Compare commits

...
Author SHA1 Message Date
Michal Nowak e6ded8ed5b Omit spurious string from unit test debugging efforts
When both 'broken' and 'failed' test cases appear in unit test output

...
===> Broken tests
lib/isc/tests/socket_test:main  ->  broken: Test case timed out  [300.022s]
===> Failed tests
lib/isc/tests/time_test:main  ->  failed: 2 of 6 tests failed  [0.006s]
===> Summary
...

spurious '===>' string gets matched, that results in the following
error:

  Usage error for command debug: '===>' is not a test case identifier (missing ':'?).

Following change makes sure the string is omitted.

I checked on FreeBSD and OpenBSD that the AWK construct is supported.
2020-01-08 15:20:26 +01:00
Ondřej Surý 3bce0c2c20 Merge branch '1525-inline-system-test-failed-need-to-wait-for-zone-to-be-loaded' into 'master'
Resolve "inline system test failed, need to wait for zone to be loaded."

Closes #1525

See merge request isc-projects/bind9!2796
2020-01-08 07:23:42 +00:00
Mark AndrewsandOndřej Surý 2dc4d72fa9 address some timing issues in inline system test 2020-01-08 08:23:03 +01:00
Ondřej Surý cd17b773b1 Merge branch '1513-inline-system-test-failed' into 'master'
Resolve "inline system test failed"

Closes #1513

See merge request isc-projects/bind9!2777
2020-01-08 07:17:47 +00:00
Mark AndrewsandOndřej Surý 13fa80ede8 Address timing issues in 'inline' system test.
"rndc signing -serial <value>" could take longer than a second to
complete.  Loop waiting for update to succeed.

For tests where "rndc signing -serial <value>" is supposed to not
succeed, repeatedly test that we don't get the new serial, then
test that we have the old value.  This should prevent false negatives.
2020-01-07 16:14:12 +01:00
Ondřej Surý e3d8732548 Merge branch '1467-xfer-test-suppress-zone-transfer-when-we-are-going-to-retry' into 'master'
Resolve "xfer test: suppress zone transfer when we are going to retry."

Closes #1467

See merge request isc-projects/bind9!2735
2020-01-07 13:56:35 +00:00
Mark AndrewsandOndřej Surý 05aa45c602 improve forensic logs
improve forensic logs by directing output to per sub-test named
files and reporting the sub-subtest number.
2020-01-07 14:23:48 +01:00
Mark AndrewsandOndřej Surý 9bd6720f58 suppress unnecessary zone transfer
suppressed unnecessary zone transfer in "test mapped zone with
out of zone data" sub-test.
2020-01-07 14:23:17 +01:00
Mark AndrewsandOndřej Surý 46982b414b Improve forensic logging in "testing basic zone transfer functionality"
Split the "testing basic zone transfer functionality" into primary and
secondary parts to improve forensic logging.
2020-01-07 14:23:08 +01:00
Matthijs Mekking 2c38dd5474 Merge branch 'copyrights-2020' into 'master'
Update copyrights 2020

See merge request isc-projects/bind9!2809
2020-01-06 17:53:09 +00:00
Matthijs Mekking 935a2ae33f Update copyrights 2020
Happy New Year!
2020-01-06 15:05:03 +01:00
Michal Nowak db9ad43294 Merge branch 'mnowak/get-the-backtraces-out-of-unit-test-coredumps' into 'master'
Gather debug info on broken unit tests

See merge request isc-projects/bind9!2699
2020-01-06 11:25:09 +00:00
Michal Nowak 6a94e6ba73 Gather debug info on broken unit tests 2020-01-06 11:25:09 +00:00
Michał Kępień fc0fe4c5a7 Merge branch 'michal/misc-doc-fixes' into 'master'
Miscellaneous documentation fixes

See merge request isc-projects/bind9!2800
2020-01-03 08:24:18 +00:00
Michał Kępień 56f388cae1 Fix minor CHANGES issues 2020-01-03 09:08:09 +01:00
Michał Kępień b2f3eaf188 Fix whitespace and punctuation in release notes 2020-01-03 09:08:09 +01:00
Michał Kępień 2d00143ab1 Prevent splitting GitLab identifiers across lines
GitLab issue and merge request numbers placed in release notes (in the
form of "#1234" for issues and "!5678" for merge requests) should not be
split across two lines.  Extend the shell pipeline generating
doc/arm/notes.txt with a sed invocation which prevents such splitting.
2020-01-03 09:08:09 +01:00
Evan Hunt 996c1d3727 Merge branch 'each-copyrights' into 'master'
update copyright year to 2020

See merge request isc-projects/bind9!2801
2020-01-03 05:53:01 +00:00
Evan Hunt 2df13f79ef update copyright year to 2020 2020-01-02 21:45:30 -08:00
Mark Andrews 993633ad96 Merge branch '1530-lib-dns-gen-c-29-26-fatal-error-isc-platform-h-no-such-file-or-directory' into 'master'
Resolve "lib/dns/gen.c:29:26: fatal error: isc/platform.h: No such file or directory"

Closes #1530

See merge request isc-projects/bind9!2792
2019-12-22 21:18:09 +00:00
Mark Andrews 848c1c8b8b remove duplicate #includes 2019-12-23 07:47:36 +11:00
Mark Andrews 7278f2529a revert d10fbdec for lib/dns/gen.c as it is a build platform executable 2019-12-23 07:37:13 +11:00
Mark Andrews 39780ae54f Merge branch '1501-summary-threadsanitizer-lock-order-inversion-potential-deadlock-in-pthread_rwlock_wrlock' into 'master'
Resolve "SUMMARY: ThreadSanitizer: lock-order-inversion (potential deadlock) in pthread_rwlock_wrlock - zone_postload"

See merge request isc-projects/bind9!2776
2019-12-20 10:57:43 +00:00
Mark Andrews d26e125438 Refactor loop body as copy_non_dnssec_records. 2019-12-20 21:31:23 +11:00
Ondřej SurýandMark Andrews bff83b9480 Add failure handling when iterators don't end with ISC_R_NOMORE 2019-12-20 21:31:23 +11:00
Ondřej SurýandMark Andrews 6012479419 Refactor receive_secure_db to make the variables and code flow around the iterator more local 2019-12-20 21:31:23 +11:00
Mark Andrews 9d8f9cc8f2 Call dns_dbiterator_destroy earlier to prevent potential deadlock. 2019-12-20 21:31:23 +11:00
Mark Andrews dafb1eb8bb Merge branch '1523-pkcs11-destroy-s-usage-message-is-misleading' into 'master'
Resolve "pkcs11-destroy's usage message is misleading"

Closes #1523

See merge request isc-projects/bind9!2785
2019-12-20 08:56:11 +00:00
Mark Andrews 41d827893e update usage message 2019-12-20 08:28:37 +00:00
Mark Andrews 3352a38da4 Merge branch '1418-threadsanitizer-data-race-dig-c-2542-in-main' into 'master'
Resolve "ThreadSanitizer: data race dig.c:2542 in main"

Closes #1418

See merge request isc-projects/bind9!2647
2019-12-20 05:57:50 +00:00
Ondřej SurýandMark Andrews b218bf5227 Fix the concurrent access to batchname in dig.c 2019-12-20 03:43:04 +00:00
Mark Andrews f8ec2140be Merge branch 'feature/master/maxminddb-version' into 'master'
Include maxminddb and protobuf version in named -V

See merge request isc-projects/bind9!2686
2019-12-17 23:58:31 +00:00
Mark Andrews 2f2bc03b2d add CHANGES 2019-12-18 10:57:25 +11:00
Petr MenšíkandMark Andrews 85f3476894 Include protobuf-c version
Include used version of protobuf-c in version info, both link time and
runtime version is available.
2019-12-17 23:46:52 +00:00
Petr MenšíkandMark Andrews e6d7384c0d Provide GeoIP2 library version in version
Libmaxmind does not provide any version macro for link time version.
Print at least runtime version library used, if linked.
2019-12-17 23:46:52 +00:00
Mark Andrews 0b7339ac6e Merge branch '1482-autosign-system-test-failed' into 'master'
Resolve "autosign system test failed"

Closes #1461 and #1482

See merge request isc-projects/bind9!2773
2019-12-13 08:58:14 +00:00
Mark Andrews 17d25dbf47 Fix autosign system test issues.
* report when NSEC3PARAM is not yet present
* allow more time for NSEC3PARAM to become present
* adjust frequency failure message
2019-12-13 08:31:56 +00:00
Ondřej Surý c2421a1ec3 Merge branch '1414-threadsanitizer-data-race-task-c-367-in-task_shutdown-v9_14+' into 'master'
Convert task->flags to C11 atomics

Closes #1414

See merge request isc-projects/bind9!2768
2019-12-13 07:41:53 +00:00
Ondřej Surý 5746172da3 Convert task flags to C11 atomics 2019-12-13 07:10:25 +01:00
Evan Hunt de42a7aa9f Merge branch 'prep-release-v9_15_7' into 'master'
Prep 9.15.7

See merge request isc-projects/bind9!2771
2019-12-13 00:00:45 +00:00
Tinderbox User 67bac2bcd9 Merge branch 'prep-release' 2019-12-12 23:59:51 +00:00
Tinderbox User e088272172 prep 9.15.7 2019-12-12 23:59:39 +00:00
Evan Hunt a3dc02103a Merge branch '1392-initial-tcp-highwater-wrong' into 'master'
Resolve "Initial TCP high-water value is wrong"

Closes #1392

See merge request isc-projects/bind9!2610
2019-12-12 19:52:36 +00:00
Evan Hunt 8c48c4f738 CHANGES 2019-12-12 11:24:26 -08:00
Diego FronzaandEvan Hunt 114520425c Added tcp-highwater test on initial statistics verification
The initial tcp statistics test was not testing tcp-highwater counter,
but only initial number of current TCP clients, so this missing test was
added to ensure initial tcp-highwater value is correct.
2019-12-12 11:23:11 -08:00
Diego FronzaandEvan Hunt ed9853e739 Fix tcp-highwater stats updating
After the network manager rewrite, tcp-higwater stats was only being
updated when a valid DNS query was received over tcp.

It turns out tcp-quota is updated right after a tcp connection is
accepted, before any data is read, so in the event that some client
connect but don't send a valid query, it wouldn't be taken into
account to update tcp-highwater stats, that is wrong.

This commit fix tcp-highwater to update its stats whenever a tcp connection
is established, independent of what happens after (timeout/invalid
request, etc).
2019-12-12 11:23:10 -08:00
Diego FronzaandEvan Hunt ead7b3dc53 Fix tcp-highwater initial value
During BIND startup it scans for network interfaces available, in this
process it ensures that for every interface it will bind and listen to,
at least one socket will be always available accepting connections on
that interface, this way avoiding some DOS attacks that could exploit
tcp quota on some interface and make others unavailable.

