(prevkey, keystr, sizeof(keystr));
|
||||
dst_key_getprivateformat(prevkey, &major, &minor);
|
||||
if (major != DST_MAJOR_VERSION || minor < DST_MINOR_VERSION)
|
||||
fatal("Predecessor has incompatible format "
|
||||
"version %d.%d\n\t", major, minor);
|
||||
|
||||
result = dst_key_gettime(prevkey, DST_TIME_ACTIVATE, &when);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Predecessor has no activation date. "
|
||||
"You must set one before\n\t"
|
||||
"generating a successor.");
|
||||
|
||||
result = dst_key_gettime(prevkey, DST_TIME_INACTIVE, &act);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("Predecessor has no inactivation date. "
|
||||
"You must set one before\n\t"
|
||||
"generating a successor.");
|
||||
|
||||
pub = act - prepub;
|
||||
if (pub < now && prepub != 0)
|
||||
fatal("Predecessor will become inactive before the\n\t"
|
||||
"prepublication period ends. Either change "
|
||||
"its inactivation date,\n\t"
|
||||
"or use the -i option to set a shorter "
|
||||
"prepublication interval.");
|
||||
|
||||
result = dst_key_gettime(prevkey, DST_TIME_DELETE, &when);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fprintf(stderr, "%s: WARNING: Predecessor has no "
|
||||
"removal date;\n\t"
|
||||
"it will remain in the zone "
|
||||
"indefinitely after rollover.\n",
|
||||
program);
|
||||
|
||||
changed = setpub = setact = ISC_TRUE;
|
||||
dst_key_free(&prevkey);
|
||||
} else {
|
||||
if (prepub < 0)
|
||||
prepub = 0;
|
||||
|
||||
if (prepub > 0) {
|
||||
if (setpub && setact && (act - prepub) < pub)
|
||||
fatal("Activation and publication dates "
|
||||
"are closer together than the\n\t"
|
||||
"prepublication interval.");
|
||||
|
||||
if (setpub && !setact) {
|
||||
setact = ISC_TRUE;
|
||||
act = pub + prepub;
|
||||
} else if (setact && !setpub) {
|
||||
setpub = ISC_TRUE;
|
||||
pub = act - prepub;
|
||||
}
|
||||
|
||||
if ((act - prepub) < now)
|
||||
fatal("Time until activation is shorter "
|
||||
"than the\n\tprepublication interval.");
|
||||
}
|
||||
}
|
||||
|
||||
if (directory != NULL) {
|
||||
filename = argv[isc_commandline_index];
|
||||
} else {
|
||||
result = isc_file_splitpath(mctx, argv[isc_commandline_index],
|
||||
&directory, &filename);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot process filename %s: %s",
|
||||
argv[isc_commandline_index],
|
||||
isc_result_totext(result));
|
||||
}
|
||||
|
||||
result = dst_key_fromnamedfile(filename, directory,
|
||||
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE,
|
||||
mctx, &key);
|
||||
@@ -349,6 +449,17 @@ main(int argc, char **argv) {
|
||||
|
||||
dst_key_format(key, keystr, sizeof(keystr));
|
||||
|
||||
if (predecessor != NULL) {
|
||||
if (!dns_name_equal(name, dst_key_name(key)))
|
||||
fatal("Key name mismatch");
|
||||
if (alg != dst_key_alg(key))
|
||||
fatal("Key algorithm mismatch");
|
||||
if (size != dst_key_size(key))
|
||||
fatal("Key size mismatch");
|
||||
if (flags != dst_key_flags(key))
|
||||
fatal("Key flags mismatch");
|
||||
}
|
||||
|
||||
if (force)
|
||||
set_keyversion(key);
|
||||
else
|
||||
@@ -401,6 +512,16 @@ main(int argc, char **argv) {
|
||||
else if (unsetdel)
|
||||
dst_key_unsettime(key, DST_TIME_DELETE);
|
||||
|
||||
/*
|
||||
* No metadata changes were made but we're forcing an upgrade
|
||||
* to the new format anyway: use "-P now -A now" as the default
|
||||
*/
|
||||
if (force && !changed) {
|
||||
dst_key_settime(key, DST_TIME_PUBLISH, now);
|
||||
dst_key_settime(key, DST_TIME_ACTIVATE, now);
|
||||
changed = ISC_TRUE;
|
||||
}
|
||||
|
||||
/*
|
||||
* Print out time values, if -p was used.
|
||||
*/
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-settime.docbook,v 1.7 2009/11/03 21:44:46 each Exp $ -->
|
||||
<!-- $Id: dnssec-settime.docbook,v 1.7.24.6 2011/03/21 23:46:28 tbox Exp $ -->
|
||||
<refentry id="man.dnssec-settime">
|
||||
<refentryinfo>
|
||||
<date>July 15, 2009</date>
|
||||
@@ -37,6 +37,8 @@
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2009</year>
|
||||
<year>2010</year>
|
||||
<year>2011</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -97,7 +99,9 @@
|
||||
fail when attempting to update a legacy key. With this option,
|
||||
the key will be recreated in the new format, but with the
|
||||
original key data retained. The key's creation date will be
|
||||
set to the present time.
|
||||
set to the present time. If no other values are specified,
|
||||
then the key's publication and activation dates will also
|
||||
be set to the present time.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
@@ -210,6 +214,47 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-S <replaceable class="parameter">predecessor key</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Select a key for which the key being modified will be an
|
||||
explicit successor. The name, algorithm, size, and type of the
|
||||
predecessor key must exactly match those of the key being
|
||||
modified. The activation date of the successor key will be set
|
||||
to the inactivation date of the predecessor. The publication
|
||||
date will be set to the activation date minus the prepublication
|
||||
interval, which defaults to 30 days.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-i <replaceable class="parameter">interval</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the prepublication interval for a key. If set, then
|
||||
the publication and activation dates must be separated by at least
|
||||
this much time. If the activation date is specified but the
|
||||
publication date isn't, then the publication date will default
|
||||
to this much time before the activation date; conversely, if
|
||||
the publication date is specified but activation date isn't,
|
||||
then activation will be set to this much time after publication.
|
||||
</para>
|
||||
<para>
|
||||
If the key is being set to be an explicit successor to another
|
||||
key, then the default prepublication interval is 30 days;
|
||||
otherwise it is zero.
|
||||
</para>
|
||||
<para>
|
||||
As with date offsets, if the argument is followed by one of
|
||||
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
|
||||
interval is measured in years, months, weeks, days, hours,
|
||||
or minutes, respectively. Without a suffix, the interval is
|
||||
measured in seconds.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
@@ -231,7 +276,7 @@
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-p <replaceable class="parameter">C/P/A/R/U/D/all</replaceable></term>
|
||||
<term>-p <replaceable class="parameter">C/P/A/R/I/D/all</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Print a specific metadata value or set of metadata values.
|
||||
@@ -240,8 +285,8 @@
|
||||
<option>C</option> for the creation date,
|
||||
<option>P</option> for the publication date,
|
||||
<option>A</option> for the activation date,
|
||||
<option>R</option> for the revokation date,
|
||||
<option>U</option> for the unpublication date, or
|
||||
<option>R</option> for the revocation date,
|
||||
<option>I</option> for the inactivation date, or
|
||||
<option>D</option> for the deletion date.
|
||||
To print all of the metadata, use <option>-p all</option>.
|
||||
</para>
|
||||
|
||||
@@ -1,20 +1,19 @@
|
||||
<!--
|
||||
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: dnssec-settime.html,v 1.9 2009/11/03 21:58:30 tbox Exp $ -->
|
||||
<!-- $Id: dnssec-settime.html,v 1.9.24.7 2011/03/22 02:10:55 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -32,7 +31,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-settime</code> [<code class="option">-f</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] {keyfile}</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543416"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543422"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-settime</strong></span>
|
||||
reads a DNSSEC private key file and sets the key timing metadata
|
||||
as specified by the <code class="option">-P</code>, <code class="option">-A</code>,
|
||||
@@ -57,7 +56,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543464"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543470"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-f</span></dt>
|
||||
<dd><p>
|
||||
@@ -66,7 +65,9 @@
|
||||
fail when attempting to update a legacy key. With this option,
|
||||
the key will be recreated in the new format, but with the
|
||||
original key data retained. The key's creation date will be
|
||||
set to the present time.
|
||||
set to the present time. If no other values are specified,
|
||||
then the key's publication and activation dates will also
|
||||
be set to the present time.
|
||||
</p></dd>
|
||||
<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd><p>
|
||||
@@ -88,7 +89,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543556"></a><h2>TIMING OPTIONS</h2>
|
||||
<a name="id2543562"></a><h2>TIMING OPTIONS</h2>
|
||||
<p>
|
||||
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
|
||||
If the argument begins with a '+' or '-', it is interpreted as
|
||||
@@ -130,10 +131,44 @@
|
||||
date, the key will no longer be included in the zone. (It
|
||||
may remain in the key repository, however.)
|
||||
</p></dd>
|
||||
<dt><span class="term">-S <em class="replaceable"><code>predecessor key</code></em></span></dt>
|
||||
<dd><p>
|
||||
Select a key for which the key being modified will be an
|
||||
explicit successor. The name, algorithm, size, and type of the
|
||||
predecessor key must exactly match those of the key being
|
||||
modified. The activation date of the successor key will be set
|
||||
to the inactivation date of the predecessor. The publication
|
||||
date will be set to the activation date minus the prepublication
|
||||
interval, which defaults to 30 days.
|
||||
</p></dd>
|
||||
<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the prepublication interval for a key. If set, then
|
||||
the publication and activation dates must be separated by at least
|
||||
this much time. If the activation date is specified but the
|
||||
publication date isn't, then the publication date will default
|
||||
to this much time before the activation date; conversely, if
|
||||
the publication date is specified but activation date isn't,
|
||||
then activation will be set to this much time after publication.
|
||||
</p>
|
||||
<p>
|
||||
If the key is being set to be an explicit successor to another
|
||||
key, then the default prepublication interval is 30 days;
|
||||
otherwise it is zero.
|
||||
</p>
|
||||
<p>
|
||||
As with date offsets, if the argument is followed by one of
|
||||
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
|
||||
interval is measured in years, months, weeks, days, hours,
|
||||
or minutes, respectively. Without a suffix, the interval is
|
||||
measured in seconds.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543654"></a><h2>PRINTING OPTIONS</h2>
|
||||
<a name="id2543701"></a><h2>PRINTING OPTIONS</h2>
|
||||
<p>
|
||||
<span><strong class="command">dnssec-settime</strong></span> can also be used to print the
|
||||
timing metadata associated with a key.
|
||||
@@ -143,7 +178,7 @@
|
||||
<dd><p>
|
||||
Print times in UNIX epoch format.
|
||||
</p></dd>
|
||||
<dt><span class="term">-p <em class="replaceable"><code>C/P/A/R/U/D/all</code></em></span></dt>
|
||||
<dt><span class="term">-p <em class="replaceable"><code>C/P/A/R/I/D/all</code></em></span></dt>
|
||||
<dd><p>
|
||||
Print a specific metadata value or set of metadata values.
|
||||
The <code class="option">-p</code> option may be followed by one or more
|
||||
@@ -151,15 +186,15 @@
|
||||
<code class="option">C</code> for the creation date,
|
||||
<code class="option">P</code> for the publication date,
|
||||
<code class="option">A</code> for the activation date,
|
||||
<code class="option">R</code> for the revokation date,
|
||||
<code class="option">U</code> for the unpublication date, or
|
||||
<code class="option">R</code> for the revocation date,
|
||||
<code class="option">I</code> for the inactivation date, or
|
||||
<code class="option">D</code> for the deletion date.
|
||||
To print all of the metadata, use <code class="option">-p all</code>.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543732"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2543915"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
|
||||
@@ -167,7 +202,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543765"></a><h2>AUTHOR</h2>
|
||||
<a name="id2543948"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
+162
-104
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Portions Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -29,7 +29,7 @@
|
||||
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: dnssec-signzone.c,v 1.258.4.2 2010/01/05 23:47:58 tbox Exp $ */
|
||||
/* $Id: dnssec-signzone.c,v 1.258.4.11 2011/05/07 00:24:13 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -338,7 +338,7 @@ keythatsigned(dns_rdata_rrsig_t *rrsig) {
|
||||
} else {
|
||||
dns_dnsseckey_create(mctx, &pubkey, &key);
|
||||
}
|
||||
key->force_publish = ISC_TRUE;
|
||||
key->force_publish = ISC_FALSE;
|
||||
key->force_sign = ISC_FALSE;
|
||||
ISC_LIST_APPEND(keylist, key, link);
|
||||
|
||||
@@ -486,32 +486,32 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
||||
if (!expired)
|
||||
keep = ISC_TRUE;
|
||||
} else if (issigningkey(key)) {
|
||||
if (!expired && setverifies(name, set, key->key,
|
||||
&sigrdata)) {
|
||||
if (!expired && rrsig.originalttl == set->ttl &&
|
||||
setverifies(name, set, key->key, &sigrdata)) {
|
||||
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
||||
keep = ISC_TRUE;
|
||||
wassignedby[key->index] = ISC_TRUE;
|
||||
nowsignedby[key->index] = ISC_TRUE;
|
||||
} else {
|
||||
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
||||
sigstr,
|
||||
expired ? "expired" :
|
||||
"failed to verify");
|
||||
sigstr, expired ? "expired" :
|
||||
rrsig.originalttl != set->ttl ?
|
||||
"ttl change" : "failed to verify");
|
||||
wassignedby[key->index] = ISC_TRUE;
|
||||
resign = ISC_TRUE;
|
||||
}
|
||||
} else if (iszonekey(key)) {
|
||||
if (!expired && setverifies(name, set, key->key,
|
||||
&sigrdata)) {
|
||||
if (!expired && rrsig.originalttl == set->ttl &&
|
||||
setverifies(name, set, key->key, &sigrdata)) {
|
||||
vbprintf(2, "\trrsig by %s retained\n", sigstr);
|
||||
keep = ISC_TRUE;
|
||||
wassignedby[key->index] = ISC_TRUE;
|
||||
nowsignedby[key->index] = ISC_TRUE;
|
||||
} else {
|
||||
vbprintf(2, "\trrsig by %s dropped - %s\n",
|
||||
sigstr,
|
||||
expired ? "expired" :
|
||||
"failed to verify");
|
||||
sigstr, expired ? "expired" :
|
||||
rrsig.originalttl != set->ttl ?
|
||||
"ttl change" : "failed to verify");
|
||||
wassignedby[key->index] = ISC_TRUE;
|
||||
}
|
||||
} else if (!expired) {
|
||||
@@ -522,7 +522,8 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
|
||||
}
|
||||
|
||||
if (keep) {
|
||||
nowsignedby[key->index] = ISC_TRUE;
|
||||
if (key != NULL)
|
||||
nowsignedby[key->index] = ISC_TRUE;
|
||||
INCSTAT(nretained);
|
||||
if (sigset.ttl != ttl) {
|
||||
vbprintf(2, "\tfixing ttl %s\n", sigstr);
|
||||
@@ -1387,6 +1388,13 @@ verifyset(dns_rdataset_t *rdataset, dns_name_t *name, dns_dbnode_t *node,
|
||||
|
||||
dns_rdataset_current(&sigrdataset, &rdata);
|
||||
dns_rdata_tostruct(&rdata, &sig, NULL);
|
||||
if (rdataset->ttl != sig.originalttl) {
|
||||
dns_name_format(name, namebuf, sizeof(namebuf));
|
||||
type_format(rdataset->type, typebuf, sizeof(typebuf));
|
||||
fprintf(stderr, "TTL mismatch for %s %s keytag %u\n",
|
||||
namebuf, typebuf, sig.keyid);
|
||||
continue;
|
||||
}
|
||||
if ((set_algorithms[sig.algorithm] != 0) ||
|
||||
(ksk_algorithms[sig.algorithm] == 0))
|
||||
continue;
|
||||
@@ -1443,14 +1451,14 @@ verifynode(dns_name_t *name, dns_dbnode_t *node, isc_boolean_t delegation,
|
||||
/*%
|
||||
* Verify that certain things are sane:
|
||||
*
|
||||
* The apex has a DNSKEY record with at least one KSK, and at least
|
||||
* The apex has a DNSKEY RRset with at least one KSK, and at least
|
||||
* one ZSK if the -x flag was not used.
|
||||
*
|
||||
* The DNSKEY record was signed with at least one of the KSKs in this
|
||||
* set.
|
||||
* The DNSKEY record was signed with at least one of the KSKs in
|
||||
* the DNSKEY RRset.
|
||||
*
|
||||
* The rest of the zone was signed with at least one of the ZSKs
|
||||
* present in the DNSKEY RRSET.
|
||||
* present in the DNSKEY RRset.
|
||||
*/
|
||||
static void
|
||||
verifyzone(void) {
|
||||
@@ -1461,13 +1469,12 @@ verifyzone(void) {
|
||||
dns_name_t *name, *nextname, *zonecut;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
dns_rdataset_t rdataset;
|
||||
dns_rdataset_t sigrdataset;
|
||||
dns_rdataset_t keyset, soaset;
|
||||
dns_rdataset_t keysigs, soasigs;
|
||||
int i;
|
||||
isc_boolean_t done = ISC_FALSE;
|
||||
isc_boolean_t first = ISC_TRUE;
|
||||
isc_boolean_t goodksk = ISC_FALSE;
|
||||
isc_boolean_t goodzsk = ISC_FALSE;
|
||||
isc_result_t result;
|
||||
unsigned char revoked_ksk[256];
|
||||
unsigned char revoked_zsk[256];
|
||||
@@ -1489,18 +1496,30 @@ verifyzone(void) {
|
||||
fatal("failed to find the zone's origin: %s",
|
||||
isc_result_totext(result));
|
||||
|
||||
dns_rdataset_init(&rdataset);
|
||||
dns_rdataset_init(&sigrdataset);
|
||||
dns_rdataset_init(&keyset);
|
||||
dns_rdataset_init(&keysigs);
|
||||
dns_rdataset_init(&soaset);
|
||||
dns_rdataset_init(&soasigs);
|
||||
|
||||
result = dns_db_findrdataset(gdb, node, gversion,
|
||||
dns_rdatatype_dnskey,
|
||||
0, 0, &rdataset, &sigrdataset);
|
||||
dns_db_detachnode(gdb, &node);
|
||||
0, 0, &keyset, &keysigs);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot find DNSKEY rrset\n");
|
||||
|
||||
if (!dns_rdataset_isassociated(&sigrdataset))
|
||||
result = dns_db_findrdataset(gdb, node, gversion,
|
||||
dns_rdatatype_soa,
|
||||
0, 0, &soaset, &soasigs);
|
||||
dns_db_detachnode(gdb, &node);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("cannot find SOA rrset\n");
|
||||
|
||||
if (!dns_rdataset_isassociated(&keysigs))
|
||||
fatal("cannot find DNSKEY RRSIGs\n");
|
||||
|
||||
if (!dns_rdataset_isassociated(&soasigs))
|
||||
fatal("cannot find SOA RRSIGs\n");
|
||||
|
||||
memset(revoked_ksk, 0, sizeof(revoked_ksk));
|
||||
memset(revoked_zsk, 0, sizeof(revoked_zsk));
|
||||
memset(standby_ksk, 0, sizeof(standby_ksk));
|
||||
@@ -1517,10 +1536,10 @@ verifyzone(void) {
|
||||
* and one ZSK per algorithm in it (or, if -x was used, one
|
||||
* self-signing KSK).
|
||||
*/
|
||||
for (result = dns_rdataset_first(&rdataset);
|
||||
for (result = dns_rdataset_first(&keyset);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdataset_next(&rdataset)) {
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
result = dns_rdataset_next(&keyset)) {
|
||||
dns_rdataset_current(&keyset, &rdata);
|
||||
result = dns_rdata_tostruct(&rdata, &dnskey, NULL);
|
||||
check_result(result, "dns_rdata_tostruct");
|
||||
|
||||
@@ -1528,8 +1547,8 @@ verifyzone(void) {
|
||||
;
|
||||
else if ((dnskey.flags & DNS_KEYFLAG_REVOKE) != 0) {
|
||||
if ((dnskey.flags & DNS_KEYFLAG_KSK) != 0 &&
|
||||
!dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
|
||||
&sigrdataset, ISC_FALSE,
|
||||
!dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
|
||||
&keysigs, ISC_FALSE,
|
||||
mctx)) {
|
||||
char namebuf[DNS_NAME_FORMATSIZE];
|
||||
char buffer[1024];
|
||||
@@ -1551,8 +1570,8 @@ verifyzone(void) {
|
||||
revoked_zsk[dnskey.algorithm] != 255)
|
||||
revoked_zsk[dnskey.algorithm]++;
|
||||
} else if ((dnskey.flags & DNS_KEYFLAG_KSK) != 0) {
|
||||
if (dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
|
||||
&sigrdataset, ISC_FALSE, mctx)) {
|
||||
if (dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
|
||||
&keysigs, ISC_FALSE, mctx)) {
|
||||
if (ksk_algorithms[dnskey.algorithm] != 255)
|
||||
ksk_algorithms[dnskey.algorithm]++;
|
||||
goodksk = ISC_TRUE;
|
||||
@@ -1560,8 +1579,8 @@ verifyzone(void) {
|
||||
if (standby_ksk[dnskey.algorithm] != 255)
|
||||
standby_ksk[dnskey.algorithm]++;
|
||||
}
|
||||
} else if (dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
|
||||
&sigrdataset, ISC_FALSE,
|
||||
} else if (dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
|
||||
&keysigs, ISC_FALSE,
|
||||
mctx)) {
|
||||
#ifdef ALLOW_KSKLESS_ZONES
|
||||
if (self_algorithms[dnskey.algorithm] != 255)
|
||||
@@ -1569,7 +1588,10 @@ verifyzone(void) {
|
||||
#endif
|
||||
if (zsk_algorithms[dnskey.algorithm] != 255)
|
||||
zsk_algorithms[dnskey.algorithm]++;
|
||||
goodzsk = ISC_TRUE;
|
||||
} else if (dns_dnssec_signs(&rdata, gorigin, &soaset,
|
||||
&soasigs, ISC_FALSE, mctx)) {
|
||||
if (zsk_algorithms[dnskey.algorithm] != 255)
|
||||
zsk_algorithms[dnskey.algorithm]++;
|
||||
} else {
|
||||
if (standby_zsk[dnskey.algorithm] != 255)
|
||||
standby_zsk[dnskey.algorithm]++;
|
||||
@@ -1580,7 +1602,9 @@ verifyzone(void) {
|
||||
dns_rdata_freestruct(&dnskey);
|
||||
dns_rdata_reset(&rdata);
|
||||
}
|
||||
dns_rdataset_disassociate(&sigrdataset);
|
||||
dns_rdataset_disassociate(&keysigs);
|
||||
dns_rdataset_disassociate(&soaset);
|
||||
dns_rdataset_disassociate(&soasigs);
|
||||
|
||||
#ifdef ALLOW_KSKLESS_ZONES
|
||||
if (!goodksk) {
|
||||
@@ -1595,7 +1619,7 @@ verifyzone(void) {
|
||||
}
|
||||
#else
|
||||
if (!goodksk) {
|
||||
fatal("no self signed KSK's found");
|
||||
fatal("No self signed KSK's found");
|
||||
}
|
||||
#endif
|
||||
|
||||
@@ -1655,12 +1679,21 @@ verifyzone(void) {
|
||||
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
if (!dns_name_issubdomain(name, gorigin)) {
|
||||
dns_db_detachnode(gdb, &node);
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
if (result == ISC_R_NOMORE)
|
||||
done = ISC_TRUE;
|
||||
else
|
||||
check_result(result, "dns_dbiterator_next()");
|
||||
continue;
|
||||
}
|
||||
if (delegation(name, node, NULL)) {
|
||||
zonecut = dns_fixedname_name(&fzonecut);
|
||||
dns_name_copy(name, zonecut, NULL);
|
||||
isdelegation = ISC_TRUE;
|
||||
}
|
||||
verifynode(name, node, isdelegation, &rdataset,
|
||||
verifynode(name, node, isdelegation, &keyset,
|
||||
ksk_algorithms, bad_algorithms);
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
nextnode = NULL;
|
||||
@@ -1697,13 +1730,13 @@ verifyzone(void) {
|
||||
result = dns_dbiterator_next(dbiter) ) {
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
verifynode(name, node, ISC_FALSE, &rdataset,
|
||||
verifynode(name, node, ISC_FALSE, &keyset,
|
||||
ksk_algorithms, bad_algorithms);
|
||||
dns_db_detachnode(gdb, &node);
|
||||
}
|
||||
dns_dbiterator_destroy(&dbiter);
|
||||
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
dns_rdataset_disassociate(&keyset);
|
||||
|
||||
/*
|
||||
* If we made it this far, we have what we consider a properly signed
|
||||
@@ -1990,6 +2023,46 @@ add_ds(dns_name_t *name, dns_dbnode_t *node, isc_uint32_t nsttl) {
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Remove records of the given type and their signatures.
|
||||
*/
|
||||
static void
|
||||
remove_records(dns_dbnode_t *node, dns_rdatatype_t which) {
|
||||
isc_result_t result;
|
||||
dns_rdatatype_t type, covers;
|
||||
dns_rdatasetiter_t *rdsiter = NULL;
|
||||
dns_rdataset_t rdataset;
|
||||
|
||||
dns_rdataset_init(&rdataset);
|
||||
|
||||
/*
|
||||
* Delete any records of the given type at the apex.
|
||||
*/
|
||||
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
|
||||
check_result(result, "dns_db_allrdatasets()");
|
||||
for (result = dns_rdatasetiter_first(rdsiter);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdatasetiter_next(rdsiter)) {
|
||||
dns_rdatasetiter_current(rdsiter, &rdataset);
|
||||
type = rdataset.type;
|
||||
covers = rdataset.covers;
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
if (type == which || covers == which) {
|
||||
if (which == dns_rdatatype_nsec && !update_chain)
|
||||
fatal("Zone contains NSEC records. Use -u "
|
||||
"to update to NSEC3.");
|
||||
if (which == dns_rdatatype_nsec3param && !update_chain)
|
||||
fatal("Zone contains NSEC3 chains. Use -u "
|
||||
"to update to NSEC.");
|
||||
result = dns_db_deleterdataset(gdb, node, gversion,
|
||||
type, covers);
|
||||
check_result(result, "dns_db_deleterdataset()");
|
||||
continue;
|
||||
}
|
||||
}
|
||||
dns_rdatasetiter_destroy(&rdsiter);
|
||||
}
|
||||
|
||||
/*%
|
||||
* Generate NSEC records for the zone and remove NSEC3/NSEC3PARAM records.
|
||||
*/
|
||||
@@ -2049,36 +2122,25 @@ nsecify(void) {
|
||||
result = dns_dbiterator_first(dbiter);
|
||||
check_result(result, "dns_dbiterator_first()");
|
||||
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
|
||||
/*
|
||||
* Delete any NSEC3PARAM records at the apex.