In the previous network implementation this initial "reserved" tcp-quota
used by BIND was already been added to the tcp-highwater stats, but with
the new network code it was necesary to add this workaround to ensure
tcp-highwater stats reflect the tcp-quota used by BIND after startup.
2019-12-12 11:23:10 -08:00
132 changed files with 3516 additions and 3084 deletions
+7
View File
@@ -23,6 +23,9 @@ variables:
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
# Pass run-time flags to AddressSanitizer to get core dumps on error.
ASAN_OPTIONS_COMMON: abort_on_error=1:disable_coredump=0:unmap_shadow_on_exit=1
TARBALL_COMPRESSOR: xz TARBALL_COMPRESSOR: xz
TARBALL_EXTENSION: xz TARBALL_EXTENSION: xz
@@ -805,6 +808,8 @@ asan:sid:amd64:
<<: *build_job <<: *build_job
system:asan:sid:amd64: system:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *system_test_job <<: *system_test_job
dependencies: dependencies:
@@ -812,6 +817,8 @@ system:asan:sid:amd64:
needs: ["asan:sid:amd64"] needs: ["asan:sid:amd64"]
unit:asan:sid:amd64: unit:asan:sid:amd64:
variables:
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
<<: *debian_sid_amd64_image <<: *debian_sid_amd64_image
<<: *unit_test_job <<: *unit_test_job
dependencies: dependencies:
+11 -3
View File
@@ -1,13 +1,21 @@
5337. [func] 'named -V' now reports maxminddb and protobuf-c
versions. [GL !2686]
--- 9.15.7 released ---
5336. [bug] The TCP high-water statistic could report an
incorrect value on startup. [GL #1392]
5335. [func] Make TCP listening code multithreaded. [GL !2659] 5335. [func] Make TCP listening code multithreaded. [GL !2659]
5334. [doc] Update documentation with dnssec-policy clarifications. 5334. [doc] Update documentation with dnssec-policy clarifications.
Also change some defaults. Also change some defaults. [GL !2711]
5333. [bug] Fix duration printing on Solaris when value is not 5333. [bug] Fix duration printing on Solaris when value is not
an ISO 8601 duration. [GL #1460] an ISO 8601 duration. [GL #1460]
5332. [func] Renamed "dnssec-keys" configuration statement 5332. [func] Renamed "dnssec-keys" configuration statement
to the more descriptive "trust-anchors". to the more descriptive "trust-anchors". [GL !2702]
5331. [func] Use compiler-provided mechanisms for thread local 5331. [func] Use compiler-provided mechanisms for thread local
storage, and make the requirement for such mechanisms storage, and make the requirement for such mechanisms
@@ -26,7 +34,7 @@
dropped because the recursive-clients quota was dropped because the recursive-clients quota was
exceeded. [GL #1399] exceeded. [GL #1399]
5326. [bug] Add python dependancy on 'distutils.core' to configure. 5326. [bug] Add Python dependency on 'distutils.core' to configure.
'distutils.core' is required for installation. 'distutils.core' is required for installation.
[GL #1397] [GL #1397]
+1 -1
View File
@@ -1,4 +1,4 @@
Copyright (C) 1996-2019 Internet Systems Consortium, Inc. ("ISC") Copyright (C) 1996-2020 Internet Systems Consortium, Inc. ("ISC")
This Source Code Form is subject to the terms of the Mozilla Public This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0. If a copy of the MPL was not distributed with this License, v. 2.0. If a copy of the MPL was not distributed with this
+7 -6
View File
@@ -115,9 +115,9 @@ of changes from BIND 9.14 and earlier releases. New features include:
for zones, enabling automatic key regeneration and rollover. for zones, enabling automatic key regeneration and rollover.
* New new network manager based on libuv. * New new network manager based on libuv.
* Support for the new GeoIP2 geolocation API * Support for the new GeoIP2 geolocation API
* Improved DNSSEC trust anchor configuration using dnssec-keys, * Improved DNSSEC trust anchor configuration using the trust-anchors
permitting configuration of trust anchors in DS as well as DNSKEY statement, permitting configuration of trust anchors in DS as well as
format. DNSKEY format.
* YAML output for dig, mdig, and delv. * YAML output for dig, mdig, and delv.
Building BIND Building BIND
@@ -180,9 +180,10 @@ Dependencies
Portions of BIND that are written in Python, including dnssec-keymgr, Portions of BIND that are written in Python, including dnssec-keymgr,
dnssec-coverage, dnssec-checkds, and some of the system tests, require the dnssec-coverage, dnssec-checkds, and some of the system tests, require the
argparse and ply modules to be available. argparse is a standard module as argparse, ply and distutils.core modules to be available. argparse is a
of Python 2.7 and Python 3.2. ply is available from https:// standard module as of Python 2.7 and Python 3.2. ply is available from
pypi.python.org/pypi/ply. https://pypi.python.org/pypi/ply. distutils.core is required for
installation.
Compile-time options Compile-time options
+1
View File
@@ -41,6 +41,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -44,6 +44,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -38,6 +38,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -45,6 +45,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -144,7 +144,7 @@ options\&.
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
\fBdelv\fR \fBdelv\fR
treats treats
\fBdnssec\-keys\fR\fBinitial\-key\fR \fBtrust\-anchors\fR\fBinitial\-key\fR
and and
\fBstatic\-key\fR \fBstatic\-key\fR
entries identically\&. That is, even if a key is configured with entries identically\&. That is, even if a key is configured with
+1
View File
@@ -40,6 +40,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -197,7 +197,7 @@
</p> </p>
<p> <p>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code> <span class="command"><strong>delv</strong></span> treats <code class="option">trust-anchors</code>
<code class="option">initial-key</code> and <code class="option">static-key</code> <code class="option">initial-key</code> and <code class="option">static-key</code>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <span class="command"><strong>initial-key</strong></span>, indicating that it is with <span class="command"><strong>initial-key</strong></span>, indicating that it is
+16 -13
View File
@@ -54,7 +54,7 @@
dig_lookup_t *default_lookup = NULL; dig_lookup_t *default_lookup = NULL;
static char *batchname = NULL; static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0);
static FILE *batchfp = NULL; static FILE *batchfp = NULL;
static char *argv0; static char *argv0;
static int addresscount = 0; static int addresscount = 0;
@@ -1874,7 +1874,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
value); value);
return (value_from_next); return (value_from_next);
case 'f': case 'f':
batchname = value; atomic_store(&batchname, (uintptr_t)value);
return (value_from_next); return (value_from_next);
case 'k': case 'k':
strlcpy(keyfile, value, sizeof(keyfile)); strlcpy(keyfile, value, sizeof(keyfile));
@@ -2327,13 +2327,15 @@ parse_args(bool is_batchfile, bool config_only,
* first entry, then trust the callback in dighost_shutdown * first entry, then trust the callback in dighost_shutdown
* to get the rest * to get the rest
*/ */
if ((batchname != NULL) && !(is_batchfile)) { char *filename = (char *)atomic_load(&batchname);
if (strcmp(batchname, "-") == 0) if ((filename != NULL) && !(is_batchfile)) {
if (strcmp(filename, "-") == 0) {
batchfp = stdin; batchfp = stdin;
else } else {
batchfp = fopen(batchname, "r"); batchfp = fopen(filename, "r");
}
if (batchfp == NULL) { if (batchfp == NULL) {
perror(batchname); perror(filename);
if (exitcode < 8) if (exitcode < 8)
exitcode = 8; exitcode = 8;
fatal("couldn't open specified batch file"); fatal("couldn't open specified batch file");
@@ -2388,14 +2390,14 @@ query_finished(void) {
int bargc; int bargc;
char *bargv[16]; char *bargv[16];
if (batchname == NULL) { if (atomic_load(&batchname) == 0) {
isc_app_shutdown(); isc_app_shutdown();
return; return;
} }
fflush(stdout); fflush(stdout);
if (feof(batchfp)) { if (feof(batchfp)) {
batchname = NULL; atomic_store(&batchname, 0);
isc_app_shutdown(); isc_app_shutdown();
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
@@ -2409,7 +2411,7 @@ query_finished(void) {
parse_args(true, false, bargc, (char **)bargv); parse_args(true, false, bargc, (char **)bargv);
start_lookup(); start_lookup();
} else { } else {
batchname = NULL; atomic_store(&batchname, 0);
if (batchfp != stdin) if (batchfp != stdin)
fclose(batchfp); fclose(batchfp);
isc_app_shutdown(); isc_app_shutdown();
@@ -2539,10 +2541,11 @@ void dig_query_start()
void void
dig_shutdown() { dig_shutdown() {
destroy_lookup(default_lookup); destroy_lookup(default_lookup);
if (batchname != NULL) { if (atomic_load(&batchname) != 0) {
if (batchfp != stdin) if (batchfp != stdin) {
fclose(batchfp); fclose(batchfp);
batchname = NULL; }
atomic_store(&batchname, 0);
} }
cancel_all(); cancel_all();
destroy_libs(); destroy_libs();
+1
View File
@@ -53,6 +53,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -48,6 +48,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -72,6 +72,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -41,6 +41,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -42,6 +42,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -39,6 +39,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -44,6 +44,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -51,6 +51,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -39,6 +39,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -41,6 +41,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -51,6 +51,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -38,6 +38,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+15
View File
@@ -59,6 +59,10 @@
#include <json_c_version.h> #include <json_c_version.h>
#endif /* HAVE_JSON_C */ #endif /* HAVE_JSON_C */
#ifdef HAVE_GEOIP2
#include <maxminddb.h>
#endif
/* /*
* Defining NAMED_MAIN provides storage declarations (rather than extern) * Defining NAMED_MAIN provides storage declarations (rather than extern)
* for variables in named/globals.h. * for variables in named/globals.h.
@@ -548,6 +552,17 @@ OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
ZLIB_VERSION); ZLIB_VERSION);
printf("linked to zlib version: %s\n", printf("linked to zlib version: %s\n",
zlibVersion()); zlibVersion());
#endif
#if defined(HAVE_GEOIP2)
/* Unfortunately, no version define on link time */
printf("linked to maxminddb version: %s\n",
MMDB_lib_version());
#endif
#if defined(HAVE_DNSTAP)
printf("compiled with protobuf-c version: %s\n",
PROTOBUF_C_VERSION);
printf("linked to protobuf-c version: %s\n",
protobuf_c_version());
#endif #endif
printf("threads support is enabled\n\n"); printf("threads support is enabled\n\n");
+21 -21
View File
@@ -97,20 +97,6 @@ dlz \fIstring\fR {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "DNSSEC-KEYS"
.sp
.if n \{\
.RS 4
.\}
.nf
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "DYNDB" .SH "DYNDB"
.sp .sp
.if n \{\ .if n \{\
@@ -164,7 +150,7 @@ logging {
.\} .\}
.SH "MANAGED-KEYS" .SH "MANAGED-KEYS"
.PP .PP
Deprecated \- see DNSSEC\-KEYS\&. Deprecated \- see TRUST\-ANCHORS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -565,9 +551,23 @@ statistics\-channels {
.if n \{\ .if n \{\
.RE .RE
.\} .\}
.SH "TRUST-ANCHORS"
.sp
.if n \{\
.RS 4
.\}
.nf
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds )
\fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
.fi
.if n \{\
.RE
.\}
.SH "TRUSTED-KEYS" .SH "TRUSTED-KEYS"
.PP .PP
Deprecated \- see DNSSEC\-KEYS\&. Deprecated \- see TRUST\-ANCHORS\&.
.sp .sp
.if n \{\ .if n \{\
.RS 4 .RS 4
@@ -655,10 +655,6 @@ view \fIstring\fR [ \fIclass\fR ] {
dnsrps\-options { \fIunspecified\-text\fR }; dnsrps\-options { \fIunspecified\-text\fR };
dnssec\-accept\-expired \fIboolean\fR; dnssec\-accept\-expired \fIboolean\fR;
dnssec\-dnskey\-kskonly \fIboolean\fR; dnssec\-dnskey\-kskonly \fIboolean\fR;
dnssec\-keys { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
dnssec\-loadkeys\-interval \fIinteger\fR; dnssec\-loadkeys\-interval \fIinteger\fR;
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR; dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
dnssec\-secure\-to\-insecure \fIboolean\fR; dnssec\-secure\-to\-insecure \fIboolean\fR;
@@ -849,6 +845,10 @@ view \fIstring\fR [ \fIclass\fR ] {
transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * )
] [ dscp \fIinteger\fR ]; ] [ dscp \fIinteger\fR ];
trust\-anchor\-telemetry \fIboolean\fR; // experimental trust\-anchor\-telemetry \fIboolean\fR; // experimental
trust\-anchors { \fIstring\fR ( static\-key |
initial\-key | static\-ds | initial\-ds
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIquoted_string\fR; \&.\&.\&. };
trusted\-keys { \fIstring\fR trusted\-keys { \fIstring\fR
\fIinteger\fR \fIinteger\fR \fIinteger\fR \fIinteger\fR
\fIinteger\fR \fIinteger\fR
@@ -1074,7 +1074,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
.\} .\}
.nf .nf
dnssec\-policy \fIstring\fR { dnssec\-policy \fIstring\fR {
dnskey\-ttl \fIttlval\fR; dnskey\-ttl \fIduration\fR;
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. }; keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
parent\-ds\-ttl \fIduration\fR; parent\-ds\-ttl \fIduration\fR;
parent\-propagation\-delay \fIduration\fR; parent\-propagation\-delay \fIduration\fR;
+1
View File
@@ -49,6 +49,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+26 -26
View File
@@ -92,17 +92,7 @@ dlz
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.11"></a><h2>DNSSEC-KEYS</h2> <a name="id-1.11"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection">
<a name="id-1.12"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br> dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
    <em class="replaceable"><code>unspecified-text</code></em> };<br>     <em class="replaceable"><code>unspecified-text</code></em> };<br>
@@ -110,7 +100,7 @@ dyndb
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13"></a><h2>KEY</h2> <a name="id-1.12"></a><h2>KEY</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
key <em class="replaceable"><code>string</code></em> {<br> key <em class="replaceable"><code>string</code></em> {<br>
algorithm <em class="replaceable"><code>string</code></em>;<br> algorithm <em class="replaceable"><code>string</code></em>;<br>
@@ -120,7 +110,7 @@ key
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.14"></a><h2>LOGGING</h2> <a name="id-1.13"></a><h2>LOGGING</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
logging {<br> logging {<br>
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br> category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
@@ -141,8 +131,8 @@ logging
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.15"></a><h2>MANAGED-KEYS</h2> <a name="id-1.14"></a><h2>MANAGED-KEYS</h2>
<p>Deprecated - see DNSSEC-KEYS.</p> <p>Deprecated - see TRUST-ANCHORS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br> managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
    | initial-key | static-ds |<br>     | initial-key | static-ds |<br>
@@ -152,7 +142,7 @@ managed-keys
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.16"></a><h2>MASTERS</h2> <a name="id-1.15"></a><h2>MASTERS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br> masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
    <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>     <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
@@ -162,7 +152,7 @@ masters
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.17"></a><h2>OPTIONS</h2> <a name="id-1.16"></a><h2>OPTIONS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
options {<br> options {<br>
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br> allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
@@ -461,7 +451,7 @@ options
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.18"></a><h2>PLUGIN</h2> <a name="id-1.17"></a><h2>PLUGIN</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br> plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
    } ];<br>     } ];<br>
@@ -469,7 +459,7 @@ plugin
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.19"></a><h2>SERVER</h2> <a name="id-1.18"></a><h2>SERVER</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
server <em class="replaceable"><code>netprefix</code></em> {<br> server <em class="replaceable"><code>netprefix</code></em> {<br>
bogus <em class="replaceable"><code>boolean</code></em>;<br> bogus <em class="replaceable"><code>boolean</code></em>;<br>
@@ -507,7 +497,7 @@ server
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.20"></a><h2>STATISTICS-CHANNELS</h2> <a name="id-1.19"></a><h2>STATISTICS-CHANNELS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
statistics-channels {<br> statistics-channels {<br>
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br> inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
@@ -518,9 +508,19 @@ statistics-channels
</p></div> </p></div>
</div> </div>
<div class="refsection">
<a name="id-1.20"></a><h2>TRUST-ANCHORS</h2>
<div class="literallayout"><p><br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection"> <div class="refsection">
<a name="id-1.21"></a><h2>TRUSTED-KEYS</h2> <a name="id-1.21"></a><h2>TRUSTED-KEYS</h2>
<p>Deprecated - see DNSSEC-KEYS.</p> <p>Deprecated - see TRUST-ANCHORS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
@@ -600,10 +600,6 @@ view
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br> dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br> dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br> dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br> dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br> dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br> dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
@@ -794,6 +790,10 @@ view
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br> transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
    ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>     ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br> trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
trusted-keys { <em class="replaceable"><code>string</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em><br>
@@ -1012,7 +1012,7 @@ zone
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dnssec-policy <em class="replaceable"><code>string</code></em> {<br> dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br> dnskey-ttl <em class="replaceable"><code>duration</code></em>;<br>
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br> keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br> parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br> parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
+1
View File
@@ -49,6 +49,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -50,6 +50,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -124,7 +124,7 @@ main(int argc, char *argv[]) {
if (errflg || (id && (label != NULL))) { if (errflg || (id && (label != NULL))) {
fprintf(stderr, "Usage:\n"); fprintf(stderr, "Usage:\n");
fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] " fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] "
"[-i id | -l label] [-p pin] [-w waittime]\n"); "{-i id | -l label} [-p pin] [-w waittime]\n");
exit(1); exit(1);
} }
+1
View File
@@ -38,6 +38,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -39,6 +39,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -38,6 +38,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -37,6 +37,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -33,6 +33,7 @@
<copyright> <copyright>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -40,6 +40,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -38,6 +38,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -35,6 +35,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -516,7 +516,7 @@ timer\&.
\fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR \fBsecroots \fR\fB[\-]\fR\fB \fR\fB[\fIview \&.\&.\&.\fR]\fR
.RS 4 .RS 4
Dump the security roots (i\&.e\&., trust anchors configured via Dump the security roots (i\&.e\&., trust anchors configured via
\fBdnssec\-keys\fR \fBtrust\-anchors\fR
statements, or the managed\-keys or trusted\-keys statements (both deprecated), or via statements, or the managed\-keys or trusted\-keys statements (both deprecated), or via
\fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&. \fBdnssec\-validation auto\fR) and negative trust anchors for the specified views\&. If no view is specified, all views are dumped\&. Security roots will indicate whether they are configured as trusted keys, managed keys, or initializing managed keys (managed keys that have not yet been updated by a successful key refresh query)\&.
.sp .sp
+1
View File
@@ -43,6 +43,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -44,6 +44,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1 -1
View File
@@ -654,7 +654,7 @@
<dd> <dd>
<p> <p>
Dump the security roots (i.e., trust anchors Dump the security roots (i.e., trust anchors
configured via <span class="command"><strong>dnssec-keys</strong></span> statements, or the configured via <span class="command"><strong>trust-anchors</strong></span> statements, or the
managed-keys or trusted-keys statements (both deprecated), or managed-keys or trusted-keys statements (both deprecated), or
via <span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust via <span class="command"><strong>dnssec-validation auto</strong></span>) and negative trust
anchors for the specified views. If no view is specified, all anchors for the specified views. If no view is specified, all
+10
View File
@@ -1,4 +1,14 @@
#!/bin/sh #!/bin/sh
#
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
#
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
#
# See the COPYRIGHT file distributed with this work for additional
# information regarding copyright ownership.
if [ -n "${SOFTHSM2_CONF}" ] && command -v softhsm2-util >/dev/null; then if [ -n "${SOFTHSM2_CONF}" ] && command -v softhsm2-util >/dev/null; then
SOFTHSM2_DIR=$(dirname "$SOFTHSM2_CONF") SOFTHSM2_DIR=$(dirname "$SOFTHSM2_CONF")
mkdir -p "${SOFTHSM2_DIR}/tokens" mkdir -p "${SOFTHSM2_DIR}/tokens"
+10 -3
View File
@@ -117,8 +117,12 @@ checkjitter () {
echo_i "checking whether all frequencies fall into <$_low;$_high> range" echo_i "checking whether all frequencies fall into <$_low;$_high> range"
for _num in $_expiretimes for _num in $_expiretimes
do do
if [ $_num -gt $_high ] || [ $_num -lt $_low ]; then if [ $_num -gt $_high ]; then
echo_i "error: too many RRSIG records ($_num) with the same expiration time" echo_i "error: too many RRSIG records ($_num) in expiration bucket"
_ret=1
fi
if [ $_num -lt $_low ]; then
echo_i "error: too few RRSIG records ($_num) in expiration bucket"
_ret=1 _ret=1
fi fi
done done
@@ -1051,7 +1055,10 @@ check_if_nsec3param_exists() {
$DIG $DIGOPTS NSEC3PARAM jitter.nsec3.example @10.53.0.3 > dig.out.ns3.1.test$n || return 1 $DIG $DIGOPTS NSEC3PARAM jitter.nsec3.example @10.53.0.3 > dig.out.ns3.1.test$n || return 1
grep -q "^jitter\.nsec3\.example\..*NSEC3PARAM" dig.out.ns3.1.test$n || return 1 grep -q "^jitter\.nsec3\.example\..*NSEC3PARAM" dig.out.ns3.1.test$n || return 1
} }
retry_quiet 20 check_if_nsec3param_exists || ret=1 retry_quiet 40 check_if_nsec3param_exists || {
echo_i "error: NSEC3PARAM not present yet"
ret=1
}
$DIG $DIGOPTS AXFR jitter.nsec3.example @10.53.0.3 > dig.out.ns3.2.test$n || ret=1 $DIG $DIGOPTS AXFR jitter.nsec3.example @10.53.0.3 > dig.out.ns3.2.test$n || ret=1
# Check jitter distribution. # Check jitter distribution.
checkjitter dig.out.ns3.2.test$n || ret=1 checkjitter dig.out.ns3.2.test$n || ret=1
+20 -32
View File
@@ -15,6 +15,12 @@ SYSTEMTESTTOP=..
DIGOPTS="+tcp +dnssec -p ${PORT}" DIGOPTS="+tcp +dnssec -p ${PORT}"
RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s" RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
wait_for_serial() (
$DIG $DIGOPTS "@$1" "$2" SOA > "$4"
serial=$(awk '$4 == "SOA" { print $7 }' "$4")
[ "$3" -eq "${serial:--1}" ]
)
status=0 status=0
n=0 n=0
@@ -1014,10 +1020,7 @@ ret=0
$DIG $DIGOPTS nsec3. SOA @10.53.0.3 > dig.out.n3.pre.test$n $DIG $DIGOPTS nsec3. SOA @10.53.0.3 > dig.out.n3.pre.test$n
newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] + 10) if ($field[3] eq "SOA"); }' < dig.out.n3.pre.test$n` newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] + 10) if ($field[3] eq "SOA"); }' < dig.out.n3.pre.test$n`
$RNDCCMD 10.53.0.3 signing -serial ${newserial:-0} nsec3 > /dev/null 2>&1 $RNDCCMD 10.53.0.3 signing -serial ${newserial:-0} nsec3 > /dev/null 2>&1
sleep 1 retry_quiet 5 wait_for_serial 10.53.0.3 nsec3. "${newserial:-0}" dig.out.ns3.post.test$n || ret=1
$DIG $DIGOPTS nsec3. SOA @10.53.0.3 > dig.out.ns3.post.test$n
serial=`awk '$4 == "SOA" { print $7 }' dig.out.ns3.post.test$n`
[ ${newserial:-0} -eq ${serial:-1} ] || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1047,10 +1050,7 @@ newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n",
$RNDCCMD 10.53.0.3 freeze nsec3 > /dev/null 2>&1 $RNDCCMD 10.53.0.3 freeze nsec3 > /dev/null 2>&1
$RNDCCMD 10.53.0.3 signing -serial ${newserial:-0} nsec3 > /dev/null 2>&1 $RNDCCMD 10.53.0.3 signing -serial ${newserial:-0} nsec3 > /dev/null 2>&1
$RNDCCMD 10.53.0.3 thaw nsec3 > /dev/null 2>&1 $RNDCCMD 10.53.0.3 thaw nsec3 > /dev/null 2>&1
sleep 1 retry_quiet 5 wait_for_serial 10.53.0.3 nsec3. "${newserial:-0}" dig.out.ns3.post1.test$n || ret=1
$DIG $DIGOPTS nsec3. SOA @10.53.0.3 > dig.out.ns3.post.test$n
serial=`awk '$4 == "SOA" { print $7 }' dig.out.ns3.post.test$n`
[ ${newserial:-0} -eq ${serial:-1} ] || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1060,10 +1060,7 @@ ret=0
$DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.pre.test$n $DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.pre.test$n
newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] + 10) if ($field[3] eq "SOA"); }' < dig.out.ns2.pre.test$n` newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] + 10) if ($field[3] eq "SOA"); }' < dig.out.ns2.pre.test$n`
$RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1 $RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1
sleep 1 retry_quiet 5 wait_for_serial 10.53.0.2 bits. "${newserial:-0}" dig.out.ns2.post.test$n || ret=1
$DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.post.test$n
serial=`awk '$4 == "SOA" { print $7 }' dig.out.ns2.post.test$n`
[ ${newserial:-0} -eq ${serial:-1} ] || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1074,10 +1071,8 @@ $DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.pre.test$n
oldserial=`awk '$4 == "SOA" { print $7 }' dig.out.ns2.pre.test$n` oldserial=`awk '$4 == "SOA" { print $7 }' dig.out.ns2.pre.test$n`
newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] - 10) if ($field[3] eq "SOA"); }' < dig.out.ns2.pre.test$n` newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n", $field[6] - 10) if ($field[3] eq "SOA"); }' < dig.out.ns2.pre.test$n`
$RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1 $RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1
sleep 1 retry_quiet 5 wait_for_serial 10.53.0.2 bits. "${newserial:-1}" dig.out.ns2.post1.test$n && ret=1
$DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.post.test$n retry_quiet 5 wait_for_serial 10.53.0.2 bits. "${oldserial:-1}" dig.out.ns2.post2.test$n || ret=1
serial=`awk '$4 == "SOA" { print $7 }' dig.out.ns2.post.test$n`
[ ${oldserial:-0} -eq ${serial:-1} ] || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1090,10 +1085,8 @@ newserial=`$PERL -e 'while (<>) { chomp; my @field = split /\s+/; printf("%u\n",
$RNDCCMD 10.53.0.2 freeze bits > /dev/null 2>&1 $RNDCCMD 10.53.0.2 freeze bits > /dev/null 2>&1
$RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1 $RNDCCMD 10.53.0.2 signing -serial ${newserial:-0} bits > /dev/null 2>&1
$RNDCCMD 10.53.0.2 thaw bits > /dev/null 2>&1 $RNDCCMD 10.53.0.2 thaw bits > /dev/null 2>&1
sleep 1 retry_quiet 5 wait_for_serial 10.53.0.2 bits. "${newserial:-1}" dig.out.ns2.post1.test$n && ret=1
$DIG $DIGOPTS bits. SOA @10.53.0.2 > dig.out.ns2.post.test$n retry_quiet 5 wait_for_serial 10.53.0.2 bits. "${oldserial:-1}" dig.out.ns2.post2.test$n || ret=1
serial=`awk '$4 == "SOA" { print $7 }' dig.out.ns2.post.test$n`
[ ${oldserial:-0} -eq ${serial:-1} ] || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=`expr $status + $ret` status=`expr $status + $ret`
@@ -1339,18 +1332,12 @@ ret=0
mv Kdelayedkeys* ns3/ mv Kdelayedkeys* ns3/
$RNDCCMD 10.53.0.3 loadkeys delayedkeys > rndc.out.ns3.pre.test$n 2>&1 || ret=1 $RNDCCMD 10.53.0.3 loadkeys delayedkeys > rndc.out.ns3.pre.test$n 2>&1 || ret=1
# Wait until the zone is signed. # Wait until the zone is signed.
ans=1 check_done_signing () (
for i in 1 2 3 4 5 6 7 8 9 10 $RNDCCMD 10.53.0.3 signing -list delayedkeys > signing.out.test$n 2>&1
do num=`grep "Done signing with" signing.out.test$n | wc -l`
$RNDCCMD 10.53.0.3 signing -list delayedkeys > signing.out.test$n 2>&1 [ $num -eq 2 ]
num=`grep "Done signing with" signing.out.test$n | wc -l` )
if [ $num -eq 2 ]; then retry_quiet 10 check_done_signing || ret=1
ans=0
break
fi
sleep 1
done
if [ $ans != 0 ]; then ret=1; fi
# Halt rather than stopping the server to prevent the master file from being # Halt rather than stopping the server to prevent the master file from being
# flushed upon shutdown since we specifically want to avoid it. # flushed upon shutdown since we specifically want to avoid it.
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc --halt --port ${CONTROLPORT} inline ns3 $PERL $SYSTEMTESTTOP/stop.pl --use-rndc --halt --port ${CONTROLPORT} inline ns3
@@ -1369,6 +1356,7 @@ $PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} inline ns3
# unless the records contained in it were scheduled for resigning, no resigning # unless the records contained in it were scheduled for resigning, no resigning
# event will be scheduled at all since the secure zone master file contains no # event will be scheduled at all since the secure zone master file contains no
# DNSSEC records. # DNSSEC records.
wait_for_log 20 "all zones loaded" ns3/named.run || ret=1
$RNDCCMD 10.53.0.3 zonestatus delayedkeys > rndc.out.ns3.post.test$n 2>&1 || ret=1 $RNDCCMD 10.53.0.3 zonestatus delayedkeys > rndc.out.ns3.post.test$n 2>&1 || ret=1
grep "next resign node:" rndc.out.ns3.post.test$n > /dev/null || ret=1 grep "next resign node:" rndc.out.ns3.post.test$n > /dev/null || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
+4
View File
@@ -105,6 +105,10 @@ echo_i "TCP high-water: check initial statistics ($n)"
ret=0 ret=0
refresh_tcp_stats refresh_tcp_stats
assert_int_equal "${TCP_CUR}" 0 "current TCP clients count" || ret=1 assert_int_equal "${TCP_CUR}" 0 "current TCP clients count" || ret=1
# We compare initial tcp-highwater value with 1 because as part of the
# system test startup, the script start.pl executes dig to check if target
# named is running, and that increments tcp-quota by one.
assert_int_equal "${TCP_HIGH}" 1 "tcp-highwater count" || ret=1