|
||||
*/
|
||||
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
|
||||
check_result(result, "dns_db_allrdatasets()");
|
||||
for (result = dns_rdatasetiter_first(rdsiter);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdatasetiter_next(rdsiter)) {
|
||||
dns_rdatasetiter_current(rdsiter, &rdataset);
|
||||
type = rdataset.type;
|
||||
covers = rdataset.covers;
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
if (type == dns_rdatatype_nsec3param ||
|
||||
covers == dns_rdatatype_nsec3param) {
|
||||
result = dns_db_deleterdataset(gdb, node, gversion,
|
||||
type, covers);
|
||||
check_result(result,
|
||||
"dns_db_deleterdataset(nsec3param/rrsig)");
|
||||
continue;
|
||||
}
|
||||
}
|
||||
dns_rdatasetiter_destroy(&rdsiter);
|
||||
dns_db_detachnode(gdb, &node);
|
||||
|
||||
while (!done) {
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
/*
|
||||
* Skip out-of-zone records.
|
||||
*/
|
||||
if (!dns_name_issubdomain(name, gorigin)) {
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
if (result == ISC_R_NOMORE)
|
||||
done = ISC_TRUE;
|
||||
else
|
||||
check_result(result, "dns_dbiterator_next()");
|
||||
dns_db_detachnode(gdb, &node);
|
||||
continue;
|
||||
}
|
||||
|
||||
if (dns_name_equal(name, gorigin))
|
||||
remove_records(node, dns_rdatatype_nsec3param);
|
||||
|
||||
if (delegation(name, node, &nsttl)) {
|
||||
zonecut = dns_fixedname_name(&fzonecut);
|
||||
dns_name_copy(name, zonecut, NULL);
|
||||
@@ -2154,6 +2216,7 @@ addnsec3param(const unsigned char *salt, size_t salt_length,
|
||||
result = dns_rdata_fromstruct(&rdata, gclass,
|
||||
dns_rdatatype_nsec3param,
|
||||
&nsec3param, &b);
|
||||
check_result(result, "dns_rdata_fromstruct()");
|
||||
rdatalist.rdclass = rdata.rdclass;
|
||||
rdatalist.type = rdata.type;
|
||||
rdatalist.covers = 0;
|
||||
@@ -2451,8 +2514,6 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
|
||||
dns_fixedname_t fname, fnextname, fzonecut;
|
||||
dns_name_t *name, *nextname, *zonecut;
|
||||
dns_rdataset_t rdataset;
|
||||
dns_rdatasetiter_t *rdsiter = NULL;
|
||||
dns_rdatatype_t type, covers;
|
||||
int order;
|
||||
isc_boolean_t active;
|
||||
isc_boolean_t done = ISC_FALSE;
|
||||
@@ -2477,40 +2538,25 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
|
||||
result = dns_dbiterator_first(dbiter);
|
||||
check_result(result, "dns_dbiterator_first()");
|
||||
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
|
||||
/*
|
||||
* Delete any NSEC records at the apex.
|
||||
*/
|
||||
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
|
||||
check_result(result, "dns_db_allrdatasets()");
|
||||
for (result = dns_rdatasetiter_first(rdsiter);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdatasetiter_next(rdsiter)) {
|
||||
dns_rdatasetiter_current(rdsiter, &rdataset);
|
||||
type = rdataset.type;
|
||||
covers = rdataset.covers;
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
if (type == dns_rdatatype_nsec ||
|
||||
covers == dns_rdatatype_nsec) {
|
||||
if (!update_chain)
|
||||
fatal("Zone contains NSEC records. Use -u "
|
||||
"to update to NSEC3.");
|
||||
|
||||
result = dns_db_deleterdataset(gdb, node, gversion,
|
||||
type, covers);
|
||||
check_result(result,
|
||||
"dns_db_deleterdataset(nsec3param/rrsig)");
|
||||
continue;
|
||||
}
|
||||
}
|
||||
dns_rdatasetiter_destroy(&rdsiter);
|
||||
dns_db_detachnode(gdb, &node);
|
||||
|
||||
while (!done) {
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
/*
|
||||
* Skip out-of-zone records.
|
||||
*/
|
||||
if (!dns_name_issubdomain(name, gorigin)) {
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
if (result == ISC_R_NOMORE)
|
||||
done = ISC_TRUE;
|
||||
else
|
||||
check_result(result, "dns_dbiterator_next()");
|
||||
dns_db_detachnode(gdb, &node);
|
||||
continue;
|
||||
}
|
||||
|
||||
if (dns_name_equal(name, gorigin))
|
||||
remove_records(node, dns_rdatatype_nsec);
|
||||
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
nextnode = NULL;
|
||||
while (result == ISC_R_SUCCESS) {
|
||||
@@ -2627,6 +2673,18 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
|
||||
while (!done) {
|
||||
result = dns_dbiterator_current(dbiter, &node, name);
|
||||
check_dns_dbiterator_current(result);
|
||||
/*
|
||||
* Skip out-of-zone records.
|
||||
*/
|
||||
if (!dns_name_issubdomain(name, gorigin)) {
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
if (result == ISC_R_NOMORE)
|
||||
done = ISC_TRUE;
|
||||
else
|
||||
check_result(result, "dns_dbiterator_next()");
|
||||
dns_db_detachnode(gdb, &node);
|
||||
continue;
|
||||
}
|
||||
result = dns_dbiterator_next(dbiter);
|
||||
nextnode = NULL;
|
||||
while (result == ISC_R_SUCCESS) {
|
||||
@@ -2768,7 +2826,7 @@ loadzonekeys(isc_boolean_t preserve_keys, isc_boolean_t load_public) {
|
||||
}
|
||||
keyttl = rdataset.ttl;
|
||||
|
||||
/* Load keys corresponding to the existing DNSKEY RRset */
|
||||
/* Load keys corresponding to the existing DNSKEY RRset. */
|
||||
result = dns_dnssec_keylistfromrdataset(gorigin, directory, mctx,
|
||||
&rdataset, &keysigs, &soasigs,
|
||||
preserve_keys, load_public,
|
||||
@@ -3772,6 +3830,8 @@ main(int argc, char *argv[]) {
|
||||
nokeys = ISC_TRUE;
|
||||
}
|
||||
|
||||
warnifallksk(gdb);
|
||||
|
||||
if (IS_NSEC3) {
|
||||
unsigned int max;
|
||||
result = dns_nsec3_maxiterations(gdb, NULL, mctx, &max);
|
||||
@@ -3781,8 +3841,6 @@ main(int argc, char *argv[]) {
|
||||
"strength. Maximum iterations allowed %u.", max);
|
||||
}
|
||||
|
||||
warnifallksk(gdb);
|
||||
|
||||
gversion = NULL;
|
||||
result = dns_db_newversion(gdb, &gversion);
|
||||
check_result(result, "dns_db_newversion()");
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2002 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.109 2009/12/05 23:31:40 each Exp $
|
||||
# $Id: Makefile.in,v 1.109.2.3 2010/11/18 23:22:45 marka Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -118,7 +118,7 @@ main.@O@: main.c
|
||||
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
|
||||
-DNS_SYSCONFDIR=\"${sysconfdir}\" -c ${srcdir}/main.c
|
||||
|
||||
bind.keys.h: ${top_srcdir}/bind.keys
|
||||
bind.keys.h: ${top_srcdir}/bind.keys ${top_srcdir}/bind.keys
|
||||
${PERL} ${srcdir}/bindkeys.pl < ${top_srcdir}/bind.keys > $@
|
||||
|
||||
config.@O@: config.c bind.keys.h
|
||||
@@ -143,7 +143,10 @@ docclean manclean maintainer-clean::
|
||||
rm -f ${MANOBJS}
|
||||
|
||||
clean distclean maintainer-clean::
|
||||
rm -f ${TARGETS} ${OBJS} bind.keys.h
|
||||
rm -f ${TARGETS} ${OBJS}
|
||||
|
||||
maintainer-clean::
|
||||
rm -f bind.keys.h
|
||||
|
||||
bind9.xsl.h: bind9.xsl ${srcdir}/convertxsl.pl
|
||||
${PERL} ${srcdir}/convertxsl.pl < ${srcdir}/bind9.xsl > bind9.xsl.h
|
||||
|
||||
+96
-8
@@ -1,17 +1,105 @@
|
||||
/*
|
||||
* Generated by bindkeys.pl 1.3.104.2 2010-06-20 23:46:24 tbox Exp
|
||||
* From bind.keys 1.5.42.3 2011-03-25 17:46:40 each Exp
|
||||
*/
|
||||
#define TRUSTED_KEYS "\
|
||||
# The bind.keys file is used to override built-in DNSSEC trust anchors\n\
|
||||
# which are included as part of BIND 9. As of the current release (BIND\n\
|
||||
# 9.7), the only trust anchor it sets is the one for the ISC DNSSEC\n\
|
||||
# Lookaside Validation zone (\"dlv.isc.org\"). Trust anchors for any other\n\
|
||||
# zones MUST be configured elsewhere; if they are configured here, they\n\
|
||||
# will not be recognized or used by named.\n\
|
||||
#\n\
|
||||
# This file also contains a copy of the trust anchor for the DNS root zone\n\
|
||||
# (\".\"). However, named does not use it; it is provided here for\n\
|
||||
# informational purposes only. To switch on DNSSEC validation at the\n\
|
||||
# root, the root key below can be copied into named.conf.\n\
|
||||
#\n\
|
||||
# The built-in DLV trust anchor in this file is used directly by named.\n\
|
||||
# However, it is not activated unless specifically switched on. To use\n\
|
||||
# the DLV key, set \"dnssec-lookaside auto;\" in the named.conf options.\n\
|
||||
# Without this option being set, the key in this file is ignored.\n\
|
||||
#\n\
|
||||
# This file is NOT expected to be user-configured.\n\
|
||||
#\n\
|
||||
# These keys are current as of January 2011. If any key fails to\n\
|
||||
# initialize correctly, it may have expired. In that event you should\n\
|
||||
# replace this file with a current version. The latest version of\n\
|
||||
# bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
|
||||
\n\
|
||||
trusted-keys {\n\
|
||||
# NOTE: This key is current as of October 2009.\n\
|
||||
# If it fails to initialize correctly, it may have expired;\n\
|
||||
# see https://www.isc.org/solutions/dlv for a replacement.\n\
|
||||
dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2 brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+ 1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5 ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt TDN0YUuWrBNh\";\n\
|
||||
# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
|
||||
# NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
|
||||
# in named.conf.\n\
|
||||
dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
|
||||
brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
|
||||
1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
|
||||
ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
|
||||
Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
|
||||
QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
|
||||
TDN0YUuWrBNh\";\n\
|
||||
\n\
|
||||
# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
|
||||
# for current trust anchor information.\n\
|
||||
# NOTE: This key not active; to use it, copy it into a managed-keys\n\
|
||||
# statement in named.conf\n\
|
||||
. initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
|
||||
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
|
||||
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
|
||||
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
|
||||
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
|
||||
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
|
||||
QxA+Uk1ihz0=\";\n\
|
||||
};\n\
|
||||
"
|
||||
|
||||
#define MANAGED_KEYS "\
|
||||
# The bind.keys file is used to override built-in DNSSEC trust anchors\n\
|
||||
# which are included as part of BIND 9. As of the current release (BIND\n\
|
||||
# 9.7), the only trust anchor it sets is the one for the ISC DNSSEC\n\
|
||||
# Lookaside Validation zone (\"dlv.isc.org\"). Trust anchors for any other\n\
|
||||
# zones MUST be configured elsewhere; if they are configured here, they\n\
|
||||
# will not be recognized or used by named.\n\
|
||||
#\n\
|
||||
# This file also contains a copy of the trust anchor for the DNS root zone\n\
|
||||
# (\".\"). However, named does not use it; it is provided here for\n\
|
||||
# informational purposes only. To switch on DNSSEC validation at the\n\
|
||||
# root, the root key below can be copied into named.conf.\n\
|
||||
#\n\
|
||||
# The built-in DLV trust anchor in this file is used directly by named.\n\
|
||||
# However, it is not activated unless specifically switched on. To use\n\
|
||||
# the DLV key, set \"dnssec-lookaside auto;\" in the named.conf options.\n\
|
||||
# Without this option being set, the key in this file is ignored.\n\
|
||||
#\n\
|
||||
# This file is NOT expected to be user-configured.\n\
|
||||
#\n\
|
||||
# These keys are current as of January 2011. If any key fails to\n\
|
||||
# initialize correctly, it may have expired. In that event you should\n\
|
||||
# replace this file with a current version. The latest version of\n\
|
||||
# bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
|
||||
\n\
|
||||
managed-keys {\n\
|
||||
# NOTE: This key is current as of October 2009.\n\
|
||||
# If it fails to initialize correctly, it may have expired;\n\
|
||||
# see https://www.isc.org/solutions/dlv for a replacement.\n\
|
||||
dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2 brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+ 1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5 ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt TDN0YUuWrBNh\";\n\
|
||||
# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
|
||||
# NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
|
||||
# in named.conf.\n\
|
||||
dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
|
||||
brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
|
||||
1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
|
||||
ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
|
||||
Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
|
||||
QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
|
||||
TDN0YUuWrBNh\";\n\
|
||||
\n\
|
||||
# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
|
||||
# for current trust anchor information.\n\
|
||||
# NOTE: This key not active; to use it, copy it into a managed-keys\n\
|
||||
# statement in named.conf\n\
|
||||
. initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
|
||||
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
|
||||
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
|
||||
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
|
||||
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
|
||||
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
|
||||
QxA+Uk1ihz0=\";\n\
|
||||
};\n\
|
||||
"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* Generated by convertxsl.pl 1.14 2008/07/17 23:43:26 jinmei Exp
|
||||
* From bind9.xsl 1.21 2009/01/27 23:47:54 tbox Exp
|
||||
* Generated by convertxsl.pl 1.14 2008-07-17 23:43:26 jinmei Exp
|
||||
* From bind9.xsl 1.21 2009-01-27 23:47:54 tbox Exp
|
||||
*/
|
||||
static char xslmsg[] =
|
||||
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n"
|
||||
@@ -20,7 +20,7 @@ static char xslmsg[] =
|
||||
" - PERFORMANCE OF THIS SOFTWARE.\n"
|
||||
"-->\n"
|
||||
"\n"
|
||||
"<!-- \045Id: bind9.xsl,v 1.21 2009/01/27 23:47:54 tbox Exp \045 -->\n"
|
||||
"<!-- \045Id: bind9.xsl,v 1.21 2009-01-27 23:47:54 tbox Exp \045 -->\n"
|
||||
"\n"
|
||||
"<xsl:stylesheet version=\"1.0\"\n"
|
||||
" xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\"\n"
|
||||
|
||||
+20
-2
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env perl
|
||||
#
|
||||
# Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,19 +14,37 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: bindkeys.pl,v 1.3 2009/09/01 07:14:25 each Exp $
|
||||
# $Id: bindkeys.pl,v 1.3.104.2 2010/06/20 23:46:24 tbox Exp $
|
||||
|
||||
use strict;
|
||||
use warnings;
|
||||
|
||||
my $rev = '$Id: bindkeys.pl,v 1.3.104.2 2010/06/20 23:46:24 tbox Exp $';
|
||||
$rev =~ s/\$//g;
|
||||
$rev =~ s/,v//g;
|
||||
$rev =~ s/Id: //;
|
||||
|
||||
my $keys = "";
|
||||
|
||||
my $lines;
|
||||
while (<>) {
|
||||
chomp;
|
||||
if (/\/\* .Id:.* \*\//) {
|
||||
$keys = $_;
|
||||
next;
|
||||
}
|
||||
s/\"/\\\"/g;
|
||||
s/$/\\n\\/;
|
||||
$lines .= $_ . "\n";
|
||||
}
|
||||
|
||||
$keys =~ s/\$//g;
|
||||
$keys =~ s/\/\* Id: //;
|
||||
$keys =~ s/\*\/.*//;
|
||||
$keys =~ s/,v//;
|
||||
|
||||
print "/*\n * Generated by $rev \n * From $keys\n */\n";
|
||||
|
||||
my $mkey = '#define MANAGED_KEYS "\\' . "\n" . $lines . "\"\n";
|
||||
|
||||
$lines =~ s/managed-keys/trusted-keys/;
|
||||
|
||||
+3
-2
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: builtin.c,v 1.15 2009/03/01 02:45:38 each Exp $ */
|
||||
/* $Id: builtin.c,v 1.15.154.2 2010/08/03 23:46:17 tbox Exp $ */
|
||||
|
||||
/*! \file
|
||||
* \brief
|
||||
@@ -133,6 +133,7 @@ do_authors_lookup(dns_sdblookup_t *lookup) {
|
||||
"Andreas Gustafsson",
|
||||
"Bob Halley",
|
||||
"Evan Hunt",
|
||||
"JINMEI Tatuya",
|
||||
"David Lawrence",
|
||||
"Danny Mayer",
|
||||
"Damien Neil",
|
||||
|
||||
+6
-4
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: client.c,v 1.266 2009/10/26 23:14:53 each Exp $ */
|
||||
/* $Id: client.c,v 1.266.36.4 2011/05/06 23:46:35 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -633,6 +633,7 @@ ns_client_endrequest(ns_client_t *client) {
|
||||
dns_message_puttemprdataset(client->message, &client->opt);
|
||||
}
|
||||
|
||||
client->signer = NULL;
|
||||
client->udpsize = 512;
|
||||
client->extflags = 0;
|
||||
client->ednsversion = -1;
|
||||
@@ -1865,13 +1866,13 @@ client_request(isc_task_t *task, isc_event_t *event) {
|
||||
client->view->recursionacl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS &&
|
||||
ns_client_checkaclsilent(client, NULL,
|
||||
client->view->queryacl,
|
||||
client->view->cacheacl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS &&
|
||||
ns_client_checkaclsilent(client, &client->destaddr,
|
||||
client->view->recursiononacl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS &&
|
||||
ns_client_checkaclsilent(client, &client->destaddr,
|
||||
client->view->queryonacl,
|
||||
client->view->cacheonacl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS)
|
||||
ra = ISC_TRUE;
|
||||
|
||||
@@ -2093,6 +2094,7 @@ client_create(ns_clientmgr_t *manager, ns_client_t **clientp) {
|
||||
client->next = NULL;
|
||||
client->shutdown = NULL;
|
||||
client->shutdown_arg = NULL;
|
||||
client->signer = NULL;
|
||||
dns_name_init(&client->signername, NULL);
|
||||
client->mortal = ISC_FALSE;
|
||||
client->tcpquota = NULL;
|
||||
|
||||
+6
-14
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: config.c,v 1.106 2009/12/04 21:09:32 marka Exp $ */
|
||||
/* $Id: config.c,v 1.106.4.6 2010/08/11 18:19:54 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -80,6 +80,7 @@ options {\n\
|
||||
bindkeys-file \"" NS_SYSCONFDIR "/bind.keys\";\n\
|
||||
port 53;\n\
|
||||
recursing-file \"named.recursing\";\n\
|
||||
secroots-file \"named.secroots\";\n\
|
||||
"
|
||||
#ifdef PATH_RANDOMDEV
|
||||
"\
|
||||
@@ -158,9 +159,11 @@ options {\n\
|
||||
max-clients-per-query 100;\n\
|
||||
zero-no-soa-ttl-cache no;\n\
|
||||
nsec3-test-zone no;\n\
|
||||
allow-new-zones no;\n\
|
||||
"
|
||||
#ifdef ALLOW_FILTER_AAAA_ON_V4
|
||||
" filter-aaaa-on-v4 no;\n\
|
||||
filter-aaaa { any; };\n\
|
||||
"
|
||||
#endif
|
||||
|
||||
@@ -216,6 +219,7 @@ options {\n\
|
||||
view \"_bind\" chaos {\n\
|
||||
recursion no;\n\
|
||||
notify no;\n\
|
||||
allow-new-zones no;\n\
|
||||
\n\
|
||||
zone \"version.bind\" chaos {\n\
|
||||
type master;\n\
|
||||
@@ -238,18 +242,6 @@ view \"_bind\" chaos {\n\
|
||||
};\n\
|
||||
};\n\
|
||||
"
|
||||
|
||||
"#\n\
|
||||
# The \"_meta\" view is for zones that are used to store internal\n\
|
||||
# information for named, such as managed keys. The zones are defined\n\
|
||||
# elsewhere.\n\
|
||||
#\n\
|
||||
view \"_meta\" in {\n\
|
||||
recursion no;\n\
|
||||
notify no;\n\
|
||||
};\n\
|
||||
"
|
||||
|
||||
"#\n\
|
||||
# Default trusted key(s) for builtin DLV support\n\
|
||||
# (used if \"dnssec-lookaside auto;\" is set and\n\
|
||||
|
||||
+16
-4
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: control.c,v 1.36 2009/10/12 20:48:11 each Exp $ */
|
||||
/* $Id: control.c,v 1.36.50.5 2010/12/03 22:04:49 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -129,11 +129,16 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
|
||||
* isc_app_shutdown below.
|
||||
*/
|
||||
#endif
|
||||
/* Do not flush master files */
|
||||
ns_server_flushonshutdown(ns_g_server, ISC_FALSE);
|
||||
ns_os_shutdownmsg(command, text);
|
||||
isc_app_shutdown();
|
||||
result = ISC_R_SUCCESS;
|
||||
} else if (command_compare(command, NS_COMMAND_STOP)) {
|
||||
/*
|
||||
* "stop" is the same as "halt" except it does
|
||||
* flush master files.
|
||||
*/
|
||||
#ifdef HAVE_LIBSCF
|
||||
if (ns_smf_got_instance == 1 && ns_smf_chroot == 1) {
|
||||
result = ns_smf_add_message(text);
|
||||
@@ -153,6 +158,8 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
|
||||
} else if (command_compare(command, NS_COMMAND_DUMPDB)) {
|
||||
ns_server_dumpdb(ns_g_server, command);
|
||||
result = ISC_R_SUCCESS;
|
||||
} else if (command_compare(command, NS_COMMAND_SECROOTS)) {
|
||||
result = ns_server_dumpsecroots(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_TRACE)) {
|
||||
result = ns_server_setdebuglevel(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_NOTRACE)) {
|
||||
@@ -187,8 +194,13 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
|
||||
result = ns_server_notifycommand(ns_g_server, command, text);
|
||||
} else if (command_compare(command, NS_COMMAND_VALIDATION)) {
|
||||
result = ns_server_validation(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_SIGN)) {
|
||||
result = ns_server_sign(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_SIGN) ||
|
||||
command_compare(command, NS_COMMAND_LOADKEYS)) {
|
||||
result = ns_server_rekey(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_ADDZONE)) {
|
||||
result = ns_server_add_zone(ns_g_server, command);
|
||||
} else if (command_compare(command, NS_COMMAND_DELZONE)) {
|
||||
result = ns_server_del_zone(ns_g_server, command);
|
||||
} else {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_CONTROL, ISC_LOG_WARNING,
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2008, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: controlconf.c,v 1.60 2008/07/23 23:27:54 marka Exp $ */
|
||||
/* $Id: controlconf.c,v 1.60.290.2 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -859,7 +859,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
|
||||
cfg_obj_log(key, ns_g_lctx, ISC_LOG_WARNING,
|
||||
"secret for key '%s' on command channel: %s",
|
||||
keyid->keyname, isc_result_totext(result));
|
||||
CHECK(result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
keyid->secret.length = isc_buffer_usedlength(&b);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2001-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: control.h,v 1.27 2009/10/12 23:48:01 tbox Exp $ */
|
||||
/* $Id: control.h,v 1.27.50.4 2010/08/16 22:27:16 marka Exp $ */
|
||||
|
||||
#ifndef NAMED_CONTROL_H
|
||||
#define NAMED_CONTROL_H 1
|
||||
@@ -42,6 +42,7 @@
|
||||
#define NS_COMMAND_DUMPSTATS "stats"
|
||||
#define NS_COMMAND_QUERYLOG "querylog"
|
||||
#define NS_COMMAND_DUMPDB "dumpdb"
|
||||
#define NS_COMMAND_SECROOTS "secroots"
|
||||
#define NS_COMMAND_TRACE "trace"
|
||||
#define NS_COMMAND_NOTRACE "notrace"
|
||||
#define NS_COMMAND_FLUSH "flush"
|
||||
@@ -58,6 +59,9 @@
|
||||
#define NS_COMMAND_NOTIFY "notify"
|
||||
#define NS_COMMAND_VALIDATION "validation"
|
||||
#define NS_COMMAND_SIGN "sign"
|
||||
#define NS_COMMAND_LOADKEYS "loadkeys"
|
||||
#define NS_COMMAND_ADDZONE "addzone"
|
||||
#define NS_COMMAND_DELZONE "delzone"
|
||||
|
||||
isc_result_t
|
||||
ns_controls_create(ns_server_t *server, ns_controls_t **ctrlsp);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: globals.h,v 1.86 2009/10/05 17:30:49 fdupont Exp $ */
|
||||
/* $Id: globals.h,v 1.86.60.3 2010/09/15 12:10:53 marka Exp $ */
|
||||
|
||||
#ifndef NAMED_GLOBALS_H
|
||||
#define NAMED_GLOBALS_H 1
|
||||
@@ -149,6 +149,8 @@ EXTERN int ns_g_listen INIT(3);
|
||||
EXTERN isc_time_t ns_g_boottime;
|
||||
EXTERN isc_boolean_t ns_g_memstatistics INIT(ISC_FALSE);
|
||||
EXTERN isc_boolean_t ns_g_clienttest INIT(ISC_FALSE);
|
||||
EXTERN isc_boolean_t ns_g_nosoa INIT(ISC_FALSE);
|
||||
EXTERN isc_boolean_t ns_g_noaa INIT(ISC_FALSE);
|
||||
|
||||
#undef EXTERN
|
||||
#undef INIT
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: query.h,v 1.40 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: query.h,v 1.40.558.2 2010/09/24 08:30:58 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_QUERY_H
|
||||
#define NAMED_QUERY_H 1
|
||||
@@ -71,6 +71,8 @@ struct ns_query {
|
||||
#define NS_QUERYATTR_SECURE 0x0200
|
||||
#define NS_QUERYATTR_NOAUTHORITY 0x0400
|
||||
#define NS_QUERYATTR_NOADDITIONAL 0x0800
|
||||
#define NS_QUERYATTR_CACHEACLOKVALID 0x1000
|
||||
#define NS_QUERYATTR_CACHEACLOK 0x2000
|
||||
|
||||
isc_result_t
|
||||
ns_query_init(ns_client_t *client);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: server.h,v 1.104 2009/11/28 15:57:37 vjs Exp $ */
|
||||
/* $Id: server.h,v 1.104.8.6 2010/08/16 23:46:30 tbox Exp $ */
|
||||
|
||||
#ifndef NAMED_SERVER_H
|
||||
#define NAMED_SERVER_H 1
|
||||
@@ -54,9 +54,8 @@ struct ns_server {
|
||||
dns_acl_t *blackholeacl;
|
||||
char * statsfile; /*%< Statistics file name */
|
||||
char * dumpfile; /*%< Dump file name */
|
||||
char * secrootsfile; /*%< Secroots file name */
|
||||
char * bindkeysfile; /*%< bind.keys file name */
|
||||
isc_boolean_t managedkeys; /*%< A managed-keys
|
||||
statement exists */
|
||||
char * recfile; /*%< Recursive file name */
|
||||
isc_boolean_t version_set; /*%< User has set version */
|
||||
char * version; /*%< User-specified version */
|
||||
@@ -246,6 +245,12 @@ ns_server_dumpstats(ns_server_t *server);
|
||||
isc_result_t
|
||||
ns_server_dumpdb(ns_server_t *server, char *args);
|
||||
|
||||
/*%
|
||||
* Dump the current security roots to the secroots file.