if [ $ret != 0 ]; then echo_i "failed"; fi if [ $ret != 0 ]; then echo_i "failed"; fi
status=$((status + ret)) status=$((status + ret))
+140 -130
View File
@@ -18,11 +18,41 @@ RNDCCMD="$RNDC -c $SYSTEMTESTTOP/common/rndc.conf -p ${CONTROLPORT} -s"
status=0 status=0
n=0 n=0
n=`expr $n + 1` n=$((n+1))
echo_i "testing basic zone transfer functionality" echo_i "testing basic zone transfer functionality (from primary) ($n)"
tmp=0
$DIG $DIGOPTS example. \ $DIG $DIGOPTS example. \
@10.53.0.2 axfr > dig.out.ns2 || status=1 @10.53.0.2 axfr > dig.out.ns2.test$n || tmp=1
grep "^;" dig.out.ns2 | cat_i grep "^;" dig.out.ns2.test$n | cat_i
digcomp dig1.good dig.out.ns2.test$n || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi
status=$((status+tmp))
n=$((n+1))
echo_i "testing basic zone transfer functionality (from secondary) ($n)"
#
# Spin to allow the zone to tranfer.
#
for i in 1 2 3 4 5
do
tmp=0
$DIG $DIGOPTS example. \
@10.53.0.3 axfr > dig.out.ns3.test$n || tmp=1
grep "^;" dig.out.ns3.test$n > /dev/null || break
echo_i "plain zone re-transfer"
sleep 5
done
grep "^;" dig.out.ns3.test$n | cat_i
digcomp dig1.good dig.out.ns3.test$n || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi
status=$((status+tmp))
n=$((n+1))
echo_i "testing TSIG signed zone transfers ($n)"
$DIG $DIGOPTS tsigzone. @10.53.0.2 axfr -y tsigzone.:1234abcd8765 > dig.out.ns2.test$n || status=1
grep "^;" dig.out.ns2.test$n | cat_i
# #
# Spin to allow the zone to tranfer. # Spin to allow the zone to tranfer.
@@ -30,41 +60,16 @@ grep "^;" dig.out.ns2 | cat_i
for i in 1 2 3 4 5 for i in 1 2 3 4 5
do do
tmp=0 tmp=0
$DIG $DIGOPTS example. \ $DIG $DIGOPTS tsigzone. @10.53.0.3 axfr -y tsigzone.:1234abcd8765 > dig.out.ns3.test$n || tmp=1
@10.53.0.3 axfr > dig.out.ns3 || tmp=1 grep "^;" dig.out.ns3.test$n > /dev/null
grep "^;" dig.out.ns3 > /dev/null
if test $? -ne 0 ; then break; fi if test $? -ne 0 ; then break; fi
echo_i "plain zone re-transfer" echo_i "plain zone re-transfer"
sleep 5 sleep 5
done done
if test $tmp -eq 1 ; then status=1; fi if test $tmp -eq 1 ; then status=1; fi
grep "^;" dig.out.ns3 | cat_i grep "^;" dig.out.ns3.test$n | cat_i
digcomp dig1.good dig.out.ns2 || status=1 digcomp dig.out.ns2.test$n dig.out.ns3.test$n || status=1
digcomp dig1.good dig.out.ns3 || status=1
n=`expr $n + 1`
echo_i "testing TSIG signed zone transfers"
$DIG $DIGOPTS tsigzone. @10.53.0.2 axfr -y tsigzone.:1234abcd8765 > dig.out.ns2 || status=1
grep "^;" dig.out.ns2 | cat_i
#
# Spin to allow the zone to tranfer.
#
for i in 1 2 3 4 5
do
tmp=0
$DIG $DIGOPTS tsigzone. @10.53.0.3 axfr -y tsigzone.:1234abcd8765 > dig.out.ns3 || tmp=1
grep "^;" dig.out.ns3 > /dev/null
if test $? -ne 0 ; then break; fi
echo_i "plain zone re-transfer"
sleep 5
done
if test $tmp -eq 1 ; then status=1; fi
grep "^;" dig.out.ns3 | cat_i
digcomp dig.out.ns2 dig.out.ns3 || status=1
echo_i "reload servers for in preparation for ixfr-from-differences tests" echo_i "reload servers for in preparation for ixfr-from-differences tests"
@@ -108,28 +113,29 @@ rndc_reload ns7 10.53.0.7
sleep 3 sleep 3
echo_i "testing zone is dumped after successful transfer" n=$((n+1))
echo_i "testing zone is dumped after successful transfer ($n)"
$DIG $DIGOPTS +noall +answer +multi @10.53.0.2 \ $DIG $DIGOPTS +noall +answer +multi @10.53.0.2 \
slave. soa > dig.out.ns2 || tmp=1 slave. soa > dig.out.ns2.test$n || tmp=1
grep "1397051952 ; serial" dig.out.ns2 > /dev/null 2>&1 || tmp=1 grep "1397051952 ; serial" dig.out.ns2.test$n > /dev/null 2>&1 || tmp=1
grep "1397051952 ; serial" ns2/slave.db > /dev/null 2>&1 || tmp=1 grep "1397051952 ; serial" ns2/slave.db > /dev/null 2>&1 || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "testing ixfr-from-differences yes;" echo_i "testing ixfr-from-differences yes; ($n)"
tmp=0 tmp=0
for i in 0 1 2 3 4 5 6 7 8 9 for i in 0 1 2 3 4 5 6 7 8 9
do do
a=0 b=0 c=0 d=0 a=0 b=0 c=0 d=0
echo_i "wait for reloads..." echo_i "wait for reloads..."
$DIG $DIGOPTS @10.53.0.6 +noall +answer soa master > dig.out.soa1.ns6 $DIG $DIGOPTS @10.53.0.6 +noall +answer soa master > dig.out.soa1.ns6.test$n
grep "1397051953" dig.out.soa1.ns6 > /dev/null && a=1 grep "1397051953" dig.out.soa1.ns6.test$n > /dev/null && a=1
$DIG $DIGOPTS @10.53.0.1 +noall +answer soa slave > dig.out.soa2.ns1 $DIG $DIGOPTS @10.53.0.1 +noall +answer soa slave > dig.out.soa2.ns1.test$n
grep "1397051953" dig.out.soa2.ns1 > /dev/null && b=1 grep "1397051953" dig.out.soa2.ns1.test$n > /dev/null && b=1
$DIG $DIGOPTS @10.53.0.2 +noall +answer soa example > dig.out.soa3.ns2 $DIG $DIGOPTS @10.53.0.2 +noall +answer soa example > dig.out.soa3.ns2.test$n
grep "1397051953" dig.out.soa3.ns2 > /dev/null && c=1 grep "1397051953" dig.out.soa3.ns2.test$n > /dev/null && c=1
[ $a -eq 1 -a $b -eq 1 -a $c -eq 1 ] && break [ $a -eq 1 -a $b -eq 1 -a $c -eq 1 ] && break
sleep 2 sleep 2
done done
@@ -138,12 +144,12 @@ for i in 0 1 2 3 4 5 6 7 8 9
do do
a=0 b=0 c=0 d=0 a=0 b=0 c=0 d=0
echo_i "wait for transfers..." echo_i "wait for transfers..."
$DIG $DIGOPTS @10.53.0.3 +noall +answer soa example > dig.out.soa1.ns3 $DIG $DIGOPTS @10.53.0.3 +noall +answer soa example > dig.out.soa1.ns3.test$n
grep "1397051953" dig.out.soa1.ns3 > /dev/null && a=1 grep "1397051953" dig.out.soa1.ns3.test$n > /dev/null && a=1
$DIG $DIGOPTS @10.53.0.3 +noall +answer soa master > dig.out.soa2.ns3 $DIG $DIGOPTS @10.53.0.3 +noall +answer soa master > dig.out.soa2.ns3.test$n
grep "1397051953" dig.out.soa2.ns3 > /dev/null && b=1 grep "1397051953" dig.out.soa2.ns3.test$n > /dev/null && b=1
$DIG $DIGOPTS @10.53.0.6 +noall +answer soa slave > dig.out.soa3.ns6 $DIG $DIGOPTS @10.53.0.6 +noall +answer soa slave > dig.out.soa3.ns6.test$n
grep "1397051953" dig.out.soa3.ns6 > /dev/null && c=1 grep "1397051953" dig.out.soa3.ns6.test$n > /dev/null && c=1
[ $a -eq 1 -a $b -eq 1 -a $c -eq 1 ] && break [ $a -eq 1 -a $b -eq 1 -a $c -eq 1 ] && break
# re-notify if necessary # re-notify if necessary
@@ -154,62 +160,62 @@ do
done done
$DIG $DIGOPTS example. \ $DIG $DIGOPTS example. \
@10.53.0.3 axfr > dig.out.ns3 || tmp=1 @10.53.0.3 axfr > dig.out.ns3.test$n || tmp=1
grep "^;" dig.out.ns3 | cat_i grep "^;" dig.out.ns3.test$n | cat_i
digcomp dig2.good dig.out.ns3 || tmp=1 digcomp dig2.good dig.out.ns3.test$n || tmp=1
# ns3 has a journal iff it received an IXFR. # ns3 has a journal iff it received an IXFR.
test -f ns3/example.bk || tmp=1 test -f ns3/example.bk || tmp=1
test -f ns3/example.bk.jnl || tmp=1 test -f ns3/example.bk.jnl || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "testing ixfr-from-differences master; (master zone)" echo_i "testing ixfr-from-differences master; (master zone) ($n)"
tmp=0 tmp=0
$DIG $DIGOPTS master. \ $DIG $DIGOPTS master. \
@10.53.0.6 axfr > dig.out.ns6 || tmp=1 @10.53.0.6 axfr > dig.out.ns6.test$n || tmp=1
grep "^;" dig.out.ns6 | cat_i grep "^;" dig.out.ns6.test$n | cat_i
$DIG $DIGOPTS master. \ $DIG $DIGOPTS master. \
@10.53.0.3 axfr > dig.out.ns3 || tmp=1 @10.53.0.3 axfr > dig.out.ns3.test$n || tmp=1
grep "^;" dig.out.ns3 > /dev/null && cat_i dig.out.ns3 grep "^;" dig.out.ns3.test$n > /dev/null && cat_i dig.out.ns3.test$n
digcomp dig.out.ns6 dig.out.ns3 || tmp=1 digcomp dig.out.ns6.test$n dig.out.ns3.test$n || tmp=1
# ns3 has a journal iff it received an IXFR. # ns3 has a journal iff it received an IXFR.
test -f ns3/master.bk || tmp=1 test -f ns3/master.bk || tmp=1
test -f ns3/master.bk.jnl || tmp=1 test -f ns3/master.bk.jnl || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "testing ixfr-from-differences master; (slave zone)" echo_i "testing ixfr-from-differences master; (slave zone) ($n)"
tmp=0 tmp=0
$DIG $DIGOPTS slave. \ $DIG $DIGOPTS slave. \
@10.53.0.6 axfr > dig.out.ns6 || tmp=1 @10.53.0.6 axfr > dig.out.ns6.test$n || tmp=1
grep "^;" dig.out.ns6 | cat_i grep "^;" dig.out.ns6.test$n | cat_i
$DIG $DIGOPTS slave. \ $DIG $DIGOPTS slave. \
@10.53.0.1 axfr > dig.out.ns1 || tmp=1 @10.53.0.1 axfr > dig.out.ns1.test$n || tmp=1
grep "^;" dig.out.ns1 | cat_i grep "^;" dig.out.ns1.test$n | cat_i
digcomp dig.out.ns6 dig.out.ns1 || tmp=1 digcomp dig.out.ns6.test$n dig.out.ns1.test$n || tmp=1
# ns6 has a journal iff it received an IXFR. # ns6 has a journal iff it received an IXFR.
test -f ns6/slave.bk || tmp=1 test -f ns6/slave.bk || tmp=1
test -f ns6/slave.bk.jnl && tmp=1 test -f ns6/slave.bk.jnl && tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "testing ixfr-from-differences slave; (master zone)" echo_i "testing ixfr-from-differences slave; (master zone) ($n)"
tmp=0 tmp=0
# ns7 has a journal iff it generates an IXFR. # ns7 has a journal iff it generates an IXFR.
@@ -217,35 +223,36 @@ test -f ns7/master2.db || tmp=1
test -f ns7/master2.db.jnl && tmp=1 test -f ns7/master2.db.jnl && tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "testing ixfr-from-differences slave; (slave zone)" echo_i "testing ixfr-from-differences slave; (slave zone) ($n)"
tmp=0 tmp=0
$DIG $DIGOPTS slave. \ $DIG $DIGOPTS slave. \
@10.53.0.1 axfr > dig.out.ns1 || tmp=1 @10.53.0.1 axfr > dig.out.ns1.test$n || tmp=1
grep "^;" dig.out.ns1 | cat_i grep "^;" dig.out.ns1.test$n | cat_i
$DIG $DIGOPTS slave. \ $DIG $DIGOPTS slave. \
@10.53.0.7 axfr > dig.out.ns7 || tmp=1 @10.53.0.7 axfr > dig.out.ns7.test$n || tmp=1
grep "^;" dig.out.ns1 | cat_i grep "^;" dig.out.ns7.test$n | cat_i
digcomp dig.out.ns7 dig.out.ns1 || tmp=1 digcomp dig.out.ns7.test$n dig.out.ns1.test$n || tmp=1
# ns7 has a journal iff it generates an IXFR. # ns7 has a journal iff it generates an IXFR.
test -f ns7/slave.bk || tmp=1 test -f ns7/slave.bk || tmp=1
test -f ns7/slave.bk.jnl || tmp=1 test -f ns7/slave.bk.jnl || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
echo_i "check that a multi-message uncompressable zone transfers" n=$((n+1))
echo_i "check that a multi-message uncompressable zone transfers ($n)"
$DIG axfr . -p ${PORT} @10.53.0.4 | grep SOA > axfr.out $DIG axfr . -p ${PORT} @10.53.0.4 | grep SOA > axfr.out
if test `wc -l < axfr.out` != 2 if test `wc -l < axfr.out` != 2
then then
echo_i "failed" echo_i "failed"
status=`expr $status + 1` status=$((status+1))
fi fi
# now we test transfers with assorted TSIG glitches # now we test transfers with assorted TSIG glitches
@@ -276,20 +283,20 @@ rndc_reload ns4 10.53.0.4
for i in 0 1 2 3 4 5 6 7 8 9 for i in 0 1 2 3 4 5 6 7 8 9
do do
$DIGCMD nil. SOA > dig.out.ns4 $DIGCMD nil. SOA > dig.out.ns4.test$n
grep SOA dig.out.ns4 > /dev/null && break grep SOA dig.out.ns4.test$n > /dev/null && break
sleep 1 sleep 1
done done
sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: success" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: success" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'initial AXFR' >/dev/null || { $DIGCMD nil. TXT | grep 'initial AXFR' >/dev/null || {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
echo_i "unsigned transfer" echo_i "unsigned transfer"
@@ -303,13 +310,13 @@ sleep 2
sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: expected a TSIG or SIG(0)" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: expected a TSIG or SIG(0)" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'unsigned AXFR' >/dev/null && { $DIGCMD nil. TXT | grep 'unsigned AXFR' >/dev/null && {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
echo_i "bad keydata" echo_i "bad keydata"
@@ -323,13 +330,13 @@ sleep 2
sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: tsig verify failure" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: tsig verify failure" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'bad keydata AXFR' >/dev/null && { $DIGCMD nil. TXT | grep 'bad keydata AXFR' >/dev/null && {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
echo_i "partially-signed transfer" echo_i "partially-signed transfer"
@@ -343,13 +350,13 @@ sleep 2
sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: expected a TSIG or SIG(0)" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "Transfer status: expected a TSIG or SIG(0)" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'partially signed AXFR' >/dev/null && { $DIGCMD nil. TXT | grep 'partially signed AXFR' >/dev/null && {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
echo_i "unknown key" echo_i "unknown key"
@@ -363,13 +370,13 @@ sleep 2
sed -n "$cur,\$p" < ns4/named.run | grep "tsig key 'tsig_key': key name and algorithm do not match" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "tsig key 'tsig_key': key name and algorithm do not match" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'unknown key AXFR' >/dev/null && { $DIGCMD nil. TXT | grep 'unknown key AXFR' >/dev/null && {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
echo_i "incorrect key" echo_i "incorrect key"
@@ -383,16 +390,16 @@ sleep 2
sed -n "$cur,\$p" < ns4/named.run | grep "tsig key 'tsig_key': key name and algorithm do not match" > /dev/null || { sed -n "$cur,\$p" < ns4/named.run | grep "tsig key 'tsig_key': key name and algorithm do not match" > /dev/null || {
echo_i "failed: expected status was not logged" echo_i "failed: expected status was not logged"
status=1 status=$((status+1))
} }
cur=`awk 'END {print NR}' ns4/named.run` cur=`awk 'END {print NR}' ns4/named.run`
$DIGCMD nil. TXT | grep 'incorrect key AXFR' >/dev/null && { $DIGCMD nil. TXT | grep 'incorrect key AXFR' >/dev/null && {
echo_i "failed" echo_i "failed"
status=1 status=$((status+1))
} }
n=`expr $n + 1` n=$((n+1))
echo_i "check that we ask for and get a EDNS EXPIRE response ($n)" echo_i "check that we ask for and get a EDNS EXPIRE response ($n)"
# force a refresh query # force a refresh query
$RNDCCMD 10.53.0.7 refresh edns-expire 2>&1 | sed 's/^/ns7 /' | cat_i $RNDCCMD 10.53.0.7 refresh edns-expire 2>&1 | sed 's/^/ns7 /' | cat_i
@@ -402,56 +409,59 @@ sleep 10
expire=`awk '/edns-expire\/IN: got EDNS EXPIRE of/ { x=$9 } END { print x }' ns7/named.run` expire=`awk '/edns-expire\/IN: got EDNS EXPIRE of/ { x=$9 } END { print x }' ns7/named.run`
test ${expire:-0} -gt 0 -a ${expire:-0} -lt 1814400 || { test ${expire:-0} -gt 0 -a ${expire:-0} -lt 1814400 || {
echo_i "failed (expire=${expire:-0})" echo_i "failed (expire=${expire:-0})"
status=1 status=$((status+1))
} }
n=`expr $n + 1` n=$((n+1))
echo_i "test smaller transfer TCP message size ($n)" echo_i "test smaller transfer TCP message size ($n)"
$DIG $DIGOPTS example. @10.53.0.8 axfr \ $DIG $DIGOPTS example. @10.53.0.8 axfr \
-y key1.:1234abcd8765 > dig.out.msgsize || status=1 -y key1.:1234abcd8765 > dig.out.msgsize.test$n || status=1
$DOS2UNIX dig.out.msgsize >/dev/null 2>&1 $DOS2UNIX dig.out.msgsize.test$n >/dev/null 2>&1
bytes=`wc -c < dig.out.msgsize` bytes=`wc -c < dig.out.msgsize.test$n`
if [ $bytes -ne 459357 ]; then if [ $bytes -ne 459357 ]; then
echo_i "failed axfr size check" echo_i "failed axfr size check"
status=1 status=$((status+1))
fi fi
num_messages=`cat ns8/named.run | grep "sending TCP message of" | wc -l` num_messages=`cat ns8/named.run | grep "sending TCP message of" | wc -l`
if [ $num_messages -le 300 ]; then if [ $num_messages -le 300 ]; then
echo_i "failed transfer message count check" echo_i "failed transfer message count check"
status=1 status=$((status+1))
fi fi
n=`expr $n + 1` n=$((n+1))
echo_i "test mapped zone with out of zone data ($n)" echo_i "test mapped zone with out of zone data ($n)"
tmp=0 tmp=0
$DIG -p ${PORT} txt mapped @10.53.0.3 > dig.out.1.$n $DIG -p ${PORT} txt mapped @10.53.0.3 > dig.out.1.test$n
grep "status: NOERROR," dig.out.1.$n > /dev/null || tmp=1 grep "status: NOERROR," dig.out.1.test$n > /dev/null || tmp=1
$PERL $SYSTEMTESTTOP/stop.pl xfer ns3 $PERL $SYSTEMTESTTOP/stop.pl xfer ns3
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} xfer ns3 $PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} xfer ns3
for try in 0 1 2 3 4 5 6 7 8 9; do for try in 0 1 2 3 4 5 6 7 8 9; do
iret=0 iret=0
$DIG -p ${PORT} txt mapped @10.53.0.3 > dig.out.2.$n $DIG -p ${PORT} txt mapped @10.53.0.3 > dig.out.2.test$n
grep "status: NOERROR," dig.out.2.$n > /dev/null || iret=1 grep "status: NOERROR," dig.out.2.test$n > /dev/null || iret=1
$DIG -p ${PORT} axfr mapped @10.53.0.3 > dig.out.3.$n if [ "$iret" -eq 0 ]
digcomp knowngood.mapped dig.out.3.$n || iret=1 then
$DIG -p ${PORT} axfr mapped @10.53.0.3 > dig.out.3.test$n
digcomp knowngood.mapped dig.out.3.test$n || iret=1
fi
[ "$iret" -eq 0 ] && break [ "$iret" -eq 0 ] && break
sleep 1 sleep 1
done done
[ "$iret" -eq 0 ] || tmp=1 [ "$iret" -eq 0 ] || tmp=1
[ "$tmp" -ne 0 ] && echo_i "failed" [ "$tmp" -ne 0 ] && echo_i "failed"
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "test that a zone with too many records is rejected (AXFR) ($n)" echo_i "test that a zone with too many records is rejected (AXFR) ($n)"
tmp=0 tmp=0
grep "'axfr-too-big/IN'.*: too many records" ns6/named.run >/dev/null || tmp=1 grep "'axfr-too-big/IN'.*: too many records" ns6/named.run >/dev/null || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "test that a zone with too many records is rejected (IXFR) ($n)" echo_i "test that a zone with too many records is rejected (IXFR) ($n)"
tmp=0 tmp=0
grep "'ixfr-too-big./IN.*: too many records" ns6/named.run >/dev/null && tmp=1 grep "'ixfr-too-big./IN.*: too many records" ns6/named.run >/dev/null && tmp=1
@@ -468,18 +478,18 @@ do
done done
grep "'ixfr-too-big/IN'.*: too many records" ns6/named.run >/dev/null || tmp=1 grep "'ixfr-too-big/IN'.*: too many records" ns6/named.run >/dev/null || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "checking whether dig calculates AXFR statistics correctly" echo_i "checking whether dig calculates AXFR statistics correctly ($n)"
# Loop until the secondary server manages to transfer the "xfer-stats" zone so # Loop until the secondary server manages to transfer the "xfer-stats" zone so
# that we can both check dig output and immediately proceed with the next test. # that we can both check dig output and immediately proceed with the next test.
# Use -b so that we can discern between incoming and outgoing transfers in ns3 # Use -b so that we can discern between incoming and outgoing transfers in ns3
# logs later on. # logs later on.
tmp=1 tmp=1
for i in 1 2 3 4 5 6 7 8 9 10; do for i in 1 2 3 4 5 6 7 8 9 10; do
$DIG $DIGOPTS +noedns +stat -b 10.53.0.2 @10.53.0.3 xfer-stats. AXFR > dig.out.ns3.$n $DIG $DIGOPTS +noedns +stat -b 10.53.0.2 @10.53.0.3 xfer-stats. AXFR > dig.out.ns3.test$n
if grep "; Transfer failed" dig.out.ns3.$n > /dev/null; then if grep "; Transfer failed" dig.out.ns3.test$n > /dev/null; then
sleep 1 sleep 1
else else
tmp=0 tmp=0
@@ -489,25 +499,25 @@ done
if [ $tmp -ne 0 ]; then if [ $tmp -ne 0 ]; then
echo_i "timed out waiting for zone transfer" echo_i "timed out waiting for zone transfer"
else else
get_dig_xfer_stats dig.out.ns3.$n > stats.dig get_dig_xfer_stats dig.out.ns3.test$n > stats.dig
diff axfr-stats.good stats.dig || tmp=1 diff axfr-stats.good stats.dig || tmp=1
fi fi
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
# Note: in the next two tests, we use ns3 logs for checking both incoming and # Note: in the next two tests, we use ns3 logs for checking both incoming and
# outgoing transfer statistics as ns3 is both a secondary server (for ns1) and a # outgoing transfer statistics as ns3 is both a secondary server (for ns1) and a
# primary server (for dig queries from the previous test) for "xfer-stats". # primary server (for dig queries from the previous test) for "xfer-stats".
n=`expr $n + 1` n=$((n+1))
echo_i "checking whether named calculates incoming AXFR statistics correctly" echo_i "checking whether named calculates incoming AXFR statistics correctly ($n)"
tmp=0 tmp=0
get_named_xfer_stats ns3/named.run 10.53.0.1 xfer-stats "Transfer completed" > stats.incoming get_named_xfer_stats ns3/named.run 10.53.0.1 xfer-stats "Transfer completed" > stats.incoming
diff axfr-stats.good stats.incoming || tmp=1 diff axfr-stats.good stats.incoming || tmp=1
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
n=`expr $n + 1` n=$((n+1))
echo_i "checking whether named calculates outgoing AXFR statistics correctly" echo_i "checking whether named calculates outgoing AXFR statistics correctly ($n)"
tmp=1 tmp=1
for i in 0 1 2 3 4 5 6 7 8 9; do for i in 0 1 2 3 4 5 6 7 8 9; do
get_named_xfer_stats ns3/named.run 10.53.0.2 xfer-stats "AXFR ended" > stats.outgoing get_named_xfer_stats ns3/named.run 10.53.0.2 xfer-stats "AXFR ended" > stats.outgoing
@@ -518,7 +528,7 @@ for i in 0 1 2 3 4 5 6 7 8 9; do
sleep 1 sleep 1
done done
if test $tmp != 0 ; then echo_i "failed"; fi if test $tmp != 0 ; then echo_i "failed"; fi
status=`expr $status + $tmp` status=$((status+tmp))
echo_i "exit status: $status" echo_i "exit status: $status"
[ $status -eq 0 ] || exit 1 [ $status -eq 0 ] || exit 1
+1
View File
@@ -37,6 +37,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -37,6 +37,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -37,6 +37,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -39,6 +39,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -35,6 +35,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -36,6 +36,7 @@
<year>2016</year> <year>2016</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -39,6 +39,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
</docinfo> </docinfo>
+1
View File
@@ -35,6 +35,7 @@
<year>2017</year> <year>2017</year>
<year>2018</year> <year>2018</year>
<year>2019</year> <year>2019</year>
<year>2020</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder> <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright> </copyright>
<!-- insert copyright end --> <!-- insert copyright end -->
+1 -1
View File
@@ -614,6 +614,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -146,6 +146,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -856,6 +856,6 @@ controls {
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+7 -7
View File
@@ -1042,7 +1042,7 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
<strong class="userinput"><code>yes</code></strong>, DNSSEC validation will only occur <strong class="userinput"><code>yes</code></strong>, DNSSEC validation will only occur
if at least one trust anchor has been explicitly configured if at least one trust anchor has been explicitly configured
in <code class="filename">named.conf</code> in <code class="filename">named.conf</code>
using a <span class="command"><strong>dnssec-keys</strong></span> statement (or the using a <span class="command"><strong>trust-anchors</strong></span> statement (or the
<span class="command"><strong>managed-keys</strong></span> and <span class="command"><strong>trusted-keys</strong></span> <span class="command"><strong>managed-keys</strong></span> and <span class="command"><strong>trusted-keys</strong></span>
statements, both deprecated). statements, both deprecated).
</p> </p>
@@ -1057,7 +1057,7 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
</p> </p>
<p> <p>
The keys specified in <span class="command"><strong>dnssec-keys</strong></span> The keys specified in <span class="command"><strong>trust-anchors</strong></span>
copies of DNSKEY RRs for zones that are used to form the copies of DNSKEY RRs for zones that are used to form the
first link in the cryptographic chain of trust. Keys configured first link in the cryptographic chain of trust. Keys configured
with the keyword <span class="command"><strong>static-key</strong></span> or with the keyword <span class="command"><strong>static-key</strong></span> or
@@ -1071,7 +1071,7 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
</p> </p>
<p> <p>
<span class="command"><strong>dnssec-keys</strong></span> is described in more detail <span class="command"><strong>trust-anchors</strong></span> is described in more detail
later in this document. later in this document.
</p> </p>
@@ -1094,7 +1094,7 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
</p> </p>
<pre class="programlisting"> <pre class="programlisting">
dnssec-keys { trust-anchors {
/* Root Key */ /* Root Key */
"." initial-key 257 3 3 "BNY4wrWM1nCfJ+CXd0rVXyYmobt7sEEfK3clRbGaTwS "." initial-key 257 3 3 "BNY4wrWM1nCfJ+CXd0rVXyYmobt7sEEfK3clRbGaTwS
JxrGkxJWoZu6I7PzJu/E9gx4UC1zGAHlXKdE4zYIpRh JxrGkxJWoZu6I7PzJu/E9gx4UC1zGAHlXKdE4zYIpRh
@@ -1586,10 +1586,10 @@ options {
<p>To configure a validating resolver to use RFC 5011 to <p>To configure a validating resolver to use RFC 5011 to
maintain a trust anchor, configure the trust anchor using a maintain a trust anchor, configure the trust anchor using a
<span class="command"><strong>dnssec-keys</strong></span> statement and the <span class="command"><strong>trust-anchors</strong></span> statement and the
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span> <span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
keyword. Information about this can be found in keyword. Information about this can be found in
<a class="xref" href="Bv9ARM.ch05.html#dnssec-keys" title="dnssec-keys Statement Definition and Usage">the section called &#8220;<span class="command"><strong>dnssec-keys</strong></span> Statement Definition <a class="xref" href="Bv9ARM.ch05.html#trust-anchors" title="trust-anchors Statement Definition and Usage">the section called &#8220;<span class="command"><strong>trust-anchors</strong></span> Statement Definition
and Usage&#8221;</a>.</p> and Usage&#8221;</a>.</p>
</div> </div>
<div class="section"> <div class="section">
@@ -2915,6 +2915,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+98 -65
View File
@@ -67,8 +67,8 @@
<dt><span class="section"><a href="Bv9ARM.ch05.html#statschannels"><span class="command"><strong>statistics-channels</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#statschannels"><span class="command"><strong>statistics-channels</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#statistics_channels"><span class="command"><strong>statistics-channels</strong></span> Statement Definition and <dt><span class="section"><a href="Bv9ARM.ch05.html#statistics_channels"><span class="command"><strong>statistics-channels</strong></span> Statement Definition and
Usage</a></span></dt> Usage</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#trust_anchors"><span class="command"><strong>trust-anchors</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec-keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Definition <dt><span class="section"><a href="Bv9ARM.ch05.html#trust-anchors"><span class="command"><strong>trust-anchors</strong></span> Statement Definition
and Usage</a></span></dt> and Usage</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition <dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition
@@ -899,7 +899,7 @@
</tr> </tr>
<tr> <tr>
<td> <td>
<p><span class="command"><strong>dnssec-keys</strong></span></p> <p><span class="command"><strong>trust-anchors</strong></span></p>
</td> </td>
<td> <td>
<p> <p>
@@ -920,9 +920,9 @@
</td> </td>
<td> <td>
<p> <p>
is identical to <span class="command"><strong>dnssec-keys</strong></span>; is identical to <span class="command"><strong>trust-anchors</strong></span>;
this option is deprecated in favor this option is deprecated in favor
of <span class="command"><strong>dnssec-keys</strong></span> with of <span class="command"><strong>trust-anchors</strong></span> with
the <span class="command"><strong>initial-key</strong></span> keyword, the <span class="command"><strong>initial-key</strong></span> keyword,
and may be removed in a future release. and may be removed in a future release.
</p> </p>
@@ -936,7 +936,7 @@
<p> <p>
defines permanent trusted DNSSEC keys; defines permanent trusted DNSSEC keys;
this option is deprecated in favor this option is deprecated in favor
of <span class="command"><strong>dnssec-keys</strong></span> with of <span class="command"><strong>trust-anchors</strong></span> with
the <span class="command"><strong>static-key</strong></span> keyword, the <span class="command"><strong>static-key</strong></span> keyword,
and may be removed in a future release. and may be removed in a future release.
</p> </p>
@@ -2950,9 +2950,9 @@ badresp:1,adberr:0,findfail:0,valfail:0]
The number of seconds to wait between attempts to The number of seconds to wait between attempts to
reopen a closed output stream. The minimum is 1 second, reopen a closed output stream. The minimum is 1 second,
the maximum is 600 seconds (10 minutes), and the default the maximum is 600 seconds (10 minutes), and the default
is 5 seconds. is 5 seconds. For convenience, TTL-style time unit
For convenience, TTL-style time unit suffixes may be suffixes may be used to specify the value. It also
used to specify the value. accepts ISO 8601 duration formats.
</li> </li>
</ul></div> </ul></div>
@@ -3087,7 +3087,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
track managed DNSSEC keys (i.e., those configured using track managed DNSSEC keys (i.e., those configured using
the <span class="command"><strong>initial-key</strong></span> or the <span class="command"><strong>initial-key</strong></span> or
<span class="command"><strong>initial-ds</strong></span> keywords in a <span class="command"><strong>initial-ds</strong></span> keywords in a
<span class="command"><strong>dnssec-keys</strong></span> statement). By default, <span class="command"><strong>trust-anchors</strong></span> statement). By default,
this is the working directory. The directory this is the working directory. The directory
<span class="emphasis"><em>must</em></span> be writable by the effective <span class="emphasis"><em>must</em></span> be writable by the effective
user ID of the <span class="command"><strong>named</strong></span> process. user ID of the <span class="command"><strong>named</strong></span> process.
@@ -3455,7 +3455,7 @@ options {
as insecure. as insecure.
</p> </p>
<p> <p>
Configured trust anchors in <span class="command"><strong>dnssec-keys</strong></span> Configured trust anchors in <span class="command"><strong>trust-anchors</strong></span>
(or <span class="command"><strong>managed-keys</strong></span> or (or <span class="command"><strong>managed-keys</strong></span> or
<span class="command"><strong>trusted-keys</strong></span>, both deprecated) <span class="command"><strong>trusted-keys</strong></span>, both deprecated)
that match a disabled algorithm will be ignored and treated that match a disabled algorithm will be ignored and treated
@@ -3487,7 +3487,7 @@ options {
they are secure. If <strong class="userinput"><code>no</code></strong>, then normal they are secure. If <strong class="userinput"><code>no</code></strong>, then normal
DNSSEC validation applies allowing for insecure answers to DNSSEC validation applies allowing for insecure answers to
be accepted. The specified domain must be defined as a be accepted. The specified domain must be defined as a
trust anchor, for instance in a <span class="command"><strong>dnssec-keys</strong></span> trust anchor, for instance in a <span class="command"><strong>trust-anchors</strong></span>
statement, or <span class="command"><strong>dnssec-validation auto</strong></span> must statement, or <span class="command"><strong>dnssec-validation auto</strong></span> must