|
||||
*/
|
||||
isc_result_t
|
||||
ns_server_dumpsecroots(ns_server_t *server, char *args);
|
||||
|
||||
/*%
|
||||
* Change or increment the server debug level.
|
||||
*/
|
||||
@@ -290,11 +295,14 @@ ns_server_freeze(ns_server_t *server, isc_boolean_t freeze, char *args,
|
||||
isc_buffer_t *text);
|
||||
|
||||
/*%
|
||||
* Update a zone's DNSKEY set from the key repository, and re-sign the
|
||||
* zone if there were any changes.
|
||||
* Update a zone's DNSKEY set from the key repository. If
|
||||
* the command that triggered the call to this function was "sign",
|
||||
* then force a full signing of the zone. If it was "loadkeys",
|
||||
* then don't sign the zone; any needed changes to signatures can
|
||||
* take place incrementally.
|
||||
*/
|
||||
isc_result_t
|
||||
ns_server_sign(ns_server_t *server, char *args);
|
||||
ns_server_rekey(ns_server_t *server, char *args);
|
||||
|
||||
/*%
|
||||
* Dump the current recursive queries.
|
||||
@@ -314,4 +322,16 @@ ns_add_reserved_dispatch(ns_server_t *server, const isc_sockaddr_t *addr);
|
||||
isc_result_t
|
||||
ns_server_validation(ns_server_t *server, char *args);
|
||||
|
||||
/*%
|
||||
* Add a zone to a running process
|
||||
*/
|
||||
isc_result_t
|
||||
ns_server_add_zone(ns_server_t *server, char *args);
|
||||
|
||||
/*%
|
||||
* Deletes a zone from a running process
|
||||
*/
|
||||
isc_result_t
|
||||
ns_server_del_zone(ns_server_t *server, char *args);
|
||||
|
||||
#endif /* NAMED_SERVER_H */
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: interfacemgr.c,v 1.95 2009/01/17 23:47:42 tbox Exp $ */
|
||||
/* $Id: interfacemgr.c,v 1.95.186.2 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -379,7 +379,7 @@ ns_interface_setup(ns_interfacemgr_t *mgr, isc_sockaddr_t *addr,
|
||||
}
|
||||
}
|
||||
*ifpret = ifp;
|
||||
return (ISC_R_SUCCESS);
|
||||
return (result);
|
||||
|
||||
cleanup_interface:
|
||||
ISC_LIST_UNLINK(ifp->mgr->interfaces, ifp, link);
|
||||
@@ -964,7 +964,6 @@ isc_boolean_t
|
||||
ns_interfacemgr_listeningon(ns_interfacemgr_t *mgr, isc_sockaddr_t *addr) {
|
||||
isc_sockaddr_t *old;
|
||||
|
||||
old = ISC_LIST_HEAD(mgr->listenon);
|
||||
for (old = ISC_LIST_HEAD(mgr->listenon);
|
||||
old != NULL;
|
||||
old = ISC_LIST_NEXT(old, link))
|
||||
|
||||
+35
-22
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2007, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,12 +15,13 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: logconf.c,v 1.42 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: logconf.c,v 1.42.560.3 2011/03/05 23:51:37 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <isc/file.h>
|
||||
#include <isc/offset.h>
|
||||
#include <isc/result.h>
|
||||
#include <isc/stdio.h>
|
||||
@@ -130,7 +131,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
|
||||
}
|
||||
|
||||
type = ISC_LOG_TONULL;
|
||||
|
||||
|
||||
if (fileobj != NULL) {
|
||||
const cfg_obj_t *pathobj = cfg_tuple_get(fileobj, "file");
|
||||
const cfg_obj_t *sizeobj = cfg_tuple_get(fileobj, "size");
|
||||
@@ -140,7 +141,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
|
||||
isc_offset_t size = 0;
|
||||
|
||||
type = ISC_LOG_TOFILE;
|
||||
|
||||
|
||||
if (versionsobj != NULL && cfg_obj_isuint32(versionsobj))
|
||||
versions = cfg_obj_asuint32(versionsobj);
|
||||
if (versionsobj != NULL && cfg_obj_isstring(versionsobj) &&
|
||||
@@ -219,26 +220,38 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
|
||||
|
||||
if (result == ISC_R_SUCCESS && type == ISC_LOG_TOFILE) {
|
||||
FILE *fp;
|
||||
|
||||
/*
|
||||
* Test that the file can be opened, since isc_log_open()
|
||||
* can't effectively report failures when called in
|
||||
* isc_log_doit().
|
||||
*/
|
||||
result = isc_stdio_open(dest.file.name, "a", &fp);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
isc_log_write(ns_g_lctx, CFG_LOGCATEGORY_CONFIG,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"logging channel '%s' file '%s': %s",
|
||||
channelname, dest.file.name,
|
||||
isc_result_totext(result));
|
||||
else
|
||||
(void)isc_stdio_close(fp);
|
||||
|
||||
/*
|
||||
* Allow named to continue by returning success.
|
||||
*/
|
||||
result = ISC_R_SUCCESS;
|
||||
* Test to make sure that file is a plain file.
|
||||
* Fix defect #22771
|
||||
*/
|
||||
result = isc_file_isplainfile(dest.file.name);
|
||||
if (result == ISC_R_SUCCESS ||
|
||||
result == ISC_R_FILENOTFOUND) {
|
||||
/*
|
||||
* Test that the file can be opened, since
|
||||
* isc_log_open() can't effectively report
|
||||
* failures when called in
|
||||
* isc_log_doit().
|
||||
*/
|
||||
result = isc_stdio_open(dest.file.name, "a", &fp);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
syslog(LOG_ERR,
|
||||
"isc_stdio_open '%s' failed: %s",
|
||||
dest.file.name,
|
||||
isc_result_totext(result));
|
||||
fprintf(stderr,
|
||||
"isc_stdio_open '%s' failed: %s",
|
||||
dest.file.name,
|
||||
isc_result_totext(result));
|
||||
} else
|
||||
(void)isc_stdio_close(fp);
|
||||
} else {
|
||||
syslog(LOG_ERR, "isc_file_isplainfile '%s' failed: %s",
|
||||
dest.file.name, isc_result_totext(result));
|
||||
fprintf(stderr, "isc_file_isplainfile '%s' failed: %s",
|
||||
dest.file.name, isc_result_totext(result));
|
||||
}
|
||||
}
|
||||
|
||||
return (result);
|
||||
|
||||
+8
-3
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: main.c,v 1.175 2009/10/05 17:30:49 fdupont Exp $ */
|
||||
/* $Id: main.c,v 1.175.60.6 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -500,13 +500,17 @@ parse_command_line(int argc, char *argv[]) {
|
||||
/* XXXJAB should we make a copy? */
|
||||
ns_g_chrootdir = isc_commandline_argument;
|
||||
break;
|
||||
case 'T':
|
||||
case 'T': /* NOT DOCUMENTED */
|
||||
/*
|
||||
* clienttest: make clients single shot with their
|
||||
* own memory context.
|
||||
*/
|
||||
if (!strcmp(isc_commandline_argument, "clienttest"))
|
||||
ns_g_clienttest = ISC_TRUE;
|
||||
else if (!strcmp(isc_commandline_argument, "nosoa"))
|
||||
ns_g_nosoa = ISC_TRUE;
|
||||
else if (!strcmp(isc_commandline_argument, "noaa"))
|
||||
ns_g_noaa = ISC_TRUE;
|
||||
else if (!strcmp(isc_commandline_argument, "maxudp512"))
|
||||
maxudp = 512;
|
||||
else if (!strcmp(isc_commandline_argument, "maxudp1460"))
|
||||
@@ -542,6 +546,7 @@ parse_command_line(int argc, char *argv[]) {
|
||||
|
||||
argc -= isc_commandline_index;
|
||||
argv += isc_commandline_index;
|
||||
POST(argv);
|
||||
|
||||
if (argc > 0) {
|
||||
usage();
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -12,7 +12,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: named.conf.5,v 1.41 2009/12/04 01:13:44 tbox Exp $
|
||||
.\" $Id: named.conf.5,v 1.41.4.1 2010/05/15 02:41:59 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -310,6 +310,7 @@ options {
|
||||
use\-alt\-transfer\-source \fIboolean\fR;
|
||||
zone\-statistics \fIboolean\fR;
|
||||
key\-directory \fIquoted_string\fR;
|
||||
managed\-keys\-directory \fIquoted_string\fR;
|
||||
auto\-dnssec \fBallow\fR|\fBmaintain\fR|\fBcreate\fR|\fBoff\fR;
|
||||
try\-tcp\-refresh \fIboolean\fR;
|
||||
zero\-no\-soa\-ttl \fIboolean\fR;
|
||||
@@ -569,5 +570,5 @@ zone \fIstring\fR \fIoptional_class\fR {
|
||||
\fBrndc\fR(8),
|
||||
BIND 9 Administrator Reference Manual.
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004\-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004\-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -17,7 +17,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: named.conf.docbook,v 1.44 2009/12/03 23:18:16 each Exp $ -->
|
||||
<!-- $Id: named.conf.docbook,v 1.44.4.2 2010/05/14 23:49:18 tbox Exp $ -->
|
||||
<refentry>
|
||||
<refentryinfo>
|
||||
<date>Aug 13, 2004</date>
|
||||
@@ -42,6 +42,7 @@
|
||||
<year>2007</year>
|
||||
<year>2008</year>
|
||||
<year>2009</year>
|
||||
<year>2010</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
@@ -349,6 +350,7 @@ options {
|
||||
|
||||
zone-statistics <replaceable>boolean</replaceable>;
|
||||
key-directory <replaceable>quoted_string</replaceable>;
|
||||
managed-keys-directory <replaceable>quoted_string</replaceable>;
|
||||
auto-dnssec <constant>allow</constant>|<constant>maintain</constant>|<constant>create</constant>|<constant>off</constant>;
|
||||
try-tcp-refresh <replaceable>boolean</replaceable>;
|
||||
zero-no-soa-ttl <replaceable>boolean</replaceable>;
|
||||
|
||||
+18
-17
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -13,7 +13,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: named.conf.html,v 1.50 2009/12/04 01:13:44 tbox Exp $ -->
|
||||
<!-- $Id: named.conf.html,v 1.50.4.1 2010/05/15 02:41:59 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -31,7 +31,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">named.conf</code> </p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543346"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543349"></a><h2>DESCRIPTION</h2>
|
||||
<p><code class="filename">named.conf</code> is the configuration file
|
||||
for
|
||||
<span><strong class="command">named</strong></span>. Statements are enclosed
|
||||
@@ -50,14 +50,14 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543373"></a><h2>ACL</h2>
|
||||
<a name="id2543377"></a><h2>ACL</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
acl <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
<br>
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543389"></a><h2>KEY</h2>
|
||||
<a name="id2543393"></a><h2>KEY</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
key <em class="replaceable"><code>domain_name</code></em> {<br>
|
||||
algorithm <em class="replaceable"><code>string</code></em>;<br>
|
||||
@@ -66,7 +66,7 @@ key
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543409"></a><h2>MASTERS</h2>
|
||||
<a name="id2543412"></a><h2>MASTERS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
masters <em class="replaceable"><code>string</code></em> [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
|
||||
( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<span class="optional">port <em class="replaceable"><code>integer</code></em></span>] |<br>
|
||||
@@ -75,7 +75,7 @@ masters
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543454"></a><h2>SERVER</h2>
|
||||
<a name="id2543458"></a><h2>SERVER</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
server ( <em class="replaceable"><code>ipv4_address[<span class="optional">/prefixlen</span>]</code></em> | <em class="replaceable"><code>ipv6_address[<span class="optional">/prefixlen</span>]</code></em> ) {<br>
|
||||
bogus <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -97,7 +97,7 @@ server
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543523"></a><h2>TRUSTED-KEYS</h2>
|
||||
<a name="id2543526"></a><h2>TRUSTED-KEYS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
trusted-keys {<br>
|
||||
<em class="replaceable"><code>domain_name</code></em> <em class="replaceable"><code>flags</code></em> <em class="replaceable"><code>protocol</code></em> <em class="replaceable"><code>algorithm</code></em> <em class="replaceable"><code>key</code></em>; ... <br>
|
||||
@@ -105,7 +105,7 @@ trusted-keys
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543548"></a><h2>MANAGED-KEYS</h2>
|
||||
<a name="id2543552"></a><h2>MANAGED-KEYS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
managed-keys {<br>
|
||||
<em class="replaceable"><code>domain_name</code></em> <code class="constant">initial-key</code> <em class="replaceable"><code>flags</code></em> <em class="replaceable"><code>protocol</code></em> <em class="replaceable"><code>algorithm</code></em> <em class="replaceable"><code>key</code></em>; ... <br>
|
||||
@@ -113,7 +113,7 @@ managed-keys
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543577"></a><h2>CONTROLS</h2>
|
||||
<a name="id2543580"></a><h2>CONTROLS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
controls {<br>
|
||||
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> | * )<br>
|
||||
@@ -125,7 +125,7 @@ controls
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543612"></a><h2>LOGGING</h2>
|
||||
<a name="id2543616"></a><h2>LOGGING</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
logging {<br>
|
||||
channel <em class="replaceable"><code>string</code></em> {<br>
|
||||
@@ -143,7 +143,7 @@ logging
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543651"></a><h2>LWRES</h2>
|
||||
<a name="id2543654"></a><h2>LWRES</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
lwres {<br>
|
||||
listen-on [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
|
||||
@@ -156,7 +156,7 @@ lwres
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543692"></a><h2>OPTIONS</h2>
|
||||
<a name="id2543696"></a><h2>OPTIONS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
options {<br>
|
||||
avoid-v4-udp-ports { <em class="replaceable"><code>port</code></em>; ... };<br>
|
||||
@@ -317,6 +317,7 @@ options
|
||||
<br>
|
||||
zone-statistics <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
managed-keys-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
auto-dnssec <code class="constant">allow</code>|<code class="constant">maintain</code>|<code class="constant">create</code>|<code class="constant">off</code>;<br>
|
||||
try-tcp-refresh <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
zero-no-soa-ttl <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -347,7 +348,7 @@ options
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544532"></a><h2>VIEW</h2>
|
||||
<a name="id2544538"></a><h2>VIEW</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
view <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
|
||||
match-clients { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
@@ -498,7 +499,7 @@ view
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545203"></a><h2>ZONE</h2>
|
||||
<a name="id2545209"></a><h2>ZONE</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
zone <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
|
||||
type ( master | slave | stub | hint |<br>
|
||||
@@ -593,12 +594,12 @@ zone
|
||||
</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545514"></a><h2>FILES</h2>
|
||||
<a name="id2545521"></a><h2>FILES</h2>
|
||||
<p><code class="filename">/etc/named.conf</code>
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2545526"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2545601"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
|
||||
|
||||
+98
-54
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: query.c,v 1.335.8.1 2009/12/30 08:33:40 jinmei Exp $ */
|
||||
/* $Id: query.c,v 1.335.8.14.10.1 2011/11/16 09:37:44 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -56,6 +56,7 @@
|
||||
#include <dns/zt.h>
|
||||
|
||||
#include <named/client.h>
|
||||
#include <named/globals.h>
|
||||
#include <named/log.h>
|
||||
#include <named/server.h>
|
||||
#include <named/sortlist.h>
|
||||
@@ -819,17 +820,15 @@ query_getcachedb(ns_client_t *client, dns_name_t *name, dns_rdatatype_t qtype,
|
||||
return (DNS_R_REFUSED);
|
||||
dns_db_attach(client->view->cachedb, &db);
|
||||
|
||||
if ((client->query.attributes &
|
||||
NS_QUERYATTR_QUERYOKVALID) != 0) {
|
||||
if ((client->query.attributes & NS_QUERYATTR_CACHEACLOKVALID) != 0) {
|
||||
/*
|
||||
* We've evaluated the view's queryacl already. If
|
||||
* NS_QUERYATTR_QUERYOK is set, then the client is
|
||||
* We've evaluated the view's cacheacl already. If
|
||||
* NS_QUERYATTR_CACHEACLOK is set, then the client is
|
||||
* allowed to make queries, otherwise the query should
|
||||
* be refused.
|
||||
*/
|
||||
check_acl = ISC_FALSE;
|
||||
if ((client->query.attributes &
|
||||
NS_QUERYATTR_QUERYOK) == 0)
|
||||
if ((client->query.attributes & NS_QUERYATTR_CACHEACLOK) == 0)
|
||||
goto refuse;
|
||||
} else {
|
||||
/*
|
||||
@@ -843,16 +842,15 @@ query_getcachedb(ns_client_t *client, dns_name_t *name, dns_rdatatype_t qtype,
|
||||
char msg[NS_CLIENT_ACLMSGSIZE("query (cache)")];
|
||||
|
||||
result = ns_client_checkaclsilent(client, NULL,
|
||||
client->view->queryacl,
|
||||
client->view->cacheacl,
|
||||
ISC_TRUE);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
/*
|
||||
* We were allowed by the default
|
||||
* "allow-query" ACL. Remember this so we
|
||||
* don't have to check again.
|
||||
* We were allowed by the "allow-query-cache" ACL.
|
||||
* Remember this so we don't have to check again.
|
||||
*/
|
||||
client->query.attributes |=
|
||||
NS_QUERYATTR_QUERYOK;
|
||||
NS_QUERYATTR_CACHEACLOK;
|
||||
if (log && isc_log_wouldlog(ns_g_lctx,
|
||||
ISC_LOG_DEBUG(3)))
|
||||
{
|
||||
@@ -875,9 +873,9 @@ query_getcachedb(ns_client_t *client, dns_name_t *name, dns_rdatatype_t qtype,
|
||||
}
|
||||
/*
|
||||
* We've now evaluated the view's query ACL, and
|
||||
* the NS_QUERYATTR_QUERYOK attribute is now valid.
|
||||
* the NS_QUERYATTR_CACHEACLOKVALID attribute is now valid.
|
||||
*/
|
||||
client->query.attributes |= NS_QUERYATTR_QUERYOKVALID;
|
||||
client->query.attributes |= NS_QUERYATTR_CACHEACLOKVALID;
|
||||
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto refuse;
|
||||
@@ -1282,11 +1280,9 @@ query_addadditional(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
||||
goto addname;
|
||||
if (result == DNS_R_NCACHENXRRSET) {
|
||||
dns_rdataset_disassociate(rdataset);
|
||||
/*
|
||||
* Negative cache entries don't have sigrdatasets.
|
||||
*/
|
||||
INSIST(sigrdataset == NULL ||
|
||||
! dns_rdataset_isassociated(sigrdataset));
|
||||
if (sigrdataset != NULL &&
|
||||
dns_rdataset_isassociated(sigrdataset))
|
||||
dns_rdataset_disassociate(sigrdataset);
|
||||
}
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
mname = NULL;
|
||||
@@ -1327,8 +1323,9 @@ query_addadditional(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
||||
goto addname;
|
||||
if (result == DNS_R_NCACHENXRRSET) {
|
||||
dns_rdataset_disassociate(rdataset);
|
||||
INSIST(sigrdataset == NULL ||
|
||||
! dns_rdataset_isassociated(sigrdataset));
|
||||
if (sigrdataset != NULL &&
|
||||
dns_rdataset_isassociated(sigrdataset))
|
||||
dns_rdataset_disassociate(sigrdataset);
|
||||
}
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
mname = NULL;
|
||||
@@ -1513,6 +1510,7 @@ query_addadditional2(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
||||
need_addname = ISC_FALSE;
|
||||
zone = NULL;
|
||||
needadditionalcache = ISC_FALSE;
|
||||
POST(needadditionalcache);
|
||||
additionaltype = dns_rdatasetadditional_fromauth;
|
||||
dns_name_init(&cfname, NULL);
|
||||
|
||||
@@ -1777,10 +1775,8 @@ query_addadditional2(void *arg, dns_name_t *name, dns_rdatatype_t qtype) {
|
||||
goto setcache;
|
||||
if (result == DNS_R_NCACHENXRRSET) {
|
||||
dns_rdataset_disassociate(rdataset);
|
||||
/*
|
||||
* Negative cache entries don't have sigrdatasets.
|
||||
*/
|
||||
INSIST(! dns_rdataset_isassociated(sigrdataset));
|
||||
if (dns_rdataset_isassociated(sigrdataset))
|
||||
dns_rdataset_disassociate(sigrdataset);
|
||||
}
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
/* Remember the result as a cache */
|
||||
@@ -2038,7 +2034,7 @@ query_addrrset(ns_client_t *client, dns_name_t **namep,
|
||||
|
||||
static inline isc_result_t
|
||||
query_addsoa(ns_client_t *client, dns_db_t *db, dns_dbversion_t *version,
|
||||
isc_boolean_t zero_ttl)
|
||||
isc_boolean_t zero_ttl, isc_boolean_t isassociated)
|
||||
{
|
||||
dns_name_t *name;
|
||||
dns_dbnode_t *node;
|
||||
@@ -2055,6 +2051,12 @@ query_addsoa(ns_client_t *client, dns_db_t *db, dns_dbversion_t *version,
|
||||
rdataset = NULL;
|
||||
node = NULL;
|
||||
|
||||
/*
|
||||
* Don't add the SOA record for test which set "-T nosoa".
|
||||
*/
|
||||
if (ns_g_nosoa && (!WANTDNSSEC(client) || !isassociated))
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
/*
|
||||
* Get resources and make 'name' be the database origin.
|
||||
*/
|
||||
@@ -2792,7 +2794,7 @@ query_addds(ns_client_t *client, dns_db_t *db, dns_dbnode_t *node,
|
||||
static void
|
||||
query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
dns_dbversion_t *version, dns_name_t *name,
|
||||
isc_boolean_t ispositive)
|
||||
isc_boolean_t ispositive, isc_boolean_t nodata)
|
||||
{
|
||||
isc_buffer_t *dbuf, b;
|
||||
dns_name_t *fname;
|
||||
@@ -2980,7 +2982,7 @@ query_addwildcardproof(ns_client_t *client, dns_db_t *db,
|
||||
goto cleanup;
|
||||
|
||||
query_findclosestnsec3(wname, db, NULL, client, rdataset,
|
||||
sigrdataset, fname, ISC_FALSE, NULL);
|
||||
sigrdataset, fname, nodata, NULL);
|
||||
if (!dns_rdataset_isassociated(rdataset))
|
||||
goto cleanup;
|
||||
query_addrrset(client, &fname, &rdataset, &sigrdataset,
|
||||
@@ -3083,7 +3085,7 @@ query_addnxrrsetnsec(ns_client_t *client, dns_db_t *db,
|
||||
|
||||
/* XXX */
|
||||
query_addwildcardproof(client, db, version, client->query.qname,
|
||||
ISC_TRUE);
|
||||
ISC_TRUE, ISC_FALSE);
|
||||
|
||||
/*
|
||||
* We'll need some resources...
|
||||
@@ -3702,6 +3704,18 @@ query_findclosestnsec3(dns_name_t *qname, dns_db_t *db,
|
||||
return;
|
||||
}
|
||||
|
||||
#ifdef ALLOW_FILTER_AAAA_ON_V4
|
||||
static isc_boolean_t
|
||||
is_v4_client(ns_client_t *client) {
|
||||
if (isc_sockaddr_pf(&client->peeraddr) == AF_INET)
|
||||
return (ISC_TRUE);
|
||||
if (isc_sockaddr_pf(&client->peeraddr) == AF_INET6 &&
|
||||
IN6_IS_ADDR_V4MAPPED(&client->peeraddr.type.sin6.sin6_addr))
|
||||
return (ISC_TRUE);
|
||||
return (ISC_FALSE);
|
||||
}
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Do the bulk of query processing for the current query of 'client'.
|
||||
* If 'event' is non-NULL, we are returning from recursion and 'qtype'
|
||||
@@ -4311,7 +4325,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
query_releasename(client, &fname);
|
||||
query_addwildcardproof(client, db, version,
|
||||
client->query.qname,
|
||||
ISC_FALSE);
|
||||
ISC_FALSE, ISC_TRUE);
|
||||
}
|
||||
}
|
||||
if (dns_rdataset_isassociated(rdataset)) {
|
||||
@@ -4332,7 +4346,8 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
/*
|
||||
* Add SOA.
|
||||
*/
|
||||
result = query_addsoa(client, db, version, ISC_FALSE);
|
||||
result = query_addsoa(client, db, version, ISC_FALSE,
|
||||
dns_rdataset_isassociated(rdataset));
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
QUERY_ERROR(result);
|
||||
goto cleanup;
|
||||
@@ -4380,9 +4395,11 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
zone != NULL &&
|
||||
#endif
|
||||
dns_zone_getzeronosoattl(zone))
|
||||
result = query_addsoa(client, db, version, ISC_TRUE);
|
||||
result = query_addsoa(client, db, version, ISC_TRUE,
|
||||
dns_rdataset_isassociated(rdataset));
|
||||
else
|
||||
result = query_addsoa(client, db, version, ISC_FALSE);
|
||||
result = query_addsoa(client, db, version, ISC_FALSE,
|
||||
dns_rdataset_isassociated(rdataset));
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
QUERY_ERROR(result);
|
||||
goto cleanup;
|
||||
@@ -4397,7 +4414,8 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
&sigrdataset,
|
||||
NULL, DNS_SECTION_AUTHORITY);
|
||||
query_addwildcardproof(client, db, version,
|
||||
client->query.qname, ISC_FALSE);
|
||||
client->query.qname, ISC_FALSE,
|
||||
ISC_FALSE);
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -4583,18 +4601,19 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
goto cleanup;
|
||||
}
|
||||
result = dns_name_concatenate(prefix, tname, fname, NULL);
|
||||
|
||||
/*
|
||||
* RFC2672, section 4.1, subsection 3c says
|
||||
* we should return YXDOMAIN if the constructed
|
||||
* name would be too long.
|
||||
*/
|
||||
if (result == DNS_R_NAMETOOLONG)
|
||||
client->message->rcode = dns_rcode_yxdomain;
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
dns_message_puttempname(client->message, &tname);
|
||||
if (result == ISC_R_NOSPACE) {
|
||||
/*
|
||||
* RFC2672, section 4.1, subsection 3c says
|
||||
* we should return YXDOMAIN if the constructed
|
||||
* name would be too long.
|
||||
*/
|
||||
client->message->rcode = dns_rcode_yxdomain;
|
||||
}
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
query_keepname(client, fname, dbuf);
|
||||
/*
|
||||
* Synthesize a CNAME for this DNAME.
|
||||
@@ -4642,7 +4661,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
|
||||
if (type == dns_rdatatype_any) {
|
||||
#ifdef ALLOW_FILTER_AAAA_ON_V4
|
||||
isc_boolean_t have_aaaa, have_a, have_sig;
|
||||
isc_boolean_t have_aaaa, have_a, have_sig, filter_aaaa;
|
||||
|
||||
/*
|
||||
* The filter-aaaa-on-v4 option should
|
||||
@@ -4654,6 +4673,14 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
have_aaaa = ISC_FALSE;
|
||||
have_a = !authoritative;
|
||||
have_sig = ISC_FALSE;
|
||||
if (client->view->v4_aaaa != dns_v4_aaaa_ok &&
|
||||
is_v4_client(client) &&
|
||||
ns_client_checkaclsilent(client, NULL,
|
||||
client->view->v4_aaaa_acl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS)
|
||||
filter_aaaa = ISC_TRUE;
|
||||
else
|
||||
filter_aaaa = ISC_FALSE;
|
||||
#endif
|
||||
/*
|
||||
* XXXRTH Need to handle zonecuts with special case
|
||||
@@ -4687,9 +4714,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* Notice the presence of A and AAAAs so
|
||||
* that AAAAs can be hidden from IPv4 clients.
|
||||
*/
|
||||
if (client->view->v4_aaaa != dns_v4_aaaa_ok &&
|
||||
client->peeraddr_valid &&
|
||||
client->peeraddr.type.sa.sa_family == AF_INET) {
|
||||
if (filter_aaaa) {
|
||||
if (rdataset->type == dns_rdatatype_aaaa)
|
||||
have_aaaa = ISC_TRUE;
|
||||
else if (rdataset->type == dns_rdatatype_a)
|
||||
@@ -4746,7 +4771,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* Filter AAAAs if there is an A and there is no signature
|
||||
* or we are supposed to break DNSSEC.
|
||||
*/
|
||||
if (have_aaaa && have_a &&
|
||||
if (filter_aaaa && have_aaaa && have_a &&
|
||||
(!have_sig || !WANTDNSSEC(client) ||
|
||||
client->view->v4_aaaa == dns_v4_aaaa_break_dnssec))
|
||||
client->attributes |= NS_CLIENTATTR_FILTER_AAAA;
|
||||
@@ -4758,7 +4783,8 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
/*
|
||||
* We didn't match any rdatasets.
|
||||
*/
|
||||
if (qtype == dns_rdatatype_rrsig &&
|
||||
if ((qtype == dns_rdatatype_rrsig ||
|
||||
qtype == dns_rdatatype_sig) &&
|
||||
result == ISC_R_NOMORE) {
|
||||
/*
|
||||
* XXXRTH If this is a secure zone and we
|
||||
@@ -4767,6 +4793,18 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* glue. Ugh.
|
||||
*/
|
||||
if (!is_zone) {
|
||||
/*
|
||||
* Note: this is dead code because
|
||||
* is_zone is always true due to the
|
||||
* condition above. But naive
|
||||
* recursion would cause infinite
|
||||
* attempts of recursion because
|
||||
* the answer to (RR)SIG queries
|
||||
* won't be cached. Until we figure
|
||||
* out what we should do and implement
|
||||
* it we intentionally keep this code
|
||||
* dead.
|
||||
*/
|
||||
authoritative = ISC_FALSE;
|
||||
dns_rdatasetiter_destroy(&rdsiter);
|
||||
if (RECURSIONOK(client)) {
|
||||
@@ -4792,7 +4830,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* Add SOA.
|
||||
*/
|
||||
result = query_addsoa(client, db, version,
|
||||
ISC_FALSE);
|
||||
ISC_FALSE, ISC_FALSE);
|
||||
if (result == ISC_R_SUCCESS)
|
||||
result = ISC_R_NOMORE;
|
||||
} else {
|
||||
@@ -4822,8 +4860,10 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
* unneeded that it is best to keep it as short as possible.
|
||||
*/
|
||||
if (client->view->v4_aaaa != dns_v4_aaaa_ok &&
|
||||
client->peeraddr_valid &&
|
||||
client->peeraddr.type.sa.sa_family == AF_INET &&
|
||||
is_v4_client(client) &&
|
||||
ns_client_checkaclsilent(client, NULL,
|
||||
client->view->v4_aaaa_acl,
|
||||
ISC_TRUE) == ISC_R_SUCCESS &&
|
||||
(!WANTDNSSEC(client) ||
|
||||
sigrdataset == NULL ||
|
||||
!dns_rdataset_isassociated(sigrdataset) ||
|
||||
@@ -4949,7 +4989,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
if (need_wildcardproof && dns_db_issecure(db))
|
||||
query_addwildcardproof(client, db, version,
|
||||
dns_fixedname_name(&wildcardname),
|
||||
ISC_TRUE);
|
||||
ISC_TRUE, ISC_FALSE);
|
||||
cleanup:
|
||||
CTRACE("query_find: cleanup");
|
||||
/*
|
||||
@@ -5321,8 +5361,12 @@ ns_query_start(ns_client_t *client) {
|
||||
/*
|
||||
* Assume authoritative response until it is known to be
|
||||
* otherwise.
|
||||
*
|
||||
* If "-T noaa" has been set on the command line don't set
|
||||
* AA on authoritative answers.
|
||||
*/
|
||||
message->flags |= DNS_MESSAGEFLAG_AA;
|
||||
if (!ns_g_noaa)
|
||||
message->flags |= DNS_MESSAGEFLAG_AA;
|
||||
|
||||
/*
|
||||
* Set AD. We must clear it if we add non-validated data to a
|
||||
|
||||
+736
-120
File diff suppressed because it is too large
Load Diff
+219
-133
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: statschannel.c,v 1.24 2009/10/20 03:30:07 marka Exp $ */
|
||||
/* $Id: statschannel.c,v 1.24.40.4 2011/03/12 04:58:24 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -71,6 +71,7 @@ stats_dumparg {
|
||||
int ncounters; /* used for general statistics */
|
||||
int *counterindices; /* used for general statistics */
|
||||
isc_uint64_t *countervalues; /* used for general statistics */
|
||||
isc_result_t result;
|
||||
} stats_dumparg_t;
|
||||
|
||||
static isc_once_t once = ISC_ONCE_INIT;
|
||||
@@ -96,6 +97,8 @@ static const char *sockstats_xmldesc[isc_sockstatscounter_max];
|
||||
#define sockstats_xmldesc NULL
|
||||
#endif /* HAVE_LIBXML2 */
|
||||
|
||||
#define TRY0(a) do { xmlrc = (a); if (xmlrc < 0) goto error; } while(0)
|
||||
|
||||
/*%
|
||||
* Mapping arrays to represent statistics counters in the order of our
|
||||
* preference, regardless of the order of counter indices. For example,
|
||||
@@ -438,7 +441,7 @@ generalstat_dump(isc_statscounter_t counter, isc_uint64_t val, void *arg) {
|
||||
dumparg->countervalues[counter] = val;
|
||||
}
|
||||
|
||||
static void
|
||||
static isc_result_t
|
||||
dump_counters(isc_stats_t *stats, statsformat_t type, void *arg,
|
||||
const char *category, const char **desc, int ncounters,
|
||||
int *indices, isc_uint64_t *values, int options)
|
||||
@@ -449,6 +452,7 @@ dump_counters(isc_stats_t *stats, statsformat_t type, void *arg,
|
||||
FILE *fp;
|
||||
#ifdef HAVE_LIBXML2
|
||||
xmlTextWriterPtr writer;
|
||||
int xmlrc;
|
||||
#endif
|
||||
|
||||
#ifndef HAVE_LIBXML2
|
||||
@@ -481,31 +485,41 @@ dump_counters(isc_stats_t *stats, statsformat_t type, void *arg,
|
||||
writer = arg;
|
||||
|
||||
if (category != NULL) {
|
||||
xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR
|
||||
category);
|
||||
xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR
|
||||
desc[index]);
|
||||
xmlTextWriterEndElement(writer); /* name */
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR
|
||||
category));
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR
|
||||
"name"));
|
||||
TRY0(xmlTextWriterWriteString(writer,
|
||||
ISC_XMLCHAR
|
||||
desc[index]));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* name */
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR
|
||||
"counter");
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR
|
||||
"counter"));
|
||||
} else {
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR
|
||||
desc[index]);
|
||||
TRY0(xmlTextWriterStartElement(writer,
|
||||
ISC_XMLCHAR
|
||||
desc[index]));
|
||||
}
|
||||
xmlTextWriterWriteFormatString(writer,
|
||||
"%" ISC_PRINT_QUADFORMAT
|
||||
"u", value);
|
||||
xmlTextWriterEndElement(writer); /* counter */
|
||||
TRY0(xmlTextWriterWriteFormatString(writer,
|
||||
"%"
|
||||
ISC_PRINT_QUADFORMAT
|
||||
"u", value));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counter */
|
||||
if (category != NULL)
|
||||
xmlTextWriterEndElement(writer); /* category */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* category */
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
}
|
||||
return (ISC_R_SUCCESS);
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
return (ISC_R_FAILURE);
|
||||
#endif
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -516,6 +530,7 @@ rdtypestat_dump(dns_rdatastatstype_t type, isc_uint64_t val, void *arg) {
|
||||
FILE *fp;
|
||||
#ifdef HAVE_LIBXML2
|
||||
xmlTextWriterPtr writer;
|
||||
int xmlrc;
|
||||
#endif
|
||||
|
||||
if ((DNS_RDATASTATSTYPE_ATTR(type) & DNS_RDATASTATSTYPE_ATTR_OTHERTYPE)
|
||||
@@ -535,22 +550,28 @@ rdtypestat_dump(dns_rdatastatstype_t type, isc_uint64_t val, void *arg) {
|
||||
#ifdef HAVE_LIBXML2
|
||||
writer = dumparg->arg;
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "rdtype");
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "rdtype"));
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR typestr);
|
||||
xmlTextWriterEndElement(writer); /* name */
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "name"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR typestr));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* name */
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter");
|
||||
xmlTextWriterWriteFormatString(writer,
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter"));
|
||||
TRY0(xmlTextWriterWriteFormatString(writer,
|
||||
"%" ISC_PRINT_QUADFORMAT "u",
|
||||
val);
|
||||
xmlTextWriterEndElement(writer); /* counter */
|
||||
val));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counter */
|
||||
|
||||
xmlTextWriterEndElement(writer); /* rdtype */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* rdtype */
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
return;
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
dumparg->result = ISC_R_FAILURE;
|
||||
return;
|
||||
#endif
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -562,6 +583,7 @@ rdatasetstats_dump(dns_rdatastatstype_t type, isc_uint64_t val, void *arg) {
|
||||
isc_boolean_t nxrrset = ISC_FALSE;
|
||||
#ifdef HAVE_LIBXML2
|
||||
xmlTextWriterPtr writer;
|
||||
int xmlrc;
|
||||
#endif
|
||||
|
||||
if ((DNS_RDATASTATSTYPE_ATTR(type) & DNS_RDATASTATSTYPE_ATTR_NXDOMAIN)
|
||||
@@ -590,32 +612,39 @@ rdatasetstats_dump(dns_rdatastatstype_t type, isc_uint64_t val, void *arg) {
|
||||
#ifdef HAVE_LIBXML2
|
||||
writer = dumparg->arg;
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "rrset");
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteFormatString(writer, "%s%s",
|
||||
nxrrset ? "!" : "", typestr);
|
||||
xmlTextWriterEndElement(writer); /* name */
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "rrset"));
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "name"));
|
||||
TRY0(xmlTextWriterWriteFormatString(writer, "%s%s",
|
||||
nxrrset ? "!" : "", typestr));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* name */
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter");
|
||||
xmlTextWriterWriteFormatString(writer,
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter"));
|
||||
TRY0(xmlTextWriterWriteFormatString(writer,
|
||||
"%" ISC_PRINT_QUADFORMAT "u",
|
||||
val);
|
||||
xmlTextWriterEndElement(writer); /* counter */
|
||||
val));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counter */
|
||||
|
||||
xmlTextWriterEndElement(writer); /* rrset */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* rrset */
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
return;
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
dumparg->result = ISC_R_FAILURE;
|
||||
#endif
|
||||
|
||||
}
|
||||
|
||||
static void
|
||||
opcodestat_dump(dns_opcode_t code, isc_uint64_t val, void *arg) {
|
||||
FILE *fp = arg;
|
||||
FILE *fp;
|
||||
isc_buffer_t b;
|
||||
char codebuf[64];
|
||||
stats_dumparg_t *dumparg = arg;
|
||||
#ifdef HAVE_LIBXML2
|
||||
xmlTextWriterPtr writer;
|
||||
int xmlrc;
|
||||
#endif
|
||||
|
||||
isc_buffer_init(&b, codebuf, sizeof(codebuf) - 1);
|
||||
@@ -631,30 +660,35 @@ opcodestat_dump(dns_opcode_t code, isc_uint64_t val, void *arg) {
|
||||
#ifdef HAVE_LIBXML2
|
||||
writer = dumparg->arg;
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "opcode");
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "opcode"));
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR codebuf);
|
||||
xmlTextWriterEndElement(writer); /* name */
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "name"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR codebuf));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* name */
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter");
|
||||
xmlTextWriterWriteFormatString(writer,
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counter"));
|
||||
TRY0(xmlTextWriterWriteFormatString(writer,
|
||||
"%" ISC_PRINT_QUADFORMAT "u",
|
||||
val);
|
||||
xmlTextWriterEndElement(writer); /* counter */
|
||||
val));
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counter */
|
||||
|
||||
xmlTextWriterEndElement(writer); /* opcode */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* opcode */
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
return;
|
||||
|
||||
#ifdef HAVE_LIBXML2
|
||||
error:
|
||||
dumparg->result = ISC_R_FAILURE;
|
||||
return;
|
||||
#endif
|
||||
}
|
||||
|
||||
#ifdef HAVE_LIBXML2
|
||||
|
||||
/* XXXMLG below here sucks. */
|
||||
|
||||
#define TRY(a) do { result = (a); INSIST(result == ISC_R_SUCCESS); } while(0);
|
||||
#define TRY0(a) do { xmlrc = (a); INSIST(xmlrc >= 0); } while(0);
|
||||
|
||||
static isc_result_t
|
||||
zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
@@ -664,49 +698,55 @@ zone_xmlrender(dns_zone_t *zone, void *arg) {
|
||||
xmlTextWriterPtr writer = arg;
|
||||
isc_stats_t *zonestats;
|
||||
isc_uint64_t nsstat_values[dns_nsstatscounter_max];
|
||||
int xmlrc;
|
||||
isc_result_t result;
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "zone");
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "zone"));
|
||||
|
||||
dns_zone_name(zone, buf, sizeof(buf));
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR buf);
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "name"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR buf));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
rdclass = dns_zone_getclass(zone);
|
||||
dns_rdataclass_format(rdclass, buf, sizeof(buf));
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "rdataclass");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR buf);
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "rdataclass"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR buf));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "serial");
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "serial"));
|
||||
if (dns_zone_getserial2(zone, &serial) == ISC_R_SUCCESS)
|
||||
xmlTextWriterWriteFormatString(writer, "%u", serial);
|
||||
TRY0(xmlTextWriterWriteFormatString(writer, "%u", serial));
|
||||
else
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR "-");
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR "-"));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
zonestats = dns_zone_getrequeststats(zone);
|
||||
if (zonestats != NULL) {
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters");
|
||||
dump_counters(zonestats, statsformat_xml, writer, NULL,
|
||||
nsstats_xmldesc, dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
xmlTextWriterEndElement(writer); /* counters */
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "counters"));
|
||||
result = dump_counters(zonestats, statsformat_xml, writer, NULL,
|
||||
nsstats_xmldesc, dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* counters */
|
||||
}
|
||||
|
||||
xmlTextWriterEndElement(writer); /* zone */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* zone */
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
error:
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
static void
|
||||
static isc_result_t
|
||||
generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
char boottime[sizeof "yyyy-mm-ddThh:mm:ssZ"];
|
||||
char nowstr[sizeof "yyyy-mm-ddThh:mm:ssZ"];
|
||||
isc_time_t now;
|
||||
xmlTextWriterPtr writer;
|
||||
xmlDocPtr doc;
|
||||
xmlTextWriterPtr writer = NULL;
|
||||
xmlDocPtr doc = NULL;
|
||||
int xmlrc;
|
||||
dns_view_t *view;
|
||||
stats_dumparg_t dumparg;
|
||||
@@ -715,12 +755,15 @@ generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
isc_uint64_t resstat_values[dns_resstatscounter_max];
|
||||
isc_uint64_t zonestat_values[dns_zonestatscounter_max];
|
||||
isc_uint64_t sockstat_values[isc_sockstatscounter_max];
|
||||
isc_result_t result;
|
||||
|
||||
isc_time_now(&now);
|
||||
isc_time_formatISO8601(&ns_g_boottime, boottime, sizeof boottime);
|
||||
isc_time_formatISO8601(&now, nowstr, sizeof nowstr);
|
||||
|
||||
writer = xmlNewTextWriterDoc(&doc, 0);
|
||||
if (writer == NULL)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterStartDocument(writer, NULL, "UTF-8", NULL));
|
||||
TRY0(xmlTextWriterWritePI(writer, ISC_XMLCHAR "xml-stylesheet",
|
||||
ISC_XMLCHAR "type=\"text/xsl\" href=\"/bind9.xsl\""));
|
||||
@@ -744,27 +787,36 @@ generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
view = ISC_LIST_HEAD(server->viewlist);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "views"));
|
||||
while (view != NULL) {
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "view");
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "view"));
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "name");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR view->name);
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "name"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR view->name));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "zones");
|
||||
dns_zt_apply(view->zonetable, ISC_FALSE, zone_xmlrender,
|
||||
writer);
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "zones"));
|
||||
result = dns_zt_apply(view->zonetable, ISC_TRUE, zone_xmlrender,
|
||||
writer);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
if (view->resquerystats != NULL) {
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(view->resquerystats,
|
||||
rdtypestat_dump, &dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
}
|
||||
|
||||
if (view->resstats != NULL) {
|
||||
dump_counters(view->resstats, statsformat_xml, writer,
|
||||
"resstat", resstats_xmldesc,
|
||||
dns_resstatscounter_max, resstats_index,
|
||||
resstat_values, ISC_STATSDUMP_VERBOSE);
|
||||
result = dump_counters(view->resstats, statsformat_xml,
|
||||
writer, "resstat",
|
||||
resstats_xmldesc,
|
||||
dns_resstatscounter_max,
|
||||
resstats_index, resstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
}
|
||||
|
||||
cachestats = dns_db_getrrsetstats(view->cachedb);
|
||||
@@ -775,12 +827,15 @@ generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
ISC_XMLCHAR "name",
|
||||
ISC_XMLCHAR
|
||||
dns_cache_getname(view->cache)));
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatasetstats_dump(cachestats, rdatasetstats_dump,
|
||||
&dumparg, 0);
|
||||
if (dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* cache */
|
||||
}
|
||||
|
||||
xmlTextWriterEndElement(writer); /* view */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* view */
|
||||
|
||||
view = ISC_LIST_NEXT(view, link);
|
||||
}
|
||||
@@ -795,44 +850,63 @@ generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* taskmgr */
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "server"));
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "boot-time");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR boottime);
|
||||
xmlTextWriterEndElement(writer);
|
||||
xmlTextWriterStartElement(writer, ISC_XMLCHAR "current-time");
|
||||
xmlTextWriterWriteString(writer, ISC_XMLCHAR nowstr);
|
||||
xmlTextWriterEndElement(writer);
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "boot-time"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR boottime));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "current-time"));
|
||||
TRY0(xmlTextWriterWriteString(writer, ISC_XMLCHAR nowstr));
|
||||
TRY0(xmlTextWriterEndElement(writer));
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "requests"));
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_opcodestats_dump(server->opcodestats, opcodestat_dump, &dumparg,
|
||||
0);
|
||||
xmlTextWriterEndElement(writer); /* requests */
|
||||
if (dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* requests */
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "queries-in"));
|
||||
dumparg.result = ISC_R_SUCCESS;
|
||||
dns_rdatatypestats_dump(server->rcvquerystats, rdtypestat_dump,
|
||||
&dumparg, 0);
|
||||
xmlTextWriterEndElement(writer); /* queries-in */
|
||||
if (dumparg.result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* queries-in */
|
||||
|
||||
dump_counters(server->nsstats, statsformat_xml, writer,
|
||||
"nsstat", nsstats_xmldesc, dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values, ISC_STATSDUMP_VERBOSE);
|
||||
result = dump_counters(server->nsstats, statsformat_xml, writer,
|
||||
"nsstat", nsstats_xmldesc,
|
||||
dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values,
|
||||
ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
|
||||
dump_counters(server->zonestats, statsformat_xml, writer, "zonestat",
|
||||
zonestats_xmldesc, dns_zonestatscounter_max,
|
||||
zonestats_index, zonestat_values, ISC_STATSDUMP_VERBOSE);
|
||||
result = dump_counters(server->zonestats, statsformat_xml, writer,
|
||||
"zonestat", zonestats_xmldesc,
|
||||
dns_zonestatscounter_max, zonestats_index,
|
||||
zonestat_values, ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
|
||||
/*
|
||||
* Most of the common resolver statistics entries are 0, so we don't
|
||||
* use the verbose dump here.
|
||||
*/
|
||||
dump_counters(server->resolverstats, statsformat_xml, writer, "resstat",
|
||||
resstats_xmldesc, dns_resstatscounter_max, resstats_index,
|
||||
resstat_values, 0);
|
||||
result = dump_counters(server->resolverstats, statsformat_xml, writer,
|
||||
"resstat", resstats_xmldesc,
|
||||
dns_resstatscounter_max, resstats_index,
|
||||
resstat_values, 0);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
|
||||
dump_counters(server->sockstats, statsformat_xml, writer, "sockstat",
|
||||
sockstats_xmldesc, isc_sockstatscounter_max,
|
||||
sockstats_index, sockstat_values, ISC_STATSDUMP_VERBOSE);
|
||||
result = dump_counters(server->sockstats, statsformat_xml, writer,
|
||||
"sockstat", sockstats_xmldesc,
|
||||
isc_sockstatscounter_max, sockstats_index,
|
||||
sockstat_values, ISC_STATSDUMP_VERBOSE);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto error;
|
||||
|
||||
xmlTextWriterEndElement(writer); /* server */
|
||||
TRY0(xmlTextWriterEndElement(writer)); /* server */
|
||||
|
||||
TRY0(xmlTextWriterStartElement(writer, ISC_XMLCHAR "memory"));
|
||||
isc_mem_renderxml(writer);
|
||||
@@ -848,6 +922,14 @@ generatexml(ns_server_t *server, int *buflen, xmlChar **buf) {
|
||||
|
||||
xmlDocDumpFormatMemoryEnc(doc, buf, buflen, "UTF-8", 1);
|
||||
xmlFreeDoc(doc);
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
error:
|
||||
if (writer != NULL)
|
||||
xmlFreeTextWriter(writer);
|
||||
if (doc != NULL)
|
||||
xmlFreeDoc(doc);
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -866,21 +948,24 @@ render_index(const char *url, const char *querystring, void *arg,
|
||||
unsigned char *msg;
|
||||
int msglen;
|
||||
ns_server_t *server = arg;
|
||||
isc_result_t result;
|
||||
|
||||
UNUSED(url);
|
||||
UNUSED(querystring);
|
||||
|
||||
generatexml(server, &msglen, &msg);
|
||||
result = generatexml(server, &msglen, &msg);
|
||||
|
||||
*retcode = 200;
|
||||
*retmsg = "OK";
|
||||
*mimetype = "text/xml";
|
||||
isc_buffer_reinit(b, msg, msglen);
|
||||
isc_buffer_add(b, msglen);
|
||||
*freecb = wrap_xmlfree;
|
||||
*freecb_args = NULL;
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
*retcode = 200;
|
||||
*retmsg = "OK";
|
||||
*mimetype = "text/xml";
|
||||
isc_buffer_reinit(b, msg, msglen);
|
||||
isc_buffer_add(b, msglen);
|
||||
*freecb = wrap_xmlfree;
|
||||
*freecb_args = NULL;
|
||||
}
|
||||
|
||||
return (ISC_R_SUCCESS);
|
||||
return (result);
|
||||
}
|
||||
|
||||
#endif /* HAVE_LIBXML2 */
|
||||
@@ -1281,20 +1366,20 @@ ns_stats_dump(ns_server_t *server, FILE *fp) {
|
||||
}
|
||||
|
||||
fprintf(fp, "++ Name Server Statistics ++\n");
|
||||
dump_counters(server->nsstats, statsformat_file, fp, NULL,
|
||||
nsstats_desc, dns_nsstatscounter_max, nsstats_index,
|
||||
nsstat_values, 0);
|
||||
(void) dump_counters(server->nsstats, statsformat_file, fp, NULL,
|
||||
nsstats_desc, dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values, 0);
|
||||
|
||||
fprintf(fp, "++ Zone Maintenance Statistics ++\n");
|
||||
dump_counters(server->zonestats, statsformat_file, fp, NULL,
|
||||
zonestats_desc, dns_zonestatscounter_max,
|
||||
zonestats_index, zonestat_values, 0);
|
||||
(void) dump_counters(server->zonestats, statsformat_file, fp, NULL,
|
||||
zonestats_desc, dns_zonestatscounter_max,
|
||||
zonestats_index, zonestat_values, 0);
|
||||
|
||||
fprintf(fp, "++ Resolver Statistics ++\n");
|
||||
fprintf(fp, "[Common]\n");
|
||||
dump_counters(server->resolverstats, statsformat_file, fp, NULL,
|
||||
resstats_desc, dns_resstatscounter_max, resstats_index,
|
||||
resstat_values, 0);
|
||||
(void) dump_counters(server->resolverstats, statsformat_file, fp, NULL,
|
||||
resstats_desc, dns_resstatscounter_max,
|
||||
resstats_index, resstat_values, 0);
|
||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
||||
view != NULL;
|
||||
view = ISC_LIST_NEXT(view, link)) {
|
||||
@@ -1304,9 +1389,9 @@ ns_stats_dump(ns_server_t *server, FILE *fp) {
|
||||
fprintf(fp, "[View: default]\n");
|
||||
else
|
||||
fprintf(fp, "[View: %s]\n", view->name);
|
||||
dump_counters(view->resstats, statsformat_file, fp, NULL,
|
||||
resstats_desc, dns_resstatscounter_max,
|
||||
resstats_index, resstat_values, 0);
|
||||
(void) dump_counters(view->resstats, statsformat_file, fp, NULL,
|
||||
resstats_desc, dns_resstatscounter_max,
|
||||
resstats_index, resstat_values, 0);
|
||||
}
|
||||
|
||||
fprintf(fp, "++ Cache DB RRsets ++\n");
|
||||
@@ -1335,9 +1420,9 @@ ns_stats_dump(ns_server_t *server, FILE *fp) {
|
||||
}
|
||||
|
||||
fprintf(fp, "++ Socket I/O Statistics ++\n");
|
||||
dump_counters(server->sockstats, statsformat_file, fp, NULL,
|
||||
sockstats_desc, isc_sockstatscounter_max, sockstats_index,
|
||||
sockstat_values, 0);
|
||||
(void) dump_counters(server->sockstats, statsformat_file, fp, NULL,
|
||||
sockstats_desc, isc_sockstatscounter_max,
|
||||
sockstats_index, sockstat_values, 0);
|
||||
|
||||
fprintf(fp, "++ Per Zone Query Statistics ++\n");
|
||||
zone = NULL;
|
||||
@@ -1358,9 +1443,10 @@ ns_stats_dump(ns_server_t *server, FILE *fp) {
|
||||
fprintf(fp, " (view: %s)", view->name);
|
||||
fprintf(fp, "]\n");
|
||||
|
||||
dump_counters(zonestats, statsformat_file, fp, NULL,
|
||||
nsstats_desc, dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values, 0);
|
||||
(void) dump_counters(zonestats, statsformat_file, fp,
|
||||
NULL, nsstats_desc,
|
||||
dns_nsstatscounter_max,
|
||||
nsstats_index, nsstat_values, 0);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+7
-4
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: os.c,v 1.101 2009/08/13 07:04:38 marka Exp $ */
|
||||
/* $Id: os.c,v 1.101.110.3 2011/03/02 00:05:11 marka Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -790,6 +790,9 @@ ns_os_openfile(const char *filename, mode_t mode, isc_boolean_t switch_user) {
|
||||
free(f);
|
||||
|
||||
if (switch_user && runas_pw != NULL) {
|
||||
#ifndef HAVE_LINUXTHREADS
|
||||
gid_t oldgid = getgid();
|
||||
#endif
|
||||
/* Set UID/GID to the one we'll be running with eventually */
|
||||
setperms(runas_pw->pw_uid, runas_pw->pw_gid);
|
||||
|
||||
@@ -797,7 +800,7 @@ ns_os_openfile(const char *filename, mode_t mode, isc_boolean_t switch_user) {
|
||||
|
||||
#ifndef HAVE_LINUXTHREADS
|
||||
/* Restore UID/GID to root */
|
||||
setperms(0, 0);
|
||||
setperms(0, oldgid);
|
||||
#endif /* HAVE_LINUXTHREADS */
|
||||
|
||||
if (fd == -1) {
|
||||
@@ -950,7 +953,7 @@ ns_os_shutdownmsg(char *command, isc_buffer_t *text) {
|
||||
isc_buffer_availablelength(text),
|
||||
"pid: %ld", (long)pid);
|
||||
/* Only send a message if it is complete. */
|
||||
if (n < isc_buffer_availablelength(text))
|
||||
if (n > 0 && n < isc_buffer_availablelength(text))
|
||||
isc_buffer_add(text, n);
|
||||
}
|
||||
|
||||
|
||||
+218
-205
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: update.c,v 1.176.4.3 2009/12/30 03:55:03 marka Exp $ */
|
||||
/* $Id: update.c,v 1.176.4.14 2011/03/25 23:54:33 each Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -1250,11 +1250,10 @@ replaces_p(dns_rdata_t *update_rr, dns_rdata_t *db_rr) {
|
||||
return (ISC_FALSE);
|
||||
INSIST(db_rr->length >= 4 && update_rr->length >= 4);
|
||||
/*
|
||||
* Replace records added in this UPDATE request.