be active. be active.
</p> </p>
@@ -3646,8 +3646,11 @@ options {
<p> <p>
For convenience, TTL-style time unit suffixes can be For convenience, TTL-style time unit suffixes can be
used to specify the NTA lifetime in seconds, minutes used to specify the NTA lifetime in seconds, minutes
or hours. <code class="option">nta-lifetime</code> defaults to or hours. It also accepts ISO 8601 duration formats.
one hour. It cannot exceed one week. </p>
<p>
<code class="option">nta-lifetime</code> defaults to one hour. It
cannot exceed one week.
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>nta-recheck</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>nta-recheck</strong></span></span></dt>
@@ -3677,9 +3680,13 @@ options {
<p> <p>
For convenience, TTL-style time unit suffixes can be For convenience, TTL-style time unit suffixes can be
used to specify the NTA recheck interval in seconds, used to specify the NTA recheck interval in seconds,
minutes or hours. The default is five minutes. It minutes or hours. It also accepts ISO 8601 duration
cannot be longer than <code class="option">nta-lifetime</code> formats.
(which cannot be longer than a week). </p>
<p>
The default is five minutes. It cannot be longer than
<code class="option">nta-lifetime</code> (which cannot be longer
than a week).
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>max-zone-ttl</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>max-zone-ttl</strong></span></span></dt>
@@ -3687,7 +3694,10 @@ options {
<p> <p>
Specifies a maximum permissible TTL value in seconds. Specifies a maximum permissible TTL value in seconds.
For convenience, TTL-style time unit suffixes may be For convenience, TTL-style time unit suffixes may be
used to specify the maximum value. used to specify the maximum value. It also
accepts ISO 8601 duration formats.
</p>
<p>
When loading a zone file using a When loading a zone file using a
<code class="option">masterfile-format</code> of <code class="option">masterfile-format</code> of
<code class="constant">text</code> or <code class="constant">raw</code>, <code class="constant">text</code> or <code class="constant">raw</code>,
@@ -4500,7 +4510,7 @@ options {
Causes <span class="command"><strong>named</strong></span> to send specially-formed Causes <span class="command"><strong>named</strong></span> to send specially-formed
queries once per day to domains for which trust anchors queries once per day to domains for which trust anchors
have been configured via, e.g., have been configured via, e.g.,
<span class="command"><strong>dnssec-keys</strong></span> or <span class="command"><strong>trust-anchors</strong></span> or
<span class="command"><strong>dnssec-validation auto</strong></span>. <span class="command"><strong>dnssec-validation auto</strong></span>.
</p> </p>
<p> <p>
@@ -4691,7 +4701,7 @@ options {
<p> <p>
If set to <strong class="userinput"><code>yes</code></strong>, DNSSEC validation is If set to <strong class="userinput"><code>yes</code></strong>, DNSSEC validation is
enabled, but a trust anchor must be manually configured enabled, but a trust anchor must be manually configured
using a <span class="command"><strong>dnssec-keys</strong></span> statement (or using a <span class="command"><strong>trust-anchors</strong></span> statement (or
the <span class="command"><strong>managed-keys</strong></span> or the the <span class="command"><strong>managed-keys</strong></span> or the
<span class="command"><strong>trusted-keys</strong></span> statements, both deprecated). <span class="command"><strong>trusted-keys</strong></span> statements, both deprecated).
If there is no configured trust anchor, validation will If there is no configured trust anchor, validation will
@@ -6515,7 +6525,8 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
<span class="command"><strong>listen-on</strong></span> configuration), and <span class="command"><strong>listen-on</strong></span> configuration), and
will stop listening on interfaces that have gone away. will stop listening on interfaces that have gone away.
For convenience, TTL-style time unit suffixes may be For convenience, TTL-style time unit suffixes may be
used to specify the value. used to specify the value. It also accepts ISO 8601
duration formats.
</p> </p>
</dd> </dd>
</dl></div> </dl></div>
@@ -6795,9 +6806,13 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
stores negative answers. <span class="command"><strong>min-ncache-ttl</strong></span> is stores negative answers. <span class="command"><strong>min-ncache-ttl</strong></span> is
used to set a minimum retention time for these answers in the used to set a minimum retention time for these answers in the
server in seconds. For convenience, TTL-style time unit server in seconds. For convenience, TTL-style time unit
suffixes may be used to specify the value. The default suffixes may be used to specify the value. It also
<span class="command"><strong>min-ncache-ttl</strong></span> is <code class="literal">0</code> accepts ISO 8601 duration formats.
seconds. <span class="command"><strong>min-ncache-ttl</strong></span> cannot exceed 90 </p>
<p>
The default <span class="command"><strong>min-ncache-ttl</strong></span> is
<code class="literal">0</code> seconds.
<span class="command"><strong>min-ncache-ttl</strong></span> cannot exceed 90
seconds and will be truncated to 90 seconds if set to a seconds and will be truncated to 90 seconds if set to a
greater value. greater value.
</p> </p>
@@ -6806,10 +6821,14 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
<dd> <dd>
<p> <p>
Sets the minimum time for which the server will cache ordinary Sets the minimum time for which the server will cache ordinary
(positive) answers in seconds. For convenience, TTL-style time (positive) answers in seconds. For convenience, TTL-style
unit suffixes may be used to specify the value. The default time unit suffixes may be used to specify the value. It also
<span class="command"><strong>min-cache-ttl</strong></span> is <code class="literal">0</code> accepts ISO 8601 duration formats.
seconds. <span class="command"><strong>min-cache-ttl</strong></span> cannot exceed 90 </p>
<p>
The default <span class="command"><strong>min-cache-ttl</strong></span> is
<code class="literal">0</code> seconds.
<span class="command"><strong>min-cache-ttl</strong></span> cannot exceed 90
seconds and will be truncated to 90 seconds if set to a seconds and will be truncated to 90 seconds if set to a
greater value. greater value.
</p> </p>
@@ -6818,15 +6837,19 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
<dd> <dd>
<p> <p>
To reduce network traffic and increase performance, To reduce network traffic and increase performance,
the server stores negative answers. <span class="command"><strong>max-ncache-ttl</strong></span> is the server stores negative answers.
<span class="command"><strong>max-ncache-ttl</strong></span> is
used to set a maximum retention time for these answers in used to set a maximum retention time for these answers in
the server in seconds. the server in seconds. For convenience, TTL-style time unit
For convenience, TTL-style time unit suffixes may be suffixes may be used to specify the value. It also accepts
used to specify the value. The default ISO 8601 duration formats.
<span class="command"><strong>max-ncache-ttl</strong></span> is <code class="literal">10800</code> seconds (3 hours). </p>
<span class="command"><strong>max-ncache-ttl</strong></span> cannot exceed <p>
7 days and will The default <span class="command"><strong>max-ncache-ttl</strong></span> is
be silently truncated to 7 days if set to a greater value. <code class="literal">10800</code> seconds (3 hours).
<span class="command"><strong>max-ncache-ttl</strong></span> cannot exceed 7 days and
will be silently truncated to 7 days if set to a greater
value.
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>max-cache-ttl</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>max-cache-ttl</strong></span></span></dt>
@@ -6835,7 +6858,10 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
Sets the maximum time for which the server will Sets the maximum time for which the server will
cache ordinary (positive) answers in seconds. cache ordinary (positive) answers in seconds.
For convenience, TTL-style time unit suffixes may be For convenience, TTL-style time unit suffixes may be
used to specify the value. used to specify the value. It also accepts ISO 8601
duration formats.
</p>
<p>
The default is 604800 (one week). The default is 604800 (one week).
A value of zero may cause all queries to return A value of zero may cause all queries to return
SERVFAIL, because of lost caches of intermediate SERVFAIL, because of lost caches of intermediate
@@ -8043,7 +8069,9 @@ deny-answer-aliases { "example.net"; };
The <span class="command"><strong>max-policy-ttl</strong></span> clause changes the The <span class="command"><strong>max-policy-ttl</strong></span> clause changes the
maximum seconds from its default of 5. maximum seconds from its default of 5.
For convenience, TTL-style time unit suffixes may be For convenience, TTL-style time unit suffixes may be
used to specify the value. used to specify the value. It also accepts ISO 8601 duration
formats.
</p> </p>
<p> <p>
@@ -8139,7 +8167,8 @@ example.com CNAME rpz-tcp-only.
recent update, then the changes will not be carried out until this recent update, then the changes will not be carried out until this
interval has elapsed. The default is <code class="literal">60</code> seconds. interval has elapsed. The default is <code class="literal">60</code> seconds.
For convenience, TTL-style time unit suffixes may be For convenience, TTL-style time unit suffixes may be
used to specify the value. used to specify the value. It also accepts ISO 8601 duration
formats.
</p> </p>
</div> </div>
@@ -8849,9 +8878,9 @@ example.com CNAME rpz-tcp-only.
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h3 class="title"> <div class="titlepage"><div><div><h3 class="title">
<a name="dnssec_keys"></a><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</h3></div></div></div> <a name="trust_anchors"></a><span class="command"><strong>trust-anchors</strong></span> Statement Grammar</h3></div></div></div>
<pre class="programlisting"> <pre class="programlisting">
<span class="command"><strong>dnssec-keys</strong></span> { <em class="replaceable"><code>string</code></em> ( static-key | <span class="command"><strong>trust-anchors</strong></span> { <em class="replaceable"><code>string</code></em> ( static-key |
<span class="command"><strong>initial-key</strong></span> | static-ds | initial-ds ) <span class="command"><strong>initial-key</strong></span> | static-ds | initial-ds )
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em>
<em class="replaceable"><code>quoted_string</code></em>; ... }; <em class="replaceable"><code>quoted_string</code></em>; ... };
@@ -8859,11 +8888,11 @@ example.com CNAME rpz-tcp-only.
</div> </div>
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h3 class="title"> <div class="titlepage"><div><div><h3 class="title">
<a name="dnssec-keys"></a><span class="command"><strong>dnssec-keys</strong></span> Statement Definition <a name="trust-anchors"></a><span class="command"><strong>trust-anchors</strong></span> Statement Definition
and Usage</h3></div></div></div> and Usage</h3></div></div></div>
<p> <p>
The <span class="command"><strong>dnssec-keys</strong></span> statement defines DNSSEC The <span class="command"><strong>trust-anchors</strong></span> statement defines DNSSEC
trust anchors. DNSSEC is described in <a class="xref" href="Bv9ARM.ch04.html#DNSSEC" title="DNSSEC">the section called &#8220;DNSSEC&#8221;</a>. trust anchors. DNSSEC is described in <a class="xref" href="Bv9ARM.ch04.html#DNSSEC" title="DNSSEC">the section called &#8220;DNSSEC&#8221;</a>.
</p> </p>
<p> <p>
@@ -8882,21 +8911,21 @@ example.com CNAME rpz-tcp-only.
the <span class="command"><strong>validate-except</strong></span> option). the <span class="command"><strong>validate-except</strong></span> option).
</p> </p>
<p> <p>
All keys listed in <span class="command"><strong>dnssec-keys</strong></span>, and All keys listed in <span class="command"><strong>trust-anchors</strong></span>, and
their corresponding zones, are deemed to exist regardless their corresponding zones, are deemed to exist regardless
of what parent zones say. Only keys configured as trust anchors of what parent zones say. Only keys configured as trust anchors
are used to validate the DNSKEY RRset for the corresponding are used to validate the DNSKEY RRset for the corresponding
name. The parent's DS RRset will not be used. name. The parent's DS RRset will not be used.
</p> </p>
<p> <p>
<span class="command"><strong>dnssec-keys</strong></span> may be set at the top level <span class="command"><strong>trust-anchors</strong></span> may be set at the top level
of <code class="filename">named.conf</code> or within a view. If it is of <code class="filename">named.conf</code> or within a view. If it is
set in both places, the configurations are additive: keys set in both places, the configurations are additive: keys
defined at the top level are inherited by all views, but keys defined at the top level are inherited by all views, but keys
defined in a view are only used within that view. defined in a view are only used within that view.
</p> </p>
<p> <p>
The <span class="command"><strong>dnssec-keys</strong></span> statement can contain The <span class="command"><strong>trust-anchors</strong></span> statement can contain
multiple trust anchor entries, each consisting of a multiple trust anchor entries, each consisting of a
domain name, followed by an "anchor type" keyword indicating domain name, followed by an "anchor type" keyword indicating
the trust anchor's format, followed by the key or digest data. the trust anchor's format, followed by the key or digest data.
@@ -8936,7 +8965,7 @@ example.com CNAME rpz-tcp-only.
<span class="command"><strong>static-ds</strong></span> would be unable to validate <span class="command"><strong>static-ds</strong></span> would be unable to validate
this zone any longer; it would reply with a SERVFAIL response this zone any longer; it would reply with a SERVFAIL response
code. This would continue until the resolver operator had code. This would continue until the resolver operator had
updated the <span class="command"><strong>dnssec-keys</strong></span> statement with updated the <span class="command"><strong>trust-anchors</strong></span> statement with
the new key. the new key.
</p> </p>
<p> <p>
@@ -8972,7 +9001,7 @@ example.com CNAME rpz-tcp-only.
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span> <span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
configured in <code class="filename">named.conf</code>, it fetches the configured in <code class="filename">named.conf</code>, it fetches the
DNSKEY RRset directly from the zone apex, and validates it DNSKEY RRset directly from the zone apex, and validates it
using the trust anchor specified in <span class="command"><strong>dnssec-keys</strong></span>. using the trust anchor specified in <span class="command"><strong>trust-anchors</strong></span>.
If the DNSKEY RRset is validly signed by a key matching If the DNSKEY RRset is validly signed by a key matching
the trust anchor, then it is used as the basis for a new the trust anchor, then it is used as the basis for a new
managed keys database. managed keys database.