|
||||
* Replace NSEC3PARAM records that only differ by the
|
||||
* flags field.
|
||||
*/
|
||||
if (db_rr->data[0] == update_rr->data[0] &&
|
||||
(db_rr->data[1] & DNS_NSEC3FLAG_UPDATE) != 0 &&
|
||||
(update_rr->data[1] & DNS_NSEC3FLAG_UPDATE) != 0 &&
|
||||
memcmp(db_rr->data+2, update_rr->data+2,
|
||||
update_rr->length - 2) == 0)
|
||||
return (ISC_TRUE);
|
||||
@@ -1688,7 +1687,7 @@ next_active(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
{
|
||||
isc_result_t result;
|
||||
dns_dbiterator_t *dbit = NULL;
|
||||
isc_boolean_t has_nsec;
|
||||
isc_boolean_t has_nsec = ISC_FALSE;
|
||||
unsigned int wraps = 0;
|
||||
isc_boolean_t secure = dns_db_issecure(db);
|
||||
|
||||
@@ -1941,6 +1940,7 @@ add_sigs(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
CHECK(update_one_rr(db, ver, diff, DNS_DIFFOP_ADDRESIGN, name,
|
||||
rdataset.ttl, &sig_rdata));
|
||||
dns_rdata_reset(&sig_rdata);
|
||||
isc_buffer_init(&buffer, data, sizeof(data));
|
||||
added_sig = ISC_TRUE;
|
||||
}
|
||||
if (!added_sig) {
|
||||
@@ -2390,7 +2390,7 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
name, diff));
|
||||
}
|
||||
CHECK(add_exposed_sigs(client, zone, db, newver, name,
|
||||
cut, diff, zone_keys, nkeys,
|
||||
cut, &sig_diff, zone_keys, nkeys,
|
||||
inception, expire, check_ksk,
|
||||
keyset_kskonly));
|
||||
}
|
||||
@@ -2549,7 +2549,7 @@ update_signatures(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
privatetype, &nsec_diff));
|
||||
} else {
|
||||
CHECK(add_exposed_sigs(client, zone, db, newver, name,
|
||||
cut, diff, zone_keys, nkeys,
|
||||
cut, &sig_diff, zone_keys, nkeys,
|
||||
inception, expire, check_ksk,
|
||||
keyset_kskonly));
|
||||
CHECK(dns_nsec3_addnsec3sx(db, newver, name, nsecttl,
|
||||
@@ -3108,7 +3108,9 @@ add_nsec3param_records(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
dns_diffop_t op;
|
||||
isc_boolean_t flag;
|
||||
dns_name_t *name = dns_zone_getorigin(zone);
|
||||
dns_rdatatype_t privatetype = dns_zone_getprivatetype(zone);;
|
||||
dns_rdatatype_t privatetype = dns_zone_getprivatetype(zone);
|
||||
isc_uint32_t ttl = 0;
|
||||
isc_boolean_t ttl_good = ISC_FALSE;
|
||||
|
||||
update_log(client, zone, ISC_LOG_DEBUG(3),
|
||||
"checking for NSEC3PARAM changes");
|
||||
@@ -3131,53 +3133,143 @@ add_nsec3param_records(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
ISC_LIST_APPEND(temp_diff.tuples, tuple, link);
|
||||
}
|
||||
|
||||
/*
|
||||
* Extract TTL changes pairs, we don't need to convert these to
|
||||
* delayed changes.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
|
||||
if (tuple->op == DNS_DIFFOP_ADD) {
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
if (!ttl_good) {
|
||||
/*
|
||||
* Any adds here will contain the final
|
||||
* NSEC3PARAM RRset TTL.
|
||||
*/
|
||||
ttl = tuple->ttl;
|
||||
ttl_good = ISC_TRUE;
|
||||
}
|
||||
/*
|
||||
* Walk the temp_diff list looking for the
|
||||
* corresponding delete.
|
||||
*/
|
||||
next = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
while (next != NULL) {
|
||||
unsigned char *next_data = next->rdata.data;
|
||||
unsigned char *tuple_data = tuple->rdata.data;
|
||||
if (next_data[0] != tuple_data[0] ||
|
||||
/* Ignore flags. */
|
||||
if (next->op == DNS_DIFFOP_DEL &&
|
||||
next->rdata.length == tuple->rdata.length &&
|
||||
!memcmp(next_data, tuple_data,
|
||||
next->rdata.length)) {
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, next,
|
||||
link);
|
||||
ISC_LIST_APPEND(diff->tuples, next,
|
||||
link);
|
||||
break;
|
||||
}
|
||||
next = ISC_LIST_NEXT(next, link);
|
||||
}
|
||||
/*
|
||||
* If we have not found a pair move onto the next
|
||||
* tuple.
|
||||
*/
|
||||
if (next == NULL) {
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
continue;
|
||||
}
|
||||
/*
|
||||
* Find the next tuple to be processed before
|
||||
* unlinking then complete moving the pair to 'diff'.
|
||||
*/
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
ISC_LIST_APPEND(diff->tuples, tuple, link);
|
||||
} else
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
}
|
||||
|
||||
/*
|
||||
* Preserve any ongoing changes from a BIND 9.6.x upgrade.
|
||||
*
|
||||
* Any NSEC3PARAM records with flags other than OPTOUT named
|
||||
* in managing and should not be touched so revert such changes
|
||||
* taking into account any TTL change of the NSEC3PARAM RRset.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
if ((tuple->rdata.data[1] & ~DNS_NSEC3FLAG_OPTOUT) != 0) {
|
||||
/*
|
||||
* If we havn't had any adds then the tuple->ttl must
|
||||
* be the original ttl and should be used for any
|
||||
* future changes.
|
||||
*/
|
||||
if (!ttl_good) {
|
||||
ttl = tuple->ttl;
|
||||
ttl_good = ISC_TRUE;
|
||||
}
|
||||
op = (tuple->op == DNS_DIFFOP_DEL) ?
|
||||
DNS_DIFFOP_ADD : DNS_DIFFOP_DEL;
|
||||
CHECK(dns_difftuple_create(diff->mctx, op, name,
|
||||
ttl, &tuple->rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
dns_diff_appendminimal(diff, &tuple);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* We now have just the actual changes to the NSEC3PARAM RRset.
|
||||
* Convert the adds to delayed adds and the deletions into delayed
|
||||
* deletions.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
/*
|
||||
* If we havn't had any adds then the tuple->ttl must be the
|
||||
* original ttl and should be used for any future changes.
|
||||
*/
|
||||
if (!ttl_good) {
|
||||
ttl = tuple->ttl;
|
||||
ttl_good = ISC_TRUE;
|
||||
}
|
||||
if (tuple->op == DNS_DIFFOP_ADD) {
|
||||
/*
|
||||
* Look for any deletes which match this ADD ignoring
|
||||
* OPTOUT. We don't need to explictly remove them as
|
||||
* they will be removed a side effect of processing
|
||||
* the add.
|
||||
*/
|
||||
next = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
while (next != NULL) {
|
||||
unsigned char *next_data = next->rdata.data;
|
||||
unsigned char *tuple_data = tuple->rdata.data;
|
||||
if (next->op != DNS_DIFFOP_DEL ||
|
||||
next->rdata.length != tuple->rdata.length ||
|
||||
next_data[0] != tuple_data[0] ||
|
||||
next_data[2] != tuple_data[2] ||
|
||||
next_data[3] != tuple_data[3] ||
|
||||
next_data[4] != tuple_data[4] ||
|
||||
!memcmp(&next_data[5], &tuple_data[5],
|
||||
tuple_data[4])) {
|
||||
memcmp(next_data + 4, tuple_data + 4,
|
||||
tuple->rdata.length - 4)) {
|
||||
next = ISC_LIST_NEXT(next, link);
|
||||
continue;
|
||||
}
|
||||
op = (next->op == DNS_DIFFOP_DEL) ?
|
||||
DNS_DIFFOP_ADD : DNS_DIFFOP_DEL;
|
||||
CHECK(dns_difftuple_create(diff->mctx, op,
|
||||
name, next->ttl,
|
||||
&next->rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, next, link);
|
||||
dns_diff_appendminimal(diff, &next);
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
ISC_LIST_APPEND(diff->tuples, next, link);
|
||||
next = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
}
|
||||
|
||||
INSIST(tuple->rdata.data[1] & DNS_NSEC3FLAG_UPDATE);
|
||||
|
||||
/*
|
||||
* See if we already have a CREATE request in progress.
|
||||
*/
|
||||
dns_nsec3param_toprivate(&tuple->rdata, &rdata,
|
||||
privatetype, buf, sizeof(buf));
|
||||
buf[2] |= DNS_NSEC3FLAG_CREATE;
|
||||
buf[2] &= ~DNS_NSEC3FLAG_UPDATE;
|
||||
|
||||
CHECK(rr_exists(db, ver, name, &rdata, &flag));
|
||||
|
||||
if (!flag) {
|
||||
CHECK(dns_difftuple_create(diff->mctx,
|
||||
DNS_DIFFOP_ADD,
|
||||
name, tuple->ttl,
|
||||
&rdata,
|
||||
name, 0, &rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
}
|
||||
@@ -3193,20 +3285,20 @@ add_nsec3param_records(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
if (flag) {
|
||||
CHECK(dns_difftuple_create(diff->mctx,
|
||||
DNS_DIFFOP_DEL,
|
||||
name, tuple->ttl,
|
||||
&rdata,
|
||||
name, 0, &rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
}
|
||||
|
||||
/*
|
||||
* Remove the temporary add record.
|
||||
* Find the next tuple to be processed and remove the
|
||||
* temporary add record.
|
||||
*/
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_DEL,
|
||||
name, tuple->ttl,
|
||||
&tuple->rdata, &newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_DEL,
|
||||
name, ttl, &tuple->rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
dns_diff_appendminimal(diff, &tuple);
|
||||
dns_rdata_reset(&rdata);
|
||||
@@ -3214,48 +3306,33 @@ add_nsec3param_records(ns_client_t *client, dns_zone_t *zone, dns_db_t *db,
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
}
|
||||
|
||||
/*
|
||||
* Reverse any pending changes.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
if ((tuple->rdata.data[1] & ~DNS_NSEC3FLAG_OPTOUT) != 0) {
|
||||
op = (tuple->op == DNS_DIFFOP_DEL) ?
|
||||
DNS_DIFFOP_ADD : DNS_DIFFOP_DEL;
|
||||
CHECK(dns_difftuple_create(diff->mctx, op, name,
|
||||
tuple->ttl, &tuple->rdata,
|
||||
&newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
dns_diff_appendminimal(diff, &tuple);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Convert deletions into delayed deletions.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
INSIST(ttl_good);
|
||||
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
/*
|
||||
* See if we already have a REMOVE request in progress.
|
||||
*/
|
||||
dns_nsec3param_toprivate(&tuple->rdata, &rdata,
|
||||
privatetype, buf, sizeof(buf));
|
||||
buf[2] |= DNS_NSEC3FLAG_REMOVE;
|
||||
dns_nsec3param_toprivate(&tuple->rdata, &rdata, privatetype,
|
||||
buf, sizeof(buf));
|
||||
|
||||
buf[2] |= DNS_NSEC3FLAG_REMOVE | DNS_NSEC3FLAG_NONSEC;
|
||||
|
||||
CHECK(rr_exists(db, ver, name, &rdata, &flag));
|
||||
if (!flag) {
|
||||
buf[2] &= ~DNS_NSEC3FLAG_NONSEC;
|
||||
CHECK(rr_exists(db, ver, name, &rdata, &flag));
|
||||
}
|
||||
|
||||
if (!flag) {
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_ADD,
|
||||
name, tuple->ttl, &rdata,
|
||||
&newtuple));
|
||||
name, 0, &rdata, &newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
}
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_ADD, name,
|
||||
tuple->ttl, &tuple->rdata,
|
||||
&newtuple));
|
||||
ttl, &tuple->rdata, &newtuple));
|
||||
CHECK(do_one_tuple(&newtuple, db, ver, diff));
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
dns_diff_appendminimal(diff, &tuple);
|
||||
@@ -3288,8 +3365,7 @@ rollback_private(dns_db_t *db, dns_rdatatype_t privatetype,
|
||||
* Extract the changes to be rolled back.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(diff->tuples);
|
||||
tuple != NULL;
|
||||
tuple = next) {
|
||||
tuple != NULL; tuple = next) {
|
||||
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
|
||||
@@ -3336,7 +3412,7 @@ static isc_result_t
|
||||
add_signing_records(dns_db_t *db, dns_rdatatype_t privatetype,
|
||||
dns_dbversion_t *ver, dns_diff_t *diff)
|
||||
{
|
||||
dns_difftuple_t *tuple, *newtuple = NULL;
|
||||
dns_difftuple_t *tuple, *newtuple = NULL, *next;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
isc_boolean_t flag;
|
||||
@@ -3345,13 +3421,81 @@ add_signing_records(dns_db_t *db, dns_rdatatype_t privatetype,
|
||||
isc_uint16_t keyid;
|
||||
unsigned char buf[5];
|
||||
dns_name_t *name = dns_db_origin(db);
|
||||
dns_diff_t temp_diff;
|
||||
|
||||
dns_diff_init(diff->mctx, &temp_diff);
|
||||
|
||||
/*
|
||||
* Extract the DNSKEY tuples from the list.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(diff->tuples);
|
||||
tuple != NULL;
|
||||
tuple = ISC_LIST_NEXT(tuple, link)) {
|
||||
tuple != NULL; tuple = next) {
|
||||
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
|
||||
if (tuple->rdata.type != dns_rdatatype_dnskey)
|
||||
continue;
|
||||
|
||||
ISC_LIST_UNLINK(diff->tuples, tuple, link);
|
||||
ISC_LIST_APPEND(temp_diff.tuples, tuple, link);
|
||||
}
|
||||
|
||||
/*
|
||||
* Extract TTL changes pairs, we don't need signing records for these.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL; tuple = next) {
|
||||
if (tuple->op == DNS_DIFFOP_ADD) {
|
||||
/*
|
||||
* Walk the temp_diff list looking for the
|
||||
* corresponding delete.
|
||||
*/
|
||||
next = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
while (next != NULL) {
|
||||
unsigned char *next_data = next->rdata.data;
|
||||
unsigned char *tuple_data = tuple->rdata.data;
|
||||
if (next->op == DNS_DIFFOP_DEL &&
|
||||
dns_name_equal(&tuple->name, &next->name) &&
|
||||
next->rdata.length == tuple->rdata.length &&
|
||||
!memcmp(next_data, tuple_data,
|
||||
next->rdata.length)) {
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, next,
|
||||
link);
|
||||
ISC_LIST_APPEND(diff->tuples, next,
|
||||
link);
|
||||
break;
|
||||
}
|
||||
next = ISC_LIST_NEXT(next, link);
|
||||
}
|
||||
/*
|
||||
* If we have not found a pair move onto the next
|
||||
* tuple.
|
||||
*/
|
||||
if (next == NULL) {
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
continue;
|
||||
}
|
||||
/*
|
||||
* Find the next tuple to be processed before
|
||||
* unlinking then complete moving the pair to 'diff'.
|
||||
*/
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
ISC_LIST_APPEND(diff->tuples, tuple, link);
|
||||
} else
|
||||
next = ISC_LIST_NEXT(tuple, link);
|
||||
}
|
||||
|
||||
/*
|
||||
* Process the remaining DNSKEY entries.
|
||||
*/
|
||||
for (tuple = ISC_LIST_HEAD(temp_diff.tuples);
|
||||
tuple != NULL;
|
||||
tuple = ISC_LIST_HEAD(temp_diff.tuples)) {
|
||||
|
||||
ISC_LIST_UNLINK(temp_diff.tuples, tuple, link);
|
||||
ISC_LIST_APPEND(diff->tuples, tuple, link);
|
||||
|
||||
dns_rdata_tostruct(&tuple->rdata, &dnskey, NULL);
|
||||
if ((dnskey.flags &
|
||||
(DNS_KEYFLAG_OWNERMASK|DNS_KEYTYPE_NOAUTH))
|
||||
@@ -3392,126 +3536,9 @@ add_signing_records(dns_db_t *db, dns_rdatatype_t privatetype,
|
||||
INSIST(newtuple == NULL);
|
||||
}
|
||||
}
|
||||
failure:
|
||||
return (result);
|
||||
}
|
||||
|
||||
/*
|
||||
* Mark all NSEC3 chains for deletion without creating a NSEC chain as
|
||||
* a side effect of deleting the last chain.
|
||||
*/
|
||||
static isc_result_t
|
||||
delete_chains(dns_db_t *db, dns_dbversion_t *ver, dns_zone_t *zone,
|
||||
dns_diff_t *diff)
|
||||
{
|
||||
dns_dbnode_t *node = NULL;
|
||||
dns_difftuple_t *tuple = NULL;
|
||||
dns_name_t next;
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
dns_rdataset_t rdataset;
|
||||
isc_boolean_t flag;
|
||||
isc_result_t result = ISC_R_SUCCESS;
|
||||
unsigned char buf[DNS_NSEC3PARAM_BUFFERSIZE + 1];
|
||||
dns_name_t *origin = dns_zone_getorigin(zone);
|
||||
dns_rdatatype_t privatetype = dns_zone_getprivatetype(zone);
|
||||
|
||||
dns_name_init(&next, NULL);
|
||||
dns_rdataset_init(&rdataset);
|
||||
|
||||
result = dns_db_getoriginnode(db, &node);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
return (result);
|
||||
|
||||
/*
|
||||
* Cause all NSEC3 chains to be deleted.
|
||||
*/
|
||||
result = dns_db_findrdataset(db, node, ver, dns_rdatatype_nsec3param,
|
||||
0, (isc_stdtime_t) 0, &rdataset, NULL);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
goto try_private;
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto failure;
|
||||
|
||||
for (result = dns_rdataset_first(&rdataset);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdataset_next(&rdataset)) {
|
||||
dns_rdata_t private = DNS_RDATA_INIT;
|
||||
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_DEL, origin,
|
||||
rdataset.ttl, &rdata, &tuple));
|
||||
CHECK(do_one_tuple(&tuple, db, ver, diff));
|
||||
INSIST(tuple == NULL);
|
||||
|
||||
dns_nsec3param_toprivate(&rdata, &private, privatetype,
|
||||
buf, sizeof(buf));
|
||||
buf[2] = DNS_NSEC3FLAG_REMOVE | DNS_NSEC3FLAG_NONSEC;
|
||||
|
||||
CHECK(rr_exists(db, ver, origin, &rdata, &flag));
|
||||
|
||||
if (!flag) {
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_ADD,
|
||||
origin, 0, &rdata, &tuple));
|
||||
CHECK(do_one_tuple(&tuple, db, ver, diff));
|
||||
INSIST(tuple == NULL);
|
||||
}
|
||||
dns_rdata_reset(&rdata);
|
||||
}
|
||||
if (result != ISC_R_NOMORE)
|
||||
goto failure;
|
||||
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
|
||||
try_private:
|
||||
if (privatetype == 0)
|
||||
goto success;
|
||||
result = dns_db_findrdataset(db, node, ver, privatetype, 0,
|
||||
(isc_stdtime_t) 0, &rdataset, NULL);
|
||||
if (result == ISC_R_NOTFOUND)
|
||||
goto success;
|
||||
if (result != ISC_R_SUCCESS)
|
||||
goto failure;
|
||||
|
||||
for (result = dns_rdataset_first(&rdataset);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdataset_next(&rdataset)) {
|
||||
dns_rdataset_current(&rdataset, &rdata);
|
||||
INSIST(rdata.length <= sizeof(buf));
|
||||
memcpy(buf, rdata.data, rdata.length);
|
||||
|
||||
if (buf[0] != 0 ||
|
||||
buf[2] == (DNS_NSEC3FLAG_REMOVE | DNS_NSEC3FLAG_NONSEC)) {
|
||||
dns_rdata_reset(&rdata);
|
||||
continue;
|
||||
}
|
||||
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_DEL, origin,
|
||||
0, &rdata, &tuple));
|
||||
CHECK(do_one_tuple(&tuple, db, ver, diff));
|
||||
INSIST(tuple == NULL);
|
||||
|
||||
buf[2] = DNS_NSEC3FLAG_REMOVE | DNS_NSEC3FLAG_NONSEC;
|
||||
|
||||
CHECK(rr_exists(db, ver, origin, &rdata, &flag));
|
||||
|
||||
if (!flag) {
|
||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_ADD,
|
||||
origin, 0, &rdata, &tuple));
|
||||
CHECK(do_one_tuple(&tuple, db, ver, diff));
|
||||
INSIST(tuple == NULL);
|
||||
}
|
||||
dns_rdata_reset(&rdata);
|
||||
}
|
||||
if (result != ISC_R_NOMORE)
|
||||
goto failure;
|
||||
success:
|
||||
result = ISC_R_SUCCESS;
|
||||
|
||||
failure:
|
||||
if (dns_rdataset_isassociated(&rdataset))
|
||||
dns_rdataset_disassociate(&rdataset);
|
||||
dns_db_detachnode(db, &node);
|
||||
dns_diff_clear(&temp_diff);
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -3553,7 +3580,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
unsigned int options;
|
||||
dns_difftuple_t *tuple;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
unsigned char buf[DNS_NSEC3PARAM_BUFFERSIZE];
|
||||
isc_boolean_t had_dnskey;
|
||||
dns_rdatatype_t privatetype = dns_zone_getprivatetype(zone);
|
||||
|
||||
@@ -3702,7 +3728,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
* Check Requestor's Permissions. It seems a bit silly to do this
|
||||
* only after prerequisite testing, but that is what RFC2136 says.
|
||||
*/
|
||||
result = ISC_R_SUCCESS;
|
||||
if (ssutable == NULL)
|
||||
CHECK(checkupdateacl(client, dns_zone_getupdateacl(zone),
|
||||
"update", zonename, ISC_FALSE, ISC_FALSE));
|
||||
@@ -3938,19 +3963,6 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
"flag");
|
||||
continue;
|
||||
}
|
||||
|
||||
/*
|
||||
* NSEC3CHAIN creation flag.
|
||||
*/
|
||||
INSIST(rdata.length <= sizeof(buf));
|
||||
memcpy(buf, rdata.data, rdata.length);
|
||||
buf[1] |= DNS_NSEC3FLAG_UPDATE;
|
||||
rdata.data = buf;
|
||||
|
||||
/*
|
||||
* Force the TTL to zero for NSEC3PARAM records.
|
||||
*/
|
||||
ttl = 0;
|
||||
}
|
||||
|
||||
if ((options & DNS_ZONEOPT_CHECKWILDCARD) != 0 &&
|
||||
@@ -4174,7 +4186,8 @@ update_action(isc_task_t *task, isc_event_t *event) {
|
||||
* the last signature for the DNSKEY records are
|
||||
* remove any NSEC chain present will also be removed.
|
||||
*/
|
||||
CHECK(delete_chains(db, ver, zone, &diff));
|
||||
CHECK(dns_nsec3param_deletechains(db, ver, zone,
|
||||
&diff));
|
||||
} else if (has_dnskey && isdnssec(db, ver, privatetype)) {
|
||||
isc_uint32_t interval;
|
||||
interval = dns_zone_getsigvalidityinterval(zone);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2006, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2006, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: ntservice.c,v 1.14 2009/06/23 23:47:44 tbox Exp $ */
|
||||
/* $Id: ntservice.c,v 1.14.132.2 2011/01/13 22:30:17 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
#include <stdio.h>
|
||||
@@ -70,7 +70,8 @@ int bindmain()
|
||||
while (argv[i]) {
|
||||
if (!strcmp(argv[i], "-f") ||
|
||||
!strcmp(argv[i], "-g") ||
|
||||
!strcmp(argv[i], "-v")) {
|
||||
!strcmp(argv[i], "-v") ||
|
||||
!strcmp(argv[i], "-V")) {
|
||||
foreground = TRUE;
|
||||
break;
|
||||
}
|
||||
|
||||
+12
-10
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: xfrout.c,v 1.136 2009/06/30 02:52:32 each Exp $ */
|
||||
/* $Id: xfrout.c,v 1.136.132.2 2010/05/27 23:49:54 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -810,11 +810,13 @@ ns_xfr_start(ns_client_t *client, dns_rdatatype_t reqtype) {
|
||||
#ifdef DLZ
|
||||
{
|
||||
/*
|
||||
* Normal zone table does not have a match. Try the DLZ database
|
||||
* Normal zone table does not have a match.
|
||||
* Try the DLZ database
|
||||
*/
|
||||
if (client->view->dlzdatabase != NULL) {
|
||||
result = dns_dlzallowzonexfr(client->view,
|
||||
question_name, &client->peeraddr,
|
||||
question_name,
|
||||
&client->peeraddr,
|
||||
&db);
|
||||
|
||||
if (result == ISC_R_NOPERM) {
|
||||
@@ -1053,9 +1055,9 @@ ns_xfr_start(ns_client_t *client, dns_rdatatype_t reqtype) {
|
||||
|
||||
#ifdef DLZ
|
||||
if (is_dlz)
|
||||
CHECK(xfrout_ctx_create(mctx, client, request->id, question_name,
|
||||
reqtype, question_class, zone, db, ver,
|
||||
quota, stream,
|
||||
CHECK(xfrout_ctx_create(mctx, client, request->id,
|
||||
question_name, reqtype, question_class,
|
||||
zone, db, ver, quota, stream,
|
||||
dns_message_gettsigkey(request),
|
||||
tsigbuf,
|
||||
3600,
|
||||
@@ -1065,9 +1067,9 @@ ns_xfr_start(ns_client_t *client, dns_rdatatype_t reqtype) {
|
||||
&xfr));
|
||||
else
|
||||
#endif
|
||||
CHECK(xfrout_ctx_create(mctx, client, request->id, question_name,
|
||||
reqtype, question_class, zone, db, ver,
|
||||
quota, stream,
|
||||
CHECK(xfrout_ctx_create(mctx, client, request->id,
|
||||
question_name, reqtype, question_class,
|
||||
zone, db, ver, quota, stream,
|
||||
dns_message_gettsigkey(request),
|
||||
tsigbuf,
|
||||
dns_zone_getmaxxfrout(zone),
|
||||
|
||||
+65
-53
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: zoneconf.c,v 1.161 2009/12/04 21:09:32 marka Exp $ */
|
||||
/* $Id: zoneconf.c,v 1.161.4.8 2011/05/23 20:55:23 each Exp $ */
|
||||
|
||||
/*% */
|
||||
|
||||
@@ -121,7 +121,7 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
/* First check to see if ACL is defined within the zone */
|
||||
if (zconfig != NULL) {
|
||||
maps[0] = cfg_tuple_get(zconfig, "options");
|
||||
ns_config_get(maps, aclname, &aclobj);
|
||||
(void)ns_config_get(maps, aclname, &aclobj);
|
||||
if (aclobj != NULL) {
|
||||
aclp = NULL;
|
||||
goto parse_acl;
|
||||
@@ -135,8 +135,11 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
}
|
||||
|
||||
/* Check for default ACLs that haven't been parsed yet */
|
||||
if (vconfig != NULL)
|
||||
maps[i++] = cfg_tuple_get(vconfig, "options");
|
||||
if (vconfig != NULL) {
|
||||
const cfg_obj_t *options = cfg_tuple_get(vconfig, "options");
|
||||
if (options != NULL)
|
||||
maps[i++] = options;
|
||||
}
|
||||
if (config != NULL) {
|
||||
const cfg_obj_t *options = NULL;
|
||||
(void)cfg_map_get(config, "options", &options);
|
||||
@@ -146,7 +149,7 @@ configure_zone_acl(const cfg_obj_t *zconfig, const cfg_obj_t *vconfig,
|
||||
maps[i++] = ns_g_defaults;
|
||||
maps[i] = NULL;
|
||||
|
||||
result = ns_config_get(maps, aclname, &aclobj);
|
||||
(void)ns_config_get(maps, aclname, &aclobj);
|
||||
if (aclobj == NULL) {
|
||||
(*clearzacl)(zone);
|
||||
return (ISC_R_SUCCESS);
|
||||
@@ -386,7 +389,7 @@ zonetype_fromconfig(const cfg_obj_t *map) {
|
||||
isc_result_t result;
|
||||
|
||||
result = cfg_map_get(map, "type", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
return (ns_config_getzonetype(obj));
|
||||
}
|
||||
|
||||
@@ -450,7 +453,7 @@ checknames(dns_zonetype_t ztype, const cfg_obj_t **maps,
|
||||
INSIST(0);
|
||||
}
|
||||
result = ns_checknames_get(maps, zone, objp);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && objp != NULL && *objp != NULL);
|
||||
}
|
||||
|
||||
isc_result_t
|
||||
@@ -504,7 +507,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
maps[i++] = options;
|
||||
}
|
||||
maps[i++] = ns_g_defaults;
|
||||
maps[i++] = NULL;
|
||||
maps[i] = NULL;
|
||||
|
||||
if (vconfig != NULL)
|
||||
RETERR(ns_config_getclass(cfg_tuple_get(vconfig, "class"),
|
||||
@@ -558,6 +561,19 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
if (result == ISC_R_SUCCESS)
|
||||
filename = cfg_obj_asstring(obj);
|
||||
|
||||
/*
|
||||
* Unless we're using some alternative database, a master zone
|
||||
* will be needing a master file.
|
||||
*/
|
||||
if (ztype == dns_zone_master && cpval == default_dbtype &&
|
||||
filename == NULL) {
|
||||
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||
NS_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||
"zone '%s': 'file' not specified",
|
||||
zname);
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
masterformat = dns_masterformat_text;
|
||||
obj = NULL;
|
||||
result= ns_config_get(maps, "masterfile-format", &obj);
|
||||
@@ -593,7 +609,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "dialup", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (cfg_obj_isboolean(obj)) {
|
||||
if (cfg_obj_asboolean(obj))
|
||||
dialup = dns_dialuptype_yes;
|
||||
@@ -616,7 +632,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "zone-statistics", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
zonestats_on = cfg_obj_asboolean(obj);
|
||||
zoneqrystats = NULL;
|
||||
if (zonestats_on) {
|
||||
@@ -635,7 +651,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
if (ztype != dns_zone_stub) {
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "notify", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (cfg_obj_isboolean(obj)) {
|
||||
if (cfg_obj_asboolean(obj))
|
||||
notifytype = dns_notifytype_yes;
|
||||
@@ -671,19 +687,19 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "notify-source", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setnotifysrc4(zone, cfg_obj_assockaddr(obj)));
|
||||
ns_add_reserved_dispatch(ns_g_server, cfg_obj_assockaddr(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "notify-source-v6", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setnotifysrc6(zone, cfg_obj_assockaddr(obj)));
|
||||
ns_add_reserved_dispatch(ns_g_server, cfg_obj_assockaddr(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "notify-to-soa", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_NOTIFYTOSOA,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
@@ -696,17 +712,17 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-transfer-time-out", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setmaxxfrout(zone, cfg_obj_asuint32(obj) * 60);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-transfer-idle-out", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setidleout(zone, cfg_obj_asuint32(obj) * 60);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-journal-size", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setjournalsize(zone, -1);
|
||||
if (cfg_obj_isstring(obj)) {
|
||||
const char *str = cfg_obj_asstring(obj);
|
||||
@@ -730,13 +746,13 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "ixfr-from-differences", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (cfg_obj_isboolean(obj))
|
||||
ixfrdiff = cfg_obj_asboolean(obj);
|
||||
else if (strcasecmp(cfg_obj_asstring(obj), "master") &&
|
||||
else if (!strcasecmp(cfg_obj_asstring(obj), "master") &&
|
||||
ztype == dns_zone_master)
|
||||
ixfrdiff = ISC_TRUE;
|
||||
else if (strcasecmp(cfg_obj_asstring(obj), "slave") &&
|
||||
else if (!strcasecmp(cfg_obj_asstring(obj), "slave") &&
|
||||
ztype == dns_zone_slave)
|
||||
ixfrdiff = ISC_TRUE;
|
||||
else
|
||||
@@ -759,23 +775,23 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "notify-delay", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setnotifydelay(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-sibling", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_CHECKSIBLING,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "zero-no-soa-ttl", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setzeronosoattl(zone, cfg_obj_asboolean(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "nsec3-test-zone", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_NSEC3TESTZONE,
|
||||
cfg_obj_asboolean(obj));
|
||||
}
|
||||
@@ -804,7 +820,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-validity-interval", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
{
|
||||
const cfg_obj_t *validity, *resign;
|
||||
|
||||
@@ -835,28 +851,28 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-signatures", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setsignatures(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-nodes", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setnodes(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "sig-signing-type", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setprivatetype(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "update-check-ksk", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_UPDATECHECKKSK,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "dnssec-dnskey-kskonly", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_DNSKEYKSKONLY,
|
||||
cfg_obj_asboolean(obj));
|
||||
} else if (ztype == dns_zone_slave) {
|
||||
@@ -871,7 +887,6 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
*/
|
||||
if (ztype == dns_zone_master) {
|
||||
isc_boolean_t allow = ISC_FALSE, maint = ISC_FALSE;
|
||||
isc_boolean_t create = ISC_FALSE;
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-wildcard", &obj);
|
||||
@@ -883,7 +898,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-dup-records", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
||||
fail = ISC_FALSE;
|
||||
check = ISC_TRUE;
|
||||
@@ -898,7 +913,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-mx", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
||||
fail = ISC_FALSE;
|
||||
check = ISC_TRUE;
|
||||
@@ -913,13 +928,13 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-integrity", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_CHECKINTEGRITY,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-mx-cname", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
||||
warn = ISC_TRUE;
|
||||
ignore = ISC_FALSE;
|
||||
@@ -934,7 +949,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "check-srv-cname", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
if (strcasecmp(cfg_obj_asstring(obj), "warn") == 0) {
|
||||
warn = ISC_TRUE;
|
||||
ignore = ISC_FALSE;
|
||||
@@ -949,7 +964,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "dnssec-secure-to-insecure", &obj);
|
||||
INSIST(obj != NULL);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_SECURETOINSECURE,
|
||||
cfg_obj_asboolean(obj));
|
||||
|
||||
@@ -961,15 +976,12 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
allow = ISC_TRUE;
|
||||
else if (strcasecmp(arg, "maintain") == 0)
|
||||
allow = maint = ISC_TRUE;
|
||||
else if (strcasecmp(arg, "create") == 0)
|
||||
allow = maint = create = ISC_TRUE;
|
||||
else if (strcasecmp(arg, "off") == 0)
|
||||
;
|
||||
else
|
||||
INSIST(0);
|
||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_ALLOW, allow);
|
||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_MAINTAIN, maint);
|
||||
dns_zone_setkeyopt(zone, DNS_ZONEKEY_CREATE, create);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -981,7 +993,7 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
case dns_zone_stub:
|
||||
count = 0;
|
||||
obj = NULL;
|
||||
result = cfg_map_get(zoptions, "masters", &obj);
|
||||
(void)cfg_map_get(zoptions, "masters", &obj);
|
||||
if (obj != NULL) {
|
||||
addrs = NULL;
|
||||
keynames = NULL;
|
||||
@@ -1000,61 +1012,61 @@ ns_zone_configure(const cfg_obj_t *config, const cfg_obj_t *vconfig,
|
||||
if (count > 1) {
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "multi-master", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
multi = cfg_obj_asboolean(obj);
|
||||
}
|
||||
dns_zone_setoption(zone, DNS_ZONEOPT_MULTIMASTER, multi);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-transfer-time-in", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setmaxxfrin(zone, cfg_obj_asuint32(obj) * 60);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-transfer-idle-in", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setidlein(zone, cfg_obj_asuint32(obj) * 60);
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-refresh-time", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setmaxrefreshtime(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "min-refresh-time", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setminrefreshtime(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "max-retry-time", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setmaxretrytime(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "min-retry-time", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
dns_zone_setminretrytime(zone, cfg_obj_asuint32(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "transfer-source", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setxfrsource4(zone, cfg_obj_assockaddr(obj)));
|
||||
ns_add_reserved_dispatch(ns_g_server, cfg_obj_assockaddr(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "transfer-source-v6", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setxfrsource6(zone, cfg_obj_assockaddr(obj)));
|
||||
ns_add_reserved_dispatch(ns_g_server, cfg_obj_assockaddr(obj));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "alt-transfer-source", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setaltxfrsource4(zone, cfg_obj_assockaddr(obj)));
|
||||
|
||||
obj = NULL;
|
||||
result = ns_config_get(maps, "alt-transfer-source-v6", &obj);
|
||||
INSIST(result == ISC_R_SUCCESS);
|
||||
INSIST(result == ISC_R_SUCCESS && obj != NULL);
|
||||
RETERR(dns_zone_setaltxfrsource6(zone, cfg_obj_assockaddr(obj)));
|
||||
|
||||
obj = NULL;
|
||||
|
||||
+25
-3
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" $Id: nsupdate.1,v 1.11.42.1 2009/12/17 02:57:07 tbox Exp $
|
||||
.\" $Id: nsupdate.1,v 1.11.42.2 2010/07/10 02:41:30 tbox Exp $
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
@@ -241,6 +241,28 @@ or
|
||||
\fB\-k\fR.
|
||||
.RE
|
||||
.PP
|
||||
\fBgsstsig\fR
|
||||
.RS 4
|
||||
Use GSS\-TSIG to sign the updated. This is equivalent to specifying
|
||||
\fB\-g\fR
|
||||
on the commandline.
|
||||
.RE
|
||||
.PP
|
||||
\fBoldgsstsig\fR
|
||||
.RS 4
|
||||
Use the Windows 2000 version of GSS\-TSIG to sign the updated. This is equivalent to specifying
|
||||
\fB\-o\fR
|
||||
on the commandline.
|
||||
.RE
|
||||
.PP
|
||||
\fBrealm\fR {[realm_name]}
|
||||
.RS 4
|
||||
When using GSS\-TSIG use
|
||||
\fIrealm_name\fR
|
||||
rather than the default realm in
|
||||
\fIkrb5.conf\fR. If no realm is specified the saved realm is cleared.
|
||||
.RE
|
||||
.PP
|
||||
\fBprereq nxdomain\fR {domain\-name}
|
||||
.RS 4
|
||||
Requires that no resource record of any type exists with name
|
||||
@@ -413,7 +435,7 @@ RFC 2931,
|
||||
.PP
|
||||
The TSIG key is redundantly stored in two separate files. This is a consequence of nsupdate using the DST library for its cryptographic operations, and may change in future releases.
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2004\-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004\-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
Copyright \(co 2000\-2003 Internet Software Consortium.
|
||||
.br
|
||||
|
||||
+90
-14
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: nsupdate.c,v 1.173 2009/09/29 15:06:06 fdupont Exp $ */
|
||||
/* $Id: nsupdate.c,v 1.173.66.15 2011/05/23 22:23:05 each Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -195,6 +195,7 @@ ddebug(const char *format, ...) ISC_FORMAT_PRINTF(1, 2);
|
||||
#ifdef GSSAPI
|
||||
static dns_fixedname_t fkname;
|
||||
static isc_sockaddr_t *kserver = NULL;
|
||||
static char *realm = NULL;
|
||||
static char servicename[DNS_NAME_FORMATSIZE];
|
||||
static dns_name_t *keyname;
|
||||
typedef struct nsu_gssinfo {
|
||||
@@ -487,6 +488,19 @@ parse_hmac(dns_name_t **hmac, const char *hmacstr, size_t len) {
|
||||
return (digestbits);
|
||||
}
|
||||
|
||||
static int
|
||||
basenamelen(const char *file) {
|
||||
int len = strlen(file);
|
||||
|
||||
if (len > 1 && file[len - 1] == '.')
|
||||
len -= 1;
|
||||
else if (len > 8 && strcmp(file + len - 8, ".private") == 0)
|
||||
len -= 8;
|
||||
else if (len > 4 && strcmp(file + len - 4, ".key") == 0)
|
||||
len -= 4;
|
||||
return (len);
|
||||
}
|
||||
|
||||
static void
|
||||
setup_keystr(void) {
|
||||
unsigned char *secret = NULL;
|
||||
@@ -548,7 +562,8 @@ setup_keystr(void) {
|
||||
|
||||
debug("keycreate");
|
||||
result = dns_tsigkey_create(keyname, hmacname, secret, secretlen,
|
||||
ISC_TRUE, NULL, 0, 0, mctx, NULL, &tsigkey);
|
||||
ISC_FALSE, NULL, 0, 0, mctx, NULL,
|
||||
&tsigkey);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fprintf(stderr, "could not create key from %s: %s\n",
|
||||
keystr, dns_result_totext(result));
|
||||
@@ -626,6 +641,9 @@ setup_keyfile(isc_mem_t *mctx, isc_log_t *lctx) {
|
||||
|
||||
debug("Creating key...");
|
||||
|
||||
if (sig0key != NULL)
|
||||
dst_key_free(&sig0key);
|
||||
|
||||
/* Try reading the key from a K* pair */
|
||||
result = dst_key_fromnamedfile(keyfile, NULL,
|
||||
DST_TYPE_PRIVATE | DST_TYPE_KEY, mctx,
|
||||
@@ -639,8 +657,9 @@ setup_keyfile(isc_mem_t *mctx, isc_log_t *lctx) {
|
||||
}
|
||||
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "could not read key from %s: %s\n",
|
||||
keyfile, isc_result_totext(result));
|
||||
fprintf(stderr, "could not read key from %.*s.{private,key}: "
|
||||
"%s\n", basenamelen(keyfile), keyfile,
|
||||
isc_result_totext(result));
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -669,14 +688,16 @@ setup_keyfile(isc_mem_t *mctx, isc_log_t *lctx) {
|
||||
hmacname, dstkey, ISC_FALSE,
|
||||
NULL, 0, 0, mctx, NULL,
|
||||
&tsigkey);
|
||||
dst_key_free(&dstkey);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
fprintf(stderr, "could not create key from %s: %s\n",
|
||||
keyfile, isc_result_totext(result));
|
||||
dst_key_free(&dstkey);
|
||||
return;
|
||||
}
|
||||
} else
|
||||
sig0key = dstkey;
|
||||
} else {
|
||||
dst_key_attach(dstkey, &sig0key);
|
||||
dst_key_free(&dstkey);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
@@ -885,9 +906,12 @@ setup_system(void) {
|
||||
|
||||
if (keystr != NULL)
|
||||
setup_keystr();
|
||||
else if (local_only)
|
||||
read_sessionkey(mctx, lctx);
|
||||
else if (keyfile != NULL)
|
||||
else if (local_only) {
|
||||
result = read_sessionkey(mctx, lctx);
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("can't read key from %s: %s\n",
|
||||
keyfile, isc_result_totext(result));
|
||||
} else if (keyfile != NULL)
|
||||
setup_keyfile(mctx, lctx);
|
||||
}
|
||||
|
||||
@@ -1462,7 +1486,7 @@ evaluate_key(char *cmdline) {
|
||||
if (tsigkey != NULL)
|
||||
dns_tsigkey_detach(&tsigkey);
|
||||
result = dns_tsigkey_create(keyname, hmacname, secret, secretlen,
|
||||
ISC_TRUE, NULL, 0, 0, mctx, NULL,
|
||||
ISC_FALSE, NULL, 0, 0, mctx, NULL,
|
||||
&tsigkey);
|
||||
isc_mem_free(mctx, secret);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
@@ -1500,6 +1524,31 @@ evaluate_zone(char *cmdline) {
|
||||
return (STATUS_MORE);
|
||||
}
|
||||
|
||||
static isc_uint16_t
|
||||
evaluate_realm(char *cmdline) {
|
||||
#ifdef GSSAPI
|
||||
char *word;
|
||||
char buf[1024];
|
||||
|
||||
word = nsu_strsep(&cmdline, " \t\r\n");
|
||||
if (*word == 0) {
|
||||
if (realm != NULL)
|
||||
isc_mem_free(mctx, realm);
|
||||
realm = NULL;
|
||||
return (STATUS_MORE);
|
||||
}
|
||||
|
||||
snprintf(buf, sizeof(buf), "@%s", word);
|
||||
realm = isc_mem_strdup(mctx, buf);
|
||||
if (realm == NULL)
|
||||
fatal("out of memory");
|
||||
return (STATUS_MORE);
|
||||
#else
|
||||
UNUSED(cmdline);
|
||||
return (STATUS_SYNTAX);
|
||||
#endif
|
||||
}
|
||||
|
||||
static isc_uint16_t
|
||||
evaluate_ttl(char *cmdline) {
|
||||
char *word;
|
||||
@@ -1891,6 +1940,8 @@ get_next_command(void) {
|
||||
usegsstsig = ISC_FALSE;
|
||||
return (evaluate_key(cmdline));
|
||||
}
|
||||
if (strcasecmp(word, "realm") == 0)
|
||||
return (evaluate_realm(cmdline));
|
||||
if (strcasecmp(word, "gsstsig") == 0) {
|
||||
#ifdef GSSAPI
|
||||
usegsstsig = ISC_TRUE;
|
||||
@@ -2097,6 +2148,10 @@ send_update(dns_name_t *zonename, isc_sockaddr_t *master,
|
||||
fprintf(stderr, "Sending update to %s\n", addrbuf);
|
||||
}
|
||||
|
||||
/* Windows doesn't like the tsig name to be compressed. */
|
||||
if (updatemsg->tsigname)
|
||||
updatemsg->tsigname->attributes |= DNS_NAMEATTR_NOCOMPRESS;
|
||||
|
||||
result = dns_request_createvia3(requestmgr, updatemsg, srcaddr,
|
||||
master, options, tsigkey, timeout,
|
||||
udp_timeout, udp_retries, global_task,
|
||||
@@ -2206,6 +2261,7 @@ recvsoa(isc_task_t *task, isc_event_t *event) {
|
||||
}
|
||||
check_result(result, "dns_request_getresponse");
|
||||
section = DNS_SECTION_ANSWER;
|
||||
POST(section);
|
||||
if (debugging)
|
||||
show_message(stderr, rcvmsg, "Reply from SOA query:");
|
||||
|
||||
@@ -2419,7 +2475,7 @@ start_gssrequest(dns_name_t *master)
|
||||
servname = dns_fixedname_name(&fname);
|
||||
|
||||
result = isc_string_printf(servicename, sizeof(servicename),
|
||||
"DNS/%s", namestr);
|
||||
"DNS/%s%s", namestr, realm ? realm : "");
|
||||
if (result != ISC_R_SUCCESS)
|
||||
fatal("isc_string_printf(servicename) failed: %s",
|
||||
isc_result_totext(result));
|
||||
@@ -2457,7 +2513,6 @@ start_gssrequest(dns_name_t *master)
|
||||
isc_result_totext(result));
|
||||
|
||||
/* Build first request. */
|
||||
|
||||
context = GSS_C_NO_CONTEXT;
|
||||
result = dns_tkey_buildgssquery(rmsg, keyname, servname, NULL, 0,
|
||||
&context, use_win2k_gsstsig);
|
||||
@@ -2694,6 +2749,7 @@ start_update(void) {
|
||||
dns_name_init(name, NULL);
|
||||
dns_name_clone(userzone, name);
|
||||
} else {
|
||||
dns_rdataset_t *tmprdataset;
|
||||
result = dns_message_firstname(updatemsg, section);
|
||||
if (result == ISC_R_NOMORE) {
|
||||
section = DNS_SECTION_PREREQUISITE;
|
||||
@@ -2711,6 +2767,19 @@ start_update(void) {
|
||||
dns_message_currentname(updatemsg, section, &firstname);
|
||||
dns_name_init(name, NULL);
|
||||
dns_name_clone(firstname, name);
|
||||
/*
|
||||
* Looks to see if the first name references a DS record
|
||||
* and if that name is not the root remove a label as DS
|
||||
* records live in the parent zone so we need to start our
|
||||
* search one label up.
|
||||
*/
|
||||
tmprdataset = ISC_LIST_HEAD(firstname->list);
|
||||
if (section == DNS_SECTION_UPDATE &&
|
||||
!dns_name_equal(firstname, dns_rootname) &&
|
||||
tmprdataset->type == dns_rdatatype_ds) {
|
||||
unsigned int labels = dns_name_countlabels(name);
|
||||
dns_name_getlabelsequence(name, 1, labels - 1, name);
|
||||
}
|
||||
}
|
||||
|
||||
ISC_LIST_INIT(name->list);
|
||||
@@ -2745,8 +2814,15 @@ cleanup(void) {
|
||||
isc_mem_put(mctx, kserver, sizeof(isc_sockaddr_t));
|
||||
kserver = NULL;
|
||||
}
|
||||
if (realm != NULL) {
|
||||
isc_mem_free(mctx, realm);
|
||||
realm = NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
if (sig0key != NULL)
|
||||
dst_key_free(&sig0key);
|
||||
|
||||
ddebug("Shutting down task manager");
|
||||
isc_taskmgr_destroy(&taskmgr);
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -18,7 +18,7 @@
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- $Id: nsupdate.docbook,v 1.41.42.1 2009/12/16 07:12:49 each Exp $ -->
|
||||
<!-- $Id: nsupdate.docbook,v 1.41.42.3 2010/07/09 23:46:27 tbox Exp $ -->
|
||||
<refentry id="man.nsupdate">
|
||||
<refentryinfo>
|
||||
<date>Aug 25, 2009</date>
|
||||
@@ -41,6 +41,7 @@
|
||||
<year>2007</year>
|
||||
<year>2008</year>
|
||||
<year>2009</year>
|
||||
<year>2010</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
<copyright>
|
||||
@@ -382,6 +383,45 @@
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<command>gsstsig</command>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use GSS-TSIG to sign the updated. This is equivalent to
|
||||
specifying <option>-g</option> on the commandline.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<command>oldgsstsig</command>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Use the Windows 2000 version of GSS-TSIG to sign the updated.
|
||||
This is equivalent to specifying <option>-o</option> on the
|
||||
commandline.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<command>realm</command>
|
||||
<arg choice="req"><optional>realm_name</optional></arg>
|
||||
</term>
|
||||
<listitem>
|
||||
<para>
|
||||
When using GSS-TSIG use <parameter>realm_name</parameter> rather
|
||||
than the default realm in <filename>krb5.conf</filename>. If no
|
||||
realm is specified the saved realm is cleared.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>
|
||||
<command>prereq nxdomain</command>
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -14,7 +14,7 @@
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- $Id: nsupdate.html,v 1.48.42.1 2009/12/17 02:57:07 tbox Exp $ -->
|
||||
<!-- $Id: nsupdate.html,v 1.48.42.2 2010/07/10 02:41:30 tbox Exp $ -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
@@ -32,7 +32,7 @@
|
||||
<div class="cmdsynopsis"><p><code class="command">nsupdate</code> [<code class="option">-d</code>] [<code class="option">-D</code>] [[<code class="option">-g</code>] | [<code class="option">-o</code>] | [<code class="option">-l</code>] | [<code class="option">-y <em class="replaceable"><code>[<span class="optional">hmac:</span>]keyname:secret</code></em></code>] | [<code class="option">-k <em class="replaceable"><code>keyfile</code></em></code>]] [<code class="option">-t <em class="replaceable"><code>timeout</code></em></code>] [<code class="option">-u <em class="replaceable"><code>udptimeout</code></em></code>] [<code class="option">-r <em class="replaceable"><code>udpretries</code></em></code>] [<code class="option">-R <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-v</code>] [filename]</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543453"></a><h2>DESCRIPTION</h2>
|
||||
<a name="id2543457"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">nsupdate</strong></span>
|
||||
is used to submit Dynamic DNS Update requests as defined in RFC 2136
|
||||
to a name server.