@@ -8981,10 +9010,10 @@ example.com CNAME rpz-tcp-only.
From that point on, whenever <span class="command"><strong>named</strong></span> runs, it From that point on, whenever <span class="command"><strong>named</strong></span> runs, it
sees the <span class="command"><strong>initial-key</strong></span> or sees the <span class="command"><strong>initial-key</strong></span> or
<span class="command"><strong>initial-ds</strong></span> listed in <span class="command"><strong>initial-ds</strong></span> listed in
<span class="command"><strong>dnssec-keys</strong></span>, checks to <span class="command"><strong>trust-anchors</strong></span>, checks to
make sure RFC 5011 key maintenance has already been initialized make sure RFC 5011 key maintenance has already been initialized
for the specified domain, and if so, it simply moves on. The for the specified domain, and if so, it simply moves on. The
key specified in the <span class="command"><strong>dnssec-keys</strong></span> key specified in the <span class="command"><strong>trust-anchors</strong></span>
statement is not used to validate answers; it is statement is not used to validate answers; it is
superseded by the key or keys stored in the managed keys superseded by the key or keys stored in the managed keys
database. database.
@@ -8993,7 +9022,7 @@ example.com CNAME rpz-tcp-only.
The next time <span class="command"><strong>named</strong></span> runs after an The next time <span class="command"><strong>named</strong></span> runs after an
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span> <span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
trust anchor has been <span class="emphasis"><em>removed</em></span> from the trust anchor has been <span class="emphasis"><em>removed</em></span> from the
<span class="command"><strong>dnssec-keys</strong></span> statement (or changed to <span class="command"><strong>trust-anchors</strong></span> statement (or changed to
a <span class="command"><strong>static-key</strong></span> or <span class="command"><strong>static-ds</strong></span>), a <span class="command"><strong>static-key</strong></span> or <span class="command"><strong>static-ds</strong></span>),
the corresponding keys will be removed from the managed keys the corresponding keys will be removed from the managed keys
database, and RFC 5011 key maintenance will no longer be used database, and RFC 5011 key maintenance will no longer be used
@@ -9045,8 +9074,8 @@ example.com CNAME rpz-tcp-only.
<a name="dnssec_policy_grammar"></a><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</h3></div></div></div> <a name="dnssec_policy_grammar"></a><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</h3></div></div></div>
<pre class="programlisting"> <pre class="programlisting">
<span class="command"><strong>dnssec-policy</strong></span> <em class="replaceable"><code>string</code></em> { <span class="command"><strong>dnssec-policy</strong></span> <em class="replaceable"><code>string</code></em> {
<span class="command"><strong>dnskey-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>; <span class="command"><strong>dnskey-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
<span class="command"><strong>keys</strong></span> { ( csk | ksk | zsk ) key-directory <em class="replaceable"><code>duration</code></em> <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... }; <span class="command"><strong>keys</strong></span> { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };
<span class="command"><strong>parent-ds-ttl</strong></span> <em class="replaceable"><code>duration</code></em>; <span class="command"><strong>parent-ds-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
<span class="command"><strong>parent-propagation-delay</strong></span> <em class="replaceable"><code>duration</code></em>; <span class="command"><strong>parent-propagation-delay</strong></span> <em class="replaceable"><code>duration</code></em>;
<span class="command"><strong>parent-registration-delay</strong></span> <em class="replaceable"><code>duration</code></em>; <span class="command"><strong>parent-registration-delay</strong></span> <em class="replaceable"><code>duration</code></em>;
@@ -9136,8 +9165,8 @@ example.com CNAME rpz-tcp-only.
<p> <p>
A margin that is added to the publish interval in key A margin that is added to the publish interval in key
timing equations to give some extra time to cover timing equations to give some extra time to cover
unforeseen events. Default is <code class="constant">PT5M</code> unforeseen events. Default is <code class="constant">PT1H</code>
(5 minutes). (1 hour).
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>retire-safety</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>retire-safety</strong></span></span></dt>
@@ -9145,8 +9174,8 @@ example.com CNAME rpz-tcp-only.
<p> <p>
A margin that is added to the retire interval in key A margin that is added to the retire interval in key
timing equations to give some extra time to cover timing equations to give some extra time to cover
unforeseen events. Default is <code class="constant">PT5M</code> unforeseen events. Default is <code class="constant">PT1H</code>
(5 minutes). (1 hour).
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>signatures-refresh</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>signatures-refresh</strong></span></span></dt>
@@ -9220,7 +9249,7 @@ example.com CNAME rpz-tcp-only.
<dd> <dd>
<p> <p>
The TTL of the DS RRset that the parent uses. Default is The TTL of the DS RRset that the parent uses. Default is
<code class="constant">PT1H</code> (1 hour). <code class="constant">P1D</code> (1 day).
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>parent-propagation-delay</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>parent-propagation-delay</strong></span></span></dt>
@@ -9261,7 +9290,7 @@ example.com CNAME rpz-tcp-only.
<p> <p>
The <span class="command"><strong>managed-keys</strong></span> statement has been The <span class="command"><strong>managed-keys</strong></span> statement has been
deprecated in favor of <a class="xref" href="Bv9ARM.ch05.html#dnssec_keys" title="dnssec-keys Statement Grammar">the section called &#8220;<span class="command"><strong>dnssec-keys</strong></span> Statement Grammar&#8221;</a> deprecated in favor of <a class="xref" href="Bv9ARM.ch05.html#trust_anchors" title="trust-anchors Statement Grammar">the section called &#8220;<span class="command"><strong>trust-anchors</strong></span> Statement Grammar&#8221;</a>
with the <span class="command"><strong>initial-key</strong></span> keyword. with the <span class="command"><strong>initial-key</strong></span> keyword.
</p> </p>
</div> </div>
@@ -9282,7 +9311,7 @@ example.com CNAME rpz-tcp-only.
<p> <p>
The <span class="command"><strong>trusted-keys</strong></span> statement has been The <span class="command"><strong>trusted-keys</strong></span> statement has been
deprecated in favor of <a class="xref" href="Bv9ARM.ch05.html#dnssec_keys" title="dnssec-keys Statement Grammar">the section called &#8220;<span class="command"><strong>dnssec-keys</strong></span> Statement Grammar&#8221;</a> deprecated in favor of <a class="xref" href="Bv9ARM.ch05.html#trust_anchors" title="trust-anchors Statement Grammar">the section called &#8220;<span class="command"><strong>trust-anchors</strong></span> Statement Grammar&#8221;</a>
with the <span class="command"><strong>static-key</strong></span> keyword. with the <span class="command"><strong>static-key</strong></span> keyword.
</p> </p>
</div> </div>
@@ -9919,7 +9948,7 @@ view "external" {
(KSK) for the zone must be configured as a trust (KSK) for the zone must be configured as a trust
anchor in <code class="filename">named.conf</code>: that anchor in <code class="filename">named.conf</code>: that
is, a key for the zone must be specified in is, a key for the zone must be specified in
<span class="command"><strong>dnssec-keys</strong></span>. In the case <span class="command"><strong>trust-anchors</strong></span>. In the case
of the root zone, you may also rely on the of the root zone, you may also rely on the
built-in root trust anchor, which is enabled built-in root trust anchor, which is enabled
when <a class="xref" href="Bv9ARM.ch05.html#dnssec_validation"><span class="command"><strong>dnssec-validation</strong></span></a> is set to the when <a class="xref" href="Bv9ARM.ch05.html#dnssec_validation"><span class="command"><strong>dnssec-validation</strong></span></a> is set to the
@@ -10338,9 +10367,13 @@ view "external" {
<dt><span class="term"><span class="command"><strong>dnssec-policy</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>dnssec-policy</strong></span></span></dt>
<dd> <dd>
<p> <p>
The key and signing policy for this zone. Set to The key and signing policy for this zone. This is a string
<strong class="userinput"><code>"default"</code></strong> if you want to make use referring to a <span class="command"><strong>dnssec-policy</strong></span> statement.
of the default policy. There are two built-in policies:
<strong class="userinput"><code>"default"</code></strong> allows you to use the
default policy, and <strong class="userinput"><code>"none"</code></strong> means
not to use any DNSSEC policy, keeping the zone unsigned.
The default is <strong class="userinput"><code>"none"</code></strong>.
</p> </p>
</dd> </dd>
<dt><span class="term"><span class="command"><strong>dnssec-update-mode</strong></span></span></dt> <dt><span class="term"><span class="command"><strong>dnssec-update-mode</strong></span></span></dt>
@@ -15188,6 +15221,6 @@ HOST-127.EXAMPLE. MX 0 .
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -360,6 +360,6 @@ allow-query { !{ !10/8; any; }; key example; };
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -191,6 +191,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+103 -47
View File
@@ -36,12 +36,13 @@
<div class="toc"> <div class="toc">
<p><b>Table of Contents</b></p> <p><b>Table of Contents</b></p>
<dl class="toc"> <dl class="toc">
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.6</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.7</a></span></dt>
<dd><dl> <dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.7">Notes for BIND 9.15.7</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt>
@@ -57,7 +58,7 @@
</div> </div>
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h2 class="title" style="clear: both"> <div class="titlepage"><div><div><h2 class="title" style="clear: both">
<a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.6</h2></div></div></div> <a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.7</h2></div></div></div>
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h3 class="title"> <div class="titlepage"><div><div><h3 class="title">
@@ -101,11 +102,12 @@
C compiler. C compiler.
</p> </p>
<p> <p>
The OpenSSL cryptography library must be available for the target The <code class="filename">libuv</code> asynchronous I/O library and the
platform. A PKCS#11 provider can be used instead for Public Key OpenSSL cryptography library must be available for the target
cryptography (i.e., DNSSEC signing and validation), but OpenSSL is platform. A PKCS#11 provider can be used instead of OpenSSL for
still required for general cryptography operations such as hashing Public Key cryptography (i.e., DNSSEC signing and validation),
and random number generation. but OpenSSL is still required for general cryptography operations
such as hashing and random number generation.
</p> </p>
<p> <p>
More information can be found in the <code class="filename">PLATFORMS.md</code> More information can be found in the <code class="filename">PLATFORMS.md</code>
@@ -130,10 +132,73 @@
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h3 class="title"> <div class="titlepage"><div><div><h3 class="title">
<a name="relnotes-9.15.7"></a>Notes for BIND 9.15.7</h3></div></div></div>
<div class="section">
<div class="titlepage"><div><div><h4 class="title">
<a name="relnotes-9.15.7-changes"></a>Feature Changes</h4></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
<li class="listitem">
<p>
The <span class="command"><strong>dnssec-keys</strong></span> configuration statement,
which was introduced in 9.15.1 and revised in 9.15.6, has now
been renamed to the more descriptive
<span class="command"><strong>trust-anchors</strong></span>. [GL !2702]
</p>
<p>
(See release notes for
<a class="xref" href="Bv9ARM.ch08.html#relnotes-9.15.1-new" title="New Features">BIND 9.15.1</a>
and
<a class="xref" href="Bv9ARM.ch08.html#relnotes-9.15.6-new" title="New Features">BIND 9.15.6</a>
for prior discussion of this feature.)
</p>
</li>
<li class="listitem">
<p>
Added support for multithreaded listening for TCP connections
in the network manager [GL !2659]
</p>
</li>
</ul></div>
</div>
<div class="section">
<div class="titlepage"><div><div><h4 class="title">
<a name="relnotes-9.15.7-bugs"></a>Bug Fixes</h4></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
<li class="listitem">
<p>
Fixed a bug that caused <span class="command"><strong>named</strong></span> to leak memory
on reconfiguration when any GeoIP2 database was in use. [GL #1445]
</p>
</li>
<li class="listitem">
<p>
Fixed several possible race conditions discovered by Thread
Sanitizer.
</p>
</li>
</ul></div>
</div>
</div>
<div class="section">
<div class="titlepage"><div><div><h3 class="title">
<a name="relnotes-9.15.6"></a>Notes for BIND 9.15.6</h3></div></div></div> <a name="relnotes-9.15.6"></a>Notes for BIND 9.15.6</h3></div></div></div>
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h4 class="title"> <div class="titlepage"><div><div><h4 class="title">
<a name="relnotes-9.15.6-security"></a>Security Fixes</h4></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
<p>
Set a limit on the number of concurrently served pipelined TCP
queries. This flaw is disclosed in CVE-2019-6477. [GL #1264]
</p>
</li></ul></div>
</div>
<div class="section">
<div class="titlepage"><div><div><h4 class="title">
<a name="relnotes-9.15.6-new"></a>New Features</h4></div></div></div> <a name="relnotes-9.15.6-new"></a>New Features</h4></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "> <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
<li class="listitem"> <li class="listitem">
@@ -157,25 +222,32 @@
</p> </p>
</li> </li>
<li class="listitem"> <li class="listitem">
<p> <p>
Two new keywords have been added to the Two new keywords have been added to the
<span class="command"><strong>dnssec-keys</strong></span> statement: <span class="command"><strong>dnssec-keys</strong></span> statement:
<span class="command"><strong>initial-ds</strong></span> and <span class="command"><strong>static-ds</strong></span>. <span class="command"><strong>initial-ds</strong></span> and <span class="command"><strong>static-ds</strong></span>.
These allow the use of trust anchors in DS format instead of These allow the use of trust anchors in DS format instead of
DNSKEY format. DS format allows trust anchors to be configured DNSKEY format. DS format allows trust anchors to be configured
for keys that have not yet been published; this is the format for keys that have not yet been published; this is the format
used by IANA when announcing future root keys. used by IANA when announcing future root keys.
</p> </p>
<p> <p>
As with the <span class="command"><strong>initial-key</strong></span> and As with the <span class="command"><strong>initial-key</strong></span> and