|
||||
@@ -192,7 +192,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543785"></a><h2>INPUT FORMAT</h2>
|
||||
<a name="id2543788"></a><h2>INPUT FORMAT</h2>
|
||||
<p><span><strong class="command">nsupdate</strong></span>
|
||||
reads input from
|
||||
<em class="parameter"><code>filename</code></em>
|
||||
@@ -306,6 +306,30 @@
|
||||
overrides any key specified on the command line via
|
||||
<code class="option">-y</code> or <code class="option">-k</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
<span><strong class="command">gsstsig</strong></span>
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Use GSS-TSIG to sign the updated. This is equivalent to
|
||||
specifying <code class="option">-g</code> on the commandline.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
<span><strong class="command">oldgsstsig</strong></span>
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
Use the Windows 2000 version of GSS-TSIG to sign the updated.
|
||||
This is equivalent to specifying <code class="option">-o</code> on the
|
||||
commandline.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
<span><strong class="command">realm</strong></span>
|
||||
{[<span class="optional">realm_name</span>]}
|
||||
</span></dt>
|
||||
<dd><p>
|
||||
When using GSS-TSIG use <em class="parameter"><code>realm_name</code></em> rather
|
||||
than the default realm in <code class="filename">krb5.conf</code>. If no
|
||||
realm is specified the saved realm is cleared.
|
||||
</p></dd>
|
||||
<dt><span class="term">
|
||||
<span><strong class="command">prereq nxdomain</strong></span>
|
||||
{domain-name}
|
||||
@@ -456,7 +480,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544626"></a><h2>EXAMPLES</h2>
|
||||
<a name="id2544700"></a><h2>EXAMPLES</h2>
|
||||
<p>
|
||||
The examples below show how
|
||||
<span><strong class="command">nsupdate</strong></span>
|
||||
@@ -510,7 +534,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544669"></a><h2>FILES</h2>
|
||||
<a name="id2544744"></a><h2>FILES</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term"><code class="constant">/etc/resolv.conf</code></span></dt>
|
||||
<dd><p>
|
||||
@@ -533,7 +557,7 @@
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2544753"></a><h2>SEE ALSO</h2>
|
||||
<a name="id2544827"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<em class="citetitle">RFC 2136</em>,
|
||||
<em class="citetitle">RFC 3007</em>,
|
||||
@@ -548,7 +572,7 @@
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2542148"></a><h2>BUGS</h2>
|
||||
<a name="id2542154"></a><h2>BUGS</h2>
|
||||
<p>
|
||||
The TSIG key is redundantly stored in two separate files.
|
||||
This is a consequence of nsupdate using the DST library
|
||||
|
||||
+11
-3
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: rndc.c,v 1.126.66.1 2009/12/18 07:59:09 each Exp $ */
|
||||
/* $Id: rndc.c,v 1.126.66.7 2011/02/03 12:17:22 tbox Exp $ */
|
||||
|
||||
/*! \file */
|
||||
|
||||
@@ -96,7 +96,7 @@ usage(int status) ISC_PLATFORM_NORETURN_POST;
|
||||
static void
|
||||
usage(int status) {
|
||||
fprintf(stderr, "\
|
||||
Usage: %s [-c config] [-s server] [-p port]\n\
|
||||
Usage: %s [-b address] [-c config] [-s server] [-p port]\n\
|
||||
[-k key-file ] [-y key] [-V] command\n\
|
||||
\n\
|
||||
command is one of the following:\n\
|
||||
@@ -119,10 +119,14 @@ command is one of the following:\n\
|
||||
reconfig Reload configuration file and new zones only.\n\
|
||||
sign zone [class [view]]\n\
|
||||
Update zone keys, and sign as needed.\n\
|
||||
loadkeys zone [class [view]]\n\
|
||||
Update keys without signing immediately.\n\
|
||||
stats Write server statistics to the statistics file.\n\
|
||||
querylog Toggle query logging.\n\
|
||||
dumpdb [-all|-cache|-zones] [view ...]\n\
|
||||
Dump cache(s) to the dump file (named_dump.db).\n\
|
||||
secroots [view ...]\n\
|
||||
Write security roots to the secroots file.\n\
|
||||
stop Save pending updates to master files and stop the server.\n\
|
||||
stop -p Save pending updates to master files and stop the server\n\
|
||||
reporting process id.\n\
|
||||
@@ -141,6 +145,10 @@ command is one of the following:\n\
|
||||
validation newstate [view]\n\
|
||||
Enable / disable DNSSEC validation.\n\
|
||||
*restart Restart the server.\n\
|
||||
addzone [\"file\"] zone [class [view]] { zone-options }\n\
|
||||
Add zone to given view. Requires new-zone-file option.\n\
|
||||
delzone [\"file\"] zone [class [view]]\n\
|
||||
Removes zone from given view. Requires new-zone-file option.\n\
|
||||
\n\
|
||||
* == not yet implemented\n\
|
||||
Version: %s\n",
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.138 2009/12/05 23:31:40 each Exp $
|
||||
# $Id: Makefile.in,v 1.138.2.2 2010/09/29 23:46:41 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -41,7 +41,7 @@ LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
||||
|
||||
LIBS = @LIBS@
|
||||
|
||||
SUBDIRS = db dst master mem names net rbt sockaddr tasks timers system
|
||||
SUBDIRS = db dst master mem hashes names net rbt sockaddr tasks timers system
|
||||
|
||||
# Test programs that are built by default:
|
||||
# cfg_test is needed for regenerating doc/misc/options
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 1999-2002 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.32 2009/12/05 23:31:40 each Exp $
|
||||
# $Id: Makefile.in,v 1.32.2.2 2010/08/13 23:46:27 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -28,13 +28,15 @@ CWARNINGS =
|
||||
|
||||
DNSLIBS = ../../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||
ISCLIBS = ../../../lib/isc/libisc.@A@
|
||||
ISCCFGLIBS = ../../../lib/isccfg/libisccfg.@A@
|
||||
|
||||
DNSDEPLIBS = ../../../lib/dns/libdns.@A@
|
||||
ISCDEPLIBS = ../../../lib/isc/libisc.@A@
|
||||
ISCCFGDEPLIBS = ../../../lib/isccfg/libisccfg.@A@
|
||||
|
||||
DEPLIBS = ${DNSDEPLIBS} ${ISCDEPLIBS}
|
||||
DEPLIBS = ${DNSDEPLIBS} ${ISCCFGDEPLIBS} ${ISCDEPLIBS}
|
||||
|
||||
LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
||||
LIBS = ${DNSLIBS} ${ISCCFGLIBS} ${ISCLIBS} @LIBS@
|
||||
|
||||
TLIB = ../../../lib/tests/libt_api.@A@
|
||||
|
||||
|
||||
+18
-17
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_db.c,v 1.39 2009/09/01 00:22:25 jinmei Exp $ */
|
||||
/* $Id: t_db.c,v 1.39.104.2 2011/03/12 04:58:25 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -118,7 +118,6 @@ t_dns_db_load(char **av) {
|
||||
isc_result_t exp_load_result;
|
||||
isc_result_t exp_find_result;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
@@ -292,8 +291,6 @@ t_dns_db_zc_x(char *filename, char *db_type, char *origin, char *class,
|
||||
isc_buffer_t origin_buffer;
|
||||
dns_fixedname_t dns_origin;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
@@ -769,8 +766,6 @@ t_dns_db_currentversion(char **av) {
|
||||
dns_dbversion_t *cversionp;
|
||||
dns_dbversion_t *nversionp;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
filename = T_ARG(0);
|
||||
db_type = T_ARG(1);
|
||||
origin = T_ARG(2);
|
||||
@@ -1050,8 +1045,6 @@ t_dns_db_newversion(char **av) {
|
||||
dns_dbversion_t *nversionp;
|
||||
dns_rdatalist_t rdatalist;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
filename = T_ARG(0);
|
||||
db_type = T_ARG(1);
|
||||
origin = T_ARG(2);
|
||||
@@ -1384,7 +1377,6 @@ t_dns_db_closeversion_1(char **av) {
|
||||
existing_type = T_ARG(8);
|
||||
|
||||
nfails = 0;
|
||||
result = T_UNRESOLVED;
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
@@ -1796,7 +1788,6 @@ t_dns_db_closeversion_2(char **av) {
|
||||
existing_type = T_ARG(8);
|
||||
|
||||
nfails = 0;
|
||||
result = T_UNRESOLVED;
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
@@ -2259,8 +2250,6 @@ t_dns_db_expirenode(char **av) {
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
/*
|
||||
* Find a node, mark it as stale, do a dns_db_find on the name and
|
||||
* expect it to fail.
|
||||
@@ -2464,7 +2453,6 @@ t_dns_db_findnode_1(char **av) {
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
t_info("testing using file %s and name %s\n", filename, find_name);
|
||||
|
||||
@@ -2526,6 +2514,13 @@ t_dns_db_findnode_1(char **av) {
|
||||
isc_buffer_add(&name_buffer, len);
|
||||
dns_result = dns_name_fromtext(dns_fixedname_name(&dns_name),
|
||||
&name_buffer, NULL, 0, NULL);
|
||||
if (dns_result != ISC_R_SUCCESS) {
|
||||
t_info("dns_name_fromtext failed %s\n",
|
||||
dns_result_totext(dns_result));
|
||||
dns_db_detach(&db);
|
||||
isc_mem_destroy(&mctx);
|
||||
return(T_UNRESOLVED);
|
||||
}
|
||||
|
||||
dns_result = dns_db_findnode(db, dns_fixedname_name(&dns_name),
|
||||
ISC_FALSE, &nodep);
|
||||
@@ -2623,7 +2618,6 @@ t_dns_db_findnode_2(char **av) {
|
||||
model = T_ARG(4);
|
||||
newname = T_ARG(5);
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
db = NULL;
|
||||
mctx = NULL;
|
||||
ectx = NULL;
|
||||
@@ -2682,6 +2676,15 @@ t_dns_db_findnode_2(char **av) {
|
||||
isc_buffer_add(&name_buffer, len);
|
||||
dns_result = dns_name_fromtext(dns_fixedname_name(&dns_name),
|
||||
&name_buffer, NULL, 0, NULL);
|
||||
if (dns_result != ISC_R_SUCCESS) {
|
||||
t_info("dns_name_fromtext returned %s\n",
|
||||
dns_result_totext(dns_result));
|
||||
dns_db_detach(&db);
|
||||
isc_hash_destroy();
|
||||
isc_entropy_detach(&ectx);
|
||||
isc_mem_destroy(&mctx);
|
||||
return(T_UNRESOLVED);
|
||||
}
|
||||
|
||||
dns_result = dns_db_findnode(db, dns_fixedname_name(&dns_name),
|
||||
ISC_FALSE, &nodep);
|
||||
@@ -2816,8 +2819,6 @@ t_dns_db_find_x(char **av) {
|
||||
dns_rdatatype_t rdatatype;
|
||||
dns_dbversion_t *cversionp;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
dbfile = T_ARG(0);
|
||||
dbtype = T_ARG(1);
|
||||
dborigin = T_ARG(2);
|
||||
|
||||
+13
-13
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2006, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2006, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -14,7 +14,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: gsstest.c,v 1.8 2009/09/02 23:48:01 tbox Exp $ */
|
||||
/* $Id: gsstest.c,v 1.8.104.2 2011/03/28 23:46:38 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -101,23 +101,23 @@ console(isc_task_t *task, isc_event_t *event)
|
||||
|
||||
isc_event_free(&event);
|
||||
|
||||
while(1) {
|
||||
for (;;) {
|
||||
printf("\nCommand => ");
|
||||
scanf("%s", buf);
|
||||
|
||||
if(strcmp(buf, "quit") == 0) {
|
||||
if (strcmp(buf, "quit") == 0) {
|
||||
isc_app_shutdown();
|
||||
return;
|
||||
}
|
||||
|
||||
if(strcmp(buf, "initctx") == 0) {
|
||||
if (strcmp(buf, "initctx") == 0) {
|
||||
ev = isc_event_allocate(mctx, (void *)1, 1, initctx1,
|
||||
NULL, sizeof(*event));
|
||||
isc_task_send(task, &ev);
|
||||
return;
|
||||
}
|
||||
|
||||
if(strcmp(buf, "query") == 0) {
|
||||
if (strcmp(buf, "query") == 0) {
|
||||
ev = isc_event_allocate(mctx, (void *)1, 1, sendquery,
|
||||
NULL, sizeof(*event));
|
||||
isc_task_send(task, &ev);
|
||||
@@ -314,7 +314,7 @@ initctx2(isc_task_t *task, isc_event_t *event) {
|
||||
rdataset = ISC_LIST_HEAD(question_name->list);
|
||||
INSIST(rdataset != NULL);
|
||||
qtype = rdataset->type;
|
||||
if(qtype == dns_rdatatype_tkey) {
|
||||
if (qtype == dns_rdatatype_tkey) {
|
||||
printf("Received TKEY response from server\n");
|
||||
printf("Context completed\n");
|
||||
} else {
|
||||
@@ -324,14 +324,14 @@ initctx2(isc_task_t *task, isc_event_t *event) {
|
||||
tsigkey = NULL;
|
||||
}
|
||||
|
||||
if(response)
|
||||
if (response)
|
||||
dns_message_destroy(&response);
|
||||
|
||||
end:
|
||||
if(query)
|
||||
if (query)
|
||||
dns_message_destroy(&query);
|
||||
|
||||
if(reqev->request)
|
||||
if (reqev->request)
|
||||
dns_request_destroy(&reqev->request);
|
||||
|
||||
isc_event_free(&event);
|
||||
@@ -410,11 +410,11 @@ setup(void)
|
||||
struct in_addr inaddr;
|
||||
int c;
|
||||
|
||||
while (1) {
|
||||
for (;;) {
|
||||
printf("Server IP => ");
|
||||
c = scanf("%s", serveraddress);
|
||||
|
||||
if(c == EOF || strcmp(serveraddress, "quit") == 0) {
|
||||
if (c == EOF || strcmp(serveraddress, "quit") == 0) {
|
||||
isc_app_shutdown();
|
||||
return;
|
||||
}
|
||||
@@ -424,7 +424,7 @@ setup(void)
|
||||
return;
|
||||
}
|
||||
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
int
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.2.2.3 2010/09/29 23:46:44 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
|
||||
CINCLUDES = ${TEST_INCLUDES} ${ISC_INCLUDES}
|
||||
|
||||
CDEFINES =
|
||||
CWARNINGS =
|
||||
|
||||
ISCLIBS = ../../../lib/isc/libisc.@A@ @DNS_CRYPTO_LIBS@
|
||||
|
||||
ISCDEPLIBS = ../../../lib/isc/libisc.@A@
|
||||
|
||||
DEPLIBS = ${ISCDEPLIBS}
|
||||
|
||||
LIBS = ${ISCLIBS} @LIBS@
|
||||
|
||||
TLIB = ../../../lib/tests/libt_api.@A@
|
||||
|
||||
TARGETS = t_hashes@EXEEXT@
|
||||
|
||||
SRCS = t_hashes.c
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
t_hashes@EXEEXT@: t_hashes.@O@ ${DEPLIBS} ${TLIB}
|
||||
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ t_hashes.@O@ ${TLIB} ${LIBS}
|
||||
|
||||
test: t_hashes@EXEEXT@
|
||||
-@./t_hashes@EXEEXT@ -c @top_srcdir@/t_config -b @srcdir@ -q 60 -a
|
||||
|
||||
testhelp:
|
||||
@./t_hashes@EXEEXT@ -h
|
||||
|
||||
clean distclean::
|
||||
rm -f ${TARGETS}
|
||||
@@ -0,0 +1,467 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_hashes.c,v 1.2.2.5 2010/10/04 22:25:25 marka Exp $ */
|
||||
|
||||
/*
|
||||
* -d1 or larger shows hash or HMAC result even if correct
|
||||
*/
|
||||
|
||||
#include <config.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
|
||||
#include <isc/hmacmd5.h>
|
||||
#include <isc/hmacsha.h>
|
||||
#include <isc/md5.h>
|
||||
#include <isc/print.h>
|
||||
#include <isc/sha1.h>
|
||||
#include <isc/string.h>
|
||||
#include <isc/util.h>
|
||||
|
||||
#include <tests/t_api.h>
|
||||
|
||||
|
||||
static int nprobs;
|
||||
|
||||
typedef void(*HASH_INIT)(void *);
|
||||
typedef void(*HMAC_INIT)(void *, const unsigned char *, unsigned int);
|
||||
typedef void(*UPDATE)(void *, const unsigned char *, unsigned int);
|
||||
typedef void(*FINAL)(void *, const unsigned char *);
|
||||
typedef void(*SIGN)(void *, const unsigned char *, unsigned int);
|
||||
|
||||
typedef struct {
|
||||
const char *name;
|
||||
const unsigned char *key;
|
||||
const unsigned int key_len;
|
||||
const unsigned char *str;
|
||||
const unsigned int str_len;
|
||||
} IN;
|
||||
#define STR_INIT(s) (const unsigned char *)(s), sizeof(s)-1
|
||||
|
||||
|
||||
union {
|
||||
unsigned char b[1024];
|
||||
unsigned char md5[16];
|
||||
unsigned char sha1[ISC_SHA1_DIGESTLENGTH];
|
||||
unsigned char sha224[ISC_SHA224_DIGESTLENGTH];
|
||||
unsigned char sha256[ISC_SHA256_DIGESTLENGTH];
|
||||
unsigned char sha384[ISC_SHA384_DIGESTLENGTH];
|
||||
unsigned char sha512[ISC_SHA512_DIGESTLENGTH];
|
||||
} dbuf;
|
||||
#define DIGEST_FILL 0xdf
|
||||
|
||||
typedef struct {
|
||||
const char *str;
|
||||
const unsigned int digest_len;
|
||||
} OUT;
|
||||
|
||||
|
||||
/*
|
||||
* two ad hoc hash examples
|
||||
*/
|
||||
static IN abc = { "\"abc\"", NULL, 0, STR_INIT("abc")};
|
||||
static OUT abc_sha1 = {
|
||||
"a9993e364706816aba3e25717850c26c9cd0d89d",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT abc_sha224 = {
|
||||
"23097d223405d8228642a477bda255b32aadbce4bda0b3f7e36c9da7",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT abc_md5 = {
|
||||
"900150983cd24fb0d6963f7d28e17f72",
|
||||
16};
|
||||
|
||||
static IN abc_blah = { "\"abcdbc...\"", NULL, 0,
|
||||
STR_INIT("abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq")};
|
||||
static OUT abc_blah_sha1 = {
|
||||
"84983e441c3bd26ebaae4aa1f95129e5e54670f1",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT abc_blah_sha224 = {
|
||||
"75388b16512776cc5dba5da1fd890150b0c6455cb4f58b1952522525",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT abc_blah_md5 = {
|
||||
"8215ef0796a20bcaaae116d3876c664a",
|
||||
16};
|
||||
|
||||
/*
|
||||
* three HMAC-md5 examples from RFC 2104
|
||||
*/
|
||||
static const unsigned char rfc2104_1_key[16] = {
|
||||
0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b,
|
||||
0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b};
|
||||
static IN rfc2104_1 = {"RFC 2104 #1", rfc2104_1_key, sizeof(rfc2104_1_key),
|
||||
STR_INIT("Hi There")};
|
||||
static OUT rfc2104_1_hmac = {
|
||||
"9294727a3638bb1c13f48ef8158bfc9d",
|
||||
16};
|
||||
|
||||
static IN rfc2104_2 = {"RFC 2104 #2", STR_INIT("Jefe"),
|
||||
STR_INIT("what do ya want for nothing?")};
|
||||
static OUT rfc2104_2_hmac = {
|
||||
"750c783e6ab0b503eaa86e310a5db738",
|
||||
16};
|
||||
|
||||
static const unsigned char rfc2104_3_key[16] = {
|
||||
0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA,
|
||||
0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA};
|
||||
static const unsigned char rfc2104_3_s[50] = {
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD, 0xDD,
|
||||
0xDD, 0xDD};
|
||||
static IN rfc2104_3 = {"RFC 2104 #3", rfc2104_3_key, sizeof(rfc2104_3_key),
|
||||
rfc2104_3_s, sizeof(rfc2104_3_s)};
|
||||
static OUT rfc2104_3_hmac = {
|
||||
"56be34521d144c88dbb8c733f0e8b3f6",
|
||||
16};
|
||||
|
||||
/*
|
||||
* four three HMAC-SHA tests cut-and-pasted from RFC 4634 starting on page 86
|
||||
*/
|
||||
static const unsigned char rfc4634_1_key[20] = {
|
||||
0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b,
|
||||
0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b
|
||||
};
|
||||
static IN rfc4634_1 = {"RFC 4634 #1", rfc4634_1_key, sizeof(rfc4634_1_key),
|
||||
STR_INIT("Hi There")};
|
||||
static OUT rfc4634_1_sha1 = {
|
||||
"B617318655057264E28BC0B6FB378C8EF146BE00",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT rfc4634_1_sha224 = {
|
||||
"896FB1128ABBDF196832107CD49DF33F47B4B1169912BA4F53684B22",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT rfc4634_1_sha256 = {
|
||||
"B0344C61D8DB38535CA8AFCEAF0BF12B881DC200C9833DA726E9376C2E32"
|
||||
"CFF7",
|
||||
ISC_SHA256_DIGESTLENGTH};
|
||||
static OUT rfc4634_1_sha384 = {
|
||||
"AFD03944D84895626B0825F4AB46907F15F9DADBE4101EC682AA034C7CEB"
|
||||
"C59CFAEA9EA9076EDE7F4AF152E8B2FA9CB6",
|
||||
ISC_SHA384_DIGESTLENGTH};
|
||||
static OUT rfc4634_1_sha512 = {
|
||||
"87AA7CDEA5EF619D4FF0B4241A1D6CB02379F4E2CE4EC2787AD0B30545E1"
|
||||
"7CDEDAA833B7D6B8A702038B274EAEA3F4E4BE9D914EEB61F1702E696C20"
|
||||
"3A126854",
|
||||
ISC_SHA512_DIGESTLENGTH};
|
||||
|
||||
static IN rfc4634_2 = {"RFC 4634 #2", STR_INIT("Jefe"),
|
||||
STR_INIT("what do ya want for nothing?")};
|
||||
static OUT rfc4634_2_sha1 = {
|
||||
"EFFCDF6AE5EB2FA2D27416D5F184DF9C259A7C79",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT rfc4634_2_sha224 = {
|
||||
"A30E01098BC6DBBF45690F3A7E9E6D0F8BBEA2A39E6148008FD05E44",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT rfc4634_2_sha256 = {
|
||||
"5BDCC146BF60754E6A042426089575C75A003F089D2739839DEC58B964EC"
|
||||
"3843",
|
||||
ISC_SHA256_DIGESTLENGTH};
|
||||
static OUT rfc4634_2_sha384 = {
|
||||
"AF45D2E376484031617F78D2B58A6B1B9C7EF464F5A01B47E42EC3736322"
|
||||
"445E8E2240CA5E69E2C78B3239ECFAB21649",
|
||||
ISC_SHA384_DIGESTLENGTH};
|
||||
static OUT rfc4634_2_sha512 = {
|
||||
"164B7A7BFCF819E2E395FBE73B56E0A387BD64222E831FD610270CD7EA25"
|
||||
"05549758BF75C05A994A6D034F65F8F0E6FDCAEAB1A34D4A6B4B636E070A"
|
||||
"38BCE737",
|
||||
ISC_SHA512_DIGESTLENGTH};
|
||||
|
||||
static const unsigned char rfc4634_3_key[20] = {
|
||||
0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa,
|
||||
0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa
|
||||
};
|
||||
static const unsigned char rfc4634_3_s[50] = {
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd,
|
||||
0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd
|
||||
};
|
||||
static IN rfc4634_3 = {"RFC 4634 #3", rfc4634_3_key, sizeof(rfc4634_3_key),
|
||||
rfc4634_3_s, sizeof(rfc4634_3_s)};
|
||||
static OUT rfc4634_3_sha1 = {
|
||||
"125D7342B9AC11CD91A39AF48AA17B4F63F175D3",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT rfc4634_3_sha224 = {
|
||||
"7FB3CB3588C6C1F6FFA9694D7D6AD2649365B0C1F65D69D1EC8333EA",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT rfc4634_3_sha256 = {
|
||||
"773EA91E36800E46854DB8EBD09181A72959098B3EF8C122D9635514CED5"
|
||||
"65FE",
|
||||
ISC_SHA256_DIGESTLENGTH};
|
||||
static OUT rfc4634_3_sha384 = {
|
||||
"88062608D3E6AD8A0AA2ACE014C8A86F0AA635D947AC9FEBE83EF4E55966"
|
||||
"144B2A5AB39DC13814B94E3AB6E101A34F27",
|
||||
ISC_SHA384_DIGESTLENGTH};
|
||||
static OUT rfc4634_3_sha512 = {
|
||||
"FA73B0089D56A284EFB0F0756C890BE9B1B5DBDD8EE81A3655F83E33B227"
|
||||
"9D39BF3E848279A722C806B485A47E67C807B946A337BEE8942674278859"
|
||||
"E13292FB",
|
||||
ISC_SHA512_DIGESTLENGTH};
|
||||
|
||||
static const unsigned char rfc4634_4_key[25] = {
|
||||
0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a,
|
||||
0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14,
|
||||
0x15, 0x16, 0x17, 0x18, 0x19
|
||||
};
|
||||
static const unsigned char rfc4634_4_s[50] = {
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd,
|
||||
0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd
|
||||
};
|
||||
static IN rfc4634_4 = {"RFC 4634 #3", rfc4634_4_key, sizeof(rfc4634_4_key),
|
||||
rfc4634_4_s, sizeof(rfc4634_4_s)};
|
||||
static OUT rfc4634_4_sha1 = {
|
||||
"4C9007F4026250C6BC8414F9BF50C86C2D7235DA",
|
||||
ISC_SHA1_DIGESTLENGTH};
|
||||
static OUT rfc4634_4_sha224 = {
|
||||
"6C11506874013CAC6A2ABC1BB382627CEC6A90D86EFC012DE7AFEC5A",
|
||||
ISC_SHA224_DIGESTLENGTH};
|
||||
static OUT rfc4634_4_sha256 = {
|
||||
"82558A389A443C0EA4CC819899F2083A85F0FAA3E578F8077A2E3FF46729"
|
||||
"665B",
|
||||
ISC_SHA256_DIGESTLENGTH};
|
||||
static OUT rfc4634_4_sha384 = {
|
||||
"3E8A69B7783C25851933AB6290AF6CA77A9981480850009CC5577C6E1F57"
|
||||
"3B4E6801DD23C4A7D679CCF8A386C674CFFB",
|
||||
ISC_SHA384_DIGESTLENGTH};
|
||||
static OUT rfc4634_4_sha512 = {
|
||||
"B0BA465637458C6990E5A8C5F61D4AF7E576D97FF94B872DE76F8050361E"
|
||||
"E3DBA91CA5C11AA25EB4D679275CC5788063A5F19741120C4F2DE2ADEBEB"
|
||||
"10A298DD",
|
||||
ISC_SHA512_DIGESTLENGTH};
|
||||
|
||||
|
||||
|
||||
static const char *
|
||||
d2str(char *buf, unsigned int buf_len,
|
||||
const unsigned char *d, unsigned int d_len)
|
||||
{
|
||||
unsigned int i, l;
|
||||
|
||||
l = 0;
|
||||
for (i = 0; i < d_len && l < buf_len-4; ++i) {
|
||||
l += snprintf(&buf[l], buf_len-l, "%02x", d[i]);
|
||||
}
|
||||
if (l >= buf_len-3) {
|
||||
REQUIRE(buf_len > sizeof("..."));
|
||||
strcpy(&buf[l-sizeof(" ...")], " ...");
|
||||
}
|
||||
return buf;
|
||||
}
|
||||
|
||||
|
||||
|
||||
/*
|
||||
* Compare binary digest or HMAC to string of hex digits from an RFC
|
||||
*/
|
||||
static void
|
||||
ck(const char *name, const IN *in, const OUT *out)
|
||||
{
|
||||
char buf[sizeof(dbuf)*2+1];
|
||||
const char *str_name;
|
||||
unsigned int l;
|
||||
|
||||
d2str(buf, sizeof(buf), dbuf.b, out->digest_len);
|
||||
str_name = in->name != NULL ? in->name : (const char *)in->str;
|
||||
|
||||
if (T_debug != 0)
|
||||
t_info("%s(%s) = %s\n", name, str_name, buf);
|
||||
|
||||
if (strcasecmp(buf, out->str)) {
|
||||
t_info("%s(%s)\n%9s %s\n%9s %s\n",
|
||||
name, str_name,
|
||||
"is", buf,
|
||||
"should be", out->str);
|
||||
++nprobs;
|
||||
return;
|
||||
}
|
||||
|
||||
/*
|
||||
* check that the hash or HMAC is no longer than we think it is
|
||||
*/
|
||||
for (l = out->digest_len; l < sizeof(dbuf); ++l) {
|
||||
if (dbuf.b[l] != DIGEST_FILL) {
|
||||
t_info("byte #%d after end of %s(%s) changed to %02x\n",
|
||||
l-out->digest_len, name, str_name, dbuf.b[l]);
|
||||
++nprobs;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
|
||||
static void
|
||||
t_hash(const char *hname, HASH_INIT init, UPDATE update, FINAL final,
|
||||
IN *in, OUT *out)
|
||||
{
|
||||
union {
|
||||
unsigned char b[1024];
|
||||
isc_sha1_t sha1;
|
||||
isc_md5_t md5;
|
||||
} ctx;
|
||||
|
||||
init(&ctx);
|
||||
update(&ctx, in->str, in->str_len);
|
||||
memset(dbuf.b, DIGEST_FILL, sizeof(dbuf));
|
||||
final(&ctx, dbuf.b);
|
||||
ck(hname, in, out);
|
||||
}
|
||||
|
||||
|
||||
|
||||
/*
|
||||
* isc_sha224_final has a different calling sequence
|
||||
*/
|
||||
static void
|
||||
t_sha224(IN *in, OUT *out)
|
||||
{
|
||||
isc_sha224_t ctx;
|
||||
|
||||
memset(dbuf.b, DIGEST_FILL, sizeof(dbuf));
|
||||
isc_sha224_init(&ctx);
|
||||
isc_sha224_update(&ctx, in->str, in->str_len);
|
||||
memset(dbuf.b, DIGEST_FILL, sizeof(dbuf));
|
||||
isc_sha224_final(dbuf.b, &ctx);
|
||||
ck("SHA224", in, out);
|
||||
}
|
||||
|
||||
|
||||
|
||||
static void
|
||||
t_hashes(IN *in, OUT *out_sha1, OUT *out_sha224, OUT *out_md5)
|
||||
{
|
||||
t_hash("SHA1", (HASH_INIT)isc_sha1_init, (UPDATE)isc_sha1_update,
|
||||
(FINAL)isc_sha1_final, in, out_sha1);
|
||||
t_sha224(in, out_sha224);
|
||||
t_hash("md5", (HASH_INIT)isc_md5_init, (UPDATE)isc_md5_update,
|
||||
(FINAL)isc_md5_final, in, out_md5);
|
||||
}
|
||||
|
||||
|
||||
|
||||
/*
|
||||
* isc_hmacmd5_sign has a different calling sequence
|
||||
*/
|
||||
static void
|
||||
t_md5hmac(IN *in, OUT *out)
|
||||
{
|
||||
isc_hmacmd5_t ctx;
|
||||
|
||||
isc_hmacmd5_init(&ctx, in->key, in->key_len);
|
||||
isc_hmacmd5_update(&ctx, in->str, in->str_len);
|
||||
memset(dbuf.b, DIGEST_FILL, sizeof(dbuf));
|
||||
isc_hmacmd5_sign(&ctx, dbuf.b);
|
||||
ck("HMAC-md5", in, out);
|
||||
}
|
||||
|
||||
|
||||
|
||||
static void
|
||||
t_hmac(const char *hname, HMAC_INIT init, UPDATE update, SIGN sign,
|
||||
IN *in, OUT *out)
|
||||
{
|
||||
union {
|
||||
unsigned char b[1024];
|
||||
isc_hmacmd5_t hmacmd5;
|
||||
isc_hmacsha1_t hmacsha1;
|
||||
isc_hmacsha224_t hmacsha224;
|
||||
isc_hmacsha256_t hmacsha256;
|
||||
isc_hmacsha384_t hmacsha384;
|
||||
isc_hmacsha512_t hmacsha512;
|
||||
} ctx;
|
||||
|
||||
init(&ctx, in->key, in->key_len);
|
||||
update(&ctx, in->str, in->str_len);
|
||||
memset(dbuf.b, DIGEST_FILL, sizeof(dbuf));
|
||||
sign(&ctx, dbuf.b, out->digest_len);
|
||||
ck(hname, in, out);
|
||||
}
|
||||
|
||||
|
||||
|
||||
static void
|
||||
t_hmacs(IN *in, OUT *out_sha1, OUT *out_sha224, OUT *out_sha256,
|
||||
OUT *out_sha384, OUT *out_sha512)
|
||||
{
|
||||
t_hmac("HMAC-SHA1", (HMAC_INIT)isc_hmacsha1_init,
|
||||
(UPDATE)isc_hmacsha1_update, (SIGN)isc_hmacsha1_sign,
|
||||
in, out_sha1);
|
||||
t_hmac("HMAC-SHA224", (HMAC_INIT)isc_hmacsha224_init,
|
||||
(UPDATE)isc_hmacsha224_update, (SIGN)isc_hmacsha224_sign,
|
||||
in, out_sha224);
|
||||
t_hmac("HMAC-SHA256", (HMAC_INIT)isc_hmacsha256_init,
|
||||
(UPDATE)isc_hmacsha256_update, (SIGN)isc_hmacsha256_sign,
|
||||
in, out_sha256);
|
||||
t_hmac("HMAC-SHA384", (HMAC_INIT)isc_hmacsha384_init,
|
||||
(UPDATE)isc_hmacsha384_update, (SIGN)isc_hmacsha384_sign,
|
||||
in, out_sha384);
|
||||
t_hmac("HMAC-SHA512", (HMAC_INIT)isc_hmacsha512_init,
|
||||
(UPDATE)isc_hmacsha512_update, (SIGN)isc_hmacsha512_sign,
|
||||
in, out_sha512);
|
||||
}
|
||||
|
||||
|
||||
|
||||
/*
|
||||
* This will almost never fail, and so there is no need for the extra noise
|
||||
* that would come from breaking it into several tests.
|
||||
*/
|
||||
static void
|
||||
t1(void)
|
||||
{
|
||||
/*
|
||||
* two ad hoc hash examples
|
||||
*/
|
||||
t_hashes(&abc, &abc_sha1, &abc_sha224, &abc_md5);
|
||||
t_hashes(&abc_blah, &abc_blah_sha1, &abc_blah_sha224, &abc_blah_md5);
|
||||
|
||||
/*
|
||||
* three HMAC-md5 examples from RFC 2104
|
||||
*/
|
||||
t_md5hmac(&rfc2104_1, &rfc2104_1_hmac);
|
||||
t_md5hmac(&rfc2104_2, &rfc2104_2_hmac);
|
||||
t_md5hmac(&rfc2104_3, &rfc2104_3_hmac);
|
||||
|
||||
/*
|
||||
* four HMAC-SHA tests from RFC 4634 starting on page 86
|
||||
*/
|
||||
t_hmacs(&rfc4634_1, &rfc4634_1_sha1, &rfc4634_1_sha224,
|
||||
&rfc4634_1_sha256, &rfc4634_1_sha384, &rfc4634_1_sha512);
|
||||
t_hmacs(&rfc4634_2, &rfc4634_2_sha1, &rfc4634_2_sha224,
|
||||
&rfc4634_2_sha256, &rfc4634_2_sha384, &rfc4634_2_sha512);
|
||||
t_hmacs(&rfc4634_3, &rfc4634_3_sha1, &rfc4634_3_sha224,
|
||||
&rfc4634_3_sha256, &rfc4634_3_sha384, &rfc4634_3_sha512);
|
||||
t_hmacs(&rfc4634_4, &rfc4634_4_sha1, &rfc4634_4_sha224,
|
||||
&rfc4634_4_sha256, &rfc4634_4_sha384, &rfc4634_4_sha512);
|
||||
|
||||
if (nprobs != 0)
|
||||
t_result(T_FAIL);
|
||||
else
|
||||
t_result(T_PASS);
|
||||
}
|
||||
|
||||
|
||||
testspec_t T_testlist[] = {
|
||||
{ t1, "hashes" },
|
||||
{ NULL, NULL }
|
||||
};
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2007 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2007, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1999-2001 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: log_test.c,v 1.26 2007/06/19 23:46:59 tbox Exp $ */
|
||||
/* $Id: log_test.c,v 1.26.558.2 2011/01/14 00:51:07 tbox Exp $ */
|
||||
|
||||
/* Principal Authors: DCL */
|
||||
|
||||
@@ -306,16 +306,16 @@ main(int argc, char **argv) {
|
||||
isc_log_write1(lctx, DNS_LOGCATEGORY_GENERAL, DNS_LOGMODULE_RBTDB,
|
||||
ISC_LOG_CRITICAL, "%s", message);
|
||||
isc_log_write1(lctx, DNS_LOGCATEGORY_GENERAL, DNS_LOGMODULE_RBTDB,
|
||||
ISC_LOG_CRITICAL, message);
|
||||
ISC_LOG_CRITICAL, "%s", message);
|
||||
|
||||
isc_log_setduplicateinterval(lcfg, 1);
|
||||
message = "This message should appear twice on stderr";
|
||||
|
||||
isc_log_write1(lctx, DNS_LOGCATEGORY_GENERAL, DNS_LOGMODULE_RBTDB,
|
||||
ISC_LOG_CRITICAL, message);
|
||||
ISC_LOG_CRITICAL, "%s", message);
|
||||
sleep(2);
|
||||
isc_log_write1(lctx, DNS_LOGCATEGORY_GENERAL, DNS_LOGMODULE_RBTDB,
|
||||
ISC_LOG_CRITICAL, message);
|
||||
ISC_LOG_CRITICAL, "%s", message);
|
||||
|
||||
/*
|
||||
* Review where everything went.
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_master.c,v 1.39 2009/09/01 00:22:25 jinmei Exp $ */
|
||||
/* $Id: t_master.c,v 1.39.104.2 2011/03/12 04:58:25 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -77,7 +77,6 @@ test_master(char *testfile, char *origin, char *class, isc_result_t exp_result)
|
||||
dns_rdataclass_t rdataclass;
|
||||
isc_textregion_t textregion;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
if (T1_mctx == NULL)
|
||||
isc_result = isc_mem_create(0, 0, &T1_mctx);
|
||||
else
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_names.c,v 1.50 2009/09/01 23:47:44 tbox Exp $ */
|
||||
/* $Id: t_names.c,v 1.50.104.2 2011/03/12 04:58:25 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -179,7 +179,6 @@ getmsg(char *datafile_name, unsigned char *buf, int buflen, isc_buffer_t *pbuf)
|
||||
int c;
|
||||
int len;
|
||||
int cnt;
|
||||
unsigned int val;
|
||||
unsigned char *p;
|
||||
FILE *fp;
|
||||
|
||||
@@ -192,8 +191,8 @@ getmsg(char *datafile_name, unsigned char *buf, int buflen, isc_buffer_t *pbuf)
|
||||
p = buf;
|
||||
cnt = 0;
|
||||
len = 0;
|
||||
val = 0;
|
||||
while ((c = getc(fp)) != EOF) {
|
||||
unsigned int val;
|
||||
if ( (c == ' ') || (c == '\t') ||
|
||||
(c == '\r') || (c == '\n'))
|
||||
continue;
|
||||
@@ -1678,8 +1677,6 @@ test_dns_name_fromtext(char *test_name1, char *test_name2, char *test_origin,
|
||||
isc_result_t dns_result;
|
||||
dns_namereln_t dns_namereln;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
t_info("testing %s %s %s\n", test_name1, test_name2, test_origin);
|
||||
|
||||
isc_buffer_init(&binbuf1, junk1, BUFLEN);
|
||||
@@ -1815,8 +1812,6 @@ test_dns_name_totext(char *test_name, isc_boolean_t omit_final) {
|
||||
isc_result_t dns_result;
|
||||
dns_namereln_t dns_namereln;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
t_info("testing %s\n", test_name);
|
||||
|
||||
len = strlen(test_name);
|
||||
@@ -1983,8 +1978,6 @@ test_dns_name_fromwire(char *datafile_name, int testname_offset, int downcase,
|
||||
dns_namereln_t dns_namereln;
|
||||
dns_decompress_t dctx;
|
||||
|
||||
result = T_UNRESOLVED;
|
||||
|
||||
t_info("testing using %s\n", datafile_name);
|
||||
len = getmsg(datafile_name, buf1, BIGBUFLEN, &iscbuf1);
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -15,7 +15,7 @@
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: t_rbt.c,v 1.33 2009/09/01 00:22:25 jinmei Exp $ */
|
||||
/* $Id: t_rbt.c,v 1.33.104.2 2011/03/12 04:58:25 tbox Exp $ */
|
||||
|
||||
#include <config.h>
|
||||
|
||||
@@ -398,8 +398,7 @@ test_rbt_gen(char *filename, char *command, char *testname,
|
||||
result = T_FAIL;
|
||||
}
|
||||
} else {
|
||||
t_info("create_name failed %s\n",
|
||||
dns_result_totext(dns_result));
|
||||
t_info("create_name failed\n");
|
||||
result = T_UNRESOLVED;
|
||||
}
|
||||
} else if ((strcmp(command, "delete") == 0) ||
|
||||
@@ -1112,8 +1111,8 @@ t_dns_rbtnodechain_first(char *dbfile, char *expected_firstname,
|
||||
t_info("dns_rbtnodechain_first unexpectedly returned %s\n",
|
||||
dns_result_totext(dns_result));
|
||||
|
||||
nfails = t_namechk(dns_result, &dns_name, expected_firstname,
|
||||
&dns_origin, expected_firstorigin, DNS_R_NEWORIGIN);
|
||||
nfails += t_namechk(dns_result, &dns_name, expected_firstname,
|
||||
&dns_origin, expected_firstorigin, DNS_R_NEWORIGIN);
|
||||
|
||||
dns_fixedname_init(&dns_name);
|
||||
dns_result = dns_rbtnodechain_next(&chain,
|
||||
@@ -1303,8 +1302,8 @@ t_dns_rbtnodechain_last(char *dbfile, char *expected_lastname,
|
||||
t_info("dns_rbtnodechain_last unexpectedly returned %s\n",
|
||||
dns_result_totext(dns_result));
|
||||
}
|
||||
nfails = t_namechk(dns_result, &dns_name, expected_lastname,
|
||||
&dns_origin, expected_lastorigin, DNS_R_NEWORIGIN);
|
||||
nfails += t_namechk(dns_result, &dns_name, expected_lastname,
|
||||
&dns_origin, expected_lastorigin, DNS_R_NEWORIGIN);
|
||||
|
||||
t_info("testing for previous name of %s, origin of %s\n",
|
||||
expected_prevname, expected_prevorigin);
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Copyright (C) 2004, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2004, 2007, 2008, 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2000, 2001 Internet Software Consortium.
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -13,7 +13,7 @@
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: Makefile.in,v 1.31 2008/09/25 04:02:38 tbox Exp $
|
||||
# $Id: Makefile.in,v 1.31.268.2 2010/06/23 23:46:35 tbox Exp $
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
@@ -21,7 +21,7 @@ top_srcdir = @top_srcdir@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
|
||||
SUBDIRS = lwresd tkey
|
||||
SUBDIRS = filter-aaaa lwresd tkey
|
||||
TARGETS =
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: clean.sh,v 1.2.2.3 2010/09/15 03:36:41 marka Exp $
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f rndc.out.*
|
||||
rm -f ns2/named.conf
|
||||
rm -f */named.memstats
|
||||
rm -f ns2/*.nzf
|
||||
rm -f ns2/core*
|
||||
@@ -0,0 +1,31 @@
|
||||
; Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: added.db,v 1.2.2.2 2010/08/11 18:19:56 each Exp $
|
||||
|
||||
$ORIGIN added.example.
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
1 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
ns2 A 10.53.0.2
|
||||
MX 10 mail
|
||||
|
||||
a A 10.0.0.1
|
||||
mail A 10.0.0.2
|
||||
@@ -0,0 +1 @@
|
||||
zone previous.example { type master; file "previous.db"; };
|
||||
@@ -0,0 +1,41 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named1.conf,v 1.2.2.2 2010/08/11 18:19:56 each Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
options {
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.2; };
|
||||
listen-on-v6 { none; };
|
||||
allow-query { any; };
|
||||
recursion no;
|
||||
allow-new-zones yes;
|
||||
};
|
||||
|
||||
include "../../common/controls.conf";
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
|
||||
zone "normal.example" {
|
||||
type master;
|
||||
file "normal.db";
|
||||
};
|
||||
@@ -0,0 +1,50 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
* REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
* AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
* INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
* LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
* OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
* PERFORMANCE OF THIS SOFTWARE.
|
||||
*/
|
||||
|
||||
/* $Id: named2.conf,v 1.2.2.3 2010/09/24 05:54:06 marka Exp $ */
|
||||
|
||||
controls { /* empty */ };
|
||||
|
||||
include "../../common/controls.conf";
|
||||
|
||||
options {
|
||||
port 5300;
|
||||
pid-file "named.pid";
|
||||
listen-on { 10.53.0.2; 10.53.0.4; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
};
|
||||
|
||||
view internal {
|
||||
match-clients { 10.53.0.2; };
|
||||
allow-new-zones no;
|
||||
recursion yes;
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
};
|
||||
|
||||
view external {
|
||||
match-clients { any; };
|
||||
allow-new-zones yes;
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "../../common/root.hint";
|
||||
};
|
||||
};
|
||||
@@ -0,0 +1,31 @@
|
||||
; Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: normal.db,v 1.2.2.2 2010/08/11 18:19:56 each Exp $
|
||||
|
||||
$ORIGIN normal.example.
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
1 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
ns2 A 10.53.0.2
|
||||
MX 10 mail
|
||||
|
||||
a A 10.0.0.1
|
||||
mail A 10.0.0.2
|
||||
@@ -0,0 +1,31 @@
|
||||
; Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: previous.db,v 1.2.2.2 2010/08/11 18:19:57 each Exp $
|
||||
|
||||
$ORIGIN previous.example.
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
1 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
ns2 A 10.53.0.2
|
||||
MX 10 mail
|
||||
|
||||
a A 10.0.0.1
|
||||
mail A 10.0.0.2
|
||||
@@ -0,0 +1,20 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: setup.sh,v 1.2.2.3 2010/08/12 01:32:46 marka Exp $
|
||||
|
||||
cp -f ns2/named1.conf ns2/named.conf
|
||||
cp -f ns2/default.nzf.in ns2/3bf305731dd26307.nzf
|
||||
@@ -0,0 +1,151 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: tests.sh,v 1.2.2.4 2010/09/24 05:54:05 marka Exp $
|
||||
|
||||
SYSTEMTESTTOP=..
|
||||
. $SYSTEMTESTTOP/conf.sh
|
||||
|
||||
DIGOPTS="+tcp +nosea +nostat +nocmd +norec +noques +noauth +noadd +nostats +dnssec -p 5300"
|
||||
status=0
|
||||
n=0
|
||||
|
||||
echo "I:checking normally loaded zone ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.2 a.normal.example a > dig.out.ns2.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:checking previously added zone ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.2 a.previous.example a > dig.out.ns2.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.previous.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:adding new zone ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 addzone 'added.example { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
|
||||
$DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.added.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:adding new zone with missing master file ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +all @10.53.0.2 a.missing.example a > dig.out.ns2.pre.$n || ret=1
|
||||
grep "status: REFUSED" dig.out.ns2.pre.$n > /dev/null || ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 addzone 'missing.example { type master; file "missing.db"; };' 2> rndc.out.ns2.$n
|
||||
grep "file not found" rndc.out.ns2.$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS +all @10.53.0.2 a.missing.example a > dig.out.ns2.post.$n || ret=1
|
||||
grep "status: REFUSED" dig.out.ns2.post.$n > /dev/null || ret=1
|
||||
$PERL ../digcomp.pl dig.out.ns2.pre.$n dig.out.ns2.post.$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:deleting previously added zone ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 delzone previous.example 2>&1 | sed 's/^/I:ns2 /'
|
||||
$DIG $DIGOPTS @10.53.0.2 a.previous.example a > dig.out.ns2.$n
|
||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.previous.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:deleting newly added zone ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 delzone added.example 2>&1 | sed 's/^/I:ns2 /'
|
||||
$DIG $DIGOPTS @10.53.0.2 a.added.example a > dig.out.ns2.$n
|
||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.added.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:attempt to delete a normally-loaded zone ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 delzone normal.example 2> rndc.out.ns2.$n
|
||||
grep "permission denied" rndc.out.ns2.$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.2 a.normal.example a > dig.out.ns2.$n
|
||||
grep 'status: NOERROR' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.normal.example' dig.out.ns2.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:reconfiguring server with multiple views"
|
||||
rm -f ns2/named.conf
|
||||
cp -f ns2/named2.conf ns2/named.conf
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 reconfig 2>&1 | sed 's/^/I:ns2 /'
|
||||
sleep 5
|
||||
|
||||
echo "I:adding new zone to external view ($n)"
|
||||
# NOTE: The internal view has "recursion yes" set, and so queries for
|
||||
# nonexistent zones should return NOERROR. The external view is
|
||||
# "recursion no", so queries for nonexistent zones should return
|
||||
# REFUSED. This behavior should be the same regardless of whether
|
||||
# the zone does not exist because a) it has not yet been loaded, b)
|
||||
# it failed to load, or c) it has been deleted.
|
||||
ret=0
|
||||
$DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.intpre.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.intpre.$n > /dev/null || ret=1
|
||||
$DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.extpre.$n || ret=1
|
||||
grep 'status: REFUSED' dig.out.ns2.extpre.$n > /dev/null || ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 addzone 'added.example in external { type master; file "added.db"; };' 2>&1 | sed 's/^/I:ns2 /'
|
||||
$DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null || ret=1
|
||||
$DIG +norec $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.ext.$n > /dev/null || ret=1
|
||||
grep '^a.added.example' dig.out.ns2.ext.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:deleting newly added zone ($n)"
|
||||
ret=0
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 delzone 'added.example in external' 2>&1 | sed 's/^/I:ns2 /'
|
||||
$DIG $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.$n || ret=1
|
||||
grep 'status: REFUSED' dig.out.ns2.$n > /dev/null || ret=1
|
||||
grep '^a.added.example' dig.out.ns2.$n > /dev/null && ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:attempting to add zone to internal view ($n)"
|
||||
ret=0
|
||||
$DIG +norec $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.pre.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.pre.$n > /dev/null || ret=1
|
||||
$RNDC -c ../common/rndc.conf -s 10.53.0.2 -p 9953 addzone 'added.example in internal { type master; file "added.db"; };' 2> rndc.out.ns2.$n
|
||||
grep "permission denied" rndc.out.ns2.$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.2 -b 10.53.0.2 a.added.example a > dig.out.ns2.int.$n || ret=1
|
||||
grep 'status: NOERROR' dig.out.ns2.int.$n > /dev/null || ret=1
|
||||
$DIG $DIGOPTS @10.53.0.4 -b 10.53.0.4 a.added.example a > dig.out.ns2.ext.$n || ret=1
|
||||
grep 'status: REFUSED' dig.out.ns2.ext.$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
exit $status
|
||||
@@ -0,0 +1,25 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# $Id: clean.sh,v 1.2.2.2 2010/11/16 02:11:47 sar Exp $
|
||||
|
||||
#
|
||||
# Clean up after allow query tests.
|
||||
#
|
||||
|
||||
rm -f dig.out.*
|
||||
rm -f ns2/named.conf
|
||||
rm -f */named.memstats
|
||||
@@ -0,0 +1,31 @@
|
||||
; Copyright (C) 2010 Internet Systems Consortium, Inc. ("ISC")
|
||||
;
|
||||
; Permission to use, copy, modify, and/or distribute this software for any
|
||||
; purpose with or without fee is hereby granted, provided that the above
|
||||
; copyright notice and this permission notice appear in all copies.
|
||||
;
|
||||
; THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
; REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
; AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
; INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
; LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
; OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
; PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
; $Id: aclallow.db,v 1.2.2.2 2010/11/16 02:11:47 sar Exp $
|
||||
|
||||
$ORIGIN aclallow.example.
|
||||
$TTL 300 ; 5 minutes
|
||||
@ IN SOA mname1. . (
|
||||
1 ; serial
|
||||
20 ; refresh (20 seconds)
|
||||
20 ; retry (20 seconds)
|
||||
1814400 ; expire (3 weeks)
|
||||
3600 ; minimum (1 hour)
|
||||
)
|
||||
NS ns2
|
||||
ns2 A 10.53.0.2
|
||||
MX 10 mail
|
||||
|
||||
a A 10.0.7.1
|
||||
mail A 10.0.7.2
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user