<span class="command"><strong>static-key</strong></span> keywords, <span class="command"><strong>initial-ds</strong></span> <span class="command"><strong>static-key</strong></span> keywords, <span class="command"><strong>initial-ds</strong></span>
configures a dynamic trust anchor to be maintained via RFC 5011, and configures a dynamic trust anchor to be maintained via RFC 5011, and
<span class="command"><strong>static-ds</strong></span> configures a permanent trust anchor. <span class="command"><strong>static-ds</strong></span> configures a permanent trust anchor.
</p> </p>
<p> <p>
(Note: Currently, DNSKEY-format and DS-format trust anchors (Note: Currently, DNSKEY-format and DS-format trust anchors
cannot both be used for the same domain name.) [GL #6] [GL #622] cannot both be used for the same domain name.) [GL #6] [GL #622]
</p> </p>
</li>
<li class="listitem">
<p>
Added a new statistics variable <span class="command"><strong>tcp-highwater</strong></span>
that reports the maximum number of simultaneous TCP clients BIND
has handled while running. [GL #1206]
</p>
</li> </li>
</ul></div> </ul></div>
</div> </div>
@@ -193,27 +265,14 @@
</p> </p>
</li> </li>
<li class="listitem"> <li class="listitem">
<p> <p>
The DNSSEC validation code has been refactored for clarity and to The DNSSEC validation code has been refactored for clarity and to
reduce code duplication. [GL #622] reduce code duplication. [GL #622]
</p> </p>
</li> </li>
</ul></div> </ul></div>
</div> </div>
<div class="section">
<div class="titlepage"><div><div><h4 class="title">
<a name="relnotes-9.15.6-security"></a>Security Fixes</h4></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
<p>
Too many simultaneous pipelined TCP queries could cause
resource overuse. We now prevent this by enforcing a limit
on the number of simultaneous requests per active connection.
This flaw`is disclosed in CVE-2019-6477. [GL #1264]
</p>
</li></ul></div>
</div>
</div> </div>
<div class="section"> <div class="section">
<div class="titlepage"><div><div><h3 class="title"> <div class="titlepage"><div><div><h3 class="title">
@@ -719,9 +778,6 @@
<a name="relnotes_thanks"></a>Thank You</h3></div></div></div> <a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
<p> <p>
Thank you to everyone who assisted us in making this release possible. Thank you to everyone who assisted us in making this release possible.
If you would like to contribute to ISC to assist us in continuing to
make quality open source software, please visit our donations page at
<a class="link" href="https://www.isc.org/donate/" target="_top">https://www.isc.org/donate/</a>.
</p> </p>
</div> </div>
</div> </div>
@@ -744,6 +800,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -148,6 +148,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -914,6 +914,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -538,6 +538,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -210,6 +210,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+6 -5
View File
@@ -32,7 +32,7 @@
<div> <div>
<div><h1 class="title"> <div><h1 class="title">
<a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div> <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
<div><p class="releaseinfo">BIND Version 9.15.6</p></div> <div><p class="releaseinfo">BIND Version 9.15.7</p></div>
<div><p class="copyright">Copyright © 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div> <div><p class="copyright">Copyright © 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
</div> </div>
<hr> <hr>
@@ -192,8 +192,8 @@
<dt><span class="section"><a href="Bv9ARM.ch05.html#statschannels"><span class="command"><strong>statistics-channels</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#statschannels"><span class="command"><strong>statistics-channels</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#statistics_channels"><span class="command"><strong>statistics-channels</strong></span> Statement Definition and <dt><span class="section"><a href="Bv9ARM.ch05.html#statistics_channels"><span class="command"><strong>statistics-channels</strong></span> Statement Definition and
Usage</a></span></dt> Usage</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#trust_anchors"><span class="command"><strong>trust-anchors</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec-keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Definition <dt><span class="section"><a href="Bv9ARM.ch05.html#trust-anchors"><span class="command"><strong>trust-anchors</strong></span> Statement Definition
and Usage</a></span></dt> and Usage</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition <dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition
@@ -248,12 +248,13 @@
</dl></dd> </dl></dd>
<dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt> <dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
<dd><dl> <dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.6</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.7</a></span></dt>
<dd><dl> <dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.7">Notes for BIND 9.15.7</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt> <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt>
@@ -448,6 +449,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
Binary file not shown.
+7 -1
View File
@@ -54,10 +54,16 @@ notes.pdf: notes-wrapper.xml ${NOTESXML} releaseinfo.xml pkgversion.xml notevers
${XSLTPROC} ${top_srcdir}/doc/xsl/pre-latex.xsl notes-wrapper.xml | \ ${XSLTPROC} ${top_srcdir}/doc/xsl/pre-latex.xsl notes-wrapper.xml | \
${DBLATEX} -c notes.conf -Pdoc.layout="mainmatter" -o notes.pdf - ${DBLATEX} -c notes.conf -Pdoc.layout="mainmatter" -o notes.pdf -
# Produce notes.txt from notes.html using w3m, with some post-processing:
#
# - remove trailing spaces from every line,
# - remove empty lines from the end of the document,
# - prevent GitLab issue/MR identifiers from being split across two lines.
notes.txt: notes.html notes.txt: notes.html
${W3M} -dump -cols 75 -O ascii -T text/html < notes.html | \ ${W3M} -dump -cols 75 -O ascii -T text/html < notes.html | \
sed 's/ *$$//' | \ sed 's/ *$$//' | \
sed -e :a -e '/^\n*$$/{$$d;N;};/\n$$/ba' > notes.txt sed -e :a -e '/^\n*$$/{$$d;N;};/\n$$/ba' | \
sed '/ [!#]$$/{N;s| \([!#]\)\(\n\s*\)\([0-9][0-9]*\)|\2\1\3|;};' > notes.txt
# use xmllint to process include # use xmllint to process include
Bv9ARM.html: Bv9ARM-book.xml ${NOTESXML} releaseinfo.xml pkgversion.xml noteversion.xml Bv9ARM.html: Bv9ARM-book.xml ${NOTESXML} releaseinfo.xml pkgversion.xml noteversion.xml
+1 -1
View File
@@ -90,6 +90,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -220,6 +220,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+2 -2
View File
@@ -215,7 +215,7 @@
</p> </p>
<p> <p>
Note: When reading the trust anchor file, Note: When reading the trust anchor file,
<span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code> <span class="command"><strong>delv</strong></span> treats <code class="option">trust-anchors</code>
<code class="option">initial-key</code> and <code class="option">static-key</code> <code class="option">initial-key</code> and <code class="option">static-key</code>
entries identically. That is, even if a key is configured entries identically. That is, even if a key is configured
with <span class="command"><strong>initial-key</strong></span>, indicating that it is with <span class="command"><strong>initial-key</strong></span>, indicating that it is
@@ -621,6 +621,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -1188,6 +1188,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -376,6 +376,6 @@ nsupdate -l
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -156,6 +156,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -270,6 +270,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -341,6 +341,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -250,6 +250,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -498,6 +498,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -589,6 +589,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -405,6 +405,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -171,6 +171,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -424,6 +424,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -707,6 +707,6 @@ db.example.com.signed
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -214,6 +214,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -143,6 +143,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -168,6 +168,6 @@ plugin query "/usr/local/lib/filter-aaaa.so" {
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -366,6 +366,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -610,6 +610,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -214,6 +214,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -463,6 +463,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -117,6 +117,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -119,6 +119,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -121,6 +121,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+27 -27
View File
@@ -110,17 +110,7 @@ dlz
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.11"></a><h2>DNSSEC-KEYS</h2> <a name="id-1.13.27.11"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection">
<a name="id-1.13.27.12"></a><h2>DYNDB</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br> dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
    <em class="replaceable"><code>unspecified-text</code></em> };<br>     <em class="replaceable"><code>unspecified-text</code></em> };<br>
@@ -128,7 +118,7 @@ dyndb
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.13"></a><h2>KEY</h2> <a name="id-1.13.27.12"></a><h2>KEY</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
key <em class="replaceable"><code>string</code></em> {<br> key <em class="replaceable"><code>string</code></em> {<br>
algorithm <em class="replaceable"><code>string</code></em>;<br> algorithm <em class="replaceable"><code>string</code></em>;<br>
@@ -138,7 +128,7 @@ key
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.14"></a><h2>LOGGING</h2> <a name="id-1.13.27.13"></a><h2>LOGGING</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
logging {<br> logging {<br>
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br> category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
@@ -159,8 +149,8 @@ logging
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.15"></a><h2>MANAGED-KEYS</h2> <a name="id-1.13.27.14"></a><h2>MANAGED-KEYS</h2>
<p>Deprecated - see DNSSEC-KEYS.</p> <p>Deprecated - see TRUST-ANCHORS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br> managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
    | initial-key | static-ds |<br>     | initial-key | static-ds |<br>
@@ -170,7 +160,7 @@ managed-keys
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.16"></a><h2>MASTERS</h2> <a name="id-1.13.27.15"></a><h2>MASTERS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br> masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
    <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>     <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
@@ -180,7 +170,7 @@ masters
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.17"></a><h2>OPTIONS</h2> <a name="id-1.13.27.16"></a><h2>OPTIONS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
options {<br> options {<br>
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br> allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
@@ -479,7 +469,7 @@ options
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.18"></a><h2>PLUGIN</h2> <a name="id-1.13.27.17"></a><h2>PLUGIN</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br> plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
    } ];<br>     } ];<br>
@@ -487,7 +477,7 @@ plugin
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.19"></a><h2>SERVER</h2> <a name="id-1.13.27.18"></a><h2>SERVER</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
server <em class="replaceable"><code>netprefix</code></em> {<br> server <em class="replaceable"><code>netprefix</code></em> {<br>
bogus <em class="replaceable"><code>boolean</code></em>;<br> bogus <em class="replaceable"><code>boolean</code></em>;<br>
@@ -525,7 +515,7 @@ server
</div> </div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.20"></a><h2>STATISTICS-CHANNELS</h2> <a name="id-1.13.27.19"></a><h2>STATISTICS-CHANNELS</h2>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
statistics-channels {<br> statistics-channels {<br>
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br> inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
@@ -536,9 +526,19 @@ statistics-channels
</p></div> </p></div>
</div> </div>
<div class="refsection">
<a name="id-1.13.27.20"></a><h2>TRUST-ANCHORS</h2>
<div class="literallayout"><p><br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds )<br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
</p></div>
</div>
<div class="refsection"> <div class="refsection">
<a name="id-1.13.27.21"></a><h2>TRUSTED-KEYS</h2> <a name="id-1.13.27.21"></a><h2>TRUSTED-KEYS</h2>
<p>Deprecated - see DNSSEC-KEYS.</p> <p>Deprecated - see TRUST-ANCHORS.</p>
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
@@ -618,10 +618,6 @@ view
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br> dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br> dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br> dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br> dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br> dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br> dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
@@ -812,6 +808,10 @@ view
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br> transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
    ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>     ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br> trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
    initial-key | static-ds | initial-ds<br>
    ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
trusted-keys { <em class="replaceable"><code>string</code></em><br> trusted-keys { <em class="replaceable"><code>string</code></em><br>
    <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
    <em class="replaceable"><code>integer</code></em><br>     <em class="replaceable"><code>integer</code></em><br>
@@ -1030,7 +1030,7 @@ zone
<div class="literallayout"><p><br> <div class="literallayout"><p><br>
dnssec-policy <em class="replaceable"><code>string</code></em> {<br> dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br> dnskey-ttl <em class="replaceable"><code>duration</code></em>;<br>
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br> keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br> parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br> parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
@@ -1095,6 +1095,6 @@ dnssec-policy
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -492,6 +492,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -155,6 +155,6 @@
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>
+1 -1
View File
@@ -437,6 +437,6 @@ nslookup -query=hinfo -timeout=10
</tr> </tr>
</table> </table>
</div> </div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p> <p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.7 (Development Release)</p>
</body> </body>
</html> </html>

Some files were not shown because too many files have changed in this diff Show More